Privacy Policy
Just Apps by Juice Box Monkey Designs Inc.
Effective 11 September 2026. Last updated 11 September 2026.
This policy covers every app we publish on Apple's App Store under the Just name, including Just For Kids, and any future app in the family. It covers our websites too. Where a particular app needs its own detail, you will find it at the bottom under App specific notes.
The short version
Just For Kids collects nothing. No accounts, no ads, no analytics, no third party code of any kind. It is the one app in the family with zero outside dependencies, and that is deliberate.
Every other Just app sends usage signals to one analytics service, TelemetryDeck. Things like "the app launched" or "a note was created", along with the device model and OS version. Never your content and never your name. What rides along is a scrambled code for the installation, not for you.
No Just app has accounts, ads, ad identifiers, or tracking as Apple defines it. Anything you make in a Just app stays on your device and syncs through your own private iCloud, which we cannot read.
The long version below says the same thing with the detail a regulator, a reviewer, or a curious parent would want.
Who we are
Juice Box Monkey Designs Inc. is a Canadian corporation based in Elmira, Ontario. We are the developer of the Just apps and the data controller for the purposes of this policy.
Email: support@juiceboxmonkeydesigns.com
Post: PO Box 52, Elmira, ON N3B 2Z5, Canada
Web: juiceboxmonkeydesigns.com
Who is accountable
Canadian law asks us to name a person, not a department, and we are small enough that this is easy. Tyler Hackbart, Director, is the person accountable for personal information at Juice Box Monkey Designs Inc. and the person in charge of the protection of personal information for the purposes of Quebec's Law 25. Reach him at the email and postal address above. He reads it himself.
We make no decisions about you by automated means, in any app or on any site. Nothing you do gets scored, ranked, or used to decide anything that affects you.
If you are unhappy with how we have handled something, tell us first and we will try to put it right. If that does not work, the routes onward are listed under Your rights.
What we collect
Never, in any app
- No account, sign up, email address or password. There is nothing to create and nothing to log into.
- No advertising, no ad networks, no ad identifiers, no IDFA.
- No tracking as Apple defines it. We do not use App Tracking Transparency because we have nothing to ask permission for. We do not follow you across other companies' apps or websites.
- No crash reporting SDK.
- No profiling and no automated decision making. We do not build a picture of who you are, and nothing about you is decided by a machine.
- No selling, renting or sharing of your information, to anyone, ever.
- No location data, no contacts, no calendar, no microphone, no camera, unless an individual app names one of these below, and then only with your explicit permission and only on your device.
- None of your content. Not your notes, your lists, your files, your photos, or your child's name. None of it reaches us in any form.
In every Just app except Just For Kids
Usage signals, through a service called TelemetryDeck. The whole of the next section is about that, because it is the only thing we receive and you should be able to see all of it.
In Just For Kids
Nothing. Not a signal, not a request, not a byte.
Analytics, and the one exception
What it is
Every Just app except Just For Kids includes TelemetryDeck, a privacy focused analytics service run by TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg, Germany. It is built and hosted in Europe, and we picked it because it is the most restrained option we could find rather than the most informative one.
What gets sent
When something happens that we have asked to count, the app sends a small signal. A signal contains:
- The name of the thing that happened, for example "app launched" or "list created". A name only, never what the list said.
- A timestamp rounded to the nearest hour.
- Basic device metadata: device model, operating system version, app version, and language or region.
- A scrambled installation code, described below.
That is the entire payload. No content, no file names, no text you typed, no photos, no clipboard, no identifying detail of any kind.
The installation code, in the apps
This is the part people care about, so here is exactly how it works. The app takes a per install value, adds a secret salt, and hashes it on your device before anything is sent. TelemetryDeck then adds its own salt and hashes it a second time when it arrives. Neither we nor they keep the original, and hashing only runs one way, so the code cannot be unscrambled back into a device or a person.
What it is for is counting people rather than taps, so that five hundred launches does not turn out to be one very enthusiastic person. What it is not is the IDFA, an advertising ID, or anything shared with another company.
Here is the honest limit of it. The code is stable for as long as the app stays installed, so the signals from one installation sit together as a group even though nobody can put a name to that group. Privacy law calls that pseudonymous rather than anonymous, and we would rather use the accurate word than the flattering one. We treat these signals as personal data and give you the rights that go with them, set out below.
On our websites it works differently
The web version has no app to read a value from, so it builds its code out of your IP address, your browser user agent string, the site identifier, and a salt that changes every day, all put through the same one way hash. Your IP address is an ingredient, not a record: it is used to make the code and to work out roughly which country you are in, and it is not written to a log or kept in a database. Because the salt changes daily, the same visitor is only recognised within the same day on the same site, and never across sites.
