Your privacy in Alcove
Last updated 4 October 2026, from the app's PRIVACY.md
Alcove is a private journal that is yours alone. It is built so that no one (not Apple, not us, not anyone who opens your iCloud backup) can read what you keep. (A phone that is switched on and has been unlocked since it started is protected by iOS itself, not by a second Alcove key; see Encryption below.) This document is the canonical, honest account of how that works: what stays on your device, what is encrypted, the little that ever leaves (and in what form), and the few honest caveats. It is the source of truth for the App Store privacy label, the onboarding copy, and any marketing claim: nothing here is aspirational; it describes the code as built (verified by a full data-egress / at-rest / on-device audit, 2026-06-10; re-verified 2026-06-29 and 2026-07-03, the latter adding the opt-in backup and key-bearing-export disclosures).
There is no server we run. Alcove has no backend, no account system, and no analytics. That isn't a policy promise we could quietly break; it is the architecture. Encrypted sync uses your own iCloud. Apple services used for maps, optional weather and requested photo downloads are described below; none is a cloud AI service for your journal.
What onboarding promises
Your saved journal is encrypted on this device. All in-app AI processing uses on-device models; unavailable models fall back to local behavior, not cloud AI. We operate no journal servers and collect no analytics.
Saved journal content syncs automatically as encrypted data through your own iCloud. To use one-device storage, disable Alcove in iOS Settings under iCloud. Audio and Atlas backup are optional. Map viewing and place search use Apple Maps; weather is off until enabled and sends a coarse area to Apple. Full original photos download from iCloud Photos only on request. Siri is governed by Apple's processing before it calls the app. These distinctions matter: "no servers of ours" does not mean "no network services."
Export is available without an unlock purchase. A readable copy contains the saved authored record; a restore backup can include recordings. Unfinished recovery drafts are excluded. The export screens describe the format and coverage before sharing. See Your control below.
The five promises
- On your device. Your entries, photos' places, walks, and the AI that reads them all live and run on your iPhone.
- Encrypted, always. Everything you keep is encrypted at rest with a key only your devices hold.
- No account, no tracking. No sign-up, no email required, no analytics, no ad identifiers, no third-party SDKs that phone home.
- Sync is yours. Sync runs automatically over your own iCloud as encrypted blobs we (and Apple) cannot read, never a server we operate. To keep the journal on one iPhone, turn Alcove off under your iPhone's iCloud settings.
- You can leave with your saved data. Export a readable copy or a restore backup any time, without buying. Unfinished drafts stay local.
On-device by default
-
Unfinished notes stay local. Standalone writing and edits to notes on existing moments are saved as encrypted recovery drafts on this device after a short pause in typing and when the app backgrounds. Reopening the capture editor restores the words, date, prompt, and location choice. Each moment has its own recovery copy. Drafts are excluded from sync and exports, are not fed to AI, and are cleared when you Keep or explicitly discard them. Dictation audio, feelings, and photo selections do not yet have restart recovery. A failed write or termination before the next autosave can leave only the earlier recovery copy.
-
Finished sound takes can recover after a failed Keep. When you press Keep, the finalized audio and capture settings are staged together in an encrypted local recovery file before the journal entry is written. Reopening Add offers that recording again if the entry did not commit. The recovery file stays out of sync, exports, and AI inputs and is cleared on successful Keep or explicit Discard. This does not recover live or paused recordings terminated before Keep, or a take whose staging write failed.
-
The AI is on-device. AI-written narrations, reflections, reports, and Ask Alcove answers use Apple's on-device Foundation Models. Daily writing prompts come from an edited collection, including reviewed questions selected from current saved sources; they are not generated by a model. Your entries, calendar titles, and places are fed only to the local model. There is no remote model, no Private Cloud Compute, no Claude/OpenAI call: none is built or even linked. When the on-device model isn't available, the app falls back to plain local templates, never to a network.
