Denken Box — Privacy Policy
Last updated: May 14, 2026 · Effective: May 14, 2026
Denken Box is a personal-knowledge-management client for Supabase.
This policy explains exactly what data the app handles, where it lives, and
who can see it. The short version: we do not operate servers that store
your personal data, and your notes never touch our infrastructure.
The "bring your own Supabase" model
Denken Box is a client app. It connects to a Supabase project that
you configure and control. Your notes, decisions, projects,
conversations, and any other content you create are stored on
your Supabase project, governed by Supabase's terms and
your own Supabase account. The publisher of Denken Box (BigCat LLC)
has no access to that project and does not receive a copy of your data.
What the app stores on your device
- Supabase project URL + anon key — saved in the iOS
Keychain so the app can connect on relaunch. Protected by
kSecAttrAccessibleWhenUnlockedThisDeviceOnly.
- Authentication refresh token — issued by your
Supabase project after sign-in, saved in the iOS Keychain and gated by
biometric access (Face ID / Touch ID) when available.
- Last-used email address — saved per project so the
sign-in screen can pre-fill on relaunch. Only the email itself; never
the password.
- Offline cache — a local copy of records you've
already viewed, plus any writes you made while offline that are
waiting to sync. Stored using Apple's SwiftData framework in the app's
sandboxed container. Cleared when you remove the project from the app.
What the app sends over the network
The app communicates only with the Supabase project URL you provide. Each
request is sent directly from your device to your Supabase project's API
endpoint. There are no third-party analytics, advertising, tracking,
crash-reporting, or attribution SDKs in Denken Box.
The demo project
If you tap "Try with Demo" instead of providing your own Supabase URL,
the app connects to a demonstration Supabase project operated by BigCat
LLC. The demo project contains seeded sample data and a shared demo
account (demo@openbrainmobile.app). Do not store personal
or sensitive content in the demo project — anything you create there is
visible to other people who use the demo. We may reset the demo data at
any time.
Personal data we do not collect
- We do not collect or transmit your name, email address, or contact
information to BigCat LLC.
- We do not collect usage analytics, telemetry, crash reports, or
behavioral data.
- We do not collect device identifiers, advertising IDs, or
fingerprinting signals.
- We do not collect location data.
- We do not access your photos, contacts, microphone, camera,
health data, or HomeKit data.
Children's privacy
Denken Box is not directed at children under 13. We do not
knowingly collect personal information from children.
Third-party services
The only third-party service Denken Box communicates with is the
Supabase project you configure. Supabase's own privacy policy governs
what Supabase does with your data: supabase.com/privacy.
Your rights and choices
- Delete your data — to delete data stored in your
own Supabase project, delete it through Supabase directly. To clear
local caches and credentials from the app, open Settings → Project →
Remove Project, or delete the app from your device.
- Switch projects — you can change which Supabase
project the app connects to at any time through Settings.
- Export your data — because your data lives in your
own Supabase project, you can export it directly from Supabase using
any standard PostgreSQL or Supabase export tool.
Changes to this policy
If we change this policy, we will update the "Last updated" date above.
Material changes will be announced through an app update.
Contact
Questions about this policy or about Denken Box in general:
jason@bigcatllc.com.
© 2026 BigCat LLC. Denken Box is a personal-knowledge-management
client and is not affiliated with, endorsed by, or sponsored by Supabase
Inc.