Last updated July 26, 2026
Datum is built around a simple rule: your data is yours. There is no Datum account, no sign-up, and no server of ours that stores what you track. This page explains exactly what that means, including the narrow, deliberate exceptions.
The trackers, entries, check-ins, notes, photos/video references, and settings you create in Datum are stored locally on your device. If you're signed into iCloud, they sync across your own devices via Apple's CloudKit private database — the same mechanism Apple's own apps use, governed by Apple's privacy policy. We do not have a copy of this data, cannot read it, and have no way to access it even if asked.
Optional attachment types (photos, videos, voice notes, calendar events, weather, music, workouts, location) are captured only when you explicitly enable them for a tracker, and are stored the same way — locally and in your own iCloud, or as on-device references (e.g. a photo stays in your Photos library; Datum stores a reference to it, not a copy).
If you enable location capture for a tracker, your coordinates are captured on-device and, to resolve a place name, may be sent to Apple's map services. This happens only for trackers you've opted in, and only at the moment of capture.
Datum can save your data to a backup file. There are two ways one gets created, and neither sends anything to us:
A backup is a plain, unencrypted JSON file. It is protected by whatever protects the place it sits — your device passcode, your iCloud account — and not by a separate password of its own. Anyone who can read that location can read the backup, so treat one the way you would any other export of your own records.
A backup holds your trackers, entries, check-ins, notes, and settings, plus references to attachments rather than the attachments themselves. Photos and videos stay in your photo library and voice recordings stay in Datum's own storage; a backup points at them instead of copying them, so it is not a duplicate of your media.
Health data is deliberately excluded from every backup. When you connect a tracker to Apple Health, that data is mirrored into a separate on-device database that never syncs, and it is left out of backups entirely — because a backup can come to rest in iCloud Drive, and Apple does not permit Health data to leave your device that way. Health values are read fresh from Apple Health on each device instead. Other connected sources — Photos counts, Calendar, Reminders, and Datum's own storage usage — are included, since no such restriction applies to them.
Restoring a backup either replaces everything in the app or merges the file into what is already there, depending on which you pick, and cannot be undone from inside Datum.
Datum operates exactly one server-side component beyond Apple's own infrastructure: an anonymous push-relay that delivers scheduled notifications your device can't reliably trigger on its own (for example, a reminder that should silently log an entry without opening the app). That relay stores only:
It never receives or stores tracker data, values, names, or notes. Its source code is public and open for independent review, precisely so this claim doesn't have to be taken on faith.
If you contact support from the app's Support screen or the form on this site, your message is tied to your device's anonymous Support ID (a random token, not an account) — not your name or identity. If you instead email us directly, or use the site's support form, that email address is used only to reply to you; it is never stored alongside your tracker data or treated as tracking information.
Screenshots or screen recordings you choose to attach to a support ticket are stored to help us resolve the issue, and are automatically deleted a limited time after the ticket is closed.
Purchases are processed by Apple and a purchase-management provider, RevenueCat, and are identified only by a randomly generated, non-personal Support ID — never your name, email, or Apple ID. See Settings in the app for your Support ID.
Because Datum is local-first, the only parties that ever see any data are the infrastructure providers that make the app itself work:
We do not sell data, and there is no advertising or analytics SDK in Datum.
datumapp.info uses Plausible, a privacy-focused analytics service, to see how many people visit. Plausible sets no cookies, collects no personal data, and cannot identify you individually or track you across other websites — it counts visits, not people. This is unrelated to the app itself, which has no analytics of any kind (see above).
Because there's no account, there's nothing to delete on our end for ordinary use — deleting the app (or your data within it) removes it from your device and, if you choose, your iCloud. For a support ticket that included your email or an attachment, you can ask us to delete it by contacting support with your Support ID.
If this policy changes, we'll update the date at the top of this page. Material changes will be reflected here before they take effect.
Questions about this policy, or a request related to your data, can be sent through the app's Support screen or the form on datumapp.info.
Datum is made by EKPQA, LLC, a Delaware limited liability company.
← Back to datumapp.info