Legal
Privacy Policy
innerstory is a private journal for iPhone. This policy is short because the app does very little with your data: it keeps it on your phone.
Last updated: 16 September 2026
The short version
innerstory collects nothing. innerstory transmits nothing. There is no account, no server, and no analytics.
What innerstory stores, and where
Everything you put into innerstory — typed entries, voice recordings and their transcripts, photographs, recognised handwriting, and the connections the app finds between entries — is stored only on your iPhone.
It is encrypted with AES-256-GCM before it is written to storage. The encryption key is generated on your device, held in the iPhone’s keychain, and never leaves the device. Media files are additionally written with iOS Complete File Protection, which makes them unreadable while the phone is locked.
What leaves your device
Nothing.
innerstory makes no network connections. It has no servers of ours to talk to. There is no cloud sync, no iCloud or CloudKit storage, no backup service, no crash reporting, no analytics, no advertising, no tracking, and no advertising identifier. The app contains no third-party SDKs of any kind.
Speech transcription, handwriting recognition and the analysis that finds connections between your entries all run on your iPhone, using frameworks built into iOS. You can use every feature of the app in airplane mode.
Access to your device
- Microphone — used only while you are recording a voice note, and only after you grant permission. Recordings are encrypted on the device.
- Camera — used only when you choose to take a photo or scan a page.
- Photos — innerstory uses Apple’s system photo picker. It never receives access to your photo library; only the specific images you select are handed to it. Location and camera metadata are removed from every image before it is stored.
- Face ID / Touch ID — used only to unlock the app. Biometric data is handled entirely by iOS and is never seen by, or available to, innerstory.
Data you choose to export
Settings includes an export that writes your entries to a plain text file you can save or share wherever you like. That file is not encrypted — that is deliberate, so it stays readable for as long as you keep it. Once you move that file somewhere else, this policy no longer governs it, and where it ends up is your choice.
Deleting your data
Deleting the innerstory app from your iPhone deletes everything it holds, including the encryption key. There is no copy anywhere else, so this cannot be undone. Any export files you saved elsewhere are not affected.
Children
innerstory is not directed at children, collects no personal information from anyone, and transmits no data.
Changes to this policy
If a future version of innerstory changes what happens to your data, this policy will be updated before that version is released, and the change will be described in the app’s release notes.
Contact
Questions about this policy: support@innerstory.app.
If you want the detail behind the claims above, the security page describes exactly how the encryption, the key handling and the lock behave.