Prameya Privacy

OmniCadence — Privacy Policy

Effective date: 7 October 2026
Last updated: 7 October 2026
Publisher: Prameya LLC (“Prameya”, “we”, “us”)
App: OmniCadence (called OmniOps in earlier versions of the app and of this policy) for iPhone, iPad, Mac and Apple Vision Pro, with an Apple Watch app and an Apple TV app — bundle ID legal.prameya.OmniOps (the Apple TV app uses the same ID; the Apple Watch app is legal.prameya.OmniOps.watch)
Contact: admin@prameya.legal
Scope: This policy covers the OmniCadence app on every device listed above, its Home Screen widget and its Apple Watch complications, and nothing else. Prameya's other apps have their own policies, because they work differently. Index: https://prameyallc.github.io/privacy/
Canonical public URL (slug stays omniops): https://prameyallc.github.io/privacy/omniops/

This policy describes the app you actually install — what the shipping build does, not what
an earlier plan for it said. The 23 September 2026 rewrite replaced a version (last updated
26 August 2026) that said the app opened no network connections, used no iCloud, sent no
notifications and had no model download. The app can now do all of those things, as described
below; the 23 September 2026 "what changed" entry in §10 lists each correction.


The short version

The app sends Prameya nothing. There is no account, no sign-in, no analytics SDK, no
advertising SDK, no third-party crash reporter, and no server of ours that receives
anything. The only information about the app that reaches us is what Apple itself reports to
developers (App Store statistics, and crash reports if you share them with developers); see §3.

Your journal lives on your device. The four logs (work, decisions, reflections, habits),
your notes and your review cadences are stored in the app's own storage.

iCloud sync is off until you turn it on. On iPhone, iPad and Mac, More ▸ iCloud ▸
Sync with iCloud keeps a short headline of each journal entry (for example its date, title
and ratings — never its notes) in your own iCloud private database, so your devices show the
same journal. See §4.

A few small iCloud items are kept only while sync is on: which tab and which reading you
last opened, the ID number of an entry you were editing and of the decision you pinned, your
appearance choice and the Home Screen widget's state. They contain no journal text. With sync
off none of them is saved to iCloud, and turning sync off removes them. See §4.

Ask answers on your device. The Ask tab appears only where Apple Intelligence is turned
on and ready, and Apple's on-device model answers first. If it cannot, Ask can use an optional
model that is downloaded from Hugging Face only after you choose to download it. Your
question is never sent to us or to any server.

Notifications only if you turn them on. On a new install, reminders are off until you
switch them on in More.

No health data. No HealthKit. The app does not request HealthKit permission, does
not declare HealthKit entitlements, and contains no HealthKit code.

The app has five tabs (You / Understand / Do / Ask / More); Ask is shown only where Apple
Intelligence can answer. The disclaimer (educational + habit support; not consulting / audit /
certification) is shown on the first-run screen and in More ▸ Legal ▸ Legal & Safety.
Understand reads knowledge packs that ship inside the app. Do writes your journal on the device.


Available tiers

There is one paid upgrade, OmniCadence Pro, sold as three products. Buying any one of
them grants exactly the same Pro — there are no separate feature tiers.

Product Price (US) Billing
OmniCadence Pro Monthly $5.99 Auto-renews monthly. 7-day free trial for accounts Apple offers it to.
OmniCadence Pro Annual $39.99 Auto-renews yearly. 7-day free trial for accounts Apple offers it to.
OmniCadence Pro Lifetime $99.99 One-time purchase. Not a subscription.

Family Sharing is enabled on all three. Subscriptions renew until you cancel (how, on each
device, is under Cancellation and refunds below); Lifetime is a one-time non-consumable.

The journal is free and stays free. Without paying anything you get the knowledge
packs, all four logs unlimited, the streak and consistency score, Ask, iCloud sync and raw
JSON export, with no account and no time limit. Pro adds review analytics, review cadences
you set (weekly, monthly or quarterly, with optional reminders), Markdown export and the
formatted review PDF.

iCloud sync is not a paid feature. It is free, optional and off until you turn it on,
whether or not you buy Pro. If a subscription lapses you keep your own data and can still
export it in its raw form; only the Pro tools stop.

