Privacy Policy
Short version: Nullpark does not collect any data about you, on this website or in our apps. No analytics, no cookies, no tracking, no ads.
This page covers the website nullpark.ca and the iOS apps Nullpark publishes on the App Store, currently Boundary. We build privacy-first iOS apps, so it would be a little strange to run a website that quietly harvested its visitors. This one doesn't, and neither do the apps. Here is exactly what that means, in plain terms: first for this site, then for each app.
What this site collects
Nothing. There is no analytics, no tracking pixel, no advertising, no fingerprinting, and no third-party scripts running on these pages. There are no accounts, no comments, no forms, and no newsletter signup, so there is nothing to fill in and nothing to submit.
Nothing stored in your browser
Nothing is stored in your browser. This site sets no cookies and writes nothing to your browser's storage.
No third-party requests
Everything a page loads, the fonts, the images, the styles, and any small bit of JavaScript, is served from this domain. The fonts are self-hosted rather than pulled from Google Fonts, and there are no external embeds. Loading a page here does not quietly call out to anyone else's servers.
The obvious exception is up to you: if a page links to another site (for example, an app's App Store page) and you click it, you go to that site, which has its own rules.
Hosting: Cloudflare
This is a static site hosted on Cloudflare Pages. As the hosting and CDN provider, Cloudflare sits between your browser and the site in order to deliver it to you. Anything Cloudflare collects or processes in that role is governed entirely by Cloudflare's own privacy policy and data processing terms, not by us. For what that involves, refer to them directly:
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
To be clear about the boundary: we do not run any analytics, we have not enabled visitor tracking, and we have no dashboard that identifies you individually or ties you personally to what you view. Whatever happens at the hosting layer is between you and Cloudflare under their policy. We do not collect, store, or look at anything about you.
Our apps
Nullpark's iOS apps are built on the same idea as this site: your data stays on your device, and we do not collect it. None of the apps on this page asks you to create an account, and none of them contains analytics, crash reporting, advertising, tracking, or code from other companies (third-party SDKs). Each app ships with a privacy manifest that declares no collected data and no tracking, we file each app's App Privacy label on the App Store as "Data Not Collected", and we keep this page in step with what the apps actually do.
"We collect nothing" still leaves fair questions about what happens on your phone, so each app gets its own section below spelling out what it touches, what it keeps, and where your content can go. Right now that is one app, Boundary. We will add others here when they ship.
Our apps are general-audience utilities, not designed for or marketed to children. Because they collect no data, they collect none from anyone, children included.
Boundary
Boundary is an iPhone app that catches what you did not mean to leak. It finds personal details and secrets in text before you paste it into an AI assistant, and it blurs faces and blacks out sensitive text in screenshots. It also strips hidden metadata (location, camera, edit history) from photos before you share them, audits your photo library for leftover metadata, and drafts deletion-request letters to platforms. Every one of those jobs runs on your phone. Boundary has no servers, no accounts, and no analytics. This section is the long version.
What Boundary collects
Nothing. Boundary does not collect or transmit any personal data to Nullpark or to anyone else, and it keeps nothing about you anywhere except the on-device working files described below. It contains no analytics, no crash reporting, no advertising, no tracking, and no code from other companies: it is built only from the frameworks Apple ships with iOS. It never asks you to sign up or sign in, so there is no Nullpark account and nothing for us to hold. The only connection the app itself opens is to Apple's App Store, for purchases (see Purchases). Boundary's privacy manifest declares no collected data and no tracking, its App Privacy label on the App Store is filed as "Data Not Collected" in every category, and the rest of this section explains why that is true.
Everything runs on your phone
When you hand Boundary text or an image, the work happens on your phone using Apple's built-in frameworks. Vision finds faces and reads text in images. Natural Language and Apple's data detectors, plus a bundled pattern list, spot names of people, places, and organizations, email addresses, phone numbers, postal addresses, dates, card numbers, government identifiers, network addresses, API keys, and other secrets. ImageIO reads and removes photo metadata. Face blur uses face detection (a box around each face), not facial recognition: Boundary never creates or stores a face template and never compares faces across images.
Apart from Apple's purchase system (see Purchases), Boundary makes no network connection of its own. It contains no code that could upload your photos, your text, or your prompts anywhere, and every feature that reads your content does its work with the connection off. Pro features unlock by checking the purchase record Apple's StoreKit keeps on your phone, never a server of ours. The only other thing in Boundary that needs a connection is sending a deletion letter, and that goes out through your own mail app (see below). Detection is best-effort: Boundary masks what it finds, and it can miss things.
What Boundary keeps on your phone
Very little: three settings, and photos only for as long as you are working on them.
- Three settings: whether you have finished onboarding, which metadata to strip for each app you share to (a saved preference; today the share extension strips everything regardless of it), and whether the Letters tab is shown. They live in Boundary's own private storage on your phone and contain no personal content.
