Legal
Privacy Policy
Effective April 7, 2026 · Last updated April 7, 2026
TL;DR
Knoted has no accounts, no emails, and no names. The only identifier is a random UUID stored on your device. Your location is used on-device only — never logged or sold. All knot data lives in Apple CloudKit. We have no servers, no analytics, and no ads. We can't share what we don't have.
Contents
- 01Overview
- 02Information We Collect
- 03Information We Do Not Collect
- 04How We Use Your Information
- 05Data Storage and Security
- 06Third-Party Services
- 07Location Permissions in Detail
- 08Data Retention and Deletion
- 09Your Rights
- 10Children's Privacy
- 11Apple App Store Privacy Labels
- 12Changes to This Policy
- 13Contact Us
Overview
Knoted is built on a single privacy principle: we cannot share what we never had. The app is designed so that identifying information is architecturally impossible to collect — not just withheld by policy. There are no accounts, no emails, no names, no passwords, and no tracking identifiers tied to your real identity.
This document describes exactly what data is collected, why it is collected, how it is stored, and what rights you have over it. It is written to meet the requirements of the Apple App Store, the California Consumer Privacy Act (CCPA), and the General Data Protection Regulation (GDPR) where applicable.
Effective Date: April 7, 2026
Last Updated: April 7, 2026
Developer: Phani Sai Ram Munipalli
Contact: phanisaimunipalli@gmail.com
Information We Collect
We collect the minimum data required for Knoted to function. Nothing more.
1. Anonymous Device Identifier
When you first open Knoted, the app generates a random UUID (Universally Unique Identifier) and stores it in your device Keychain. This identifier is:
- Randomly generated — not derived from your Apple ID, name, email, or any other personal data
- Not shared with Apple or any third party
- Used only to associate your knots and votes within the app
- Deleted permanently when you delete the app (Keychain entry removed)
This identifier is our equivalent of a session token. It lets the app know "this device dropped that knot" without knowing anything about who owns the device.
2. Precise Location Data
Knoted requests access to your device GPS location for three specific purposes:
- Discovery: To show knots near your current location on the map
- Dropping: To record the GPS coordinates of the knot you are creating
- Presence verification: To confirm you are physically within 100 meters of a knot before allowing you to vote on it
Location data is used on-device in real time. We do not store your location history, movement patterns, or travel routes. Your location is never sent to our servers (we do not operate servers). Only the coordinates of knots you intentionally drop are recorded in CloudKit.
Background Location:If you grant "Always" location permission, Knoted uses iOS region monitoring to deliver a local notification when you enter a neighborhood that has knots. This processing happens entirely on your device via Apple's Core Location framework. No location data is transmitted to any external service during background operation.
3. Knot Content
When you drop a knot, the following data is stored in Apple CloudKit (iCloud public database):
- The text of the knot (up to 140 characters)
- The tag you selected (Food, Parking, Tip, Warning, Restroom, or Shortcut)
- The GPS coordinates where the knot was placed
- Your anonymous device ID (not linked to any personal identity)
- A timestamp (date and time of creation)
- Upvote and downvote counts
Knot content is public — any Knoted user within proximity can read it. Do not include personal information in your knots.
4. Vote Records
When you upvote or downvote a knot, a record is stored in CloudKit containing your anonymous device ID and the knot ID. This prevents duplicate votes. It does not record your location at the time of voting beyond what was already used for the proximity check.
Information We Do Not Collect
The following categories of data are never collected by Knoted:
- Name, email address, phone number, or any contact information
- Apple ID, iCloud account email, or any Apple account details
- Device name, model identifier beyond what iOS provides to all apps
- Photos, camera roll, microphone recordings, or media files
- Contacts, calendar, health data, or any other app data
- Browsing history, search history, or cross-app behavior
- Advertising Identifier (IDFA) — Knoted does not request this
- IP address or network metadata stored in association with your identity
- Payment information of any kind
- Biometric data
- Financial or employment information
- Sensitive personal information of any category
How We Use Your Information
The data we collect is used exclusively for the following purposes:
- App functionality: Displaying knots on the map, processing drops and votes, and enforcing the 100-meter presence gate
- Spam and abuse prevention: The anonymous device ID is used to rate-limit drops and votes per device to prevent flooding
- Background notifications: If you opt in, delivering local notifications when you enter areas with active knots
- Data expiration: Automatically removing knots that have not received any upvotes within 60 days
We do not use your data for advertising, profiling, behavioral analysis, or sale to third parties. We have no business model that depends on your data. The app is free and contains no advertising.
Data Storage and Security
Apple CloudKit
All knot and vote data is stored in Apple's CloudKit public database. CloudKit is managed and secured by Apple, Inc. Apple applies encryption in transit (TLS) and at rest. Apple's privacy practices for CloudKit are governed by the Apple Privacy Policy.
We do not operate our own backend servers, databases, or data warehouses. We have no infrastructure that holds a copy of your data.