Free vs paid tier data collection

OmniCadence is free to use, and buying Pro does not change what data Prameya collects. Free and Pro alike:

The difference is which tools you get, not data handling. All four logs, the streak and raw JSON export are free; Pro adds review analytics, review cadences, Markdown export and the review PDF. Neither tier sends anything to Prameya.

Cancellation and refunds

Subscriptions are managed entirely through your Apple ID:

StoreKit transaction data

StoreKit on your device tells the app which OmniCadence Pro products your Apple Account owns.
The app asks when it starts, when you bring it to the front, after a purchase or restore, and
whenever StoreKit reports a change such as a renewal or refund. It keeps the answer in memory
only while it runs, and uses it to decide which tools to unlock. The app saves no copy of its
own, does not store a transaction ID, and sends nothing about a purchase to Prameya. Earlier
versions also wrote a small record to the app's settings (whether you had Pro, when a
subscription ran until, and whether a free trial was running). This version neither writes nor
reads it, and it is deleted when you delete the app (on Mac, when you also remove the sandbox
container at ~/Library/Containers/legal.prameya.OmniOps).

If you restore purchases (by tapping "Restore Purchases" in the app), or redeem an offer code,
StoreKit talks to Apple's servers. That communication is between your device and Apple; Prameya
is not involved and sees nothing from it. Apple keeps its own record of the transaction under
Apple's terms.


1. Who publishes this

Prameya LLC. Privacy contact: admin@prameya.legal.


2. What the app stores on your device

The app writes a journal when you log work, a decision, a reflection or a habit, or set up
and complete a review cadence. That journal is one JSON file in a folder of its own inside the
app's Application Support folder. On iPhone, iPad and Apple Vision Pro that journal folder is
protected so its files cannot be read while the device is locked (except a file the app already
had open when it locked). The copy that iCloud sync keeps on the device (in the table below)
is kept in the same folder with the same protection. Earlier versions kept it directly in the
Application Support folder with the system's standard protection, under which it can be read
once the device has been unlocked after starting up; when this version starts, with sync on or
off, it moves that copy into the protected folder and deletes the old one (if the move cannot
finish, it tries again at the next start). On Mac the files sit inside the
sandboxed app container and are covered by FileVault if it is on. There is no Keychain write.

What Where
Your journal: each entry's date and notes; for work, the title, category, minutes spent and impact; for decisions, the title, framework, revisit note and optional dollar note; for reflections, the area and two 1–5 ratings; for habits, the habit type, completion and minutes; plus your review cadences (name, interval, due date, reminder switch) and completed reviews with what you wrote in them On this device, Application Support folder
Sync bookkeeping inside the journal file: when each entry last changed, and which entries were deleted and when On this device, in the journal file (kept whether or not sync is on); a deleted entry's marker is removed after 90 days
Which readings you have opened On this device, next to the journal
The journal as it was just before your last import On this device, next to the journal
Once iCloud sync has been turned on: a copy of the synced headlines, kept by Apple's iCloud sync. Turn Off leaves it; Turn Off and Remove from iCloud or Erase deletes the headlines On this device, in the journal's protected folder, and in your iCloud (see §4)
The decision you pinned from Apple Watch (its ID number) On this device, the app's settings; while iCloud sync is on, also in the iCloud key-value items (§4)
A request from the widget or the "Log a decision" shortcut to open the decision form, until the app opens it On this device, the app's settings
Settings: first-run acknowledgement and the date you gave it, appearance, whether Ask answers are on, your Ask-model choice with the model and version it was given for, which model was selected, whether reminders are on, whether iCloud sync is on (and whether it was ever on, any removal still waiting to reach iCloud, and that the one-time clean-up described in §4 has run); on a device that had an earlier version, the old Pro record it may have left (see "StoreKit transaction data") On this device, the app's settings
A one-time marker that model files left by earlier versions were removed, and how much space that freed On this device, the app's settings
The optional Ask model's files, only if you chose to download them (see §4) On this device, the app's Caches folder, excluded from backups
An export you asked for On this device, a temporary folder excluded from backups, only while More is on screen
Analytics identifiers None

Performance reports. At launch on iPhone, iPad, Mac and Apple Vision Pro the app registers
with Apple's MetricKit. When the operating system delivers its daily performance and diagnostic
summaries, the app writes a short line to the device's own system log: average launch and hang
times, disk writes, and counts of crashes, hangs and abnormal exits. Those numbers are computed by
the operating system and contain nothing you typed. The app does not send them anywhere.

