KettuJoin the list

Privacy Policy

Last updated 25 September 2026 · Elie Baier, Switzerland

The short version. Your ideas and files are stored so they are there when you come back, and we do not read them, sell them or train on them. The website uses cookieless analytics and stores nothing on your device, which is why there is no cookie banner. The app records which screens and features you use, linked to your account but never to what you write, and Settings turns that off. Joining the mailing list keeps your address and which link brought you here, until you unsubscribe. An idea leaves only when you send it: by pressing the research button, or by using a cloud model to transcribe your voice notes — which is the default only on an iPhone that cannot transcribe by itself, and which Settings lets you turn off. Then only that idea, or that recording, goes. You can take everything with you as a zip, and delete the lot from the app.

Who we are

Kettu is run by Elie Baier, an individual trading as Kettu, in Switzerland. For anything in this policy, write to support@getkettu.app.

Elie Baier is the data controller: the person who decides what is collected and why, and who is answerable for it.

What we collect

Your account

There are three ways to have one, and they differ in what we are given.

  • Sign in with Apple. We are given an account identifier and an email address. If you use Hide My Email, that address is a relay one and we never see your real one. Apple sends your name once, on the very first sign-in, and we store it so the app can greet you by it; if you do not give one, we do not have one. We never receive your Apple password — that sign-in happens with Apple, not with us.
  • An email address and a password. We send a confirmation link to the address before the account works, so we know it reaches you. The password is stored only as a hash, by Supabase, and is never visible to us — not in the database, not in a log, and not to anyone answering a support email.
  • As a guest. You can use the app without an account at all. There is no address, no name and no password — only an identifier, so your ideas have somewhere to belong. We are given nothing about you.

Turning a guest account into a real one keeps the same account. It adds an address to something that already exists rather than making a second one, so everything you have already written stays where it is.

What you write and attach

Your ideas, their titles, your workspaces and any files you attach — the recordings of your voice notes included — are stored on our infrastructure so that they are there on your next device and your next launch. That is a different statement from the one below it, and both are true:

  • We do not read them. Access is enforced in the database itself — every table carries row-level security keyed to workspace membership, so an idea is reachable only by the people in the workspace it belongs to.
  • We do not sell them, and never will. There is no advertising on this product and no data broker in the chain.
  • We do not train models on them. Not ours, and not anybody else’s.

The mailing list

If you give us your email address on this website, we keep three things: the address, which form on the page you typed it into, and where you came from. Nothing else — no name, and no account, because joining the list is not an account.

“Where you came from” means the tag on the link you followed — we put a different one in each place we post — or, if there was no tag, the name of the site that sent you, such as reddit.com, and the community on it, such as r/SideProject, when the link we are given says so. Never the address of the page you were reading, and never a person’s name: if you arrived from a search, the thing you searched for is discarded before anything is stored. It is how we tell which posts were worth writing, and it is answerable only about the visit you signed up in — we store nothing on your device to work it out, which is why there is still no cookie banner here.

The list is held by Resend. We write to it when a seat opens for you, and about what lands next if that is what you signed up for. Every email carries an unsubscribe link, and one press is the end of it; you can also write to support@getkettu.app and we will take you off it. The address is never sold, and never passed to anyone but the provider that sends the email.

Analytics

On this website we use Rybbit, which is cookieless. It sets nothing on your device, does not follow you to other sites, and cannot identify you — which is why you have not been shown a cookie banner. There is nothing to consent to. It tells us which pages are read and roughly where in the world from, and nothing else.

In the app we use PostHog, in its European region, to learn which screens are opened, which features are used, and when and for how long the app is open — so we can tell what is worth building. It is linked to your account by the account’s identifier, never by your email or your name, and it is never joined to the content of your ideas: no titles, notes, files, recordings, research or workspace names. Each record carries your device model and screen size, your iOS and app versions, your language, and whether you were on Wi-Fi or mobile data. Your IP address is discarded and no location is kept.

Before you sign in, a random identifier stands in for an account, and signing in files it under yours. PostHog also holds a copy of a few facts from our database — when each account was made, what kind it is, and how many workspaces, ideas and files it has — again without any of their content. All of this is on unless you turn it off in Settings → Share Usage Data, which stops it from that moment on.

If you write to support

You get to choose what is in that email. If you use the Contact Support row in the app, it attaches a short block you can read and delete before sending: the app version, the build, your iOS version, your device model and your account identifier. It deliberately contains no access token, no key, no text from any idea, and no device name.

What stays on your phone

Idea titles, and the shortened notes shown in the list, are written by Apple’s on-device model. That happens on your iPhone. The text of your note is not sent anywhere to produce them, not to us and not to Apple.

The shortened notes are cached on your device, in the app’s own storage. Clearing them in Settings removes them.

When you record a voice note, its words are transcribed on your iPhone by Apple’s own speech recognition, as you speak, and nothing is sent anywhere to produce them. That needs iOS 26 or later and a language Apple has a model for; where your iPhone cannot do it, or where you pick a cloud model yourself, the next section is what happens instead. The recording itself is kept with the idea, stored like any file you attach, so you can listen to it again or share it — which also means it is on our infrastructure, under everything the section above says.

Research and cloud transcription: when your idea leaves

Research is the exception to everything above, and it is worth being exact about it. When you press the research button, the text of that idea is sent to an AI provider — Perplexity or OpenAI, depending on the model chosen — so it can be read and answered. The findings come back and are stored against the idea.

