Privacy Policy

Penumbra - Shadow Journal · Effective date: July 21, 2026 · Last updated: July 21, 2026

This Privacy Policy explains how Penumbra ("Penumbra", "the app", "we", "us", or "our") handles information in connection with your use of the Penumbra iOS application (bundle identifier xyz.bogtsi.umbra). Penumbra is developed and operated by an individual developer based in Israel (the "Developer").

Short version: Penumbra has no user accounts, no login, and no backend server operated by us. Everything you write — journal entries, journey progress, trigger logs, and parts-exercise answers — stays on your iPhone, in a local database, behind an optional Face ID lock that only iOS itself ever sees the biometric data for. We don't run a server and we can't read your journal. Subscriptions are handled by Apple and RevenueCat. The app shows no ads and contains no analytics or advertising SDK of any kind.

1. Who we are & how to contact us

Penumbra is operated by a solo developer based in Israel. For any privacy question or request, contact us at support@bogtsi.xyz.

2. Data stored locally on your device

The following information is created and stored only on your device, in a local SQLite database inside the app's own sandbox. It is never transmitted to us — we operate no server to receive it — and we cannot access it:

Because this data lives only on your device, it is removed when you delete the app, or when you use the double-confirmed delete all data option in Penumbra's Settings. We provide no cloud backup or sync of this information ourselves; if you use iCloud device backup, your device backup is governed by Apple's own policies, not by us.

3. Face ID / passcode app lock

Penumbra offers an optional lock on the app itself, toggled off by default in Settings. When it's on, opening the app calls iOS's own LocalAuthentication framework, which shows the standard system Face ID, Touch ID, or passcode prompt.

Penumbra never receives, sees, or stores any biometric data. Face ID and Touch ID are handled entirely by iOS, inside Apple's own Secure Enclave. Our app receives only a yes/no result — "unlocked" or "not unlocked" — and nothing else. If the check fails for any reason (no biometrics enrolled, a mid-authentication interruption, a device error), Penumbra fails closed: it treats the app as still locked rather than opening it or crashing.

You can turn the lock on or off at any time in Penumbra's Settings. Turning it off does not delete or expose any of your existing entries — it only changes whether the app requires a check before opening.

4. Local notifications

If you enable the daily reminder, Penumbra schedules a local notification on your device only, generated and delivered on-device. We use no push tokens and send no remote push notifications, and the reminder's text never contains anything you've written — only a generic prompt-to-reflect or the name of your active journey and its next day number.

5. Exporting your data (text & PDF)

Penumbra can export your entries as plain text (free, for everyone) or as a PDF (a Penumbra Pro feature). Either way, the app builds the file or text on your device and hands it to the standard iOS share sheet or a "Copy/Share" action. Where it goes next is entirely your choice — Files, Mail, another app — and that destination's handling of it is governed by whatever app or service you choose. The file or text is not sent anywhere by us.

6. Third-party services that process data

Penumbra relies on a small number of third-party services. When you use the app, some of these services may collect or process data directly, under their own privacy policies. We map each one below.

ServiceWhen it appliesWhat it processesPurpose
RevenueCat When you start, restore, or manage a Penumbra Pro subscription Purchase and subscription data, keyed to a pseudonymous app-user identifier (we never set a user ID, because there are no accounts). No journal content, trigger logs, or other writing is ever sent to RevenueCat. To process purchases, validate receipts, and unlock Pro features
Apple / App Store Download, updates, and in-app purchases Purchase transactions and standard App Store data handled by Apple. Payment is made to Apple with your Apple ID — the Developer never receives or sees your payment card details. App distribution and payment processing
iOS LocalAuthentication Only if you turn the Face ID / passcode lock on in Settings A pass/fail authentication result. No biometric data is provided to Penumbra or to us — see Section 3. To lock the app so only you can open it
Expo / EAS App build, distribution, and over-the-air updates Used to build and ship the app and to deliver JavaScript updates; the app sends no journal content or personal data to Expo at runtime as part of Penumbra's features To build and ship app updates

We use no analytics or crash-reporting SDKs of our own (no Firebase, Sentry, Amplitude, or similar), and Penumbra's own code makes no network requests to any server we operate. Penumbra does not integrate with Apple Health / HealthKit and does not request any Health permissions.

Advertising & App Tracking Transparency (ATT)

Penumbra contains no advertising and no advertising SDK. The app displays no ads, contains no third-party ad or tracking framework, and does not collect or use the advertising identifier (IDFA). Because nothing in the app tracks you, Penumbra never presents Apple's App Tracking Transparency prompt. If advertising were ever introduced in a future version, this Privacy Policy would be updated before it shipped — but doing so would work against the app's core design, since advertising would require exactly the kind of data collection Penumbra is built to avoid.

7. Third-party privacy policies

The services above process data under their own privacy policies, which we encourage you to review:

8. How we use information

We ourselves do not collect or receive your personal data, journal content, or trigger logs on any server. Information is used only for the purposes described above: providing app features on-device (journeys, the reflection deck, the trigger log, insights, exports, reminders), and processing subscriptions. We do not sell your personal data, and we do not use it for advertising or profiling — there is no mechanism in the app by which we could, since nothing you write ever reaches us.

9. Data retention

Data stored locally on your device is retained until you delete it in the app, use the delete-all-data option in Settings, or uninstall the app. Data processed by third parties (RevenueCat, Apple) is retained according to their respective policies.

10. Your choices & controls

11. Children's privacy

Penumbra is not directed to children and is not intended for use by anyone under the age of 13 (or the minimum age of digital consent in your jurisdiction, such as 16 under the GDPR). We do not knowingly collect personal information from children — indeed, we do not collect it from anyone, since nothing written in the app is transmitted to us. In line with the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's protections for children (GDPR-K), if you believe a child has provided personal information through the app, please contact us at support@bogtsi.xyz.

12. International users

The Developer is based in Israel. Penumbra is available through the Apple App Store internationally. The third-party services we use (RevenueCat, Apple) may process data in various countries, including the United States, in accordance with their own policies and legal safeguards. Your journal entries, journey progress, and trigger logs are not part of any such transfer — they never leave your device. By using the app, you understand that the limited subscription information described above may be processed in countries other than your own.

13. Security

Because your journal stays on your device, its security is tied to your device's own protections (passcode, encryption) plus, if you enable it, the app's own Face ID / passcode lock, handled entirely by iOS. Data handled by third-party services is protected under their respective security practices. No method of storage or transmission is 100% secure.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here; your continued use of the app after an update constitutes acceptance of the revised policy.

15. Contact

Questions about this Privacy Policy or your data? Email support@bogtsi.xyz.