Cadence Reader

Privacy Policy

Last updated 27 September 2026 · Effective 27 September 2026

You can use Cadence without an account. Your books stay on your device unless you subscribe to Cadence Plus and turn on cloud sync, which stores them for your own account and nobody else's.

The short version: You can use Cadence without an account. Requests the app makes to our service carry technical information (section 7); on Android, Google Play Billing also sends Google technical information (section 10). A problem report is sent only if you choose to send it. We do not keep the name or email address from your sign-in, and there are no passwords. On the free plan your books stay on your device. On Cadence Plus we sync facts about your reading between your devices, and if you turn on cloud sync we also store your book files, for your own account only. Neural voices, where Cadence offers them, speak on your device. There is no advertising and no tracking, and we do not sell your information.

1. Who we are

Cadence Reader is made by SUBVERTING COMPLEXITY (PTY) LTD, registered in South Africa (registration 2026/180066/07), at 301 Turin Street, Lombardy Estate, Paradiso, Pretoria 0081, South Africa. In this policy that company is "we".

You can reach us at support@subvertingcomplexity.com. Our staff read messages sent to it. You can also send us a problem report from inside the app (section 8).

This policy covers the Cadence Reader app on iOS and iPadOS, on Android, and the Cadence web reader. It is published in accordance with the requirements of the Apple App Store and Google Play, and with the Protection of Personal Information Act, 2013 (POPIA) of South Africa.

2. Your Cadence account

You can use Cadence without an account. Reading, listening and importing books all work without one. Before you sign in, requests to our service carry the technical information described in section 7; on Android, Google Play Billing also sends Google the technical information described in section 10. A problem report is sent only if you choose to send one (section 8).

An account is created only when you sign in with Apple or with Google. We do not use passwords, so we do not store, hash or reset one.

When you sign in, Apple or Google tells us a stable identifier for you. We do not keep your name or your email address. On iPhone and iPad, signing in also sends Apple's record of your download of Cadence, and we keep its identifier, which belongs to the Apple Account that downloaded the app. We link it to your account and use it to find that account again when you sign in. When you sign in through a browser, we ask Apple for nothing beyond the sign-in itself and Google for only the basic sign-in permission.

Your account record holds a random account identifier, when it was created and its status, and which sign-ins are linked to it and when. Sections 5, 6 and 12 describe some of the other facts we keep about an account, such as its storage allowance and its link to your purchases.

Each device you sign in on gets a session. For each session we keep details including a one-way hash of its sign-in token, never the token itself; whether it is the app or a browser; when it started, when it expires and whether it was ended; and when it was last used, which we update at most about once an hour. For a sign-in in the app, we also keep the random identifier the app creates for your installation, and a name and platform for the device so you can recognise it, such as "Pixel 8" and Android. A sign-in on the web reader currently records no device name or platform. We do not keep your IP address or the name you gave your phone against a session. A session lasts up to 90 days in the app and up to 30 days in a browser.

On every plan, Your devices in Settings lists the sessions that are still live, and lets you sign one device or every other device out. Signing a device out ends its session and deletes nothing on it. The list never shows the random installation identifier or any token.

On your device, the sign-in token is protected by the iOS Keychain or the Android Keystore. A browser sign-in uses one secure, HTTP-only session cookie and a short-lived cookie that exists only while the sign-in completes. The session cookie is set for cadencereader.app and every address under it, so your browser sends it to all of them, including this website, not only to the one that signed you in. That is what lets one sign-in work for both the web reader and our server. The domain is ours, and so is every address under it. The short-lived cookie goes only to the address that set it. This website also sets a cr-theme cookie, if you use its light and dark button, which holds only that choice for up to one year. We set no other cookies for readers. Cloudflare, which runs our servers, may set cookies of its own that it needs to protect the service.

If you stop using Sign in with Apple for Cadence, Apple tells us and we end every session on that account. If you delete your Apple account, Apple tells us and we delete your Cadence account as described in section 12.

