Spoons — Privacy Policy
Contact: privacy@getspoons.app or hello@getspoons.app
Estimated read time: 25 minutes. If you need this document in a different format, see Section 18 or email privacy@getspoons.app.
Read This First (Quick Summary)
In the app: We collect nothing. Your energy logs live on your phone. Even if we wanted to see them, we couldn't. There's no servers.
The app never connects to our servers — since we have none. The only network activity is Apple/Google verifying your subscription status and delivering updates. Your energy logs and personal data are never transmitted to us or anyone else.
On the website: Your email (only if you join the waitlist or contact us). That's it.
No tracking/marketing cookies, but one essential security cookie. No sneaky data collection. No tracking which pages you visit. This keeps the website fast and secure.
We never: Sell your data. Show ads. Track you.
You can:
- Unsubscribe: Click the link at the bottom of any email
- Delete logs: Uninstall the app (logs only exist on your device)
- Delete support emails: Email privacy@getspoons.app
Questions? privacy@getspoons.app
A note on “we” vs “I”: Spoons is built and run by one person. This policy uses “we” because that’s legal convention, but in sections about personal commitments (like the no-sale promise and privacy architecture), I use “I” because those are my promises. Same person either way.
The summary above covers everything that matters. The sections below are the legal details — read them when you have the energy.
1) Overview
There is no data to handle. It never reaches us and we never see it.
In the app: Zero data collection. Your energy logs live on your device. The app updates through app stores but has no internet connection.
The Spoons app has no servers and makes zero network connections. It does not transmit your logs or any data to us or anyone.
The only network activity related to Spoons happens at the operating system level: Apple or Google verifying your subscription status and delivering app updates. This happens outside the app itself — Spoons never initiates, controls, or sees any of it.
Your logs stay on your device. Even if your phone is offline for months, the app continues to work normally. Subscription verification happens the next time your device connects — your existing logs and functionality are never interrupted by being offline.
Even if we wanted to see your logs, we couldn't. They don't exist on our end.
On the website: No tracking or marketing cookies. Only an essential security cookie for site security (see Section 10).
Just your email for two things:
- Waitlist (one email when Spoons launches)
- Optional blog updates (energy tracking tips, burnout posts - you choose, unsubscribe anytime)
Nothing else.
If you don’t join the waitlist or email us, we don’t know who you are and we don’t collect personal information from you directly.
Our website hosting/security providers may process limited technical data (like IP address) to keep the site secure, but we don’t use it to identify you.
Why trust us? This policy is a commitment we operate under. If we ever change what we collect or how we use it, we will update this policy and provide advance notice.
Our website already has 0 trackers and will always remain that way. We built the app with no server connection. Adding one would mean changing the fundamental architecture of the app — something we will never do.
You don’t have to take our word for it. The app makes no network connections. If you’re technically inclined, you can verify this yourself using your phone’s network monitor or any packet inspection tool. We invite the scrutiny.
Why We Built It This Way
Other autism apps have neurotypical assumptions baked in from day one. Sketchy data collection. Strongly steered toward parents of autistic children. NOTHING for us.
We built Spoons specifically for autistic adults to be completely reliable and work at 0 energy.
Our first decisions:
Offline-first. No server connection. Your data never leaves your device.
Usable in under 8 seconds. To avoid meltdowns and shutdowns like most apps cause. We minimized friction entirely to work in crisis moments at 0 energy.
We didn't want to promise to protect your data.
We wanted to make it impossible for us to access it in the first place.
Other apps make vague promises about data protection. Professional wording disguised as lying.
This isn't a promise. It's how we built the app.
A note on discretion: We understand that in some regions and situations, an autism-related app on your phone could create real risk — from stigma, from employers, from family. Spoons has no visible branding in your notification tray (because we don’t send notifications), no account that links to your identity, and no data that leaves your device. Your use of Spoons is between you and your phone. That’s by design, not by accident.
2) What Data We Collect
A) In the Spoons App: ZERO
We do NOT collect:
- ❌ Your energy logs (stored on your device only)
- ❌ Your location
- ❌ Your device information
- ❌ Your usage patterns
- ❌ Any analytics or tracking data
- ❌ Any personal information whatsoever
Note: Apple and Google may collect their own app analytics (crash reports, session data) through their platforms. We have disabled all optional analytics collection in both App Store Connect and Google Play Console. We don’t request, access, or use any platform-level analytics data. See their privacy policies for details on what they collect independently.
