one-by.one

Privacy Policy

One by One Privacy Policy

Last updated: September 24, 2026

One by One is an iPhone and Apple Watch app that turns a stuck moment or short input into a small Begin flow with AI assistance. Personal features can be used without signing in; account and AI connection features use a One by One account. Most app data is stored on device using Apple's app storage technologies, and if iCloud is enabled it may sync through the user's private iCloud or CloudKit storage.

Data Stored in the App

One by One stores Begin flows, steps, execution records, notes, completion/skip/not-right feedback, notification settings, Calendar export settings, saved place labels or context, and subscription entitlement cache data that users create or use in the app.

This data is stored using Apple's app storage technologies. If the user's Apple Account has iCloud enabled and the app can use iCloud, the data may sync through the user's private iCloud or CloudKit storage.

Remote AI Processing

AI suggestions are a core One by One feature. By default, AI-backed features may call a Supabase Edge Function to turn input into an executable flow, and the server may send the prompt to a DeepSeek model.

When users use AI-backed features, the app may send user-entered text, flow feedback, selected candidate information, recent app context needed for flow generation, app language, input language, time zone and time context, energy baseline, and, when location-based recommendations are used, the selected place type or saved place name. One by One intentionally does not include precise location coordinates in AI prompts.

For request limits, abuse prevention, error analysis, reliability, and quality checks, the Supabase backend may record request metadata such as a user ID when an auth token contains one, an IP- or user-agent-derived rate-limit identifier, limit scope, function name, task type, model, request status, app and input language, input and note character counts, input hash, execution ID, token counts, processing duration, error information, and structured generation result metadata.

Remote AI processing is used only to provide app functionality. It is not used for advertising or cross-app tracking, and One by One does not sell this data. AI-backed Begin generation and step adjustment are core features, so remote AI processing is used by default when those features are used.

App Store Privacy Summary

For the first release, the App Store privacy answers disclose Other User Content, Coarse Location, User ID, Product Interaction, Performance Data, and Other Diagnostic Data for App Functionality. These categories are marked as linked to the user conservatively because remote AI request logs can be associated with quota or auth identifiers. They are not used for tracking.

iCloud Sync

One by One uses Apple's private CloudKit database for iCloud sync. Begin flow, step, execution record, note, setting, and saved context data may be stored in the user's private iCloud account. iCloud availability and storage are managed by the user's Apple Account and iOS settings.

This private iCloud data is managed by Apple. Signed-in account features also use the Supabase backend described below.

Account Data and Deletion

When you sign in, One by One stores your account, workspace and device associations, shared plans and activity, AI connection permissions, delivery records, and related operational data on its Supabase backend.

You can select Delete Account on the Account screen. After you confirm and the server accepts the request, deletion is immediate, with no grace period. The server deletes your account and sign-in sessions; account-owned workspaces, AI connections and grants, devices, shared plans, activity and execution records, delivery and receipt records, push endpoints, and account-linked AI usage logs. The app then erases its One by One records, saved session, and notifications on this iPhone. For Sign in with Apple, the app asks Apple to confirm again and the server attempts to revoke the Apple authorization; a revocation failure does not delay account deletion.

Deleting the account does not remove legacy NextKan data, files or Calendar events you exported, copies already saved in AI chats or other external services, or data in your Apple-managed private iCloud or CloudKit storage. It does not cancel an App Store subscription; manage that separately through Apple.

Purchases

One by One Pro subscriptions are processed by Apple through the App Store. One by One uses StoreKit to check the current entitlement and provide purchase and restore flows. Payment information is handled by Apple and is not collected by One by One.

Notifications

If users enable reminders, One by One schedules local notifications on device. Notification permission is managed in iOS Settings.

Calendar

If users enable Calendar export, One by One may request Calendar access and create events for completed Begin steps in a One by One calendar. One by One does not upload the user's full Calendar data to Supabase, DeepSeek, or its own server.

Location

If users enable location-based recommendations, One by One may use location permission to match the current location with saved places. When AI-backed features are used, saved place names or broad place context may be included in the AI prompt. Precise coordinates are intentionally not sent to the AI service.

Analytics, Advertising, and Tracking

One by One currently does not include third-party analytics SDKs, advertising SDKs, or cross-app tracking. The remote AI operational records described above are used for app functionality, request limits, abuse prevention, error analysis, reliability, and quality checks.

Contact

For privacy questions, email support@one-by.one.