What is never kept
No IP addresses in the logs or in the database. No cookies and no browser storage, in the apps or on the sites. Nothing that another company could join to its own records to work out who you are.
How long it is kept
TelemetryDeck keeps the signals to draw the charts we look at. Recent signals stay queryable for the dashboards; older ones move to cold storage, which TelemetryDeck expects to clear out after seven to ten years and does not currently guarantee a date for. We think that is longer than it needs to be and we have said so. Because the signals carry no name, no account and no contact detail, age does not make them any more revealing than they were on day one.
What we ask of TelemetryDeck
TelemetryDeck is the only third party that receives anything from our apps, and it is bound to protect what it receives to the same standard this policy sets out. It does not sell it, does not share it with advertisers or data brokers, and does not use it for its own purposes. Their terms are at telemetrydeck.com/privacy. If that ever stops being true, we drop them.
Why we do it at all
We are a very small studio building several apps at once. The signals tell us which features are worth keeping, which OS versions we can stop supporting, and whether a release broke something. That is the whole reason. Nobody is being scored, segmented, or sold.
In Apple's words
On the App Store listing for these apps, this is declared as Product Interaction and Other Usage Data, under Analytics, marked Not Linked to You and Not Used for Tracking.
Turning it off
There is no switch inside the apps today, and we are not going to pretend otherwise. If you want an app that sends nothing at all, Just For Kids already is one. A setting for the others is something we are considering, so if you want it, write to us and say so and it moves up the list.
If you want to object to the analytics as a matter of your rights rather than just turn it off, email us and say so. We will log the objection, count it towards building the setting, and tell you plainly what we can and cannot do about signals already sent, which is honestly not much, because we cannot tell which ones came from you.
Where your data lives
On your device. The things you create in a Just app, and the settings you choose, are stored locally on the device using Apple's standard storage frameworks.
In your own iCloud, if you use it. Where an app offers sync between your devices, it uses Apple's CloudKit private database. That means your data goes into your personal iCloud account, under your Apple Account, encrypted in transit and at rest by Apple.
This part is worth reading twice: a CloudKit private database is yours, not ours. We have no access to it, no console that shows it, and no technical means of reading it. Apple processes that data as part of the iCloud service you already have, under Apple's own privacy policy at apple.com/legal/privacy.
If you sign out of iCloud, or turn off iCloud Drive for the app, sync simply stops and your data stays on the device.
Photos, files and other content you choose
Some of our apps let you bring in your own content, for example choosing a photo as a child's avatar, or dragging a file into a capture app. When you do that:
- You pick the item yourself through Apple's own picker. We never get access to your photo library or file system as a whole.
- The item is stored on your device, and in your private iCloud if sync is on.
- It is never sent to us or to anyone else.
If an app needs permission for something like your photo library, iOS asks you, and you can change your answer at any time in the Settings app.
Children, and Just For Kids
Just For Kids is built for children and is listed in Apple's Kids Category. We took that seriously and designed for it rather than retrofitting it.
Just For Kids is the one app in the family with no analytics at all. It has zero third party package dependencies, makes no network requests of its own, and every framework it imports is Apple's. That is checkable from the app's dependency list rather than something you have to take on trust.
So, in Just For Kids specifically:
- We collect no personal information from children. Not names, not ages, not photos, not usage. A child's profile name and avatar exist only on the family's own devices and in the family's own iCloud.
- No advertising of any kind, including no contextual ads.
- No analytics, so nothing about how a child uses the app is measured or transmitted.
- No in app purchases and no purchasing opportunities inside the app.
- No social features, no chat, no messaging, no user generated content shared with anyone.
- Links out of the app, and the settings screens that contain them, sit behind a parental gate.
- Its privacy manifest declares no tracking, no tracking domains, and no collected data types.
Because we collect nothing from children, we do not need and do not seek verifiable parental consent under the United States Children's Online Privacy Protection Act (COPPA), and there is no children's data for us to retain, disclose or delete. The same reasoning applies to the UK Age Appropriate Design Code and to equivalent rules elsewhere.
The other Just apps are general audience utilities. They are not children's apps and are not listed in the Kids Category.
If you are a parent or guardian and you have a question about any of this, write to us at the address above and we will answer.
What Apple may tell us
We buy nothing and receive nothing from any data broker or advertiser. Apart from the analytics described above, there are only three ways information about app usage reaches us at all, and all three come from Apple:
- Sales and download reports. App Store Connect shows us aggregate, anonymous numbers: how many people downloaded or bought an app, in which countries, on which device types. We cannot identify anyone from these.