Export and sharing. Every export is a file or text you choose to share (Share sheet).
Export my journal (free) writes the whole journal as JSON — including notes, revisit notes
and dollar notes. Export to Markdown and Export review PDF (Pro) write formatted
copies. Share this decision hands one decision's title, date, framework, revisit note and
notes to the Share sheet as text. Files are written only when you tap, into a temporary folder
of their own that is excluded from backups, and deleted when you leave the More screen; any
left over are cleared the next time More opens. Exports no longer carry the disclaimer text.

Import replaces the on-device journal with a previously exported file you choose (on
iPhone, iPad, Mac and Apple Vision Pro). It asks you to confirm first; the journal it replaces
is kept as the pre-import copy; a file that does not decode as an OmniCadence export is refused
and the journal is not changed. On Mac the app can read only the file you pick.

Backups. If iCloud Backup or a computer backup is on, Apple's device backup may include
the journal and settings. That is Apple's processing, not ours. The downloaded Ask model and
export files are excluded from backups.

Erase. More ▸ Journal ▸ Erase journal and iCloud data, after you confirm, deletes the
journal, the pre-import copy and the list of readings opened on this device; forgets the pinned
decision; removes the iCloud key-value items described in §4; and, if iCloud sync was ever turned
on on this device, deletes the synced headlines from your iCloud and turns sync off here. On Apple
Vision Pro, which does not sync (§4), the same row is titled Erase journal; it deletes what is
on that device and has nothing in iCloud to remove. Another device that still syncs keeps its own
entries and can upload them again. Erase does not delete the downloaded Ask model (More ▸ Ask
model ▸ Remove the downloaded model does) or your settings. Pro is not affected: this version
does not store it, and StoreKit still reports it. Erase also makes the app forget the reading you
last opened and the entry you were editing, so their IDs are not put into later Handoff offers,
and on iPhone it refreshes the Apple Watch's prompts from the now-empty journal and tells the
Watch there is no reading to continue and no pinned decision; an Apple Watch app that is open
drops its Continue row. Because Erase turns sync off on this device, nothing is saved to the
key-value items after it until you turn sync on again. Erase does not reach the app's memory on
your other devices: another device where sync is still on remembers the reading it last opened,
and can save that reading's ID to the key-value items again at its next tab change.

Deleting the app removes the container on iPhone, iPad and Apple Vision Pro, including
the journal and any downloaded model. On Mac the sandbox container under
~/Library/Containers/legal.prameya.OmniOps outlives the app and has to be removed
separately. Deleting the app does not remove anything the app put in your iCloud; use Erase
first if you want that gone.

Apple Watch

The Apple Watch app has three tabs. Now shows three prompts ("Review today's habit",
"Write one line", "Pin last decision"); your iPhone sends their current wording over Apple's
connection between the two devices, and the habit prompt can name today's open habit type.
Tapping Confirm sends the choice to the iPhone, which marks today's habit done (adding a
completed habit entry if there is none for today), adds a work entry titled "Logged block", or
pins your newest decision. Snooze and Decline are sent too and change nothing.

The pinned decision is shown at the top of Do on the iPhone (and, while iCloud sync is on,
on your iPad and Mac) and at the top of the Watch's Now tab, with its title and date.
Unpin on either removes it; deleting the decision or Erase also removes it. The iPhone
keeps the pin (the decision's ID number) in its own settings, and in the iCloud key-value items
only while sync is on. To show it, the iPhone sends the pinned decision's title and date to your
paired Watch over the same connection; the Watch keeps the latest copy it was sent.

