Effective date: 2026-07-06
Operator: River.io LLC
Contact: jeff@river.io
App: ClientAPT for Android (io.river.clientapt)
This is the privacy policy for ClientAPT, an on-device appointment and client manager for service professionals. We wrote this policy to be short on purpose, because the product itself is short on data handling: ClientAPT does not collect, share, transmit, or process any user data outside of your phone.
Nothing. ClientAPT does not collect any personal information, device identifiers, contacts, location, or usage analytics.
The Android INTERNET permission is not declared in the app
manifest. The app cannot make outbound network requests of any
kind. There is no server, no telemetry endpoint, no analytics
backend.
Nothing. ClientAPT does not share any user data with River.io
LLC, with third parties, with advertisers, or with anyone else.
The app ships no SDKs that transmit data off-device (no Firebase
Analytics, no Crashlytics, no Sentry, no AdMob, no AppsFlyer, no
similar libraries). This is verified at build time by an
in-source audit test (LeakAuditTest) that grep-checks the
release artifact for forbidden symbols and fails the build if
any are found.
The data you enter — clients, appointments, services, photos, and purchases — is stored only on the device, inside an encrypted SQLite database. Encryption is provided by:
Photos captured in the app are stored inside the app’s own encrypted container. They are never written to the Android MediaStore or to any folder outside the app’s private storage.
Clients flagged as “sensitive” require a separate sensitive PIN to view their notes, photos, and service details. Biometric unlock does not bypass the sensitive PIN.
The current release has no backup or export feature. Your data never leaves the device in any form. (An optional, passphrase- encrypted, on-device export may be offered in a future release; this policy will be updated when it ships.)
Appointment reminder notifications contain only the time of the
appointment (literally "Appointment at HH:MM"). They never
contain client names, services, addresses, or any other personal
information.
ClientAPT is intended for adult service professionals (tattoo artists, stylists, and similar). It is not directed at children and does not collect data from anyone.
The current release contains no in-app purchases.
ClientAPT requests Android permissions only when needed:
ClientAPT does not request:
Because the app does not collect or share data, there is nothing for River.io LLC to delete or export on your behalf. The data is yours, on your device:
If we ever change this policy, we will update the effective date at the top of this document and post the new version at the same URL. Material changes will also be noted inside the app’s Settings → About screen.
Questions about this policy or about ClientAPT’s data handling:
River.io LLC Email: jeff@river.io Website: https://www.river.io