Privacy Policy

Told is a shared journal for photos and small moments with the people you invite. End-to-end encryption is how those entries stay private — not the name of the product. This page describes Told as it actually works today. It is a reachable public policy for toldjournal.com and the Told iOS app. Formal controller language, retention schedules, and regional-rights wording still need counsel review; until that review lands, we only state facts we can stand behind.

What Told is

Told is a place to keep photos, notes, and small moments, and share them only with people you invite into a Space. There is no public follower graph and no advertising network in the app.

Journal content and encryption

Entries, photos, video, voice, and similar journal media are encrypted on your device before they leave it. Told’s Empire backend stores that ciphertext. Empire does not decrypt journal content. Ready media files are served from a public read-only object store as ciphertext; only clients that already have the keys can open them.

Your device keeps a local plaintext copy for the signed-in account so the app can work offline. If you lose the device and have no recovery backup, historical entries can become unreadable. Told cannot reconstruct those keys.

Account and sign-in

Sign-in is provided by Clerk. To create a Told account you need a Clerk user with a name, username, and primary email address. Empire stores those registration fields, the Clerk user ID, and an optional profile image URL so the service can identify the account, show members, and process deletion. That account metadata is not journal ciphertext.

An optional identity-recovery backup is an opaque encrypted blob. Empire stores the blob and cannot tell a correct recovery key from an incorrect one.

Notifications

If you allow notifications, Told registers a device push token through Apple and Expo so Empire can deliver activity alerts. Lock-screen and inbox copy is generic. Told does not put journal text, photo contents, or other encrypted entry bodies into those notifications.

Content reports

A Space member can report an Entry they can see. The app encrypts a frozen copy of that Entry to Told moderators. Empire stores routing metadata and the encrypted report package; it does not decrypt the evidence. Moderators review reports in the app. Reasons include spam, harassment, hate, violence, sexual content, child safety, privacy, and other.

Account deletion

You can delete your account in the app under Profile settings. Deletion removes your Clerk sign-in, your Empire registration, shares you created, memberships, notification delivery for that account, and the local data for that account on the device that performs deletion. You must transfer or delete Spaces you still own, and you cannot delete the last Admin account until another Admin exists. Encrypted media bytes may remain in storage until they are no longer referenced and ordinary cleanup runs. Told cannot read those bytes.

Device permissions

Told asks for device permissions only to create journal content:

Services that see account data

Journal ciphertext is stored on Cloudflare (Workers, D1 metadata, and R2 object storage). Account sign-in is handled by Clerk. Push delivery uses Apple and Expo. We do not claim signed Data Processing Addenda or extra subprocessors here; counsel will complete that list.

The current iOS app does not ship a separate product-analytics, advertising, or crash-reporting SDK.

What this page does not finish

The legal entity name, postal address, named privacy contact, retention periods beyond the product behavior above, international transfer clauses, and state or EU rights request procedures are not published yet. Those sections will be written by counsel and added here without changing this URL.

Contact

Questions about this policy: see toldjournal.com/support.