OneNect

OneNect privacy policy

Last updated: 2 September 2026

Techno Optics LLC, trading as OneNect, is the controller of the personal data described in this notice, except where you use OneNect through an organisation. Where you do, that organisation is the controller of the information it puts into OneNect and of the purposes it chooses there, and we act on its instructions. The section headed "If you use OneNect through an organisation" explains which is which and how to reach yours.

In short

OneNect is a communication and wellbeing app. Techno Optics LLC builds it and runs it. Organisations run it for the people who belong to them: a workplace, a congregation, a club or a household.

OneNect itself is open: anyone can sign up for a personal account and use it with their family and their friends. OneNect Corp, OneNect Faith and OneNect Estate are joined by invitation, from the organisation that runs one. Some screens can be read without signing in, and what is on them depends on the organisation whose OneNect you are reading.

We do not sell your personal data, we do not share it with advertisers, and we do not track you across other companies' apps or websites.

If you use OneNect through an organisation

Your employer, your church, your club or your household may run OneNect for its members. Where it does, it decides which features are available to you, what it asks you for, who inside it can see what, and how long it keeps things. For that information the organisation is the controller and we act on its instructions.

We remain the controller of your account itself: signing in, keeping your session secure, delivering notifications to your device, diagnosing faults, and keeping the service running and safe. Nobody's organisation can switch those off, which is why they are ours. We also choose where OneNect is hosted and which providers we use to run it, which the section headed "Who else handles your data" lists.

To ask about the information your organisation holds, or to exercise your rights over it, contact your organisation. If you write to us instead we will tell you within five working days who to ask, and pass your request on.

What we collect, and why

If you browse without signing in

We do not ask you for anything and we build no profile of you.

Our servers keep the record any web service keeps in order to answer a request and to stay secure: the network address the request came from, and the app or browser version that sent it. Two things go further than that, and we would rather say so than round it down. A screen that orients itself to where you are sends the coordinates your device offers, so that it can answer. If the app hits a fault, an error report is recorded. Legal basis: our legitimate interest in operating a working and secure service.

If you contact us through the app

When you use the "Talk to us" form we collect your name and email address, your topic and message, and the part of the organisation's directory your question is about. You can also give us a phone number and the name of your company or organisation, both optional, if you would rather be called or you want us to know who you are with. The message reaches the people the organisation has chosen to answer that kind of question, by notification, email or text message depending on how each of them asked to be told. Legal basis: your consent, and the organisation's legitimate interest in answering an enquiry.

If you sign in

Account and profile. Name, email address, job title or role, department, office or site, profile photo, and language preference. Where an organisation provisions you through its own single sign on or directory, those details come from it and it decides what they say. Its legal basis is performance of your contract of employment or membership, or its legitimate interest in operating an application for its members.

We are the controller of the account itself: your credentials, your sign in, and the security of your session, including our ability to sign every device out at once. No organisation can switch those off, which is why they are ours rather than its. Legal basis: performance of our terms of use with you, and our legitimate interest in operating a secure service.

Precise location. Only while the app is open, and only if you allow it. We collect your exact coordinates rather than a rounded or approximate position. We do this because a safety alert can be aimed at an area as small as 100 metres across, and because an emergency alert you raise yourself has to tell a responder where you actually are. We use it for three things: to reach you with safety alerts that apply to the site you are at, to pass your position to responders if you raise an emergency alert, and to show relevant local content. We do not track your location in the background, and we do not build a location history: only your most recent position is stored, and each update overwrites the one before it. You can refuse or withdraw this at any time in your device settings, and the app continues to work, though geo targeted safety alerts will not be able to reach you. Legal basis: your consent, and where an organisation runs OneNect for you, its legitimate interest in health and safety.

Step counts. If you turn on step counting, we read the daily step total from your device's motion sensor to power your personal goal. We store a daily total, not a movement trace, not a route, and not continuous activity data. This is optional and off until you enable it. Under GDPR this is health data, so our legal basis is your explicit consent, which you can withdraw at any time by turning step counting off. Withdrawing deletes the daily totals we hold: we do not merely stop adding to them. Your calendar goes back to holding no reading for those days, your figure stops appearing on any challenge or club board, and if you had agreed to show your figure to a step club that agreement ends with it. A score already recorded in a challenge that has finished stays as that challenge's result, because it is a record of a competition rather than a reading of your walking.

Reading today's total from your phone's health record. Your phone keeps a health record of your walking: Apple Health on an iPhone, Health Connect on an Android phone. Reading today's daily total out of that record is a separate choice from step counting, asked for on its own, and off until you turn it on yourself. That includes everybody who turned step counting on before this existed: agreeing to one has never been agreeing to the other, and nobody is opted in by default.

It is worth having if you wear an Apple Watch or a fitness band, or if your phone spends the day on a desk. That walking is recorded by the watch rather than by the phone, so without this your figure here can be far lower than the one your own Health app shows. We read one number per day, the total, and nothing else: never a route, a location, a time of day, a workout, or any other measurement the record holds. We never write anything to your health record.

