What leaves your phone.
“Private” is a word anyone can put on an app. So instead of the word, every app we make declares one of three tiers below, and the tier says exactly what the app does and does not send. You can check it — put the app behind a network proxy and watch.
Sealed
No network exists. There is nothing to leak.
Our journalling and wellbeing apps — including one in development now.
- No network calls of any kind. The only framework that touches anything external is Apple’s own purchase system.
- No usage data. Not anonymous, not aggregated, not “just a counter”. None.
- No sync. Backup is to your own device, off by default.
- Speech recognition runs on your phone. If your phone can’t do it, the app asks you to type — it never falls back to a server.
- App Store privacy label: Data Not Collected.
Local-first
What you write stays on your phone. Anything we measure is anonymous, and you can switch it off.
Had it?
- Everything you write, photograph or record is stored on your device and is never uploaded.
- It leaves only when you tap something that sends it — a search, a share sheet, an email you chose to open.
- This tier allows anonymous usage counts — which screens get opened, nothing more. Today none of our apps collect even that; each app’s own page tells you where it stands, and it will be updated in the same release as any change, never before.
- Sync, if offered, moves your data between your own devices through Apple’s iCloud — never through a server of ours.
- Every core feature works with no signal at all.
Connected
The network can be part of the app — and every part of it is disclosed.
Mattered?, Later?, Aced it?
- Broadcast, the default: the app downloads a small file we publish — a weekly challenge, some tips. Read-only, and the request carries nothing that identifies you or your device. Mattered? works this way.
- Two-way, for our lowest-stakes apps: sync between your own devices, anonymous usage counts, or a server that genuinely makes the app better. You can see that it happens, and you can switch it off. Later? and Aced it? are allowed this; each app’s own page says what it actually does today.
- Switch it off, or lose signal, and every core feature still works.
- The privacy policy, the app’s page and the App Store privacy label change in the same release as the code — never before, never after.
- Where an app’s users are more exposed than its data it behaves like the tier below.
True at every tier
- No third-party code. No analytics vendors, no crash reporters, no ad networks, no trackers — not in any app, at any tier.
- No accounts. Nothing to sign up for, no email address collected.
- What you write is yours. It never leaves the device unless you do something that sends it.
- The privacy policy and the App Store privacy label describe the app you actually have installed. Neither is ever written ahead of the code.
Why there are tiers at all
We used to apply the strictest rule to everything, which sounds better than it is. A mood journal and a list of things to look up later are not the same kind of secret. Treating them identically meant the strict promise got quieter — it was everywhere, so it meant nothing anywhere — while apps that could safely have had useful things, like syncing to your iPad, went without.
So we ask one question per app: what does it cost you if this leaks? If the answer is a regulator, a lawsuit, a relationship or a diagnosis, the app is Tier 0 and stays sealed. If the answer is that you would be mildly annoyed, it is Tier 1 and what you wrote still stays on your phone. Moving an app up a tier is never quiet: the policy and the store label change in the same release as the code.