What We Stand For: Privacy as an Engineering Constraint
By Sanctum Labs Inc. ·
TL;DR — We use anonymized, aggregated analytics to know if our products work — not who's using them. No personally identifiable information (PII), no third-party tracking SDKs, no behavioral profiles. All user data is encrypted — no single system, including ours, can connect your identity to your activity. We will never sell your data or use it for advertising.
Almost every app you install wants to track your activity — across other apps, across websites, across your device. We take a different approach. We use anonymizedThe process of removing personal details so that data can no longer be linked back to a specific person. analytics strictly to assess whether our products are working as they should — but we never collect PIIPersonally Identifiable Information — data that can identify a specific person, such as name, email, phone number, or device ID., never track across apps, and never request or store data we don't need.
The industry default
A 2022 Oxford University study (opens in a new tab) analyzed 24,000 apps across iOS and Android and found that 90% of Android apps and over 60% of iOS apps share data with Google-owned tracking companies. A separate 2023 study (opens in a new tab) found that nearly half of popular apps contact third-party tracker domainsServers operated by companies other than the app developer, used to collect user data for advertising, analytics, or profiling. even when the user hasn't given consent. Most of this is buried in privacy policies that, in a landmark 2008 study (opens in a new tab), researchers at Carnegie Mellon estimated would take the average person 76 workdays per year to actually read. Cisco's 2024 global survey (opens in a new tab) of consumers across 12 countries found that 75% won't buy from a company they don't trust with their data — yet only 53% are even aware their country has privacy laws.
When Apple gave users a simple choice — "Allow this app to track your activity across other companies' apps and websites?" — US tracking rates dropped from 72.63% to 17.90% (opens in a new tab), with similar declines across 18 other countries studied. The demand for privacy was always there. The industry just never asked.
Why tracking is a problem
Most people assume tracking means seeing ads for shoes you browsed once. The reality is far worse. Apps can collect your precise GPS location, contacts, browsing history, health data, and device identifiersUnique codes assigned to your specific device — like a digital serial number — that can be used to recognize it across apps and websites. — and share all of it with third parties you've never heard of.
That data doesn't stay safe. In January 2025, a massive data breach hit location data brokerCompanies that collect and sell personal information about consumers — often without their knowledge — to other businesses. Gravy Analytics (opens in a new tab), exposing tens of millions of precise phone coordinates collected from apps like Tinder, Candy Crush, MyFitnessPal, and Muslim prayer apps. Most of these apps didn't even know Gravy was collecting the data — it was siphoned through the advertising ecosystem (opens in a new tab) without the developers' consent.
In 2024, the FTC banned data broker X-Mode (opens in a new tab) from selling sensitive location data harvested from ordinary apps — data that had previously been used to track US military personnel (opens in a new tab) moving between bases, homes, and off-site locations. It's not just a US problem. That same year, Italy's data protection authority fined food delivery platform Foodinho €5 million (opens in a new tab) for tracking the GPS location of over 35,000 delivery riders — including when they weren't working — and sharing that data with third parties without their knowledge.
Even when users opt out, it doesn't always work. After Apple introduced App Tracking Transparency, some developers turned to device fingerprintingA tracking technique that combines device characteristics — model, screen size, installed fonts, OS version — to create a unique identifier, even without cookies or login. (opens in a new tab) — using device model, screen resolution, installed fonts, and network information to identify users without their consent. Apple banned the practice and introduced Privacy ManifestsFiles that Apple requires app developers to include, declaring what data their app collects and which third-party code it uses to access information. in 2024, but companies, including Meta and Spotify (opens in a new tab), were found breaking the rules almost immediately.
This is the core problem: when your data is collected, you lose control of where it ends up. It doesn't matter how trustworthy the app seems — once data enters the ad-tech pipeline, it can be aggregated, sold, breached, or misused in ways nobody anticipated.
What we actually collect
We're not anti-data. We're anti-surveillance. Here's the line we draw:
What we collect:
- Crash reports: We know when something breaks, but not who experienced it.
- Performance diagnostics: We monitor app launch times, error rates, and frame render performanceA measure of how smoothly the app's animations and interface move on your screen..
- Data sanitization: All diagnostics are stripped of personally identifiable information before they leave your device.
What we never collect:
- Extraneous data: We never collect anything that isn't required for a feature to function or for us to maintain the product.
- Tracking identifiers: We never use device identifiers for the purpose of tracking you.
- Behavioral profiles: We don't build a model of who you are or what you do.
How we enforce this:
- Identity-activity partitioningA design approach that keeps your identity (who you are) and your activity (what you do) in separate systems so they can never be combined.: Our architecture ensures that identity and activity data are never stored together, so no single system — including ours — can connect who you are to what you do.
- No ad-tech SDKs: We don't use third-party analytics SDKsSoftware Development Kits — premade building blocks of code that developers add to their apps. These often send your data back to the company that created them. that feed the ad-tech pipeline described above. Where we use third-party services for other functionality, we vet them carefully and ensure no PII is shared without your consent.
- AggregatedCombining individual data points into group-level summaries so that no single person's behavior can be identified. diagnostics: We see trends across all users, never individual sessions.
- Opt-in reporting: Crash reports require your approval — you review what's shared before anything is sent.
The result: we know if a feature is working. We don't know who is using it.
The trade-off
This approach has real costs. We can't show you ads tailored to your behavior. We can't sell audience insights to third parties. We can't build a profile of your habits to predict what you'll do next. These are the growth levers most apps rely on — in-app advertising alone reached $390 billion in 2025 (opens in a new tab), much of it powered by behavioral targetingServing ads based on a user's tracked behavior — like browsing history and app usage across different websites and apps — rather than just what they're looking at right now..
That's a deliberate choice. We'd rather build privacy-first products that earn your trust than optimize for metrics that require your surveillance. And because of our partitioned architecture, a breach of our systems wouldn't expose your personal information.
Our commitment
Your data is not our business model. We will never sell your data or share it with advertisers. We will never collect more than what's needed to keep our products working.
As our products evolve, so might the data we need to maintain them. If it does, you'll know — we'll publish exactly what we collect, how it's used, and why. No fine print, no legalese, no surprises. You can read our full Privacy Policy at any time.