Privacy policy
PRESS runs locally on your device. If you explicitly consent, it may send accepted PRESS counts in anonymous batches. Sending is optional and turning it off does not restrict local use.
Data sent
Each upload contains only press_count and a random one-time batch_id UUID for duplicate prevention. The UUID is not used to identify or profile a person or device. PRESS does not send an account, name, email address, advertising ID, device ID, location, contacts, Seed, tap timestamps, coordinates, event history, locale, or share result.
A successful acknowledgement for a consented batch may return a non-identifying world Phase descriptor containing only phase and expires_at. The device uses it locally only to determine QR event eligibility. This response metadata contains no global total, threshold, Seed, event history, or personally identifiable information (PII); it is not additional upload data.
Device and service data
The device stores the local count, unsent batches, Seed, consent state, and event display and input-protection state. Choosing STOP SENDING deletes unsent counts and batches from the device and stops future sending. On the service side, accepted counts are used for the anonymous shared PRESS total and fixed-threshold evaluation. Batch UUIDs are retained for 30 days for retry and duplicate prevention, then removed by scheduled cleanup. Anomaly records are removed after their 48-hour ECHO period. Milestone records and the aggregated total are retained while the service operates. These records are not linked to a person or device, so an individual user’s portion cannot be separated and deleted. After the UUID retention period, PRESS cannot guarantee exact-once processing if the same UUID is reused. PRESS does not export this data to an external archive or automatically forward it to an external service. At service retirement, PRESS stops accepting uploads and deletes the production D1 database. This does not guarantee that already-installed devices stop attempting to send automatically. Provider-managed recovery history or infrastructure copies follow the applicable provider terms; PRESS does not guarantee their complete deletion.
Network metadata
Workers Logs are disabled for this Worker. Cloudflare processes the request IP as a Rate Limiting abuse-control key. It may also process other standard edge and security metadata for delivery and protection, including a sampled IP and an inferred country or region. Depending on the product, Cloudflare documents retention windows of up to 24 hours for sampled security events and up to 7 days for Security Analytics. This is provider-side network metadata, not GPS or device location collected by PRESS. The PRESS application database does not store IP addresses. Retention of provider-managed metadata follows the applicable Cloudflare service terms; these product windows do not guarantee complete deletion of all provider records.
Sharing
Only after you tap SHARE, PRESS passes an image and text to the operating system share sheet. You choose, edit, or cancel the destination. PRESS does not receive the destination or result. Temporary file retention follows the OS and destination app.
Effective date: 2026-09-08