Revised 28 September 2026
Your journal is processed on your iPhone. Onekept has no account, journal server, ads, tracking, or analytics SDK. The app collects no data: we do not receive your recordings, entries, usage or identifiers through the app.
Recordings, transcripts, reflections, summaries, and recovery records are stored in the app's private container. Settings are stored locally. iOS provides sandboxing and device data protection. The widget shares a smaller local snapshot containing derived lines, dates and counts, plus its language and routing state. It does not receive recordings or full transcripts.
SpeechAnalyzer transcribes on the device. iOS may download speech assets from Apple when a language is first used. Foundation Models processes reflection and summary prompts locally. If the model is unavailable or fails, the app produces a basic local result. Model availability and output quality depend on the device, language and installed resources.
Onekept does not provide a sync or cloud-backup service. Device backups and transfers managed by iOS are separate and may include app data according to your settings. See Apple's backup guidance.
Text and Markdown exports include entries or saved summaries. A restorable folder archive can include entries, their reflections, audio and saved summaries. An older folder without summaries still restores and does not invent reviews. The folder is readable and has no additional Onekept encryption. Onekept's Face ID lock protects the app, not exported files or archive folders. Move a copy outside the app folder before removing the app. Files you send to another app or storage provider are subject to that destination's privacy practices.
The optional app lock uses iOS authentication; Onekept does not receive your biometric data. Widgets are designed to hide their text when the app lock is enabled. Siri requires local device authentication before reading a saved weekly summary. Siri itself is an Apple service, governed by Siri and Dictation privacy terms; an app shortcut is not a guarantee that every Siri request is processed offline.
Daily and weekly reminders are optional local notifications. There is no push server. The weekly reminder opens the summary flow; it does not generate a summary in the background.
The app sends diagnostic events to Apple's system logging facility and has no diagnostic upload service. Those events are fixed labels plus an allowlisted error family and numeric code. They do not include freeform error text, transcripts, titles or file names. The app has no log store of its own. System log storage and diagnostic sharing are controlled by iOS.
Complete access is sold through Apple's in-app purchase system (StoreKit). Apple processes the payment and your Apple Account details; the developer receives no payment details and no information that identifies you. The app asks Apple only whether a purchase is active. It never sends journal content, recordings or transcripts for a purchase. Which free samples you have used and your purchase status are kept on your device. There is no Onekept account, so purchases are restored through Apple with Restore purchases. Apple's handling of purchases is governed by Apple's Privacy Policy.
If you email support, we receive the address and information you choose to send so we can handle your request. Do not send recordings, transcripts or sensitive diagnostic content. The website remembers your language choice in local storage. Web hosting and email providers process requests needed to deliver those services under their own terms; the app's lack of analytics is not a claim that a web server receives no connection data.
You can edit, export and delete saved entries from the app. Deleting an entry removes its associated audio when it is safe to do so. Delete everything also removes the app's recovery record and recordings it owns in its recordings directory. Archive folders you already wrote, copies in Files and backups managed by iOS stay where they are. Deleting the app removes its private container, but does not erase those independent copies or messages sent to support. We do not hold a remote copy of your journal that we can restore.
Onekept is not directed at children. Changes to this policy will be published with a revised date. Contact us with privacy requests concerning information you sent to support; the absence of a journal backend does not remove applicable privacy rights.
Onekept is operated by One Studio — Paulo Mateus Oliveira Guerra Tecnologia da Informação Ltda, CNPJ 68.620.790/0001-41, Rua Pais Leme 215, conj. 1713, Pinheiros, São Paulo/SP 05424-150, Brazil.
Privacy and support: support@onekept.app.