A Nod Privacy Policy

Privacy Policy

Effective date: September 10, 2026

A Nod is an iPhone app for keeping track of the books, films, shows and podcasts people recommend to you, and who recommended them. This policy explains what data A Nod handles, where it goes, and what we don’t do.

The Short Version

A Nod does not collect your data. There is no A Nod account, no A Nod server, and no analytics. Everything you put into the app stays on your iPhone, and — if you turn on sync — in your own private iCloud storage, which only you can read. Almost Right Creative cannot see your recommendations, the people you record them from, your notes, or your ratings. Not because we promise not to look, but because the app was built without anywhere for that information to go.

The rest of this page explains that in detail, including the moments when A Nod talks to the outside world and exactly what it says.

Who This Policy Is From

A Nod is made by Almost Right Creative (“we”, “us”). This policy covers the A Nod iPhone app and its Share Extension and widgets. It does not cover the third-party services described below, each of which has its own policy.

If you have a question about anything here, write to support@almostrightcreative.com.

What A Nod Stores, and Where

A Nod stores what you put into it:

  • Items you have been recommended — title, creator, year, medium, and cover art — along with any links you saved alongside them and your own private note about why a link mattered.
  • The people who recommended them: the name you gave them, a photo, and any social handles you recorded. If you linked a person to your Contacts, A Nod also keeps Apple’s identifier for that contact, so it can keep the name and photo current — see the next section.
  • The recommendations themselves: when each one happened, the reason you were given, your status, a timestamped history of when you changed that status, and your own verdict once you got to it.
  • Your own free-text notes on an item.

All of this is written to a database on your device. If you enable iCloud sync in Settings, that same database is mirrored into the private database of your personal iCloud account, using Apple’s CloudKit. Private-database records are readable only by you through your Apple Account. Almost Right Creative holds no credentials for your data and cannot query, export, or restore it. If you never turn sync on, nothing leaves the device at all.

There is no A Nod server. We do not operate a backend, we do not maintain user accounts, and there is no copy of your library anywhere that we could hand over, sell, lose, or be compelled to produce.

Contacts

A Nod can optionally read your Contacts to make it faster to attach a recommendation to a person you already know. This is a convenience, never a requirement — you can use every part of the app, including adding people, without granting Contacts access, and you can revoke it at any time in iOS Settings.

When you do grant it, the lookup happens entirely on your device, and your contact data is never transmitted anywhere by A Nod. A Nod reads only a contact’s name, nickname, and thumbnail photo. It does not read, and cannot see, phone numbers or email addresses.

When you link a person in A Nod to one of your contacts, A Nod stores Apple’s identifier for that contact alongside its own record, so that it can recognise the same person later and keep their name and photo in step with your address book. That identifier is a local reference that means nothing outside your device and your own iCloud account, and it travels only where the rest of your library travels. If you would rather not have that link, add people by typing a name instead — nothing about the app requires Contacts.

Deleting a contact from your address book does not delete anything from A Nod; your recommendation history stays intact, because A Nod’s records are keyed on identifiers it generates itself, not on your address book.

When A Nod Talks to the Internet

Every request below is one you set off, by adding an item or sharing one. None of them is scheduled, none happens in the background, and none carries anything about you.

Looking things up. When you add an item, A Nod tries to find its cover, creator, and year so you do not have to type them. It sends the text you typed — or the link you shared — to public catalogue services, choosing between them by what kind of thing you are adding:

  • Open Library, operated by the Internet Archive, for books — policy
  • Hardcover, for books, only if you choose it as your book source and connect your own Hardcover account. Open Library is the default; unless you choose Hardcover and sign in, A Nod never contacts Hardcover at all — policy
  • Apple’s iTunes Search API for films, podcasts, and music — policy
  • TVmaze for television — policy
  • Wikidata and Wikimedia Commons for film details and freely-licensed posters — policy
  • Spotify and YouTube, through their public preview endpoints, when what you shared is a Spotify or YouTube link — Spotify policy, Google policy

These requests carry the search text or the URL, and an identification of the app itself with an address you can reach us at — which those services ask for, so that they can contact whoever is querying them. They carry no information about you: no name, no account, no device or user identifier, no advertising id, and no other part of your library. They never carry the person who recommended the item, your reason, your status, or your verdict.

