The short version
Ribbons does not send content saved in your Ribbons to a Ribbons-operated content server. Your saved text, images, links, PDFs, notes, Drawers, and locally extracted searchable text live on your device and, when sync is enabled, in your iCloud account.
Ribbons does use limited online services for privacy-protected product analytics, anonymous installation registration, optional Sign in with Apple accounts, referrals and rewards, account deletion, and subscription status. Apple and RevenueCat also process purchase and subscription data. This Policy explains those boundaries in detail.
Who is responsible for your data
Ribbons’ developer—the person or business identified as the seller on Ribbons’ App Store listing—is responsible for the personal data Ribbons controls (“Ribbons”, “we”, “us”, or “our”). You can contact us through our support page.
Apple separately controls data it processes for iCloud, the App Store, StoreKit, Sign in with Apple, and Siri. Other linked websites and embedded services control the information they receive directly.
Ribbons and on-device processing
Depending on what you choose to save, Ribbons handles:
- text and rich text;
- images and image previews;
- PDF files and page information;
- web addresses, page titles, and link previews;
- names, notes, favourites, and Drawer membership; and
- text recognised or extracted from supported images, PDFs, and web pages you share from Safari, plus the local search index and match locations used to find it again.
Ribbons stores this information in an app-owned file area and local database. Image text recognition, PDF text extraction, and search indexing run on your device using Apple frameworks. Ribbons does not send this content to an advertising, analytics, or generative-AI service as part of that processing. Optional Siri and Shortcuts interactions are described below.
The Share Extension temporarily stages only the content you choose after you tap Save, so the main Ribbons app can import it. This staging area is shared only between Ribbons and its extension on your device.
Siri and Shortcuts
If you use Ribbons through Siri or Apple’s Shortcuts app, Ribbons receives the inputs needed for the action, such as search words, dictated text, a link, selected files, or an Item or Drawer selection. Ribbons searches your personal library on your device. It can provide Item names, content types, Drawer names, and matching text excerpts to Siri and Shortcuts to help you choose a result or complete an action. Siri may display results or speak response text aloud. Shortcuts can also receive content you request and pass it to other actions or services in a shortcut you run.
This integration does not record your voice in Ribbons or send your search words, Item titles, Drawer names, or saved content to Ribbons’ product analytics or account and referral service. Content saved through Siri or Shortcuts uses the same local storage and optional iCloud sync described in this Policy. Ribbons actions require the device running them to be unlocked.
Apple operates Siri and handles voice processing, transcripts, and related request data under its own policies. Depending on your device and settings, Siri may process requests on your device or send data to Apple’s servers. Ribbons’ local search does not mean the entire Siri interaction stays on your device. See Apple’s Siri, Dictation & Privacy notice for its processing, retention, and available controls.
You can manage Siri access for Ribbons and Siri history in Apple device settings, and manage shortcuts and automations in the Shortcuts app. Ribbons does not need Siri to save or search content within the app. Removing a shortcut does not delete Items already saved in Ribbons.
Save to Ribbons for Chrome
When you open the Chrome extension, it reads the current page’s URL, title, and declared preview-image address to show a review. It asks the connected Ribbons Mac app for your personal Drawers and whether the link is already saved. It does not continuously monitor your browsing or read your browser history, passwords, or cookies.
Clicking Save sends the link, optional name and note, and chosen Drawer to Ribbons on the same Mac. The extension keeps a pending save and its result in that Chrome profile’s local storage until the popup acknowledges the result, so an interrupted save can recover safely. This data is not stored in Chrome Sync. Local save receipts let Ribbons import each save once; saved items use the iCloud settings described below. The extension does not send your saved content to a Ribbons-operated server or include an analytics service.
Preview images are optional. Before you save, the Mac app may request an image directly from the website or image host, which receives the requested address and normal network information such as your IP address. This preview request does not use Chrome’s cookies or login credentials. Saving does not wait for the image to load.
The Mac app checks its last verified Ribbons Pro access before accepting a new Chrome save. The extension receives the result, not your Apple credentials or payment details. You can revoke the connection in Ribbons Settings. Removing the extension clears its Chrome storage; it does not delete items already saved in Ribbons. Manage those items in Ribbons and through your iCloud settings.
iCloud sync and Shared Drawers
If iCloud sync is enabled, Ribbons uses Apple CloudKit to copy supported records and files from your Ribbons into your private iCloud database. That data counts towards your iCloud storage and is handled by Apple under Apple’s iCloud terms and privacy policy. Ribbons’ developer cannot browse your private CloudKit database through the Ribbons account and referral service.
When search sync is enabled, Ribbons also stores recognised text from your personal images and PDFs, saved webpage text, and the locations of matching passages in your private iCloud database. This helps your other devices find saved content before its original file finishes downloading. This search data counts towards your iCloud storage. Search continues to work locally when you are offline. Search data from Shared Drawers is not included in this personal search sync.
When you share a Drawer, Apple moves or copies the relevant data into a CloudKit sharing space that invited participants can access. Participants receive the content and changes covered by their permission. They may copy or export content, so removing access later cannot remove copies they already made.