The app works completely offline and never sends data to any server. As stated in Section 1: even if we wanted to access your logs, we couldn’t. They don’t exist on our end.
B) On the Website: Minimal
1. Email Address (Optional - Waitlist Only)
When: If you sign up for the waitlist at getspoons.app
What we collect:
- Your email address
- Signup date
How we use it:
- Send app launch announcement
- Send optional weekly updates (unsubscribe anytime)
Where stored: Mailchimp
Mailchimp is owned by Intuit. We use Mailchimp exclusively for waitlist emails. Your email address in Mailchimp is not connected to any other Intuit products, services, or advertising platforms. We do not share additional data with Intuit beyond what Mailchimp requires to deliver your emails.
Your control: Click "unsubscribe" in any email or email privacy@getspoons.app
2. Search Performance Data (Google Search Console)
When: People find your site through Google search
What we collect: We use Google Search Console to see how people find us through search. This shows us:
- Search queries that led to our site ("autism energy tracker," "autism energy," etc.)
- Which pages got clicked from search results
- Country where the searcher is located (general, not precise)
- Device type used for the search (desktop/mobile/tablet)
- Search performance (how many times we appeared in search, how many clicked)
This is search performance data, not on-site tracking. We see what brought you here from Google, but not what you do once you're on the site.
What we DON'T collect:❌ Your IP address (We have disabled Webflow’s built-in site analytics. Our hosting provider can serve the website without tracking your behavior on it.)❌ Which pages you visit once you're on the site❌ How long you stay❌ Where you click❌ Personal identifiers❌ Cross-site tracking❌ Advertising profiles
How we use it: See which blog posts attract search traffic. Understand what autistic adults are searching for. That's it.
Provider: Google Search Console - Privacy: https://policies.google.com/privacy
3. Support Emails
When: If you email hello@getspoons.app or privacy@getspoons.app
What we collect:
- Your email address
- Your message content
- Any attachments (e.g., screenshots)
How we use it:
- Answer your question
- Fix bugs
- Improve the app
Where stored: Proton Mail (privacy-focused email provider with encryption at rest)
Retention: 2 years, then deleted
4. Subscription Data: We Don't Collect It
Billing is handled by Apple and Google:
- They collect your payment info (we never see it)
- They process payments. We never see your name, payment method, or any personal details. We only know that transactions occurred—not who made them.
- We never know your name, payment method, or personal details
For Apple's privacy: https://www.apple.com/legal/privacy/
For Google's privacy: https://policies.google.com/privacy
5. Diagnosis Fund Page
The Spoons Diagnosis Fund helps autistic adults access funded diagnosis assessments. The program is not yet accepting
applications. When it launches in 2027, this section will be updated with the full operational details. Here is the framework we are building to.
What we will collect from applicants:
- Full legal name (required for bank/tax compliance when paying clinics)
- Email address (for communication about their application only)
- Country of residence
- Official clinic quote or invoice upload (must show: clinic letterhead,
patient name, service description, total cost)
- Clinic contact information (website, phone, email)
- Consent to contact the clinic to verify the invoice
- Financial need statement (self-attestation in early years; spot-check 10% with documentation Year 3+)
- Spot-checks may request a brief confirmation of financial situation (such as a signed statement or proof of government assistance enrollment) but will never require bank statements, tax returns, pay stubs, or detailed financial records. We know what invasive means-testing feels like. We won’t replicate it.
What we will NEVER collect from applicants:
❌ Full medical history
❌ Therapy records
❌ Detailed financial records (bank statements, tax returns)
❌ Information about family members
❌ Anything beyond what is needed to verify the clinic,
confirm eligibility, and process payment
How applicant data will be handled:
- Stored in Airtable (encrypted at rest, SOC 2 compliant)
- Access limited to Omari only (Year 1-4), then Omari + Executive Director (Year 5+)
- Partner organizations see only: applicant first name, region, application status, and diagnosis outcome (confirmed/pending)
- Partners never see financial need statements
- Clinic receives only: applicant name and Spoons as payer
- Retention: Approved applications — data retained for 3 years after diagnosis completion for impact reporting, then deleted. Denied or withdrawn applications — data deleted within 90 days of denial or withdrawal, unless the applicant requests immediate deletion. We do not retain records of people we couldn’t help longer than necessary to close their case.
