Privacy Policy
Effective 5 October 2026
Summary. Pond is designed so that the passwords, photos, files and documents you store never reach us. They remain on your device, encrypted, under your sole control. We do not operate accounts, advertising, analytics or tracking. The only personal data we may handle is what you choose to send us: a support email, or a post or vote on our community board, on the Website or in the App. A few optional features contact other services directly from your device, and this Policy explains exactly what they send.
1. Scope
This Privacy Policy ("Policy") explains how personal data is handled in connection with the Pond application for Apple devices (the "App") and the website at everease.com.co (the "Website"), together the "Services". It does not apply to third-party services, which are governed by their own policies.
2. Who we are
Pond is developed and provided by its independent developer (the "Developer"), who is identified as the seller on Pond's App Store product page. "Everease" is a brand name used by the Developer; it is not a company or other separate legal entity. In this Policy, "we", "us" and "our" mean the Developer and any successor to which the Services are transferred. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), the Developer is the controller of the limited personal data described in Section 4. Contact: support@everease.com.co.
3. Content you store in the App
Passwords, passkeys, verification codes, payment card details, identity documents, photos, videos, files, notes and any other information you add to the App ("User Content") are stored locally on your device, encrypted, and in any backup files you choose to create. The App excludes its vaults from your device's iCloud Backup, so no copy of User Content is placed on a server by the App. User Content is not transmitted to us. We do not have access to it and have no technical means to view, copy, recover, decrypt, modify or delete it. Accordingly, we do not act as a controller or processor of User Content.
Features that analyse your photos, such as recognising faces, text and objects for search, run on your device using Apple's frameworks. Their results stay on your device.
4. Personal data we process
The App collects no personal data for us in the ordinary course of use. It has no account system and contains no advertising, analytics or tracking software, and we do not track you across apps or websites owned by other companies. The only personal data we may process arises in the limited situations described below.
When you contact us
If you write to us, we receive your email address, your name if you include it, and whatever you choose to tell us. When you use Write to us or Report a problem in the App, the message is prepared with the App's version and your iOS version, and Report a problem also adds your device model; you can see and edit all of it before sending. We use this information only to read and answer your message and to provide support. Our legal basis under the GDPR is our legitimate interest in responding to you and, where your message relates to the App you use, the performance of our agreement with you. We keep correspondence for up to 24 months after our last exchange, unless the law requires us to keep it longer, and then delete it.
When you visit the Website
The Website uses no cookies, analytics or trackers and loads no third-party fonts. The only third-party script is Cloudflare Turnstile, which loads on the community page only when you start writing a post (see below). Like any website, it is delivered by a hosting provider, Cloudflare, which processes technical connection data such as your IP address, browser type and the pages requested, in order to deliver the Website and protect it from abuse. Cloudflare acts as our service provider, and our legal basis is our legitimate interest in operating a secure website. This data is retained according to Cloudflare's standard log retention.
The community board at everease.com.co/pond/community lets anyone suggest features, vote ideas up or down and ask questions, without an account. It is optional, and the App shows the same board.
Posts. When you post, we store what you write, whether it is an idea or a question, whether it was sent from the Website or the App, and the time. Posts are reviewed before they are published, and published posts and our answers are public. Please do not include personal information, passwords or anything from your vault in a post.
Your email address, if you add one. You can add an email address to a post if you'd like a reply. It is optional, it is never published or shown on the board, and we use it only to reply to you about that post. We delete it automatically 12 months after the post, or sooner if you ask or the post is deleted.
Votes. When you first vote a post up or down, your browser or the App creates a random identifier and keeps it in its local storage on your device. We store only a one-way hash of that identifier, together with whether you voted up or down, so that each person's vote counts once. It is not linked to your name, email address or device, and you can remove it by clearing your browser's site data.
Spam protection. To limit spam, we store a one-way hash of your IP address combined with a secret value that changes every day. It lets us limit the number of posts and votes from one connection in a day, and cannot be turned back into your IP address or linked across days. When you start writing, Cloudflare Turnstile checks that you are a person, not a bot. Turnstile processes signals from your browser and device for this purpose only, as described in Cloudflare's Turnstile privacy addendum.
Our legal basis is our legitimate interest in running a useful, spam-free community and in improving Pond; for an email address you add, it is your consent, which you can withdraw at any time by asking us to delete it. Published posts remain until they are removed by us or at your request. Votes are kept while the post they belong to exists. Hashed IP data becomes unlinkable after the day it was created. Because there are no accounts, please include the post's title and the date when asking us to remove something you wrote.
Cookies and browser storage
The Website does not use cookies. Two small items may be kept in your browser's local storage, and only after you act: the anonymous voting identifier described above, when you first vote, and your choice of language, when you pick one from the language menu, so that the Website shows that language next time. Both are strictly necessary to provide what you asked for. Cloudflare Turnstile may process information on your device when you start writing a post, solely to tell people and bots apart. Because no non-essential cookies or trackers are used, we do not show a cookie banner.