- Dictation is on-device. Voice entries use the on-device speech
recognizer only (
requiresOnDeviceRecognition = true, a hard invariant). If a device can't transcribe locally, dictation is simply absent; audio is never sent anywhere. - Voice recognition stays here; saved words sync encrypted. A sound memo's audio is
encrypted (AES-GCM) on this device, and its transcript is read entirely
on-device: by Apple's SpeechAnalyzer (which has no server path; the
only thing it ever downloads is the on-device language model, never your
audio), or, where that model is not installed for your language yet, by
the older on-device recognizer under the same
requiresOnDeviceRecognitioninvariant. The words are stored encrypted alongside your timeline and sync with your authored memories to your private iCloud. This does not upload audio for recognition. The audio normally never leaves the device either; the exceptions are deliberate, opt-in choices, and both upload the same already-encrypted file (ciphertext only, see the list below): from the recordings list (Settings → Backup & sync → Backup and Restore → Voice notes) you can offload a single recording to your own iCloud to free local space, and on the same page you can turn on Back up everything so your recordings ride to your own iCloud and return on a new device. Audio is uploaded only when you offload or turn audio backup on. No local recognition, no words; never a server. - What was around a voice note is opt-in, and heard here. Turn on the Voice notes source (Sources, off by default) and Apple's on-device sound classifier listens to a memo's encrypted audio for what was around it: rain, a crowd, birdsong, a train. The voice note itself is saved whole, as always; what this adds is a few words about the surroundings. Your own voice is never one of the answers (speech and the sounds a person makes are left out, as are private or alarming ones), the audio is read from a transient copy the way transcription reads it, and what is saved is a few words on the note, encrypted with the timeline. Nothing leaves the device. Off, nothing is derived.
- The recognizer is told your own words, and they go no further. To hear names it has never met ("Priya", a street, an employer), the on-device recognizer is handed a short list of hints drawn from your journal: people and places your entries name, plans on your calendar, towns your moments happened in. The list is built on the device, held in memory only (never written to disk, never synced), and given only to the on-device recognizer.
- Photo reading is on-device (and the words are opt-in). The timeline stores photo dates and places only, and it mirrors your library: a photo you delete or hide in Photos leaves the timeline (and the Scrapbook, the map and Ask) instead of staying as an empty card, checked against the library on this device, never over a network. With the Photos source on, Alcove also reads two wordless things on this device: a quality score, so the Scrapbook can lead with your best shots (and a receipt or a document never leads a collage), and where the eye goes in the frame, so a crop keeps the subject instead of the middle. Nothing is stored but a number and a point. Turn on What's in your photos (Sources → Photos → Refine, off by default) and Apple's on-device Vision additionally reads what a photo shows ("water", "a dog"), any words in it (a sign, a menu: for finding the photo, never for a narration), and how many faces are in it (a count, never who) to ground the day's narration and to let you ask for a photo by what is in it. On iOS 27, where Apple's on-device language model can see images, the same switch also lets it write one plain line about a photo ("a lighthouse on a rocky shore"); it is told never to say who anyone is. Pixels are read in memory and never stored; scores, words, counts and captions are encrypted like everything else and never leave the device. With the switch off, none of it is derived. This reading may also run while the phone is charging and idle (a system background task); it is the same reading, on the same device, with the same switches.
- Finding meaning is on-device too. Ask Alcove and Threads reach
past exact words to related moments using an on-device text embedding:
Apple's
NLContextualEmbeddingwhere its model is present, the older on-device sentence model otherwise. Like SpeechAnalyzer, it may download Apple's model assets over the air, but never your words: your entries are turned into vectors and stored encrypted on this device, and neither the text nor the vectors ever leave it. - Each entry is read once, on the device, and the reading stays here. So that the week, the year, Trends and Ask can draw on everything you wrote rather than the first lines of it, the on-device model reads each entry once and notes what it holds: a few topics, the people and places it names, the feelings it voices, and one line saying what it is about. A name is saved only if it is actually in your entry. These notes are stored encrypted on this device, are never synced (each device reads its own copy of your entries), and are removed with the entry.
- Suggestions stay out of our reach. "Suggested from your day" (Add → the picker) uses Apple's Journaling Suggestions, which runs out of process: the system shows you places, companions, and what you listened to, drawn from signals on your phone that Alcove never sees, and hands back only the one you tap. Nothing is read without that tap, and what you keep lands in the same encrypted timeline as everything else. It is not a new way for data to leave; it is a way for you to bring more in, privately.
