MYSELF
Privacy Policy
IN SHORT
- This is a journal you keep for yourself. Every record you write stays on your own device by default — we hold no copy of it on our servers.
- There is no account and no sign-up. We do not collect your name, phone number, email address or contacts, and the app never asks where you are on its own — your location is read only when you choose to send a place (see “Location”). The app contains no advertising or tracking SDK and no third-party analytics of how you use it. Its one third-party component, RevenueCat, only keeps a record of purchases (see “Purchases and RevenueCat”).
- Part of what you record is sent onward only when you use the AI — when you message an AI role, and when the app periodically distills those conversations and your recent records into the AI's memory. That is the AI feature doing its job. If you never talk to an AI role, nothing you write ever leaves your device. One other thing reaches outside: when you share a link into the app, your device asks that link's own site for its title and cover (see “Shared links and music”).
1What we do not collect
To leave no room for doubt, here is what this app does not do:
- It requires no registration or sign-in; there is no user account on our side.
- It does not collect your name, phone number, email address, identity documents, contacts or calendar.
- It never tracks your location, in the background or otherwise: your location is read only at the moment you open the page for sending a place yourself (see “Location”).
- It does not collect the advertising identifier (IDFA), serves no ads, and performs no cross-app or cross-site tracking.
- It integrates no advertising, marketing-push, crash-reporting or usage-analytics SDK. The only third-party component in the app is RevenueCat, which keeps a record of purchases and receives nothing you write — see “Purchases and RevenueCat”.
- We do not sell, rent, or trade your personal information with anyone for marketing purposes.
2iCloud sync (optional)
iCloud sync is part of Pro — a subscription or the lifetime purchase — and you can switch it off at any time (Settings → iCloud Sync). When it is on, records sync through Apple's CloudKit into your own private iCloud database (container iCloud.name.wangchengfeng.talk-to-myself), so they reach your other devices and survive a lost phone. If a Pro subscription ends, syncing stops the next time the app launches: the records on your device stay where they are, and the copy already in your iCloud stays there until you delete it (see “Data retention and deletion”).
3Microphone and speech recognition
The microphone is only ever live after an explicit action of yours. Holding the talk button records a voice record: it stops the moment you lift your finger, and the recording is stored on the device as a voice message (and syncs to your own iCloud if iCloud sync is on).
Turning speech into text uses Apple's speech recognition framework. When the device supports on-device recognition, the app requires recognition to happen locally. On a device that does not, live transcription is handled by Apple's system speech service — an Apple system behaviour, and even then the audio never touches our servers. Older voice records are transcribed later strictly on-device, or not at all.
The transcript is kept on the device alongside the recording as a machine note. The app does not display it; it exists only so the AI can understand voice records — see “What using the AI sends”. Voice records never leave the device as audio.
Voice dictation in an AI chat is the one deliberate exception. Tapping the microphone beside the AI chat's input field records while you speak; when you tap stop, the app sends that one recording to our server, which passes it directly to OpenAI's transcription model to turn into text. The words land in the input field for you to review, edit, send — or delete. Our server does not store the recording or its transcript; the audio passes through only for the moment of transcription. OpenAI's provider data practices apply. Nothing is recorded until you tap the microphone, and nothing is sent until you tap stop.
4Photos
You can send a photo from your library into a role's chat as a record. The app reads only the photos you pick yourself in the system picker; it does not scan your library or read anything else in it. Photos are stored in the record on your device (and sync to your own iCloud if iCloud sync is on). Apart from the AI feature described under “What using the AI sends”, they are not uploaded anywhere.
Saving a review's share image to your library is the other way round: the first time you tap Save to Photos, the system asks for permission to add photos. That grant lets the app put that one image into your library and nothing else — it cannot read, list or change any photo in it.
5Location
You can send a place into a role's chat as a record (⊕ → Location). Your location is read only when you open that page yourself, and only once, to show where you are and the places nearby; the app never reads it in the background or at any other time. Location access is optional: without it you can still search for a place, or drag the map to pick one.
