Effective September 6, 2026
Privacy Policy
What the app sends
As Lived does not collect your journal content, account identifiers, search queries, diagnostics, or usage analytics. The current app does not create an online account or connect to Clerk or a developer-operated journal API. It does not upload your photos, videos, recordings, captions, transcripts, faces, locations, or mood records to us.
On-device access
New journals open without sign-in. If you upgrade an existing beta archive, the app asks you to verify with Face ID or your device passcode before using that archive without its former account gate. Existing entry and journal privacy locks remain in place. No archive content is sent away during this verification.
Earlier beta accounts
Earlier TestFlight builds used Clerk for Apple sign-in. Upgrading does not automatically delete a previously created online account. See account and information details for the separate controls available to earlier beta testers. The current app does not use those accounts to open or store your journal.
What stays on your device
In the current release, the protected app container may hold memories, captions, typed notes, local speech transcripts, dates, favorites, tags, user-entered people, place labels, app-owned photo, video, and voice files, on-device visual-analysis results, legacy recap plans and videos retained from earlier builds, Daily Context facts explicitly accepted in an earlier internal build or restored archive, settings, a rebuildable search index, thumbnails, and backup history. The current release does not acquire new Daily Context suggestions.
Apple services and user-selected providers
Apple frameworks may use a network connection when iCloud Photos retrieves an original you explicitly request or when Apple reverse-geocodes a photo coordinate into a place label. The current app does not use EventKit, HealthKit, WeatherKit, or MusicKit for Daily Context. If you choose a third-party Files provider or share destination, that provider receives only the files or archive data you select and applies its own privacy policy.
Daily Context controls
Daily Context acquisition is unavailable in the current release. This build has no Calendar, Reminders, Health, Apple Music, Weather, or Photos-metadata context provider and does not present controls that can request those services. It never collects provider history in the background or fills gaps through scraping or inference. If an upgraded or restored archive contains facts accepted in an earlier internal build, you can still read, edit, remove, clear, search, export, back up, restore, and delete those local records without changing your prose.
Mood and activity controls
Mood tracking is optional, local, and off on a fresh install. As Lived stores a mood or energy value only after you enable tracking and select it; it does not infer emotion, mental health, diagnoses, personality, relationships, or causes from your memories or media. You can edit or delete check-ins, turn off new tracking while keeping existing data, or erase mood data separately. Trends and reflections use bounded deterministic calculations or supported on-device Apple models, hide conclusions when samples are too small, and exclude protected-journal content until you authenticate. Mood values, notes, activities, analytics, and reflections are not sent to the developer, hosted media, analytics, or a cloud AI service.
Photos, camera, microphone, speech, and other permissions
These permissions are requested only for features you choose. Denying them does not prevent text-only memories. Voice transcription is configured to require supported on-device recognition and does not fall back to a developer speech service.
On-device analysis
In the current release, visual analysis, OCR, search, and supported story-generation features run on the device. The app never automatically names a person and prohibits sensitive personal-trait inferences. The current app does not offer Daily Context acquisition or context-to-draft generation, and no context or archive content is sent to a remote AI. You can disable visual analysis.
Backups and data deletion
You start every backup and choose its Files destination. Optional encryption uses a passphrase that the app does not store and the developer cannot recover. Deleting the app can delete its private on-device archive; a separate Files backup is not deleted with the app. A backup includes legacy context facts you explicitly attached, and the current app acquires no new suggestions. Use Settings → Data controls to delete the local archive. Backups in Files are separate copies under your control and must be deleted separately if you no longer want them.
Security and diagnostics
The app can lock its archive UI with device authentication and obscures its interface when leaving the foreground. Release logs use a closed set of technical events. The public beta does not execute Daily Context providers or emit provider-query diagnostics. Logs exclude legacy context values, private content, identifiers, coordinates, filenames, and encryption material.