There is one deliberate exception. If you connect your Hardcover account, you sign in on Hardcover’s own page and approve what A Nod may do there. Hardcover then gives A Nod a token, and each request to Hardcover carries it, which identifies your Hardcover account to Hardcover and to no one else. A Nod keeps that token only in this device’s Keychain, never syncs it, and never sends it anywhere but Hardcover. Disconnect in Settings at any time — A Nod asks Hardcover to revoke the token and forgets it — and you can also revoke A Nod under Hardcover › Account › Authorized Apps.

Syncing with your Hardcover shelf. Connecting an account asks for permission to read your Hardcover library and to update it. Reading and writing are separate things, and A Nod does the second only when you switch “Send my status to Hardcover” on — it is off until you turn it on, and turning it off stops any change that has not been sent yet.

While it is on, A Nod writes two things to your Hardcover account, for books only: whether you have a book on your list, are reading it, finished it, or gave up on it; and the page you are on. Those appear on your Hardcover profile under Hardcover’s own privacy settings, not ours. In the other direction, A Nod reads the same two things back, so a change you make on Hardcover shows up here. If a book has changed in both places since they last agreed, A Nod asks you which to keep rather than choosing.

Nothing else is ever sent. Not the person who recommended a book to you, not your reason for wanting it, not your verdict once you have finished, and not your notes — those never leave your device and your iCloud account. Hardcover’s API would accept a rating and a written review; A Nod never asks for permission to write either, and never sends them.

Following a link you shared. If you share a shortened link — a bit.ly, amzn.to, t.co, or similar — A Nod asks it where it points so it can identify what you are actually adding, which means a request to that shortener and to each site it redirects through. If no catalogue can identify what you shared, A Nod falls back to Apple’s LinkPresentation framework, which fetches a preview straight from the page you shared. Those requests go to whatever sites are involved, whichever they are; we do not control them and cannot list them in advance.

Podcasts. Finding a podcast’s artwork means fetching its RSS feed, which is hosted by whoever publishes the podcast rather than by Apple. Adding a podcast will therefore reach that publisher’s host.

Showing cover art. A Nod generally stores the address of a cover rather than a copy of the image, which keeps its database small. The practical consequence is that your phone re-fetches the image from wherever it lives each time it needs to draw it — from Apple’s, TVmaze’s, Spotify’s, YouTube’s, Open Library’s, Hardcover’s, Wikimedia’s, or a podcast publisher’s image servers. Those servers see an ordinary image request from your device. (Preview images captured by LinkPresentation are the exception; those are stored on the device.)

As with any request to any website, every service above can see the IP address the request came from and may log it under its own policy.

Buying the unlock or leaving a tip. Purchases go through Apple’s App Store using StoreKit. Apple handles the transaction; we never see your payment details, and the app receives only a confirmation that an entitlement is valid. We can see anonymous, aggregate sales figures in App Store Connect — how many copies sold in a country on a day — and nothing that identifies a buyer.

When You Share an Item

If you pass an item on to someone, A Nod builds a share containing a picture card, a short message, and a link. You see all three before you send anything, and the message is yours to edit.

Which of your own words travel depends on who the share is for, and the app draws that line for you rather than leaving it to a setting.

A nod back — thanking the person who recommended something — is addressed to one person who already knows you, so it can carry your verdict on the thing and their name. That is rather the point of telling them you finished it.

A public post is a different audience, so it is narrower by construction: it carries the item, whether you have finished it, and nothing about your verdict, the person who recommended it, or your reason. That is not a default you could change by accident; the card and its message are built without those fields.