3. Data stored on your device

Whatever plan you are on, Cadence keeps these in its own storage on your device:

  • The books, documents, pictures, audio and video you import, their covers, and the text Cadence recognises in pictures and scanned pages.
  • Your place in each book, your bookmarks and their notes, your favourite and finished marks, and the collections you make and which books are in them.
  • The words you have told Cadence how to say, and how, for one book or for every book.
  • If you use Cadence Plus, the books your other devices have imported, listed with their title, author and your place but with no file until you download it (section 4) or import it on this device.
  • Your settings, including voice, speed, theme and per-book settings.
  • If you choose a folder for Cadence to watch, the record of which folder and what it has imported from it.
  • Changes waiting to sync, and problem reports waiting to send.
  • The last error the app recorded, and a log of recent errors and warnings, after Cadence has taken out what it recognises as file paths, web addresses, file names and quoted text.
  • The random installation identifier from section 2, and, if you are signed in, your sign-in token, your account identifier and what your plan includes (section 6).
  • Which Cadence account each book was imported under, so that the library shows each account on the device only its own books.
  • If you use Cadence Plus, the neural voices you download (section 4), until you delete them.
  • Short audio clips of the sentences Cadence is reading or is about to read, in the app's cache. Your device may clear them at any time, and Cadence removes a book's clips when you delete the book.
  • Which voice packs' extra terms you have accepted, the version of those terms and when you accepted them (section 4).
  • Working data Cadence derives from these, such as a search index of your books' text.

Signing out in the app on iOS or Android asks our server to end that session, then removes your sign-in token and your plan from your device. If the server cannot be reached, the app removes the local token but the server session may remain valid until it expires. Your books stay on the device, and the library shows them again when you sign back in to the same account.

You can delete a book in the app. You can also remove every book from your device at once, from Settings, Remove local books, with everything Cadence keeps about them, including places, bookmarks, marks, collections, recognised text, watched folders, the changes waiting to sync, problem reports waiting to send and every spoken clip. Your settings, your sign-in, your plan and your downloaded voices stay. On a phone, the removal finishes when you next open Cadence. You can delete downloaded voices from Settings, Voice, Downloaded voices, on any plan. Uninstalling Cadence removes its storage from your device.

Backups work differently on each platform. On iPhone and iPad, Cadence's storage, apart from caches and downloaded voices, is included in your own iCloud or computer backup, and its documents folder, which holds your books and library data, can be seen in the Files app. On Android, if you have turned on your phone's backup, Android may include a small part of Cadence's storage in your own Google backup, such as the titles and authors of books that in-car listening can list; your books, your reading data and your sign-in token are left out. We never receive these backups.

4. Your books, and the files you choose to sync

On the Free plan, and on Cadence Plus with cloud sync off, your books stay on your device. We do not receive them.

Text recognition runs on your device.

Voices. Cadence reads aloud with the voices your device or browser provides and, where Cadence offers them, on Cadence Plus in the iPhone, iPad and Android apps, with neural voices you download. Some voices your device or browser provides work over the internet. With one of those, the text it reads goes to the company that provides the voice, under that company's own privacy policy, not to us. On Android, Cadence marks these voices "needs internet".

A neural voice needs a model, which you download when you choose Download for that voice. Your phone fetches it from our download host, which runs on Cloudflare. The request asks only for the file. It carries no account, no sign-in, no installation identifier and nothing about your books. Like any request over the internet, it shows the host your IP address, which file you asked for, which can show which voice you chose, and the standard details your phone's download system adds to every request. Cloudflare may record these details in its logs, as section 7 describes.

Once the model is on your device, Cadence turns text into speech on your device. The text a neural voice reads, and the audio it produces, are not sent to us or to anyone else to do this. Which voice you choose for a book is part of that book's settings, which sync on Cadence Plus (section 5).

Some voice packs have extra terms of use, which you accept before you first use the pack (our Terms of Service, sections 30 and 31). Cadence keeps a record on your device of which pack's terms you accepted, which version of them, and when, so that it does not ask again on that device. If the terms change, you are asked again.

Cloud sync on Cadence Plus. If you subscribe to Cadence Plus and turn on cloud sync, Cadence uploads your library content so your other devices can download it:

  • the file Cadence keeps for each book, whether it is a book, a document, a recording or a book assembled from pictures; for a video, that is the audio if Cadence lifted it out when you imported the video, and otherwise the whole video;
  • the text Cadence recognised in pictures and scanned pages, with where each line sits on the page;
  • a fingerprint (hash) of each book file, the size of what is stored, and the records needed to manage it, such as which books point at a file, whether it is stored, and how much of your storage it uses.

We use these only to upload, store, sync, download, secure and delete your files, and to work out how much storage you use. Your synced files are private to your account. Another reader, including a member of the same Cadence family, cannot reach them.

