Legal
My One Button is a product of K.B.A. Investments Limited, a private limited company registered in England and Wales.
In this policy, "we", "us", and "our" mean K.B.A. Investments Limited trading as My One Button. "You" and "your" mean the person using the My One Button app or website.
K.B.A. Investments Limited is the data controller for personal data processed through My One Button. This means we decide what data is collected and why.
This policy applies to:
If you click a link from our app or website to a third-party service (for example, a payment provider), that service has its own privacy policy. This one only covers what we do.
We collect only what we need to make the product work. Here is everything we collect, broken down by category.
When you sign up, we ask for:
We use this to create your account, send you transactional emails (such as password resets), and identify you when you sign back in.
When you use My One Button, you can capture text or speak into the microphone. Whatever you say or type is your capture.
You can capture from your phone or your Apple Watch. A watch records the clip and hands it to your phone, which then processes it exactly as described below — the watch is another way in, not a different journey. (Wear OS watch support is on our roadmap; we will update this policy when it ships, before it reaches you.)
We store:
We do not store voice audio. When you speak, your audio is sent to a transcription service (see Section 12), converted to text, and discarded. Only the text is kept.
Anything you set up in Settings — your enabled categories, your reminder preferences, your appearance choices, your notification settings — is stored against your account so the app behaves the way you want it to.
To keep the service running safely, we collect:
We do not run advertising trackers or product-analytics trackers, and we do not use this data for advertising or share it with advertisers.
My One Button can connect to Apple Health so your Wins and habit trackers tick themselves from what you have already done. If your phone already knows you walked, you should not have to tell the app.
Nothing is read until you allow it. The first time you open your Wins screen, iOS asks with Apple’s own Health permission screen, and you choose exactly which metrics to allow — or none at all. You can switch the whole connection off (or back on) at any time in Settings → Apple Health inside the app, and change the per-metric grants in the Health app, under Sharing.
If you allow it, the app reads:
This data never leaves your phone. It is read on the device, used on the device to tick a Win or a habit, and that is the end of it. It is never sent to our servers, never sent to any AI, never stored by us, and never sold or shared with anyone. We could not hand it to a third party even if we were asked to, because we never receive it in the first place.
We can only read it. We can never change it. The app asks iOS for read access and nothing else, so it is not capable of adding to, altering or deleting anything in Apple Health — not even by mistake.
Our lawful basis is your consent (UK GDPR Article 6(1)(a)), and because health information is special-category data, we also rely on your explicit consent (Article 9(2)(a)). It carries the strongest protection in law. That is exactly why we have built it this way: opt-in, on-device only, and switched off again in one tap.
Apple Health is an iPhone feature. On Android, no health data is read at all.
My One Button can put your dated items into your phone's calendar, so a reminder you spoke also appears where you already look.
Calendar sync is off by default. You switch it on in Settings, and your phone asks your permission at that moment.
When it is on:
Our lawful basis is your consent, given when you switch sync on and withdrawn when you switch it off.
When you subscribe, we collect:
We do not see or store your card details. Payment is handled by Apple's App Store or Google Play when you subscribe. They send us the result of the transaction; we never touch the card itself.
If you email us at [email protected] or use our in-app feedback form, we keep the conversation so we can help you. This includes your name, email, and the content of the message.
We use your data only for these purposes:
We do not:
We keep your data only as long as we need to.
| Data | Retention period |
|---|---|
| Account data | While your account is active, plus 30 days after you delete it |
| Captures | While your account is active, plus 30 days after you delete it |
| Deleted captures (recoverable) | 30 days, then permanently deleted |
| Archived captures | Indefinitely, until you delete them |
| Payment records | 7 years (UK tax law requirement) |
| Support correspondence | 2 years from the last message |
| Server logs | 90 days |
| Backups | 30 days, rolling |
When you delete your account, we permanently delete all your personal data within 30 days, except for payment records we are legally required to keep.
Under UK GDPR, you have the following rights:
Email [email protected] with the right you want to exercise. We will respond within one calendar month, free of charge. If your request is unusually complex, we may extend by two months and let you know.
We will ask you to verify your identity before acting on a request, to make sure we're not handing your data to someone pretending to be you.
If you believe we have not handled your data properly, please contact us first at [email protected] so we can try to put it right.
If you remain unsatisfied, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator:
We take security seriously. Our practices include:
If you discover a security vulnerability, please report it responsibly to [email protected]. We will work with you in good faith and will not take legal action against good-faith security research.
No system is 100% secure. If a breach affecting your data occurs, we will notify you and the ICO within 72 hours, as UK GDPR requires.
Encrypted. Private. Only you can see what you capture. We don't sell your data. We never will.
The My One Button app uses the minimum number of cookies and storage items needed to make the service work:
We do not use:
We do not run analytics or advertising trackers on the app or the website. Payments happen inside Apple's App Store or Google Play, under their own privacy policies — no payment cookies are set by us.
If we add any non-essential cookies in future, we will ask for your consent before using them.
For more detail, see our Cookie Notice at https://myonebutton.com/cookies.