- The map is on-device, including place names. The Fog-of-World map and your trails are rendered and stored only on the device. When the Atlas takes a location fix to show the blue dot (opening the map, the recenter button, or while path logging is on), it also notes the ~22 m hex cell under you, quantized, never the raw fix, so the ground you're standing on clears its fog. Those cells live in the same encrypted device-local store as everything else, pass the Privacy-Zone rule before they're written, and leave the device only if you opt into Atlas backup (as ciphertext, like trails). The names of the cities, states, countries and continents you've explored (the Atlas region awards, and the "near …" lines through the app) are resolved entirely offline, from bundled geographic data shipped inside the app (GeoNames cities, Natural Earth admin-1/admin-0 boundaries). No coordinate is ever sent anywhere to be named. (This used to be an opt-in reverse-geocoding call to Apple, Alcove's one location egress; it has been removed.)
- Weather is opt-in, off by default. Turn on Local weather (Sources → Places → Refine) and Alcove asks Apple Weather for the temperature and conditions over places your days actually held, at most a few coarse (~25 km) cells per day, results stored encrypted like everything else. Off, and no coordinate ever goes to a weather service.
What "encrypted" means here
- Every store of journal data is encrypted with AES-GCM-256 before it
touches disk (
nonce ‖ ciphertext ‖ tag, algorithmaes-gcm-256-v1). This covers all of it: entries, day records, the daily invitations, chance-card history, streak, weekly reports, Scrapbook narration, the timeline index (photo references + geotags), trails (GPS paths), Privacy Zones, and the Ask search index (meaning-vectors derived from your entries, computed on-device). - The encryption key is a 256-bit random key generated on-device and stored in the iCloud Keychain (Apple's end-to-end-encrypted keystore). It never leaves for any server, is never written into any file except a backup you export yourself, and is never logged. It roams to your other devices only through iCloud Keychain, which Apple itself cannot read. The copy stored on this device is marked this-device-only, so it never goes into an iCloud or computer backup of the phone either; restoring such a backup onto a new phone brings the journal back through iCloud Keychain or a backup file you exported, not through the device backup.
- Encrypted files are excluded from iCloud/iTunes device backups, so the ciphertext doesn't even ride along in a backup.
- When the key can be read. The key and the files use iOS's "after first unlock" protection, so your map can keep logging a walk while the phone is locked in your pocket. That means a phone that is switched on and has been unlocked once since it started holds the key in a readable state; switching the phone off restores full protection. App Lock guards the app itself, not the files underneath it.
Sync goes to your own iCloud, as ciphertext only
- Sync runs automatically and uses CloudKit's private database in your own iCloud account. We have no database of our own. To keep the journal on one device, turn Alcove off in Settings → [your name] → iCloud; Alcove has no switch of its own for this yet.
- What is uploaded is the already-encrypted file: the raw AES-GCM envelope bytes. Apple's servers store ciphertext; the key stays in your Keychain. Neither Apple nor we can read it.
- These categories always sync: entries, day records, chance-card history, daily invitations, intentions, and authored timeline memories (moments, feelings, recording transcripts/references, and notes on gathered sources). A source note keeps its own stable identity and context. Another device receives it as a standalone moment rather than guessing which local photo, workout, or calendar item it belongs to. The originating device retains its source binding while that source is available. Source removal detaches authored content instead of deleting it. Unannotated gathered items do not join this carrier, apart from feelings retained conservatively as memories. With the opt-in iCloud backup turned on, more of your world rides the same ciphertext-only path: your voice-note audio (encrypted AES-GCM files as CloudKit assets), and, if Atlas backup is on, your trail shards, your imported Fog of World map, and the visited-ground hexes, so a new device can bring your fog back. All of it is the already-encrypted envelope bytes; none of it is readable by anyone but you. Your Privacy Zones never sync at all, under any setting; they are the one thing that stays only where you set it. With backup off, trails stay device-only too (re-derived per device).
- The honest caveat (metadata): because sync uses CloudKit, Apple can see the existence of encrypted records (a handful by default; more with backup on, including one per backed-up recording), their sizes, and modification times for an iCloud-synced user, and each record's name, which says what kind of data it holds and, for a backed-up map, which month (a record for one month's paths exists, another month's may not). It can never see content. Record sizes are a coarse hint that you journal more or less; the words, the places, the feelings, never visible. This is intrinsic to using iCloud and is the one thing about sync we don't control. Sync off → none of this.
