Privacy Policy
Last Updated: September 2026
This Privacy Policy explains how Caffeinated Math, an umbrella of HJJB, LLC (“we,” “us,” or “our”), handles information when you use webRios (“the App”).
1. Summary
webRios processes all R code, scripts, and data on your device. We do not collect, transmit, or store your code or computation results.
2. What We Don’t Collect
We do not collect:
- Your R code or scripts
- Your data files or computation results
- Your plots or visualizations
- Your variable names or values
- The contents of your files
All R computation happens locally on your device. We have no access to what you write or run.
3. What We May Collect
Device Information
When you use the App, we may collect basic device information for compatibility and support purposes:
- Device type and model
- iOS version
- App version
Crash Reports
If the App crashes, anonymous crash reports may be sent to help us improve stability. These reports contain technical information about the crash but not your code or data.
Analytics
We may use Apple’s App Analytics to understand general usage patterns. This data is aggregated and anonymized by Apple before we receive it.
4. Tracking
We do not use advertising identifiers, do not participate in ad networks, and do not track your activity across other apps or websites. The App does not request permission through Apple’s App Tracking Transparency framework because there is nothing to track.
5. Third-Party Services
R Package Repository
When you browse or install R packages, your device connects directly to the webR package repository (repo.r-wasm.org). We do not intercept, relay, or log these requests. The App keeps a copy of the package list on your device and checks the repository for a newer one at most once a day. The one-line package descriptions shown in Browse are bundled with the App, so looking at them contacts no one.
Network Requests From Your R Code
R code you run can make network requests, for example with the httr2 package. By default, these go directly from your device to the sites your code contacts, through a proxy that runs inside the App. We do not intercept, relay, or log them.
If you choose the public proxy in Settings → R Session → Network, or allow it as a fallback, those requests instead pass through a public proxy service hosted at r-universe.dev, which we do not operate. That service can see your device’s IP address and the addresses of the sites your code contacts, and it can read requests that are not encrypted (http rather than https). Its operator’s own terms and privacy practices apply. The App tells you when it falls back to the public proxy.
Interactive Plots
Interactive plots from packages such as leaflet and plotly are small web pages, and they can load content from the internet when you open them. A map, for example, downloads its tiles from the tile server the package names, and that server sees your device’s IP address and the area you are looking at. This happens as soon as you open the plot, and the network setting in Settings → R Session → Network does not cover it.
iCloud Drive Sync
If you use the iCloud sync feature in Settings, your R scripts are copied to and from your iCloud Drive. Apple handles iCloud storage and transfer. See Apple’s iCloud security overview.
GitHub Gist Export
The Editor can publish a file as a GitHub Gist. This sends your code to GitHub using a personal access token you provide. Before you export, the App asks GitHub which account the token belongs to and shows it, so you can see where your code will be published. We do not store or relay the token or the code. See GitHub’s Privacy Statement.
Send Feedback
The feedback form in Settings sends your message to our support email, along with a summary of your app settings and any diagnostic logs you leave switched on. The settings summary lists your settings, how many files are in the current project, and the names of your installed packages; it contains no file names and no code. You can preview everything before sending, and switch any of it off. This is the only feature in the app that transmits information to us directly. We use it solely to diagnose issues and improve the app.
Photos
Sharing a plot and choosing Save Image adds it to your photo library. iOS asks your permission the first time. The App asks only to add images, never to read your library.
Files You Open in the App
When you open a file in webRios from another app, the App reads it on your device. A file sent from Mail or Messages is moved into your current project; a file elsewhere, such as in iCloud Drive, is read where it is and not copied. Nothing is sent to us.
Apple Services
As an iOS app, standard Apple services may apply, including App Analytics and crash reporting. See Apple’s Privacy Policy for details.
6. Data Storage and Security
Your R scripts, data files, and app settings are stored in the App’s sandboxed storage on your device. This data:
- Remains on your device, unless you send it somewhere yourself
- Is never sent to us, apart from the settings summary and logs you choose to include in a feedback message
- Is deleted when you uninstall the App
- May be included in iCloud backups if enabled
Your R scripts and data files are visible to you in the Files app, under webRios. The App also keeps working copies you will not see there: autosaved editor tabs, your execution history, pinned plots (each with the line of code that drew it), a copy of the R package list, and error logs. Deleting a script in the Files app does not remove those copies. Uninstalling the App removes everything.
iOS Spotlight Search
So that you can find your scripts from the home screen, the App gives iOS’s search index a copy of the first 10 KB of each .R, .Rmd and .qmd file, along with its name and the function and package names it mentions. iOS holds that index on your device and uses it to answer your own searches. It is not sent to us, and it is not published anywhere.
Entries are added or refreshed when the App starts and whenever you save, create, rename or move a file. Deleting a file inside the App removes its entry; a file deleted elsewhere, such as in the Files app, leaves an entry that is removed when you tap it, or expires on its own 30 days after it was written. Uninstalling the App removes them all. There is currently no setting to turn this off.
7. Data Retention
We do not retain user data on our systems. Feedback messages are kept only long enough to act on. Crash reports and analytics data processed through Apple are subject to Apple’s data retention policies.
8. Children’s Privacy
The App is intended for users aged 18 and older. The App does not contain adult content. This requirement exists to avoid any risk regarding data from minors. Because all computation and storage happens entirely on your device, we do not collect information from any user, regardless of age.
9. Your Rights
Since the App does not collect personal data, most data rights can be exercised directly on your device by managing or deleting your files. Uninstalling the App removes all locally stored data.
California residents: We do not sell or share personal information as defined under the California Consumer Privacy Act (CCPA/CPRA).
EU/EEA residents: If you have questions about your rights under the General Data Protection Regulation (GDPR), contact us at the address below.
10. Changes to This Policy
We may update this Privacy Policy occasionally. Changes will be reflected in the “Last Updated” date at the top of this page and communicated through App Store update notes for significant changes.
11. Contact Us
For privacy-related questions, contact us at support@caffeinatedmath.com.
Published by Caffeinated Math, an umbrella of HJJB, LLC.