Legal
Odd Community Privacy Policy
One privacy policy for every Odd Community app. The first part applies to all of them. Each app then has its own section, which says exactly what that app stores, where, and who can read it.
Who we are
This is the privacy policy for the apps published by OddBold LLC, trading as Odd Community (“Odd Community”, “we”, “us”): BestFriend, Raw Daily, Hansel and Quarterly Goals. OddBold LLC is the publisher of every app on this page and the data controller for each of them. Privacy contact: oddcommunityreview@gmail.com.
Principles common to all our apps
- Local first. Each app keeps your core data on your device.
- No sign-in needed to start. You can use each app’s core features without signing in.
- Encrypted on your device. Each app encrypts its main local database with a key held on your device. Not everything every app stores is covered by that encryption; each app’s section says exactly what is.
- Plain disclosure. Each app’s section says what leaves your device, when, and who can read it.
Where an app’s section is more specific than this part, the app’s section applies.
Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Data kept only on your device is already in your hands. For anything we hold, email oddcommunityreview@gmail.com and say which app your request is about. Each app’s section explains its own deletion and request options. Never send passwords, login codes, recovery phrases or encryption keys.
Children
BestFriend, Raw Daily and Quarterly Goals are not directed at children under 13. Their sections give the details.
Changes
We date each change at the top of this page. Where an app has its own effective date, it is shown at the start of that app’s section, and that section’s own commitments about changes still apply.
Contact
Email oddcommunityreview@gmail.com about any app on this page.
BestFriend
BestFriend is a private notebook for your close friendships. Your notebook is saved on your phone. Optional backup, sharing, and feedback features send data off the device as described below. Backup content is encrypted on your device with a key derived from your recovery phrase.
The short version
BestFriend is a private notebook for your close friendships. It is local-first: your friendship notebook is saved in the app's database on your phone. Optional backup, profile and city sharing, friend notes, and feedback can send data off the device. Account and delivery identifiers are also processed by our service providers.
You can optionally create an account to back your data up to our servers. For backup, your device encrypts the content before it leaves the phone, using a key derived from a recovery phrase that only you hold. Our servers store encrypted backup content, which we cannot decrypt.
We do not sell your data. We do not share it with advertisers or data brokers. We do not build advertising profiles. There is no social feed, no follower graph, and no algorithm ranking your friends.
1. Who we are
BestFriend ("the app") is published by OddBold LLC, trading as Odd Community. The optional account and encrypted cloud backup service are also operated by OddBold LLC. "We" and "us" in this policy mean OddBold LLC, which is the data controller. Privacy contact: oddcommunityreview@gmail.com.
2. Your local notebook
The following is saved in the app's local database. It can also leave your device when included in optional encrypted backup, a profile or note you share, or feedback text or screenshots you submit:
- Friends you add: names, nicknames, phone numbers, email addresses, city, notes
- "Satellites": partners, children, pets and their details
- Birthdays and other important dates
- Your contact-frequency goals and engagement history
- Avatar photos you choose or take
- Anything you type into a note
Without backup, losing your phone can mean losing your notebook. We cannot recover notebook data held only on that device. The app tells you this in plain language during onboarding; this policy repeats it because it is the single most important consequence of the local-first design.
Contacts
If you choose to import friends from your address book, the app asks for the iOS/Android contacts permission and reads your contacts on the device so it can show you a picker. Only the entries you actively select are copied into BestFriend's local database. The app does not upload your address book as a contact list. Selected friend records can be included in optional encrypted backup, and contacts you do not select are not retained by the app after the picker closes. You can decline the permission and add friends manually; nothing else in the app is gated on it.
Photos and camera
You can attach an avatar to a friend or your own profile. Images are stored locally; selected images can be included in encrypted backup or profile sharing. Feedback also lets you choose up to three images to upload as attachments. The app does not upload your photo library as a whole.
3. Optional account (email sign-in)
Email sign-in is optional. You can use the core notebook without an email address or a sign-in step.
We use Supabase (Supabase Inc.) for authentication and server storage. The app attempts to create an anonymous session automatically so invitations and other network features can work without email sign-up. Supabase processes, on our behalf:
- your email address, if you choose email sign-in
- account identifiers, including an anonymous account identifier, authentication tokens, and session identifiers
- the timestamps and IP address associated with sign-in requests, as an ordinary part of operating an internet service and detecting abuse
Purpose: to authenticate network requests, associate encrypted backups with your account, and route invitations, shared profiles, friend notes, and feedback. Legal basis (EEA/UK): performance of a contract you asked for.
