Duly

Privacy Policy

What Duly does with what you say, in plain words. Last updated October 4, 2026.

The short version

What you say

Duly listens only while the capture bar is open. Your iPhone turns your voice into text. When it can't do that on its own for your language (this depends on the language and the iOS version), the audio goes to Apple's speech recognition while you talk, under Apple's privacy policy. The recording is saved on your iPhone so you can play it back, and it never goes to Duly's server or to iCloud.

Apple Watch in Duly 1.1

On Apple Watch, Duly records only while you're recording a ramble. The recording goes from the watch to your own iPhone, which turns it into text as described above, and is then removed from the watch.

With Duly Pro, the watch first sends the recording to Duly's server, so your ramble is sorted even when your iPhone isn't nearby. The server passes the recording to an AI model through OpenRouter, which turns it into text; the text is then sorted as described below, and the result goes back to the watch and on to your iPhone. Apart from Apple’s speech recognition described above, this is the only time Duly sends a recording outside your devices. Duly's server keeps neither the recording nor its text, and the same rules apply to the AI provider as for sorting: it may not train on what it receives or store it for its own use.

Sorting, idea sketches and note briefings

To sort a ramble, Duly sends its text and a limited set of saved items and lists to its server: their text, dates, entries and the identifiers needed to check requested changes. Older source quotes, generated idea sketches and note briefings are excluded from this sorting context. Your language, time zone and the time of the original recording are included, so a later retry interprets relative dates from when you spoke. The server runs on Vercel in Frankfurt, Germany.

The AI first reads only your current request. After the app's requested sources and changes are determined, only the saved text needed for those operations goes to a separate text-processing step. Item and list identifiers are not passed to that text step. The app verifies a signed result before applying changes. If more than one saved item or list could be the target, Duly saves your original words as a private note instead of changing those items. If saved data has changed, the ramble remains on your device for another try.

The server passes the text to an AI model through OpenRouter and sends the result back to your iPhone. Duly asks OpenRouter to use only AI providers that don't train on what they receive or store it for their own use. A provider may still hold a request for a limited time, for example to detect abuse. The model may run outside the EU, for example in the United States. Duly's server doesn't store what you said: its logs record timing, cost and how many things were changed, never the words. Idea sketches (the gist, angles and first steps for an idea) and note briefings (a gist and key points for a longer note) work the same way, using the item's title and text.

Details for things to try in Duly 1.1

When you save a movie, show, book or place to try, Duly looks up its details: the cover, the year, who's in it, what it's about, the address. Your iPhone or iPad sends only the title, straight to the service that has the answer and not through Duly's server: TVmaze for shows, Wikipedia and Wikidata (the Wikimedia Foundation) for movies, Apple for books and for places (Apple Maps), and Open Library (the Internet Archive) for books Apple doesn't have. Covers are loaded from the same services.

Like any website you visit, these services see your internet address with the request. They get nothing else from Duly: no account, no ID and nothing else you've saved. Your location isn't used to find a place. What's found is kept on your device. "Where to watch" opens JustWatch's search for the title in your browser, and only when you tap it.

Keeping the service safe

New app versions require Apple's App Attest proof before sorting; email preferences require this proof in all supported versions. Earlier app versions keep the existing sorting route and per-address allowance during the update period. The server keeps the installation key's public half, its ID and a replay counter. If verification is unavailable, your ramble waits safely on your device. A separate random identifier in the device Keychain keeps the daily allowance consistent when the app's key changes. Allowances use the server's UTC day, and their counts and request identifiers expire after two days. Requests carry device authorization alongside the text or Watch audio being processed, so this content is associated with your installation for app functionality. These security identifiers are separate from usage statistics. An encrypted email credential binds a verified address to the app's installation key for email security; the credential is kept in the device Keychain, not in Duly's server database.

Your things and iCloud

Everything you save (reminders, lists, ideas, notes and the rest) is stored on your device. If you have Duly Pro and turn on iCloud Sync, it's also kept in your own private iCloud database, encrypted by Apple, so your other devices can show it. Duly's developer can't read it. Turning sync off stops syncing, and your things stay on your device.

A list you share is kept in iCloud, and the people you invite can see and change it. When you stop sharing it, they lose access.

Signing in

Signing in is optional. Sign in with Apple gives Duly an ID for your Apple account and, if available, your name and email. They're kept on your devices, in your iCloud Keychain and iCloud so your other devices know it's you. Your email and first name also go through Duly's server to Resend for an account confirmation after registration. Product updates are separate and require your choice (see Emails below). You can pick a photo for your profile; it's kept on your devices and in your iCloud, never on Duly's server.