Your library content may contain, or may indirectly reveal, sensitive or special-category personal information. For example, the books or documents in your library may reveal information concerning health, religious or philosophical beliefs, political opinions, sexuality or other sensitive characteristics.

Cadence processes this information only to provide the functionality you request. Cadence does not use your library content to infer, profile, advertise to or make decisions about you based on sensitive characteristics. We do not routinely look through synced files for copyright or any other purpose. We check that each uploaded book file matches the size and fingerprint your device sent, to make sure what we store is the file you sent, and we may use automated measures against malware and abuse.

We process your synced library content because it is needed to provide the cloud sync service you ask for. Where required by applicable data-protection law, including in relation to special personal information under POPIA or special-category personal data under the GDPR, Cadence relies on your explicit consent for this processing. Cadence asks for that consent before cloud sync is turned on, and does not turn it on without it.

You may withdraw this consent by turning off Automatic sync in Settings, Library, on each device where you turned it on. Withdrawal does not affect processing that was lawful before consent was withdrawn. Cloud content will then be handled as section 11 describes.

5. What we hold if you subscribe to Cadence Plus

On the Free plan, nothing syncs. The app does not try, and our servers refuse a sync request from an account without Cadence Plus.

On Cadence Plus, signed in, Cadence keeps these in step between your devices:

  • Your library list. Each book's title and author, what kind of file it is, when you added it, how large its file is, a fingerprint of the file's contents, and whether you stopped syncing its file. The fingerprint lets Cadence recognise the same file when you import it on another device. It cannot be turned back into the file.
  • Your place in each book, and how far through it you are.
  • Per-book settings.
  • Favourite and finished marks, with when you set them.
  • Bookmarks, with where each one is, the note you wrote on it and when you made it.
  • The words you have told Cadence how to say: each word, how to say it, and whether it is for one book or for every book.
  • Your collections: the name you gave each one, when you made it, and which books are in it.

When you remove something, a marker saying it was removed is kept so your other devices remove it too. You can delete synced books one at a time, or all of them at once from Settings, Delete synced books, which removes each one from every device in the same way. Books that never synced stay on your device.

With cloud sync on (section 4), your other devices download a book's file from the cloud, automatically or when you open the book, as you choose in Settings. In a browser, a file is downloaded only when you ask. With it off, or for a book whose sync you stopped, your other devices list the book with no file, and to read it there you import the file. If the file is the same one, Cadence puts it under the book already listed, so your place, bookmarks and settings are there. A different file is added as a new book.

Storage. Cadence Plus normally includes 15 GB of cloud storage. An identical file is stored and counted once, however many of your books use it. When the storage is full, further uploads are refused until there is room; nothing already stored is deleted to make room.

Cadence families. A Cadence Plus subscriber can share it with up to five other people. The family shares one storage allowance, but each member has their own private library. Everyone in the family can see the family's total use of that storage and their own.The subscriber sees, for each member, the name that member chose to give when they joined, and when they joined. The subscriber never sees a member's books, titles, authors, files, recognised text or reading, and never their account identifier or email address, which we do not hold.

6. What we hold about your purchases

Apple and Google sell Cadence Plus. We never see your card, your billing address or your Apple or Google account details.

You need to be signed in to Cadence to buy or restore Cadence Plus. If a purchase reaches the app while you are signed out, such as a renewal, the app does not tell us about it until you sign in. Apple and Google still tell us directly about renewals and other changes to a subscription we already know about.

When you buy, the app attaches an identifier to the purchase so it can be linked to your Cadence account. On Apple, that identifier is your Cadence account identifier. On Google, it is a one-way digest of it. The app then sends us the purchase's transaction reference, and we ask Apple or Google directly for its details. Apple and Google also tell us when a subscription renews, lapses, is refunded or changes.

We also keep, for Cadence accounts, the one-way digest we send Google. It is derived from your Cadence account identifier and cannot be turned back into it. We keep it so that when Google tells us about a purchase we have no record of, we can find the account it belongs to instead of guessing.

For each subscription we keep the store's own references and dates for it, such as which store sold it and which product it is, its status, when it started, expires, entered a grace period or was revoked, whether it will renew, and the identifier the app attached. We do not keep the price, the currency or your country.

Your device receives what it needs to show and apply your plan, such as whether you have Cadence Plus, until when, where it comes from and whether it will renew.