- Applicants can request deletion at any time by emailing privacy@getspoons.app
Diagnosis outcome data (anonymized and aggregated) may be
shared in annual impact reports. No individual applicant will be identifiable in public reporting without their explicit written consent.
Important: This does not change the app. The Spoons app still collects zero data and your logs still stay on your device.
3) How We Use Your Data
Email addresses:
- Send waitlist updates
- Respond to support requests
- That's it. Nothing else.
Website analytics:
- Understand which blog posts are helpful
- Fix broken pages
- That's it. Nothing else.
We will NEVER:
- ❌ Sell your data
- ❌ Use it for advertising
- ❌Share it (except with service providers: Mailchimp for emails, Proton for support emails, Webflow for website hosting)
- ❌ Track you across other sites
- ❌ Build profiles about you
4) How We Protect Your Data
In the app:
- Your logs never leave your device = nothing to protect on our end
- No account = no password to steal
- No cloud = no cloud breaches
Email & website:
- HTTPS encryption
- Mailchimp security (SOC 2 compliant, encryption at rest — details: mailchimp.com/about/security)
- Proton Mail encryption (end-to-end for support emails)
What we can't protect:
- Exports you share with others
- Device backups (iCloud/Google Drive) if you enable them
- Your device security (Use a passcode!)
5) Third-Party Services
App Distribution:
- Apple App Store - Privacy: https://www.apple.com/legal/privacy/
- Google Play - Privacy: https://policies.google.com/privacy
Website & Email:
- Webflow (website hosting) - Privacy: https://webflow.com/legal/privacy
- Mailchimp (waitlist emails) - Privacy: https://www.intuit.com/privacy/statement/
- Proton Mail (support emails) - Privacy: https://proton.me/legal/privacy
- Make/Integromat (automation tool that routes your contact form submission to our email list — it only processes the email address you voluntarily provide) - Privacy: https://www.make.com/en/privacy
Diagnosis Fund Operations (launching 2027):
Bill.com (invoice processing and clinic payments) - Privacy: https://www.bill.com/privacy
Wise (international payments to clinics) - Privacy: https://wise.com/us/legal/global-privacy-statement
These services process clinic payment information only. They never see applicant energy logs, medical details, or financial need statements. They see only what is required to send payment to a clinic: clinic name, invoice amount, and payment destination.
Important: These services have their own policies. None of them see your energy logs (because we don't have them either).
6) Your Rights
Access Your Data
Email privacy@getspoons.app with subject: "Data Access Request"
We'll send you:
- Your email address (if you joined waitlist)
- Signup date
- Any support emails you sent
Note: Your energy logs aren't included because we don't have them
Delete Your Data
No rush. Email whenever you have the energy.
- Waitlist email: Click "unsubscribe" in any email
- Everything: Email privacy@getspoons.app with subject: "Delete My Data"
- Energy logs: Uninstall the app (they're only on your device)
Timeline: Within 30 days (usually 48 hours)
If you request deletion, we delete your data immediately — we don’t wait for the standard retention period to expire. The retention periods in Section 7 are maximums for when you DON’T request deletion, not minimums we force you to wait through.
ADD THIS (new text)
If you shared something in a support email you didn’t mean to:
We understand that burnout, meltdowns, and executive function crashes can affect what you write. If you emailed us during a difficult moment and shared more personal information than you intended, email privacy@getspoons.app and ask us to delete specific emails or portions of emails. We’ll do it, no questions asked. We only retain what’s necessary to resolve your technical issue — nothing more.
Export Your Data
- Energy logs: Tap "Export" in app settings (CSV). You can import this file into Spoons on a new device — your history transfers with you.
- Email data: Email privacy@getspoons.app with subject: "Export My Data"
Regional Rights
European Union / UK (GDPR):
- Right to access, delete, export (covered above)
- Right to rectification (correct inaccurate data — email us if your details need updating)
- Right to restrict processing: You can unsubscribe from waitlist emails anytime. If you never joined the waitlist or contacted support, we have no data about you to process.
