ettúi

Privacy Policy.

Effective: 2026-05-19

This is the privacy policy for ettúi — the iOS app, the iOS Safari Share Extension, and the website at ettui.com. It explains what data we collect, why, and what your rights are.

We tried to make this short and direct. If anything is unclear, email us at privacy@ettui.com.

Who we are

Ettúi is operated by Henrik Wiberg. You can reach us at privacy@ettui.com.

What ettúi is for

Ettúi lets you save highlights and bookmarks of articles you read on the web. When you select text on a page and share it through the iOS Share sheet (or paste it into the website), we save the highlight, the page's URL, and a couple of details about the page (its title and favicon) so you can find and revisit it later. If you save without selecting any text, we treat the entry as a bookmark.

Data we collect

Account data

When you create a full account (iOS or web):

  • Email address — used to sign in and recover your account.
  • Password — stored hashed using a one-way cryptographic function. We never see your plain-text password.

When you start a demo (guest) account:

  • No email or password is collected.
  • A randomly generated session token identifies your demo account so the items you save can be associated with it.

The content you save

For each highlight or bookmark:

  • The highlighted text (or empty, for bookmarks).
  • The URL of the source page.
  • The page title, extracted from the page when you share it.
  • The favicon URL of the source.
  • Tags you add to the item.
  • Timestamps of when items were created.

Technical and operational data

iOS app and Share Extension:

  • Your account token is stored on-device in the iOS Keychain (encrypted by iOS and protected by your device passcode/biometrics). The Share Extension reads it from a shared keychain group so it can save quotes on your behalf.
  • The Share Extension reads, from the page you share from: the page's URL, its title (document.title), the selected text (if any), and the favicon link declared in the page's HTML. Nothing else is read from the page.
  • Our backend logs network requests (IP address, timestamps, request paths, app version) for operations and security. These are retained for up to 30 days.
  • iOS-level diagnostics (crash reports) are handled by Apple and only reach us if you've opted into sharing crash data with developers via your iOS settings. They don't contain the content of your saved items.

Website (ettui.com):

  • The website uses cookies to keep you signed in (a session cookie) and to remember simple preferences. You can disable cookies in your browser settings, but the site won't be able to keep you signed in.
  • The website uses Google Analytics to understand how visitors use the site (which pages are visited, basic device information, approximate geographic region). Google Analytics sets its own cookies and collects an anonymized identifier. We use this only in aggregate; we do not use it to identify individual users. See "Analytics" below for how to opt out.
  • Our web server logs the standard fields any web service records: browser type, language preference, referring site, request path, IP address, and timestamps. These are retained for up to 30 days.

The iOS app does not use cookies and does not use Google Analytics or any other third-party analytics service.

What we don't collect

  • We don't run ads, and we don't share data with advertising networks.
  • We don't sell your data.
  • We don't track you across other apps or websites (beyond the aggregate site analytics described above).
  • We don't access your contacts, location, photos, microphone, or camera.

Analytics (website only)

The ettui.com website uses Google Analytics to measure aggregate usage. Google may set cookies and collect a randomized identifier, your IP address (truncated where possible), and standard browser metadata. Google processes this data on our behalf as described in Google's Privacy Policy.

You can opt out of Google Analytics in two ways:

  • Install Google's official Analytics Opt-out Browser Add-on.
  • Decline analytics cookies via our cookie banner the first time you visit the site.

The iOS app uses neither Google Analytics nor any other analytics SDK.

How long we keep your data

  • Full accounts — until you delete them. You can delete your account from inside the iOS app (in the filter panel, long-press your email address) or from the equivalent option on the website. Deletion is permanent and removes all your saved quotes, bookmarks, and tags.
  • Demo (guest) accounts — automatically deleted after 48 hours of inactivity.
  • Backups — deleted account data may persist in encrypted database backups for up to 7 days before being permanently purged.
  • Server logs — retained for up to 30 days for operational and security purposes.

Who has access to your data

  • You.
  • Us (the people who operate ettúi) — for support and operations, and only when necessary.
  • Heroku (Salesforce, Inc.) — hosts our backend infrastructure. Your data is stored on Heroku's US-based servers. Heroku acts as a sub-processor and is bound by its own privacy and security obligations.
  • Google LLC — provides analytics for the ettui.com website via Google Analytics (website only; not used in the iOS app). Google processes aggregate usage data on US-based infrastructure under standard data-processing terms.
  • Apple — for App Store crash reports, if and only if you've opted into sharing them via iOS Settings. These don't contain the content of your saved items.

We don't share your data with anyone else, except where required by law (e.g. valid legal process) or where strictly necessary to protect ourselves or our users from imminent harm.

International data transfers

Our backend runs on Heroku's US-based infrastructure. If you're in the European Economic Area, the United Kingdom, or Switzerland, your personal data will be transferred to and stored in the United States. We rely on standard contractual clauses (or equivalent legal mechanisms) with our sub-processors to provide appropriate safeguards for these transfers.

Your rights

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correct — ask us to fix information that's wrong.
  • Delete — delete your account and all associated data, at any time, from within the iOS app or the website. Deletion is permanent.
  • Export — request a JSON export of your saved content. Email privacy@ettui.com to request one.
  • Object — object to or restrict our processing of your data.

If you're in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, email privacy@ettui.com.

Cookies (website only)

The website uses cookies for:

  • Session cookie (strictly necessary) — keeps you signed in. This cookie is always set and does not require your consent.
  • Analytics cookie (optional) — we use Google Analytics to understand how people use the site in aggregate. This cookie is only set if you choose to accept it via the cookie banner. You can change your preference at any time from the cookie preferences link in the footer.

We don't use advertising or cross-site tracking cookies. You can disable all cookies in your browser settings; the site will continue to load but will not be able to keep you signed in.

The iOS app does not use cookies.

Children

Ettúi is not intended for anyone under 13 years old (or under 16 if you reside in the European Economic Area). We do not knowingly collect personal data from anyone in those age groups. If you believe a child has provided us with personal data, email us at privacy@ettui.com and we'll delete it.

Security

  • Passwords are hashed using a one-way cryptographic function before storage.
  • All network traffic between the iOS app, the website, and our backend uses HTTPS.
  • On iOS, your account token is stored in the system Keychain, which is encrypted and protected by your device passcode and biometrics.
  • Our backend (Heroku) provides standard infrastructure-level security and isolation.

No system is perfectly secure, but we take reasonable, industry-standard steps to protect your data.

Changes to this policy

If we make material changes, we'll update the Effective date at the top of this page and notify you in-app (or by email, if you have a full account) before the change takes effect. Continued use of ettúi after the effective date constitutes acceptance of the updated policy.

Contact

Privacy questions, data requests, or complaints: privacy@ettui.com

We use Google Analytics to understand how people use Ettúi in aggregate. No personal data is sold or shared with advertisers. Learn more.