worren
features how it works pricing faq
join waitlist
legal

Privacy Policy

Effective date: 3 October 2026

This policy explains what personal information Worren collects, why, who it is shared with, how long it is kept, and the choices you have. It covers the Worren iOS app (bundle ID m3ln.worren), the Worren backend service, and the website at worren.world. We have tried to write it in plain language. If something is unclear, ask us through the support page.

The short version

  • Worren turns a sentence you write into a small tracking app. To do that, the text you write when building (or changing) an app is sent to our servers and on to an AI provider.
  • The entries you log inside your apps (your weights, moods, expenses, and so on) stay on your device. They are not uploaded to our servers or to the AI provider.
  • We keep a small account record: your name, your email address (which may be an Apple private-relay address), and a few counters and preferences.
  • We use product analytics and crash reporting that are designed not to include what you type or what you log. They do include a Worren account ID and basic technical information.
  • We do not sell your personal information, do not share it for advertising, do not show ads, and do not track you across other companies' apps or websites.
  • You can delete your account, and the data tied to it, yourself in the app: Settings > Account > Delete account.

1. Who we are

Worren is operated by Shaurya, an individual developer ("Worren", "we", "us"). For data protection laws such as the GDPR and UK GDPR, we are the controller of the personal information described in this policy. The best way to reach us for anything about privacy is the support page (choose "Question about my data").

2. What we collect

Information you give us

  • Account details. If you sign in with Apple, we receive from Apple a stable, app-specific Apple user ID, your name (only the first time you authorise, and only if you share it) and your email address, which may be Apple's private relay address if you choose "Hide My Email". If you create an email account instead, we collect your name, email address and a password. We never store your password itself, only a salted hash of it.
  • Onboarding choices. Whether you want our newsletter, how you heard about Worren, and what you plan to use Worren for. These are picked from lists, not typed.
  • What you ask the AI to build. Your app idea, any answers you give to the follow-up questions, the app name, the fields proposed for your app (names, labels and types), and later any change you ask for. See section 3.
  • Subscription purchases. If you buy Worren Pro, the purchase is made through Apple. We do not receive your card or other payment details. See "RevenueCat" in section 5.
  • Messages to us. If you write to support or join the waitlist on our website, we receive your email address and whatever you tell us.

Information created when you use Worren

  • Session data. When you sign in, our server creates a session. We store a one-way hash of the session token (not the token itself), and when the session was created, last used and expires. Sessions expire after 90 days without use.
  • App registrations. When you create an app, the server stores an app ID, the app's name, a random secret for that app, an identifier generated on your device that labels your apps, and the account that owns it. The fields and layout of your app are kept on your device.
  • Usage allowances. How many builds you have used this week and, for free accounts, how many "high effort" builds you have used, so we can apply the limits for your plan.
  • Notification token. If you turn on notifications in Settings, your device's Apple Push Notification service (APNs) token is stored with your account. Worren does not currently send push notifications; the token is stored so that we can tell you when a long build finishes. Reminders you set inside your apps are scheduled on your device and do not use our servers.
  • Records sent by tools you connect. Our servers have an endpoint that can receive records for an app if someone uses that app's private secret. The Worren app does not use it to upload your entries. If you or a tool you set up sends records there, they are stored on our servers and deleted with your account.

Information collected automatically

  • Product analytics (PostHog). Events such as signing up, starting a session, giving a first prompt, building an app (with counts such as the number of fields, how long the build took, and the outcome), opening an app, saving an entry (only the number of fields, not their values), using a bundled template, or running a Shortcuts action. For the prompt we send only its length. Events are tied to your Worren account ID after you sign in, and to a random identifier before that. Standard technical details that the analytics service adds (such as app version, device and OS type, and an approximate location derived from your IP address) may be included. Automatic capture of screens, taps and session recordings is turned off.
  • AI usage analytics (PostHog). Our server also records, for each AI request, how it went: which model answered, how long it took, token counts, cost, and an error type if it failed. It does not record the text of your prompts or of the AI's answers.
  • Crash and error reports (Sentry). If the app or our server crashes or hits an error, a report is sent with the error type, the place in the code it happened, your Worren account ID, and technical details such as app version, device model and OS version. We configure these reports so they do not include prompts, entries, app contents, field names, screenshots, or the screen layout. Server reports also include the request path (without query strings), the type of browser or app making the request, and the country that Cloudflare derives from the connection. A small sample of server requests is also recorded for performance monitoring.
  • Server logs. Our hosting provider (Cloudflare) records requests to our servers, and our server writes operational log lines such as job IDs, account IDs and error codes. These logs are kept for a short time (see section 8). Network infrastructure necessarily sees your IP address when your device connects.