What is kept is only the place you choose to send — its name, address and map coordinates — stored in the record on your device (and in your own iCloud if iCloud sync is on). The map, the place names and the search come from Apple's Maps service, under Apple's privacy policy; our server is not involved.
A place you have recorded can be sent to the AI as its name and address, in text — see “What using the AI sends”. The AI never receives its map coordinates.
6Shared links and music
You can share a song from a music app, or any web page, into a role's chat (the system share sheet → Me with Me), or paste a music link into a chat. It is kept as a card: the link's address, its title, the artist for a song, and a small cover image — stored in the record on your device (and in your own iCloud if iCloud sync is on). Plain text shared this way becomes an ordinary written record.
To show that card, your device asks the link's own site for its title and cover — once, at the moment you share or paste the link. The request goes straight from your device to the service the link belongs to (for example Apple Music, Spotify, NetEase Cloud Music or QQ Music), which sees what it would see of any visitor to that public page — your IP address and the page asked for — and nothing from your journal. The request carries no cookies and does not pass through our server. The card is not refreshed afterwards. Tapping it opens the link in that service's app or in your browser, where that service's own privacy policy applies.
A link you have recorded can be sent to the AI as the words on its card — a song's title and artist, or a page's title and site name — see “What using the AI sends”. The AI never receives the link's address or its cover image.
7What using the AI sends
When you use the AI, some of what you have recorded in the app is sent to the AI so that it can do its job. This is one of the app's features rather than a side effect: it is what lets the AI understand you and answer in a way that fits your life rather than in generalities.
Three kinds of requests leave the device. Chat: when you message an AI role, a bounded selection of your records and that role’s conversation is sent to generate the reply. If you ask about something from further back, the AI can have the app search your records on your device — by date, keyword or role — and the records it finds are sent as text with a follow-up request (up to about 40 per search). Photos and audio are never sent this way, and other AI roles’ conversations are never searched. If you ask an AI role to note something down for you, it can have the app write it into one of your roles on your device, as your own record — marked as noted by that AI role, with a receipt under its reply that lets you undo it. The words it writes pass through our server only within that conversation’s requests, and are not stored there. Memory: from time to time — typically when the app moves to the background after enough new material has gathered — that role’s recent conversation and the records you have recently written in non-AI roles (as text), together with the memory built so far, are sent so the model can distill them into a short set of remembered facts and a summary of earlier conversation. Your records take part in this only after you have talked to an AI role at least once. The remembered facts are shared by all of your AI roles; raw AI conversations and earlier-conversation summaries remain separate for each role. What comes back is stored on your device, not on our servers, and shapes how the AI replies to you later. You can review, edit, pin or delete every remembered item, or clear them all, under Settings → AI Memory.
Review: a weekly or monthly review is generated only when you tap the button for it — never in the background. That one request sends the text you wrote in that week or month (together with AI roles’ replies in it and a few counts the app has already made, such as records per day), and what comes back is a short paragraph stored on your device. Photos, audio, voice transcripts, places and shared links are not part of a review request.
A voice record can be included as its transcribed text once the device has transcribed it (see “Microphone and speech recognition”), a place you have sent as its name and address in text, never its coordinates (see “Location”), and a song or page you have shared as the words on its card — title, artist and site name — never its address (see “Shared links and music”). Photos you sent into an AI chat can accompany these requests; the memory request may carry a photo one last time so it can be described in a line of the summary. These requests never carry audio — the one case where audio leaves the device is the voice dictation you start yourself, described under “Microphone and speech recognition”.
What is sent is used solely to generate that one reply, that one memory-and-summary update, or that one review. We do not write it to a database, do not use it to train models, and do not use it for profiling or advertising of any kind. The memory the AI keeps about you lives on your device, where you can always see and change it.
8Purchases and RevenueCat
Purchases are made through Apple's App Store. We never see your payment details or your Apple ID.
