This policy applies to the LetMeBe iOS/iPadOS app, its supporting API, and letmebe.app. It is a privacy notice, not a request for blanket consent. We rely on the legal bases described below and ask for consent only where the law requires it.
Scope and controller
LetMeBe (“we”, “us”, or “our”) operates the app and determines why and how the app-specific personal data described in this policy is processed. LetMeBe is therefore the controller for that processing.
Privacy questions and requests may be sent to [email protected]. Apple, your chosen DNS resolver, and some other services described below determine their own purposes for certain data and may act as independent controllers under their own notices.
No LetMeBe account is required. We generally do not ask for your name, postal address, phone number, or email address to use the app. An email address is processed if you contact support.
What we do not do
- We do not sell personal data or share it for cross-context behavioural advertising.
- We do not use advertising identifiers or third-party advertising SDKs.
- We do not use Mixpanel, Google Analytics, Firebase Analytics, HubSpot, Smartlook, or New Relic in the current app or these legal pages.
- We do not read the content of web pages, messages, calls, photos, contacts, or files.
- We do not use app data to make decisions that produce legal or similarly significant effects about you.
LetMeBe is a DNS-filtering tool, not an anonymity service. A DNS resolver and network intermediaries may still see network metadata as described below.
Data we process
| Category | Examples | Where it is processed |
|---|---|---|
| Installation and user identifiers | A device-scoped UUID and the same pseudonymous identifier used as the RevenueCat App User ID. | Device, RevenueCat, and LetMeBe’s API. The API hashes the device UUID before storing DNS evidence. |
| Purchase information | Products, entitlement and subscription status, purchase dates, receipt or transaction-validation metadata, and original app version. | Apple and RevenueCat. LetMeBe does not receive your full payment-card details. |
| DNS and network observations | Selected app ID, observed domain, DNS answer IP, record type, observation time, catalog version, and matched rule or match type. | Device and, for catalog intelligence, LetMeBe’s Cloudflare-hosted API. |
| Configuration and app state | Selected apps, custom domains or IP rules, blocklists, DNS provider choice, VPN status, and observation-session state. | Primarily on your device and in the app’s shared container used by its network extension. |
| Technical and request data | IP address, request time, URL path, user agent, country, device/OS/app version, locale, performance and security metadata. | Cloudflare edge services and, where applicable, RevenueCat. |
| Support communications | Your email address, message, attachments, diagnostic details you choose to provide, and our response. | Our email and support systems. |
A pseudonymous identifier is still personal data when it can distinguish the same installation or be combined with other information. We treat it accordingly.
What stays on your device
LetMeBe creates an Apple Network Extension configuration and locally evaluates DNS requests against the apps and rules you choose. The selected-app list, custom blocking rules, blocking state, and related configuration are stored in the app or its shared app-group container so the app and its network extension can work together.
Blocked DNS requests are handled locally. Allowed DNS requests are forwarded over HTTPS to the resolver you select. Available presets currently include Cloudflare, Cloudflare Family, Quad9, AdGuard DNS, Google Public DNS, NextDNS, and a custom DNS-over-HTTPS endpoint. Your selected resolver can receive the DNS queries needed to answer them, together with ordinary network metadata such as your source IP address.
iOS controls device backups, keychain behaviour, and deletion of app containers. Removing the app normally removes its app-container configuration, but system-level VPN entries, backups, or identifiers stored by iOS may require separate removal through iOS settings.
DNS intelligence and catalog improvement
LetMeBe can submit small batches of DNS observations to improve the accuracy of its shared app-blocking catalog. Each observation can contain the selected app’s catalog ID, a domain requested while that app was being observed, the returned IP address, DNS record type, observation time, matching information, and the catalog version.
The request URL contains a device-scoped UUID. Before DNS evidence is stored, the API transforms that UUID into a one-way, namespace-specific SHA-256 pseudonym. We use the observations to validate candidate domain and IP rules, detect shared infrastructure, review safety, prevent duplicate evidence, and publish more accurate catalog releases.
Important distinction: domain names can reveal which online services an app contacts and are treated as browsing-history data in Apple’s privacy manifest. The feature does not capture page contents, messages, or the contents of network packets.
Purchases and subscriptions
Apple processes App Store payments. RevenueCat receives a pseudonymous App User ID, Apple receipt or transaction information, product and entitlement status, purchase dates, and limited device/app metadata so it can validate purchases, prevent fraud, restore access, and provide subscription analytics.
LetMeBe configures RevenueCat with a device-scoped UUID rather than your name or email address. RevenueCat’s customer history can therefore associate purchases and entitlement activity with the same pseudonymous installation. Apple and RevenueCat process data under their own applicable privacy terms.
Website and support data
Website
The site is delivered through Cloudflare. Cloudflare processes ordinary edge request and security data, which can include IP address, user agent, request time, host, path, protocol, status code, country, and threat signals. Cloudflare Web Analytics also provides aggregated page, referrer, browser, device, country, and performance metrics. We do not add advertising trackers or marketing cookies to these legal pages.
Support
If you email us, we process the contact details and contents you provide to answer the request, troubleshoot, maintain records, and protect legal rights. Please send only the diagnostic information needed for your issue and do not include passwords, payment-card numbers, or unrelated sensitive information.