Ribbons stores technical sync state locally, such as device-scoped identifiers, record revisions, change tokens, queued changes, and deletion markers. CloudKit receives corresponding record and asset identifiers so it can sync safely and avoid duplicate or conflicting changes.
Optional Ribbons account data
When you first open Ribbons and connect to the internet, the app registers an anonymous installation with our service. We store a hashed random installation credential, platform, app version and build, test or production environment, and first and most recent registration times. The credential is stored in your device Keychain. This registration does not include your name, email, or saved content, and does not sign you in. If you later sign in with Apple, we link the registration to your verified Ribbons account. Separate devices may have separate registrations. This operational registration is separate from optional product analytics.
You can use Ribbons without giving Ribbons’ API your name or email address. If you choose Sign in with Apple for referral features, the app does not request name or email scopes. Ribbons’ service verifies Apple’s identity token and stores only what it needs to run the account:
- a unique Sign in with Apple subject identifier;
- a randomly generated Ribbons user identifier;
- a RevenueCat App User ID and a reusable referral code;
- hashed session tokens, session expiry times, and account creation and update times; and
- short-lived, single-use security nonces used to protect sign-in.
The app keeps its account access token and Apple user identifier in the device Keychain. It uses Apple’s credential-state service to notice when Sign in with Apple has been disconnected.
Subscriptions and purchase data
Apple processes payment details and charges. Ribbons does not receive your full card or bank information. Ribbons uses RevenueCat to load current App Store offers, determine whether Apple reports that you are eligible for a free trial, complete or restore a purchase, and decide whether Ribbons Pro is active.
Apple and RevenueCat may provide Ribbons and its service with purchase and subscription information such as an anonymous or Ribbons-linked App User ID, product and entitlement identifiers, offer and period type, purchase and expiry dates, transaction identifiers, cancellation or refund status, store environment, and whether a transaction is family-shared. Ribbons’ service stores the subset needed to verify referrals, rewards, account deletion, and webhook processing.
Starting the three-day free trial is free and does not count as a paid referral conversion. If you do not cancel at least 24 hours before the trial ends, Apple charges the monthly or annual plan you selected at the price shown in the App Store purchase sheet.
Referral and reward data
If you use referral features, Ribbons processes your referral code, who referred whom through generated Ribbons user IDs, referral status and timestamps, reward tier and status, qualifying transaction identifiers, and promotional-offer identifiers.
For a Shared Drawer referral, the app sends a one-way hash of the CloudKit share identity and the relevant CloudKit participant identifier to Ribbons’ service. The service combines them into a hashed invitation reference; it does not store the raw participant identifier. It does not receive the Drawer name, participant name, participant email address, share URL, or any Item content.
Links, previews, maps, and embedded content
Ribbons may connect directly from your device to a saved website to follow a redirect or fetch a title and preview image. For supported links, it may instead contact services such as Apple’s link metadata and Maps services, the Apple Music catalogue, YouTube, or TikTok. Opening an embedded YouTube, TikTok, or X item loads content from that provider.
Those providers receive the normal information sent with an internet request, which can include the requested URL or content identifier, IP address, device and browser information, and their own cookies or website data. Some embeds use a temporary in-memory web session; TikTok’s player currently uses the device’s standard WebKit website data store. The provider’s privacy policy governs its processing. Ribbons does not add this browsing activity to its account and referral database.
Product analytics and technical data
Website analytics
If you choose Allow analytics on getribbons.app, the website uses PostHog's European Union service to measure page views, unique visitors, links and buttons selected, video playback, device and browser information, and approximate visitor location such as country, region, or city. PostHog derives location from network information; this is an estimate, not your precise location. Website analytics may use cookies or local storage to recognise a returning browser. We do not send content from your saved Ribbons, search terms, or form entries to website analytics.
Website analytics starts only after you choose Allow analytics. You can decline or change your choice using Analytics settings in the website footer. Declining stops website analytics on that browser. This choice is separate from Share Product Analytics in the Ribbons app. The website does not use PostHog session replay.
App analytics
Ribbons uses PostHog's European Union service to understand app reliability and how features are used. Analytics can include app opens, platform and app version, screens or sheets viewed, buttons and settings used, item type and count, sharing or purchase outcomes, referral funnel steps, and non-content error categories. App analytics use a pseudonymous installation identifier and are not linked to your optional Ribbons account. Backend product events are stateless service metrics without a Ribbons user ID or another stable person identifier. App product analytics are disabled by default. You can opt in with Share Product Analytics in Ribbons Settings, and turn them off again at any time. On iPhone and iPad, an optional prompt also offers this choice after your first save.
The app does not use session replay or collect screenshots, console logs, network payloads, or automatic element interactions through PostHog. Ribbons removes saved content, URLs, filenames, search terms, Drawer names, referral codes, account identifiers, Apple identity values, and CloudKit share or participant identifiers from analytics events.
When the app contacts Ribbons’ limited online service, Ribbons and its hosting provider process standard network and operational data such as IP address, request ID, request route and method, timing, rate-limit data, and error category. We use this information to deliver the request, prevent abuse, secure the service, and diagnose failures. We do not intentionally place content saved in Ribbons, Apple subjects, referral codes, or CloudKit participant identifiers in application logs.