To keep a record of which purchases exist, the app includes one third-party component: the SDK of RevenueCat (RevenueCat, Inc., United States). When the app starts, and when you buy or restore a purchase, the app sends RevenueCat:
- a random anonymous ID that RevenueCat generates for this installation;
- Apple's signed record of your purchases in this app — product, purchase and expiry dates, transaction IDs, price, currency and App Store country;
- basic technical details: the device's vendor identifier (IDFV — specific to our apps on your device, and not the advertising identifier), device model, system version, app version, your preferred languages and, as with any network request, your IP address.
RevenueCat receives nothing you write: no records, photos, recordings, AI conversations or AI memory — and no name, email address or Apple ID. We use it only to keep a record of purchases; it is not used for advertising or to track you across apps. Whether Pro is unlocked is decided by Apple's StoreKit on your device and by our own server, not by RevenueCat. RevenueCat handles this data on our behalf, under its own privacy policy at revenuecat.com/privacy.
9What our server stores
To verify purchases (a Pro subscription or the lifetime purchase), prevent double billing, limit abuse and account for model cost, our database stores only the metadata below. None of it contains the content of your records or the model's replies.
| Item | Content | Purpose |
|---|---|---|
| Account token hash | The SHA-256 of a random UUID generated on your device (no Apple ID, and it cannot be reversed into an identity). Requests made under a lifetime purchase are counted under the SHA-256 of that purchase's App Store transaction ID instead | Ties purchase state and usage together without needing an account |
| Purchase details | For a subscription: App Store transaction IDs, product ID, sandbox/production environment, expiry, last verification time. For a lifetime purchase: its App Store transaction IDs, the environment, whether Apple has refunded or revoked it, and when that was last checked | Deciding whether the subscription is active, or the lifetime purchase still stands |
| Request and usage metadata | For each AI request: the role's ID, the request kind (chat / memory / review), model name, status, token counts (including prompt-cache metering), timestamps, and an error code when one occurred — never the content | Request deduplication, rate limiting, troubleshooting and cost accounting |
| Free-allowance counter | How many free AI replies the account has used in the current calendar month | Metering the monthly free allowance |
10Data retention and deletion
On your device and in iCloud
- Settings → Data Management → Erase All Data asks you to type a confirmation word, then permanently deletes every record, photo and recording on the device — and, if this device ever synced, the copy in your iCloud along with it. This cannot be undone. (Deleting the iCloud copy needs a network connection and a signed-in iCloud account; if it does not go through, the app says so.)
- Deleting the app removes its local data. The iCloud copy can also be removed at any time under Settings → Apple Account → iCloud → Manage Account Storage.
- You can export first: Settings → Data Management → Export records produces a PDF (for reading and printing) or JSON (a structured backup).
Metadata on our server
We keep this metadata only for as long as the purposes set out under “What our server stores” require, and delete it once it is no longer needed:
- Purchase details: for a subscription, kept until it has ended and any refund, billing dispute or reconciliation arising from it has been settled; for a lifetime purchase, kept for as long as the purchase stands, since that record is what keeps authorizing your AI requests.
- Request and usage metadata: kept until it is no longer needed for request deduplication, troubleshooting and cost accounting.
To have the records on our server that relate to your purchase deleted, contact us at the address at the foot of this page.
Because the content of your records is never written to our servers' storage — what an AI request sends only passes through server memory to produce the response — there is no journal content there to delete.
11Your rights and choices
- Access and export: everything lives on your device, and Export records gives you a complete copy whenever you want one.
- Correction and deletion: records can be deleted one at a time, in batches, or all at once.
- Withdrawing consent: switch off iCloud sync, cancel the Pro subscription, or revoke any permission in system Settings.
12Minors
This app is not designed for children under 14 and we do not knowingly collect their personal information. If you are a minor, please use it with the consent and guidance of a guardian; guardians who need something addressed can contact us at the address below.
13Changes to this policy
This policy is updated whenever the app's behaviour changes, and the date at the top of the page moves with it. If a change materially expands what we collect or how we use it, we will say so prominently in the app and, where required, ask for your consent again. Continuing to use the app means you accept the updated policy.
Contact us
For any privacy question, request or complaint, email wangchengfengx@gmail.com.