privacy
Dated .
This page says what the Museum of Sorrow app for iPhone keeps on the phone, what it sends, and to whom. It also covers this website. “We” is the developer of the app.
What never leaves the phone
- What you type. The feeling you type is read on the phone and matched to a word on the phone. It is not sent to us or to anyone else.
- Your notes. A note you write under a word is stored on the phone and nowhere else.
- Your journal. The journal is stored on the phone and nowhere else. That a word was kept or let go is one of the events listed below.
On an iPhone that has Apple Intelligence, Apple’s on-device language model reads the typed text to choose among the words the app found and to write one line. That model runs on the phone. A text that brought up the crisis card is not given to it.
What the app sends
The app sends a list of events to a server that we run. An event is a name and a few values, and each value comes from a fixed list: a word of the collection, a page of the app, a size range, a reason. No event holds anything you typed.
Every event carries these:
- A random install id, which the app makes the first time it opens. It is not your name, your Apple Account, or an advertising identifier. When the app is deleted the id is deleted with it, and a new install that is not restored from a backup gets a new one. The id is part of a backup of the phone, so it stays the same when a phone is restored from a backup or moved to a new phone.
- A random id for the event itself, a random id for the session, the position of the event in the session, and the time on the phone.
- The version and the build of the app, whether it is a development build or a release build, the word “ios”, and a level, which is “info” or “error”.
The server adds one thing to each event: the time at which it received it.
The events say these things:
- That the app was opened, and which pages were entered and left, each with a rough duration.
- That a search was asked for with nothing typed.
- For each search: the word the app found and the group of feelings that word belongs to, whether the fit was close or loose, and roughly how long the typed text was, as one of a few size ranges. When no word was found, that fact and nothing of the text.
- Which words were opened, and which were kept or let go.
- That a note was saved, with a rough length. Never the note.
- Whether the crisis card was shown and why: a phrase from a list of self-harm phrases, a word of despair together with a negative sentiment score, or the “crisis help” button. Whether the crisis help was opened. Whether a hotline number was touched, with the country that hotline serves. Not the number, and not where you are: the app does not use location.
- That a word of the week was scheduled, that one of its notifications was opened, or that notifications were refused.
- That the tip page was shown, and whether a purchase was completed, cancelled, or failed, with a reason from a fixed list. No price, no transaction id, no Apple Account.
- That the search animation was skipped, that the lines of the first visit were shown and how they left, that a room or a corridor of the journal was drawn, and, in a version of the app with music, that music started and roughly how long it played.
- Failures, as codes from fixed lists: a search that failed, a purchase that failed, events that could not be delivered. Also which stored data the search used.
- Whether the on-device model wrote its line, and when it did not, the reason, as one word from a fixed list: for example that the phone has no such model, that the model was too slow, that it said none of the words fits, or that it was not asked because the text had brought up the crisis card.
We use the events to see whether the app works and where people stop. In the terms of Apple’s privacy labels they are search history, health (the crisis card events), a device id, purchase history, product interaction, and diagnostics. Each is linked to the install id. None is used to track you.
Crash reports
The App Store version of the app sends a report to Sentry when it crashes or stops responding: where in the code it happened, the iOS version, the model of the phone, the version and the build of the app, and the install id, so that a crash can be matched with the events before it. The reporter is set to attach no personal data and to keep no trail of what was done before the crash.
Where it goes
- Events go over HTTPS to a Cloudflare Worker that we run. It stores them in a Cloudflare R2 bucket. Our code does not read or store the IP address of the phone; Cloudflare, as the host, handles the connection.
- Crash reports go to Sentry (Functional Software, Inc.).
Nobody else receives anything. Nothing is sold, and nothing is used for advertising.
What the app does not do
- It has no account. It asks for no name, no email address, and no contacts.
- It has no ads, and it does not use the advertising identifier.
- It does not track you across apps or websites of other companies.
- It holds no analytics software of another company. The crash reporter is the only software of another company in it.
- It does not use location, the camera, the microphone, or your photos.
- It sends no push notifications from a server. The word of the week is a notification that the phone schedules for itself, and it is off until you turn it on.
The tip
The tip is bought through Apple, and Apple handles the payment. The app never sees a card number or an Apple Account.
How long it is kept
No period after which the events are deleted is set yet. When one is set, this page will state it.
The app does not show its install id, and the records hold no name, no email address and no account. So a request cannot be matched to a person, and we cannot find the records of one person to delete them. They are deleted when the period above ends, for everyone. To ask what kinds of records are held, write to the address below.
This website
This website sets no cookies, runs no scripts, and has no analytics. It is hosted on Cloudflare Pages, and Cloudflare, like any host, sees the address a request comes from.
Changes
When the app changes what it sends, this page changes with it, and so does the date at the top.