Bit | Privacy Policy

Effective date: 10 August 2026 Last updated: 10 August 2026 Version: 2026-08-10

The short version

Bit is a soundboard for iMessage. You record short clips, keep them on your phone, and send them to friends.

Your recordings never reach our servers. Not when you record them, not when you save them, not when you send them. There is no Bit account for ordinary use, no advertising, and no tracking across apps or websites.

Audio can leave your device only through Apple services you direct: your private CloudKit database for sync and an attachment to a Messages recipient. It never reaches a Bit server. Separately, Bit can send pseudonymous, installation-scoped usage events to PostHog (which you can turn off in Settings), StoreKit communicates with Apple for purchases, and a report you choose to submit sends information about a sound to Bit without sending the audio. If you contact support in the app, Bit sends the topic, message, reply email, app and iOS versions, and any screenshots you choose to attach to our support inbox.

Who we are

Bit is operated by One Percent Studios LLC, a California limited liability company.

For privacy questions, contact privacy@onepercentstudios.net. See Contact for the safety and copyright channels.

What stays on your device

Everything you create in Bit is stored locally on your iPhone, in a container shared between the Bit app and its iMessage extension:

The app and Messages extension share this data through Bit's App Group container. The policy-acceptance record is excluded from device backups so a restored installation must accept the current policies again. It is not sent to Bit or PostHog. We cannot see the rest of this local library data. There is no Bit server-side copy and no mechanism for us to request one.

iCloud backup and sync

If you're signed into iCloud, Bit syncs your sounds to your own iCloud private database so they survive a lost phone and appear on your other devices.

This uses Apple's CloudKit private database, which means the data lives in your personal iCloud account under your Apple ID. One Percent Studios cannot read it. We have no access to your private database: not the audio, not the names, not the arrangement. Apple's handling of that data is governed by Apple's Privacy Policy.

You can stop this at any time by turning off iCloud for Bit in iOS Settings.

Sending sounds to friends

When you send a sound in Messages, the audio travels as an ordinary iMessage attachment, directly from your device to your recipient's, over Apple's infrastructure. It does not pass through, and is not copied to, any Bit server.

A small amount of information travels inside the attachment file so the receiving copy of Bit knows what it's looking at: an identifier for the sound, its name and duration, and a one-way fingerprint (described below). The receiving copy of Bit uses this metadata to preserve the sound's identity. Like metadata in any file, it may also be inspectable by someone with access to the attachment and compatible tools.

Once you send a sound, your recipient has a copy. If they save it, that copy is theirs and lives on their device. We cannot delete it, and neither can you. It is the same as any photo or file you send someone.

If you report a sound, from either the app or the Messages extension, we receive, and store on our servers:

What Why
The sound's identifier and its one-way fingerprint To match other copies of the same sound
The sound's name, duration, and how it was created To review the report
The category you chose (copyright, privacy/voice consent, harassment, hateful or sexual content, other) To route and prioritize
Any description you type To understand the complaint
Your email address, only if you choose to enter one To follow up with you
Whether the report came from the app or the Messages extension To reproduce the context

We never receive the audio. No report path uploads the recording.

About the fingerprint

The fingerprint (originHash) is a SHA-256 hash computed over a normalized version of the audio. It is one-way: it cannot be reversed into audio, and it tells us nothing about what the sound contains. Its only purpose is to recognize when two devices hold copies of the same recording, so that an actioned report can stop that specific sound from spreading further inside Bit.

Bit publishes a list of restricted fingerprints, which the app downloads periodically. That request carries no account and no device identifier. Like every internet request it does disclose your device's IP address to our server; we use it in application memory to rate-limit abuse, normally for at most one minute. There is no IP address column in Bit's database.

The one exception is diagnostic: when we move the API to new infrastructure, we briefly log the raw connection details of incoming requests, including IP addresses, so we can confirm the rate limiter is identifying callers correctly rather than lumping everyone together. Getting this wrong would let one caller degrade the service for everybody, and it cannot be verified any other way. The window is short, it is switched off again immediately afterwards, and those logs age out on our host's normal retention schedule rather than being copied into our database.

What a report can and cannot do

If we action a report, Bit will refuse to save or send that sound going forward. It cannot delete copies already on people's devices, and it cannot reach into Messages conversations. This is a limitation of the design, not a policy choice. See the takedown runbook.

Formal statutory copyright notices should go to our published copyright contact (copyright@onepercentstudios.net) rather than through the in-app report, which is a preliminary review channel.