- Crash and performance data. If you have turned on Share With App Developers in iOS Settings, under Privacy and Security, then Analytics and Improvements, Apple may give us aggregated crash logs and performance measurements. This is Apple's system, controlled by your setting, and you can turn it off at any time. It contains no personal information.
- Ratings and reviews. If you write a review on the App Store, it is public, and it carries whatever nickname is on your Apple Account. That is Apple's service, not ours.
Some of our apps use Apple's StoreKit to show the standard "enjoying this app?" rating prompt. That prompt sends nothing about you to us.
Purchases
Our apps are paid once, with no subscriptions. Payment is handled entirely by Apple. We never see your card number, your billing address, or your Apple Account details. Apple's terms and privacy policy govern the transaction, and refunds go through Apple.
Our websites
Our marketing and support pages, this one included, set no cookies at all and run no ad networks. They do run TelemetryDeck's web script to count page views, which works the way described above: no cookies, a code rebuilt daily from your IP address and browser user agent, and no IP address written down anywhere.
Because we set nothing on your device and keep no profile, a Do Not Track signal from your browser changes nothing about what we do. We do not respond to it, for the simple reason that there is nothing for it to switch off.
Our hosting provider keeps standard server logs, which may include IP addresses and browser user agent strings, for a short period for security and reliability. We do not use these to build a profile of you or to identify you.
If you send us a message through a contact form, we keep the message and your reply address for as long as it takes to answer you and a reasonable while after in case you write back, and no longer. If you sign up to be notified about an app, we keep your email address until the notice goes out or until you ask us to drop it, whichever comes first. We do not add you to anything else, every email we send carries a one click unsubscribe, and asking us to delete your address is enough.
Some pages link to third party sites, such as Apple's App Store. Once you leave our site, that site's own privacy policy applies.
Who else touches any of this
A short list, because it is a short list.
- Apple. The App Store, iCloud and StoreKit, under Apple's own privacy policy.
- TelemetryDeck GmbH, Germany. Usage analytics for every app except Just For Kids, and for our websites.
- Our website host. Serving these pages and keeping short lived server logs.
That is the complete list. No brokers, no advertisers, nobody else.
Legal bases, for people in the UK, EU and EEA
For Just For Kids there is no processing to justify, because there is none.
For the analytics in the other apps and on this site, we treat the signals as pseudonymous personal data rather than argue they are anonymous. Our legal basis is legitimate interest under Article 6(1)(f). The interest is a specific one: knowing which features are used, which devices and OS versions we still need to support, and whether a release broke something, so that a very small studio spends its time on the right things. We think that is proportionate because the signals carry no name, no account, no contact detail and no content, and because you can object at any time.
For the launch notice email list, our legal basis is your consent, which you give by typing your address in and can withdraw at any time. For answering a message you send us, it is taking steps at your request. For server logs, it is legitimate interest in keeping the site secure and available.
We are not required to appoint a Data Protection Officer and we have not appointed one. Privacy questions go to the person named under Who is accountable, below, and they are answered by a human.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of personal information about you, to object to processing, and to complain to a regulator. That includes rights under the UK and EU GDPR, Canada's PIPEDA, the California Consumer Privacy Act as amended, and similar laws.
We can honour most of these immediately, because we hold almost nothing.
- Just For Kids. We hold nothing at all, so there is nothing to give you, correct, or erase.
- Analytics. We hold signals tied to a scrambled installation code, not to you, and we cannot work backwards from the code to a person. The flip side is that we cannot pick your signals out of the pile to show you or delete them either, because we have no way of telling which ones are yours. Under Article 11 of the GDPR we are not required to collect more information about you in order to identify you, and we are not going to start. If you can give us something that would let us find your records, we will use it for that and nothing else.
- Email you have sent us. Ask and we will delete it.
Your right to object, separately. Because the analytics runs on legitimate interest rather than your consent, you have a standing right to object to it. You do not need a reason. Email us, say you object, and we will act on it as described under Turning it off above. We answer any privacy request within thirty days and usually a lot sooner.
We have never sold or shared personal information, and we never will. We are too small to meet the thresholds that make a company a "business" under the California Consumer Privacy Act, so it does not apply to us, and we would rather say that than post a "Do Not Sell" link implying we had something to sell. We do not sell or share personal information as the CCPA defines those terms, including for cross context behavioural advertising, and we do not handle sensitive personal information. If you are a Californian and you want to ask us what we hold or tell us to delete it, ask anyway and we will treat it like any other request.
If you want to delete the data our apps hold, it is entirely in your hands:
- On device: delete the app. iOS removes its local data with it.
- In iCloud: go to Settings, tap your name, then iCloud, then Manage Account Storage, and delete the app's data. You can also delete records from within apps that offer it.
