Privacy

Private by default.

Draft for legal review · 2026-08-08

CabinCalm is designed so the core experience works without an account. Your trigger choices, reflections, and offline content are stored on the iPhone by default, protected by iOS file protection and an encryption key kept in Keychain.

Current access boundary

The current iPhone build does not request calendar, location, notification, camera, microphone, or contact access. It does not offer account sync, live companion sharing, or background flight tracking. Those are future product decisions, not current data practices; they must receive a separate privacy review before implementation.

Telemetry

The native iPhone target links pinned PostHog iOS 3.69.3, but the checked-in public project token and host are empty, so the SDK is disabled and unconfigured by default and sends nothing. It can activate only after you explicitly enable Share anonymous product analytics and the app has both a valid public token and a valid HTTPS ingestion host. When active, a closed app-specific event, property, and value schema permits only product-use events under a random, resettable, non-linked identifier; it excludes flight details, trigger choices, anxiety scores, reflections, free text, screen recordings, crash reports, and person profiles. CabinCalm ships no advertising SDK, requests no ATT permission, uses no IDFA, and disables session replay.

This site has an optional, separate telemetry path. It is disabled until you choose Allow anonymous analytics; declining or making no choice sends nothing. The preference is stored locally in this browser so the site does not need a cookie or account. When enabled and the endpoint is configured, the source contract sends schema version 1 events named marketing_page_view and marketing_cta_clicked, with the page path and a small allowlisted surface/CTA value. It does not send flight details, trigger choices, reflections, anxiety scores, names, email, precise location, or free text. The Worker rejects unknown events and properties.

The optional website endpoint is designed for Cloudflare Workers and D1. Cloudflare may process request and abuse-prevention metadata, and Turnstile may process a challenge token when configured; the current site source does not use PostHog or an advertising processor. The Worker source defaults to deleting telemetry rows after 30 days, with a bounded 7–365-day configuration range and scheduled cleanup. The exact production processor configuration and retention value must be confirmed before publication.

Your controls

Settings provides export and delete for local data. The current Share summary action stays on-device and does not create a recipient account or live link. For optional site telemetry, clearing this site’s storage withdraws the local consent choice; no account exists. The current Worker has an authenticated operator deletion route for records before a supplied date, but there is no public self-service telemetry deletion form or staffed privacy mailbox in this source build. That process, the public contact, and any deployed deletion request are manual release gates.

This page is a product draft, not the final legal notice. The public privacy URL, processor terms, exact production retention, contact/deletion process, and App Store privacy answers require legal and deployment review before publication.

Back to CabinCalm