4. Encrypted cloud backup
Backup is off by default and must be switched on by you.
- Your device generates a BIP39 recovery phrase. From it we derive, on the device, a master key and from that a backup key.
- Your data is encrypted on the device with AES-256-GCM before any upload.
- For backup content, we receive and store only ciphertext, in storage scoped by row-level security to your account id. Backup metadata includes account and device identifiers, version, and size. We never receive your recovery phrase or backup keys.
- We cannot decrypt your backup and we cannot reset your recovery phrase. If you lose the phrase, the backup is permanently unrecoverable. This is a deliberate property of the design, not a limitation we can work around for you.
- Deleting your account deletes the stored ciphertext.
How much we back up depends on your account's backup capacity. Some accounts back up your 5 closest friends; others back up your whole roster.
Adding friends in the app is unlimited and free forever, with or without an account. This number describes only how many friends we hold an encrypted copy of — never how many you can add or keep. Friends beyond it remain stored on your device permanently and at no cost; they are simply not copied to us. Nothing is deleted and nothing is blocked.
Account state changes how much encrypted backup content we hold. It does not give us the key to read that backup content.
5. Location sharing (optional)
Location sharing works in both directions. With location permission, the app obtains a location fix and uses the device's geocoding service to determine your city. It shares a city name with eligible connected friends under the app's sharing settings. The same feature lets you see the city of a friend, if that friend has separately chosen to share it with you. Each direction is its own choice: you sharing with a friend does not require, or grant, seeing theirs, and vice versa.
Profile and invitation sharing encrypt city information before upload. Some other city updates send a city name and update time that our service can read. Not all city sharing is end-to-end encrypted. Connections to our service use HTTPS to protect data while it travels over the network.
- Location access is optional and requires OS permission, which you can revoke at any time. Granting permission can enable default city sharing for eligible friends without an existing sharing preference; sharing can be turned off in the app.
- BestFriend uses "While Using the App" location only. It does not use background location and cannot check where you are while the app is closed. Your city is read when you open the app, so the city your friends see is the city you were in the last time you used BestFriend.
- What you see of a friend's location is a city name, not a live map or a real-time position — it updates when their shared city changes, not continuously.
- The app uses coordinates to determine your city through the device's geocoding service. It does not send precise coordinates in its city-status or profile-sharing payloads, or use them for advertising.
- Turning sharing off stops future updates. It cannot delete a city a friend has already seen, because that copy is already on their device.
6. Your profile
BestFriend lets you create a profile for yourself — separate from the friends you add. It holds:
- a display name, and optionally an avatar;
- a base city — where you live, or where you expect to be a lot — which you set yourself and which only changes when you change it;
- a current city, which the app may refresh when you open it, if you have granted location permission;
- interests you enter, each stamped with when you last confirmed it so that a stale interest can be flagged to you rather than shown to someone as though it were current.
Your profile is stored in the encrypted local database. Parts you choose to share can leave the device. Creating one is optional; you can skip it during onboarding and the app works exactly as it otherwise would.
Each part of your profile carries its own visibility setting, which you control:
- Private — not included in automatic profile sharing with connections. Your current city is private by default. Information you choose to include in feedback is submitted separately; optional backup follows section 4.
- Visible to connections — eligible to be shared with people you have actively connected with.
If and when a part of your profile is shared with a connection, it travels over a per-recipient encrypted profile-sharing path: it is encrypted on your device for that specific recipient, the server relays ciphertext only, and we cannot read it. There is no separate, unencrypted route for profile data.
Changing your city never changes who can see it, and the app never creates a profile for you as a side effect of anything else — a profile exists only because you made one. Deleting your account deletes your profile and interests along with the rest of your data (section 10).
7. Analytics and crash reporting
Supabase processes authentication, encrypted backup and sharing payloads, readable city-status fields, feedback, and delivery metadata on our behalf. Expo and the platform push service process notification tokens for remote note notifications. These services can receive identifiers and request metadata independently of analytics.
| Provider | What it receives | Why |
|---|---|---|
| PostHog | Anonymous product-usage events (screen views, feature usage, counts, performance timings) keyed to a rotating anonymous identifier that is not your account, email, device advertising id, or phone number | To see which features are used and where the app is slow |
| Sentry | Crash and error reports: stack traces, OS/app version, device model | To find and fix crashes |
PostHog and Sentry reporting depend on the configuration of the installed build. They are not enabled in the Android public-beta configuration prepared on 2026-10-01.