PostHog and hosting providers receive the IP address needed to handle a network request. Ribbons disables PostHog geolocation enrichment for app analytics; website analytics uses approximate location as described above. The app contains no third-party advertising SDK. We do not sell personal data or use it for targeted advertising or cross-app tracking.
Why we use this information
We use personal data only as needed to:
- save, search, sync, and share content at your direction;
- authenticate optional accounts and keep subscription access in sync;
- operate referrals and issue earned rewards;
- prevent fraud, abuse, and unauthorised access;
- understand feature use, improve Ribbons, maintain reliability, and investigate errors; and
- comply with law and enforce our Terms.
Where UK or European data-protection law applies, our legal bases are performance of our contract with you, our legitimate interests in securing and operating Ribbons, your consent or direction where a feature asks you to share information, and compliance with legal obligations.
Service providers and disclosure
We disclose only the information needed to:
- Apple for iCloud and CloudKit, Sign in with Apple, App Store billing, purchase verification, Siri and Shortcuts, maps, and related Apple platform services;
- RevenueCat for product offers, trial eligibility, receipt and entitlement verification, subscription status, and deletion of a linked subscription customer record;
- Railway and its infrastructure providers to host Ribbons’ limited account, referral, and subscription-metadata service and database;
- PostHog to provide privacy-protected product analytics and crash reporting in its European Union service; and
- websites and embed providers you use when you ask Ribbons to save, preview, resolve, open, or play their content.
We may also disclose information when required by law, to protect people or the service, or as part of a business transfer subject to appropriate safeguards. We do not give service providers permission to use your data for their own advertising.
You can read the relevant provider policies at Apple, RevenueCat, and Railway, and PostHog.
Retention and deletion
- Content saved in Ribbons: remains on your device and in iCloud until you delete it, remove the app’s local data, or manage it through Apple’s iCloud controls. Deletion must sync before other devices will receive it.
- Ribbons account: remains until you delete it in Ribbons or it must be removed for security or legal reasons.
- Installation registration: remains until removed through a privacy request or deletion of its linked Ribbons account. Opening the app again after account deletion can create a fresh anonymous registration.
- Referral and reward records: remain while your account or the related programme is active and as needed to settle rewards, refunds, disputes, fraud, and legal obligations.
- Operational logs: remain only for the period reasonably needed for security, reliability, and legal compliance, subject to infrastructure retention settings.
- Analytics: remain according to the configured PostHog project retention period and are deleted or aggregated when no longer reasonably needed for product analytics, reliability, and security.
Using Delete Account removes the Ribbons user, sessions, rewards, referral shares, linked RevenueCat customer, and directly linked webhook records. If another person already earned a reward from your referral, Ribbons keeps an anonymised qualification entry so their earned reward is not taken away. Updated versions of Ribbons also remove your saved library, files and allowance history from this device and Ribbons’ private iCloud storage. Drawers you own stop being shared; you leave other people’s shared Drawers without deleting their originals. A small marker without saved content remains so updated devices can recognize the deletion when they reconnect. Use the latest Ribbons on all your devices: older versions only delete the referral account and may upload retained library content again. Account deletion does not cancel an App Store subscription.
Security and international processing
Ribbons uses Apple platform protections, local app storage, Keychain storage for account sessions, HTTPS for network requests, hashed server session tokens, authenticated CloudKit access, and restricted service credentials. No storage or transmission method is completely secure, so keep your device and Apple Account protected.
Apple, RevenueCat, Railway, PostHog, and their providers may process data in countries other than where you live. Ribbons sends PostHog analytics to its European Union service. Where required, we rely on contractual and other lawful transfer safeguards offered by those providers.
Your choices and rights
You can:
- add, edit, delete, or stop sharing content in Ribbons;
- turn iCloud access for Ribbons off in Apple device settings;
- manage Siri access and history in Apple device settings, and shortcuts and automations in the Shortcuts app;
- avoid or disconnect the optional Sign in with Apple account if you do not want to use referral features;
- delete your Ribbons account from Settings;
- turn off Share Product Analytics in Ribbons Settings at any time;
- manage or cancel Ribbons Pro in your Apple Account subscription settings; and
- contact us through our support page to request access, correction, deletion, restriction, portability, or objection where applicable.
You may also complain to your local data-protection authority. For data controlled by Apple, use Apple’s privacy tools and support channels. Deleting a Ribbons account and cancelling an Apple subscription are separate actions.
Children
Ribbons is not directed to children who cannot lawfully consent to data processing where they live. A parent or guardian should manage a minor’s use where required. If you believe a child has created an optional Ribbons account without the required permission, contact us through our support page.
Changes and contact
We may update this Policy when Ribbons, the law, or our providers change. We will update the effective date and provide additional notice for material changes where required.
For privacy questions or requests, use our support page. Please do not include sensitive content from your Ribbons in a support message.
Your use of Ribbons is also subject to our Terms of Use.