---
title: Privacy | Pocket Chronicle
description: What Pocket Chronicle collects about you and your child, where it lives, what runs on your phone instead of our servers, and what we will never do with it.
url: /privacy
---

Small print

# Privacy

This page carries more weight than the terms page, because most of what's in here isn't about you. It's about a child who didn't choose any of it. So it's written to be read all the way through rather than agreed to.

## There are two people in this document

**You** — the account holder, a parent or guardian. You signed in, you own the account, and you're the one this page gives rights to.

**Your child** — the person the archive is about. They have no account, no login and no way to sign in. Everything held about them was typed, photographed or recorded by you.

That split is the unusual thing about this app, and almost every paragraph below turns on it. A privacy page for a social app describes one person describing themselves. This one describes a parent keeping a record of somebody else — somebody who will one day be old enough to have an opinion about it.

## What we collect

Itemised, because a list is harder to hide things in than a paragraph.

### How you sign in

Sign in with Apple, Sign in with Google, or a link sent to your email address. Whichever you pick, what we keep is an identifier from that provider, and a display name and an email address *if* they give us one.

**An email address is optional on your account and always has been.** If you use Apple's Hide My Email, we get a `privaterelay.appleid.com` address and that is genuinely all we get — we never inspect it, never try to work out the address behind it, and the app doesn't behave differently when it sees one. Apple can also switch the forwarding off later, at which point our email stops reaching you and we have no way to know that it hasn't. That's a real limitation, not a footnote, and it's why push notifications and in-app messages matter as much as email here.

We never see a password, because there isn't one. Sign-in tokens are stored as SHA-256 hashes rather than as the token itself, the token your phone carries expires in fifteen minutes, and the longer-lived one rotates every time it's used.

### What you put in

- **Your child.** Their name, their birthdate, their pronouns if you set them, a photograph if you add one, and your household's timezone.

- **Entries.** The title and the body you write, the date the thing actually happened, your child's age in months at that moment, and whether you sealed it for later.

- **Media.** Photographs, video and audio recordings, and when each was captured.

- **Tags**, and a note of whether you chose each one or your phone suggested it.

- **Which prompts you were served, answered or dismissed**, and on what day.

- **Timestamps** on all of it — when a thing was created, changed, or last signed in for.

**One thing on this list is smaller than it sounds.** There's a monthly measurement mission that asks you to measure your child's height and weight and take a photograph against the same wall. That's a question, not a health record: there is no height field and no weight field anywhere in Pocket Chronicle, nothing connects to Apple Health, and whatever you type goes in as ordinary entry text like every other answer. We say so because "we collect your child's height and weight" would be the wrong thing to picture.

### What the app needs to run

A push token for your phone, if you've turned notifications on, so Apple can deliver them. Ordinary server logs. Nothing else — there is no advertising identifier, no device fingerprint, and no behavioural event stream.

**What a notification contains, since it renders on a locked screen other people can see:** your child's first name, and the text of the day's prompt. It cannot contain an entry, a transcript or a photograph — there is no field on the message that could hold one.

## Your child does not have an account

**Pocket Chronicle is not directed to children and is not built for them to use.** There is no child login, no child profile they control, no messaging, no feed and nothing for a child to sign up to. Everything about your child in here is data a parent entered about someone else — which is the ordinary situation for a family record and an unusual one for an app.

We don't ask your child anything, we don't ask you anything about them beyond what the prompts ask, and there is no route by which a child could give us data themselves.

## The AI runs on your phone

Three things in Pocket Chronicle use a model, and **all three run on your iPhone, against Apple's own on-device models**. None of them sends your child's photographs, video, audio or words to us or to anyone else to be processed.

- **Transcription.** When you record their voice, the words are worked out on the phone by Apple's speech framework, offline. The audio file is not sent anywhere to be transcribed.

- **Tags.** Your phone reads what you wrote and suggests a few tags, using Apple's on-device model. Sealed entries are skipped entirely — the phone doesn't read those at all.

