Last updated 19 September 2026
Privacy Policy
The Unsorry app collects no personal data: no account, no advertising, no profiling. The one thing we ask for lives on this website, not in the app — the waiting-list form on the home page, which asks for an email address and nothing else; it is described under “The waiting list”. The app embeds two third-party components: the one that runs purchases and draws the subscription screen, and an anonymous usage measurement that stays off until you switch it on yourself. When you use them, it also relies on Apple services: iCloud Drive for your capsules, Apple Health for your cycle, Maps to look up a place. All of it is described below. This page describes precisely what the app does with information, which is very little.
Data we collect
From you, through the app: nothing at all. No server of ours receives anything about you from the app — the two requests it can make to our site — a version check and, if a correction exists, an attested download — are anonymous and carry nothing you typed. The one thing a server of ours does receive is the email address you type yourself into the waiting-list form on the home page, if you choose to — see “The waiting list”. There is no ad framework inside the app, and the one usage measurement that exists is off when you install it: until you switch it on in Settings › Privacy it is not even started — nothing is queued, nothing is sent later. See “Usage stats” below.
Two outside services can handle data for us. The first runs subscriptions and the lifetime purchase and draws the subscription screen; it only comes into play when the app checks, makes or restores a purchase, or loads that screen, and everything it sees is spelled out under “Subscription and lifetime purchase” below. The second measures how the app is used, and only if you switched it on; everything it sees is spelled out under “Usage stats”. Neither of them ever receives your name, your onboarding first name, your email address, your payment details, your words, your capsules or anything about your cycle. (The address you may leave on the site’s waiting list is not passed to them either: it goes to a third provider, Neon, and nowhere else — see “The waiting list”.)
Your first name
The app asks for a first name on first launch, and it is optional: you can continue without giving one. It is used only to compose the eyebrow shown above the affirmation and the title of the daily notification.
That name is written to the app’s local storage, shared with its widgets. It is never sent over a network, never attached to a request, and never inserted into the text of an affirmation. You can change or remove it in the app’s Settings.
Data stored on your device
The app’s entire state stays locally on your iPhone: your first name, the intentions you picked at onboarding, the life themes you turned on, your favourite affirmations, your board (pinned affirmations, visions, images, words and colours), your visual style, your app icon, your language, your reminder times, your level, XP, ✦ and streak, your proofs, your Comfort reserve, your self-portraits and, if you turned it on, your cycle.
Images you add to the board are picked with the iOS photo picker — the app only sees the ones you hand it — then copied into the app’s private storage, and never leave it: they are not uploaded, not analysed, not shared. Removing them from the board deletes them for good.
This information is deleted when you delete the app, except for capsules already stored in your iCloud Drive (see below). If you use your iPhone’s iCloud Backup or an encrypted local backup, that backup may include it; those are Apple’s encrypted backups, governed by Apple’s terms, not ours.
Your capsules and iCloud
A capsule is a message for your future self: a text, a voice recording or a video, with its date, its theme, what should open it and, later, your answer to “did it come true?”. Reflections you keep and Comfort messages are stored the same way. The microphone and the camera are only used while you record.
Capsules are written on your phone, in the app’s private storage, where iOS keeps them encrypted while the iPhone is locked. If the “Sync my capsules with iCloud” switch is on in the app’s Settings (it is by default when your iPhone is signed in to iCloud), they are stored in your own private iCloud Drive space, hidden from the Files app, and show up on your other devices signed in to the same account. That is Apple’s infrastructure, on your account, encrypted under Apple’s terms: we have no access to it, and no capsule ever passes through us.
Nobody reads a sealed capsule, least of all us: it is never sent anywhere else, never analysed, never transcribed. Deleting a capsule in the app deletes it from your phone and, if it is there, from iCloud Drive. Turning the switch off brings a copy back to your phone; what is already in iCloud stays there until you erase it.
Deleting the app does not erase capsules stored in iCloud Drive. To erase those too, use your account’s iCloud storage management (iOS Settings › your name › iCloud), where the app is listed by name.
Your cycle
Cycle tracking is off by default and only turns on if you ask for it (app Settings › My cycle). It is used to tune some reflection questions and to open a capsule at the start of a phase; the daily card never depends on it. It is not a medical feature: the app predicts nothing and gives no health advice.
