Vooli
Privacy policy
Last updated: July 22, 2026 · Effective: July 22, 2026
The short version: your data stays on your device. Summary in plain English at the bottom.
1. Who we are
Vooli is operated by Vooli LLC, a Tennessee limited liability company. For the purposes of GDPR / UK GDPR, Vooli LLC is the data controller for the limited personal data described in this policy.
Contact for privacy questions: support@vooli.app. We do not have a designated Data Protection Officer (we are too small to require one under GDPR Article 37); privacy requests route to the same address and a human answers them.
2. Local-first: your data stays on your device
Vooli is a local-first, single-user app. The tasks, lists, routines, habits, focus sessions, notes, and completion times you create live in a database on your device, protected at rest by iOS Data Protection. There is no Vooli account, no sign-in, no email or password, and no Vooli server that holds a copy of your content. We literally do not have it.
If you turn on iCloud sync (optional), your data syncs between your own Apple devices through your iCloud account (Apple CloudKit). That copy lives in your iCloud, governed by Apple’s privacy policy and your Apple settings. It never passes through, and is never stored by, Vooli.
Reminders and timers are scheduled locally on your device. We do not run a push server and we do not hold a device push token.
3. What touches a third party
Because your content stays on your device, most of the app involves no data leaving it at all. The narrow exceptions:
- Purchases. If you buy the one-time Vooli Pro unlock, the purchase is handled by Apple and your entitlement state is managed by RevenueCat, keyed to an anonymous, app-generated identifier. We never see your name, card, or Apple ID. We only learn whether this install is “Pro” or not.
- Optional iCloud sync. Handled by Apple through your own iCloud (see section 2).
- This website. vooli.app is served by Vercel, which processes standard web-server logs (IP address, browser type) to deliver and secure the page. The site sets no tracking cookies.
- Email you send us. If you email support, we receive your message and address so we can reply.
What we do NOT collect: No account, email, or password. No third-party analytics (no Google Analytics, Mixpanel, Amplitude, Segment). No advertising or tracking SDKs. The app does not request App Tracking Transparency permission because there is nothing to track. We do not collect device location or contacts. The app reads your accessibility preferences locally (Reduce Motion, Reduce Transparency, Increase Contrast) but never transmits them.
Device permissions: Vooli can ask for a handful of iOS permissions, each for a specific feature. None of the data they touch is sent to Vooli; it is used on your device.
- Microphone & Speech Recognition. For the “Voice” task, Vooli uses the microphone and Apple’s speech recognition, set to run on-device, to turn what you say into task text. Only the resulting text is saved, on your device. No audio is stored or sent to Vooli. (The separate “Hey Siri, add to Vooli” path is Siri itself; Vooli receives only the final text.)
- Apple Music (Media Library). Only if you connect it on the dock’s music page. Vooli reads the system now-playing info so you can see and control playback in Dock Mode. Nothing is sent to Vooli.
- Apple Health. Only if you link a habit to Health. Vooli reads step count and workout data on your device to auto-check that habit. The Health data stays on your device, is never sent to Vooli, and is never used for advertising.
- Calendar. Only if you add the calendar page to a dock. Vooli reads your events to show them on the dock; they are not sent to Vooli.
- NFC. Used to link a dock or NFC tag to a dock profile by writing a Vooli link to the tag. No personal data is read from or written to the tag beyond that link.
Shared content (Share Sheet, Siri, widgets): When you use the Share Sheet to send a page title or URL to Vooli, dictate a task to Siri, or tap the QuickAdd lock-screen widget, only the resulting text lands in your bank, on your device. URLs are stored verbatim as the task title; we do not fetch or preview the linked page.
Crash diagnostics: iOS may send Apple anonymous crash logs from any app if you opted into Share with App Developers in your device settings. We see only what Apple shares, and it is not linked to any identity (there is no account to link it to).
4. Why we process it (lawful basis)
Under EU and UK GDPR, every processing activity needs a named lawful basis. Because Vooli holds so little, the list is short:
- Performance of a contract (Article 6(1)(b)). Delivering the Vooli Pro unlock you purchased, and answering a support request you send us.
- Legitimate interests (Article 6(1)(f)). Operating and securing this website (standard server logs). We have balanced this against your rights and conclude it does not override them.
- Consent (Article 6(1)(a)). Notifications fire only after you grant iOS notification permission, and they are scheduled locally on your device. You can revoke this any time in iOS Settings → Notifications → Vooli.