What stays on your device

  • Entries you log in your apps, in a local database in the app's storage.
  • The apps themselves (their screens and layouts), drafts, groups, and your appearance settings.
  • Your sign-in session and each app's secret, in the iOS Keychain.

We do not have access to these. Apple may include app data in your device or iCloud backups, subject to your Apple settings. Because you decide what to track, your entries may include sensitive information such as health or financial details. Worren does not upload them, but anyone with access to your unlocked device could see them. Shortcuts actions you set up run on your device and use your entries locally.

Apart from notifications, which are optional, Worren does not ask for access to your contacts, photos, camera, microphone, location or health data.

3. How the AI features work

To build an app, ask follow-up questions, or change an app, the Worren app sends the following to our server: your description, your answers, the app name, the proposed field names, labels and types, and, when you change an existing app, your change request together with the app's current screens and field structure. It does not send your logged entries.

Our server forwards this text to a large language model through OpenRouter, a service that routes requests to model providers (for example NVIDIA, Google or Cohere, depending on what is available). We mostly use models offered free of charge, and the model that answers can change from request to request. We do not send your name, email address or account ID to the AI provider.

The generated app definition comes back to our server and then to your device. To make the process reliable (for example if your connection drops, or if the request has to wait for capacity), our server stores each build request and its result, including your prompt, for up to 7 days before it is automatically deleted.

OpenRouter says it does not use your inputs or outputs to train models, and does not keep prompts by default. The companies that run the individual models have their own policies, and some, particularly for free models, may log requests or use them to improve their models. We do not control this. Please do not put passwords, financial account numbers, or other highly sensitive personal information in what you write to the AI. You can describe an app without including real personal details; you enter real data later, on your device.

The AI makes the app's structure. It does not make decisions about you that have legal or similarly significant effects.

4. Why we use your information, and our legal bases

Where the GDPR or UK GDPR applies, we rely on these legal bases:

PurposeInformationLegal basis
Create and run your account, sign you in, apply plan limits, restore your Pro access Account details, session data, usage allowances, purchase status Contract (providing Worren to you)
Build and change apps with AI, and keep the result safe for up to 7 days Prompts, answers, app names, field structure, generated app Contract
Notify you about your builds, if you turn notifications on Notification token Consent (your choice in Settings and in iOS)
Fix bugs and crashes, keep the service secure and prevent abuse (for example by limiting repeated failed sign-ins) Crash and error reports, server logs, failed sign-in counts Legitimate interests (running a secure, working service)
Understand how Worren is used and improve it, and manage AI cost and reliability Product and AI usage analytics, onboarding choices Legitimate interests (improving the product), balanced against your privacy by keeping the data free of your content
Send product updates by email, if you chose that Email address, newsletter choice Consent, which you can withdraw at any time
Answer your messages, and contact people on the waitlist Email address and your message Legitimate interests, or steps you asked us to take
Meet legal obligations and handle legal claims As needed Legal obligation, legitimate interests

Where we rely on legitimate interests you can object (see section 10). We do not use your information for advertising, and we do not build advertising profiles.

5. Who we share information with

We use the service providers below to run Worren. They process information on our behalf, or, in Apple's case, under Apple's own terms. We do not sell your information. Cloudflare, PostHog, Sentry and RevenueCat process it for us and not for their own advertising; the AI model providers are covered separately in section 3.