A purchase record stays with the Cadence account that subscribed. If that Cadence account was deleted, and the same Apple or Google purchase is later bought again, restored or reported by the app while signed in to a different Cadence account, the purchase record can move to that account. In practice, only someone with access to the same Apple or Google account can cause it. On Apple, we also ask Apple to attach the new account's identifier to the subscription. Each move is kept in a record that cannot be changed, naming the subscription, the store, the old and new account identifiers and when it happened. Our staff can see that record on the account.

7. Technical information we necessarily see

  • Your IP address, the random installation identifier from section 2, and your account identifier if you are signed in, to limit how often requests can be made and to prevent abuse. The app sends the installation identifier with its requests. The counters that use them are short-lived and expire automatically within a few hours.
  • Your app version and platform, sent with each request.
  • Request records. Cloudflare, which runs our servers, records details of each request in its platform logs, including the IP address. Our own log lines for a request that did not succeed hold its request identifier, method, path and result, and never the request body. A sign-in attempt is logged with its kind and outcome, but not who signed in. Some of our log lines name an account identifier, for example when an account is deleted, its stored files are cleared, a purchase or sync step fails, or its sessions are ended.
  • Voice downloads. When you download a neural voice (section 4), our download host sees your IP address, which file you asked for, and the standard details your phone adds to the request. The request carries no account and no installation identifier.

We use these only to run and protect the service, and we do not build a profile of you from them.

8. If you report a problem

Cadence has a Report a problem form. You can open it in four ways: from Settings, from Reader settings while you are reading a book, with the Report this button on the screen Cadence shows when it runs into an unexpected error, and by shaking your phone or tablet. A shake only asks whether you want to report a problem. It does not open the form or send anything by itself, and you can turn it off with Shake to report a problem in Settings. Whichever way you open the form, nothing is sent until you press Send report.

What we receive is what you typed, when you wrote the report, and a short technical note that the form shows you before you send it: your app version, your platform and its version, your device model, which plan you are on, and the last error the app recorded. If you open the form with Report this, the note carries the error that caused that screen, shortened in the same way. Opening the form from a book does not itself attach that book. Your own description may include details about a book if you type them.

If Cadence has recorded recent errors or warnings, the form also offers to attach a log of them. Its checkbox is ticked each time the form opens; you can untick it before sending. Cadence makes a best effort to remove book titles, text from books and file names from the log, but it may still contain some. If you leave the box ticked, we store the log with your report on our servers. The email copy of the report does not include the log.

To notice a shake, Cadence reads your device's motion sensor while Cadence is open on your screen and Shake to report a problem is on. It stops reading it when you switch away from Cadence or lock the screen, including while a book is being read aloud. There is no shake on the web. The readings stay on your device and are not stored or sent. Cadence does not ask for motion or physical activity permission.

The email address field is optional and is empty unless you fill it in. We use it only to contact you about that report, usually to ask a question if the report is not clear enough to act on. It is not a support ticket. We may not reply to a report that is already clear, and sending one does not promise you a fix.

You can report a problem without an account, and we do not create one to accept it. If you are signed in when you send it, your account identifier is stored with the report.

Reports, including an attached log if you leave its box ticked, are stored on our servers and deleted automatically about 90 days after we receive them. We also try to email a copy without the log to the support mailbox at the address in section 1, which our email provider holds. A rate limit or delivery error may prevent that email, but the stored report remains available to our staff. Support mail may be forwarded to staff inboxes. Copies in the support mailbox and those inboxes may be kept longer, until deleted by hand. Deleting your Cadence account does not delete a report before its 90 days end.

If you would like a report deleted sooner, write to the address in section 1 with the email address you gave in the report, or roughly when you sent it and what it said. We will delete the stored report and take reasonable steps to have the email copies deleted.

9. What we do not do

  • No advertising and no advertising identifiers.
  • No analytics, no crash reporting SDK, and no session recording. In the Android app, Google's Play Billing library sends Google information about its own operation (section 10). It goes to Google, not to us.
  • No tracking across other apps or websites.
  • No selling of your information, and no sharing of it for advertising.
  • No profiling, and no automated decisions that have legal or similarly significant effects on you.
  • No reading or indexing of your books on our servers, and no routine review of the files you sync (section 4 says what is checked).
  • No access to your location, contacts, calendars or microphone.
  • No access to the camera or your photos unless you ask for it. Cadence asks for the camera only when you choose Camera to photograph the pages of a book, and it reads only the pictures you pick when you choose Photos. Cadence turns them into a book on your device. Like any other book, it syncs only as sections 4 and 5 describe, if you use Cadence Plus.