Optional feedback
If you send feedback, Supabase stores the category and message you enter, your account identifier, app/build version, operating system, and device name or model. Up to three images you explicitly attach are compressed and uploaded to a private storage bucket. Feedback text, images, and diagnostics are readable by the service; they are not end-to-end encrypted. They help us respond to feedback and investigate problems. If you include personal information in a message or image, it is included in that submission. An optional email fallback opens your mail app with your message and device details addressed to our support email.
Notes:
- Analytics events never contain your friends' names, notes, phone numbers, emails, photos, or location. They describe interactions with the app, not the contents of it.
- BestFriend contains no in-app purchases, so we operate no payment processing and receive no billing or payment-card data of any kind.
- Apple and Google provide us aggregate, non-identifying download and crash statistics under their own privacy policies.
We do not track you
"Tracking", as Apple defines it, means linking your data with data from other companies' apps or websites for advertising, or sharing it with data brokers. BestFriend does none of this. We do not use the advertising identifier (IDFA/AAID), we run no ad SDKs, and we sell no data. Our iOS privacy manifest declares NSPrivacyTracking = false accordingly.
8. Notifications
Reminders and birthday nudges are scheduled and delivered locally by your device. Their contents are not sent to our servers. Remote friend-note notifications use an optional push token registered with Expo and stored with your account identifier and platform; this is separate from local reminders.
9. Children
BestFriend is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data. If you record a child's name or birthday as a "satellite" of a friend, that information is your own note about someone in your life, and the storage and optional-transfer rules described above apply to it.
10. Delete your account and request data deletion
In the app: open Settings, choose Delete Account, and follow the confirmation instructions. When a session is available, the app requests server account and backup deletion before wiping the local database, avatar files, and encryption keys. Without a usable session, local deletion does not establish that server data has been deleted.
Without the app: email oddcommunityreview@gmail.com with the subject BestFriend account and data deletion. State that you want your account and associated data deleted, and include the email address associated with your account, if any. You do not need to reinstall the app. If you used an anonymous session, describe the data you want deleted so we can help identify it. Never send passwords, recovery phrases, or encryption keys.
- Local data stays on your device until you delete it in the app or uninstall the app.
- Backup ciphertext is retained while your account exists.
- Account deletion is intended to remove the Supabase account, associated database rows, and stored backup ciphertext. Successful in-app deletion also wipes local data and keys. Deletion is not reversible.
- Feedback attachment files are stored separately from feedback database rows. Account deletion or uninstalling the app may not remove those files. If you submitted feedback, include its attachments in your email deletion request.
- Copies already received by friends are on their devices and are not erased by deleting your account. Security audit records may be retained in de-identified form.
- Crash and analytics records are retained by Sentry and PostHog under their own retention windows and are not linked to your account.
The email pathway above is also available for requests to delete specific data without deleting your account. We may need to verify which account or submission belongs to you before acting; we cannot retrieve notebook data held only on your device.
11. Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. For anything stored only on your device, you already hold all of these rights directly — the data is in your hands, not ours. For account data, contact us and we will act within the period required by applicable law.
We do not sell or "share" personal information as those terms are defined by the California Consumer Privacy Act.
12. International transfers
Our infrastructure providers may process data in the United States and the European Union. Because backup content is end-to-end encrypted, any cross-border transfer of that content is a transfer of ciphertext only.
13. Security
Two different things are encrypted, in two different ways, and we describe them separately rather than blurring them together:
- The database on your phone is encrypted at rest with SQLCipher (AES-256). Its key is generated on the device and stored in the iOS Keychain / Android Keystore, protected by your device passcode and available only when the device is unlocked.
- Backup content is encrypted on the device with AES-256-GCM before upload, under a key derived from your recovery phrase using Argon2id. Transport is TLS in both cases.
A consequence worth stating plainly: because the database key lives in your device's secure storage, and because we hold no copy of it, a device wipe or a lost keychain entry means that local data cannot be recovered by us — only a backup you enabled, plus your recovery phrase, can restore it.
No system is perfect, and we will notify affected users of a breach as required by law. Encrypted backup and sharing content remain ciphertext on our servers. Readable city-status fields, feedback submissions and attachments, and account or delivery metadata do not have that same protection.
