Storage Architecture

On-Device by Default

Trip logs, GPS traces, and vehicle telemetry stay on your phone. We operate no user database.

Data Lifecycle

90-Day Tokenization

Place names are stripped and converted to meaningless tokens after 90 days; deleted at 400 days.

Business Model

Zero Ad Tracking

No advertising SDKs, no behavioral trackers, and no third-party data broker sales. Ever.

Hardware Security

Keychain Isolation

Home and work addresses are sealed in the iOS Keychain, excluded from iCloud and device backups.

01

Scope & Core Principles

Applicability & Ecosystem

This policy governs the Onism commute app, OnismOBD, their iPhone and Apple Watch experiences, interactive widgets, Live Activities, and this website. “Onism,” “we,” and “our” refer to the software developer.

Minimal-Surface Architecture

We engineer software with an aggressive local-first posture: intelligence runs directly on your device, external services use insulating proxy gateways, and personal mobility history is physically protected by Apple hardware.

02

Onism commute data kept on your device

On-Device Commute Telemetry Inventory100% On-Device · 0B Egress
Location & Commute
Current / Recent GPSTrip History LogsSaved Places & PresetsTransfer Slack Buffers
Intelligence & AI
Learned Routine ModelsValidation RecordsNeural Engine ContextCalendar Event Links
Transit Preferences
Station & Line FiltersParking AllocationsMTA Alert PreferencesOffline Route Timetables
Glanceables & Cache
Apple Watch StateInteractive WidgetsLive Activity SessionsCached Maps & Weather

Home & work sealed in Keychain

Stored in the iOS Keychain, marked so they never leave this device, and excluded from iCloud and iTunes/Finder backups entirely.

90-Day Tokenization & 400-Day Erasure

Place names and street addresses are converted to non-reversible tokens at 90 days, and records are permanently erased at 400 days.

Zero-Egress Apple Intelligence

Writes plain-language summaries on-device via Apple Neural Engine. Zero prompts or trip data leave your physical device.

Offline Timetables & Cache

Complete MTA schedules ship inside the application binary and run offline with local route validation caches.

03

OnismOBD data kept on your device

On-Device OBD Telemetry InventoryIsolated on Hardware · Local Core Data
Vehicle Profiles & State
Vehicle Profiles & VINTrouble Codes (DTCs)Sensor Freeze FramesI/M Readiness Monitors
Trip & Telemetry Logs
Timestamped GPS RoutesCAN-Bus Telemetry TracesFuel Economy (MPG)Service & Maintenance Logs
On-Device Copilot
Ask My Car Chat HistoryTelemetry SummariesDiagnostic Model NotesCustom ECU PIDs
Glanceables & Playback
Compressed Drive ReplaysLock Screen WidgetsDynamic Island GaugesCached Ambient Weather

Without adapter, Bluetooth stays off

In phone-only mode the app never activates the Bluetooth radio. Zero battery draw, zero radio broadcast.

Ask My Car uses bounded summaries

Answers execute on-device from snapshot summaries with a hard evidence cap. Precise GPS route traces are never exposed.

Shared clips hide start & end zones

Exported drive recordings automatically mask coordinates surrounding your home, garage, and workplace by default.

Air-gapped mechanic reports

DTC trouble codes, freeze frame snapshots, and I/M readiness monitors are compiled into PDF reports 100% offline.

04

Optional private iCloud sync

Onism Commute Sync

Syncs saved routes, presets, places, and favorites across your own devices. Home/work addresses and learned routine profiles are strictly excluded and never leave the device.

OnismOBD Vehicle Sync

Syncs preferences, vehicle profiles, fuel logs, and service history through your personal Apple iCloud account. Large drive-replay telemetry archives are strictly excluded.

05

What leaves your device

Transit schedules & status

Timetables ship inside the app. Live departures and delays fetch directly from the MTA carrying standard HTTP metadata only. No location, routes, habits, or identifiers are transmitted.

Apple platform services

Map rendering, walking directions, geocoding, and calendar lookups use native Apple APIs governed by Apple's privacy policy. Sign in with Apple identities remain sealed in local Keychain.

Weather Gateway at onism.ai

To look up ambient conditions, Onism sends sanitized requests to the dedicated Onism Weather Gateway at https://onism.ai/api/weather.

Gateway Privacy Specifications
  • Rounds coordinates to 4 decimal places (~11m city-block resolution) before forwarding;
  • Holds weather provider API keys strictly server-side, never inside app binaries;
  • Returns only temperature, condition codes, observation timestamp, and unit system;
  • Applies strict cache: no-store and private, no-store headers;
  • Zero database persistence: coordinates, IPs, and payloads are never logged to disk.

Optional Owner-Controlled Live Dashboard

Disabled by default until you pair a personal server URL and token. Telemetry streams directly and exclusively to your private server. Onism never receives, routes, or stores this data.

06

Website Data

Our public pages operate with zero ad networks, zero tracking pixels, zero cookies, and zero cross-site profiling. Standard edge transport logs are processed strictly for security and rate limiting.

07

Retention & Deletion

You retain full data sovereignty: trigger Reset Learning, Erase Commute History, or Delete All My Data at any time. All local trip history auto-purges at 400 days.

08

Security & Policy

Engineered with HTTPS encryption, server-only credentials, bounded API schemas, and strict child privacy protection. Any material updates are highlighted in upcoming release notes.

Questions about your data?

Privacy inquiries & verification.

If you have any questions about how Onism processes data or wish to verify on-device retention, write to us directly.