Learn shows the knowledge packs that ship with the Watch app and offers to continue the
reading you last opened: the iPhone tells the Watch which one over that connection, whether or
not sync is on, and while a device of yours has sync on the iCloud key-value items can tell it
too (the newer of the two is used). The complications show the title of the reading named in
the iCloud key-value items, which the Watch looks up from that reading's ID in the knowledge
packs it ships, or a fixed prompt ("Log a decision") when those items name no reading it
ships, as while sync is off. The app does not save the title: the Watch looks it up each time the
complication updates, and the key-value items still name the reading only by its ID. More
shows the disclaimer. The Watch keeps no journal, has no Ask and sells nothing.

Apple TV

The Apple TV app shows the knowledge packs that ship with it (Library) and offers to continue
the reading you last opened on another device (Continue), read from the iCloud key-value items,
which exist only while a device of yours has iCloud sync on; otherwise there is nothing to
continue. Its About tab shows the disclaimer (§9), the short version of this policy and the terms
line, as text built into the app; it fetches nothing. It keeps no journal, has no Ask, sends no
notifications and sells nothing.

Home Screen widget and Shortcuts

On iPhone and iPad the Home Screen widget shows a fixed "Log a decision" prompt. The widget and
the "Log a decision" shortcut (Siri and Shortcuts) open the app on the decision form. If the app
is not ready yet, a one-word "open the decision form" note waits in the app's settings on the
device and is cleared when the app opens the form; it is no longer put in iCloud. Neither shows
journal content.

Reminders

More ▸ Reminders ▸ Daily reminders is off on a new install. Turning it on (or turning on a
review cadence's reminder, below) is what asks the system for permission to send notifications
(the system asks only if you have not answered before). If you allow it, the app schedules two
local notifications a day: "Review today's habit" at 8 AM and "Write one line" at 8 PM. Their
Confirm button marks today's habit done or adds a "Logged block" work entry, as on the
Watch; Snooze schedules one reminder again later; a plain tap opens the matching form and
writes nothing. With Pro, each review cadence has its own reminder switch, off by default; a
cadence reminder arrives at 9 AM on its due day and names only the interval ("Weekly review
due"), never your own words. All reminders are scheduled and delivered by the device itself; nothing is sent to
us or to any server. Turning the switch off removes them. An installation that already had
notification permission from an earlier version keeps its reminders on until you turn them off.


3. What the app does not do

Checked against the app's source, entitlements, Info.plist and privacy manifests:

What Apple tells us. Apple gives every developer aggregate App Store statistics (such as
downloads, sales and crash counts) that do not identify you. If you have turned on Share With
App Developers
in your device's Analytics & Improvements settings, Apple may also give us
crash and performance reports from your device through App Store Connect. That is Apple's
system, run under Apple's terms and your setting; the reports contain technical information,
not your journal, and the app's own code does not send them.

PrivacyInfo.xcprivacy declares no tracking, no tracking domains and no collected data types.
It declares two required-reason APIs: the app's own settings (UserDefaults, reason CA92.1) and
the free disk space check made before the optional model download (reason E174.1). The Watch,
Apple TV and widget manifests declare no tracking and no collected data types. Apple's App
Privacy label is answered in App Store Connect under Apple's own definition of "collect"; that
definition does not narrow anything in this policy.


4. Network

Prameya runs no server, and the app never contacts one of ours. Everything that leaves
your device goes to Apple, or — only if you choose the optional model download — to Hugging
Face:

  1. Apple iCloud — only if you turn on sync (iPhone, iPad, Mac): the journal headlines and
    the small key-value items, which the Apple Watch, Apple TV and widget apps can read.
  2. Handoff — where you left off, to your nearby devices signed in to the same Apple Account.
  3. Apple Watch — the connection between your iPhone and your paired Watch: the prompts,
    your choices, the reading you last opened and the pinned decision's title and date.
  4. The App Store — StoreKit purchases, restores, offer codes and subscription checks.
  5. Hugging Face — the optional Ask model download, only after you choose it.
  6. Links you tap — for example "Open the source" under a reading or in Acknowledgements &
    Sources, Support, Email support, the privacy policy, the Terms of Use and Apple's pages. They
    open in your browser or Mail app, which contacts that site the way any visit does.

