This Privacy Policy explains how Penumbra ("Penumbra", "the app", "we", "us", or "our") handles information in connection with your use of the Penumbra iOS application (bundle identifier xyz.bogtsi.umbra). Penumbra is developed and operated by an individual developer based in Israel (the "Developer").
Penumbra is operated by a solo developer based in Israel. For any privacy question or request, contact us at support@bogtsi.xyz.
The following information is created and stored only on your device, in a local SQLite database inside the app's own sandbox. It is never transmitted to us — we operate no server to receive it — and we cannot access it:
Because this data lives only on your device, it is removed when you delete the app, or when you use the double-confirmed delete all data option in Penumbra's Settings. We provide no cloud backup or sync of this information ourselves; if you use iCloud device backup, your device backup is governed by Apple's own policies, not by us.
Penumbra offers an optional lock on the app itself, toggled off by default in Settings. When it's on, opening the app calls iOS's own LocalAuthentication framework, which shows the standard system Face ID, Touch ID, or passcode prompt.
You can turn the lock on or off at any time in Penumbra's Settings. Turning it off does not delete or expose any of your existing entries — it only changes whether the app requires a check before opening.
If you enable the daily reminder, Penumbra schedules a local notification on your device only, generated and delivered on-device. We use no push tokens and send no remote push notifications, and the reminder's text never contains anything you've written — only a generic prompt-to-reflect or the name of your active journey and its next day number.
Penumbra can export your entries as plain text (free, for everyone) or as a PDF (a Penumbra Pro feature). Either way, the app builds the file or text on your device and hands it to the standard iOS share sheet or a "Copy/Share" action. Where it goes next is entirely your choice — Files, Mail, another app — and that destination's handling of it is governed by whatever app or service you choose. The file or text is not sent anywhere by us.
Penumbra relies on a small number of third-party services. When you use the app, some of these services may collect or process data directly, under their own privacy policies. We map each one below.
| Service | When it applies | What it processes | Purpose |
|---|---|---|---|
| RevenueCat | When you start, restore, or manage a Penumbra Pro subscription | Purchase and subscription data, keyed to a pseudonymous app-user identifier (we never set a user ID, because there are no accounts). No journal content, trigger logs, or other writing is ever sent to RevenueCat. | To process purchases, validate receipts, and unlock Pro features |
| Apple / App Store | Download, updates, and in-app purchases | Purchase transactions and standard App Store data handled by Apple. Payment is made to Apple with your Apple ID — the Developer never receives or sees your payment card details. | App distribution and payment processing |
| iOS LocalAuthentication | Only if you turn the Face ID / passcode lock on in Settings | A pass/fail authentication result. No biometric data is provided to Penumbra or to us — see Section 3. | To lock the app so only you can open it |
| Expo / EAS | App build, distribution, and over-the-air updates | Used to build and ship the app and to deliver JavaScript updates; the app sends no journal content or personal data to Expo at runtime as part of Penumbra's features | To build and ship app updates |
We use no analytics or crash-reporting SDKs of our own (no Firebase, Sentry, Amplitude, or similar), and Penumbra's own code makes no network requests to any server we operate. Penumbra does not integrate with Apple Health / HealthKit and does not request any Health permissions.
Penumbra contains no advertising and no advertising SDK. The app displays no ads, contains no third-party ad or tracking framework, and does not collect or use the advertising identifier (IDFA). Because nothing in the app tracks you, Penumbra never presents Apple's App Tracking Transparency prompt. If advertising were ever introduced in a future version, this Privacy Policy would be updated before it shipped — but doing so would work against the app's core design, since advertising would require exactly the kind of data collection Penumbra is built to avoid.
The services above process data under their own privacy policies, which we encourage you to review:
We ourselves do not collect or receive your personal data, journal content, or trigger logs on any server. Information is used only for the purposes described above: providing app features on-device (journeys, the reflection deck, the trigger log, insights, exports, reminders), and processing subscriptions. We do not sell your personal data, and we do not use it for advertising or profiling — there is no mechanism in the app by which we could, since nothing you write ever reaches us.
Data stored locally on your device is retained until you delete it in the app, use the delete-all-data option in Settings, or uninstall the app. Data processed by third parties (RevenueCat, Apple) is retained according to their respective policies.
Penumbra is not directed to children and is not intended for use by anyone under the age of 13 (or the minimum age of digital consent in your jurisdiction, such as 16 under the GDPR). We do not knowingly collect personal information from children — indeed, we do not collect it from anyone, since nothing written in the app is transmitted to us. In line with the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's protections for children (GDPR-K), if you believe a child has provided personal information through the app, please contact us at support@bogtsi.xyz.
The Developer is based in Israel. Penumbra is available through the Apple App Store internationally. The third-party services we use (RevenueCat, Apple) may process data in various countries, including the United States, in accordance with their own policies and legal safeguards. Your journal entries, journey progress, and trigger logs are not part of any such transfer — they never leave your device. By using the app, you understand that the limited subscription information described above may be processed in countries other than your own.
Because your journal stays on your device, its security is tied to your device's own protections (passcode, encryption) plus, if you enable it, the app's own Face ID / passcode lock, handled entirely by iOS. Data handled by third-party services is protected under their respective security practices. No method of storage or transmission is 100% secure.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here; your continued use of the app after an update constitutes acceptance of the revised policy.
Questions about this Privacy Policy or your data? Email support@bogtsi.xyz.