The app keeps two values only: the first day of your last period and the length of your cycle. They stay in the app’s local storage, on this iPhone. They never go to iCloud Drive, never into a notification, never into the recap, never to our providers, and never into usage stats — in no form, not even the fact that you open that screen.
If you tap “Use Apple Health”, iOS asks you to let the app read your period days — read-only: the app writes nothing to Health. It reads the last fifteen months, works out the latest cycle start and a length, keeps only those two values, and reads Health again when you come back to the app to follow your changes. Raw Health data is never copied or sent. You can withdraw that access at any time in iOS Settings › Privacy & Security › Health.
Turning cycle tracking off erases both values and the link to Apple Health. A capsule you sealed until a phase keeps the name of that phase (for example “luteal”) and its opening date, like any capsule — so in your iCloud Drive if sync is on — but never your dates or your cycle length. Like the rest of the app, those two values may be part of your iPhone’s encrypted backup.
Your self-portraits
Self-portrait offers one photo a week, taken with the app’s camera at the moment you take it. Each photo is redrawn as a 1,080-pixel JPEG with no metadata at all — no location, no device — and stored in the app’s private storage, on your iPhone.
Your self-portraits never go to iCloud Drive, are never uploaded and never analysed: no face recognition, no processing off your phone. The film of your year in faces is put together on the iPhone when you open it, and erased when you close it. Like the rest of the app, self-portraits may be part of your iPhone’s encrypted backup, and they are gone when you delete the app.
Places and calendar
Place capsules. Location permission is only asked for when you seal your first Place capsule, and only “while using the app” — never “always”. You look the place up by name: the search and the map that shows it are served by Maps, Apple’s service, under Apple’s terms. The coordinates, radius and name of the place you chose are written into the capsule — so into your iCloud Drive if sync is on.
There is no continuous location tracking and no history. iOS itself watches for your arrival within the radius and shows the notification; the app does not receive your location. When you open the app while a Place capsule is sealed, it asks for your location once to check whether you are there, then forgets it: it is neither stored nor sent.
Calendar capsules. The app has no access to your calendar. You type the name of the appointment yourself and pick its time; both are copied into the capsule when you seal it.
Network requests
Everything you use daily works with no network at all: the app ships with its full corpus embedded. It makes four kinds of network request to us or our providers, the last of them optional: downloading a versioned corpus file published on this website, so corrections can reach you without an app update; the purchase calls described under “Subscription and lifetime purchase”, which happen at launch and around a purchase or a restore; loading the subscription screen, whose layout and pictograms (icons.pawwalls.com) are served by our subscription provider; and, if and only if you turned on the switch in Settings › Privacy, sending the usage stats described below. None of them is needed to read your affirmation of the day. The subscription screen is the one screen that does need the network, and it says so when it cannot load.
The Apple services the app uses — iCloud sync for your capsules, the place search and map from Maps — do not go through us: they connect your iPhone to Apple, under Apple’s terms, and carry nothing to this website. Apple Health is read on the device, with no network.
The corpus request is anonymous. It is authenticated with App Attest, an Apple mechanism that proves the request comes from a genuine installation of the app: the proof rests on a cryptographic key generated inside your iPhone’s Secure Enclave. That key names no person, does not follow reinstalls, and carries no account, no advertising identifier and no cookie.
Like any HTTPS request, each of these requests necessarily exposes your IP address to the host receiving it, which may keep it briefly in standard server logs. We do not use those logs to identify or profile anyone, and we do not join them to anything else.
Subscription and lifetime purchase
Unsorry Plus is sold through Apple’s App Store, as a yearly or monthly auto-renewing subscription or as a one-time lifetime purchase. Apple handles the payment, the billing and the renewal; we never see or receive your payment details. Apple provides us with aggregated, anonymous sales reports.
To validate a purchase and to restore your access from one device to another, the app uses RevenueCat, a subscription service operated by RevenueCat, Inc. in the United States. It acts as our processor: it handles this data on our instructions, for that purpose and for no purpose of its own.