To prove that an email address belongs to you, the app sends Apple’s signed identity token to Duly’s server over an encrypted connection. The server verifies it and immediately discards it, without logging or storing the token or its Apple account ID. A limited-lived, encrypted credential on your device authorizes later changes to that same address. You may need to confirm with Apple again when it expires; your saved email choice does not change.

Subscriptions

Apple handles payment for Duly Pro, and Duly never sees your payment details. Duly uses RevenueCat to check whether your subscription is active. RevenueCat receives your App Store purchase records and an account identifier to check access and provide subscription analytics. When you sign in with Apple, Duly verifies Apple's identity proof on its server and derives an opaque identifier tied to that Apple sign-in account. RevenueCat retains this identifier and its purchase history so the same account can access Duly Pro across devices. Guests use an anonymous identifier. Duly does not send your name, email address or raw Apple account identifier to RevenueCat. Apple identity proofs are processed for verification and are not stored or logged on Duly's server. The verified mapping is kept in your device's Keychain. Signing out stops use of the previous account's access on that device; it does not cancel an App Store subscription. See RevenueCat's privacy policy.

Emails

After your first successful Sign in with Apple registration, Duly sends one account confirmation through Resend. It confirms your account and gives support information. It contains no product promotion and does not subscribe you to any mailing list. Resend receives your email address and first name to deliver it, and is based in the United States.

Duly news is optional. After signing in, the app asks once whether you want email updates. Only choosing yes subscribes you to the Duly news list and sends a separate updates welcome. Choosing no or dismissing the prompt does not subscribe you. Saved declines and email unsubscribes remain protected, and earlier automatic defaults are not treated as affirmative consent. On this website, entering your address under "Get updates" sends a confirmation link. You join Duly news only after opening that link and choosing to confirm; merely viewing the page does not subscribe you. The link expires after 24 hours. Signup responses do not reveal whether an address is already subscribed.

Updates use your email and first name in Resend's contact list. Every updates email has an unsubscribe link, and you can also turn Email Me News off in Settings. Account confirmations and product updates have separate delivery records; unsubscribing from news does not prevent a necessary account message.

Offline changes wait on your device and retry when the app is online. Duly's existing server storage keeps a keyed digest of the address, preference provenance, request identifiers and separate account/update delivery progress so retries do not duplicate emails or reverse an opt-out; it does not keep the address or first name there. Suppression records remain until deletion is requested. To have your address and these records removed completely, write to the address below.

Usage statistics

To see which features people use and where things go wrong, Duly sends short usage events to PostHog in its EU Cloud. An event is a name, like "a ramble was sorted" or "the paywall was shown", with a few fixed details: spoken, typed or from Apple Watch, how many things changed, why a ramble waited to be sorted, or an iCloud error code. Events also count app launches and updates. They never contain what you say, type or save.

Events include device model, system and app version, language, time zone, whether this is a development, TestFlight or App Store build, and random installation and session IDs. These let us count returning installations and feature use. They are not connected to your name, email, Apple account, iCloud data or subscription ID. PostHog is configured to discard internet addresses, skip location enrichment and create no person profiles. Screen recording, automatic interaction capture, notification capture and session replay are disabled.

You can turn this off in Duly's Settings > Share Usage Statistics. Your choice carries over when you update the app.

Earlier beta builds use TelemetryDeck, based in Germany, with data stored in the EU. Those events include device model, system and app version, language, region and time zone. Its device identifier is hashed on the device and again by TelemetryDeck; your internet address is not stored. Historical events stay there. After installing a current build, new events go to PostHog.

Notifications and widgets

Reminder notifications are scheduled on your iPhone. Widgets read your next reminders from your iPhone. Nothing goes to a server for either.

What Duly doesn't do

Duly doesn't show ads, sell or share data for advertising, or track you across other apps or websites. The usage statistics above aren't connected to your account and aren't used for advertising.

Deleting your data

Email preference and delivery records remain as described above, including keyed address digests that protect your unsubscribe choice. To request deletion of those records and your Resend contact, or ask about your data, write to the address below.

Children

Duly isn't made for children under 13 and doesn't knowingly collect data from them.

Your rights

Depending on where you live (for example under the GDPR or Turkey's KVKK), you have the right to ask what data is held about you, to have it corrected or deleted, and to complain to your data protection authority. Since your things stay on your devices and in your iCloud, most of this is in your hands, and anything else can be asked by email.

Changes

If this policy changes, the new version will be posted here with a new date. Important changes will also be mentioned in the app's release notes.

Contact

Duly is made by Ömer Balkan. Questions about privacy: support@useduly.app.