14. Changes
We will update the "last updated" date above and, for material changes, notify you in the app before the change takes effect.
Raw Daily
Raw Daily is a private voice-and-text journal by OddBold LLC, trading as Odd Community.
Last Updated / Effective: 2026-09-30
Canonical URL: odd.community/privacy#rawdaily
1. Summary
You can write, record, transcribe, and revisit your journal without an account. Core journaling works offline. Transcription and optional fact-finding run on your device; Raw Daily does not send your journal to an AI service. There is no AI reflection or summarization of your journal.
Your private journal stays on your device unless you deliberately export it or submit selected content for anonymous sharing. Anonymous sharing is a separate, optional network service described below.
2. What the app stores, and where
Journal entries and transcripts live in a SQLCipher encrypted database. Its encryption key lives in the device's secure keychain; we do not receive that key. Voice recordings are retained so you can listen again, including multiple takes for an entry. They are separate WAV files in the app's private storage, protected by the device's operating system and app sandbox. They are not encrypted by SQLCipher. Device security, a strong device passcode, and access to an unlocked device affect their protection.
Settings live locally. Account session credentials are held in secure keychain storage. On iOS, the encrypted journal database in Library may be included in device backups; a copied database still requires its encryption key to open. The app attempts to exclude Documents and its recording directories from iCloud backups on each launch, which also covers local audio backup snapshots when the exclusion succeeds. If it cannot verify recording exclusion, it warns you before recording and offers “Not Now” or “Record Anyway.” Choosing to continue can allow unencrypted recordings into an iCloud backup if that device backup is enabled. On iOS, creating an audio backup snapshot or restoring its recordings requires confirmed backup exclusion for the destination directory; the operation stops if that protection cannot be confirmed. Android builds disable app backup and device transfer through their manifest and extraction rules. These controls do not guarantee backup exclusion on unsupported platforms. Deleting an entry removes its local recordings. Uninstalling the app removes its local app data; copies you exported and content you submitted online require separate deletion.
3. Network access
Core writing, recording, playback, transcription, and fact-finding do not need a network connection once their models are installed. Model downloads expose normal request information such as IP address to the download host, but do not contain journal content. App updates are handled by Apple or Google under their policies.
Optional sign-in sends authentication information to Supabase. Optional anonymous sharing sends only the content you approve, as described in section 5. Requests to remove shared content also use the network and may wait in a local retry queue while offline. Raw Daily does not use your journal for advertising or tracking.
4. Optional account
An account is not required for local journaling. If you sign in, our authentication provider, Supabase, processes your email address, account identifier, and sign-in credentials or provider information. Account sessions are stored in your device's secure keychain. Signing in does not automatically upload your private journal or recordings and does not provide cross-device journal sync.
Signing out leaves your local journal intact. Account deletion and removal of content already submitted online are distinct from uninstalling the app. Contact us for account or privacy requests.
5. Exports and anonymous sharing
You choose where an export goes, including whether to use a cloud drive or another app. A full ZIP journal archive includes text and retained voice recordings; text-only JSON and Markdown exports omit audio. Exports are readable by anyone with access to the files, so protect them as you would your journal. Local backup snapshots also retain the associated audio files; they remain in app-private storage subject to the platform backup behavior described in section 2.
Anonymous sharing requires your explicit approval of the selected quote and rendered card before submission. The approved quote/card and submission metadata are uploaded to our moderation service on Supabase. Moderators can read the submitted content. Approved cards may be published anonymously on the Odd Community Instagram account; your email or account name is not printed on the card. The submitted words themselves can identify you or others, so review them before consenting. Your full entry, other journal entries, and voice recordings are not part of that submission.
You can request removal from the app's sharing history. An offline request is queued until a connection is available. Removal requests require moderation and are not immediate. We can remove content we control, but cannot erase screenshots, reposts, or other copies made by third parties. Local deletion of an entry or uninstalling the app does not retract an online submission.
6. Crash diagnostics
Crash reporting is optional and requires consent; the default is no. Approved reports contain technical diagnostics such as stack traces, app version, and device type. Journal content, transcripts, and recordings are excluded.
7. Children
Raw Daily is not directed at children under 13, and we do not knowingly collect personal information from children.
8. Your choices
Use the app without an account. Keep your device locked and protect exported files. Delete local entries or the app to remove local app data. Decline optional sharing or crash reporting. Request removal of online submissions separately from local deletion. Contact us to request account deletion or help with privacy requests.