At each launch and at each purchase, the RevenueCat component embedded in the app sends to its servers: a random, anonymous identifier it generates for your installation, your App Store purchase receipt and transaction history, the app version, the iOS version, the device model and the locale. During onboarding, the app also passes it the answer you picked to “How did you hear about the app?” (for example TikTok, Instagram or the App Store), as a code, so we know which channels lead to a purchase. It never sends your name, your onboarding first name, your email address or your payment details. As with any HTTPS request, your IP address is exposed in transit.
The subscription screen itself is laid out remotely: when you open it, the app fetches its description from RevenueCat — the text, the colours, the arrangement — along with the pictograms shown on it. That fetch exposes your IP address in transit, like any HTTPS request, and RevenueCat records that the screen was shown, then confirmed or dismissed, attached to the same random identifier. The prices come from the App Store, not from us. Nothing you put into the app — your first name, your favourites, your photos, your capsules, your streak — takes any part in that exchange. If that layout cannot be fetched, the app says so and offers to retry; nothing else in the app is affected.
RevenueCat keeps this data on servers in the United States. The identifier itself is a random string minted on your iPhone and connected to nothing else — it points at a purchase, never at you. Their own privacy policy lives at https://www.revenuecat.com/privacy
Usage stats (off by default)
To know what earns its place in the app and what does not, the app can send usage stats. This is off when you install it and stays off until you turn it on: app Settings → Privacy → “Share anonymous stats”. While the switch is off the measurement component is not even started — there is no queue, no delayed send, and nothing is caught up on the day you turn it on.
What goes out once you have agreed is a closed list of event names — “app opened”, “ritual done”, “capsule sealed”, “subscription screen shown”, “purchase completed” — with technical labels attached: which of the three rituals, the life-theme code (for example “amour-de-soi”), the kind of capsule (text, voice, video), your level, your language, and durations rounded into bands (“8 to 30 days”) rather than exact values.
What never goes out, and technically cannot: your first name, the text of any affirmation, anything you write in a reflection, the contents of a capsule, the name of a place or an appointment, a location, a photo, a self-portrait, a recording. A value we send can only be a number, a yes/no, or a lowercase technical code with no space and no accent — a sentence you wrote does not pass that filter and is dropped before sending. This is not a promise to be careful, it is the shape of the code, and our automated tests check it.
Your cycle appears in no form at all: not the phase, not your period date, not even the fact that you open that screen. Knowing someone uses that feature is already health information about her, and there is no “except for stats” exception to what this page promises.
No profile is built: there is no account, no email, no advertising identifier, and no link is made to your subscription. Events carry a random device identifier that names no one and follows nothing else. There is no session recording, no screenshot, and no automatic capture of what you tap: only the events we wrote one by one are sent.
The provider is PostHog, Inc., which hosts this data in the United States and acts as a processor: it handles it on our instructions, for this purpose and for no purpose of its own. Its privacy policy: https://posthog.com/privacy
You can turn the switch off at any time; sending stops immediately and the random identifier is discarded. Turning it back on later generates a new one: the two periods are not tied together.
Notifications
Every notification is scheduled locally by your iPhone: the affirmation of the day, whose content is computed on the device from the embedded corpus, and the notice that a capsule is ready to open. There is no push server: neither your first name, nor the affirmation of the day, nor your capsules pass through us. No notification mentions your cycle, and none shows what a capsule says.
Children
Unsorry is written for adult women and is not aimed at children. Since the app collects personal information from no one, it collects none from children either.
This website
Every page on this site is static. No cookie is set, and no font or image is pulled from a third-party domain. The site has one form — the waiting list on the home page, described just below — and it asks for an email address and nothing else. Our host keeps the ordinary access logs any web server keeps, nothing more.
