Privacy statement

It stays on your phone

Packlet keeps your work on your own device. This page says what lives there, at which three moments something crosses the network, and what we can see about you. That last part is almost nothing, and that is not a promise but a consequence of how the app is built.

Revised 20 September 2026 NL EN

On the device

Your notes are files on your phone

Whatever you write, record or photograph lands in the app's protected area as plain Markdown files. There is no account and no sign-in, so there is no user administration in which we could look you up.

The coach runs on your phone itself, on a language model stored there. There is no cloud model and no fallback to one: put the device in airplane mode and it keeps working.

What is stored locally
Your notes, coach conversations, recordings, photos, your workspaces and the log of what the app did.
What we see of it
Nothing. There is no screen, no export and no key that would give us access to those files.
Analytics
None. No Firebase, no Mixpanel, no Sentry. The privacy file Apple requires lists zero collected data types and tracking set to false.
Photos
EXIF data, including the place a photo was taken, is stripped when the photo is saved.
Encryption
The files are encrypted as long as your phone has a passcode; that is the iOS default. You can also set a PIN on Packlet itself.

The network

Three moments when something crosses the network

The core loop of the app is offline. A check guards that and blocks a release: a script scans the code for network calls and fails on anything outside a recorded list with a name and a reason.

01

Fetching the model

Once, on first launch, the app downloads two models: the one that lets you dictate and the one the coach thinks with. Around 2.8 GB together, over Wi-Fi, and never again after that.

What goes out
Nothing. It is a download, not an upload.
Personal data
None, apart from the IP address every download leaves with the party serving the file.

02

Apple, while the app is in testing

The app reaches testers through TestFlight, because that is how an iOS app travels outside the App Store. Apple is a party here, separate from us, with its own terms and privacy policy. What that means in practice is below.

03

The room, if you enter one yourself

This is the only place where content crosses, and it takes an action from you. Someone opens a room and shows a code; whoever joins scans it and confirms. Without that action the app opens no connection at all.

What crosses
Concepts and scores, encrypted.
What does not
Your notes and quotes. They stay on the device.
The relay
A pass-through without storage: no table, no row, no retention period.
How often asked
Every session, again.

A residual risk, and it stays one: everyone who scanned the same code shares a single key. In a room of people who know each other that is bearable; for an open audience it would not be.

The beta

What we see of you while you test

While Packlet is not in the App Store yet, you install it through TestFlight. Who you are to us depends on how you came in.

Through the public link
You are anonymous to us. Apple shows us no name and no email address. We see counts: when the app was installed, how many sessions there were, and whether it crashed.
Through an email invitation
Then your name and email address do appear in our tester list, because you gave them to us or to your programme.
Feedback you send in TestFlight
We read it, along with the screenshot you attach. If you came in through the public link, adding your email address is your own choice; if you do, it is visible only on that one report.
Crash reports
Apple passes crash data from the app on to us. We put no crash service of our own in the app.

Use your own Apple account for TestFlight, not one belonging to your school. What you write in the app never touches that account, but the installation is tied to it.

Your rights

Taking it with you, erasing it, and what we cannot do

Take it with you
One button hands you your notes, evidence and coach conversations as plain Markdown files. Readable in any text editor and in Obsidian, without Packlet.
Erase
One button, confirmed by typing a word, deletes everything the app holds about you. No bin, no flag, and it cannot be undone.
Access
You already have it: the files are yours and they are on your device.
What we cannot do
Read, restore or remotely delete your notes. If you lose your phone, there is no copy with us.

This site

What packlet.app itself keeps

The website is the one surface where we do keep something about you, and only if you fill in a form yourself.

Waiting list and whitepaper
If you sign up we keep your name, your email address, the time and which form it was. We use it to send you that one email and, later, word about the beta.
Where that lives
In the key-value store of Vercel, our hosting party. The email itself goes out through Resend, which receives your address and the contents of that message.
For how long
Until you ask to come off. One email to info@packlet.app is enough.
Cookies and statistics
No analytics, no tracking cookies. The only cookie this site sets belongs to our own admin screen and is set only when we sign in there.

Research

If you take part in a minor, research runs alongside it

That research is not ours. A school runs it and is responsible for it: that is where you give your consent, where you ask your questions, and where you withdraw that consent again.

Researchers get nothing from the app. That data does not exist: there is no account, no server and no measurement. What a researcher sees of you, you see too, because it is what you say in an interview, fill in on a questionnaire, or show them yourself.

Taking part in the research and using the app are two separate things. Either one works without the other.

Contact

Who we are

Packlet is made by Tulku B.V., Surinamestraat 11 e, 8931 CW Leeuwarden, the Netherlands, registered with the Dutch Chamber of Commerce under number 94081808. If you have a question about this statement, or want something removed, write to info@packlet.app.

If we cannot resolve it together, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).