Privacy Policy
Last updated: 8 September 2026
Multi is a personal app for tasks, habits, expenses and training. It is built so that your information stays on your iPhone. There is no Multi account and no Multi server. This page explains exactly what that means, including for the two things new in this version: Apple Health and the Apple Watch app.
The short version. Everything you put into Multi is stored locally on your device. iCloud sync is off unless you deliberately turn it on, and even then your data goes to your own private iCloud, not to us. Voice capture, receipt scanning and Apple Health access are all processed entirely on your device. We run no analytics, no advertising and no tracking of any kind. The one thing that leaves your device is what your subscription requires: Apple and our subscription-management processor need to know whether your purchase is active, covered in full in §9. We do not sell your data, and there is nothing else for us to share, because we never receive it.
1. Who we are
Multi (“the app”, “we”, “us”) is an iPhone application. For any question about this policy or about privacy in the app, email hello@getmulti.app.
2. Where your data lives
All of the content you create in Multi is stored locally on your device, in the app’s own database. That includes your items and their titles and notes, repeat rules, completion history, amounts and currencies, budgets, reminder settings, scanned receipt images, and your app preferences such as the accent theme.
There is no Multi server and no Multi user account. We do not operate a backend that stores your content, so there is no copy of your list held by us, and nothing for us to look at, hand over or lose.
3. iCloud sync (off by default)
Multi can sync your data between your own Apple devices. This is off by default. It only becomes active if you do both of the following:
- Sign in with Apple inside the app, and
- Explicitly enable iCloud sync in the app’s settings.
When sync is enabled, your data is stored in your own private iCloud — specifically, Apple’s CloudKit private database, which belongs to your Apple Account. It is not sent to us, and we cannot read it. Apple’s handling of that data is governed by Apple’s own privacy policy.
If you turn sync off, the app returns to storing your data only on the device.
4. Sign in with Apple
Sign in with Apple exists in Multi for one reason: it is the gate for enabling iCloud sync. It is not required to use the app.
When you sign in, the app stores the Apple user identifier — and your display name, if Apple provides it (Apple supplies this only once, at first sign-in) — on your device, in the iOS Keychain. This identifier is what lets the app associate your data with your private iCloud database. If you use Apple’s “Hide My Email” option, we never see a real email address; in fact we do not receive your email address at all.
5. Voice capture
Multi lets you speak several items at once and turns them into entries. This is processed entirely on your device. The speech recognition and the language model that interprets what you said both run locally on the iPhone. Audio is not uploaded anywhere — not to us, and not to a third-party speech service. Recordings are not retained after the text has been produced. Voice capture currently understands English.
Using it requires your permission for the microphone and for speech recognition. iOS will ask you, and you can withdraw either permission at any time in the iOS Settings app.
6. Receipt scanning and OCR
When you scan a receipt or document for an expense, the image is captured with the camera and the text is read using on-device OCR. The recognition happens locally; nothing is sent to a server for processing. Receipt photos are stored in the app’s local database on your device and are never uploaded to us. If you have enabled iCloud sync, they sync to your own private iCloud along with the rest of your data.
Scanning requires camera access, and choosing an existing image requires photo library access. Both are requested by iOS and can be revoked in the iOS Settings app.
7. Notifications
Reminders, and the alert when you pass a monthly budget, are delivered as local notifications scheduled on your device. They are not push notifications sent from a server, and scheduling them does not transmit anything. Notification permission is requested by iOS and can be turned off at any time.
8. Analytics, tracking and advertising
Multi runs no analytics, no advertising and no tracking of any kind. We do not use cookies, device fingerprinting, an advertising identifier, attribution frameworks or crash-reporting services that profile you. We do not build a profile of you, and there is no cross-app or cross-site tracking. The one piece of third-party code in the app exists solely to run subscriptions, described in full below — it is not an analytics or advertising SDK, and it is configured never to use your purchase data for tracking.
We do not sell your data and we do not share it. There is nothing to sell or share, because content you create in Multi never reaches us.
9. Purchases
Subscriptions and the lifetime purchase are billed through Apple’s App Store. Payment is processed by Apple. We never see your payment details — no card number, no billing address.
To know whether your subscription is active across your devices, the app uses RevenueCat, a subscription-management service, alongside Apple’s own StoreKit. RevenueCat receives your purchase history and an anonymous app-specific identifier — not your name, email or payment details — and uses it solely to tell the app which features you’ve unlocked. This data is not used for advertising or cross-app tracking, and it is the only data that leaves your device for a purpose other than iCloud sync. See RevenueCat’s privacy policy for how they handle it.
10. Apple Health
If you turn on Training, Multi can connect to Apple Health. This is entirely optional and is only ever asked for at the moment it would actually be used — never at launch, and never before you’ve chosen to use Training.
With permission, Multi reads your step count, body weight and active energy so the Train tab can show them without you typing them in twice, and writes the workouts you finish back to Health, so they count in the Fitness app and anywhere else that reads from Health. All of this happens on your device, through Apple’s own HealthKit framework — Health data is never transmitted to us or to any server we operate, and it plays no part in the RevenueCat data described above. Declining Health access, or granting only some of it, leaves every part of the app — Training included — fully working.
11. Apple Watch
The Multi Watch app installs automatically alongside the phone app on a paired Apple Watch. Your training plan and the sessions you log travel between your iPhone and your Watch using Apple’s own WatchConnectivity framework — device to device, over your own devices’ connection, never through a server of ours. If your phone isn’t reachable, the Watch app keeps a cached copy of your plan and syncs what you logged the next time it can.
12. Children
Multi is not directed at children under 13, and we do not knowingly collect information from them. Since the app collects no personal content at all — the one exception, RevenueCat's purchase data, is described above — there is nothing for us to hold about any user regardless of age.
13. Your control over your data
- Export. You can export your data from within the app at any time.
- Delete individual data. Deleting an item in the app deletes it from the device’s database (and from your private iCloud, if sync is enabled).
- Delete everything. Deleting the app from your iPhone deletes the local data it stored. If you had enabled iCloud sync, you can additionally remove the app’s data from your iCloud storage in the iOS Settings app, under your Apple Account → iCloud.
- Turn sync off. Disabling iCloud sync in the app stops further syncing.
- Revoke permissions. Microphone, speech recognition, camera, photos, Apple Health and notifications can each be withdrawn in the iOS Settings app.
Because we hold no personal data about you, requests to access, correct or erase data held by us have nothing to act on. Rights of this kind under laws such as the GDPR and the CCPA are satisfied by the fact that the data is in your hands, on your device, and is exportable and deletable by you.
14. Security
Your data is protected by iOS itself: the app’s storage sits inside the app’s sandbox and benefits from your device’s encryption and passcode. The Apple user identifier is held in the Keychain. If iCloud sync is enabled, data in transit and at rest in iCloud is protected by Apple’s infrastructure. Keeping your device passcode-locked and up to date is the most effective thing you can do to protect it.
15. Changes to this policy
If this policy changes, we will update this page and the “Last updated” date at the top. Substantive changes will also be noted in the app’s release notes.
16. Contact
Privacy questions are welcome at hello@getmulti.app.