BackPrivacy Policy

Privacy Policy

Effective date: March 23, 2026

Untold Archives (“the App”) is operated at untoldarchives.app. We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.

1. Information We Collect

Account information

If you create an account, we collect your email address and basic profile information. You may also sign in using Apple Sign-In or Google Sign-In (OAuth), in which case we receive your name and email address from the identity provider. We do not receive or store your password from OAuth providers.

Reading activity

We record which story cards you view, swipe past, save to your library, or read in full. This data is associated with your account or anonymous session ID and is used to personalise your feed, power recommendations, and track your reading streak.

Journal entries

If you use the journalling feature, your written reflections are stored in our database tied to your account or anonymous session ID. Journal entries are private by default, are not used to train AI models, and are not shared with third parties.

Push notification tokens

If you opt in to push notifications, we store the device token provided by Apple Push Notification Service (APNs) or Google Firebase Cloud Messaging (FCM). These tokens are used solely to deliver notifications you have requested (e.g., daily story reminders, streak reminders). You can revoke notification permissions at any time through your device settings.

Payment information

If you subscribe to Untold Archives Pro, payment is processed by Apple (App Store), Google (Google Play), or RevenueCat. We do not directly collect or store your credit card number, billing address, or other payment details. We receive only a subscription status and transaction identifier from these providers.

Automatically collected data

When you use the App, standard technical information may be collected, including your IP address, device type, operating system version, app version, and general usage analytics. This data is used for debugging, security, and improving the App.

2. How We Use Your Information

  • To personalise your story feed based on what you've read and saved.
  • To track your reading streak and display progress statistics on your profile.
  • To sync your library, journal entries, and preferences across devices when signed in.
  • To send push notifications you have opted into (daily stories, streak reminders).
  • To process and manage your subscription through Apple, Google, or RevenueCat.
  • To improve the quality and relevance of content in the App.
  • To detect and prevent fraud, abuse, or security incidents.

We do not use your data for advertising, and we do not build advertising profiles. We do not sell, rent, or share your data with advertisers or data brokers.

3. Third-Party Services

Supabase

We use Supabase for our database, authentication, and file storage. Your account data, reading activity, and journal entries are stored there. Supabase is SOC 2 certified and stores data in secure cloud infrastructure. See supabase.com/privacy.

Expo (Push Notifications)

We use Expo's push notification service to deliver notifications to your device. Expo receives your device push token and the notification content. See expo.dev/privacy.

RevenueCat (Payments)

We use RevenueCat to manage in-app subscriptions across platforms. RevenueCat receives your anonymised user identifier and subscription status from Apple or Google. See revenuecat.com/privacy.

Apple and Google (OAuth and Payments)

If you sign in with Apple or Google, authentication is handled by the respective provider. If you purchase a subscription through the App Store or Google Play, the payment is processed entirely by Apple or Google. We receive only your authentication token and subscription status. See apple.com/legal/privacy and policies.google.com/privacy.

Vercel

Our web app is hosted on Vercel, which may log standard server access logs (IP address, request path, timestamp) for security and debugging purposes. See vercel.com/legal/privacy-policy.

Anthropic and OpenAI

Story text is generated using Anthropic's Claude API. Card images are generated using OpenAI's image API. Content generation happens server-side during our editorial process — your personal data and journal entries are not sent to these providers.

4. Data Retention and Deletion

We retain your account data, reading history, and journal entries for as long as your account is active, in order to provide and improve your experience.

Clearing reading history

You can clear your reading history at any time from your Profile settings. This will reset your feed recommendations but will not delete your account.

Deleting your account

You can request full account deletion from your Profile settings or by emailing us at privacy@untoldarchives.app. Upon deletion, we will permanently remove your account data, reading history, journal entries, and push notification tokens within 30 days. Server access logs may be retained for up to 90 days for security purposes before automatic deletion.

Subscription data

If you have an active subscription, cancelling it through Apple or Google does not delete your account. You must separately request account deletion if desired. RevenueCat may retain anonymised transaction records as required for financial compliance.

5. Children's Privacy (COPPA Compliance)

Untold Archives is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, you may not use the App.

In the European Economic Area, the minimum age is 16 unless a member state has provided for a lower age (which shall not be below 13).

If we learn that we have collected personal information from a child under the applicable minimum age without verified parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@untoldarchives.app.

6. Local Storage

The following data may be stored only on your device and is not uploaded to our servers unless you are signed in:

  • The IDs of cards you have already seen (to avoid showing duplicates)
  • Your saved / library card IDs
  • Your display name preference
  • Your text size and reading mode preferences
  • Notification preferences
  • Reading streak data

Clearing your browser or app storage will reset all locally stored data.

7. Your Rights

Depending on where you are located, you may have the right to:

  • Access the data we hold about you
  • Request correction of any inaccurate data
  • Request deletion of your account and associated data
  • Object to or restrict certain processing
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent for optional data processing (e.g., push notifications)

To exercise any of these rights, email us at privacy@untoldarchives.app. We will respond within 30 days.

8. Security

We use HTTPS for all data in transit. Data at rest is protected by Supabase's Row-Level Security policies, which restrict access so that users can only view their own data. Authentication tokens are securely stored and transmitted.

No security measure is perfect. We take reasonable steps to protect the data we hold, but we cannot guarantee absolute security. If we become aware of a data breach that affects your personal information, we will notify you in accordance with applicable law.

9. International Data Transfers

Your data may be processed and stored in the United States or other countries where our service providers operate. By using the App, you consent to the transfer of your data to these countries, which may have different data protection laws than your country of residence.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the App or via email if you have an account. The “Effective date” at the top of this page will be updated accordingly. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

11. Contact

Questions or concerns about this Privacy Policy? Reach us at privacy@untoldarchives.app.

Untold Archives — Last updated March 2026