10. Who else touches your data

  • Cloudflare runs our servers, database and logs, sends problem report emails, stores the files you sync (section 4) in its R2 storage service, and serves the neural voices you download (section 4). Cloudflare encrypts stored files at rest, and files travel between your device and Cloudflare encrypted. Your synced files and other information may be processed outside South Africa or outside your own country, under contractual safeguards with Cloudflare.
  • Apple provides Sign in with Apple and sells Cadence Plus on the App Store.
  • Google provides Sign in with Google and sells Cadence Plus on Google Play. In the Android app, Google's Play Billing library, which Cadence uses to sell Cadence Plus, also sends Google information about how the library itself is working: whether its requests to Google Play succeeded or failed, and whether it could connect, with technical details of your phone such as its model, Android version, language and region settings, mobile network and connection type. It does this whether or not you buy anything or sign in, because each time Cadence starts or comes back to the screen it asks Google Play whether you already own Cadence Plus. Google says it uses this to improve the library and to help with errors. It goes to Google, not to us, and Google documents no way for an app to turn it off.
  • Our email provider, currently Purelymail, holds the support mailbox that receives problem report emails and messages you send us. Support mail may be forwarded to staff inboxes held by other mail providers, such as Google, which may also store those copies.

We use no analytics or advertising partners. Apple and Google collect information under their own privacy policies when you use their sign-in and stores, and Google collects the Play Billing information above under its own privacy policy.

A small number of people at Subverting Complexity can use an internal admin page, behind Cloudflare Access. From it they can see an account's identifier, creation date and status; which sign-in providers it uses and when they were linked; its sessions, including each device's name, platform and installation identifier and when it was last used; its subscription records and any moves between accounts; whether it has Cadence Plus and why; how many items it has synced and when it last synced, but not what they are; its storage allowance and use, and whose family storage it uses; and problem reports in full. They can also act on an account, for example to sign it out, delete it, grant Cadence Plus or change its storage allowance. Staff do not open synced files, except where the law requires or allows it, for example to investigate a specific legal complaint. What staff do on the admin page is recorded, and that record is kept for two years.

11. How long we keep things

  • Your synced library data (section 5): for as long as your account exists, including after Cadence Plus ends, so it is there if you come back. Removal markers are kept for the same time.
  • Your synced book files (section 4): until you delete the book, stop its sync or turn cloud sync off. The cloud copy is then deleted, usually when your device next syncs, unless another of your books uses the identical file.
  • Text recognised from pictures and scanned pages that you synced (section 4): until you remove that text in the app with Remove OCR text, your files are deleted after Cadence Plus ends, or you delete your account. It may stay in our storage after you delete its book, stop its sync or turn cloud sync off.
  • After Cadence Plus ends, or you leave or are removed from a Cadence family, your synced files are kept for about 30 days so you can download them, and then deleted, unless Plus resumes in that time. Where the law gives you the right to have them erased sooner, you can ask us under section 12.
  • Deletion from Cloudflare's storage may not immediately remove copies held in Cloudflare's own backup and recovery systems.
  • Your account, sign-in links and sessions: until you delete your account. Expired and ended sessions are kept until then too. A sign-in link also goes when you remove it.
  • Your membership of a Cadence family, with the name you gave when you joined: while you are a member.
  • The voice terms you accepted (section 4): on your device, until you uninstall Cadence.
  • Purchase records, and records of purchases moving between accounts: kept after you delete your account, as described in section 12.
  • Problem reports you send us: the server copy, including any attached log, is deleted about 90 days after we receive it. A copy without the log in the support mailbox or a staff inbox may be kept longer, until deleted by hand. Deleting your account does not delete reports, but you can ask us to delete one sooner.
  • Short-lived records, such as rate-limit counters, copies of responses that let a repeated request get the same answer, sign-ins in progress, and Apple and Google purchase notifications we have already handled: they expire automatically, within a few minutes to about a week.
  • Records of what staff do on the admin page: two years.

12. Deleting your data

You can delete your account and what we hold for it from Settings in the app. We do not need an email address to prove it is you, because you are already signed in. It happens straight away and cannot be undone.

We delete any files stored for your account, including recognised text; your synced library list, reading places, per-book settings, favourites, finished marks, bookmarks, the words in your Pronunciation lists, and your collections; your membership of any Cadence family; short-lived records kept against your account; every session; and your links to Apple and Google. Your account is then marked as deleted. A few short-lived records, such as some rate-limit counters, are not deleted but expire on their own within a few hours.

