Secure Space Logo
Secure Space

An emotional regulation practice for secure attachment. Designed for privacy.

© 2026 SECURE SPACE

Privacy Policy

Last Updated: October 7, 2026

Our Core Commitment:

Your privacy is not a feature — it is the foundation of Secure Space. This policy explains what data exists, where it lives, and who can see it. Your personal content — everything you write, reflect on, or share within the app — stays only with you.

Secure Space does not collect, transmit, or store your personal content on any server of ours. We have no backend, and we cannot see your journal entries, your feelings, your patterns, the people you add, or your reflections. What you write stays on your device. Only two things can ever leave it: a small set of anonymous usage signals that contain nothing you wrote or chose (used only to improve onboarding), and — only if you turn it on, and only on iOS 27 — the content of a single request sent to Apple's Private Cloud Compute to get a more thoughtful result. That request goes to Apple, never to us.

1. Our Core Commitment

Secure Space does not collect, transmit, or store your personal content on any server of ours. We have no backend, and we cannot see your journal entries, your feelings, your patterns, the people you add, or your reflections. What you write stays on your device. Only two things can ever leave it: a small set of anonymous usage signals that contain nothing you wrote or chose (used only to improve onboarding), and — only if you turn it on, and only on iOS 27 — the content of a single request sent to Apple's Private Cloud Compute to get a more thoughtful result. That request goes to Apple, never to us.

2. Data You Create

When you use Secure Space, the following data is created and stored locally on your device only using Apple's Core Data framework:

  • People you add (name, relationship stage, dates, moments, notes, and a photo if you choose one — stored as a small resized image)
  • Practice sessions, focus choices, and Look Back reflections
  • Journal entries (trigger descriptions, emotions, story, facts, reframes, action plans)
  • Quick trigger check-ins
  • Assessment results (attachment style, sensitivity mode)
  • Behavioral pattern logs and pattern alert history
  • Reflection and progress data (Secure Path stage history, emotion summaries, recommendations)
  • Growth signal interpretations and trend data
  • Bloom mascot state and animation preferences
  • Grounding anchor and reframe usage
  • App preferences and settings (haptic feedback, app lock, notification preferences)

None of this data is ever transmitted to Secure Space or any third party. It exists only in your device's local storage.

Deleting the app permanently deletes all of this data. You may also reset assessment and profile data at any time via Settings → Data → Reset All Data.

3. On-Device Processing

By default, everything Secure Space does to understand what you write — spotting patterns, your Secure Path, growth signals, reframe suggestions, Bloom's mood — happens on your device. Your writing is never used to train any AI model, and Secure Space doesn't use any outside AI service. The one optional exception is Private Cloud Compute, explained in Section 5, which only happens when you say yes.

4. On-Device Intelligence (Apple Intelligence)

On iPhones that support Apple Intelligence (iOS 26 and later), Secure Space can use Apple's on-device model for the features below. It runs on your phone, not in the cloud:

  • Tone analysis in Secure Send — when you tap Check tone, the model analyzes your draft message for communication patterns. The draft never leaves your device.
  • Polish in Secure Send — when you tap Polish for me, the model rewrites your draft into a regulated version. The original draft and the polished version both stay on your device.
  • Situation matching in Check-In — when you describe what's happening in free text, the model interprets your situation to surface relevant emotional patterns and guide your reflection. Your input never leaves your device.

When these run on your phone, your text stays on your phone — it isn't sent to Apple, to us, or to anyone else. On older iOS versions the app uses simpler built-in logic instead. When you add a conversation screenshot to Secure Send, the text in it is also read on your device.

No content from Secure Send is stored, logged, or analyzed by Secure Space.

5. Apple Private Cloud Compute (Optional)

If you're on iOS 27 with Apple Intelligence, Secure Space can offer more thoughtful results by using Apple's Private Cloud Compute. This is Apple's own private service for Apple Intelligence, Apple designed it so that your request is used only to answer you, isnbuilt so that your request is used only to answer you, is not stored, and can't be read by Apple or anyone else. It's the same protection Apple uses for its own features.apos;t stored, and canbuilt so that your request is used only to answer you, is not stored, and can't be read by Apple or anyone else. It's the same protection Apple uses for its own features.apos;t be read by Apple or anyone else.

It's always your choice. Secure Space asks before using it, and you can choose to keep everything on your device instead. If you say no, or it isn't available, the app simply does the same thing on your phone. It's used in four places:

  • Reset reframes. Only that Reset's answers are used — what happened, how you felt, your story, and the facts — plus a little general context about you, like your attachment tendency and what you're going through, so the reframe fits where you are. Nothing else from the app.
  • Polishing a message in Secure Send. Your draft, and — if you picked a person — only their relationship stage (like dating or partner). Never their name, history, or notes.
  • Reading a conversation screenshot. You see and can edit the text from your screenshot first. Only after you choose to continue is the screenshot and that text used, along with your draft.
  • Repair. Two optional reads. One looks at how your message might land: it uses your draft message and what you wrote in that Repair, but not anything you marked “Not mine to carry.” The other reads a conversation screenshot you add, after you've seen and edited its text.

These requests go from your phone straight to Apple. They never pass through Secure Space, we never see them, and we don't save your screenshots. You can learn more about how Private Cloud Compute protects your data in Apple's own documentation.