- Right to complain to your Data Protection Authority
California (CCPA):
- Right to know, delete, opt-out of sale
- We don't sell data, so opt-out is automatic
Brazil (LGPD):
- Right to access, correct, delete
- Right to data portability
Australia:
- Right to access and correct
- Complaint to OAIC if needed
India (DPDP Act 2023):
Right to access and correct personal data
- Right to access and correct personal data
- Right to erasure
- Right to grievance redressal
Contact privacy@getspoons.app to exercise these rights
All regions:
- Your local privacy laws apply
- Email privacy@getspoons.app to exercise rights
7) Data Retention
Energy logs: On your device until you delete them
Email addresses: Until you unsubscribe (then deleted within 30 days)
Support emails: 2 years, then deleted
Website analytics: Aggregate data for 2 years (no personal identifiers)
If Spoons closes or I'm unable to run it:
I will never sell Spoons to another company. This is a personal commitment, not a business strategy.
To make this commitment durable beyond personal intent:
- Per our Terms of Service (Section 18), any successor operator must honor these privacy commitments and the 40% diagnosis funding allocation — or the app code is released to the autistic community under the AGPL-3.0 license. This is an enforcement mechanism, not a suggestion
- Beginning in 2031–2032, diagnosis funding operations will transfer to a 501(c)(3) foundation with board oversight, ensuring the mission and privacy architecture survive independently of any individual
- Partner organizations will receive advance notice of any ownership or structural changes and retain the right to terminate partnerships and require data deletion
If Spoons must shut down (death, disability, or unforeseen circumstances):
- All waitlist subscribers will be emailed 90 days before shutdown (or as soon as legally possible)
- All email addresses will be permanently deleted within 30 days
- Support emails will be deleted within 30 days
- There will be no voluntary sale or acquisition. In extreme circumstances (estate transfer, legal incapacity), any successor must honor these exact privacy commitments — or all data is deleted before transfer and the code is released under AGPL-3.0. See our Terms of Service, Section 18, for the full enforcement mechanism.
- To be clear: Spoons will never be sold, acquired, merged, or transferred as a business transaction. The only circumstances under which another person would operate Spoons are those in which I am no longer able to — and even then, only under the exact same commitments described in these documents."
- Your energy logs remain unaffected (they're only on your device)
In the unlikely event of forced company transfer (legal judgment, estate issues):
- The acquiring party must agree to these exact privacy terms OR all data is deleted before transfer
- You will be notified with maximum advance notice
- You will have the option to delete your email from our list before any transfer
This is legally binding.
Diagnosis Fund data if Spoons shuts down:
- In-progress applications: All active applications will be completed before shutdown. No applicant will be abandoned mid-process. If completion is impossible, applicants will be connected directly with the partner organization to continue through an alternative path.
- Completed records: Anonymized impact data (number of diagnoses funded, regions served) may be transferred to the successor foundation or published in a final transparency report. All personally identifiable applicant data will be deleted within 90 days of shutdown.
- Lifetime access codes: All issued codes remain valid. If the app code is released under AGPL-3.0, community maintainers will receive the validation system to honor existing codes.
- Partner organization records: Partners will be notified 90 days in advance and given the option to request immediate deletion of shared data.
8) Children's Privacy
Age requirement: 13+
We don't knowingly collect data from children under 13.
If we discover a child under 13 provided data, we delete it immediately.
Parents: Contact privacy@getspoons.app if concerned.
Note: Spoons is designed for autistic adults, but teens 13+ can use it. If you're under 18, consider discussing the app with a parent or trusted adult - they might find it helpful to understand how your energy works.
9) International Users
Where your data lives:
- Energy logs: On your device (whatever country you're in)
- Emails: Mailchimp servers (US and EU regions)
- Support: Proton servers (Switzerland - strong privacy laws)
If you're in the EU or UK:
- Full GDPR protections apply to your data
- Data transfers to US use Standard Contractual Clauses (legal agreements requiring US companies to protect your data at EU standards)
- You can request your data stay in EU-only servers - email privacy@getspoons.app
If you're in another country:
- Your local privacy laws apply
- Email privacy@getspoons.app to exercise your rights under your local laws
10) Cookies
In the app: No cookies
On website: One essential security cookie only.
