T ToneFlush

Privacy Policy

Last updated 3 August 2026 · applies to the ToneFlush app for iPhone, version 1.0.0 and later.

The short version

ToneFlush has no account system, no advertising and no tracking, and it never asks who you are. Everything you can see in the app — your settings, your speaker-test readings — stays on your iPhone.

Two things do leave it, and neither carries your name, your email address or anything that identifies you:

What ToneFlush stores on your device

ToneFlush keeps no history of the cleaning sessions you run. Nothing is written down about what played, when, or how it went.

This information is written to the app's own storage on your device. It is not transmitted anywhere, is not backed by any server, and is removed when you delete the app.

What ToneFlush does not collect

Microphone

The Speaker Test measures your speakers by playing a ladder of tones out of each one and listening to what comes back. That needs the microphone, and ToneFlush asks for it the first time you tap Run test — never at launch, and never as a condition of using anything else in the app. If you decline, every other feature continues to work.

While a measurement runs, audio is held in memory just long enough to be measured — about a second at a time — and is then overwritten by the audio that follows. It is never written to a file, never kept after the run, and never sent anywhere. ToneFlush has no code that could upload it.

What is kept is the result: a small set of decibel figures and ratios for your last two measurements, stored on your iPhone so the app can show you what changed between them. No audio is part of that.

No audio and no measurement ever leaves your iPhone, so nothing in this section appears in ToneFlush's App Store privacy label. Using a sensor on your device is not the same as collecting data from it.

Network use

Every feature of ToneFlush works offline. Tones are generated on your device; there are no downloads, no remote configuration and no content to fetch.

The network is used for two things. Around the purchase — showing the price, buying, and restoring what you already own — which goes to Apple and to RevenueCat. And to send the anonymous usage events described below, which go to PostHog. Events are batched and sent in the background; nothing in the app waits for them, and everything keeps working if they never arrive.

Purchases

ToneFlush's unlock is sold through the App Store as a single one-time purchase. Nothing renews. Billing and refunds are handled by Apple through your Apple Account, under Apple's privacy policy rather than this one. ToneFlush never sees your card, your Apple Account or any other payment information.

Whether the unlock is active is decided by RevenueCat, a purchase-management service. When you buy or restore, RevenueCat receives:

It does not receive your name, your email address, your Apple Account, or anything about how you use ToneFlush. There is no account to create and no profile built from this. RevenueCat processes it on our behalf; its own privacy policy is at revenuecat.com/privacy.

Usage analytics

ToneFlush sends a small set of anonymous events to PostHog, a product analytics service, so we can see how the app is actually used — which is the only way to find out that a step is confusing, that a screen is never reached, or that a session is failing for a reason nobody reported.

What is sent. Only events the app deliberately reports, each with a short list of properties. Roughly:

What is not sent. No audio, ever — see Microphone. No recording or replay of the screen. No crash reports. Nothing that identifies you, because the app does not know anything that would.

Who the events belong to. A random identifier that PostHog generates for this installation of the app, and nothing else. It is not your Apple Account, not the advertising identifier and not derived from your device; a second phone running ToneFlush is simply a second, unconnected identifier. That same random identifier is also stored on the RevenueCat purchase record, so that a purchase can be understood alongside the events that led to it.

What the network itself reveals. Like any HTTPS request, an event carries your app version, device model, operating-system version, language and IP address. PostHog turns the IP address into an approximate location — country and region — so we can see which storefronts the app is used in.

Where it goes. PostHog Cloud, in the United States, processing the data on our behalf. Its privacy policy is at posthog.com/privacy.

Children

ToneFlush is not directed at children and asks no one — including children — for personal details.

Third parties

Two, and no others:

There is no advertising network, no attribution service, no crash reporter and no data broker. Nothing collected by either service is combined with data about you from anybody else's apps or websites, which is why ToneFlush's App Store listing says it does not track you.

Your rights

Nothing that identifies you is collected, so there is no account to access, correct or export. Everything the app stores is on your device and under your control: delete the app to remove it all at once.

Deleting the app also ends the analytics: the random identifier the events were grouped under is stored with the app's own data and goes with it. A fresh install is a new identifier with nothing joining it to the old one.

If you want the purchase record held by RevenueCat, or the events held by PostHog, deleted, write to the address below. For the purchase record, include your App Store purchase receipt; deleting it also removes our ability to restore your unlock, so it cannot be undone. For the analytics events, we can delete the identifier they are grouped under and everything attached to it.

Contact

If you have a question about this policy, write to info.trimtone@gmail.com.

Changes to this policy

If this policy changes, the updated version will be published on this page with a new date at the top. Material changes will also be noted in the app's release notes.