Privacy Policy
Effective September 18, 2026
Lest is a voice-first reminder app for iPhone. This policy says what leaves your phone, where it goes, and why. It is written to be read.
The short version
- Your reminders, transcripts, places and contacts live on your iPhone. There is no account and no sign-up.
- When you capture a reminder, the words you said are sent to our server and on to Anthropic's Claude to be turned into a structured reminder. They are processed, not stored, and not used to train AI models.
- Your precise location never leaves the phone. Place reminders use iOS's own on-device region monitoring. Only your city is sent with a capture, so "the store" can mean the one near you.
- We keep counts of how many requests each anonymous install makes, so nobody can run up our bills, and a handful of onboarding milestones so we can tell whether the app is working for new users.
- Payments are handled by Apple. We never see your card. RevenueCat manages the subscription on our behalf.
What stays on your phone
Reminder text and transcripts, times and places, resolved coordinates and addresses, the places you have picked for "the gym" or "work", your home location, completion history, and your settings. All of it is stored in a local database on the device. Contacts are read on the device only when you send a reminder to a friend, to match the name you said; the contact list is never uploaded.
Speech is transcribed by iOS on the device. Audio is never sent anywhere.
What is sent when you capture a reminder
To turn "buy hot sauce at Walmart" into a reminder that fires at Walmart, the app sends our server (hosted by Supabase) the following:
- the transcript text of what you said;
- the current time and your time zone;
- your current city, as a name, never coordinates;
- a random anonymous identifier for this install (your Support ID).
Our server sends the transcript, time and city to Anthropic, whose Claude models parse it. Anthropic states that API inputs are not used to train its models and are retained only as long as needed to provide the service.
When a reminder depends on an event ("the next Texans game", "the Severance finale"), the app looks the time up. For sports teams the query goes to ESPN's public schedule service and contains only the team name. For anything else the query is sent to Anthropic with permission to run a web search. Found answers are cached on our server, keyed by the question, not by you, so the next person asking gets the answer without a new search.
What we keep on our server
- Usage counts. For each anonymous identifier, the number of requests and lookups per day. This is how we cap costs and stop abuse. Kept for up to 12 months.
- Decisions. When a lookup is refused or fails, we record that it happened, the query, and a short excerpt of the transcript, against the anonymous identifier, so support can see why. Kept for up to 12 months.
- Subscription status. Whether the anonymous identifier has an active trial or subscription, from RevenueCat, cached for a few hours at a time.
- Onboarding milestones. Events such as "first open", "paywall shown" and "trial started", against a separate random install identifier, so we can tell whether new users get through setup. No reminder content is included. Kept for up to 12 months.
None of this is linked to your name, email, Apple ID or phone number. We do not sell data, run ads, or share data with data brokers.
Purchases
Subscriptions are sold through Apple's App Store. Apple processes the payment and holds your billing details; we never see them. RevenueCat receives the App Store transaction and your anonymous identifier to manage the subscription and tell the app whether it is active. Refunds are handled by Apple.
Crash reports
If crash reporting is enabled in a build, crashes are sent to Sentry with the device model, iOS version, app version and the technical trace. Reminder content is not included.
Permissions
- Location, Always: so place reminders can fire when the app is closed. Region monitoring is done by iOS on the device.
- Microphone and speech recognition: to capture reminders by voice. Transcription happens on the device.
- Notifications: to deliver reminders.
- Contacts: only when you send a reminder to a friend, to match a name.
Every permission can be changed in iOS Settings at any time.
Children
Lest is not directed at children under 13 and we do not knowingly collect information from them.
Your choices
"Reset everything" in Settings deletes all app data on the phone and abandons the anonymous identifier; a new one is created on the next launch. To have the server-side records tied to a Support ID deleted, email trev@holliday.io with the ID.
Changes
When this policy changes, the effective date at the top changes with it, and this page is always the current version. For a change that matters, we will also say so in the app's release notes.