- Nothing you process. Text you type or select, prompts, findings, and audit results are held in memory while the app is running and are never written to disk. Boundary keeps no history of prompts, findings, or scans.
- Working copies while you share. When you share photos through Boundary, the share extension copies them into its own private working folder while the share sheet is open and deletes them when you finish or cancel. If iOS interrupts the share before then, the copies are removed the next time the share extension runs.
- Photos staged for the app. If you choose "Process more in Boundary" from the share sheet, the share extension copies the original photo, up to ten at a time, into Boundary's private storage so the main app can pick it up, and hands the app a link that carries only an ID, never the photo. The photo stays there until you save or cancel that session in Boundary; while a save is in progress, the cleaned result sits alongside it briefly. If you swipe the session away or tap "See plans" instead, it waits on your phone, readable only by Boundary, until you come back and finish or cancel it, or until iOS clears the cache. Repeated shares queue up the same way. Nothing in that storage ever leaves your phone.
- No purchase records. Boundary writes nothing about your purchase status to disk. It keeps your current tier in memory while the app runs and re-reads it from Apple's StoreKit at launch, when you come back from the background, after a purchase or restore, and whenever StoreKit reports a change (see Purchases).
Boundary itself uses no iCloud, no cloud sync, and no keychain. If you back your iPhone up to iCloud or a computer, the three settings are included like any app's data. Boundary is the only app that can read its private storage, and deleting the app removes all of the above from your phone (an earlier backup may still hold the three settings until it is replaced).
Permissions
The only system permission Boundary ever asks for is Photos, and only in two situations:
- Library audit. The first time you tap "Start audit", Boundary shows a short screen explaining what it will and will not do with your library; when you tap Continue, iOS asks for photo library access, and you can grant all photos or pick specific ones. Boundary then reads the metadata of your most recent photos (50 on the free tier, 10,000 with Pro, the paid tier described under Purchases) to show how many still carry GPS coordinates, camera details, or editing software, and a hygiene score. It reads still photos that are already on your phone, never downloads from iCloud, never modifies or deletes a photo, never uploads anything, and holds the results only in memory: they are never written to disk and are gone when the app quits. iOS has no read-only option for the photo library, so the prompt you see asks for read and write access. Boundary never edits or deletes anything in your library; the only thing it ever writes is a new photo, and only when you choose to save a cleaned copy (next item). If you picked specific photos, a "Select more photos" row in the audit lets you change the selection later.
- Saving a cleaned copy. When you choose to save a cleaned image to your library, with the Save button in Boundary or Save Image in the share sheet, iOS asks for add-only access (unless you already granted library access for the audit) and Boundary adds the cleaned image as a new photo. Your original is never changed.
Photos you share into Boundary through the share sheet or a "Redact with Boundary" action need no permission: you chose them, and Boundary only ever sees those. You can change or revoke Boundary's photo access at any time in iOS Settings (Privacy & Security, then Photos); everything you share into Boundary yourself keeps working without it. Boundary does not request access to your camera, microphone, location, contacts, or anything else on your phone, and it never reads your clipboard.
Where your cleaned content goes
Boundary sends none of your content anywhere on its own. Every piece of your content that leaves the app does so because you chose a destination, through a standard iOS mechanism. Remember that detection is best-effort: masking covers what Boundary found, and anything it missed travels as-is.
- Your clipboard. "Send" in the prompt editor and in the "Redact with Boundary" text action copies the masked text to your clipboard and, if you picked an AI app (ChatGPT, Claude, Gemini, or GitHub Copilot Chat in VS Code), opens that app. The app is opened by name only: Boundary passes it no text. The masked text reaches the AI service only when you paste it there (or if that app reads your clipboard itself, which iOS asks you to allow). From that point on, that service's privacy policy applies, not ours. The clipboard is a system feature: what you copy stays there until you copy something else, any app you paste into can read it, and if you use Apple's Universal Clipboard it can appear on your other Apple devices.
- Back to the app you were in. The "Redact with Boundary" actions return the masked text or the redacted image to the app you invoked them from. The redacted image is a fresh copy with no metadata, at most 3840 pixels on its longest side.
- The share sheet. Cleaned photos from the share extension go to whatever you pick in iOS's share sheet (Messages, Mail, AirDrop, Save Image, another app). Boundary does not record what you pick. The cleaned file's name is built from the name the source app gave it, with " cleaned" added before the extension (a screenshot's file name, for example, can still include the time it was taken), even though the metadata inside the file is removed. If the source app supplies no name, as the Photos app does not, the file is called "Cleaned photo".
- Your photo library, when you save a cleaned copy (see Permissions). A cleaned photo you save is then part of your library, including iCloud Photos if you use it.
- Shortcuts and Siri. The "Redact PII in Text" and "Detect PII in Text" actions process the text your shortcut gives them on your phone and hand the result back to the Shortcuts app. "Detect" returns the items it found, verbatim, so your own shortcut can branch on them; where that result goes next is up to your shortcut. If you invoke an action by voice, Siri handles your speech under Apple's terms before the text reaches Boundary.
