Privacy Policy
We set no cookies of our own. We use cookieless analytics, keep scrubbed error reports, and relay contact messages without saving them in our database.
Effective 8 September 2026.
Who we are
Numen Technologies Limited operates numen.ie and is the data controller for the processing described here.
Numen Technologies Limited
Work Hub, 77 Camden Street
Dublin D02XE80
Ireland
Registered in Ireland with CRO number 677823.
For any privacy question or request, write to us at [email protected].
What this policy covers
This policy covers numen.ie, our corporate site, including the contact form and the server endpoint Apple calls to select retention messages for Slop or Not subscriptions. The apps have their own policies.
Each app has its own site and its own privacy policy, since each one processes different data in different ways. For an app's data practices, read its policy directly:
This policy also does not cover other companies. When you follow a link from this site to somewhere else, that site runs under its own privacy policy.
The contact form
If you write to us through the form on the contact page, you send us your name, your email address, and your message. There is nothing else on the form.
Our API does not save form submissions to its database. The message is relayed to our mailbox by our email delivery provider, and it then lives in our mail account for as long as we need it to answer you.
The form is protected by Cloudflare Turnstile, so Cloudflare receives the connection data it needs to tell a person from a bot, and by a per-IP rate limit.
The Discord badge
The contact page shows how many people are currently online in our Discord community. Your browser asks the one per-page endpoint every Numen site calls, which also tells our other sites whether to ask before creating an analytics identifier; this site does not use that part of the answer, and creates no such identifier for anyone. Nothing about you is sent to Discord, and the badge works the same whether or not you have a Discord account.
If you click through and join the community, that happens on Discord's servers under Discord's own privacy policy, not ours.
Analytics
We measure how the site is used with an analytics tool we host ourselves on our own infrastructure and serve from our own domain. There is no Google Analytics, no tag manager, and no advertising pixel anywhere on this site.
It sets no cookies and builds no cross-site profile. It records page paths, the query string an inbound link carries (including campaign tags and advertising click IDs), referrers, your browser, operating system, device type, screen size, browser language, and an approximate location down to city level, derived from your IP address. It also records named events such as a link click.
Your IP address is processed transiently to derive that approximate location and the daily-salted hash that groups a visit. It is not stored.
The legal basis is our legitimate interest in understanding how our own site performs. We weighed that against your interests and concluded it is proportionate: the measurement is first-party, cookieless, content-free, confined to this one site, and never shared with an advertising network.
Error reports
When something on the site breaks, your browser can send an error report to an error tracker we also host ourselves. The report describes the failure so we can fix it.
Before a browser error report is stored, query strings are stripped from URLs and identifiers are removed. The legal basis is our legitimate interest in keeping the site working.
The same error tracker also receives performance measurements: ordinary page loads and requests are timed and sent there even when nothing breaks, scrubbed the same way. We use those measurements only to keep the site fast and working, on the same legal basis and with the same handling as the error reports.
Cookies and browser storage
We set no cookies of our own, for analytics, for preferences, or for anything else. There is therefore nothing here to consent to, and no consent banner.
Our CDN, Cloudflare, may set a short-lived cf_clearancecookie if it has to challenge suspicious traffic. That is a security measure to protect the site, not tracking, and it is listed in the table below with everything else.
The table below is the complete list of what keeps state in your browser on this site. None of it tells us who you are:
| Name | Type | Purpose | Duration |
|---|---|---|---|
| Theme preference | Local storage, first-party | Remembers whether you chose the light or the dark theme. | Until you clear it |
| Cloudflare Turnstile | Third-party security challenge | Tells a person from a bot on the contact form. Turnstile keeps its own short-lived state in your browser while the check runs. | Per challenge, set by Cloudflare |
| cf_clearance | Cookie, set by Cloudflare | Appears only if Cloudflare has to challenge suspicious traffic, so that a visitor who passes the challenge is not asked again. It protects the site; it does not track you. On an ordinary visit it is never set. | Short-lived, set by Cloudflare |
We do not embed third-party video or social widgets on this site. If we ever do, the embed will not load until you click it.
Why we process data, and on what legal basis
| What we do | Data involved | Legal basis (GDPR) |
|---|---|---|
| Select an App Store retention message for a Slop or Not subscription | Subscription transaction identifier, app and product identifiers, locale, request identifier, environment and signing time supplied by Apple | Article 6(1)(f), our legitimate interest in providing subscription information and checking message delivery |
| Answer a message you sent us | Name, email address, message | Article 6(1)(b) and Article 6(1)(f), answering your request |
| Block bots and keep the contact form available | Connection data processed by Cloudflare Turnstile, and a per-IP rate limit | Article 6(1)(f), our legitimate interest in a form that survives abuse |
| Measure how the site is used | Cookieless, content-free page and event data | Article 6(1)(f), our legitimate interest in improving our own site |
| Diagnose errors | Error reports and performance measurements with query strings stripped from URLs and identifiers removed | Article 6(1)(f), our legitimate interest in a working site |
| Meet legal obligations, including accounting and tax | Records our accountants and the law require | Article 6(1)(c), legal obligation |
App Store subscription messages
When you view your Slop or Not subscription details in your Apple Account, Apple can send our server the subscription's original transaction identifier, app and product identifiers, locale, a request identifier, the server environment and signing time. We verify Apple's signature and return a message identifier for Apple to display if you select Cancel Subscription. We select the message by product and locale, without building a subscription profile or storing the transaction identifier.
