Security & Trust

Your captures stay yours

Last updated: 25 July 2026  ·  Version 1.3

You're putting your whole brain into one place. We take that seriously.

This page explains how we protect your data, how AI sees your captures, what we will never do, and how you stay in control. No marketing fluff. Just the facts.

How your data is protected

  • Encrypted in transit — every connection between your device and our servers uses TLS (HTTPS). Nothing travels in the clear.
  • Encrypted at rest — data stored in our database is encrypted using AES-256.
  • Stored on Supabase in the EU (Ireland) — your captures live in the EU.
  • Row-level security — our database is configured so your captures are only accessible to your account. This is enforced at the database layer itself, not just in the app.
  • Automatic encrypted backups — daily, retained for 30 days, so your data survives a failure on our end.
  • Access controls — only authorised team members can access production systems, with logging on every access, and two-factor authentication required.
  • UK GDPR compliant — we follow UK and EU data protection law.
  • 72-hour breach notification — if a breach affecting your data ever occurs, we will notify you and the Information Commissioner's Office within 72 hours, as the law requires.

No system is 100% secure, and we won't pretend otherwise. What we promise is the controls above, honestly applied, and honesty with you if anything ever goes wrong.

How AI sees your captures

My One Button uses AI in two specific ways. We want you to know exactly what happens.

Voice transcription

When you speak into the orb:

  1. Your voice audio is sent to OpenAI's Whisper API.
  2. Whisper converts it to text and returns the text to us.
  3. The audio is discarded immediately.
  4. We store only the transcribed text — we keep your words, never your voice.

OpenAI does not use Whisper API audio to train its models when accessed through the API, per their published API terms.

Sorting

After transcription (or when you type), the text of your capture is sent to Google's Gemini API. Gemini reads the text and decides which of the app's places it belongs in — Tasks, Reminders, Shopping List, People, My Notes, or Wins. The result is returned and we file the capture against your account.

If Google's service is ever unavailable, a standby sorter (Anthropic's Claude API) can perform the same task under the same protections. Whichever service does the sorting:

  • No name is attached.
  • No email is attached.
  • No account ID is attached.

The AI sees only the text of the capture itself. Neither Google nor Anthropic uses this data to train their models when accessed through their paid APIs, per their published API terms.

What stays on your phone

Two things My One Button can read never travel to us at all. Both are off until you switch them on.

  • Apple Health. If you connect it, the app reads your activity, sleep and vitals so your Wins and habits tick themselves. It is read on your phone, used on your phone, and never sent to our servers or to any AI. We could not share it if we were asked to — we never receive it. And we ask iOS for read access only, so the app is not capable of changing anything in Apple Health.
  • Your calendar. Turn sync on and your dated items appear in a separate calendar of ours named “My One Button”. We never write into your own calendars, and switching sync off removes ours cleanly.

What we will never do

  • Never sell your data. Not to advertisers. Not to data brokers. Not to anyone.
  • Never share your captures with advertisers.
  • Never read your captures except where strictly necessary to operate the service or where we are legally required to.
  • Never use your captures to train AI models without your explicit consent. If we ever want to do this in future, we will ask you first, and you will always be able to say no.
  • Never touch your card. Payment happens inside Apple's App Store or Google Play — we never see or store your card details.

You stay in control

  • Export everything, anytime. Settings → Data → Export. You get a file with all your captures, settings, and metadata — all of it, however much you have.
  • Delete your account, anytime. Settings → Help & Data → Data. Your data is permanently deleted within 30 days, except for payment records we are legally required to keep.
  • Archived captures are kept indefinitely. Nothing you archive is ever automatically deleted — it stays until you delete it.
  • Deleted captures are recoverable for 30 days. If you change your mind, you have a month to restore. After that, deleted means deleted.
  • Two-tap delete confirmation. Nothing important gets deleted by accident.

Sub-processors

A small number of trusted third parties help us run My One Button. Each one only sees the data they need to do their job, under strict contracts that require them to protect it.

ProviderWhat they doWhere data is processed
SupabaseDatabase, sign-in, file storageEU (Ireland — eu-west-1)
Google Cloud (Cloud Run)Runs our server — every capture passes through it on the way to being sortedEU (Belgium — europe-west1)
OpenAI (Whisper API)Voice-to-text transcription — audio discarded after transcriptionUS (with UK/EU data transfer safeguards)
Google (Gemini API)AI sorting — reads the text of a capture and returns which place it belongs inUS (with UK/EU data transfer safeguards)
Anthropic (Claude API)Standby AI sorter — used only if Google's service is unavailableUS (with UK/EU data transfer safeguards)
Apple App Store / Google Play BillingPayment processing for subscriptionsManaged by Apple / Google
GoHighLevel (with Mailgun)Our website, its forms (contact and feedback), and our emails to youUS (with UK/EU data transfer safeguards)
Google WorkspaceOur team email (your support emails reach us here)US (with UK/EU data transfer safeguards)
SentryError monitoring, scrubbed of personal content — no capturesUS (with UK/EU data transfer safeguards)

When data is transferred outside the UK or EU, we rely on Standard Contractual Clauses approved by the UK Information Commissioner's Office, or UK Adequacy Decisions where the receiving country has been formally recognised as providing adequate protection.

Your rights

Under UK GDPR, you have the right to:

  • Access — get a copy of the data we hold about you
  • Rectification — correct any data that's wrong
  • Erasure — ask us to delete your data ("right to be forgotten")
  • Restriction — ask us to pause processing while we sort something out
  • Portability — get your data in a portable format to take elsewhere
  • Object — object to processing based on legitimate interest
  • Withdraw consent — for anything based on consent
  • Complain to the ICO — if you're not happy with how we've handled your data

To exercise any of these rights, email [email protected]. We will respond within one calendar month, free of charge. Full detail in our Privacy Policy.

Reporting a security vulnerability

If you discover a security vulnerability, please report it responsibly to [email protected]. We will work with you in good faith and will not take legal action against good-faith security research.

Read the full documents

  • Privacy Policy — what data we collect, how we use it, your rights
  • Terms of Service — the contract between you and us
  • Cookie Notice — what cookies we use and why

Contact

  • All security, privacy, and general enquiries: [email protected]
  • Post: K.B.A. Investments Limited, 129 Marston Road, Stafford, Staffordshire, England, ST16 3BT

K.B.A. Investments Limited (Companies House number 03345267), trading as My One Button.
Last updated: 20 July 2026. Version 1.2.

My One Button
Privacy Policy Terms of Service Cookie Notice Security Support Contact

[email protected]