Neither action requires anything from us, and neither is reversible, so take a copy first if you want one.
Residents of the UK and EEA may complain to their national data protection authority. Canadians may complain to the Office of the Privacy Commissioner of Canada. We would rather hear from you first.
Where data goes internationally
We hold no content of yours anywhere. Where an app syncs through iCloud, the location of that storage and any international transfer is determined by Apple as part of the iCloud service, and is described in Apple's privacy policy.
Analytics signals go to servers in Germany, which is to say inside the EU, and we read the dashboard from Canada. Canada holds an adequacy decision from the European Commission, and an equivalent determination from the UK, covering commercial organisations that are subject to PIPEDA. We are one of those organisations, which is what makes the adequacy decision apply to us, so no extra transfer paperwork is needed for the little there is.
For Quebec residents, the same two flows are the only ones that leave the province: signals to Germany, and a dashboard read from Ontario. We have assessed both and are satisfied the information gets adequate protection, given that it carries no name, no account and no content, and that Germany sits under the GDPR.
Security
Data on your device is protected by iOS itself, including the device passcode, Face ID or Touch ID, and file level encryption. Data in iCloud is encrypted in transit and at rest by Apple. Because we hold no copy of your content anywhere, there is no server of ours that could be breached and no database of ours that could leak.
The analytics we do receive is anonymised on your device before it leaves it, so the worst case there is that somebody learns how many people opened an app on a Tuesday.
No method of storage or transmission is perfectly secure, and we do not claim otherwise. We do claim that the safest data is the data nobody collected.
Changes to this policy
If we change what our apps do, we will change this policy before or at the same time, and we will update the date at the top. We also read the whole thing over at least once a year whether anything has changed or not. Material changes will be noted in the app's release notes as well. The current version always lives at justblank.app/privacy.
Contact
Questions, corrections, or a concern about a child's privacy:
Email: support@juiceboxmonkeydesigns.com
Post: PO Box 52, Elmira, ON N3B 2Z5, Canada
Web: juiceboxmonkeydesigns.com
We read everything and we answer.
App specific notes
Everything above applies to every app. These notes add the detail particular to each one.
Just For Kids
No analytics- Analytics: none. No TelemetryDeck, no third party packages, and no network requests of the app's own.
- Child profiles. A parent creates a profile for each child with a name, a colour, and either a built in icon or a photo from the device's photo library. All of it stays on the device and in the family's private iCloud. We never see any of it.
- Photo library access. Only through Apple's photo picker, only when a parent chooses a photo, and only for the single image chosen. The app has no access to the rest of the library.
- Sync. Profiles, per child settings and activity data sync between the family's own iPhones and iPads through the family's private iCloud. Sync can be stopped by turning off iCloud for the app.
- The Activity Log. The app keeps a log of what happened in the app, visible to the parent in Settings. It is a feature for parents, not analytics. It is stored on the device and never leaves it.
- The Phone activity is pretend. It has no telephony access and no network access. It dials nothing and connects to nothing.
- Animal Sounds and Match play local audio and show local images that ship inside the app. Nothing is downloaded.
- Parental gate. Settings, and every link that leaves the app, sit behind an arithmetic gate intended to be answerable by an adult and not by a young child.
- Guided Access. The app includes a guide to turning on Apple's Guided Access feature. The app cannot turn Guided Access on or off, and cannot read anything from it beyond whether its own session is active.
- Required Reason APIs. The app uses UserDefaults to remember its own settings on the device, declared under Apple's reason code CA92.1, accessed only by this app. Its privacy manifest declares no tracking, no tracking domains, and no collected data types.
Just Drop
Usage analytics- Analytics: TelemetryDeck, exactly as described above. Event names and device metadata, never the thing you dropped.
- Captured text, images and files are stored on the device and, where enabled, in your private iCloud. Nothing is uploaded to us.
- The app reads the system pasteboard only when you ask it to capture, and only the item you capture.
Just Jot and Quick Jot for Mac
Usage analytics- Analytics: TelemetryDeck, exactly as described above.
- Notes are stored on the device and, where enabled, in your private iCloud. The text of a note never reaches us, in any form or at any size.
Just Shopping
Usage analytics- Analytics: TelemetryDeck, exactly as described above.
- Lists and items are stored on the device and, where enabled, in your private iCloud. What is on your list is your business.
Future Just apps
Every new app follows the general policy above, and unless we say otherwise here it includes the same usage analytics as the rest. If one ever does something that needs explaining, it gets its own block here before it ships.
We have written this in plain language on purpose. If anything here is unclear, or you think we have got something wrong, write to us and we will explain it or fix it.