Alcove

Your privacy in Alcove

Last updated 4 October 2026, from the app's PRIVACY.md

Alcove is a private journal that is yours alone. It is built so that no one (not Apple, not us, not anyone who opens your iCloud backup) can read what you keep. (A phone that is switched on and has been unlocked since it started is protected by iOS itself, not by a second Alcove key; see Encryption below.) This document is the canonical, honest account of how that works: what stays on your device, what is encrypted, the little that ever leaves (and in what form), and the few honest caveats. It is the source of truth for the App Store privacy label, the onboarding copy, and any marketing claim: nothing here is aspirational; it describes the code as built (verified by a full data-egress / at-rest / on-device audit, 2026-06-10; re-verified 2026-06-29 and 2026-07-03, the latter adding the opt-in backup and key-bearing-export disclosures).

There is no server we run. Alcove has no backend, no account system, and no analytics. That isn't a policy promise we could quietly break; it is the architecture. Encrypted sync uses your own iCloud. Apple services used for maps, optional weather and requested photo downloads are described below; none is a cloud AI service for your journal.


What onboarding promises

Your saved journal is encrypted on this device. All in-app AI processing uses on-device models; unavailable models fall back to local behavior, not cloud AI. We operate no journal servers and collect no analytics.

Saved journal content syncs automatically as encrypted data through your own iCloud. To use one-device storage, disable Alcove in iOS Settings under iCloud. Audio and Atlas backup are optional. Map viewing and place search use Apple Maps; weather is off until enabled and sends a coarse area to Apple. Full original photos download from iCloud Photos only on request. Siri is governed by Apple's processing before it calls the app. These distinctions matter: "no servers of ours" does not mean "no network services."

Export is available without an unlock purchase. A readable copy contains the saved authored record; a restore backup can include recordings. Unfinished recovery drafts are excluded. The export screens describe the format and coverage before sharing. See Your control below.

The five promises

  1. On your device. Your entries, photos' places, walks, and the AI that reads them all live and run on your iPhone.
  2. Encrypted, always. Everything you keep is encrypted at rest with a key only your devices hold.
  3. No account, no tracking. No sign-up, no email required, no analytics, no ad identifiers, no third-party SDKs that phone home.
  4. Sync is yours. Sync runs automatically over your own iCloud as encrypted blobs we (and Apple) cannot read, never a server we operate. To keep the journal on one iPhone, turn Alcove off under your iPhone's iCloud settings.
  5. You can leave with your saved data. Export a readable copy or a restore backup any time, without buying. Unfinished drafts stay local.

On-device by default

What "encrypted" means here

Sync goes to your own iCloud, as ciphertext only

No accounts, no tracking

Location, precisely

Location is the most sensitive thing a journal touches, so here is the exact picture, without rounding:

What the rest of your phone can see

Everything that leaves the device

  1. Encrypted CloudKit blobs to your own iCloud private DB: the synced journal scopes (sync on), and, with Back up everything on, your voice recordings and trail shards (or a single recording you offload from the recordings list, under Backup and Restore). Ciphertext only, in your own iCloud.
  2. The encryption key + identity (and the trial-start date) via iCloud Keychain (Apple E2EE); the trial date is a timestamp, never content.
  3. A user-initiated export: either a plaintext JSON copy, or a .alcovebackup restore file, each explicitly sent through the iOS share sheet. The backup file carries your encrypted data and your journal key: raw by default so one file restores everything, or wrapped under a password you choose (the export screen says which, plainly). This is data portability; you choose where it goes, and the file deserves the same care as the journal itself.
  4. The purchase (a one-time unlock) runs through StoreKit 2 directly: Apple's App Store sees a receipt and an anonymous purchase, never journal content. No subscription, no RevenueCat, no payments middleman; nothing else is involved, and there is no account with us.
  5. (Opt-in, off by default) Local weather: if you turn on Local weather, coarse (~25 km) cells of places your days held are sent to Apple Weather to get temperature and conditions back, at most a few lookups per day, with results cached and stored encrypted. Apple Maps requests also identify an area, as described below.
  6. (Only while you type) Location-search text: when you use the timeline's Where filter and type a place ("San Francisco", "California", a café), those characters go to Apple's map-search service to offer matches. Only the text you type, only while you're searching. Alcove asks for results across the whole world rather than near you, and the matching of your moments against the area you pick happens entirely on-device.
  7. Map tiles and map pictures: to draw a map, Apple Maps is asked for the area on screen: the Atlas while you look at it, and the small map beside an entry, photo, walk or voice note (and a Scrapbook route) when you open it. That request carries the place, never your words, and goes to Apple's Maps service, which is not tied to your Apple ID. The small maps are never drawn for a place inside a Privacy Zone.
  8. (Only when you tap it) Download full photo: a photo or video whose original lives in your iCloud Photos opens as the preview this device has. Tapping Download full photo asks Apple's Photos framework to bring that one original down from your own iCloud Photos, as the Photos app would. Nothing is sent by Alcove; every other photo read stays on the device.
  9. Siri: if you ask Alcove something through Siri, what you say is handled by Siri under Apple's terms before Alcove sees it, and Alcove hands back only the words Siri speaks. Questions that read your journal back need this iPhone unlocked, and a locked chest answers nothing.

That is the entire list. Apart from those Apple services, each sending only what's described above, there is no other network path in the app: no HTTP client, no socket, no web view. A few links you can tap (the credits, this policy) open in Safari. (Place names are resolved entirely on-device from bundled data, © GeoNames (CC BY 4.0) and Natural Earth (public domain), so naming where you've been sends nothing anywhere.)

Your control

Open hardening (tracked, honest)

These are known edges we are closing or watching, listed here because a real privacy story names its own seams:

  1. Entry-stamp location in sync (a disclosed, deliberate choice). A place-stamped entry's coordinate syncs end-to-end-encrypted to your own iCloud so the entry reads the same on all your devices; no server can read it. We keep this and word every location claim precisely to match ("encrypted end to end, no server can read it"). Want zero location egress? Leave entry stamping off and Atlas backup off. Privacy Zones never sync regardless.
  2. Payments are resolved (StoreKit-direct). The app offers a 3-day free trial, then a one-time unlock purchase via StoreKit 2, entitlements checked on-device against the App Store, no RevenueCat or other middleman. Apple sees a receipt + an anonymous purchase, never content, so "no third party sees you're even a user" holds. (The trial start roams in iCloud Keychain so it's once per Apple ID; it's a date, not content.)
  3. Compile-out guard. Add a build/CI check that fails if a server SDK (Supabase, etc.) ever becomes linkable, so the "no backend" guarantee can't regress silently.
  4. CloudKit metadata. Inherent to iCloud sync; documented above, not code-fixable. Disclosed plainly rather than hidden.
  5. Words readable on a switched-on phone. The key and files use the "after first unlock" protection class so walks keep logging while the phone is locked. Planned: encrypt your words under a second key that is only readable while the phone is unlocked, leaving only the map writing in the background.
  6. An in-app "keep this journal on this device" switch. Today this is done in the iPhone's iCloud settings; a switch under Backup & sync is planned.

Last verified against the codebase: 2026-09-29 (the elevation audit: map tiles and pictures, Siri, sync being automatic, and when the key can be read, added to match the code). Keep this document honest: if the code changes, change this first.