No accounts, no tracking
- No account is required, ever. Identity is a random ID generated on your device. Anonymous use is first-class forever.
- Sign in with Apple is optional and gates nothing; it exists only to let your identity roam for multi-device continuity (and the future Duo chest). Its identifier and your given name live in iCloud Keychain, not in any backup, not on any server.
- Zero third-party SDKs. No analytics, attribution, crash-reporting, or advertising frameworks are linked, not PostHog, Sentry, Firebase, AppsFlyer, Facebook, anything. No IDFA, no App Tracking Transparency prompt because there is nothing to track. The App Store label is "Data Not Collected."
Location, precisely
Location is the most sensitive thing a journal touches, so here is the exact picture, without rounding:
- Privacy Zones never leave the device: not even encrypted. They don't sync, under any setting. Trails stay device-only by default; they leave only if you opt into Atlas backup, and then only as encrypted ciphertext to your own private iCloud (so a new device can restore your fog). Turn Atlas backup off and they never leave at all.
- Privacy Zones redact before storage. A zone you drop (e.g. home) is checked at the moment of capture, in both the one-shot entry stamp and the live trail recorder: a fix inside a zone is never written, never flushed, never stored.
- A zone added later can clear what was stored before it. Each zone shows how many saved moments and path points fall inside it and offers to clear them, after asking. Entries keep their words and lose only the place, as an edit that syncs to your other devices; timeline moments and stored paths are cut on this device. A path backup already in your iCloud (encrypted, readable only with your key) keeps its own copy.
- An entry's place stamp is end-to-end encrypted. If you opt into stamping an entry with where you were, and you use iCloud sync, that coordinate travels inside the encrypted entry blob to your own private iCloud so the entry reads the same on your other devices. No server sees it in readable form, but, to be fully honest, those encrypted bytes do leave the device. (This is exactly why every location claim in the app is worded precisely: "encrypted end to end, no server can read it," never "never leaves your device": the latter is true for Privacy Zones and for trails with Atlas backup off, but not for a stamped entry you also sync. Atlas backup can send encrypted trails to your own iCloud; Privacy Zones never sync.)
- Stamping is off by default and opt-in.
What the rest of your phone can see
- Widgets show the look's colours, today's card, and how much of a chosen place you've explored, as a percentage. Never your words: the widgets read a small file that holds no journal text.
- Apple Watch shows today's card and the look's colours, sent from your iPhone to your own paired watch. No words you wrote, no places and no counts go to the watch.
- Spotlight never receives your entries. Its index sits outside the journal's encryption, so searching your writing happens only in Alcove's own Find.
- Siri answers "Ask Alcove" on this device from your own words, and a locked journal answers nothing. Keeping a thought through Siri writes it straight into the encrypted journal, and so does a general journaling request ("add to my journal that…"): the entry Siri gets back is read on this device only, a locked journal hands nothing back, and the location Siri may offer is not saved.
- Notifications carry a year ("You wrote something on this day in 2024", "You took photos on this day in 2021") or a general line inviting you to write. Never an entry, and never a photo.
Everything that leaves the device
- Encrypted CloudKit blobs to your own iCloud private DB: the synced journal scopes (sync on), and, with Back up everything on, your voice recordings and trail shards (or a single recording you offload from the recordings list, under Backup and Restore). Ciphertext only, in your own iCloud.
- The encryption key + identity (and the trial-start date) via iCloud Keychain (Apple E2EE); the trial date is a timestamp, never content.
- A user-initiated export: either a plaintext JSON copy, or a
.alcovebackuprestore file, each explicitly sent through the iOS share sheet. The backup file carries your encrypted data and your journal key: raw by default so one file restores everything, or wrapped under a password you choose (the export screen says which, plainly). This is data portability; you choose where it goes, and the file deserves the same care as the journal itself. - The purchase (a one-time unlock) runs through StoreKit 2 directly: Apple's App Store sees a receipt and an anonymous purchase, never journal content. No subscription, no RevenueCat, no payments middleman; nothing else is involved, and there is no account with us.
- (Opt-in, off by default) Local weather: if you turn on Local weather, coarse (~25 km) cells of places your days held are sent to Apple Weather to get temperature and conditions back, at most a few lookups per day, with results cached and stored encrypted. Apple Maps requests also identify an area, as described below.