- Your email, for letters. The Letters tab drafts deletion requests, citing the EU right to erasure, to seven platforms: Meta, TikTok, X, Google, Apple, Snapchat, and LinkedIn. You type your name, an account identifier, and a date of birth, which is inserted only where a template calls for it (today, only the Meta letter). Boundary fills the template on your phone and opens your Mail compose sheet, pre-addressed to the platform's privacy address; if you have no mail account set up in Apple Mail, it shows you the letter to copy into another mail client yourself. Your own mail account sends it (or keeps it as a draft), and the reply comes back to you. Boundary does not store what you typed, learns only whether you sent, saved, or cancelled the message, and makes no network call. Once sent, the letter is in your mail provider's hands and the recipient's. The templates are not legal advice.
Purchases
Boundary's Pro features are sold through Apple's App Store as in-app purchases: a monthly or annual auto-renewing subscription, or a one-time Lifetime purchase. Apple processes the payment and holds your billing details; Boundary never sees your payment information, and there is no Nullpark account behind a purchase.
To decide which features to unlock, the app uses Apple's StoreKit purchase system to read the purchase record Apple keeps on your phone. This is the one part of Boundary that talks to the internet. StoreKit contacts the App Store to load prices when you open the plans screen, to complete a purchase, and to restore purchases (which may ask you to sign in to your Apple Account). It also keeps the purchase record on your phone current on its own schedule, and Boundary re-reads that record at launch, when you return from the background, and whenever Apple reports a change such as a renewal or refund. The "Redact with Boundary" actions and the Shortcuts actions do the same read to check whether Pro is active; they never show prices or purchase screens. Those exchanges are between your phone and Apple, carry none of your photos, text, or prompts, and are governed by Apple's privacy policy:
Apple Privacy Policy: https://www.apple.com/legal/privacy/
Boundary does not check purchases against any server of its own and uses no third-party billing or subscription service. Managing, cancelling, or refunding a subscription happens in your Apple Account settings, not in the app, and deleting the app does not cancel a subscription. Boundary's terms of use are Apple's standard end user license agreement:
Apple Licensed Application End User License Agreement: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
Deleting your data
Boundary holds nothing about you anywhere but on your phone, so there is nothing to request from us. To clear what is on your phone: finish or cancel any pending "Process more" session to remove its staged photo, copy something else to replace what is on your clipboard, reset the per-app preferences from Settings if you like, revoke photo access in iOS Settings, and delete the app to remove its settings and private storage entirely. Purchases belong to your Apple Account and survive deletion: "Restore purchases" brings them back after a reinstall, and a subscription keeps renewing until you cancel it in your Apple Account settings.
The fine print
An honest "nothing leaves your phone" needs its edges drawn:
- Apple's own software. Downloading and updating Boundary from the App Store, StoreKit purchases, and iOS features such as keyboard autocorrect, dictation, Writing Tools, Siri, and Universal Clipboard are Apple's, and they run under Apple's privacy policy. Boundary itself sends none of your content to Apple; what you do with the system keyboard, dictation, Writing Tools, or Siri inside Boundary's text fields is handled by iOS, not by Boundary.
- What Apple shares with us. Apple shows developers aggregate App Store figures (downloads, sales) that do not identify anyone. If you have turned on sharing analytics with app developers in iOS Settings (Privacy & Security, then Analytics & Improvements), Apple may also pass us crash reports for Boundary. Those come from Apple under Apple's terms, contain none of your content, and we would use them only to fix bugs. Boundary itself contains no crash reporting.
- Third parties you choose. ChatGPT, Claude, Gemini, VS Code, the platforms you email, your mail provider, and anything you pick in the share sheet are third parties with their own policies. Boundary hands them only what you choose to send and has no relationship with them.
- Diagnostics. Nothing in Boundary can send diagnostics to us. On a failure it writes a one-line error description (never your content) to the iOS system log on your phone. iOS keeps that log under Apple's rules, and it leaves your phone only if you choose to share diagnostics with Apple.
Changes
If any of this ever changes, for this site or for an app, we will update this page and say so plainly. When an app's behaviour changes in a way that matters here, we update its section before that update ships and move the date below. For now the honest answer is the simple one: we are not collecting anything.
History: August 22, 2026, added the Our apps and Boundary sections. July 17, 2026, first published.
Who we are
Nullpark is a trade name of 17785852 Canada Inc., a corporation incorporated under the Canada Business Corporations Act (CBCA), with its registered office in Ontario, Canada. The same company publishes our apps on the App Store under the developer name Nullpark.
The bottom line, in case any of the detail above ever drifts out of date: we do not want any trackers on this site or in our apps, and we do not want any information collected about you. We will do everything we can to keep it that way.