Privacy Policy
Effective: July 27, 2026
App: Guiding Light
Developer: Frozen Grape (“we,” “us,” “our”)
Contact: support@frozengrape.app
In one sentence
Guiding Light is built so we can’t read your journal entries, and we don’t try.
In a few more
Your journal entries are encrypted on your iPhone with a key only you hold. We don’t have a copy of that key. We don’t run analytics on what you write. We don’t sell your data. We don’t show you ads. The few moments when something does leave your device — when you ask the reflective companion for a question, when you download narrated audio, and a small count of anonymous usage events you can switch off — we explain below.
What stays on your device
- Journal entries. Encrypted with AES-256-GCM. The encryption key lives in your iPhone’s Keychain, gated behind Face ID, Touch ID, or your device passcode. The key is bound to this device and never leaves it — not to iCloud, not to us, not to anywhere.
- Encrypted “looking back” reflections you write when marking a prayer answered. Same encryption.
- Audio downloads. Once an audio narration is on your phone, it stays there and plays without contacting us. You control which translations and voices are downloaded.
- Your master key. We can’t read your entries. Neither can anyone else with our cooperation, including in response to a legal request, because we don’t have access. If you lose your device and key, your encrypted entries cannot be recovered.
What is not encrypted on your device
A few pieces of metadata stay in plaintext on your phone so the app can function without unlocking on every screen:
- The date and time of each entry
- Which “mode” the entry was written under (e.g., Prayer Journal, Gratitude)
- The character count
- Detected theme tags (e.g., “anxiety”, “gratitude”) — see “How theme detection works” below. Computed on this device, never sent anywhere
- Whether the entry has been marked as an answered prayer, and when
These never leave your device either, but they aren’t behind the encryption boundary.
How theme detection works
Guiding Light notices recurring themes in your writing — “4 entries this week mention work” — so you can see patterns over time. We want to be precise about how, because “the app analyses my journal” deserves a real answer.
When you save an entry, the app converts its text into a numeric representation (a “sentence embedding”) using Apple’s on-device Natural Language framework, which ships with iOS. It compares that representation against a fixed, human-written list of about 30 themes bundled in the app, and tags the entry with the closest matches. No text is generated, no model is trained on you, and no cloud service is involved.
Everything about this happens on your iPhone:
- The embedding is computed on-device by iOS itself. Your entry text is not sent anywhere to be analysed.
- The theme list is fixed and written by hand. The app cannot invent a new theme about you; adding one requires a new app release.
- Themes are plain descriptive nouns (“work,” “grief,” “doubt”). The app reports counts and dates, never judgements about you.
- If a theme doesn’t fit, you can hide it. That signal stays on your device and is never reported to us.
What we collect
Nothing that identifies you. No accounts in V1.0. No usernames, no email addresses, no name, no contacts, no location. No third-party analytics SDKs of any kind (no Mixpanel, no Amplitude, no Firebase Analytics, no Segment, no Sentry-with-user-attribution, no Google).
We do run a small amount of first-party data collection on our own server, described immediately below, and we use two third-party processors for specific features, described after that. That is the complete list.
What our own server receives
An anonymous device identifier
The app generates a random identifier the first time it runs — a UUID, not Apple’s advertising or vendor ID — and sends it with the requests described below as X-GL-Device-ID. It is not linked to your identity, because we have no identity for you: no account, no email, nothing to link it to. Delete and reinstall the app and it becomes a brand-new identifier with no connection to the old one.
We use it for three things, and nothing else:
- Rate limiting. So one device can’t exhaust the reflective companion’s shared capacity. We store one row per allowed request (a timestamp and the identifier) on a rolling 7-day window, then it ages out.
- Subscription status. If you subscribe to Guiding Light Plus, we store a row recording that this install has an active entitlement, so premium features work. Apple tells us about renewals and cancellations; we never see your payment details.
- App integrity (Apple App Attest). To stop other people’s software from impersonating the app and running up our AI bill, your iPhone registers a hardware-backed key with us and signs each request. We store the key’s public half, its identifier, and a counter. This proves a request came from a genuine copy of Guiding Light on a real Apple device. It says nothing about who you are and cannot be used to identify you.
Anonymous usage counts — and how to turn them off
So we can tell whether the app works (are people finishing onboarding? does the companion actually get used?), the app sends per-day counts of a fixed list of events, keyed to the anonymous identifier above. For example: app_opened: 4, entry_saved: 2.
What this is not: there is no journal text, no verse text, no theme names, no free text of any kind, no screen-by-screen trail, and no timestamps finer than the day. The event names are a short allowlist fixed in advance — things like app_opened, onboarding_completed, entry_saved, reflection_requested, upsell_shown. Our server drops any name that isn’t on the list. We cannot add a new one without shipping an app update and a server update.
You can switch this off, and it is genuinely off — not merely unreported:
- Settings → Privacy → turn off usage counts, or
- Settings → Privacy → Local-only mode, which disables it along with everything else that uses the network.
With either enabled, the app stops recording events at the source; nothing is buffered and nothing is sent later.
Third-party services
Anthropic — reflective companion
When you write a journal entry and Guiding Light shows you a reflective question or related scripture, the text of that entry is sent to Anthropic’s Claude API to generate the question. This is the only time the plaintext of an entry leaves your device.
