Watchful
Privacy policy

Your data, explained.

Last updated 22 September 2026. This privacy policy applies to Watchful on Android and iOS. Publisher: James Cullimore. Contact: info@jamescullimore.dev.

What stays on your device

The app stores your watchers and preferences locally. OpenAI results and comparison history are limited to the most recent 100 runs per watcher. Gemini keeps only the latest result per watcher in memory for the current app session, including sources and Google Search suggestions. Gemini output is not saved to persistent app storage or reused in later checks, and disappears when the app process closes. Check times, provider names and operational status are retained locally for cooldowns and status display. This version removes Gemini results saved by earlier test builds; device backups are controlled separately by your operating system. On Android, choosing a specific paired device for a car trigger also stores its name and Bluetooth address locally. API keys are stored separately using Android Keystore-backed encryption or the iOS Keychain. We do not operate a watcher-content server or require an app account.

What a check shares

After you choose and authorize a provider, a check sends your watcher instructions, preferences, notification conditions and available search-area context to Google Gemini or OpenAI. OpenAI checks may also include prior OpenAI results for comparison; Gemini checks do not include previous results. Your API key authenticates that request. Local watcher identifiers and Bluetooth device addresses are not included in the AI prompt. There is no automatic switch to another provider.

Each watcher check may send available approximate location information or your saved fallback town to your selected AI provider, even when the watcher is not explicitly location-based. Location permission is optional. Android can use a car connection as a trigger; iOS uses an automation you configure in Shortcuts. The app does not read other apps’ notifications.

AI providers and international processing

Your selected provider processes submitted data under its own terms, including any account-tier-specific retention and data-use rules. The app requests non-stored API interactions where supported; this does not guarantee that the provider retains no data. Google states that Google Search grounding retains prompts, context and output for 30 days. Do not enter information you are not comfortable sharing with that provider. Processing may take place outside your country.

Read Google’s Gemini API terms and OpenAI’s privacy policy.

Purchases

For Pro purchases, Apple or Google processes payment. RevenueCat is initialized when the app starts, including for free users, to retrieve purchase status and available purchase offers. It processes an app-specific customer identifier and the purchase, entitlement and technical information needed for these functions and to verify and restore Pro. We do not receive your payment-card details. Watcher content and API keys are not sent to RevenueCat. Read RevenueCat’s privacy policy.

Notifications and sources

Notifications are generated locally and may appear on your lock screen according to your system settings. Gemini notifications contain a generic check-complete message, not generated findings; the result may have expired if the app session ended before you open it. Opening a source visits that publisher in your browser. The source website receives the usual web request information. Google attribution displayed with Gemini results may load permitted images from external servers.

Controls and deletion

Use “Pause all AI checks” in Settings to stop new watcher checks. A request already sent may finish. This does not prevent provider connection or configuration tests that you manually initiate from sending requests. Remove API keys independently in Settings; this removes the local copy and does not revoke the key in your provider account. Delete a watcher to remove its saved history from this device. Remove each saved key before uninstalling if you want to ensure its removal from iOS Keychain. Local preferences and history may also be affected by your operating system’s backup settings.

Deleting app data does not delete records held by AI providers, app stores, or RevenueCat. Contact the relevant AI provider or app store about its records. For privacy or deletion requests concerning end-user data processed by RevenueCat on our behalf, or publisher-held purchase/support records, contact us at info@jamescullimore.dev.

Purpose, legal basis, and your rights

We use the data necessary to provide requested checks, manage purchases, and answer support requests. Optional personal-data sharing is subject to your permission. Where applicable, processing also relies on performing the requested service and meeting legal obligations. You may request access, correction, deletion, restriction, portability, or object to relevant processing, and may complain to your data-protection authority. Contact us to exercise rights relating to data we control.

Support and this website

If you email support, we receive your email address, any name you provide, your message and attachments, and our replies. For purchase support, this may include transaction references or receipts you choose to send. We use Google Workspace (Gmail) for info@jamescullimore.dev; our address/domain is managed through Squarespace. Do not send API keys, passwords or payment-card details. The app does not include its own analytics or advertising-tracking integration. The RevenueCat data processing described above supports purchase functionality. This app site has no advertising or analytics scripts and uses local assets. The existing website host may process access logs; the publisher’s website privacy notice describes hosting.

Support correspondence and retention

Support messages are stored in our Google Workspace mailbox. An automatic deletion schedule has not yet been configured. You can request deletion of publisher-held support records by emailing info@jamescullimore.dev. We assess whether particular records must be retained for applicable legal obligations or an ongoing dispute and explain any applicable exception. This support-mail process is separate from deleting local app history and from the retention practices of AI providers and app stores.

For support necessary to perform a contract with you or take steps at your request before entering a contract, we rely on Article 6(1)(b) GDPR. For other enquiries, we rely on Article 6(1)(f) GDPR and our legitimate interest in responding to enquiries and resolving service problems. Retention required by a specific legal obligation relies on Article 6(1)(c) GDPR; retaining evidence necessary for legal claims may rely on Article 6(1)(f) GDPR.

Changes

The policy date will be updated when practices change. Material changes to provider sharing will be explained in the app before additional personal data is sent.