ProviderWhat it does for WorrenInformation it receives
Cloudflare Hosts our backend (Workers), our database (D1) and our website (Pages) Everything stored on our servers (section 2), and request data such as IP address when you connect to our servers or website
OpenRouter and the model providers it routes to Runs the AI models that design your apps The text described in section 3 (not your entries, name, email or account ID)
Apple Sign in with Apple, push notifications (APNs), App Store purchases For sign-in, your Apple ID details as you choose to share them. For push, your device token (only if notifications are on). Apple handles your payment details; we do not receive them.
RevenueCat Manages Worren Pro subscriptions and checks whether you are subscribed Your Worren account ID, your purchase and subscription status, and technical data such as IP address. Our server may also ask RevenueCat whether your account has Pro when you request a Pro-only build.
PostHog Product analytics, feature flags and AI usage analytics The events described in section 2, your Worren account ID, and standard technical details
Sentry Crash and error reporting for the app and server Error reports as described in section 2, with your Worren account ID
Google Fonts Delivers fonts to the website (not used in the app) Your IP address and browser details when you load a page on worren.world

We may also disclose information if the law requires it, to protect the rights, safety or security of our users or the service, or to a successor if Worren is ever transferred to someone else (we would tell you and the policy would continue to apply).

6. What we do not do

  • We do not sell your personal information or share it for cross-context behavioural advertising.
  • We do not show ads, and we do not use the advertising identifier. Worren does not "track" you in the sense of Apple's App Tracking Transparency rules, so it does not show a tracking prompt.
  • We do not combine your data with data from other companies' apps or websites.
  • We do not use your entries or your prompts to train AI models of our own.
  • Because we do not track you across sites and apps, there is nothing for a "Do Not Track" signal to switch off. The same goes for Global Privacy Control signals.

7. International transfers

Worren's providers operate internationally, and most are based in, or use infrastructure in, the United States. Your information may therefore be processed in countries other than yours, including countries whose data protection laws differ from those in the EEA or UK. Where the GDPR or UK GDPR requires it, we rely on the safeguards our providers offer, such as the European Commission's standard contractual clauses, the UK addendum, or the EU-US Data Privacy Framework. You can ask us for more information about these safeguards through the support page.

8. How long we keep information

InformationHow long
Account details, onboarding choices, usage allowances, app registrationsUntil you delete your account
SessionsUntil you sign out or delete your account, or 90 days after you last used the session
Notification tokenUntil you sign out, turn notifications off, or delete your account
AI build requests and results (including your prompt)Automatically deleted about 7 days after the request finished. This still applies if you delete your account in the meantime.
Failed sign-in countersShort-lived; they reset after 15 minutes and are removed when you delete your account
Server logs (Cloudflare)Up to about 7 days
Crash and error reports (Sentry)Up to 90 days
Analytics events (PostHog)Up to 12 months
Database recovery history (Cloudflare D1)The database keeps a rolling history that lets us restore it after an accident, for up to 30 days. Deleted data can persist in that history until it ages out.
Waitlist email addressUntil you ask us to remove it, or until we no longer need it to contact waitlist members
Support messagesAs long as needed to help you and a reasonable time afterwards
Subscription records (Apple, RevenueCat)As long as these providers need them for billing, tax and legal reasons, under their own policies

Data on your own device stays there until you delete the app, an individual app, or your account.

9. Deleting your account and your data

You can delete your account at any time in the app: Settings > Account > Delete account, then confirm. This cannot be undone. When you confirm:

  • Our server deletes your account record, sign-in details (including a password hash, if you had one), sessions, onboarding choices, notification tokens, build counters, the apps registered to your account and any records stored for them.
  • If you signed in with Apple, we ask Apple to revoke the connection between your Apple ID and Worren.
  • The app erases everything Worren keeps on that device: your apps, drafts, groups, entries, reminders and stored secrets, and signs you out.