6. Siri and App Shortcuts

On iOS 27, you can use Siri to jump into Secure Space — for example, “Siri, open Secure Send in Secure Space” or “Siri, search delayed replies in Secure Space.” Siri can open Check-In, Reset, Ground Me, Secure Send, today's reframe, and search the Library.

  • Siri just opens the right place in the app. What it says back is always generic, and it never reads out your entries, drafts, people, or reflections.
  • Your phone needs to be unlocked to use these.
  • For Library search, Secure Space only receives the words you said, and the search happens on your phone.
  • Your writing and reframes aren't added to Spotlight or shared with Siri.

Siri is Apple's, so your voice request is handled by Apple under its privacy policy. Secure Space never receives your voice or recordings.

7. Face ID and Touch ID

If you enable App Lock, Secure Space uses Apple's LocalAuthentication framework to authenticate you via Face ID, Touch ID, or your device passcode. We never access, store, or transmit your biometric data. Authentication is handled entirely by iOS and your device's secure enclave — Secure Space only receives a yes/no result.

Your Face ID and Touch ID data never leaves your device.

8. Subscriptions — RevenueCat

Secure Space uses RevenueCat to manage Pro subscriptions. When you purchase or restore a subscription, RevenueCat processes limited transaction data including:

  • App Store transaction receipts
  • Subscription status (active, expired, trial)
  • Country/region (derived from App Store, not your location)
  • An anonymous app user ID (not linked to your name or email)

RevenueCat does not receive any journal content, assessment results, or personal reflections. Their privacy policy is available at revenuecat.com/privacy.

All payment processing is handled by Apple. Secure Space never sees your payment details.

9. Product Analytics — PostHog

Secure Space uses PostHog for limited product analytics — specifically to understand where users encounter friction during onboarding, so we can improve that experience over time. PostHog processes the following signals:

  • Which onboarding steps the user has completed
  • Progress through the initial assessment (by step position only — not the user's answers or results)

PostHog assigns a random identifier generated on your device to group activity from that device together for analysis. This identifier is not linked to your name, email, Apple ID, or any other personal information.

PostHog never receives anything you type or select, your assessment answers or results, any journal content, or any personally identifying information. There is no session recording or screen capture of any kind — only the limited signals listed above. Their privacy policy is available at posthog.com/privacy.

PostHog's infrastructure may log your device's IP address at the network level as a standard part of processing inbound requests — this is an inherent property of any outbound network connection, not data Secure Space intentionally transmits.

PostHog is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. Analytics data is hosted on PostHog's US Cloud infrastructure. A signed Data Processing Agreement is available on request at privacy@posthog.com.

10. Notifications

If you grant notification permission, Secure Space schedules local notifications for follow-up reminders, reflection nudges, reflection-ready alerts (after every 5th completed Reset), and trial reminder notifications. These notifications are generated and delivered entirely on-device. No notification content is sent to a server.

You can manage or disable notifications at any time via Settings → Notifications in iOS.

11. Widgets

Secure Space includes home screen widgets (daily reframe, quick actions) and lock screen widgets that display your daily reframe and streak. This data is written to a shared App Group container on your device. It does not leave your device and is not accessible to Secure Space or anyone else remotely.

12. Analytics and Crash Reporting

Secure Space uses PostHog for limited onboarding analytics to improve the onboarding experience, as described in Section 9. No other third-party analytics or behavioral tracking SDKs are used (no Firebase, no Mixpanel, no Amplitude).

Xcode's optional crash reporting (via Apple's infrastructure) may collect anonymized crash logs if you have opted into sharing app analytics with developers in your iOS settings. This data is anonymized by Apple and only shows technical crash information — no journal content is ever included. You can control this in iOS Settings → Privacy & Security → Analytics & Improvements.

13. Children's Privacy

Secure Space is not intended for users under 17. We do not knowingly collect data from children under 17. Because all data is stored locally and we have no server-side data collection, there is no mechanism by which we would receive a child's data. If you believe a child under 17 is using the app, please contact us.

14. Your Rights

Because all your data lives on your device, you are always in full control:

  • Access: All your data is readable within the app
  • Delete: Use Settings → Data → Reset All Data to delete assessment data, or delete the app to remove everything
  • Export: You can screenshot or manually export entries at any time
  • Portability: Your data is not locked in any cloud — it is yours, on your device

If you are in the EU (GDPR) or California (CCPA), the above rights apply to you by default given our architecture. Since we hold no personal data on our servers, there is nothing for us to provide, correct, or delete on our end beyond what you can already do yourself. For requests related to PostHog's processing (Section 9), you may also contact privacy@posthog.com directly.

15. Data Retention

Data lives on your device for as long as you keep the app installed. Deleting the app removes all locally stored data permanently. Secure Space retains no copies.

Secure Space doesn't keep anything you send to Private Cloud Compute, because it never receives it. Apple's handling is described in Section 5.

PostHog retains analytics events in accordance with their data retention policy, available at posthog.com/privacy.

16. Third-Party Links

The app may contain links to external websites (such as this privacy policy page). We are not responsible for the privacy practices of those sites and encourage you to review their policies independently.

17. Changes to This Policy

If we make material changes to this policy, we will update the "Last Updated" date and notify you within the app. Continued use of Secure Space after changes are posted constitutes acceptance of the revised policy.

18. Contact

For privacy questions or concerns:

hello@securespace.app

© 2026 Secure Space. All rights reserved.