We use Cloudflare (through Webflow hosting) for site security and DDoS protection. Cloudflare sets one cookie:
_cfuvid (Cloudflare security cookie)
- Purpose: Bot detection, rate limiting, DDoS protection
- Duration: Session only (deleted when you close your browser)
- Tracking: Does NOT track you or identify you personally
- Essential: Required for site security
We will never add:❌ Advertising cookies❌ Tracking cookies❌ Analytics cookies❌ Third-party marketing cookies
You can disable cookies in browser settings, but site security features may not work properly.
11) Security Incidents
If there's a data breach:
- We investigate immediately
- Notify you within 72 hours
- Report to authorities as required
- Fix the issue
How we notify:
- Website announcement on getspoons.app (primary notification method)
- Email to waitlist subscribers and anyone who contacted support
Note: We cannot directly notify app users because Spoons has no accounts and no communication channel. Website announcements are the only way to reach the broader user base.
Good news: Your energy logs are on your device, so they can't be breached through our systems.
Partner organization notification:
If a breach involves data shared through the Diagnosis Fund or partnership operations, affected partner organizations will be notified directly within 24 hours via their designated contact email. This notification will include:
- What data was affected
- Which referrals or applicants may be impacted
- What we are doing to contain and resolve the breach
- Recommended actions for the partner organization
This 24-hour direct notification is separate from and faster than public disclosure. Partner organizations need time to notify their own community members and fulfill their own privacy obligations.
If a partner organization experiences a breach:
Our partnership agreements require partner organizations to notify us within 24 hours of discovering any breach that may affect shared data (referral information, applicant details). Upon receiving such notification, we will:
- Assess which Spoons applicants may be affected
- Notify affected applicants within 48 hours of our learning about the breach
- Work with the partner to contain the impact
- Document the incident in our annual transparency report
Partner organizations are independent data controllers. We cannot prevent breaches on their systems, but we can ensure you’re informed quickly if one affects your data.
12) Law Enforcement & Legal Requests
If law enforcement or a government authority requests user data:
For app data: We cannot provide energy logs, usage patterns, or any in-app data because we don’t have access to it. The app has no servers and we have no way to retrieve data from your device. We will clearly explain this to any requesting authority.
For email/website data: If we receive a valid legal order (subpoena, court order, or equivalent in your jurisdiction) for waitlist emails or support correspondence, we will:
- Carefully review the request for legal validity
- Narrow our response to the minimum data legally required
- Notify you that a request was made, unless we are legally prohibited from doing so
- Never voluntarily provide data beyond what is legally compelled
We have received zero law enforcement requests to date. If this changes, we will publish an annual transparency note in our transparency reports (beginning 2027) stating the number of requests received and how they were handled, without identifying affected users.
We will never build backdoors, add surveillance capabilities, or modify the app architecture in response to government pressure. If any authority attempts to compel this, we will disclose it publicly and, if necessary, trigger the open-source release described in our Terms of Service (Section 18).
13) Our Privacy Commitment
The Spoons app will ALWAYS be:
✅ Zero-data-collection in the app
✅ Your logs stay on your device only
✅ No tracking or analytics in the app
✅ No ads, ever
We will NEVER:
❌ Add cloud syncing that reads your logs without your explicit, opt-in consent (and even then, we'll never have access to unencrypted data)
❌ Add analytics that track your usage in the app
❌ Add ads or third-party trackers to the app
❌ Sell your data or share it with third parties (except service providers listed in Section 5)
❌ Change the app architecture to collect data
What this means:
App updates may add features, but will never change our zero-knowledge architecture. We will never have access to your energy logs.
Your energy logs stay on your device only. We don’t collect them, so we can’t access them or give them to anyone.
If we ever consider changes to this core commitment:
- We will announce 90 days in advance
- Explain exactly why and what would change
- Give you the option to export all data and stay on the old version
- Never force you to update to a version that violates this commitment
A note about phone permissions: Future iOS or Android updates may change what permissions apps must declare. If your phone ever shows a network permission request for Spoons, that’s your operating system’s requirement, not ours. The app itself will never use network access to transmit your data. If an OS update fundamentally conflicts with our zero-data architecture, we will communicate clearly about what changed, why, and what it means for your privacy.
This is my personal commitment.
Your privacy is sacred. We will never break your trust.
14) Changes to This Policy
Current version: 1.0 (April 2, 2026)
We may update this policy.
