This policy describes how the iOS app published by ninjahawk under the bundle identifier com.ninjahawk.slot03 handles information. It is written against the app's own source code; every claim below can be checked in it.
The short version
There is no account, there is no server of ours, and there is no analytics. The app runs entirely on your phone. It reads public posts by calling public APIs directly from the device, ranks them on the device, and stores what it remembers on the device.
No account is required
You can install the app and read the whole feed without signing in or giving us anything. Signing in is optional and exists only so you can post, reply, like, repost, bookmark or follow using your own account on another service (Mastodon or Bluesky). There is no account with us to create, and we hold no user record of any kind.
We do not operate a server
The app has no backend. Nothing is proxied through us, nothing about what you read is sent to us, and no copy of your feed, your interests or your activity exists anywhere but on your phone.
Services your device contacts directly
Because the app talks to these services straight from your phone, each one receives your device's IP address and the requests it makes, exactly as a web browser visiting the same site would. Their own privacy policies apply to what they do with that. We receive none of it.
- Mastodon instances — public timelines, trends, hashtag timelines, threads, profiles and search, across roughly sixteen public servers.
- Bluesky —
public.api.bsky.app,api.bsky.appandbsky.socialfor public feeds, posts and, if you sign in, your session. - Hacker News —
hacker-news.firebaseio.com(Firebase) andhn.algolia.com(Algolia) for stories and comments. - Lemmy and PieFed instances — public community feeds and comments.
- Lobsters —
lobste.rspublic JSON. - 4chan —
a.4cdn.organdi.4cdn.orgfor public thread JSON and images. - Steam —
store.steampowered.comandcdn.cloudflare.steamstatic.comfor public game reviews and artwork. - Imgur —
api.imgur.comandi.imgur.com. Inert unless a client id is configured in the build. - ESPN, Kalshi and CoinGecko — public scores, event odds and coin prices for the cards on the Explore screen.
- Link hosts — when a post links out, the app fetches that page's own metadata and preview image to draw the card, and loads pictures and video from wherever the post's network hosts them (including image CDNs such as
i.ytimg.com). Opening a link in the app's built-in browser loads that site normally, so the site sees your device as any browser visit would.
We do not add identifiers to these requests, and none of them carries an account of ours, because there isn't one.
What is stored, and where
On your device only
All of the following is kept in the app's own storage (UserDefaults and files inside the app's container). It is never uploaded.
- Seen-post ledger — which posts you have already been shown, so the feed does not repeat itself.
- Interest profile — a set of weights the ranker learns from what you open, linger on, save or skip.
- Saved posts and bookmarks, and the list of posts kept for offline reading (the "reserve"), stored as files in the app's Application Support directory.
- Image cache — pictures the feed has loaded, held in memory and in the system URL cache on the device.
- Mutes and blocks — the accounts, domains and words you have muted or blocked. Stored locally on purpose, so they work when you are signed out.
- Reports you have filed — the post's address, the account's handle, the category you picked and any note, listed under Settings, Your reports.
- Settings — appearance, notification preferences, sensitive-content settings, pinned tabs, reserve size.
- Usage counters — a per-day count of opens, refreshes and posts opened, used by the app for its own decisions (such as when to ask about notifications). It has nowhere to go and is not sent anywhere.
In the iOS Keychain
If you sign in, that service's access token is stored in the Keychain, one entry per account, and is used only to talk to that service. Signing out deletes it. You can also revoke the app's access from the service's own settings at any time (on Mastodon, Preferences, Account, Authorized apps; on Bluesky, Settings, App passwords, which is the only way the app signs in there).
How to clear it
Blocks, mutes and reports are managed in Settings; the interest profile has a Reset button there; the offline reserve is emptied by setting its size to Off; signing out removes the tokens. Deleting the app removes everything above, including the Keychain entries, because none of it exists anywhere else.
Notifications
Notifications, if you turn them on, are scheduled locally by the app from content it has already fetched. There is no push server, no device token is sent anywhere, and we have no way to send you a message.
No analytics, no ads, no tracking
The app contains no analytics SDK, no advertising SDK, no attribution or crash-reporting SDK, and no tracking of any kind. It does not use the advertising identifier and does not ask for App Tracking Transparency permission, because it has nothing to track with.
Third-party code. The app has exactly one third-party dependency: Nuke, an open-source image loading library. It loads and caches pictures on the device and sends nothing anywhere on its own. There are no others.
Apple's App Store Connect reports aggregate, anonymised install and session figures to developers for any app on the store; that comes from Apple and is controlled by your device's own "Share With App Developers" analytics setting, not by this app.
Reports and moderation
Filing a report hides the post for you immediately and records it on your device. It also opens your mail app with a pre-filled message — the post's address, the account, the network, the reason you chose and the app version — addressed to the support address below. That message is sent by you, from your mail account, and is read by a person; reports are acted on within 24 hours. If you are signed in to Mastodon and the post is a Mastodon post, the report is additionally sent to that account's own server through Mastodon's public reports API, so a moderator there can act on the account.
Children
The app is not directed at children. It shows unmoderated public posts from open social networks and is rated accordingly on the App Store. We do not knowingly collect information from anyone, of any age, because the app collects nothing.
Changes
If this policy changes, the new version replaces this page and the date at the top changes with it.
Contact
Questions about this policy, or anything else: icebreakermint10@gmail.com