— clientAPT · Legal —

PRIVACY POLICY

Effective 2026-06-28.

clientAPT is published by river.io LLC. This page describes what data the app and this website collect, what we do with it, and what your rights are. The summary is short because the data flows are short — we do not collect any personal information about you, your clients, or your practice.

— 01 · What the app collects —

Nothing. clientAPT does not include analytics, telemetry, crash reporters, advertising SDKs, or any third-party libraries that phone home. The app makes no network calls during normal operation. There is no developer account to sign in to, no server we operate, and no place we could store your data even if we wanted to.

Concretely, the app does not:

  • Send appointment, client, photo, or note data anywhere off your device.
  • Sync to iCloud, hand off to the iOS Calendar, expose entries to Spotlight, or donate intents to Siri.
  • Open Maps, tel:, mailto:, or sms: links.
  • Read or write the iOS Contacts database.
  • Place photos in the system Photos library or its iCloud backups.
  • Use any advertising identifier, device identifier, or cross-app tracking signal.
— 02 · What lives on your device —

The data you enter — clients, appointments, services, photographs, and notes — is stored in two encrypted SQLite databases inside the app's private container. Both databases are sealed with SQLCipher (AES-256 page encryption). Fields you mark sensitive are wrapped a second time with AES-GCM using a key derived from a separate PIN.

Database keys are derived from your PIN at every unlock using Argon2id at a memory-hard work factor. The keys are never stored on disk; they exist only in memory while the vault is open, and they are zeroed out the moment the app re-locks, backgrounds, or you enter a wrong PIN four times.

— 03 · Backups —

The current release has no backup or export feature. Your data never leaves the device in any form. An optional, passphrase-encrypted, on-device export may be offered in a future release; this policy will be updated when it ships.

— 04 · App Store purchases —

clientAPT is sold through Apple's App Store. Apple processes the purchase, handles your payment information, and supplies receipt validation. We receive aggregate sales reports from Apple (units sold per day, by region) that do not identify you. Refer to Apple's privacy policy for how Apple handles its part of the transaction.

— 05 · This website —

This site (river.io) is a static page hosted on GitHub Pages. We do not run our own analytics here. GitHub may keep standard web-server access logs for security and abuse-detection purposes; refer to GitHub's general privacy statement for what they retain. We do not embed advertising tags, tracking pixels, or third-party scripts. The page loads webfonts from Google Fonts; consult Google's privacy policy for that connection.

— 06 · Children —

clientAPT is built for adults running an appointment-based practice. It is not directed at children under 13 (or under 16 where the applicable law is GDPR), and we do not knowingly collect any data from children. If you believe a child has used the app, please contact us at privacy@river.io and we will help, although practically there is nothing for us to delete because we never had it.

— 07 · Your rights —

Because we do not collect or store data about you, the usual rights to access, correct, delete, port, or restrict processing of personal data (GDPR Articles 15–22, CCPA §1798.100 et seq., and equivalents) do not produce a record from us. The data lives on your device. You can delete it by uninstalling the app or wiping the vault from inside Settings.

— 08 · Changes to this policy —

If we change how the app or this site handles data, we will update this page and the effective date above. Material changes will also be noted on the GitHub repository changelog. Because the app does not phone home, there is no in-app banner to notify you — re-visit this page when a new version ships.

— 09 · Contact —

Privacy questions: privacy@river.io.
Security disclosure: reporting@river.io with subject clientAPT vuln:.

▸ Back to clientAPT