cloakfeed.Back to site

Privacy Policy.

Privacy Policy

CloakFeed has no user accounts, no backend and no analytics. Everything you import, follow, read, highlight and note is stored on your device only. We — the developers of CloakFeed — never receive it, because there is nowhere for it to be sent.

Last updated 22 August 2026

The short version. We collect nothing. The app talks to the internet only to fetch the feeds you follow, the images inside the articles you open (unless you turn images off), and — if you choose to connect one — your own mailbox, directly over TLS. No data flows to CloakFeed, because CloakFeed operates no server that could receive it.

1. Who this policy is about

This policy covers the CloakFeed mobile application for Android and iOS (“the app”) and this website, cloakfeed.com. Where data protection law such as the GDPR uses the word “controller”, that role would fall to us for personal data we determine the purposes of — but as described below, the app is designed so that we hold none. Data you create in the app stays under your control, on your hardware.

2. What we collect

Nothing. There is no sign-up, no login, no user identifier, no advertising ID, no crash-reporting SDK, no analytics SDK, no telemetry ping, and no “anonymous usage statistics” toggle that quietly defaults to on. The app ships with no third-party tracking libraries.

We do not build profiles, we do not sell or share personal information, and we do not have a database of users to breach, subpoena or sell in an acquisition. If we ever add anything that transmits data, it will be stated here first and it will be off until you turn it on.

3. What the app stores on your device

All of it lives in the app’s private storage area, which other apps cannot read, and it is removed when you uninstall the app.

WhatWhere it is kept
Feeds you follow, imported newsletters and articles, their text, extracted image links, read state, reading position, saved items and import batchesA local SQLite database inside the app’s own folder
Your notes and highlightsThe same local database
Preferences: theme, reading font size and background, image loading, notification toggle, chosen interests, recently viewed feeds, whether onboarding is doneLocal key–value storage on the device
PDFs you import, and cached feed artworkFiles in the app’s private directory
Mail app passwords, if you connect a mailboxThe platform keystore — Keychain on iOS, EncryptedSharedPreferences on Android — never the database, and never an export

The database records only the name of the keystore entry, so a copy of it hands over the label of a locked box rather than what is inside.

4. Every connection the app makes

These requests go from your device straight to the destination. None of them passes through us; there is no CloakFeed proxy, relay or CDN in the path.

Feeds

When you refresh, follow a feed or search for one by address, your device requests that feed’s URL directly. The publisher’s server sees what any RSS reader shows it: your IP address, the request, and the time. We see nothing. The bundled starter catalogue is shipped inside the app, so browsing it contacts no one at all.

Images

Images inside an article are fetched from wherever the publisher hosts them, and only when you open that article. Turning Load images off in Account means the sender’s image server is never contacted. The app also strips tracking pixels and invisible beacons out of newsletter markup before rendering, so opening a newsletter does not report back to the sender the way it does in a normal mail client.

Connected mailboxes (optional)

If you connect Gmail or iCloud Mail, the app opens a TLS connection from your device to imap.gmail.com or imap.mail.me.com on port 993 and signs in with the app-specific password you generated with that provider. The first scan reaches back 90 days; after that it asks only for messages newer than the last one it saw.

Message contents are parsed on your device and stored in the same local database as any other import. Nothing about your mailbox — addresses, subjects, bodies, or the fact that a connection exists — is sent to us or to any third party. Disconnecting deletes the app password from the keystore rather than merely pausing the sync, and you can revoke it from the provider’s side at any time, which cuts the app off instantly.

Links you tap

Opening an article’s original link, a provider’s app-password page, or the Kill the Newsletter relay hands the URL to your system browser. From that point the site’s own privacy policy applies.

Nothing else

The app has no ads, no ad networks, no attribution SDK, no push server and no remote configuration. Notifications, if you enable them, are scheduled locally by your device after a refresh finds new items — no push token is created and nothing leaves the phone.

5. Files you import

OPML, MBOX, EML, PDF and ZIP files you pick are read on your device by code inside the app. They are not uploaded anywhere. The app records a fingerprint of an import so it can recognise the same export if you pick it twice; that fingerprint stays local too.

6. Permissions the app asks for

  • Files / documents — only for the file you select in the picker when importing. The app has no ability to browse your storage.
  • Notifications — optional, for a local alert after a refresh brings in new items.
  • Network — to fetch feeds, article images and, if connected, mail.

The app requests no contacts, location, camera, microphone, calendar or advertising-identifier access.

7. Your control over your data

  • Export — Account › Export produces a JSON file of your feeds, items, notes and highlights and hands it to the system share sheet. You choose the destination; the app never transmits it. App passwords are deliberately excluded from exports.
  • Reset — Account › Reset app data erases notes, highlights, items, feeds and every stored mail credential.
  • Uninstall — removes the database, the preferences, the cached files and the keystore entries with it.

Rights such as access, rectification, erasure, portability and objection under the GDPR, UK GDPR, CCPA/CPRA and comparable laws are satisfied directly by these controls: the data is in your possession, and we hold no copy to hand over or delete. We do not sell or share personal information as those terms are defined under the CPRA, and there is nothing to opt out of.

8. Retention and security

Data stays on your device until you delete it, reset the app, or uninstall. It is protected by your platform’s app sandbox and device encryption, so a device lock screen is a meaningful part of it. Mail credentials additionally sit in the hardware-backed keystore. We run no servers, so there is no server-side retention period and no backup of your reading held by us. If you back your device up to iCloud or Google, that copy is governed by Apple’s or Google’s policies, not this one.

9. Children

CloakFeed is not directed at children under 13 (or the equivalent age in your country), and since the app collects no personal data, none is knowingly collected from children.

10. This website

cloakfeed.com is a static marketing site. It sets no cookies, runs no analytics and embeds no third-party trackers. Fonts are served from Google Fonts, and our host records standard server logs (IP address, time, page) for the purpose of serving and securing the site.

11. Changes

If this policy changes, the date at the top changes with it, and any change that affects what the app transmits will be described here in plain terms before it ships.

12. Contact

Questions about privacy: privacy@cloakfeed.com. The terms governing use of the app are in the Terms of Service.

CloakFeed

Reading that stays on your phone.

Legal

  • Privacy
  • Terms

Contact

  • privacy@cloakfeed.com

© 2026 CloakFeed. All rights reserved.