The site counts its page views with PostHog, whose script is served by this site and which runs in cookieless mode: the measurement stores nothing on your device — no cookie, no local storage. It sends PostHog each page view with the referrer, device type, browser and operating system; what is recorded as the page is its path (for example /en/privacy/), without the part after a “?”, so no campaign parameter and no token. PostHog’s servers count visitors with a hash of your IP address, your browser and a salt that changes every day and is then deleted; that hash cannot be reversed, and the IP address itself is discarded on arrival. Come back tomorrow and you count as a new visit: we would rather count low than follow you around. No profile is built, no click is captured, no session is recorded. Those requests go through our own domain. PostHog, Inc. acts as our processor under its data processing agreement; these statistics are hosted in the United States. Its policy: https://posthog.com/privacy
The site also counts its page views with Google Analytics, whose script is the only one this site loads from a third-party domain (googletagmanager.com), and which runs in its cookieless mode: every consent signal is declared to it as refused, so it sets no cookie, reads nothing from your browser and keeps no identifier — it only sends Google each page view with the referrer, an approximate location derived from your IP address (which Google Analytics does not store), device type, browser and operating system. Google Ireland Limited acts as our processor for that measurement; these statistics are hosted in the United States under the EU–US Data Privacy Framework. Its policy: https://policies.google.com/privacy
The site finally counts its page views with Vercel Web Analytics. Its script is served by this site, from our own domain: here too your browser contacts no third-party domain. It sets no cookie and no local storage, creates no profile and keeps no persistent identifier — it sends each page view with the referrer, the country, the device type, the browser and the operating system, and visitors are counted through an ephemeral fingerprint computed on the servers, never an identifier placed on your device. Vercel Inc., which already hosts this site (see the legal notice), acts as our processor for that measurement. Its policy: https://vercel.com/legal/privacy-policy
All three measurements rest on our legitimate interest in knowing how the site is used. You are shown no consent banner because nothing is written to or read from your browser — there is nothing to consent to. Since none of the three keeps an identifier there is nothing to erase, but you can write to us with any question.
The waiting list
The site’s home page offers a form: you leave an email address there to be told when the app ships. It is optional — the site works entirely without it, and the app has no need of it at all.
What we record: your email address, the language of the page you signed up from (so we write to you in that language), and the date. Nothing else. We do not record your IP address, your browser, the page you came from or your name — the form does not ask for them and the server does not keep them.
Why: to send you one email, on the day the app ships. One. That address is used for nothing else: no newsletter, no follow-up, no advertising, no resale, no passing it to anyone. The legal basis is your consent, given when you submit the form; the notice next to it on the page says exactly that.
Where: with Neon Inc., our database host, acting as our processor under its data processing agreement. The database sits in the European Union (Frankfurt). Their policy: https://neon.com/privacy-policy
How long: until the launch email has gone out, after which the list is deleted. Before that, you can ask to be removed at any time by writing to emmanuel+unsorry@captaindev.io; we delete the row on receipt, and no copy and no archive of it remains. Through the same channel you can also ask for access to what we hold — which will be your address, your language and your sign-up date.
Export and erase
The app has no “Export my data” or “Erase everything” button: your data lives with you, not with us, and this is how you erase it. A capsule is deleted from within the app, from your phone and from iCloud Drive alike. Turning cycle tracking off erases your dates. Deleting the app erases everything it keeps on your iPhone — first name, board, proofs, self-portraits, cycle, progress. Capsules stored in iCloud Drive are erased from your account’s iCloud storage management (iOS Settings › your name › iCloud).
You can get your capsules back on another device by keeping iCloud sync on, and share an affirmation or your recap as an image.
Your rights
The only personal data we hold is the email address you may have left on the site’s waiting list. You can ask for access to it, or for it to be corrected or erased, by writing to emmanuel+unsorry@captaindev.io, and we do it on receipt: erasure is immediate and final, there is no archive. Everything else is not ours to hold: your first name, your capsules, your cycle and your photos are on your phone and in your own iCloud, under your sole control. The one identifier that exists elsewhere is the random one generated for your installation by our subscription provider: it names no person, and we can have it erased on request, along with the purchase history attached to it. Erasing it does not cancel a subscription, which lives with Apple. If you turned usage stats on, the random identifier attached to them can be erased the same way — and turning the switch off in the app’s Settings is enough to stop all sending, with no need to write to us. Write to us and we will look into it.
Changes to this policy
Should the app ever start doing something different with data, you will read it here before it ships — new date at the top, and a line in the release notes for anything substantive.
Contact
Questions about privacy: emmanuel+unsorry@captaindev.io