Twofold

Effective August 30, 2026

Privacy Policy

Twofold keeps your journal local unless you explicitly enable iCloud Sync in a version that offers it. Twofold does not collect your journal content for developer access.

How the app works

Twofold stores recordings, transcripts, summaries, corrections, and Insights in the app's local container on your device. App Store version 1.0 is local-only. The app has no developer-operated account or backend, advertising SDK, or analytics SDK.

On-device processing

Speech transcription runs on device using Apple's Speech framework. On supported devices, eligible transcript content is organized on device using Apple's Foundation Models framework. The app has no cloud AI fallback.

Apple may download operating-system speech or model resources. Twofold does not intentionally include journal content in those resource requests.

Collection and tracking

Twofold does not collect app data for developer access or track you across apps or websites. It keeps only bounded, content-free operational and sync diagnostics locally for reliability and troubleshooting and does not transmit those diagnostics to the developer.

A future version may offer optional privacy-bounded product analytics to understand feature adoption and reliability. Before that collection begins, this policy and the App Store disclosures will identify the processor, data categories, purposes, consent controls, retention, and deletion process. Journal recordings, transcripts, authored or generated text, prompts, titles, topics, filenames, and journal identifiers will not be analytics data. This future possibility does not change the current version.

Optional iCloud Sync

App Store version 1.0 does not include cloud synchronization. In a later version where iCloud Sync is available, it remains off until you enable it. No separate Twofold password or recovery code is required.

When enabled, Twofold encrypts active videos, audio, transcripts, generated content, and deletion or restoration state on your device before storing encrypted records and files in your Apple account's private CloudKit database. Local originals remain on your device. The data uses your iCloud storage, and uploads may stop if iCloud is unavailable, restricted, or full.

Twofold uses no public CloudKit database for journal content. A supported device signed into the same iCloud account can recover the private sync configuration automatically. The developer does not operate a sync server or browse another user's private database. Apple operates iCloud under Apple's terms and privacy policy. Disabling sync stops future transfers but does not delete your local journal or records already in iCloud.

Permissions

Storage and backups

Finalized videos, local journal metadata, temporary audio, and generated exports use iOS file protection. Encrypted device backups or iCloud Backup may include app-container data under Apple's backup controls.

Export all journal data

In a version that offers Export All Journal Data, you may create a standard ZIP containing readable text, structured JSON, original recordings, Insights, and unexpired Recently Deleted reflections. Settings, reminders, sync state, and diagnostics are not included. The ZIP is not password protected. Temporary export files are removed after sharing or when the app next launches; saved or shared copies remain at their destination.

Sharing and export

You may export individual journal data, share an original recording, or create a complete portable ZIP through the iOS share sheet. The destination you select may process or retain that data under its own terms. Complete exports contain sensitive readable content and recordings without a password. Twofold cannot control data after you share it outside the app.

Retention and deletion

Journal data remains in the app container until you delete it, remove the app, or iOS otherwise manages app data. In a version that offers Recently Deleted, a deleted reflection remains recoverable there for 30 days before permanent purge. You may delete an original video while preserving its processed entry. With sync enabled, deletion and restoration state syncs between participating devices. Disabling sync alone does not delete encrypted cloud records. Exported, synchronized, shared, and backup copies may require separate deletion through Twofold, Apple account storage controls, or their destination.

Changes

This policy and the App Store disclosures will be reviewed before releases that change cloud synchronization, hosted AI, product analytics, accounts, remote diagnostics, external assistants, or other off-device processing.

Contact

support@solidberry.com