Information from Apple
Apple sells and distributes the App. Apple provides us with aggregated sales reports that do not identify you. If you have chosen to share analytics with app developers in your device settings, Apple may also provide anonymous crash and performance reports, which never include User Content. We use this information only to understand sales and to fix defects, based on our legitimate interests.
5. Third-party services used by optional features
Some optional features send requests directly from your device to independent third parties. These third parties act as separate controllers under their own privacy policies. We do not receive these requests or their results.
Password breach check and leak alerts
Breach checking is off until you turn it on. When it checks whether a password has appeared in a known data breach, your device creates a one-way SHA-1 hash of the password and sends only the first five characters of that hash to Have I Been Pwned's Pwned Passwords service. It returns a list of matching hashes, and your device compares them locally. The password itself, the full hash and the account it belongs to never leave your device. While breach checking and leak alerts are on, the App repeats this check from time to time in the background, and may also download Have I Been Pwned's public list of breached websites, which it compares with your saved web addresses on your device. Have I Been Pwned receives your IP address as part of each request. Its practices are described in its privacy policy.
Website logos
To show a logo next to a saved login, your device sends the domain name of the saved web address (for example, example.com) and the App's Brandfetch client identifier to Brandfetch, a company based in Switzerland. The full web address, your username and your password are never sent. Brandfetch receives your IP address as part of the request and states that it may retain server logs, including IP addresses, for up to 90 days for operational and security purposes. The App keeps the logos it receives on your device so that it does not need to request them again. Brandfetch's practices are described in its privacy policy.
Apple Maps
When you view your photos on a map or look at where a photo was taken, the App asks Apple's Maps service for the name of the place at those coordinates. When you look up an address in Keys, the text you type is sent to Apple's Maps search. Apple processes these requests under its own privacy policy.
Our legal basis for these features is our legitimate interest in providing functionality that you choose to use. If you prefer that no such requests are made, keep breach checking off, do not save web addresses with your logins, and do not use the photo map or address search.
6. What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not collect sensitive personal information, biometric data or precise location. Face ID and Touch ID are handled entirely by Apple's operating system; the App receives only a pass or fail result.
- We do not use personal data for automated decision-making or profiling.
7. Disclosure, including to authorities
Community posts that we publish are public by design. Otherwise, we disclose the limited personal data in Section 4 only to service providers acting on our instructions, where required by law or valid legal process, to protect our rights, or in connection with a transfer of the Services. Because User Content is never in our possession, we are unable to provide it to any person, including government agencies, law enforcement authorities or courts.
8. International transfers
Our service providers, including Cloudflare and Apple, may process data outside your country. Where personal data from the EEA or UK is transferred, we rely on adequacy decisions (such as the ones recognising Switzerland and, for certified companies, the EU-U.S. Data Privacy Framework) or on Standard Contractual Clauses and equivalent safeguards.
9. Security
The App encrypts User Content on your device and relies on the security architecture of Apple's operating system together with the passcode and biometric settings you choose. The security of User Content also depends on how you protect your device, your codes, your backup files and their passphrases. No method of storage or transmission is completely secure.
10. Your rights
European Economic Area and United Kingdom
You have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority.
United States
Residents of California and other states with comprehensive privacy laws have the right to know what personal information we collect and how it is used, and to access, correct and delete it. In the preceding twelve months, the categories of personal information we may have collected are identifiers (an email address, if you contacted us or added one to a community post, and the hashed identifiers described in Section 4), device information you chose to send with a message (App version, iOS version and device model), and content you chose to send us or post on the community board. We collect them only for the purposes described in Section 4. We have not sold or shared personal information, and we will not discriminate against you for exercising your rights. Because we do not sell, share or track, there is nothing for a Global Privacy Control or Do Not Track signal to switch off, but we treat such signals as a request to opt out where the law requires it. You may use an authorised agent.
Mexico
Under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares, you have the rights of access, rectification, cancellation and opposition (ARCO rights) and may revoke your consent.
Colombia
Under Law 1581 of 2012 (Habeas Data), you have the right to know, update, rectify and request the deletion of your personal data, to request proof of any authorisation, to be informed of how your data is used, and to file a complaint with the Superintendencia de Industria y Comercio.
To exercise any right, email support@everease.com.co. We may need to verify your request and will respond within the period required by applicable law. Because we hold no User Content, requests will typically concern correspondence you have sent us or posts you have made on the community board.
11. Children
The Services are not directed to children under 13, or under the minimum age required in their country. We do not knowingly collect personal data from children. Children under 13 should not post on the community board. If you believe a child has contacted us or posted, please let us know and we will delete the correspondence or post.
12. Changes to this Policy
We may update this Policy from time to time. The updated version will be posted on this page with a new effective date. Where changes are material, we will provide additional notice, such as in the App's release notes. If this Policy is translated, the English version prevails to the extent permitted by law.