- **The daily prompt.** Your child's name and pronouns are put into the prompt sentence on the phone, so the personalised version never leaves it.

**Two honest limits on that.** All three need a recent iPhone running a recent version of iOS with Apple Intelligence available; on a phone without it, Pocket Chronicle simply doesn't do them rather than falling back to a server. And the transcript and the tags, once produced, **are uploaded and stored on our servers as ordinary text**, in the clear, so that search can find them. The processing is private to your phone. The result is stored the same way the words you type are.

**No photograph, video or recording you save is ever sent to an AI company.** We want to be precise rather than sweeping about that, because there are AI services in our bill: we use them to write our own marketing posts and to draft candidate prompts for the library. Those calls carry our own words. They have never carried yours, your child's name, an entry, or a file from an archive, and no part of the app can reach them.

## Where it lives, and who else touches it

We run on other companies' machines, and naming them is more useful than the phrase "trusted partners".

- **Fly.io** runs the server. Its primary machine is in Chicago.

- **Neon** runs the Postgres database that holds your entries, your child's details, transcripts and tags. It's hosted in the United States.

- **Tigris** holds the photographs, video and recordings. It is a globally distributed store rather than a single-region one, so we're not going to name a region for your media and pretend it means something it doesn't.

- **Apple** — for signing in, for delivering notifications, and for the subscription. **Google** — only if you chose Sign in with Google, and only for signing in.

- **Resend** sends our email.

Those five are the whole list. Each of them keeps its own operational logs, the way any infrastructure company does — that's normal, and pretending otherwise would be the dishonest version of this paragraph.

Your media sits in a **private** bucket. Nothing in it is readable by a URL anybody could guess or share for long: the app is handed a short-lived signed link each time it needs a file, and our server never passes the bytes through itself.

## What we never do

- **No advertising.** Not on any tier, not ever. There is no second customer here.

- **We do not sell your data**, rent it, trade it, or hand it to a data broker.

- **We do not train models on your content.** Nothing you or your child put in here is used to improve any model, ours or anyone else's.

- **No third-party analytics.** The iPhone app has no analytics SDK, no crash reporter and no attribution kit in it — it has no third-party code at all. Neither does the server.

- **No enrichment.** We don't look you up, buy data about you, or append anything to what you gave us.

## How long we keep it

**Until you tell us not to.** That's the plain answer today, and it is deliberately not dressed up as a schedule.

Nothing in Pocket Chronicle expires on its own. Stopping paying doesn't start a clock on your archive, going quiet for a year doesn't, and there is no automatic deletion of anything for inactivity. The only thing that removes data is you asking us to.

**We intend that to change in one narrow way, and we'd rather tell you before it does than after.** An archive that has been both unpaid and unopened for years costs money to store, and we expect to eventually age out its *media* — never its text. If we build that, this page changes first, the timings appear here, and you'll get an email and a free export before it could apply to you. None of it exists today, so none of it is written here as though it did.

## Seeing it, taking it out, and deleting it

**Export.** There's a full export of the archive, and it's free on every tier including the free one. It's a zip of ordinary files in folders by date plus an `index.html` that opens in any browser, offline, with no account and no server. It's per child, so a household with three children takes three of them, and the parent role on the archive is what's needed to run one. [The longer promise about the export is here.](/promise.md)

**Correction.** Everything about your child is editable in the app, and so is everything you wrote. If something is wrong somewhere you can't reach, email us.

**Deletion.** You can ask us to close your account from inside the app — Settings, then the card at the bottom. It waits seven days, signs you out immediately, and is cancelled the moment you sign back in. If you are the only parent on the archive it takes everything, including the files themselves out of storage. If your child's other parent is still on it, it removes you and leaves the archive with them, and the entries you wrote stay there with your name taken off. [The terms page says the same at more length.](/terms.md)

**And the part we're not going to smooth over:** the piece that carries out deletion on a schedule is not fully in service yet. Your request is honoured, but if you want it confirmed to you in writing, email [hello@pocketchronicle.app](mailto:hello@pocketchronicle.app) and a person will do it by hand and tell you when it's done.

