Privacy Policy
Last updated: August 9, 2026
Nowlist (“the app”) is a local-first task capture app for iOS. This policy explains what data the app processes, where it is stored, and what leaves your device.
Summary
- Your tasks and captures are stored on your device using SwiftData, including data shared with the Home Screen widget via an App Group container.
- There is no account, no cloud sync, and no analytics SDK in the app.
- Optional cloud speech-to-text and AI extraction are routed through our secure proxy on a physical iOS device. No API key is stored in the app.
Data stored on your device
Nowlist stores the following locally on your iPhone or iPad:
- Task titles, notes, tags, due dates, snooze dates, and completion status
- Capture text and attached images you choose to save
- App preferences (dictation engine, morning reminder time, language settings)
- An App Attest key identifier used to authenticate cloud requests (not your tasks or personal content)
This data lives in a SwiftData store on your device. The widget extension reads the same store through the App Group group.com.quangtm.nowlist so your Today list can appear on the Home Screen. Task data is not stored on Nowlist servers.
Optional cloud processing
If you choose cloud dictation or cloud AI extraction on a physical device, audio or text may be sent from the app to our proxy at nowlistai.vercel.app, which forwards requests to OpenRouter and its underlying model providers for transcription or task extraction. Requests are authenticated with Apple App Attest so only genuine installs of the app can use the proxy. We do not operate a separate account system for cloud AI.
On-device options (Apple Speech, WhisperKit) process audio on your device when selected and do not use the cloud proxy.
Cloud STT and AI extraction require your permission before any content is sent to our proxy and OpenRouter.
Permissions
- Microphone — used for voice capture in Talk to Me when you start recording.
- Photos / Camera — used when you attach images in Capture or receive shared images from the Share Extension.
- Notifications — used only for the optional local morning reminder you can enable in Profile.
- Location — optional. Used only for place-based reminders you configure (Home / Work). Always access is requested so notifications can fire when the app is closed. Location is processed on-device for geofencing; task location data is not sent to Nowlist servers.
You can revoke permissions at any time in iOS Settings. Features that depend on a permission will stop working until permission is granted again.
What we do not collect
- No user accounts or sign-in
- No cross-device sync of your tasks
- No advertising identifiers or third-party analytics
- No sale of personal data
Third parties
When you use cloud STT or extraction on a physical device, request content necessary for those features is processed by our Vercel-hosted proxy and then by OpenRouter and its model providers. Apple system frameworks (Speech, Photos, UserNotifications, DeviceCheck App Attest) are used according to Apple’s policies.
When you use the in-app contact form, your name, email, and message are sent directly from your device to FormSubmit (formsubmit.co) so we can receive and respond. Optional device metadata (app version, iOS version, device model, locale, and time zone) is included only if you turn on the “Include device info” toggle.
When you use the website contact form, your name, email, and message are sent through our website to FormSubmit. If you open the contact page from a link in the app, the app version may be included to help with support; the web form does not collect other device metadata.
We do not operate a separate contact inbox server.
Data retention and deletion
Your data remains on your device until you delete tasks, captures, or uninstall the app. Uninstalling Nowlist removes the app’s local data from your device.
Children
Nowlist is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes
We may update this policy as the app evolves. The “Last updated” date at the top will change when we do.
Contact
Questions about this policy or your data:
Send us a message through the contact form.
Support page: nowlistai.vercel.app/support