It’s a short list. We only ask for what actually makes the app work.
The app records your screen while you use it. That is on by default, and you can turn it off in the app: Settings, under PRIVACY, the row called “analytics and recording.” Turning it off stops the counting and the recording on your phone, straight away. Text and pictures are meant to be blanked out on your device before a frame is ever stored, and on August 29, 2026 we checked one of our own recordings and found that this does not always work: ordinary interface text read back off it, and an account email address was legible in the box it had been typed into. We have written the correction, and until frames from a corrected build have actually been looked at we will not tell you a recording cannot hold something you had on screen. The bullet below headed “A recording of your screen” is the full account, including how to have your recordings deleted today rather than in 30 days.
- Your email address: to create and secure your account (via Supabase Auth).
- What Sign in with Apple or Google hands us: if you choose one of those buttons instead of an email code, the provider returns a unique account identifier, your email address (Apple’s may be a private relay address), and your name if you let it through. That is the whole of it. We ask for no other permission, we never read your Gmail, contacts, calendar, files or photos, and we never post anything anywhere on your behalf. What comes back is stored in Supabase Auth purely to be your login, is used for nothing else, is never sold, shared, or used for advertising, and is deleted with the rest of your account.
- Your display name: the name your friends see, and the name that appears on anything you post to the public community board.
- Your daily log: whatever you say, and whatever you type alongside it. A log now takes a voice note, so almost every day you log carries a recording, and that recording is kept as well as transcribed. The demand lifts in exactly two situations, both of them a door that is shut rather than a preference: a microphone your phone will not ask you about again, and a transcription service that will not answer. It never lifts because you would rather not, and there is no setting for it. The audio goes to OpenAI to become the text your score is generated from, which happens only after you have agreed to it on the screen described in section 03, and the file itself is stored in a private bucket where the friends you have accepted can press play on it for 14 days. The file is then deleted outright once it is 30 days old, whether or not you ask. Section 04 has the detail on who can hear it.
- Your device’s time zone: a zone name like “Asia/Kuala Lumpur”, stored on your profile so a “day” ends at your midnight and not ours, and so an evening reminder fires at the hour you picked. It is a zone name, never a coordinate.
- Your health score: the number your log generates, plus the average of your last 14 logged days.
- Anything you post to the community board: the feature requests, comments, and votes you choose to submit. These are public by design, carry your display name, and are handled by Canny (see section 03). Nothing on the board is private; your daily logs never appear there.
- Photos you attach to a day: at least one, and up to six. A photo is no longer something you add if you feel like it, it is part of what a log is. The demand lifts only if the picker on your phone will not open at all, which is the photo half of the same rule: compulsory for anyone who can, never impossible for anyone who cannot. The files live in a private bucket, and adding one grants your accepted friends’ accounts read access to it for the next 14 days. There is no per-photo private setting, so treat anything you attach as shared with your circle. Remove one and it comes off your day for everyone. Section 04 has the detail.
- Your spoken promise: the one line you read out loud when you set up. The audio goes to OpenAI to be turned into text, and that text goes to Anthropic to check you actually said the line. This is the first thing the app ever sends to an AI service, so it is the moment the app stops and asks your permission: section 03 has the screen, the field-by-field list of what each company receives, and what neither of them is given. The clip itself is then kept, in a private folder that only your own account can read. That is the difference between it and a spoken daily log: a daily log is audible to your accepted friends for 14 days, and your promise is audible to nobody but you. It goes when your account goes.
- Product analytics: Mr. Chud ships PostHog, and it is the only analytics SDK in the app. It records what you did, and separately it records your screen, which is described in full in the next bullet. Both stop when you turn analytics off in Settings. The event stream itself carries only: named product events (opened the app, finished onboarding, logged a day, saw the paywall), the screen you’re on, your Supabase user id, your app version, and your platform. It also records a recording of your screen, which gets a bullet of its own below because it needs more than a clause, and that bullet is the one to read. The PostHog SDK also attaches ordinary technical context to each event by itself: your device model, OS and OS version, app build, screen size, timezone and the SDK version. We tell PostHog to skip its IP-based location lookup, and that part does what we said it does: on August 30, 2026 we counted every event the app sent in the previous week, and not one of the 1,207 of them carried a city, a region, a postcode, a country or a coordinate. Here is the part we will not round off, because this page had it wrong until today. Skipping the lookup does not throw away the address the lookup would have read. Your phone reaches PostHog over the internet, so every event arrives carrying your IP address. An IP address can be resolved to an approximate place by whoever holds it. We already say exactly that about Sentry, two bullets below, and it was not honest to say it there and not here: this page used to tell you that an event from a recent version of the app arrives with no location on it at all, and the address had been sitting on every one of them the whole time. There is a setting on PostHog’s side that discards that address as the event lands instead of storing it. We switched it on on August 30, 2026. We checked it rather than assuming it: we sent one event just before the change and one just after, from the same computer on the same connection, and the earlier one has an address stored against it while the later one has none at all. It needed no update from you, and because it happens where the event lands rather than where it is sent, it covers every version of the app at once, including old ones already on phones that we can no longer change. Events sent by older versions, before the lookup switch existed, carried more than the address: a coarse city, a postcode and an approximate latitude and longitude, every one of them worked out from that same IP address and never from your device, and those older events are still in our analytics under your user id. The last event to carry a coordinate was sent on August 19, 2026. None of it comes from GPS, we never ask your device where it is, and we do not use any of it for anything. Section 04 has what happens to that record when you delete your account. The code enforces a hard no-content rule on events: every property that goes out on one is an enum, a boolean, a count, or a coarse band, so entry text, reflections, your Chud’s name, your username, your email and any token are structurally incapable of ending up in an event. That rule is about events, and it is not the whole story, because a screen recording is not a property and no rule about properties reaches one. Masking is what is meant to keep content out of a recording, and we are honest below about the day we found it does not always manage it. The next bullet is that, in full. Even your score goes in as a band (“60-79”), never the words behind it. It runs on our own PostHog project, it is used only to see which parts of the app work, and it is never used for advertising or joined with your activity in any other app or website.
