Privacy policy
The short version: we collect nothing. There is no account, no analytics, no trackers, and no server of ours. Your documents are encrypted on your device with a key we never have, and the only things that ever leave it are listed below, in full, with what each one carries.
This policy is written so that each sentence can be checked against what the app does. If you find one that is not true, tell us at support@ralab.io and we will correct either the app or the sentence.
1. Who we are
RA Lab makes Document Organiser and runs this website. We are the data controller for anything described here, which, as you will see, is very little. Contact: support@ralab.io.
2. What we collect
Nothing. The app has no account to create and no sign-in. It contains no analytics, no crash reporting, no advertising or tracking code, and no third-party software development kits that could make a request on their own. Its App Store privacy label is “Data Not Collected”, and its privacy manifest declares no collected data and no tracking.
We therefore hold no personal data about users of the app. The one exception is email: if you write to us, we have your message and your address, as described in section 8.
3. What the app stores on your device
Everything you put into the app stays on your iPhone or iPad:
- the documents themselves — the photographs, scans, PDFs and other files you add;
- the text read off their pages, so you can search them;
- the details read from cards and identity documents, such as a card number, an ID number, a name or an expiry date, and any detail you add yourself;
- names, hashtags, folders, pins and reminders.
All of it is encrypted on the device (AES-GCM) under a key that is kept in the device’s Keychain and released only by Face ID, Touch ID or your passcode. The app locks itself soon after you leave it and immediately when the device locks. Sensitive numbers are masked on screen until you ask to see one, anything you copy is cleared from the clipboard shortly afterwards and is not handed to other devices, and the app warns you when you take a screenshot, because a screenshot is outside its encryption.
Uninstalling the app deletes everything it stored on that device.
4. What leaves your device, and why
This is the complete list.
4.1 Backup to your own iCloud
Unless you turn it off, the app keeps an encrypted copy of your library in your iCloud account, in the app’s private area of iCloud (CloudKit’s private database), so that losing the device does not mean losing your documents, and so that a second device signed into the same account can have the same library.
- What goes up is the same encrypted file that sits on your device. It is never decrypted on the way and cannot be opened without your key.
- The key that opens it is shared between your devices only through iCloud Keychain, which Apple end-to-end encrypts. It is never sent to iCloud’s document storage and never to us.
- We have no access to your iCloud account, cannot query it, and hold no credentials for it. Apple hosts it underApple’s privacy policy; Apple cannot read the documents either, because Apple does not hold the key.
- You can stop backup on any device from the app’s sync screen. A device you stop never restarts it on its own. What that device had already sent stays in your iCloud until you delete it there (in iOS: Settings › your name › iCloud › Manage Account Storage › Documents).
4.2 Fetching the optional reader
On a device without Apple Intelligence, the app can download its own reading model — about 1.4 GB in two files — so that it can answer questions about a document on the device. This happens only when you press the Download button, never on its own.
- The two files are fetched over HTTPS from two fixed addresses onHugging Face, pinned to an exact published version and verified against stored fingerprints before they are used.
- The request carries nothing about you or your documents: no body, no identifiers, no query. Hugging Face sees what any web host sees of any download — your IP address and the standard headers iOS puts on every request — under Hugging Face’s privacy policy.
- Once downloaded, the reader runs entirely on the device. Nothing about a document is ever sent anywhere to be read. You can remove the download at any time from Settings › On-device intelligence.
4.3 What you share or export yourself
When you share a document, a page or an export of your whole library, it leaves through the iOS share sheet to the app or person you choose, unencrypted, in its original format. That is you sending it, and where it goes is up to you.
4.4 Apple’s own services
Purchases, the free month’s entitlement and subscription status go through Apple’s App Store (StoreKit), and reminders you set go into a calendar of the app’s own in your calendar account, if you allow it. These are Apple’s services on your device, covered by Apple’s privacy policy. We receive no payment details and no personal data from Apple about you.
5. Reading on the device
Text is recognised with iOS’s own on-device text recognition. Questions you ask a document are answered by Apple Intelligence, on devices that have it, or by the downloaded reader described in 4.2. In both cases the reading happens on the device, and nothing from a document is transmitted to be read.
6. Permissions the app asks for
- Camera — to scan a card or document. Scans are read on the device and encrypted before they are stored.
- Photos — to import a picture of a card or document, in the same way.
- Face ID — to unlock your documents and to reveal a masked number. If Face ID is not available or fails, your passcode is offered.
- Calendar (full access) — to keep the reminders you set in a calendar of the app’s own, named Documents, and to find that calendar again. iOS has no permission for “only this app’s own calendar”, so it must ask for more than the app uses. The app never reads or changes your other events, and a reminder never contains a card or ID number.
- Notifications — for at most two kinds of local notice, neither of which names a document.
Declining any of these disables only the feature that needs it.
7. This website
ralab.io is a set of static pages. It sets no cookies, runs no scripts, loads nothing from third parties, and has no analytics. It is served by Cloudflare, which, like any host, handles the request your browser makes and may keep standard server logs for security, underCloudflare’s privacy policy. We do not look at them.
8. Email
If you write to support@ralab.io orfeedback@ralab.io, we have your email address and what you wrote, for as long as it takes to deal with it and for our records of the conversation. Our mail is hosted by Google Workspace. Please never send a document, a card number or an ID number; we do not need them and will not ask.
9. Children
The app is not directed at children under 13, and we knowingly collect no data from anyone, of any age.
10. Your rights
Because we hold no data about you beyond any email you have sent, there is nothing to access, correct, export or delete on our side — the data is on your devices and in your own iCloud, under your control. If you have emailed us and would like that correspondence deleted, ask and we will delete it. If you believe we have got any of this wrong, you can also complain to your local data protection authority.
11. Changes
If the app ever starts doing something this policy does not describe, the policy will change first, the date at the top will move, and the app’s own privacy page will say so. We do not treat a quiet edit to this page as notice.