- (Only while you type) Location-search text: when you use the timeline's Where filter and type a place ("San Francisco", "California", a café), those characters go to Apple's map-search service to offer matches. Only the text you type, only while you're searching. Alcove asks for results across the whole world rather than near you, and the matching of your moments against the area you pick happens entirely on-device.
- Map tiles and map pictures: to draw a map, Apple Maps is asked for the area on screen: the Atlas while you look at it, and the small map beside an entry, photo, walk or voice note (and a Scrapbook route) when you open it. That request carries the place, never your words, and goes to Apple's Maps service, which is not tied to your Apple ID. The small maps are never drawn for a place inside a Privacy Zone.
- (Only when you tap it) Download full photo: a photo or video whose original lives in your iCloud Photos opens as the preview this device has. Tapping Download full photo asks Apple's Photos framework to bring that one original down from your own iCloud Photos, as the Photos app would. Nothing is sent by Alcove; every other photo read stays on the device.
- Siri: if you ask Alcove something through Siri, what you say is handled by Siri under Apple's terms before Alcove sees it, and Alcove hands back only the words Siri speaks. Questions that read your journal back need this iPhone unlocked, and a locked chest answers nothing.
That is the entire list. Apart from those Apple services, each sending only what's described above, there is no other network path in the app: no HTTP client, no socket, no web view. A few links you can tap (the credits, this policy) open in Safari. (Place names are resolved entirely on-device from bundled data, © GeoNames (CC BY 4.0) and Natural Earth (public domain), so naming where you've been sends nothing anywhere.)
Your control
- Export everything, any time (Settings → Backup & sync → Backup and Restore → Export a copy): a self-contained restore file, or a readable plaintext JSON copy. The readable copy includes saved entries, feelings, authored notes on gathered moments, goals, day summaries, and card history. It includes recording transcripts and references, not audio files, and is not a restore format. If a covered saved scope cannot be read, the readable export fails rather than silently leaving it out. Unfinished drafts remain excluded from both export formats.
- Erase everything locally, any time: delete the app and every scope file, encrypted recording, and preference on the device goes with it (your encrypted iCloud copies remain yours, under your Apple ID).
- App Lock (Face ID, Touch ID, or passcode) with a privacy veil that hides content in the app switcher.
- Privacy Zones to fence off places that should never be recorded.
- Per-source opt-in: photos, places, health, calendar each off until you turn them on, each explained before it asks.
Open hardening (tracked, honest)
These are known edges we are closing or watching, listed here because a real privacy story names its own seams:
- Entry-stamp location in sync (a disclosed, deliberate choice). A place-stamped entry's coordinate syncs end-to-end-encrypted to your own iCloud so the entry reads the same on all your devices; no server can read it. We keep this and word every location claim precisely to match ("encrypted end to end, no server can read it"). Want zero location egress? Leave entry stamping off and Atlas backup off. Privacy Zones never sync regardless.
- Payments are resolved (StoreKit-direct). The app offers a 3-day free trial, then a one-time unlock purchase via StoreKit 2, entitlements checked on-device against the App Store, no RevenueCat or other middleman. Apple sees a receipt + an anonymous purchase, never content, so "no third party sees you're even a user" holds. (The trial start roams in iCloud Keychain so it's once per Apple ID; it's a date, not content.)
- Compile-out guard. Add a build/CI check that fails if a server SDK (Supabase, etc.) ever becomes linkable, so the "no backend" guarantee can't regress silently.
- CloudKit metadata. Inherent to iCloud sync; documented above, not code-fixable. Disclosed plainly rather than hidden.
- Words readable on a switched-on phone. The key and files use the "after first unlock" protection class so walks keep logging while the phone is locked. Planned: encrypt your words under a second key that is only readable while the phone is unlocked, leaving only the map writing in the background.
- An in-app "keep this journal on this device" switch. Today this is done in the iPhone's iCloud settings; a switch under Backup & sync is planned.
Last verified against the codebase: 2026-09-29 (the elevation audit: map tiles and pictures, Siri, sync being automatic, and when the key can be read, added to match the code). Keep this document honest: if the code changes, change this first.