Privacy
What we hold, and what we refuse to
Short version: there is no account, no name, no email, no advertising identifier, and no third-party analytics. Nothing recorded on your phone leaves it unless you decide it should.
What a seat is
A seat is an opaque random token stored on your device. It is not derived from your phone number, your email, your device identifier, or anything else about you, and it cannot be reversed into any of those. Two seats cannot be linked to the same person by us.
What the app stores on your device
- Your seat token, in the operating system's secure storage.
- The measured offset between your phone's clock and real time.
- Which UTC zone you said you would be standing in.
- Whether you have armed the moment, and the scheduled local alarm.
All of it is removed when you uninstall the app. None of it is a personal identifier.
What we never collect
- Your name, email address, or phone number.
- Your precise location. The app asks which UTC zone you will be in — a choice you make from a list of twenty-four, not a coordinate.
- Advertising identifiers, cross-app tracking, or third-party analytics SDKs.
- Who you sent an invite to. Sending a code opens your own share sheet; the invite is spent when somebody claims it, and the only thing that returns to you is a count.
The microphone, stated carefully
Recording is not in the current build at all. The permission is not requested and the capture code is not shipped. When it is added, these are the rules it will be built to, and they are already written into the codebase as the contract any implementation has to satisfy:
- Asked for separately, in its own words. Arming the moment is never treated as consent to record.
- A fixed six-second window, stopped in code rather than by a timer the interface is trusted to honour.
- Stored on the device only. There is no automatic-upload setting to get wrong.
- Nothing is uploaded unless you have listened back to it and then chosen to upload it.
The bystander problem
This is the part that deserves a straight answer rather than a paragraph of boilerplate. A six-second recording made in a public square captures the voices of people who never installed this app, never agreed to anything, and cannot be asked afterwards.
Our position: recordings stay on the device by default, precisely because that keeps the question from arising at all. Any public archive of captured audio will be made of individually cleared submissions — a person deciding, after hearing their own recording, that this specific one may be published — rather than bulk aggregation of whatever the microphones picked up. If that standard cannot be met for a given recording, it does not go in the archive.
If you believe a published recording contains you and you did not agree to it, write to hello@manouri.ovh and it will be removed. You do not have to explain yourself or prove anything.
This website
No cookies are set and no analytics run. Web fonts are loaded from Google Fonts, which means Google's servers see the request — if that matters to you, a font-blocking extension breaks nothing here.
Your rights
Under the GDPR you may ask what is held about you, ask for it to be deleted, and complain to your national supervisory authority. Because a seat is an anonymous token, in most cases the honest answer to “what do you hold about me” is “nothing that identifies you” — and deleting the app deletes the rest. For anything else, write to hello@manouri.ovh.
Last updated 24 August 2026. Material changes will be dated here, not quietly edited.