When we do:
- New effective date at top
- Material changes will be announced on our website (getspoons.app)
Material changes:
- Collecting new data types
- New third-party sharing
- Reducing privacy rights
Your options:
- Stop using the service before changes take effect
- Export your data and unsubscribe from emails at any time
- Cancel your subscription at any time
We’ll always give you enough time and information to make an informed choice about staying.
Changelog:
All material changes to this policy will be logged here with the date, version number, and a plain-language summary of what changed.
We won't assume silence means agreement. But legally, continued use after changes take effect constitutes acceptance. We'd rather you actively choose to stay.
15) Contact
Privacy questions:
Response time: Within 30 days (usually 48 hours)
Mailing address: 4030 Wake Forest Road Ste 349, Raleigh, NC 27609
16) What Makes Spoons Privacy-First
✅ Zero data collection in the app
✅ Your logs never leave your device
✅ No tracking, no ads, no analytics in app
✅ Minimal website data (email + basic stats only)
✅ Export anytime, delete anytime
✅ No data selling, ever
Privacy isn't a feature - it's how we built Spoons.
17) Partner Organization Data
This section is primarily relevant to partner organizations, but we include it here because you deserve to see how we handle data at every level — not just your data, but the data that flows through the systems your subscription supports.
Spoons partners with autism advocacy organizations to operate the Diagnosis Fund. This section covers how we handle data shared between Spoons and partner organizations.
What partner organizations share with us:
- Referral information (applicant name, region, eligibility notes)
- Staff contact details (name, email, role)
- Organizational information (programs, capacity, clinic relationships)
What we share with partner organizations:
- Applicant first name and application status
- Diagnosis outcome (confirmed/pending/declined)
- Aggregated impact data (number of diagnoses funded, regional totals)
- We never share applicant financial need statements with partners
How partner data is handled:
- Stored separately from user data in dedicated partnership records
- Access limited to Omari (Year 1–4), then Omari + Executive Director (Year 5+)
- Encrypted at rest (Airtable SOC 2 + Proton Mail)
- Staff contact details retained for duration of partnership + 90 days after termination
- Referral data follows same retention as applicant data (3 years post-diagnosis, then deleted)
If a partnership ends:
- Partner is notified 90 days before any data changes
- Active referrals are completed (no applicant is abandoned mid-process)
- Partner staff contact details deleted within 90 days
- Referral data retained per standard retention schedule (applicants consented to Spoons, not to the partner)
- Partner can request immediate deletion of their organizational data by emailing privacy@getspoons.app
Partner organizations are independent data controllers for their own records. We do not access, manage, or take responsibility for how partners store information on their end. Each partnership agreement specifies mutual data handling obligations.
Diagnosis fund and partnership inquiries: parternships@getspoons.app
18) Data Processing Agreements
This section is for partner organizations reviewing our data handling practices, but we keep it visible because transparency means showing the full picture.
Partner organizations that share personal data with Spoons may require a Data Processing Agreement (DPA). We support this.
Our standard DPA covers:
- Purpose and scope of data processing
- Types of personal data shared
- Duration of processing
- Security measures in place
- Sub-processor list (Airtable, Proton Mail, Bill.com, Wise)
- Breach notification obligations (72-hour direct notification to partner — see Section 11)
- Data deletion upon partnership termination
- Audit rights
For UK/EU partners: Our DPA includes Standard Contractual Clauses (SCCs) for international data transfers and complies with GDPR Article 28 requirements.
To request our DPA template or discuss data processing terms: privacy@getspoons.app
We will execute a DPA with any partner organization before any personal data is shared. No exceptions.
10) Accessibility
This privacy policy is designed for cognitive accessibility.
What we've done:
- Plain language throughout (no unnecessary legal jargon)
- Summary section at top covering all key points
- Clear section headings for navigation
- Screen-reader compatible formatting
- High-contrast text on getspoons.app (WCAG 2.2 AA, AAA where possible — consistent with our Terms of Service, Section 10)
Alternative formats available on request:
- Large print version
- Plain text version (no formatting)
- Audio summary
If any part of this policy is unclear or difficult to process, email privacy@getspoons.app and we will explain it in whatever format works for you.
Accessibility is not an add-on. It is how we write everything.