Privacy in Parched
Parched is made by Dudley Development, LLC. This page describes the current test version. We'll update it before adding new ways to process your writing.
Your journal
Journal text, photos, drawings, Stickies, prompt feedback, and personal preferences are stored in an encrypted vault on your device. Its key is kept in the device Keychain. The vault is excluded from the operating system's automatic backup. You can create a separate encrypted recovery file.
Optional personal prompts use eligible writing on supported devices through Apple's on-device model. You can turn this off or exclude a particular page. The current app does not send journal text to a cloud model. Cloud generation and automatic encrypted sync are not active.
Your account and shared content
We use Supabase in the US West region for authentication and the server features. Your account contains an identifier, sign-in email, and any identity information supplied by the sign-in provider. Your social profile includes the username and display name you choose.
When you deliberately share with friends or publish to a public board, the selected text or contribution is sent to the server so its intended readers can see it. Public contributions may include text, pictures, or drawings. Friends, invitations, blocks, reports, and access permissions are also stored there. Private journal pages are not automatically published.
Prepared agent features can store selected readable text, approved profile facts, grants, suggested actions, and access records. No agent connection is active in this test version. Future connections will require a separate opt-in. Revoking access prevents future reads; it cannot remove a copy a recipient already saved.
Device permissions
Notifications are optional. Selecting a photo uses the system photo picker. Saving an exported image asks for permission to add it to Photos. Calendar and Reminders access is requested when you choose their respective tools. Face ID or device authentication is used when you enable journal locking or confirm a protected recovery action.
Your calendar is not sent to an AI service. A reminder is created only after you choose its details or approve a suggestion. Notifications do not include your journal words.
Advertising and service records
There is no ad SDK, cross-app tracking, or session replay in the app. We do not sell journal content or use it for ad targeting.
Supabase and Cloudflare process the technical information needed to operate their services, such as request timing, network addresses, and error records. Account emails use our configured Cloudflare sending service. Support emails go to our support mailbox. Avoid including sensitive writing when contacting us.
Removal and recovery
Deleted local pages are recoverable in Trash for seven days. Expired items are removed from the active vault when the app processes them. The previous encrypted recovery snapshot and recovery files you exported can retain older copies. Deleting a server account removes its server account data and associated copies through the app's deletion workflow. Provider backups follow the provider's retention process.
Removing the app can remove device-local writing. Export a recovery file first. Content a friend, social app, or agent already copied is outside our ability to recall.
To ask about access, correction, or removal of server information, contact support@dudleyapps.com.
Parched