Three things follow from that, and all three matter:

  • It happens only when you ask. Writing an idea down sends it nowhere. There is a button, and nothing runs until it is pressed.
  • Only the idea you asked about is sent. Not your other ideas, not your files, not your account.
  • Those providers are bound by their own terms as our processors. We do not permit them to train on what is sent, but their handling is ultimately theirs — if that matters to you, do not run research on an idea you would not want a third party to process.

Cloud transcription is the one other way anything leaves. Each recording you make from then on is sent to OpenAI or Groq — whichever company offers the model in use — to be transcribed, and the words come back into your note. Recordings made beforehand are not sent, and neither is anything else about the idea.

There are two ways it comes to be on, and one of them is not a choice you made. Picking a model under Voice Notes in Settings is the obvious one. The other is that an iPhone that cannot transcribe by itself uses a cloud model by default — iOS 18 to 25 have no on-device speech recognition of this kind, and neither does a language Apple has no model for — because the alternative is a voice note that never gets any words at all. The Voice Notes page always names the company that receives the recording, and Don’t Send Recordings there keeps every recording on your iPhone, with no words written for it.

To keep what this costs within bounds we record how long each such recording was, which model transcribed it and what that cost — never the words. The words exist only in your note.

Why we are allowed to hold it

Under the GDPR the reasons have names, and ours are these:

  • To give you the service you asked for — your account, your ideas, your files, and research when you request it. Without this data there is no product.
  • Our legitimate interest in understanding how the product is used and in keeping it secure — the analytics above, linked to your account but kept deliberately thin so that interest does not outweigh yours, and switched off with one switch in Settings.
  • Your consent — the mailing list, which you join by typing an address into a form and nothing else, and where anything else ever requires it. You can take it back at any time, and unsubscribing is taking it back.

Who else touches it

These are every company involved in running Kettu. They act on our instructions, they are not permitted to use your data for their own purposes, and none of them is paying us for access to it — we do not sell your data to anybody, for anything.

WhoWhat forWhere
SupabaseDatabase, file storage, authentication and the research worker. Everything you create is held here, and account emails are sent from here.United States
AppleSign in with Apple, and distribution through the App Store and TestFlight.United States, Ireland
PerplexityResearch. Receives the text of the idea you asked about, and only then.United States
OpenAIResearch, and transcription. Receives the text of the idea you asked about, or a voice note, when an OpenAI model is the one transcribing — which it is by default on an iPhone that cannot transcribe by itself.United States
GroqTranscription, if you pick its model. Receives a voice note you recorded from then on, and nothing else — never an idea's text.United States
PostHogApp analytics: which screens you open and which features you use, linked to your account's identifier and never to anything you write, record or attach. Also holds a copy of when each account was made and how many workspaces, ideas and files it has, without any of their content.Germany
RybbitWebsite analytics. Cookieless, and receives no account information.Germany
ResendThe mailing list on this website. Holds the address you give us and where you arrived from, and sends the email when a seat opens.United States

Several sit outside Switzerland and the EEA. Where they do, transfers rest on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.

How long we keep it

Your account and everything in it stays until you delete it. We are not holding anything back for a rainy day.

  • Delete an idea and it goes, along with its files and any research attached to it.
  • Delete your account and the whole of it goes: ideas, files, workspaces, research, usage data, and the account record itself. We complete this within 30 days, and backups age out within a further 30.
  • The mailing list is kept until you leave it. Unsubscribing removes you from it, and having an account or not makes no difference either way — the two are separate lists of separate things.
  • Usage data from the app is linked to your account, so it goes with it: deleting your account erases it from PostHog before anything else is removed, within the same 30 days, and the copy of your account’s facts held there is replaced every day. Otherwise PostHog keeps usage data for a year. Turning off Share Usage Data stops new data from that moment; to have what was already sent erased, write to us.
  • Website analytics are not tied to anyone and are kept in aggregate.
  • A guest account has no address attached, so once you lose that session on that device there is no way for anyone — including us — to reach it again. That is the trade for not having given us anything. Adding an address in the app fixes it, and keeps everything already written.

What you can ask us to do

Under the Swiss FADP and the GDPR you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to stop processing it, and object to processing based on legitimate interest. Write to support@getkettu.app and we will answer within 30 days. It costs nothing.

To delete your account, use Delete Account in the app’s settings. It removes everything described above. If you would rather we did it, email instead.

You do not need us for a copy of your ideas: every idea can be shared out of the app as a zip, containing the note as Markdown and every file beside it. It opens on a machine that has never heard of this app, which is the point.

If you think we have got something wrong, you can complain to the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or to the data protection authority where you live in the EU or UK. We would rather you told us first.

Keeping it safe

Data is encrypted in transit and at rest. Every table is protected by row-level security in the database, so authorisation does not depend on the app asking the right question — the database refuses the wrong one. Files are held in a private bucket, reachable only through short-lived signed links issued to someone who is already a member of the workspace.

No system is perfect. If we ever suffer a breach that puts you at risk, we will tell you and the relevant authority, promptly and in plain words.

Children

Kettu is not intended for anyone under 16, and we do not knowingly collect anything from them. If you believe a child has given us data, write to support@getkettu.app and we will remove it.

Changes to this policy

If this changes, the date at the top changes with it, and it only moves when the words do. For anything that materially affects you — a new category of data, a new purpose — we will tell you in the app or by email before it takes effect, rather than leaving you to notice.