One Think / legal
Privacy Policy
How Anywhere for iOS handles relationship and location information, followed by the separate practices of the One Think website and Anywhere invitation page.
Effective September 1, 2026
In this policy
- Anywhere for iOS
- Pairing, the three location choices, Find sessions, Together Quiet, Sky memories, widgets, exports, and deletion.
- Website & invitations
- The One Think marketing site, contact form, hosting logs, and invitation details kept after the # in an Anywhere link.
- Choices & rights
- How to narrow or stop sharing, unpair, make a privacy request, or complain to a regulator.
1. Scope and controller
This policy applies to the Anywhere iOS app, the One Think website at onethink.io, the Anywhere invitation page, and support or privacy correspondence with us. The company responsible for those services is:
One Think, Inc.131 Continental Drive
Newark, DE 19702
United States
privacy@onethink.io
Apple independently controls its own services and describes them in its own terms and privacy notices. The paired person who receives information through Anywhere may also save, remember, screenshot, or export what they receive; this policy cannot control their independent actions.
2. Anywhere for iOS
Reciprocal CloudKit design
Anywhere does not create an Anywhere account and does not send relationship or location records to an operator-run relationship database. It uses Apple CloudKit with the Apple Accounts already signed into the two iPhones.
Each person owns a private CloudKit zone containing their own Presence, Find-session, and Sky records, and grants the paired person access through Apple’s shared database. Each person writes to their own zone and reads the other person’s owner records through that other person’s share. One Think does not receive a separate server-side copy and does not have a product tool for looking up a couple’s relationship records.
Pairing and identity
Pairing uses one-time CloudKit share records, reciprocal proof records, random identifiers, pairing state, and the first name a person uses in Anywhere. Apple may separately show Apple Account identity information in its CloudKit sharing interface. Pairing proof completes before any coordinate, place, or time zone is published. A proof-only record is marked Paused and carries identity and share state, not location.
The invitation that a person sends keeps its bearer capability in the user-facing link fragment. To complete reciprocal access, the invited phone creates a second one-time CloudKit share URL and writes that raw URL string into a Handshake record in the inviter-owned zone shared with it. The inviter reads the URL to accept the reciprocal share and then attempts a change-tag-checked redaction of that exact URL field. If redaction cannot complete, the URL can remain until a later retry or deletion of its owning relationship zone; after successful redaction, an empty Handshake record can remain. The reciprocal capability has the same 24-hour acceptance window as the invitation.
Your three location choices
Anywhere publishes location only after the two people have paired and the person sharing has chosen a mode. The mode controls what Apple Maps and the paired person receive:
- Precise: Anywhere sends the current coordinate to Apple Maps for place lookup and saves the coordinate, horizontal accuracy, city, country, time zone, and measurement time in that person’s CloudKit Presence for the paired person. This mode supports direction, distance, Find, and Together Quiet.
- Approximate: Anywhere first rounds the coordinate to a cell about 1.1 kilometres wide. Apple Maps and the paired person receive only that rounded point, coarse accuracy, its place and time zone, and the measurement time. Approximate supports rough distance, direction, and Find using that rounded point. At close range, the rounded geometry can wander. Together Quiet requires both people to use Precise.
- Paused: Anywhere sends no coordinate to Apple Maps or CloudKit, removes location fields from Presence, and keeps only the chosen name, pairing, explicit paused state, and Sky.
Earlier Anywhere versions offered a retired City only choice. The current app no longer offers that choice, but it can still read a legacy paired person’s City only record without inventing a coordinate: it shows only the place and time-zone information that record contains until the person chooses a current mode.
If Precise is selected while iOS Precise Location is off, Anywhere behaves as Approximate until precise access returns. Precise and Approximate updates normally occur after meaningful movement or elapsed time rather than continuously. Background behavior depends on iOS authorization, system scheduling, significant-change delivery, and—for Together Quiet—region monitoring; Anywhere does not assume continuous background GPS.
Requests, Find, and Together Quiet
A flare request and five-minute Find session can process random request and session identifiers, requested/joined/ended state, start and expiry times, facing values and their timestamps, alignment evidence, and replay-resistant sequence values. Find is available when both people use Precise or Approximate; Approximate uses each rounded point. Muting incoming flares is stored on the receiving phone and sends no refusal receipt.
Together Quiet requires both people to use Precise. It uses fresh location and accuracy on each phone to test whether the phones are nearby, then saves random claim and acknowledgement identifiers and evidence times in each person’s Presence. It reduces ordinary location updates for a bounded period. It proves only that the phones met the app’s proximity and accuracy conditions; it does not prove that two people are together or safe.