Either way, read what you are about to send. It is all visible in the share sheet, and anything you would rather not say can be edited or removed first.

The link is narrower and fixed: it carries only the item’s public facts — title, creator, year, medium, and the address of its cover art. It never carries the reason you were given, your status, or your verdict, and it never carries anything about anyone else in your library.

Nothing is uploaded to build any of this. The link is self-contained, so there is no record of it anywhere: we do not see that you shared, what you shared, or with whom. Once you send it, where it goes is a matter for whichever app you sent it through — and note that some messaging apps fetch a preview of a link you paste, which is that app’s behaviour rather than A Nod’s.

What We Do Not Do

A Nod contains no analytics SDK, no crash reporter, no advertising framework, and no third-party tracking code of any kind. It has no third-party software dependencies at all. It does not track you across apps or websites, and it does not share or sell information about you, because it has none to share.

Spotlight and Siri

So that you can find your library from Spotlight search or ask Siri about it, A Nod publishes some of its contents to the on-device search index that iOS maintains. That index is part of iOS, stays on your device, and is removed when you delete the app.

What goes into it is deliberately narrow. Titles, creators, the names of people who recommended things, and the fact that a recommendation happened on a date can be indexed. Your reason for wanting something, your verdict after finishing it, and an item’s status are never indexed and never exposed to Siri. That boundary is enforced in the app’s code and covered by its automated tests, because the private half of a recommendation is the half worth protecting.

Within that boundary you can narrow it further. Settings › Your data has two switches — one for the names of people who recommended things, one for the fact that a recommendation happened on a date — and either can be turned off. Turning one off removes what it covers from the index straight away, rather than at some later point.

A Nod also offers Shortcuts and Siri actions for logging a recommendation and for marking something started or finished. Those run on your device, and using them tells Siri only what you ask it to do.

Diagnostics and Support

A Nod sends us no diagnostic reports. If iOS asks whether to share crash and usage data with developers and you say yes, Apple may provide us with aggregated, anonymised crash reports through App Store Connect; that is an Apple mechanism you control in iOS Settings, and it contains no A Nod content.

If you email support, we will have whatever you write to us and your email address, used only to answer you. We do not add it to a mailing list.

Children’s Privacy

A Nod is not directed at children under 13, and we do not knowingly collect information from them. Since the app collects nothing from anyone, there is nothing for us to delete on request — but if you have a concern, write to us.

Data Retention and Deletion

Because your library lives on your device and in your own iCloud account, you control it directly and do not need to ask us for anything.

To pass something on, use the app’s share feature. To delete everything on the device, delete the app. To remove what iCloud is holding, open iOS Settings, tap your name, then iCloud, then Manage Account Storage, and delete A Nod’s data — or turn off A Nod under iCloud to stop syncing while keeping what is on the device.

We hold no copy, so there is nothing for us to retain and no retention period to describe.

Your Rights Under GDPR, UK GDPR, and CCPA

If you are in the European Economic Area, the United Kingdom, or California, data-protection law gives you rights to access, correct, delete, port, and restrict the processing of your personal data, and to object to it. Those rights are exercised against whoever holds the data. For A Nod, that is you: we are not a controller or processor of your library, because we never receive it. You can exercise every one of those rights yourself, immediately, using the controls described above.

We do not sell or share personal information as those terms are defined under California law, and we have no personal information to sell.

For the limited data that does reach a third party — the search text or link you send to a catalogue or preview service, and your purchase with Apple — the relevant rights are exercised against that provider under its own policy, linked above.

Changes to This Policy

If the app changes in a way that changes this policy, the updated version will be posted at this URL with a revised effective date. If a change is significant — if A Nod ever begins collecting something it does not collect today — we will say so in the app before it takes effect, not quietly here.

Contact

Almost Right Creative support@almostrightcreative.com