6. Retention
Your app content lives on your device for as long as you keep it. Delete a task and it is gone; delete the app and its local database goes with it. If you enabled iCloud sync, manage or remove that copy in iOS Settings → your name → iCloud, or by turning off Manage Storage for Vooli. Because we hold no copy of your content, there is nothing on our side to retain or delete.
Purchase records held by Apple and RevenueCat follow their retention policies. Website server logs are short-lived and contain no app content. Support emails are kept only as long as needed to resolve your request.
7. International data transfers
Your app content does not transfer to Vooli at all — it stays on your device, and any sync stays within your own iCloud. The limited data that does reach a third party (purchase state at RevenueCat, this website at Vercel, and any email you send us) is processed in the United States. For any transfer of EU / UK / Swiss personal data to a US sub-processor, we rely on that provider’s Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework. Email us for details of the safeguards in force.
8. Your rights (GDPR, UK GDPR, CCPA, state laws)
Because your data lives on your device, you already hold most of these rights directly:
- Access / export. Your content is on your device; there is no server copy to request.
- Delete. Delete items in-app, or delete the app to remove the local database entirely. Manage any iCloud copy in iOS Settings.
- Correct. Edit anything in-app at any time.
For the limited data we do handle (purchase state, support correspondence), EU / UK residents have the rights to access, rectify, erase, restrict, port, object, and withdraw consent (GDPR Articles 15–21, 7), and to lodge a complaint with a supervisory authority (EU: your national DPA via the EDPB members list; UK: the ICO). We hope you email us first so we can fix it.
California residents (CCPA / CPRA). You have the right to know what we collect (see section 3), to delete, to correct, and to non-discrimination. We do not sell or share personal information for cross-context behavioral advertising, have not in the prior 12 months, and have no plans to. Other US state privacy laws (CO, CT, VA, UT, TX, OR, MT, DE, IA, NJ) grant analogous rights; the same email contact applies and we honor requests under the highest applicable standard.
9. Children (COPPA)
Vooli is intended for users aged 13 and older (16 and older in the European Economic Area). We do not knowingly collect personal information from children under 13 (or under 16 in the EEA).
We do not market to children, include child-directed content, or collect any data category COPPA treats as sensitive. If we learn that we have collected personal information from a child under 13 (or under 16 in the EEA) without verified parental consent, we will delete it promptly. Parents with a concern should email support@vooli.app.
10. Security
Your content is protected on your device by iOS Data Protection (encrypted at rest, Complete-Until-First-Unlock class) — the same protection Apple applies to Reminders and that apps like Things use. Optional sync travels over Apple’s encrypted iCloud (CloudKit). This website is served over TLS 1.2+. Because there is no Vooli account or server holding your content, there is no server database to breach. No system is perfectly secure, but if we ever become aware of an incident affecting personal data we handle, we will act promptly and notify affected people where required (GDPR Article 33 timing, applied globally).
11. Accessibility
We aim to meet WCAG 2.1 AA on both this website and the Vooli iOS app. The website supports keyboard navigation, screen readers, Reduce Motion, dark mode, and 200% zoom without horizontal scroll. The iOS app supports VoiceOver, Dynamic Type, Reduce Motion, Reduce Transparency, and Increase Contrast via system settings.
If you hit an accessibility barrier, email support@vooli.app and we will fix it as a priority. We treat accessibility defects as functional bugs, not aesthetic preferences.
12. Changes
If we make material changes to this policy we’ll update the “Last updated” date at the top and post the new version here before it takes effect. Because we have no account and no email list, this page is the source of truth.
13. Contact
Privacy or data-rights questions: support@vooli.app. Mailing address available on written request.
Summary in plain English
- Your data stays on your device. There is no account and no Vooli server holding your stuff.
- No analytics. No ads. No tracking SDKs. Ever.
- Optional sync uses your own iCloud (Apple), not us.
- The only third parties involved: Apple (purchases + optional iCloud), RevenueCat (whether you’re Pro, via an anonymous id), and Vercel (this website).
- Delete items in-app, or delete the app to wipe local data. Manage any iCloud copy in iOS Settings.
- EU / UK / California / other state-law residents: full rights. Email us and we’ll honor it.
- Vooli is for users 13+ (16+ in the EU). We do not knowingly accept kids.
- We aim for WCAG 2.1 AA. Tell us if we missed.