Privacy policy.
Effective date: August 1, 2026
Your record lives on your device. The app has no accounts, no tracking, and no analytics. We never see your entries, your photos, or your children's information — and we built it that way on purpose. The only thing that ever leaves your phone automatically is an anonymous cryptographic fingerprint (a hash) used to prove when an entry was sealed. A hash cannot be reversed into your content.
This marketing website is a separate thing, and it does use Google Analytics — with cookies off until you say otherwise. Details in The website below. Nothing the website measures touches the app or your record.
Who we are
Documented ("we", "us") makes the Documented iOS app and operates the documented.co website. This policy explains what information the app and the website handle, and — mostly — what they deliberately don't.
The app
Your entries stay on your device
Everything you log in Documented — text, photos, video, voice recordings, receipts, message-thread captures, locations, and the details of your entries — is stored locally on your iPhone. We do not operate servers that receive, store, or process your record. We cannot read, access, recover, or delete your entries, because they are never sent to us.
No account, no sign-up
Documented does not require an account. We do not collect your name, email address, phone number, or any other identifier to use the app.
No analytics or tracking
The app contains no advertising, no third-party analytics SDKs, and no trackers. Our App Store privacy label is "Data Not Collected." We do not know how many entries you have written, which screens you use, or whether you opened the app today.
This is a statement about the app. The documented.co website is measured separately and is described below. The two share nothing.
iCloud sync
If iCloud is enabled on your device, your record syncs automatically to your private iCloud database so it survives a lost or replaced phone. This sync happens between your device and your own Apple iCloud account, under Apple's iCloud terms and encryption. We have no access to your iCloud data. You can turn iCloud off for Documented at any time in iOS Settings, and you can remove the app's iCloud data in Settings → Apple ID → iCloud → Manage Storage.
Trusted timestamps (the one thing that leaves your phone)
When you seal an entry, the app computes a SHA-256 hash of it — a fixed-length cryptographic fingerprint — and sends only that hash to an independent RFC-3161 timestamp authority, which returns a signed proof of the time. The hash contains none of your content and cannot be reversed into it. The timestamp authority never receives your entries, media, location, or identity beyond the technical minimum any internet request involves (such as an IP address handled per that provider's own policy).
Location
Adding a location to an entry is optional. If you grant location permission, the coordinates are attached to the entry on your device and go nowhere else. You can decline or revoke the permission at any time; the app works fully without it.
Face ID / Touch ID
The app's biometric lock uses Apple's on-device authentication. Biometric data is managed entirely by iOS and never reaches us or the app itself.
Exports are yours to control
Nothing in your record is shared with anyone unless and until you choose to export it. When you export a PDF, you decide where it goes — the app hands it to the iOS share sheet and keeps no copy anywhere else.
Deleting your data
Deleting the app deletes the record stored on your device. If iCloud sync was on, you can remove the synced copy from your iCloud account as described above. Because we hold no copy, there is nothing for us to delete on our side.
Children's privacy
Documented is made for adults documenting their own parenting. The app is not directed at children, and we do not collect personal information from anyone — including children. Information about your children that you record stays on your device, under your control.
The website
documented.co is a static marketing site. It is not the app, it never receives anything from the app, and none of what follows applies to your record.
Analytics and cookies
The website uses Google Analytics 4 so we can see which pages people find useful and which ones fail them. Here is exactly how it is configured:
- Cookies are off until you accept them. Analytics loads in Google's Consent Mode with storage denied by default. Until you press Accept on the banner, no analytics cookie is written and no visitor ID is kept — we receive an anonymous, aggregate page count and nothing that follows you between visits.
- If you accept, Google Analytics sets its standard cookies (
_gaand similar) so returning visits can be recognised as returning. You can change your mind by clearing this site's cookies and site data in your browser, which brings the banner back. - If you decline, that choice is remembered locally and the banner stays gone. Analytics continues in its cookieless mode.
- No advertising, ever. Google's ad-related signals (
ad_storage,ad_user_data,ad_personalization) are denied permanently and are never granted, even if you accept. We run no ad tech, no remarketing, and no cross-site tracking pixels. - What we measure. Pages viewed, roughly where in the world the visit came from, what kind of device it was, and clicks on the App Store buttons. We do not collect names, email addresses, or anything you type.
All of this lives in one auditable file — /assets/analytics.js — if you would rather read the code than take our word for it.
Also worth knowing
- Hosting. The site is served by Vercel, whose infrastructure may keep short-lived technical logs (such as IP addresses) to deliver and secure the site, per Vercel's privacy policy.
- Fonts. Pages load typefaces from Google Fonts, which means your browser requests font files from Google's servers, per Google's privacy policy.
Purchases
If you purchase a subscription, the transaction is processed by Apple through the App Store. We receive no payment card details. Apple's handling of purchase data is described in Apple's privacy policy.
Changes to this policy
If we change this policy, we will post the updated version here with a new effective date. Because the app is local-first, changes that would ever send more data off your device would be called out prominently, not buried.
Contact
Questions about this policy or your privacy: privacy@documented.co.
Documented is not a law firm and does not provide legal advice. Records are tamper-evident, not tamper-proof.