Some things are not removed instantly:

  • Temporary AI build records, server logs and database recovery history age out on the schedule in section 8.
  • Analytics and crash reports already sent to PostHog and Sentry are tied to your account ID, which no longer refers to anyone once your account is deleted. Ask us on the support page if you want them removed sooner.
  • RevenueCat and Apple keep subscription and purchase records under their own policies. Deleting your Worren account does not cancel an active subscription. Cancel it in your Apple ID subscription settings first.
  • If you joined the waitlist from our website, that email address is stored separately from your app account. Ask us on the support page to remove it.

If you cannot use the in-app option, contact us through the support page and we will do it for you.

10. Your rights and choices

Everyone can:

  • Correct your name, email or other account details by asking us on the support page.
  • Turn off notifications in Settings > Notifications, or in iOS Settings.
  • Leave the newsletter by asking us on the support page.
  • Remove your data by deleting an app or your account (section 9).

If you are in the EEA, the UK or Switzerland, you also have the right to: access your personal information and get a copy; have it corrected; have it erased; restrict or object to our use of it (including where we rely on legitimate interests); receive it in a portable format; and withdraw consent at any time (this does not affect what we did before). To use these rights, contact us through the support page. We will reply within one month, and may ask you to confirm your identity first. You also have the right to complain to your local data protection authority. In the UK this is the Information Commissioner's Office; in the EU, you can find your authority on the European Data Protection Board's website.

Your entries are on your device, so you already hold the data you log. If you want help exporting it, ask us.

11. California and other US state privacy rights

This section is our notice at collection for residents of California and other US states with privacy laws.

  • Categories we collect (in the last 12 months): identifiers (name, email address, Worren account ID, Apple user ID, device-generated identifiers, device token, IP address); commercial information (subscription status); internet or app activity (analytics events); user content you give the AI (prompts, answers, app names and structures); approximate location, which may be derived from your IP address; and technical and crash data. Details are in section 2.
  • Purposes: providing and securing Worren, product analytics and improvement, customer support, and legal compliance (section 4).
  • Sale and sharing: we do not sell personal information and do not share it for cross-context behavioural advertising. We do not knowingly sell or share the personal information of anyone under 16.
  • Sensitive personal information: we do not intentionally collect it. Your account sign-in details (a password, if you chose email sign-in) are treated as sensitive in California; we use them only to sign you in. If you type sensitive information into the AI prompt box, it is processed as described in section 3, so please avoid doing so. We do not use sensitive personal information to infer characteristics about you.
  • Retention: see section 8.
  • Your rights: to know what we collect, use and disclose; to access and delete your information; to correct it; to opt out of sale or sharing (not applicable, because we do neither); and to not be treated worse for using your rights. Delete your account in the app, or use the support page for other requests. We will verify your request by matching it to your account and may reply by email. You may use an authorised agent. We aim to respond within 45 days.

12. Children

Worren is not directed to children under 13, and you must be at least 13 to use it (or older if the law where you live requires a higher age to consent to online services, which is up to 16 in some EU countries). We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us through the support page and we will delete it.

13. Security

We protect your information with measures that include encrypted connections (HTTPS) between the app, our servers and our providers; salted password hashing; storing only a hash of session tokens; keeping your session and app secrets in the iOS Keychain on your device; limiting repeated failed sign-in attempts; scrubbing prompts, entries and request contents from error reports; and restricting access to our systems to the developer. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach that affects your personal information, we will notify you and the authorities as the law requires.

14. The website

The worren.world website does not use advertising or analytics cookies, and we do not run analytics scripts on it. It is hosted by Cloudflare, which processes connection data as described above. It loads fonts from Google Fonts, so Google receives your IP address and browser details. The waitlist form sends your email address to our server, where it is stored along with the date and where you signed up. The support form opens your own email app with a pre-filled message to us; what you send reaches us through your email provider, and we see your email address and message.

15. Changes to this policy

We may update this policy as Worren changes or as the law changes. The date at the top shows when it last changed. If a change is significant, for example if we start using your information in a new way, we will tell you in the app or by email before it takes effect, and ask for your consent where the law requires it.

16. Contact

For questions, requests, or complaints about privacy, use the Worren support page and choose "Question about my data". We usually reply within two days.

worren
registrysupportprivacy
© 2026 Worren