Sky memories
Each completed mutual Find session can create a Sky memory with an identifier derived from that session, so more than one memory can be kept on the same day. Older memories may use UTC-day identifiers. A current memory stores the date; both city and optional country labels; both time-zone identifiers; distance rounded to one decimal mile; the saving phone’s map bearing rounded to a whole degree; each person’s signed approach arc in five-degree steps; and each place’s solar elevation rounded to a whole degree. Memories created by earlier versions may additionally retain a separate session identifier, both map bearings, and both location-fix times. A Sky memory does not store latitude or longitude, but these retained facts are location-derived. Distance and bearing can describe a relative position when one endpoint is known.
Each person creates and keeps an independent Sky copy in their own CloudKit zone, a local application-support mirror, and—until CloudKit acknowledges a newly completed memory—a local retry journal on their own phone. This is why one person cannot erase the other person’s retained Sky copy.
On-device storage, widgets, notifications, and exports
- Anywhere keeps settings, sharing and pairing state, publishing state, mute choices, and caches in local app storage.
- An App Group snapshot lets the widget display the paired person’s name, place, time zone, distance when allowed, fix time, sharing state, and a bounded Together Quiet expiry. Widget values are marked privacy-sensitive for system presentation.
- Apple Push Notification service and CloudKit subscriptions deliver change hints so Anywhere can fetch updated records. A visible local notification can include the paired person’s display name.
- Star keepsakes are rendered on the phone from the reduced, location-derived Sky data described above. The person can send the rendered image through the iOS share sheet or grant add-only Photos permission. The chosen destination then receives that image; Anywhere does not browse the photo library.
App Store disclosure
For App Store privacy-disclosure purposes, Anywhere processes precise location, coarse location, name, and product-interaction data linked to the user’s iCloud and pairing identity for app functionality. It does not use those categories for tracking. Anywhere contains no ads, advertising SDKs, custom analytics SDKs, or non-Apple networking dependency.
3. Why information is used
- App functionality
- To pair two people, apply the selected privacy mode, calculate permitted direction and distance, sync reciprocal records, deliver flares, run Find and Together Quiet, render widgets, and keep Sky.
- Website functionality
- To deliver the site, render an invitation in the browser, process a requested inquiry, prevent abuse, and keep the pages secure.
- Support and improvement
- To answer messages and use TestFlight information Apple makes available to diagnose problems and improve the beta.
- Legal obligations
- To protect rights and safety, comply with law, and establish or respond to legal claims.
Where law requires a legal basis, we rely on performing the service or taking steps the user requests, consent where it is required, our legitimate interests in operating, securing, supporting, and improving the services, and compliance with legal obligations. iOS permission prompts are platform controls in addition to these legal bases.
We do not use Anywhere or the website to make decisions about a person based solely on automated processing that produce legal or similarly significant effects.
4. Retention, pausing, and erasing
- Presence: the current record is updated in place rather than building a coordinate trail. Restricting the sharing mode replaces or removes fields. A Sky memory is a separate historical record containing the reduced, location-derived facts described above, but no latitude or longitude.
- Sessions and Together Quiet: live values expire or are replaced as the feature changes state, but ended state or protocol records can remain in the person’s zone until that zone is deleted.
- Sky: each person’s independent copy remains until that person removes their own relationship zone through unpairing or replacement. One person’s unpair cannot delete the other person’s copy, screenshots, or exports.
- Unpair: Anywhere immediately clears the initiating phone’s relationship display and widget, then persists and retries cleanup that scrubs its Presence and Session, removes reciprocal share access, deletes its own Field zone, leaves the other person’s shared zone, and clears local relationship state. Offline conditions or iCloud errors can delay cleanup; Anywhere retries and reports when removal remains incomplete rather than claiming that remote deletion already succeeded.
- Reset This Device: clears local state only. It is not unpairing and can leave CloudKit records and the paired person’s existing access intact.
- Deleting Anywhere or leaving TestFlight: does not by itself unpair or delete CloudKit records. Unpair before deleting the app if the intent is to end sharing and remove this person’s zone.
Apple retains CloudKit, push, Maps, Photos, App Store, and TestFlight information under Apple’s own policies. Support and privacy correspondence is kept only as long as reasonably needed to answer the request, maintain necessary business or legal records, and resolve disputes; a person can ask us to delete information we control.