- A recording of your screen: PostHog also records the session itself. It is on by default, and there is a switch for it in the app: Settings, under PRIVACY, the row called “analytics and recording.” That screen names PostHog, says what a recording holds, and turns both the counting and the recording off on your phone the moment you press it. It is saved on your device, so it survives signing out. What a recording is for is the shape of the session: which screen you were on, where you tapped, what you scrolled past, how long you sat there, and the order you did it in. Text and pictures are meant to be covered over on your phone, inside the recorder, before a frame is stored, so that the words of your log, the transcript that came back, the reflection you typed, your promise, your Chud’s name, your username, your email and every photograph on your day leave your device as blank blocks. On August 29, 2026 we checked one of our own recordings, and that did not reliably happen. Ordinary interface text read back off it plainly, and on the sign-in screen an account email address was legible in the box it had been typed into. We are not going to tell you a recording never holds content when we have watched one hold an email address. Why it happens is worth a sentence, because it tells you what to expect: what leaves your phone is a picture of the real screen with rectangles painted over the parts that are not meant to be read, so every frame carries the real pixels underneath, and a rectangle that lands in the wrong place, or never gets worked out at all, leaves what is under it showing. The parts we have not caught leaking are not therefore safe. The account in that recording had no entries and no photos on it, so there was no log text and no picture on the screen to leak, and we have not yet watched a single frame of the writing screen or the reading screen. The system photo picker is drawn by a screen this app does not control and the recorder is told to cover those too, which is the same kind of promise as the rest of this paragraph, so read it the same way. We have written a correction to the masking and it travels with the app rather than with this page, so until frames from a corrected build have actually been looked at, treat anything the app draws on your screen as something a recording may hold, legibly. That is also the plainest reason the switch above exists. The rest of this has not changed and is worth having straight. A recording is never shown to your friends, never sold, never used for advertising, and never sent anywhere outside the processors in section 03. The recorder’s console and network channels are switched off, so a log line or a request address is not a second way out. A recording is deleted 30 days after it is made. Beyond the switch in the app there are two further controls and both work today: recording is also governed by a single setting on our side, which the app re-reads every time it starts, so it can be stopped on every phone at once without shipping an update, and if you would rather we held none of your recordings at all, email us and we will purge them now along with the rest of your analytics record.
- Crash diagnostics: Mr. Chud ships Sentry, and it is the only crash-reporting SDK in the app. When the app crashes or hits an error it sends Sentry the error and its stack trace, your app version and build, your device model, OS and OS version, and your Supabase user id, so a crash can be tied to a session rather than guessed at. Sentry is never sent a screenshot, a view hierarchy, or a session recording: an unmasked picture of this app is a journal entry, so all three are switched off in the code and are meant to stay off. The screen recording described just above is PostHog’s, and none of it is ever copied here. It never receives the text of a log, your reflection, your Chud’s name, your username or your email. One thing we will not round off: the report travels over the internet to Sentry’s servers, so Sentry’s own systems see the IP address the request arrives from, and an IP address can be resolved to an approximate country and region. We never ask your device for its location, no coordinate is stored on a crash report, and we do not use that region for anything. Separately, Apple and Google may hand us their own crash reports through App Store Connect and Play Console, and only if your device is set to share diagnostics with them.
That’s it. No GPS or precise location, no contacts access, no browsing history, no advertising identifiers, and no microphone access outside of two moments: the voice note a daily log requires, and the promise you read out loud at setup. Both of those are asked for where they happen, and neither is asked for before it happens. On both platforms the microphone dialog is raised by the recorder you are looking at, the first time you press record on it. In practice that is during setup, on the promise step, because reading the promise out loud is the first recording the app ever asks anyone for; if you reach the log first, the log raises it there instead. Before either of those, and before anything is sent to a transcription service, the app shows you the AI permission screen described in section 03. Your photo library is never opened: the picker that appears belongs to iOS or to Android, it runs outside this app, and what comes back is the pictures you tapped and nothing else, so Mr. Chud has no reading of your library and never asks for one.
Mr. Chud