Any of these by email to [hello@pocketchronicle.app](mailto:hello@pocketchronicle.app), and a person will handle it. No request form, no verification maze. You have these rights whichever privacy law applies to you, and we're not going to make you cite one.

## Security, scoped honestly

**What we can say:** everything travels over HTTPS and the server refuses plain HTTP. The database connection requires TLS. Media lives in a private bucket reached only by short-lived signed links. Sign-in tokens are stored as hashes, short-lived, and rotated. Your archive is private to you and to anyone you have invited — there is no feed, no discovery and no public profile.

**What we're not going to say:** we hold no security certification. Not SOC 2, not ISO 27001, nothing. Pocket Chronicle is built by one person, and a page claiming an audit that never happened would be a worse breach of trust than the gap it was hiding.

**And one thing worth knowing about sealed entries.** Sealing a letter is a promise between you and your future kid, kept by the app's interface — it is not encryption and it is not a lock. You can open a sealed entry yourself at any time, and an export includes sealed entries in plain text. If you write something you'd want protected from somebody with your phone in their hand, that isn't what a seal is for.

## Children's privacy

**Pocket Chronicle is not directed to children under 13, and no child has an account here.** We don't knowingly collect anything from a child, because there is no way for a child to give us anything — the only person who can put data in is the signed-in parent.

Data *about* a child is the whole point of the product, and the parent supplying it is the person the law expects to make that decision. If you believe a child has somehow been given access to an account here, email [hello@pocketchronicle.app](mailto:hello@pocketchronicle.app) and we'll close it.

**What happens when your child grows up.** The honest answer is that we haven't built a handover yet, and we're not going to describe one as though we had. There is no mechanism today for a grown child to claim their own archive, and no automatic transfer at any age. What exists today is the export — which is the whole archive, in ordinary files, readable without us — and a parent can hand that over on any day they decide is the right one. When something better exists, it will be a thing a family chooses rather than a switch that flips on a birthday, and it will be described here before it ships.

## This website

Everything above is about the app. The website you're reading is a much smaller subject.

It sets no cookies and runs no analytics. The fonts are ours and the images are ours, and no page here phones anywhere to watch you read it. There is no consent banner because there is no tracking to consent to. You can confirm that in your browser's developer tools, and we'd rather you did.

It collects nothing until you decide to [join the waitlist](/waitlist.md). If you do, the form sends your email address, which page you were on when you typed it, and the token the anti-spam check hands back. Three fields, and that is the entire request body — you can watch it leave in your browser's network tab. There's one hidden field in that form and it is not a tracker: an empty box a human never sees and an automated script fills in anyway. If it comes back with anything in it we quietly drop the signup.

**The one thing on this site that isn't ours** is [Cloudflare Turnstile](https://www.cloudflare.com/products/turnstile/), which checks the signup form. It loads on the two pages carrying that form and nowhere else, and it is the only third-party code this site ever runs. It sets no advertising cookie and doesn't profile you across other websites, but it does see your IP address and something about your browser, because that is how it tells a person from a script. That's a real third party seeing something real, and it belongs here rather than in a footnote.

Your address then goes to Resend, the company that sends our email, and the list lives there — we keep no copy of it in our own database, and the server that receives the form creates no row. Every email has a one-click unsubscribe, which removes you rather than moving you to a quieter list. One honest detail: unsubscribing leaves your address on a suppression list at Resend, which is how they know never to mail you again. Ask us to delete it outright and we will.

## Changes

When this page changes, the date below moves with it, and the date is the notice. If a change is one that affects what we collect or how long we keep it, you'll hear about it by email before it takes effect rather than after.

This page was last checked against what the app and the site actually do on August 25, 2026.