We record the verified request identifier, environment, product, locale, response status and processing time in diagnostic server logs. The signed request and subscription transaction identifier are not included in those logs. The request is processed in memory and is not saved in a database. Apple does not send us your payment details through this endpoint.
Who else is involved
We keep as much as possible in our own hands. Our analytics, our error tracking, and our databases are all operated by us, not bought as a service, so they are not third parties receiving your data.
These providers process data on our behalf:
- Our hosting provider - runs our servers.
- Cloudflare - DNS, TLS, content delivery, Turnstile, and encrypted off-site backup storage (R2).
- Our email delivery provider - delivery of messages sent through the contact form.
Apple operates the App Store and handles the subscription messaging described above under its own privacy policy. We return only a message identifier to Apple; we do not send it our diagnostic logs.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models. We disclose data to a public authority only where the law requires it.
How long we keep things
We keep little:
- Contact form submissions: never written to a database. The message ends up in our mailbox and stays there for as long as we need it to deal with your request.
- Analytics: kept indefinitely as event records. Our analytics groups a visit using a hash that is re-salted every day, so there is no identifier that follows you from one day to the next, and the IP address the hash is derived from is not stored. Where an inbound link carried an advertising click ID, that ID stays part of the recorded URL.
- Error reports and performance measurements: kept while they are useful for fixing the fault or keeping the site fast, with query strings stripped from URLs and identifiers removed before they are stored.
- App Store retention requests: the signed request and transaction identifier are processed in memory and discarded. Diagnostic server logs retain the verified request identifier, environment, product, locale, response status and processing time. The endpoint does not automatically delete these log entries; their retention depends on the server logging configuration.
Our servers are backed up nightly to encrypted off-site storage. Those backups can contain the analytics and the scrubbed error and performance records described above. The API does not save contact submissions in its database, but messages remain in our mailbox and follow that mail system's retention and backup process.
International transfers
We are an Irish company. The cloud servers that run this site and its API are hosted in the European Union. Some of the providers listed above are established in the United States and may process data there or in other countries.
The safeguard for each transfer depends on that provider's arrangement: either an adequacy decision or the European Commission's standard contractual clauses, as required by Chapter V of the GDPR. Contact us if you need the current details for a particular provider.
Apple's handling of subscription information, including international transfers, is described in itsPrivacy Policy.
Security
Traffic to the site is encrypted in transit. Backups are encrypted. Access to production systems is limited to the people who need it.
If we ever suffer a breach that puts your rights at risk, we will notify the Irish Data Protection Commission and, where the law requires it, you.
Children
This is a company website. It is not directed at children, and we do not knowingly collect personal data from children. If you think a child has sent us personal data through the contact form, write to [email protected] and we will delete it.
Your rights
Which rights you have depends on where you live. To exercise any of them, write to [email protected]. We answer within the time the applicable law allows, and there is no charge. We may ask you for enough information to be sure the request is really yours, and no more.
One limitation: we hold little information about you. We may hold support messages, cookieless analytics records, scrubbed website error reports, and App Store request diagnostic logs, but the contact API does not save submissions in its database. If we cannot find data that identifies you, we will tell you so rather than invent a match.
European Union and European Economic Area (GDPR)
You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing that already happened.
Where we rely on legitimate interests, you can object on grounds relating to your particular situation, and we will stop unless we have compelling grounds that override yours.
Our lead supervisory authority is the Irish Data Protection Commission. You can complain to it, or to the authority in the country where you live. The list of national authorities is published by the European Data Protection Board.
United Kingdom (UK GDPR and Data Protection Act 2018)
You have the same set of rights described above. You can complain to the Information Commissioner's Office at ico.org.uk.
United States state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to know what personal information we collect, to get a copy of it, to have it deleted, to correct it, and not to be treated worse for exercising those rights. Not every right exists in every state.
We do not sell personal information and we do not share it for cross-context behavioral advertising, in any state. Because there is no sale or sharing to stop, a Global Privacy Control signal has nothing here to opt you out of. We do not use sensitive personal information to infer characteristics about you.
To exercise a state right, write to [email protected]. If we cannot verify a request, we will say so and explain why.
Canada (PIPEDA)
You can ask what personal information we hold about you, how we use it, and who we disclose it to, and you can ask us to correct it. You can complain to the Office of the Privacy Commissioner of Canada.
If you are in Quebec, Law 25 gives you further rights, including rights around automated decisions and data portability. We do not make automated decisions that produce legal effects about you.
Brazil (LGPD)
You have the right to confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about with whom we share data, and revocation of consent. You can complain to the Autoridade Nacional de Proteção de Dados.
India (Digital Personal Data Protection Act 2023)
You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance route. Send grievances to [email protected], which is our contact point for this purpose.
Changes to this policy
We update this policy when what we do changes. The effective date at the top always tells you which version you are reading. We keep a full revision history of this page, and we will share the relevant changes on request.
We do not ask you to click a box accepting it.
Contact us
Privacy questions, requests, and complaints all go to the same address: [email protected]
The terms that govern your use of this site are in our Terms of Use.