Leaving it off does not stop your steps. Your phone keeps counting with its own motion sensor exactly as it does now, and your calendar, your streaks, and any challenge or club board carry on. The only difference is that walking your phone did not see is not added in.

Under GDPR this is health data, so our legal basis is your explicit consent, which you can withdraw at any time under Devices & activity in your profile, and the reading stops at once. Unlike step counting, withdrawing this one does not delete the daily totals already recorded. Each of those is a single figure your phone and your health record contributed to together, and there is no way to take only the record's part back out; those days are also held under your step counting consent, which is still live. Your figure goes back to what your phone counts on its own, and if you want the days deleted as well, turning step counting off deletes all of them.

Showing your step figure to other people. Turning step counting on does not show your figure to anybody. Publishing it to colleagues is a separate choice, and there are two ways to make it, each asked for on its own:

Neither choice is retroactive. We publish only the days you walked from the moment you agreed onwards; days walked before that stay private. If you decline, or have not been asked yet, you still appear in the club's member list with your name and photo, as you already do, and carry no step figure. Under GDPR this is health data, so our legal basis for publishing it is your explicit consent.

Where the challenge or the club belongs to an organisation running OneNect, publishing your figure to it is a disclosure to that organisation, which becomes the controller of what it receives from that point and decides what it does with it. That is a different event from us reading your health record, which stays ours, and it is why the two are asked for separately.

Reading your step record while you are not using the app. The choices above say WHAT we read. This one is about WHEN, and it is asked separately because it is a real change rather than a detail.

If you allow it, the app can read the daily step total out of your phone's health record while the app is closed or in the background. Nothing else changes. It is still one number per day, the daily total, and still nothing else: no route, no location, no time of day, no workout or activity type, no heart rate, and no other measurement your record may hold. It is still only your own record, still kept no longer, and still shown to nobody unless you have separately chosen to publish your figure.

We ask for this because a step count that is only correct while you have the app open is not much use. Your phone counts all day; without this, your figure only catches up when you happen to look at it, which is why a figure on a club board can be hours behind what your phone knows.

On an Android phone this is a permission Health Connect asks you for in its own screen, separate from the one that lets us read your steps at all. On an iPhone it is part of the health permission you grant Apple Health. On both, you can withdraw it there at any time without turning step counting off, and the app falls back to reading your figure while you are using it.

Being explicit about the trade, because it is your data and the honest answer matters more than the feature: allowing this means the app looks at your health record at moments when you are not looking at your phone. We think that is worth it for a figure that is right rather than stale, and it is why it is a separate choice you can decline and still use everything else.

Step history already in your phone's health record. Separately, and only if you turn it on yourself, the app can read daily step totals out of the health record your phone keeps: Apple Health on an iPhone, Health Connect on an Android phone. That record is not only this phone's own counting. It can include days from before you installed OneNect, and days recorded by an Apple Watch, a fitness band or another health or fitness app you use, because these stores aggregate what every device and app signed into them has written. So a day we import may be a day this phone never counted, and may have been measured by a device we have no relationship with.

This is a second choice, not part of turning step counting on: counting your steps from today onwards and reading what was already recorded in the past are different things, and we ask for them separately. We read one number per day, the daily total, and nothing else - no route, no location, no time of day, no workout or activity type, no heart rate, and no other health measurement your record may hold. We do not read which device or app recorded a day, beyond storing which health store the figure came from. We read back as far as the start of the previous calendar year and no further, matching how long we keep step totals at all. On Android, Health Connect normally limits an app to the last 30 days unless Google has separately approved deeper access, so less is usually available there. A day your record holds nothing for is left blank rather than recorded as a zero.

Imported days are shown only to you: they do not earn points, do not count towards streaks, awards or any leaderboard, and do not change where you or anyone else stands. Under GDPR this is health data, so our legal basis is your explicit consent, which you can withdraw at any time in your profile. Withdrawing deletes the days that were imported: we do not merely stop adding to them. Days the app counted itself are not affected, and declining or withdrawing leaves the rest of the app working exactly as it did.

Photos and videos. Only files you choose. The app reads nothing from your photo library until you pick something to attach to a post, a volunteer log or your profile picture.

Content you create. Posts, comments, messages, IT and legal requests, volunteer logs, event responses and similar.

Shipping addresses. If you request branded promotional items or printed material through the app, we keep the delivery addresses you save in your address book, including the recipient name, street address, city, region, postcode and country, so that the items can be shipped and so you do not have to type an address twice. Where a request is placed for an event or on somebody else's behalf, we also keep that recipient's name, phone number and email address and the date it is needed by. Nothing in the app is sold or paid for, so we never collect a payment card, billing address or bank detail.

Requests you place for promotional items. What you asked for, how many, the delivery address you chose, and the status history of the request. Nothing here is a purchase: the items are goods the organisation supplies free of charge, no payment is taken and no price is charged to you. The request is visible to the colleagues who fulfil and approve it, together with your name and email address, and the internal cost of the goods is attributed to a department for the organisation's own budgeting. The organisation is the controller of this, and its legal basis is its legitimate interest in running a supply and fulfilment process for its members.

