Privacy is part of the build
An app knows a lot about the people who use it: their habits, their health, their plans. At CodeWave, deciding what an app is allowed to know is a design decision, made at the start of every project and checked until release.
Why it matters
People install an app to get something done, not to hand over their data. Respecting that is fair to users, and it also makes better software.
Trust
Users keep the apps they trust. A clear answer to “where does my data go?” is part of the product.
Less risk
Data that is never collected cannot leak, be stolen or be misused. Less data also means less to secure and maintain.
The law
The RGPD requires data protection by design and by default. Building it in from day one costs far less than fixing it later.
Six rules for every app
These apply to every app CodeWave builds, whatever it does.
Collect the minimum
Before a field is added, it must answer one question: which feature breaks without it? If none does, it is not added.
Device first
Data is written to the phone first and the app works offline. It goes to a server only when a feature, like sync or sharing, needs it.
Encrypted and locked down
Encrypted connections everywhere, and server rules so each person can only read their own data or what was shared with them.
No hidden trackers
No advertising identifiers and no third-party analytics that follow people across apps. Crash reports carry no personal data.
Real consent
Anything optional is off until the user turns it on. Saying no is as easy as saying yes, and can be changed at any time.
Plain language
The app and its privacy policy say what is collected and why, in words anyone can read, not in legal jargon.
Where data lives
Data that only you need stays on your phone. Data you choose to share is synced over an encrypted connection, and only the people you choose can read it.
| Kind of data | By default | Why |
|---|---|---|
| Health and sensitive data | Device only | Too personal to leave the phone. Opt-in, never synced. |
| What you create (notes, lists…) | Device first | Synced only if you sign in or share it. |
| Account email | Server | To sign in. Never used for marketing without consent. |
| Location, contacts, ad identifiers | Not collected | Unless a feature you start really needs it, and only for that. |
Privacy at every stage
Privacy is not a final check. It has a task in each stage of the project.
- DesignMap every piece of data: what, why, where it is stored, how long it is kept.
- BuildReview each library and SDK before adding it. Write access rules on the server.
- TestAutomated tests check that one user can never read another user’s data.
- ReleaseAccurate App Store and Google Play privacy labels, and a readable privacy policy.
- RunDelete data on schedule, and review the data map when a feature changes.
Your rights, built in
Under the RGPD you can see, export, correct or delete your data. In CodeWave apps, export and account deletion are buttons in Settings, not an email to send and wait on.
For client projects
I bring the same method to client work: a data map at the start of the project, a review of every SDK before it is added, and documentation your DPO can use for the processing register.