What we keep:

  • The account identifier, with its creation date and when any Cadence Plus it had through a family or from us ended, marked as deleted.
  • The purchase records described in section 6. They hold no name, email address or device, but they do hold the store's references and the identifier the app attached, which on Apple is the deleted account's identifier. Refunds, disputes and tax rules need them. As section 6 says, a record can move to a different Cadence account if the same Apple or Google purchase is later used there, and that move is recorded.
  • The one-way Google account digest described in section 6, kept with the account row. It is derived from the identifier we already keep, and a purchase record may still name it.
  • Any Cadence Plus we gave the account directly, marked as ended.
  • A Cadence family you started stays with its subscription, so its members keep their Cadence Plus while that subscription lasts.
  • Problem reports (section 8), with the deleted account's identifier if they were sent signed in.
  • Records of what staff did on the account (section 10).

Deleting your account signs you out on that device and leaves your books and downloaded voices on it. It does not cancel Cadence Plus. Cancel that in your App Store or Google Play subscriptions.

You can also ask us to delete your data by writing to the address in section 1. That includes your synced files during the 30 days after Cadence Plus ends, where the law gives you that right. If we delete your account at your request, we can also cancel a renewing Google Play subscription at the same time if you ask.

13. Permissions

  • Files. Cadence opens files only when you pick, share or open them into it, or from a folder you choose for Cadence to watch.
  • Clipboard. When you open the import menu, Cadence asks your device whether the clipboard holds text or a picture, so that it knows whether to offer Clipboard as a source. That question does not read what you copied. Cadence reads the content itself only after you choose Clipboard: on iPhone and iPad you press Apple's own Paste button and iOS hands the content over, so Cadence never reads the clipboard itself; on Android, choosing Clipboard reads what you copied straight away. What you paste becomes a book on your device, which syncs only as sections 4 and 5 describe. Cadence never looks at the clipboard in the background.
  • Background audio, so listening continues when you leave the app.
  • Notifications (Android, optional), for the playback controls.
  • Motion sensor (iPhone, iPad and Android, not on the web), only to notice a shake, which asks whether you want to report a problem (section 8). It needs no permission, the readings never leave your device, and you can turn it off with Shake to report a problem in Settings.
  • Media controls, Live Activities, widgets and in-car listening show a book's title, author, cover and progress, and in-car listening can list the books in your library. That information is handed to your device's operating system, which may show it on connected devices such as a car, a watch or Bluetooth speakers. Cadence does not send it to us for this.

14. Children

Cadence is not directed at children and we do not knowingly collect information from children. Cadence does not take part in the Apple Kids Category or Google Play's Designed for Families programme. There is no chat, no sharing of content between readers, and no advertising. A problem report is sent only to us, never shown to another reader. Cadence Plus is bought through Apple or Google, subject to their parental controls.

15. Your rights

Depending on where you live, you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to object to how we use it, or to receive a copy. Write to support@subvertingcomplexity.com and we will respond within the time the law requires. Because we do not keep your email address, we may ask you for details that help us find your account. Section 12 is the fastest route to deletion, and it does not require you to write to us at all. It does not delete problem reports (section 8).

Under POPIA in South Africa you have the right to be notified about whether your personal information is being processed, to request access to it, to request correction or deletion, to object to processing, and to lodge a complaint with South Africa's Information Regulator (inforegulator.org.za). Where the GDPR applies to you, the equivalent rights are available on the same email address.

16. Security

Data on your device sits in Cadence's app storage, protected by your device's security. Your sign-in token is protected by the iOS Keychain or the Android Keystore; in a browser, it is held only in the HTTP-only cookie described in section 2. Data travelling between the app and our servers is encrypted. On our servers, sign-in tokens are stored only as a one-way hash. The admin page is behind Cloudflare Access and a list of named staff. Keep your device's operating system up to date and protect it with a passcode or biometric lock.

17. Changes to this policy

We update this page when what we do changes, and we aim to do so before the change reaches you. The "Last updated" date above is when it last changed. Where a change is significant, we will tell you, for example in the app or on this page.

18. Contact us

For any questions about this Privacy Policy or your privacy, contact our Information Officer at:

SUBVERTING COMPLEXITY (PTY) LTD
301 Turin Street, Lombardy Estate, Paradiso
Pretoria 0081, South Africa
Email: support@subvertingcomplexity.com
Web: subvertingcomplexity.com