5. Website and Anywhere invitations
Invitation fragments
An Anywhere invitation can place three values in the fragment of its URL—the portion after #: an encoded CloudKit share capability, an optional sender first name, and a creation time. Encoding is not encryption. Anyone who obtains a still-valid capability may be able to accept the invitation, so treat the entire link as private and send it only to the intended person.
Web browsers do not transmit URL fragments in the ordinary request to a web host. The invitation page reads the name and creation time locally to personalize the greeting and show an expired state after 24 hours; it does not submit the fragment through a form or analytics request and does not write it to cookies or browser storage. The page’s expired message does not itself revoke CloudKit access or delete copies of the link.
The full link can remain in browser history, a messaging service, a clipboard, a screenshot, or any other place where the sender or recipient puts it. Those services handle the link under their own policies.
Contact form and email
The One Think contact form sends the email address entered, together with fixed website-inquiry labels, through Formspree. Formspree can also process technical request information such as IP address, browser type, access time, and referring page under its Privacy Policy. If someone emails us directly, we receive the address, message, and anything included in it. Do not send location, an invitation link, or other sensitive relationship information through the form.
Hosting and request information
The website host can process ordinary request information such as IP address, browser or device type, requested path, and request time to deliver and secure the pages. The fragment after # is not part of that request. We do not add advertising trackers or analytics to the site.
6. Apple TestFlight and diagnostics
If One Think offers Anywhere through an Apple TestFlight link, opening that link leaves this site for a separate Apple service. Apple may collect beta participation, device, usage, crash, diagnostic, and voluntary feedback information and make some of it available to One Think as the beta provider. Anywhere itself contains no crash-reporting or analytics SDK.
Apple controls its own processing. See Apple’s TestFlight privacy information and TestFlight Terms. Removing a beta app does not necessarily erase information already sent to Apple or made available to the beta provider.
7. Recipients and international processing
Information is disclosed only as needed for the service or as directed by the user:
- The paired person receives the information permitted by the selected sharing mode and reciprocal features.
- Apple provides iCloud and CloudKit, Maps place lookup, push notifications, Photos, the App Store, and TestFlight under Apple’s terms and privacy notices.
- User-chosen destinations receive a star image or invitation link when the user deliberately shares it.
- Website providers process contact-form and hosting information as described above.
- Authorities or advisers may receive information when reasonably necessary to comply with law, protect rights or safety, or handle a legal claim.
We do not sell personal information or disclose it for cross-context behavioural advertising. One Think is based in the United States, and Apple, Formspree, hosting, email, and support providers may process information in countries other than the user’s. Where required, we use applicable contractual or other legal safeguards for transfers we control.
8. Choices and rights
Anywhere provides direct controls to choose Precise, Approximate, or Paused; change iOS location, notification, or Photos permission; mute flares locally; and unpair. A person can also stop using the website, remove a link from browser history where possible, avoid the contact form, or leave TestFlight through Apple.
Depending on where a person lives, they may have rights to access, correct, delete, restrict, or receive a copy of personal information; object to certain processing; or withdraw consent. They may also complain to a local data-protection authority. Email privacy@onethink.io to make a request. We may need enough information to verify and complete it.
Because One Think has no relationship-data backend, we cannot remotely look up, export, change, or delete a couple’s CloudKit records on their behalf. Anywhere displays the current relationship information it can read, lets a person change what their Presence shares, and uses Unpair to delete that person’s own relationship zone. Apple explains that privacy.apple.com exports do not include third-party developers’ CloudKit container records, and Anywhere does not currently provide a full machine-readable export of all CloudKit records. We can act on support, website, or TestFlight information that One Think actually controls.
9. Security and age limits
Anywhere relies on Apple’s account, device, CloudKit, and transport protections and adds reciprocal proof, one-person share access, bounded invitations, restrictive privacy modes, and persisted cleanup. No system is perfectly secure. Protect both iPhones and Apple Accounts, keep invitation links private, and unpair promptly when sharing should end.
Anywhere is for people aged 18 and older. It is not a child or family-tracking product and must never be used to monitor a child. The general website pages are not directed to children under 13. If a child has sent personal information to One Think improperly, contact us so we can address it.
10. Changes and contact
We may update this policy as Anywhere, the website, providers, or legal requirements change. We will update the effective date above and provide any additional notice required by law. Material changes to app processing will be surfaced through the app or its distribution channel as appropriate.
Questions and privacy requests can be sent to privacy@onethink.io. Product help is available on the Support page.