Activity totals for points and leaderboards. If you take part in the wellness, volunteering and recognition features, we count what you have done across the app, for example how many volunteer hours you have logged, posts and comments you have made, kudos you have sent, polls you have voted in and requests you have placed. These counts drive your points balance, your level and the achievements you unlock, and where you have joined a leaderboard your name and score are visible to other participants. This is not used to evaluate your performance at work. The organisation running the programme is the controller of it, and its legal basis is its legitimate interest in running the programme, together with your choice to take part.

Device information for notifications. A push notification token that identifies your device to Apple's or Google's notification service, plus the device name and platform, so that alerts reach you and so you can see which of your devices is counting your steps.

Diagnostics. If the app crashes or hits an error we collect a technical report through Sentry: the error, a stack trace, the app version, the device model and operating system version. This is used to fix faults. Legal basis: our legitimate interest in a working, secure application.

Safety alerts

An organisation running OneNect can send urgent safety alerts to its members, including alerts that take over the screen and sound an alarm. This is for reaching people quickly when there is an emergency such as severe weather or an incident on a site. An alert is sent to the people assigned to the affected site, and to anyone whose most recent position falls inside the affected area.

The organisation decides that an alert is sent, what it says, and which site or area it reaches. It relies on its legitimate interest in protecting health and safety, and in some cases on a vital interest under GDPR Article 6(1)(d). We build and operate the delivery: the geofence, the take-over-screen behaviour and the channels an alert travels over are ours. Where an alert reaches you because your most recent position falls inside the affected area, that use of your position is part of that delivery.

Who else handles your data

We use the providers below. Each is bound by contract to handle data only on our instructions. Where an organisation is the controller, these are our sub-processors for it, engaged under our agreement with that organisation. We publish changes to this list on this page and tell customer organisations before a new provider starts, so that an organisation can object.

ProcessorPurposeWhere
SupabaseDatabase, file storage and backupsUnited States
Fly.ioApplication hostingUnited States
UpstashSession and cache storageUnited States
Expo (Expo Application Services)Push notification delivery, app updatesUnited States
Apple, GooglePush notification delivery to your deviceGlobal
SentryCrash and error reportingUnited States
AnthropicMachine translation of content into your languageUnited States
ResendDelivery of the email we send youUnited States
VercelHosting for the web pages that accompany the appUnited States
Google Maps PlatformMaps, and the address suggestions offered when you type oneGlobal

An organisation may also connect services of its own using its own credentials. Those are not on the list above, because we do not choose them, and where an organisation has connected one the data goes to the account it holds with that provider. The two most common are an IT service desk, Techottic or ServiceNow, and a store or giving platform the organisation already runs. Your organisation can tell you which it uses.

When you report an IT problem, the ticket carries your name, email address, site and department to whichever service desk your organisation uses, so a technician knows who is affected and can reply to you. Nothing else about you is sent with it.

We do not sell personal data. We do not share it for advertising. We do not use it to train machine learning models.

International transfers

Techno Optics LLC is established in the United States, and OneNect and its data are operated from there. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with encryption in transit and at rest. Where an organisation is the controller, the clauses that apply are the ones in our agreement with that organisation. An organisation can choose where its data and backups are held.

How long we keep it

Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent at any time.

If you are in the EEA, the UK or Switzerland these rights come from GDPR or UK GDPR. If you are in Brazil they come from the LGPD. If you are in California they come from the CCPA as amended by the CPRA, and we confirm that we have not sold or shared personal information in the preceding twelve months.

To exercise these rights over the data we control, write to contact@technooptics.com. We answer within one month, and tell you if we need longer, which the law allows in limited cases. If you are in California we answer within 45 days.

For data your organisation controls, ask your organisation. If you write to us we will identify the right contact and pass your request on within five working days.

If you are in the EEA, the UK or Switzerland you also have the right to complain to your local supervisory authority.

Children

OneNect is not directed at children under 13, and we do not knowingly collect data from them. Anyone taking part in volunteering or wellness activities through an organisation running OneNect should be 13 or older, or should use the app with a parent or guardian.

Security

Data is encrypted in transit using HTTPS and at rest by our storage providers. Access to production data is limited to staff who need it. Sensitive values are encrypted with a dedicated key. We keep an audit trail of administrative actions.

Changes

If we change this policy we will update the date at the top and, where the change is significant, tell you in the app.

Contact

Techno Optics LLC, trading as OneNect

contact@technooptics.com

EEA availability and representative. Techno Optics LLC has no establishment in the European Economic Area. Pending appointment of a representative under GDPR Article 27, OneNect is NOT offered in EEA territories, and the app is withheld from those App Store and Google Play regions. Article 3(2) turns on offering a service to people in the Union, so withholding it is a lawful alternative to appointing a representative. If we later offer OneNect in the EEA, we will designate a representative under Article 27 and name them here before doing so. An organisation running OneNect from outside the Union has to make the same assessment for itself, for the data it controls.