Privacy Policy
foldnote holds the private correspondence of two people. This page says exactly what is stored, who can reach it, and how to take it back.
Last updated 27 August 2026 · applies to foldnote for iOS
1The short version
- No phone number, ever. foldnote does not ask for one and has no field to put one in.
- No advertising, no ad identifiers, no data sold or shared with brokers. There is no advertising business here to feed.
- Your notes are private to the two of you, enforced in the database rather than in the app. They are not end-to-end encrypted — see section 8, which explains what that does and does not mean.
- You can delete your account from inside the app, without emailing anybody, and it takes effect immediately.
- Your history is never held hostage. Cancelling a subscription does not hide, lock, or delete anything you have made.
2Who this is with
foldnote is made and operated by set legalEntity in site.config.ts. In data-protection terms that is the controller of the personal data described here. Questions, requests and complaints go to set contactEmail in site.config.ts.
3What foldnote collects
Things you enter
- An account identifier. If you use Sign in with Apple, that is the identifier Apple issues plus whatever address you chose to share — including Apple’s private relay address, if that is what you picked. If you sign in with an email address, that address.
- A display name, and optionally pronouns and a profile photo. Pronouns are a free-text field, not a menu; whatever you type is stored as typed.
- Facts about the relationship the app needs in order to work: the start date, a timezone, and the four setup answers — roughly how long you have been together, whether you live together, whether you are long distance, and whether there are children.
- Milestones you add, with their dates and reminder settings.
Things you make
- Notes. A note is stored as the strokes that make it — tool, colour, width and points — plus any text layers and any photograph you added, plus rendered images of the finished note used by the archive and by the widget.
- Answers to the daily question, and when each was written.
- Streak and activity dates — which days the two of you were active.
Things the app records on its own
- A push token for the device, so a note can reach the other phone.
- Subscription status — which product was bought, whether it is active, and whether the entitlement came from you or from your partner. The purchase itself is handled by Apple; card details never touch foldnote.
- Product analytics. Events about how the app is used — a note was sent, a reveal was opened, a widget was added, a paywall was shown, pairing completed and how long it took. These carry the kind of thing that happened, never its contents: no note, no answer, no question text is included in an analytics event.
- Crash and error diagnostics — the app version, the iOS version, the device model, and a stack trace when something fails.
4What it never collects
foldnote does not ask for, receive, or store: a phone number; your contacts; your location; your calendar; health or fitness data; an advertising identifier; or anything from other apps on your phone. It requests access to your photo library only at the moment you choose to put a photograph into a note, and only the photograph you pick is uploaded.
5Why each piece is collected
| What | Why | Lawful basis, where that applies |
|---|---|---|
| Account identifier, display name | To have an account at all, and to pair two of them | Performance of a contract |
| Notes, answers, milestones, photos | They are the product; storing them is the service | Performance of a contract |
| Relationship start date, stage answers, timezone | The counter, the milestones, and which questions are chosen | Performance of a contract |
| Push token | Delivering a note to the other phone and refreshing the widget | Performance of a contract |
| Subscription status | Unlocking Premium, and passing it to your partner | Performance of a contract |
| Product analytics | Finding where the app is failing people, and fixing it | Legitimate interests |
| Crash diagnostics | Making the app not crash | Legitimate interests |
6What your partner can see
This is the part worth reading twice, because foldnote is a shared space by design.
- Your partner sees your display name, pronouns and profile photo, every note you send them, your answers once you have both answered, the milestones added to the shared couple, and the streak, which belongs to both of you.
- They do not see your email address or Apple identifier, your device details, or anything you typed and did not send.
- An answer to the daily question is not visible to either of you until both have answered. The question always comes from foldnote, never from your partner, so choosing not to answer reveals nothing about what you wanted to ask.
- If one of you buys Premium, the other is told that they have Premium and that it came from their partner. No payment detail is shared in either direction.
7Who else handles it
foldnote is run by one person, on infrastructure from a small number of companies. Each of these is a processor acting on documented instructions, and none of them is permitted to use your data for their own purposes.
| Who | What they handle |
|---|---|
| Apple | Sign in with Apple, all payments and subscriptions, and push delivery through the Apple Push Notification service |
| Supabase | The database and file storage — accounts, notes, photos, answers, milestones |
| RevenueCat | Subscription state, and passing the entitlement to your partner |
| PostHog | Product analytics events |
| Sentry | Crash reports and error diagnostics |
Nothing is sold. Nothing goes to an advertising network, a data broker, or a model training set. Data may be disclosed if the law actually requires it, and if that ever happens you will be told unless telling you is itself unlawful.
8How it is protected
- Everything travels over TLS, and is encrypted at rest by the hosting provider.
- Access is enforced by row-level security in the database, not by the app asking nicely. A request that is not from one of the two people in a couple does not return that couple’s rows, whatever the app does.
- Payment card details never reach foldnote. Apple handles the transaction.
- Notes are not end-to-end encrypted, and this policy will not imply otherwise. The server holds the strokes and the images so that the widget can be rendered and your archive can survive a lost phone. That means the operator could technically access them. They are not read, not mined, and not used to train anything — but “we do not” is a different promise from “we cannot”, and you are entitled to know which one you have.
9How long it is kept
Content is kept until you delete it or delete your account, because an archive that quietly expires would defeat the point of the product. Crash diagnostics and analytics events are kept for a limited retention period set with each provider and are not used to build a profile of you.
10Deleting your account
More → Account → Delete account, inside the app. No email, no support ticket, no waiting. It is irreversible and the app says so twice before doing it.
What happens is deliberate rather than incidental, so it is written out here:
- Your account, profile, answers to daily questions, and the couple’s link between you are deleted.
- Notes you sent your partner stay in their archive, and stop identifying you. The authorship is removed — no name, no pen colour, no link back to an account. This is the one deliberate exception, and it exists because a note is a gift that already arrived: deleting your account should not reach into someone else’s memories and take things out of them. If you want a specific note gone from their archive too, delete that note before deleting your account.
- Photographs you uploaded that no remaining note refers to are removed from storage.
- A subscription is not cancelled by deleting your account — subscriptions live with Apple. Cancel it in Settings → your name → Subscriptions.
11Your rights
Depending on where you live you have some or all of the following rights: to know what is held about you, to get a copy of it, to correct it, to delete it, to restrict or object to certain processing, and to complain to your local data protection authority.
Deletion is built into the app and needs no request. For anything else, write to set contactEmail in site.config.ts and you will get an answer within 30 days. There is no charge, and asking will never affect your account.
12Notifications
Push notifications are optional and iOS asks before any are sent. When they are on, foldnote keeps their wording deliberately plain — “Sam sent you something” rather than the content of what was sent. Notification text never carries the contents of a note, an answer, or a question from an intimate category, because a phone on a kitchen table is read by whoever is standing near it.
13Children
foldnote is rated 17+ and is not intended for anyone under 17. It is not directed at children and does not knowingly collect data from them. If you believe a child has created an account, write to set contactEmail in site.config.ts and it will be removed.
14Changes to this policy
If this policy changes in a way that affects you, the date at the top changes and the app tells you before the change takes effect. Older versions are available on request.
15Contact
set legalEntity in site.config.ts
set contactEmail in site.config.ts
A postal address is required by some data protection regimes. set legalEntity in site.config.ts
Questions about this page go to set contactEmail in site.config.ts.