Purposes and legal bases
| Purpose | Typical data | EEA/UK legal basis |
|---|---|---|
| Provide app functionality | Configuration, DNS requests, app selection, identifiers, entitlement status. | Performance of our contract or steps you request before entering it. |
| Validate and restore purchases | App User ID, receipt and transaction data, products and entitlements. | Contract; legitimate interests in fraud prevention and accurate access control. |
| Improve the blocking catalog | Pseudonymous DNS observations and review records. | Legitimate interests in improving accuracy and reliability, balanced against your rights. |
| Secure and operate services | IP address, request logs, threat signals, diagnostics. | Legitimate interests in security, abuse prevention, troubleshooting, and service integrity. |
| Respond to support | Email, message, attachments, diagnostics. | Contract or legitimate interests; consent where you voluntarily provide optional information. |
| Comply with law | Transaction, request, and correspondence records as legally required. | Legal obligation and establishment, exercise, or defence of legal claims. |
Where processing relies on legitimate interests, you may object as described below. Where we rely on consent, you may withdraw it at any time without affecting prior lawful processing.
Who receives data
- Apple, for App Store distribution, payments, refunds, Family Sharing, and transaction records. See Apple’s Privacy Policy.
- RevenueCat, for subscription infrastructure, validation, entitlements, fraud prevention, and subscription analytics. See RevenueCat’s Privacy Policy.
- Cloudflare, for website delivery, API hosting, database services, security, logs, and privacy-oriented web analytics. See Cloudflare’s Privacy Policy.
- Your selected DNS resolver, which receives allowed DNS queries. Its terms and privacy policy apply. For a custom resolver, you are responsible for assessing its operator.
- Professional advisers, authorities, and transaction parties, only when reasonably necessary for legal compliance, claims, audits, security, or a lawful business reorganisation, subject to appropriate safeguards.
We require processors to handle personal data only for contracted purposes and with appropriate confidentiality, security, deletion, and transfer protections.
How long data is kept
| Data | Typical retention |
|---|---|
| Local app configuration | Until you change or remove it, delete the app data, or iOS removes it; system VPN entries and backups may follow separate iOS controls. |
| Raw DNS intelligence evidence | The production pruning policy is configured to remove observation events, aggregates, and IP evidence after 30 days. |
| Intelligence review and audit records | The production pruning policy is configured to remove completed queue items, IP activity, and review runs after 90 days. |
| Derived catalog rules | May be retained until superseded or removed because they are part of the shared blocking catalog and are not published with a device identifier. |
| Purchase and entitlement records | For the subscription lifecycle and afterwards as needed for restoration, fraud prevention, accounting, disputes, or vendor/legal retention requirements. |
| Support communications | For as long as needed to resolve the request and then for reasonable recordkeeping or legal limitation periods. |
| Cloudflare Web Analytics | Cloudflare states that unsampled beacon data is kept for 7 days and then aggregated; edge/security logs follow the applicable Cloudflare service settings and retention. |
Retention can be extended where needed to investigate abuse, preserve evidence, comply with law, or establish, exercise, or defend legal claims. Backups may persist for a limited additional period before secure rotation.
International transfers
Apple, RevenueCat, Cloudflare, and DNS providers may process data outside the European Economic Area, including in the United States. Where required, transfers are protected by an adequacy decision, the European Commission’s Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, or another legally recognised mechanism, together with supplementary safeguards where appropriate.
You may contact us for information about safeguards relevant to your data, subject to protection of confidential and security-sensitive information.
Your privacy rights
Depending on your location and subject to legal conditions and exceptions, you may have the right to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also have the right to appeal a refusal and to opt out of sale, targeted advertising, or qualifying profiling. LetMeBe does not sell data or use it for targeted advertising.
- Email [email protected] and describe your request.
- Include the pseudonymous app/device identifier only if requested and available, so we can locate records without collecting unnecessary identity documents.
- We may ask for proportionate verification and will respond within the period required by applicable law.
EEA residents may complain to their local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP). Exercising a right is free unless a request is manifestly unfounded or excessive as defined by law.
Children
LetMeBe is not designed to solicit personal data from children or to create child profiles. A parent or legal guardian should supervise use by anyone who cannot independently enter a binding agreement or exercise privacy choices under applicable law. If you believe a child has provided personal data outside the limited technical processing described here, contact us so we can assess and delete it where required.
Security and automated processing
We use measures appropriate to the nature and risk of the processing, including encrypted transport, access controls, pseudonymisation of stored device identifiers for DNS intelligence, limited retention, and service-provider safeguards. No system is perfectly secure, and we cannot guarantee that loss, misuse, or unauthorised access will never occur.
Automated checks can group, validate, or reject DNS observations and help create catalog-review candidates. Those processes affect technical blocking rules, not legal rights, credit, employment, insurance, or any other decision producing legal or similarly significant effects about a person.
Changes and contact
We may update this policy when the app, vendors, or law changes. We will publish the revised version here, update the effective date, and provide additional notice in the app or App Store when a change is material and the law requires it. A previous policy remains relevant to processing that occurred while it was effective.
Questions, rights requests, or privacy concerns can be sent to the LetMeBe privacy contact.
[email protected]