My One Button is not intended for children under 16. Under UK GDPR, online services for children require special protections, and we have not designed the product to meet those.
If you are under 16, please do not use My One Button. If we find out we've collected data from someone under 16, we will delete it.
If you believe a child under 16 has signed up, please email [email protected] and we will investigate.
UK GDPR requires us to have a lawful reason for processing your data. Here are the bases we rely on:
| What we process | Why | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Account data, captures, settings | To deliver the service you signed up for | Contract performance (Article 6(1)(b)) |
| Device and usage data | To keep the service running and fix bugs | Legitimate interest (Article 6(1)(f)) — running a reliable paid service |
| Payment data | To process subscriptions and meet tax obligations | Contract performance + Legal obligation (Articles 6(1)(b) and 6(1)(c)) |
| Marketing emails (if you opt in) | To send product updates and offers you've agreed to receive | Consent (Article 6(1)(a)) |
| Fraud prevention | To protect the service from abuse | Legitimate interest (Article 6(1)(f)) |
| Apple Health data (only if you allow it) | To fill your Wins and habit trackers from what you have already done — read on your phone, never sent to us (section 3.5) | Consent (Article 6(1)(a)) + explicit consent for special-category health data (Article 9(2)(a)) |
| Device calendar (only if you switch it on) | To show your dated items in your phone’s calendar — we write only to our own “My One Button” calendar (section 3.6) | Consent (Article 6(1)(a)) |
You can withdraw consent at any time for anything based on consent. Withdrawing consent does not affect processing that took place before you withdrew it.
We use a small number of trusted third parties to operate My One Button. Each one only sees the data they need to do their job, under strict contracts that require them to protect it.
| Provider | What they do | What data they see | Where data is processed |
|---|---|---|---|
| Supabase | Database, sign-in, file storage | Account data, captures, settings | EU (Ireland — eu-west-1) |
| Google Cloud (Cloud Run) | Runs our server — every capture passes through it on the way to being sorted | Capture text in transit, request logs (IP, device type) | EU (Belgium — europe-west1) |
| OpenAI (Whisper API) | Voice-to-text transcription | Voice audio (discarded after transcription) | US (with UK/EU data transfer safeguards) |
| Google (Gemini API) | AI sorting — reads the text of a capture and returns which place it belongs in | The text of each capture (no name, no email attached) | US (with UK/EU data transfer safeguards) |
| Anthropic (Claude API) | Standby AI sorter — used only if Google's service is unavailable | The text of each capture (no name, no email attached), only when active | US (with UK/EU data transfer safeguards) |
| Apple App Store / Google Play Billing | Payment processing for subscriptions | Subscription status, transaction data | Managed by Apple / Google |
| GoHighLevel (with Mailgun) | Our website, its forms (contact and feedback), and our emails to you | Name, email, the content of messages you send us | US (with UK/EU data transfer safeguards) |
| Google Workspace | Our team email (your support emails reach us here) | Anything you email us | US (with UK/EU data transfer safeguards) |
| Sentry | Error monitoring (so crashes get fixed) | Technical error reports, scrubbed of personal content — no captures | US (with UK/EU data transfer safeguards) |
Some of our sub-processors are based in the United States. When your data is transferred outside the UK or EU, we rely on:
This means your data has the same legal protections wherever it's processed.
This section is important. We use AI in two specific ways, and we want you to know exactly what happens.
When you speak into the microphone:
OpenAI does not use Whisper API audio to train its models when accessed through the API. We have confirmed this with their published API terms.
After transcription (or when you type), the text of your capture is sent to Google's Gemini API. Gemini reads the text and decides which of the app's places it belongs in — Tasks, Reminders, Shopping List, People, My Notes, or Wins. The result is returned to us and we file the capture accordingly.
If Google's service is ever unavailable, a standby sorter (Anthropic's Claude API) can perform the same task under the same protections. Whichever service does the sorting:
If we ever want to do any of this in the future, we will ask you for explicit consent first. You will always be able to say no.
An AI decides where each capture goes. Nobody at My One Button reads your words in order to file them, and nothing waits for a person to approve it — that is what makes it instant.
It is sometimes wrong. When it is, you move the item wherever you want it, and it stays there. And when the AI is not confident, it does not guess: the capture stays on your home screen as a card for you to place yourself.
This filing decides where a note of yours sits inside the app. It has no effect on your money, your rights, or anything outside My One Button. We are telling you plainly because they are your words, not because the law obliges us to.
We may update this policy from time to time as the product changes or the law changes.
When we make a substantive change (one that affects your rights or how we use your data), we will:
When we make a minor change (typos, clarifications, restructuring), we will update the date at the top but not necessarily email you.
The current version of this policy is always available at https://myonebutton.com/privacy.
For any privacy question, request, or complaint:
We aim to respond to all privacy enquiries within 5 working days, and to formal UK GDPR rights requests within one calendar month as the law requires.
This policy was prepared in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003.
K.B.A. Investments Limited (Companies House number 03345267), trading as My One Button.
Last updated: 25 July 2026. Version 1.3.