9. Changes
Updates are dated here. We keep app privacy disclosures aligned with the actual features and network behavior in the app.
10. Contact
OddBold LLC, trading as Odd Community — contact us through odd.community for privacy, account deletion, and shared-content removal requests.
Hansel
Speech recognition on your Mac. Separate choices for local history, accounts and billing.
Odd Community · OddBold LLC
Hansel is published by OddBold LLC, trading as Odd Community. Effective 6 October 2026. Contact: oddcommunityreview@gmail.com.
Dictation and permissions
Hansel uses microphone access for speech you choose to record. Speech recognition runs on your Mac after its speech models are downloaded. Accessibility permission supports shortcuts and inserting text into other apps. You can manage these permissions in macOS System Settings → Privacy & Security.
Text you insert, copy or export can be stored or transmitted by the destination app. Hansel’s local encryption does not protect those other copies.
Local data and encryption
The release stores transcripts, recording metadata, corrections, vocabulary and preferences locally. Its transcript database, owned audio files and database recovery backups are encrypted using a device-held key. Saved account tokens use macOS secure storage. If the required secure storage or database encryption is unavailable, these operations stop rather than save that information without encryption.
Earlier Hansel releases did not effectively encrypt the transcript database. The release migrates that database and may keep an encrypted recovery backup. Encryption and deletion cannot guarantee removal of historical disk blocks, external copies or operating-system snapshots.
Keep, export or delete local history
Local history remains until you remove it; there is no automatic expiry period. Removing Hansel.app or signing out does not erase application data or Keychain keys.
Settings → Export History lets you choose a readable JSON file containing transcripts, recording metadata, corrections and vocabulary. It excludes audio files, encryption keys and account records. Treat the export as private: it is not encrypted by Hansel.
Settings → Delete History asks for confirmation, then removes local history, custom vocabulary, app-owned audio and internal recovery backups. Finish recording and transcription first. This does not delete your account, cancel billing, remove files outside Hansel’s owned storage, or erase exports and operating-system backups.
Internet connections
Guest dictation does not require an account. Internet access is needed for speech-model downloads and app updates. Models come from FluidInference repositories on Hugging Face; releases are delivered through Odd Community’s website and release-storage services. Delivery providers can receive IP addresses and request metadata.
Optional sign-in uses an online account service to authenticate your email and retrieve membership information. Membership checks send the Hansel app code and can record account activity at most once an hour. Existing paid memberships may have Stripe billing records. All local Hansel features are free without an account or membership, including dictation, encrypted history, Your Words and voice shortcuts. There are no membership quantity limits on custom words or shortcuts. Valid shortcut-trigger rules still apply. An optional shared Odd membership is planned for device sync, cloud storage backup and premium AI models. These future services are not available yet. Planned pricing is $5.95/month or $47/year, saving 34.2% compared with twelve monthly payments. Checkout is not available. This release does not sync or back up recordings to the cloud. The local-history export does not export those providers’ account or billing records.
The release does not send reports through Hansel’s remote error-reporting API. Local application logs and macOS diagnostics can still exist. Website hosting also receives ordinary network requests; this privacy page loads no analytics scripts.
Account requests and support
For help with account records, access, correction, export or deletion, contact oddcommunityreview@gmail.com. Do not email passwords, login codes, access tokens or encryption keys. There is no self-service Hansel account-deletion control in this release. Contact support for account requests.
Account deletion and subscription cancellation are separate actions. Odd accounts may be shared across apps; a shared-account deletion can affect access to those apps. Some security and billing records may need to remain. Contact support for information about account retention and the verification needed for your request. We do not promise a fixed retention or response period here.
Quarterly Goals
Quarterly Goals keeps your goals on your phone, in an encrypted database. Version 1.0 has no account and no sign-in, and sends nothing to us or anyone else. There are no analytics, no ads and no tracking.
The short version
Quarterly Goals is for writing down four goals in each of four areas of life, Personal, Learning, Business and Relationship, every quarter, and seeing them in a 2x2 grid with up to three friends.
Version 1.0 stores everything on your device only. Your name or initials, your optional profile photo and your goals stay on your phone. The app does not send any of them to us or to anyone else. There is no account, no sign-in, no analytics, no advertising and no tracking.
Connecting with friends and an optional cloud backup are planned for later versions. Both will be end-to-end encrypted. We will update this policy before either one ships (section 4).
