Privacy Policy
Last updated 18 August 2026
Ferry has no user accounts and creates no identifier for you or your device. Nothing it sends to its server can be traced back to a person, because there is no field in which a person could be named.
1. No account, no identifier
Ferry never asks you to register and never generates a user ID, device ID or advertising ID to send anywhere. You can use the entire app in Read on this device mode without providing anything at all.
2. What Ferry sends to its own server
Ferry's server receives three things, and only these three:
- Usage counts. Counters kept on the device — articles opened,
read, saved to Later, feeds added — posted in batches as a bare map such as
{"article_open": 7}. The message has no field for an article, a feed, a session or a device, so none can be included. Because counts are batched, a report says “seven since the last one”, not “one just now”. - Device class. The single word
iphone,ipadormac. It answers “is anyone reading on iPad” without being able to answer “who”. - Feed registrations. When you follow a source, its address and title are sent so Ferry can score stories across all readers and keep a source's subscriber count accurate. No identifier travels with it: the server learns that a feed gained a subscriber, not who subscribed.
These requests carry an application key that is identical in every copy of Ferry. It authenticates the app, not you, and identifies nobody.
3. What Ferry never sends
The text of articles you read, your search queries (search runs entirely on your device), how long you spent on any particular article, your feed list as a set, your location, your contacts, or anything belonging to other apps.
Failed uploads are discarded rather than retried, deliberately: a queue that grows while you are offline eventually describes a person's week.
4. iCloud sync
If your device is signed into iCloud, your subscriptions, read state and Later queue sync between your own devices through your private iCloud database. That data lives in your personal iCloud account under Apple's terms. Ferry's developer has no access to it and keeps no copy on any Ferry server. You can switch it off in Settings → [your name] → iCloud.
5. Feeds and articles
In “Read on this device” mode, Ferry fetches feeds and article pages directly from the publishers. Those publishers see an ordinary web request from your device, including your IP address, exactly as they would if you opened the page in a browser. Ferry does not proxy these requests and has no control over what a publisher does with them.
6. Third-party reader services
If you connect a service such as FreshRSS or Inoreader, Ferry talks to that server using credentials you supply. They are stored in your device's keychain and sent only to the server you named. What that service does with your data is governed by its own privacy policy, not this one.
7. No analytics, no advertising
Ferry contains no third-party analytics SDK, no advertising network, no crash-reporting service and no cross-app or cross-site tracking of any kind.
8. Server logs
Like any web server, Ferry's records ordinary request logs — IP address, path and timestamp — in order to operate and debug the service. These logs are not joined to the usage counts above and are not used to build a profile of anyone.
9. Data retention, export and deletion
The server stores aggregate counters, not records about people. There are no per-person rows to retain, export or delete, because none are ever created. Your own reading data lives on your device and, if you enable it, in your private iCloud account — deleting the app removes the former, and iCloud settings control the latter.
10. Children
Ferry is not directed at children. It displays whichever feeds you choose to follow and can open arbitrary pages from the open web.
11. Changes to this policy
Material changes will be published on this page with a new “last updated” date.