← Cipher Haus

Privacy Policy

Last updated September 13, 2026

Overview

Cipher Haus builds two services, referred to here as I and II. This policy explains what each collects, why, and how you can control or delete it. If you only use one of them, only that section applies to you.

Service I

To use Service I, you create an account with an email address, a display name, and a password (stored as a salted hash, never in plain text). You can optionally add a phone number for verification and enable two-factor authentication.

When you leave something for someone to find, we store the content you submit (which may include audio or images) and the location where you chose to leave it. Location is only recorded at the moment you act — we don't track your location in the background.

If content is reported, we store the report and the content it refers to so it can be reviewed. We use automated filtering to catch some disallowed content before it's posted.

We don't sell your data or share it with advertisers. Moderators may access reported content and account details as needed to review reports and enforce community rules.

Service II

Service II is local-first: your entries, reflections, and progress are stored on your device by default, and you can use the full app without ever creating an account or sending data anywhere.

If you choose to create an account to sync across devices, we store the minimum needed to do that, and you can protect it with two-factor authentication. Exported backups are encrypted on your device before they leave it — we never see the unencrypted contents or hold the key.

If you generate a link to share your progress with a care provider, that link is cryptographically signed and expires automatically (currently 72 hours), and can be revoked at any time.

Service II is deliberately built to never ask for or track calorie counts, macros, weight, or BMI — this is enforced in how the app is built, not just a policy we could quietly change. We don't use advertising SDKs, analytics trackers, or sell data to brokers.

Deleting Your Data

Service I: you can delete your account directly from within the app. This removes your account and content, including any audio you've submitted.

Service II: local data can be erased from within the app at any time. If you have a cloud sync account, you can delete it directly from within the app as well.

If you're ever unable to complete a deletion in-app for any reason, contact us at support@cipher.haus and we'll take care of it.

Security

We use encryption in transit, and, where noted above, encryption at rest or on-device. If you believe you've found a security issue, please report it to security@cipher.haus rather than filing a public issue or report.

Children's Privacy

These services are not directed at children under 13, and we don't knowingly collect personal information from them.

Changes to This Policy

If anything material changes about what we collect or how we use it, we'll update this page and change the date above.

Contact