Apple Intelligence runs on your device; Ask sends nothing to Apple.

The Apple Vision Pro build carries no iCloud entitlement: it does not sync journal headlines
and does not save the key-value items to iCloud.

iCloud sync of journal headlines (optional)

More ▸ iCloud ▸ Sync with iCloud appears on iPhone, iPad and Mac and is off on a new
install. When you turn it on, the app keeps one record per journal entry in your CloudKit
private database
(container iCloud.legal.prameya.OmniOps), under your Apple Account.
Each record holds the entry's ID and which log it belongs to, when it last changed, and only
these fields:

Notes, the decision's revisit note and dollar note, work impact, habit minutes, review cadences
and completed reviews are never synced; they stay on the device where you wrote them. A second
device that syncs adds the headlines to its own journal. When an entry changes on two devices,
the newest change wins; deleting an entry leaves a deletion marker in iCloud (the entry's ID,
which log, and when — no content) so the deletion reaches your other devices. A marker is
removed from iCloud, and from the journal on each device, after 90 days; every device then
ignores it. A device that has not synced for longer than that can bring back an entry deleted
elsewhere more than 90 days earlier, and your devices then all show it again. Changes from
another device arrive when you open the app or bring it to the front.

Turning sync off asks whether to keep the synced copy in iCloud for your other devices
(Turn Off) or delete it (Turn Off and Remove from iCloud). Either way the journal on
the device stays, the key-value items below are removed, and another device that still syncs
can upload its own entries again. Erase (§2) also deletes the synced copy if this device ever turned sync on.
If a removal cannot reach iCloud at once, the app tries again the next time it opens.
Prameya cannot open your private database.

iCloud key-value items

Only while Sync with iCloud is on (iPhone, iPad and Mac), the app keeps a few small items in
Apple's iCloud key-value store for this app, so your devices, your Apple Watch, your Apple TV
and the widget can pick up where you left off:

These items contain no titles, notes or other journal text. Turning sync on saves them at once.
While sync is off none of them is saved, and the app on that device does not read them either.
Turning sync off — Turn Off and Turn Off and Remove from iCloud alike — removes them, and
so does Erase (§2). Earlier versions saved them whether or not sync was on, and also saved the
widget's "open the decision form" note there; the first time this version opens with sync off,
it removes those items once. The Apple Watch, Apple TV and widget apps only read these items.

Handoff

On iPhone, iPad, Mac and Apple Vision Pro the app tells your nearby devices signed in to the
same Apple Account where you left off — the same tab, pack ID and entry ID as above — so they
can offer to continue. This goes through Apple's Handoff.

Ask and the optional on-device model

Ask builds one message from your question, passages from the knowledge packs that match it,
and — on iPhone, iPad, Mac and Apple Vision Pro — the titles of up to four recent work entries
and four recent decisions (titles only; never notes, revisit notes or dollar notes). That message
goes to a language model running on your device:

Nothing is downloaded until you choose Download in Ask or turn on More ▸ Ask model ▸
On-device Ask model. Before offering the download, and again before loading the model, the
app checks that the device has enough free memory; before downloading it checks free disk
space. The download runs only while the app is open (on iPhone, iPad and Apple Vision Pro, only
while it is in front; on a Mac it also continues behind other windows), and while it runs the app
keeps the screen from locking on iPhone, iPad and Apple Vision Pro. It may be downloaded again
if the system clears storage space. The files are the model weights, their index, the tokenizer,
configuration files and a prompt-formatting template, pinned to one version, checked by size and
checksum after the download and by size before each load: data the model reads, not executable
code. A model answer that
fails the app's checks (cut off, garbled or empty) is replaced by the quoted pack passage.
Remove the downloaded model in More ▸ Ask model deletes the files and turns the switch off.
Earlier versions could download a different model (Qwen3 0.6B) from Hugging Face without asking;
this version deletes any of those files on its first launch.

