Privacy policy · Effective 5 August 2026

Privacy

There is nothing to collect, because nothing is collected.

In short

Retold has no account, no server, and no network code. Your recordings, transcripts, observations and weekly reviews are written to this app’s own storage on your iPhone and stay there.

We do not receive them. We could not read them if we wanted to, because they are never sent anywhere. The only bytes that ever leave your phone are the ones you hand to something else yourself — through the iOS share sheet, an export, or a backup file you save.

If you delete the app, everything goes with it. There is no copy elsewhere to ask us about.

Who this covers, and what it covers.

This policy applies to Retold, the iOS app, and to this website. Retold is made by Reboot the Future, referred to below as “we” and “us”. You can reach us at hello@example.com.

It is short because the app is built so that there is little to say. Privacy claims are cheap; this one is checkable. The app’s own privacy screen lists the frameworks linked into the binary and what each is for, and that list is reproduced on this site. If a framework is added or removed, both change with it, or the claim stops being auditable.

What we collect: nothing.

We collect no personal information, no usage data, and no diagnostics. Not in an anonymized form, not in an aggregated form, not for a legitimate interest. There is no mechanism in the app by which we could.

  • No network code — zero uses of URLSession or sockets
  • No network entitlements in the app’s signature
  • No analytics or telemetry of any kind
  • No account to create — and no backend for one to live on
  • No advertising or attribution SDKs linked into the binary
  • No silent cloud sync — backup is a button you press, encrypted with your passphrase

Because we collect nothing, there is no sale of data, no sharing with third parties, no advertising or profiling, no cross-app tracking, and no automated decision-making about you. Those sentences are not a policy position we could change quietly; they are a description of a binary with no way out to the network.

What the app holds, and where it holds it.

Retold stores what you give it, in its own container on your iPhone, under the protection iOS gives app storage:

  • Audio recordings — the original files, kept so you can play an entry back, re-transcribe it, or export it.
  • Transcripts — produced on the device, and editable by you.
  • Typed entries, titles and tags — whatever you write.
  • Observations and weekly reviews — written on the device by the on-device Apple Intelligence model.
  • Your settings — the day and hour you chose for the weekly review, reminder preferences, theme, whether the app lock is on.

All of it is processed on the device: microphone capture, speech recognition, the second transcription pass by the bundled model, and the writing of observations. No part of that pipeline involves a server, ours or anyone’s. It works in Airplane Mode, and it works the same way with no signal at all.

The app marks its audio folder as excluded from iCloud device backup. The rest of the app’s container is included in whatever backup of your iPhone you have turned on in iOS — that is Apple’s system backup of your own device, encrypted and held under your Apple Account, and not something Retold sends or can read.

We hold no copy of any of it, so we set no retention period. It stays until you delete it.

The only way anything leaves is you sending it.

Three things can move data off the phone, and each one is a button you press:

  • Share. An entry can be shared as Markdown through the standard iOS share sheet. Where it goes is your choice, and from that point it is governed by whatever you sent it to, not by us.
  • Export. A date range exports as a zip — one Markdown file per entry, plus the original recordings — and is handed to the share sheet. Nothing is uploaded. The zip goes wherever you send it.
  • Encrypted backup. Retold writes a single archive of your journal, encrypted with a passphrase you type, and hands you the file. You decide where it lives.

In every case the app hands a file to iOS and stops. It never opens a connection of its own, because it has no code that could.

The backup is a file you keep, not a service you trust.

The optional backup is encrypted with AES-GCM using a key derived from a passphrase you choose. The passphrase is never stored — not in the app, not in the file, not with us. Restoring asks for the same passphrase and opens the archive on the device.

This has a consequence worth stating plainly: if you lose the passphrase, the backup cannot be opened, by you or by anyone, including us. There is no reset, because there is nowhere a reset could come from. That is the point of it.

Nobody else holds a copy and nobody else can open it.

What the app asks permission for.

