Privacy Policy for Cupertino Lens
Last updated: September 22, 2026
Cupertino Lens (“we”, “the app”) is published by Sami Fathi. This policy describes how Cupertino Lens 3.0 for iPhone and iPad and its Home Screen widgets handle information.
Information we collect
- Content you choose to save: Articles you bookmark are stored on your device.
- Reading preferences: Appearance, reader text size, notification preferences, and your app-activity analytics choice are stored on your device.
- Widgets: A limited snapshot containing article identifiers, headlines, categories, image references, and publication or refresh dates is stored in the app’s private shared container so its widgets can display current stories.
- Notification service: The app uses OneSignal and Apple Push Notification service. Collection remains disabled and no push subscription is created until you deliberately enable New Essay or Wire news alerts and iOS permits them. After enablement, OneSignal processes a device or subscription identifier, IP address, device and operating-system information, language, time zone, network status, app session information, notification interactions, and the APNs push token needed to deliver alerts. The app sends tags for your essay and Wire notification choices and a random installation verification value. It does not send OneSignal an account ID, email address, phone number, precise location, or advertising identifier.
- Wire news follows: If you enable Wire news alerts, Cupertino Lens stores your selected publishers and keywords alongside your anonymous notification identifiers and a hashed installation credential, so it can match new headlines and short summaries while the app is closed. These follows are separate from your reading history.
- Briefings and essay notes: Prepared Briefings, topic choices, handwriting, and inline essay notes are stored on your device. Apple Intelligence processing runs on supported devices. Your Briefing focus, annotations, and notes are not sent to the Wire alert matching service or to OneSignal. Optional cloud processing and iCloud storage are described below.
- Optional Apple sign-in and comments: If you sign in with Apple, the app stores your Apple-provided user identifier and available name in this device’s Keychain. It sends Apple’s identity token and your available display name to cupertinolens.com to establish a reader account and a device session for comments. The website stores the account identifier, display name, submitted comments, and associated moderation reports and blocks. Approved comments and display names are visible to other app readers. The app does not request your email address from Apple. Signing out clears this device’s comment session; it does not delete the website’s account or comments.
- Private iCloud storage: If you enable library sync, saved stories, reading state, selected reading and Briefing preferences, and your chosen name are stored in your private iCloud database. Notes and handwriting can use iCloud Documents separately when available. Apple processes this storage under your iCloud account; it is separate from the app’s Sign in with Apple account and from notification subscriptions.
- First-party app analytics: If More → About → Share app activity is enabled, the app sends limited product-interaction events directly to cupertinolens.com over HTTPS. The events are limited to session start and end, screen entry and exit, and taps on named app controls. They may include a random identifier created for that app session, sanitized screen or control labels, screen duration, event time, and app version. They do not include article titles, advertising identifiers, or an identifier intended to follow you across sessions, apps, or websites. The server uses the request IP address transiently to enforce an hourly rate limit; it is not stored in the analytics event table.
Information we do not collect
- No account is required to read Cupertino Lens essays.
- We do not sell personal data.
- We do not track you across third-party apps or websites for advertising.
- The app does not request App Tracking Transparency permission and does not currently include a third-party advertising SDK.
How notification information is used
OneSignal processes notification and SDK information only after the consent described above, to deliver and measure the alerts you choose. Cupertino Lens does not use it for targeted advertising or sell it. Essay alerts and Wire alerts have independent controls. Turning off all remote alerts opts the subscription out and withdraws SDK consent; you can also disable alerts in iOS Settings. Briefing reminders use local notifications.
First-party app analytics
The Share app activity setting is enabled by default and can be turned off at any time. We use these first-party events only to understand screen use, drop-off, and feature interaction so we can improve reliability and the reading experience. They are not used for third-party advertising, cross-app tracking, data brokerage, or creating an advertising profile.
Crash and performance diagnostics
The app uses Sentry to identify crashes, hangs, failed requests to our website, and performance problems. Diagnostics can include stack traces, timing information, app and operating-system versions, device characteristics, a pseudonymous installation identifier, and sanitized screen and control labels. Default personal-information collection is disabled; the app does not attach your Apple sign-in identity or contact details. Screenshots, view-hierarchy attachments, and session replay are disabled. Sentry diagnostics are separate from the Share app activity setting and are not used for advertising or cross-app tracking.
Optional OpenRouter processing
Apple Intelligence is the default model provider. If you explicitly select OpenRouter and supply your own API key, relevant article text, Briefing preferences, and comment drafts used by the selected feature are sent to OpenRouter and its selected model provider. Your API key is stored in this device’s Keychain and sent only to authenticate requests to OpenRouter. It is not sent to cupertinolens.com. Requests ask for providers that deny data collection and support zero-data-retention routing; the services’ own privacy policies and your account settings apply. Cloud processing is never enabled automatically as a fallback. You can switch back to Apple Intelligence or remove the key in Intelligence settings.
Retention and deletion
In version 3.0, open More → Your Account → Delete Account to permanently remove your website reader account, comments in every moderation state, associated reports and blocks, and website sessions. Confirm with the same Apple Account. Deletion remains available when commenting is disabled or your account cannot post. After deletion, revoke Apple access in Settings → your name → Sign in with Apple → Cupertino Lens, or at account.apple.com under Sign-In & Security. Your saved stories, private notes, and iCloud library are separate from the website reader account and remain until you remove them using their own controls.
Cupertino Lens is free to use and does not require a paid subscription. Local saved articles, annotations, and preferences remain until you remove them or uninstall the app. Data stored in iCloud and the device Keychain can remain after uninstalling; removing the app does not delete your website reader account or published comments. Turning off Wire alerts removes your follows from the server when the change is confirmed. A record of the revocation is kept for up to 31 days to prevent delayed requests from restoring old follows; delivery records are also removed after 31 days. First-party analytics events are retained for up to 90 days. You can stop new analytics events by turning off More → About → Share app activity. You can request deletion of your notification information using the contact address below, and we will submit the request to OneSignal.
Network use
The app loads essays from cupertinolens.com and, in The Wire section, headline and summary data from configured publisher RSS feeds. When you open a publisher’s full article, its website loads in the app’s browser or your external browser. That publisher may receive ordinary web request information and use cookies or other website storage under its own privacy policy. Standard server logs, such as IP address, user agent, and request time, may be created by our hosting provider when the app or website is contacted; we do not use these logs to build advertising profiles.
Third-party content (The Wire)
The Wire shows titles, short summaries, and attribution from third-party RSS feeds for personal reading. Full articles and images remain the property of their publishers. Outbound links may include simple campaign parameters (for example utm_source) so we can understand that traffic came from the app; these are not used to track you across unrelated third-party apps for advertising.
App Store privacy labels
The app’s privacy information includes product interaction for analytics, notification identifiers for app functionality, and crash, performance, and other diagnostic data for reliability. Optional accounts and comments involve your name, account identifier, and user content linked to that reader account. None of these features is used for cross-app advertising tracking.
Children
The app is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the app, contact us and we will take appropriate steps.
Contact
Privacy questions: sami@cupertinolens.com