We do not sell your data. We do not share it with advertisers or data brokers. In version 1.0 we never receive it in the first place.
1. About the app
Quarterly Goals (“QG”, “the app”) is published by OddBold LLC, trading as Odd Community. Its store listing is “QG – Quarterly Goals”, and its app identifier is community.odd.qg. This section describes version 1.0 of the app, on iPhone and Android.
2. What the app stores, and where
Version 1.0 keeps only what you type in or choose:
| What | Where it is kept | Leaves your phone? |
|---|---|---|
| Your name or initials | The encrypted database on your phone | No |
| Your profile photo (optional) | The app’s private storage on your phone | No |
| Your goals | The encrypted database on your phone | No |
| The database key | Your phone’s secure storage (iOS Keychain / Android Keystore) | No |
Version 1.0 has no backup of its own. If your phone is lost, wiped or replaced, we cannot recover your goals: we never had a copy, and we hold no copy of the key.
Photos
A profile photo is optional. You choose it with your phone’s own photo picker, and the app receives only the photo you pick, not the rest of your library. The photo is stored locally in the app’s private storage and is not uploaded anywhere. Version 1.0 does not use the camera or the microphone.
Your phone’s own backups
If your phone’s system backup is switched on (iCloud Backup on iPhone, or Android’s backup to your Google account), the operating system may include the app’s files, as it does for most apps. The goals database stays encrypted inside that copy. The database key is not part of those backups: it is kept for this phone only. So restoring a backup onto a new phone does not bring your goals back. That backup is made by your phone, to your own Apple or Google account, under their terms. It is not sent to us.
3. No account, no analytics, no tracking
Version 1.0 has no account and no sign-in. It contains no analytics, crash-reporting, advertising or tracking SDKs, and no third-party code that collects data. Nothing you put into the app is sent to us or to anyone else.
We do not track you
“Tracking”, as Apple defines it, means linking your data with data from other companies’ apps or websites for advertising, or sharing it with data brokers. Quarterly Goals does none of this. The app does not use the advertising identifier (IDFA/AAID), runs no ad SDKs, and we sell no data.
What Apple and Google tell us
Apple and Google provide us aggregate, non-identifying download and crash statistics under their own privacy policies. If you test a pre-release build through Apple’s TestFlight, Apple shares with us the feedback and crash reports you choose to send, and the tester information Apple shows to developers, under Apple’s own terms. None of this includes your goals.
4. Coming soon: friends and backup
Two features are planned for later versions. Neither is in version 1.0.
- Friends: connecting with friends by invitation code, so that you can see your goals together in the grid.
- Cloud backup: an optional backup of your data.
Both will be end-to-end encrypted. Your goals, names and photos will be encrypted on your phone before they leave it, so our servers cannot read them. The servers will still see some technical information needed to deliver them, such as which accounts are connected to each other and when they sync; we will list exactly what before either feature ships.
We will update this policy before either feature ships, so that it says exactly what is sent, where, and who operates it. We make no other promise here about what those features will include or when they will arrive.
5. Children
Quarterly Goals is not directed at children under 13 (or the equivalent minimum age in your country). Version 1.0 sends us no information, so we do not collect personal data from anyone through the app, children included.
6. Delete your data
Delete the app from your phone. That removes its database and photo, and with them your goals, your name and your profile photo. We have no copy to delete, because version 1.0 never sends us anything.
- On iPhone, iOS can keep the app’s database key in the Keychain after the app is deleted. Without the database, that key unlocks nothing.
- Copies inside your phone’s own system backups follow the rules of those backups (section 2).
- Deletion is not reversible.
7. Your rights
Version 1.0 keeps everything on your device, so you already hold the rights described under Your rights directly: the data is in your hands, not ours. We hold no personal data from the app to act on.
8. Security
The database on your phone is encrypted at rest with SQLCipher (AES-256). Its key is generated on your phone and kept with expo-secure-store: in the iOS Keychain on iPhone, and protected by the Android Keystore on Android. We never receive a copy of it.
A consequence worth stating plainly: because the key lives only in your phone’s secure storage, a device wipe or a lost key means the goals cannot be recovered by us.
Encryption protects the database file. It does not stop someone who can unlock your phone from opening the app, so keep your phone locked with a passcode. No system is perfect, and we will notify affected users of a security problem as required by law.
9. Changes
We will update this section, and the “Last updated” date at the top of this page, before friend connections or cloud backup ship, and whenever what the app does with your data changes.