Your questions and Ask's answers are not saved; they disappear when you start a new chat or
close the app.

What Hugging Face sees

Like any file download, the request to Hugging Face (huggingface.co, and the Hugging Face
file-delivery hosts it redirects to) gives Hugging Face the device's IP address and the standard
request headers (which name the app and its version and the operating system version), and names
the model repository, version and files requested. Hugging Face handles it under its own terms.
It does not include your question, your journal or anything you type. We do not receive that
request.


5. Knowledge packs

The knowledge packs on Understand ship inside the app (and inside the Apple Watch and Apple TV
apps). The app does not fetch packs from the network. When you open a reading on Understand
(iPhone, iPad, Mac and Apple Vision Pro), the app records it on this device (§2) and treats it as
the reading you last opened. It offers that reading through Handoff to your nearby devices signed
in to the same Apple Account (iPhone, iPad, Mac and Apple Vision Pro, whether or not sync is on;
§4). While Sync with iCloud is on (iPhone, iPad and Mac), it keeps the reading's ID in the iCloud
key-value items (§4). On iPhone, it tells your paired Apple Watch (§2). What opening a reading
adds to each of these is the pack's ID, never journal text. Opening a reading on Apple Watch or
Apple TV records nothing. Tapping Open the source under a reading opens the cited public page
in your browser.


6. Monetization

OmniCadence presents a StoreKit paywall for OmniCadence Pro (monthly $5.99, annual $39.99,
lifetime $99.99 — see "Available tiers" above). Apple processes the purchase. The app sends
nothing about a purchase to Prameya, and we receive no name, no email, no payment card details
and no Apple Account credentials.

The journal is free. All four logs, the streak, Ask, iCloud sync and raw JSON export cost
nothing and have no time limit.


7. Children

OmniCadence is a general-audience adult tool. It is not in the Kids Category. We do not
knowingly collect information from anyone, including children: the app sends us nothing.


8. Your rights

There is nothing of yours on our servers to access, correct, or delete. What the app keeps is
on your device and, if you use iCloud, in your own iCloud under your Apple Account. More ▸
Journal ▸ Erase journal and iCloud data deletes both (§2; on Apple Vision Pro, which keeps
nothing in iCloud, the row is Erase journal); deleting the app removes the on-device
container (on Mac, also remove the sandbox container named above) but not your iCloud copy.
Rights under the GDPR / UK GDPR / CCPA-CPRA are exercised on your device; if you believe we
hold something, write to the contact in §1.

Apple (StoreKit, iCloud, Handoff) and Hugging Face (the optional model download) receive what
§4 describes under their own terms; we do not direct them and do not receive it.

We do not respond to “Do Not Track” signals, because we do not track.


9. What this app is not

The first-run screen and More ▸ Legal ▸ Legal & Safety render, verbatim:

EDUCATIONAL + HABIT SUPPORT ONLY. NOT MEDICAL/FINANCIAL/LEGAL ADVICE. Does not replace
licensed pros. On-device models limited. Consult pros.

OmniCadence supports your own process journal and improvement habits. It is not management
consulting, not an audit, and not a conformity assessment or certification against any
management-system standard.

OmniCadence does not ship aggregated avoided-cost totals or unsourced occupational /
ROI figures.


10. Changes

We update this policy when the app changes what it stores or what leaves the device — where
we can, before the change ships — and change the dates at the top. Each revision is described
here.

7 October 2026 — what changed. With an app update, and corrections:

Later on 27 September 2026 — what changed. Corrections for the Mac and Apple TV; nothing the
app does with your data changed:

27 September 2026 — what changed. With an app update:

24 September 2026 — what changed. With an app update:

23 September 2026 — what changed. This policy was rewritten to match the app as it is now:

The app still sends nothing to Prameya: no analytics, no account, and no server of ours. Earlier
versions of this policy remain in the public repository that publishes these pages:
https://github.com/prameyallc/privacy.

Terms of Use

The terms governing OmniCadence, including subscription auto-renewal and cancellation, and dispute resolution:

OmniCadence Terms of Use