This policy explains what Weavelore collects, why, who it goes to, and how you get rid of it. If you only ever read a story someone sent you on the web, most of this doesn’t apply — skip to “If you were only sent a story.”
What actually happens
What we collect — only what the app needs
- Your sign-in. You sign in with Apple. We get an Apple relay email (a forwarding address, not your real inbox unless you chose to share it) and the display name you give us. We never see or store a password.
- Your stories. The words you write, and copies of the photos you choose to put into a story when you publish or send it. We don’t reach into your photo library and take anything you didn’t place in a story.
- Where you were, if you turn tracking on. If you let the app trace a trip, we record the trail so your story can draw the route. This is off until you allow it, and you can turn it off anytime in iOS Settings.
- The people you send to. When you address a letter, you pick a recipient. We keep only the ones you actually send to, so the letter can be delivered.
- How the app is used. Basic in-app events so we can tell what’s working. This is our own analytics — not sold, not used to track you elsewhere.
What we do not do
- We do not track you across other apps or websites. No advertising identifier, no ad networks, no data brokers.
- We do not store your password or your credit card. Apple handles sign-in and, if you subscribe, payment.
- We do not use your private letters for anything but delivering them to the person you sent them to — not for publishing, not for training AI.
When a story becomes public
A story is private until you make it discoverable. Only then can it be published or used to help train AI systems, and only under our Terms. When we do, we anonymize: your name and direct identifiers come out; location and dates stay because they’re part of the story. Photos with recognizable people are never used to train AI unless you explicitly affirmed that specific photo.
Deleting your account
You can delete your account anytime in the app. We erase your login, profile and personal details, drafts and private/unsent stories and their photos, your relationship graph, and your inbox. Two things stay on purpose: letters you already sent (they belong to the people you gave them to now) and Lore you added to someone else’s story (part of their story now). Your name stays only as the author of what you chose to give. If someone else deletes their account, we remove their personal details and can no longer reach or connect them, though a plain mention another author wrote into their own story may remain.
If you were only sent a story
You can read it on the web with no account and no sign-in — we don’t collect personal information from you to show you a story. Every reader gets a low-key “Report a concern” link; you don’t need an account to use it.
The details
1. Scope
This policy covers the Weavelore iOS app and the public reader on the web. It does not cover the third parties we rely on to operate (see below); review their own policies. Weavelore is not currently offered to residents of the European Union, and this policy is written for that scope.
2. What we collect and why
Each category below is linked to your account and is not used to track you.
| Data | What it is | Why |
|---|---|---|
| The Apple relay address from Sign in with Apple | Account identity | |
| Name | The display name shown on your letters | App functionality |
| Precise location | Trip trail (GPS points), only when you enable trip tracing | Drawing your route |
| Photos | Copies of photos you place in a story, uploaded when you send or publish | App functionality |
| Contacts | Only the recipients you choose when sending a letter | Delivery |
| Product interaction | In-app engagement events (opens, sends) | Our own analytics |
We do not collect data outside these categories. If we ever need a new one, this policy and the App Store label are updated before we start. We use no advertising identifier and declare no tracking.
3. How we use it
To run the app (authenticate you, store and deliver your stories, draw your routes, deliver letters); for aggregate first-party product analytics to improve the app; and — only for stories you mark discoverable — for publishing and AI training under the Terms, subject to the anonymization and photo-likeness rules below. Private letters are excluded entirely.
4. Anonymization, likeness & Lore
In any publishing or training use we remove or anonymize direct identifiers (name, email, phone, address); we may retain location, dates, and context, because those are the substance of the story. Photos in a discoverable story are not included in AI training if they contain reasonably recognizable people, unless you explicitly affirmed that photo; photos that include minors require a conscious inclusion decision before any public publish. Reader Lore is governed by the same rules, with reader identifiers anonymized in training uses.
5. What we keep, and for how long
While your account is active, we keep your stories, photos, routes, graph, and inbox so the app works. When you delete your account, we erase your login, profile and personal identifiers, drafts/private/unsent stories and their photos and files, your relationship graph, and your analytics/letterbox/inbox. What survives, and why: letters you already sent stay live for their recipients (to keep those links working we hold a snapshot of the sent letter, including your display name as its author); Lore you contributed stays part of others’ stories; and a plain authored mention of you in someone else’s story may remain when they haven’t deleted it, because it is their content — but your identifiers and reachability are removed when you delete. Cancelling a subscription is not deletion.
6. How we protect it
Data is encrypted in transit and at rest. We do not store passwords; sign-in is delegated to Apple. Privileged server credentials never ship in the app or the web client; privileged operations run only in server-side functions. If a security breach affects your data, we will notify you within 30 days.
7. Who else touches your data
We use these providers to operate, and your data necessarily flows through them: Apple (Sign in with Apple; App Store payment); Supabase (database, storage, auth, server functions); Vercel (hosting the public reader); an email provider (delivering letter emails); and AI providers (generating journals and search embeddings from your story text). We do not sell your personal information. We share it only to run the service, and with law enforcement only where legally required.
8. Your choices
- Location: enable or disable trip tracing anytime in iOS Settings → Weavelore → Location.
- Photos & contacts: iOS asks permission before either; change access in iOS Settings. We only receive what you place in a story or the recipients you send to.
- Delete your account: in-app, anytime. This is the erase control.
- Export: you can export your stories in a portable format.
- Report a concern: on every public reader page and in a letter’s menu, no account required.
9. Legal & safety
Weavelore has zero tolerance for child sexual abuse material: suspected material is removed and reported to NCMEC’s CyberTipline, and the account terminated, with evidence preserved for law enforcement. We may disclose data where required by law or to protect users.
10. Children
Weavelore is not directed to children under 13, and we do not knowingly collect personal information from them. Photos that include minors are subject to the conscious-inclusion rule above before any public publish.
11. Changes & contact
We may update this policy; material changes appear here with a new date. For questions or requests, use the “Report a concern” / contact address published in the app and on the reader.