Three prompts, all optional except the first, and all revocable in iOS Settings at any time:

  • Microphone. Required to record. Audio is written to the app’s own storage and transcribed on the device.
  • Notifications. Off by default. If you turn them on, reminders and ‘your review is ready’ notes are scheduled on this device by iOS. There is no push server involved and nothing travels over the network.
  • Face ID or your passcode. Off by default. If you turn the app lock on, iOS performs the check and tells Retold yes or no. Retold never sees your face, your fingerprint, or your passcode.

Purchases go through Apple, not through us.

Recording, transcription, typed entries, search, export and backup are free. The observer, the weekly review and the observation library are unlocked by a purchase. That purchase is handled entirely by the App Store using StoreKit. Retold runs no backend of its own and no payment code of its own.

We never see your payment details, your Apple Account, your name, or your email address. What Apple provides to any developer is aggregated sales and download reporting, which identifies nobody. Apple’s handling of your purchase is covered by Apple’s privacy policy, not this one.

Whether you have purchased is recorded on your own device so the app knows what to unlock. That flag stays on the device.

One thing that is not ours to switch off.

iOS itself can send Apple anonymous diagnostic and usage reports, and can share some of them with the developers of the apps involved. That is a system setting you control, under Privacy & Security → Analytics & Improvements in iOS Settings, and it applies to every app on the phone, not only this one.

Retold contains no analytics code and adds nothing to those reports. We mention it because a policy that claimed the phone sends nothing, ever, would be describing something other than an iPhone.

Bundled components, all of them local.

Retold includes third-party work, but no third-party services. Each of these ships inside the app and runs on your device. None of them is a network client, and none of them receives anything:

NVIDIA Parakeet TDT 0.6b v3
The speech-to-text model that sharpens each transcript after recording, licensed CC-BY-4.0, CoreML conversion by FluidInference. The model folder ships inside the app — roughly 483 MB of the install — and never downloads.
FluidAudio
Open-source (Apache-2.0). Used purely as an on-device CoreML runner for the model above. Its offline mode is set before anything touches it, so an accidental fetch fails rather than reaching the network.
Newsreader
The typeface, by Production Type, bundled under the SIL Open Font License. It is a file in the app, not a webfont service.

Apple’s own frameworks — SwiftUI, SwiftData, AVFoundation, Speech, FoundationModels, ActivityKit, WidgetKit, AppIntents, BackgroundTasks, UserNotifications, StoreKit, CryptoKit, UniformTypeIdentifiers, LocalAuthentication — are listed one by one, with what each is for, on the privacy section of this site and inside the app under Settings → Privacy.

Your rights, and why most of them have nothing to act on.

Data protection law gives you the right to ask an operator what it holds about you, to correct it, to have it deleted, to take a copy elsewhere, and to object to its use. Those rights apply to us in full. They simply arrive at an empty room: we hold no data about you, so a request to access, correct, delete or export it would return nothing.

What you can do, without asking anyone, is exercise the same things directly on your phone:

  • See everything. It is all in the Journal tab.
  • Correct it. Titles, transcripts and tags are editable.
  • Take it with you. Settings → Export journal exports Markdown and audio.
  • Delete one thing. Delete entry and audio, from an entry.
  • Delete everything. Delete the app. Nothing survives it, anywhere.

Retold collects no personal information from anyone, of any age. There is no account, no profile, and no way for us to learn who is using it.

If you would still like to put a request to us in writing, write to hello@example.com and we will answer.

This page keeps the same promise.

No cookies, no analytics, no tracking pixel, no embedded video, and not one line of JavaScript. Every byte it needs — the typeface, the stylesheet, the icon — sits in the folder next to it. It ships a Content-Security-Policy that forbids the browser from opening a connection at all. Read the source; it is short.

Like any web server, whoever hosts these files may keep ordinary access logs. We add nothing to them and use them for nothing.

Changes to this policy.

If this policy changes, the new version is published here with a new effective date, and the app’s privacy screen is updated in the same release. A change that meaningfully altered what the app does with your journal would be described in the release notes rather than left to be discovered.

Superseded versions do not silently disappear from the record: the file that produces this page is kept in the project’s history, dated.

Effective 5 August 2026 · Reboot the Future

Questions about any of the above: hello@example.com. Practical help with the app lives on the support page.