Per Anthropic’s API terms in effect as of July 27, 2026, API submissions are not used to train Anthropic’s models. Anthropic retains data only for limited periods for abuse-detection and safety purposes. You can read their policy at https://www.anthropic.com/legal/privacy.
You can opt out of the reflective companion at any time by turning on Local-only mode in Settings → Privacy. When Local-only mode is on, no entry text is ever sent to Anthropic, full stop. You’ll see a small “Local-only mode” notice in place of the reflective companion’s questions.
OpenAI — audio narration (premium voices)
Premium narrated audio of the bundled public-domain Bible translations (Berean Standard, World English, King James, American Standard, and Young’s Literal) is generated on demand using OpenAI’s text-to-speech API (gpt-4o-mini-tts). When you tap play on a passage in a premium voice for the first time, the passage text is sent to OpenAI, the audio it returns is cached on your device, and every replay from that point on is offline. Free-tier narration is rendered entirely on your device by Apple’s built-in speech synthesizer and involves no network call at all.
No journal content is ever sent to OpenAI — only the public-domain scripture text being narrated. Per OpenAI’s API terms in effect as of July 27, 2026, API submissions are not used to train their models. You can read their policy at https://openai.com/policies/privacy-policy.
(In a future release we plan to migrate premium narration to ElevenLabs, with audio generated once on our servers and bundled into a downloadable audio library — at that point no narration request will originate from your device at all. The local-playback promise is unchanged either way: we never see what you listen to.)
Apple — App Store and device services
When you install Guiding Light, Apple processes your purchase and download under Apple’s privacy policy. We receive only the aggregate, anonymous App Store reports Apple provides to all developers (downloads, crashes, country breakdowns). These reports never include who you are or what you wrote.
If you choose to share crash logs with developers in your iOS Settings, Apple may send us anonymized crash diagnostics. These contain no journal content and no personally identifying information.
No one else
We do not use any other third-party services that receive your data. No ad networks, no CRM, no marketing tools, no behavioral analytics.
Local-only mode
You can turn on Local-only mode in Settings → Privacy. When Local-only mode is on:
- Reflective companion is disabled (no entry text leaves your device for AI)
- Anonymous usage counts stop being recorded and stop being sent
- Premium narration is not requested from OpenAI; narration falls back to your iPhone’s built-in speech synthesizer
- No future cloud-sync feature will be enabled on your account
In Local-only mode the app makes no network requests of its own at all. It remains fully usable — you give up AI-generated reflective questions and premium narration voices, and you keep everything else, including your entire journal, all five translations, and the memory layer.
What we never do
- We do not sell, rent, or trade your data with anyone.
- We do not show you advertising, in-app or otherwise.
- We do not build a profile of you for targeting purposes.
- We do not transcribe voice journaling to any third-party speech-to-text service. Voice transcription, when added, will be on-device only.
- We do not pre-fetch or “warm up” your journal in the background. Decryption happens only when you open an entry.
- We do not include your journal content in crash reports.
Children
Guiding Light is intended for users age 13 and older. We do not knowingly collect any information from children under 13, and because the app has no accounts and asks for no personal details, we hold nothing that identifies any user of any age. If you believe a child under 13 has used the app, contact us at support@frozengrape.app and we will work to address it. Deleting the app removes everything stored on the device; if you can supply the install’s anonymous identifier, we will delete the associated server-side rows as well.
Your data is yours
- Export. Settings → Privacy → “Export as Markdown” or “Export as JSON” produces a complete copy of your decrypted entries to your iPhone’s share sheet. We never see the export.
- Delete. Settings → Privacy → “Delete all entries” permanently removes every journal entry from this device. Because the entries are encrypted with a device-only key, deletion is final — there is no backup we can restore from.
- Uninstall. Deleting Guiding Light from your iPhone removes all of its data, including the master key in the Keychain. After uninstall, encrypted entries on the device cannot be recovered.
Legal requests
If we are presented with a valid legal request for journal content, we can only provide what we have, which is nothing: we hold no copy of your entries, no key to decrypt them, and nothing that records what you wrote.
To be complete rather than merely reassuring — what we could produce, for an install identified by its anonymous UUID, is the material described in “What our own server receives”: rate-limit rows, a subscription-status row, an App Attest key record, and per-day counts of allowlisted events. None of it contains journal content, and none of it identifies a person. We have no way to connect that identifier to a name, an email, or a device, because we never collect any of those.
If you have asked the reflective companion a question, Anthropic may have retained that submission per their own retention policy; in that case, the request should be directed to Anthropic, not us.
International users
Guiding Light is operated from Texas, United States. If you use the app from another country, you understand that the app may transmit data (such as a Claude API request) across borders to the United States. Where the GDPR, UK GDPR, or comparable law applies to you, you have the rights described in those laws (access, rectification, erasure, restriction, portability, objection). Because we hold almost no data about individual users, most requests will be a matter of confirming that we have nothing to act on.
To exercise these rights, contact support@frozengrape.app.
Changes to this policy
We will update this policy when the app’s behaviour changes — for example, when cloud sync ships in a future version. We will note the new effective date at the top and, where the change is material, surface a notice inside the app the next time you open it. Continued use after a change means you accept it; if you don’t, you can uninstall the app and export your data first.
Contact
Questions or concerns about this policy:
Frozen Grape
support@frozengrape.app
We read every email.