Contacting support

The in-app Contact Support form sends the topic you choose, the details you type, your required reply email, and your Bit and iOS versions to our monitored support inbox. You may also choose up to three images from the Photos picker. Bit re-renders selected images before sending them, which removes their embedded metadata and original filenames. The form does not attach sounds, recordings, videos, Messages content, or anything else automatically.

The Bit API validates and forwards the request synchronously through Cloudflare Email Service. It does not save the form or attachments to Bit's database or filesystem. Cloudflare and our email provider process the message to deliver it, and the resulting email remains in our operating mailbox for support follow-up and normal business-record retention. A failed send remains only in the form on your device so you can try again.

Accounts and purchases

Ordinary use of Bit requires no account. There is no sign-up, no login, and no password.

If you subscribe to Bit+, the purchase is handled entirely by Apple through the App Store. We receive no payment details, because Apple never shares them with us, and your subscription status is verified on your device rather than against our servers.

If a future version of Bit offers downloadable sound packs, signing in with Apple will become available for that feature alone. In that case we would store the anonymous identifier Apple provides (never your name or email, unless you choose to share them with Apple's relay) together with a record of what you purchased, so your purchases can be restored. Ordinary recording and sending would remain accountless.

Permissions Bit asks for

Pseudonymous usage data

Bit counts how its features get used so we can tell what's worth building. This is on by default and you can turn it off in Settings → Privacy → Share anonymous usage data. Turning it off also discards anything not yet sent.

What we count: that a sound was recorded, saved, sent, or deleted; which screens were opened; roughly how big your library is, in ranges rather than exact numbers; and your device model, iOS version, locale, and Bit version.

What we never collect, by design rather than by policy: your audio, the names you give your sounds, sound fingerprints, who you message, or what any message says. The events Bit can send are a fixed list defined in code; there is no way to attach free-form text to one, so a sound's name cannot leak into an event even by mistake.

Pseudonymous and not linked to your identity. We never attach a Bit account, Apple sign-in, name, email address, sound identifier, or fingerprint to these events. They carry a random identifier scoped to your device installation so separate events from that installation can be counted together. There is no advertising identifier, no cross-app or cross-site tracking, and no advertising of any kind. Bit shows no App Tracking Transparency prompt because it does not track you across other companies' apps or websites.

Who processes it. Our analytics processor is PostHog, which receives these events on our behalf and stores them in the United States. PostHog is configured to discard client IP addresses rather than store them, and its location-enrichment transformation is disabled. Session recording, surveys, automatic application-lifecycle events, and automatic screen capture are all switched off. Our current PostHog plan retains product analytics for one year. PostHog provides controls to delete an installation's person record and associated events, or to delete the entire Bit project and all its events.

What Bit does not do

How long we keep things

Anything you personally supplied in a safety report, meaning your optional email address, your description, and the reported sound's name, is erased one year after we finish reviewing the report. If a report is somehow never resolved, it is erased two years after you filed it regardless. This runs automatically on our servers every day; nobody has to remember to do it.

What survives that erasure is the impersonal part of the record: the fingerprint, whether the report was actioned, and the dates. We keep that because it is what holds a restriction in place. Deleting it would silently un-restrict a sound that was taken down. It identifies a piece of audio, not a person.

Restricted-fingerprint entries persist for as long as the restriction is in effect. Restrictions are reversible.

Support requests are not stored in Bit's database. They are delivered to our support inbox and retained there only as needed to answer the request, maintain ordinary business records, and resolve any follow-up. You can ask us to delete a support conversation by contacting privacy@onepercentstudios.net from its reply address.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export the personal information we hold about you, and to object to or restrict how we use it.

In practice the personal information we hold about an identifiable person is what they supplied in a safety report or support request: an email address, free-form description, reported sound name, or selected screenshot. To exercise any of these rights, contact us at privacy@onepercentstudios.net and include the relevant case ID or write from the support request's reply address.

Usage events are not tied to your identity, so we generally cannot find "your" events in order to export or delete them. You can stop them being collected at any time from Settings.

Everything else described in this policy lives on your device or in your own iCloud account, where it is already under your control: delete a sound in the app and it is gone from your library; turn off iCloud for Bit and syncing stops.

We do not sell or share your personal information, and we never have. There is no advertising in Bit and no data is disclosed to anyone for advertising.

Bit is currently distributed in the United States only. If we make it available elsewhere we will update this policy first.

Children

Bit is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us with personal information through a safety report or support request, contact privacy@onepercentstudios.net and we will delete it.

Changes to this policy

If we change this policy materially, we will update the effective date and version above. Bit will require you to affirmatively accept the new policy before you can create or send another sound. Declining does not by itself delete sounds already in your library.

Contact

All three route to a monitored inbox.