Device Keychain
Your anonymous device ID is stored in the iOS Keychain, which is encrypted by the operating system and tied to your device hardware. It is not backed up to iCloud (we use the non-synced Keychain group) and is not accessible to other apps.
Security Measures
Because we do not collect personal data and do not operate servers, our attack surface is minimal. The primary security layer protecting knot data is Apple's CloudKit infrastructure. On-device data (the device ID) is protected by iOS Keychain encryption and device passcode/biometric protection.
Third-Party Services
Knoted uses two Apple-provided services. No third-party analytics, advertising, or tracking SDKs are integrated.
- Apple CloudKit:Cloud database for knot and vote storage. Data is subject to Apple's terms and privacy policy. Apple does not use CloudKit data for advertising.
- Apple MapKit:Renders the interactive map. MapKit may send anonymized map tile requests to Apple servers. Apple's MapKit privacy practices are governed by Apple's privacy policy.
We have deliberately avoided integrating Firebase, Mixpanel, Amplitude, Sentry, Crashlytics, Facebook SDK, Google Analytics, or any other third-party data collection service.
Location Permissions in Detail
Knoted requests two levels of location access on iOS:
While Using the App ("When In Use")
Required for: showing the map, dropping knots, voting. This is the minimum needed to use the core feature set. You can use Knoted entirely with this permission level.
Always (Background)
Optional. If granted, iOS allows Knoted to use region monitoring to detect when you enter a geographic area that has active knots. This triggers a local notification generated on-device. No location data is transmitted externally during background operation. This is processed entirely by Apple's Core Location framework on your device.
You can change location permissions at any time in Settings → Privacy & Security → Location Services → Knoted. Downgrading to "Never" will stop the map from working but will not delete any of your previously dropped knots.
Data Retention and Deletion
Automatic Expiry
Knots with zero upvotes are automatically deleted from CloudKit after 60 days of inactivity. Knots with one or more upvotes persist indefinitely until voted down below zero, at which point they are removed.
Deleting Your Knots
You can delete any knot you created from within the app (tap the knot → Delete). Deletion is immediate and permanent. Once deleted from CloudKit, the data is unrecoverable.
Deleting the App
When you delete Knoted, the anonymous device ID is removed from your Keychain. Your previously dropped knots remain in the public CloudKit database (they are community data) but are no longer attributable to any device or person. If you want your knots removed before deleting the app, please delete them individually first or contact us.
Data Deletion Request
If you want all data associated with your anonymous device ID purged from CloudKit, email us at phanisaimunipalli@gmail.comwith the subject line "Data Deletion Request." Because there is no account or name attached, you will need to provide your anonymous device ID (found in Settings → About in the app) so we can identify your records.
Your Rights
California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act, you have the right to:
- Know what personal information is collected about you
- Delete personal information we hold about you
- Opt out of the sale of personal information (we do not sell data)
- Non-discrimination for exercising your privacy rights
Because Knoted does not collect personal information as defined by CCPA (the anonymous device ID is not linked to a real identity), most CCPA rights are satisfied by design. For deletion requests, see the section above.
European Residents (GDPR)
Under the General Data Protection Regulation, if you are in the European Economic Area, you have the right to:
- Access the data we hold about you
- Rectify inaccurate data
- Erasure ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
The lawful basis for processing your data under GDPR is legitimate interest (app functionality) and consent (location permission). To exercise any GDPR right, contact phanisaimunipalli@gmail.com.
Children's Privacy
Knoted is not directed at children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. Since no personal information is collected by design, there is no mechanism by which a child's data would be treated differently from an adult's. The anonymous device ID is age-neutral.
If you believe a child under 13 has used Knoted and you wish to have their knots removed, contact us at phanisaimunipalli@gmail.com.
Apple App Store Privacy Labels
The following reflects what is reported in Knoted's App Store privacy nutrition label:
Data Linked to You
None. Knoted does not link any data category to your identity.
Data Used to Track You
None. Knoted does not participate in cross-app tracking or advertising networks.
Data Not Linked to You
- Location: Precise location (used for app functionality only, not tracking)
- Identifiers: Device ID (anonymous, app-generated UUID only)
- User Content: Text content of knots you choose to create
Changes to This Policy
We may update this Privacy Policy when we add new features or when legal requirements change. When we do, we will update the "Last Updated" date at the top of this page. If changes are material — meaning they affect how data is collected or used in a significant new way — we will provide notice in the app on the next open after the change.
Continued use of Knoted after changes become effective constitutes your acceptance of the revised policy. If you disagree with any change, you may stop using the app and request deletion of your data.
Contact Us
For any privacy-related questions, data deletion requests, or concerns:
- Email: phanisaimunipalli@gmail.com
- Subject line for data requests: "Knoted Privacy Request"
- Response time: We aim to respond within 7 business days
If you are in the EU and believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority.
© 2026 Phani Sai Ram Munipalli · Terms of Use · Support