Talus privacy policy
Talus does not collect, share or sell any information about you. It has no accounts, no ads, no analytics and no tracking, and we run no server that it talks to. It is built only with Apple’s frameworks. What you put in it is kept on your devices and in your own iCloud account, and goes elsewhere only when you send a file yourself.
What you keep in Talus
Talus holds what you enter: meetings, agenda points and decisions, minutes, follow-ups, announcements and, if you turn it on, letters. It also holds the people you add, with a name, a role and, if you enter them, an email address and phone number, and any PDFs you attach. Talus doesn’t read your contacts, calendars or photos.
iCloud
On a device set up as the coordinator, Talus keeps your records in the private database of your iCloud account, so they sync between your iPhone, iPad and Mac. Your midweek meeting day and time sync through iCloud too. Only you can see your private iCloud data; we can’t. Apple stores it under Apple’s privacy policy. If iCloud isn’t available, Talus keeps your records on the device only.
A device set up as the notetaker never uses iCloud. It keeps the meetings sent to it on that device only, and removes each one seven days after the meeting is held (never while its notes are unsent), or seven days after it is archived.
Sending files
Talus never sends anything itself. Agenda and minutes PDFs, .talus files for the notetaker, and announcement and letter text go out only through the share sheet, by the service you choose, such as Messages, Mail or AirDrop. That service carries it under its own terms.
If you turn on the file passcode, .talus files are encrypted with AES-GCM using a key made from your passcode. The passcode is saved in the Keychain on your device and is never put in the file. A notetaker’s device saves the passcode for each meeting in its own Keychain, and deletes it when the meeting is removed.
The web notetaker
notes.talus.mov lets a notetaker without an Apple device open a .talus file in a browser. The page is a single file with no server code. Its security policy stops it from making any network connection, so the agenda, the notes and the passcode never leave the browser. They are kept in that browser’s storage until the meeting is cleared, by the same seven-day rules as the app, or until Settings › Remove everything is used. The page is hosted by Cloudflare, which, like any web host, handles the request when the page is loaded; we have turned off request logs and analytics for it.
Face ID and Touch ID
If you turn on Lock with Face ID (or Touch ID, or Optic ID), Talus asks your device to check that it’s you. The check happens on your device; Talus never sees your face or fingerprint data.
Links
A link you add to an announcement opens in your browser when you tap it, under that site’s own policy. Talus doesn’t fetch it.
Settings
Your choices, such as whether this device is the coordinator or the notetaker, the congregation name and whether the lock is on, are saved on the device. Only the midweek meeting day and time sync through iCloud.
What Apple may collect
Apple handles the download and, if you have agreed to it in your device’s settings, may share anonymous crash and usage reports with developers. That is governed by Apple’s privacy policy. Email you choose to send us reaches us with whatever you put in it; we use it only to answer you.
Children
Talus is made for adults and collects nothing from anyone, including children.
Changes and contact
If this policy changes, the new version will be posted here with a new date. Talus is made by Pronghorn Labs, part of Prairie Fire, LLC, in Colorado. Questions: hello@pronghornlabs.net.