Calmatte is a journal for things you might not say out loud. This page tells you exactly where those things go, who can read them, and how to take them back.
Effective 19 August 2026. Last updated 19 August 2026. Applies to the Calmatte iOS app and calmatte.app.
That is the summary. Everything below is the detail, and the detail is what actually binds us.
Calmatte is made by Appè Latte, based in Alberta, Canada. For anything in this policy, including a request to see or delete your data, write to support@appe-latte.ca. Appè Latte is the data controller for the information described here.
We collect only what the app needs to work. There is no hidden collection, and nothing is gathered for advertising or profiling.
When you create an account we store your email address, the display name you choose, and an account identifier. This is handled by Firebase Authentication (Google). Your device registers a push token with Apple at launch, which we pass to Firebase Authentication so it can verify sign-in requests silently. This happens whether or not you turn on reminders; it is used for account security, not for sending you marketing.
Stored in your account so it can sync between your devices and be restored if you lose your phone:
Some of this is health information about your mental state. We treat it that way: it is never used for advertising, never sold, never shared with anyone for their own purposes, and never analysed to build a profile of you.
If you subscribe, Apple processes the payment. We never see your card details. Our subscription provider, RevenueCat, receives your account identifier and the App Store receipt so the app knows whether your subscription is active.
| What | Where it lives |
|---|---|
| Voice note audio | Your phone's app storage. The audio file is never uploaded — only a reference to it is synced, so your other devices know a recording existed. |
| Voice transcription | Apple's on-device speech recognition. We require on-device recognition, so the audio is not sent to Apple's servers for transcription. |
| Matte's replies | Apple's on-device language model. See section 8. |
| Crisis detection | Local text matching in the app. Nothing is sent anywhere to decide whether to show you crisis resources. |
| App passcode | Stored in the iOS Keychain as a salted hash. We never see it and it cannot be recovered from what is stored. |
| Your safety plan | Kept on your device, and included in your end-to-end encrypted iCloud backup so it survives a lost phone — the one moment you would least want to have lost it. It is not sent to our servers, and the backup's key is yours; we cannot read it. |
| The name of the person you share briefs with | Kept on your device and never written to your account. If you create a share link, their name is placed inside the encrypted brief, which we host as ciphertext we cannot read — so it reaches our servers only in a form that is unreadable to us, and only because you chose to share. |
Under Canadian privacy law we rely on your consent. If you are in the UK or the European Economic Area, our lawful bases under the UK GDPR / GDPR are:
We use a small number of providers. Each is contractually limited to processing data on our instructions. None of them is permitted to use your content for their own purposes.
| Provider | What they process | Why |
|---|---|---|
| Google (Firebase) | Account details; your moods, journal entries, photos, thought records and questionnaire scores | Sign-in and cloud storage so your journal syncs and survives a lost phone |
| Apple | Your encrypted iCloud backup; App Store payments; on-device AI and speech (no content sent) | Backup, purchases and system features |
| RevenueCat | Your account identifier and App Store receipt | To know whether your subscription is active |
| Supabase & Vercel | Only the encrypted blob of a session brief you choose to share, plus its expiry | To host a shared link. See section 7 — they hold ciphertext they cannot read |
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.
#, and browsers never send that part to a server. We store something we cannot open.
If you create a link to share a session brief:
Anyone you send the link to can read the brief while it is live, and can save or print it. Send it only to someone you mean to give it to.
Matte answers questions about your own journal. It runs on Apple's on-device foundation model. Your entries are not sent to us, to Apple, or to any AI provider for processing, and they are not used to train any model. When the on-device model is unavailable, Matte falls back to text the app composes locally from your entries.
Matte is not a therapist and does not diagnose. It quotes your own words back to you. If something you write suggests you may be in crisis, the app detects that locally and shows you real-world help.
This is the one place the app forms an opinion about your writing, so here is exactly what it does.
The check runs entirely on your phone, using pattern matching built into the app. No entry is sent anywhere to be assessed, and no AI service is involved. It reads only the words you wrote in an entry.
Matte will not discuss, encourage, rehearse or help you plan self-harm, suicide, harming another person, or sexual activity — and it will not quote entries of yours on those subjects back to you. If what you write suggests you may be in danger, it stops and offers real help instead of a reply. That hand-off costs you nothing from your daily message allowance.
When an entry clearly describes thoughts of self-harm, or of harming someone else, the app writes down three things: the date, the category, and how sure it is. It never stores the sentence, the entry, or a quote. That record is encrypted and stays on your device — it is not sent to us, not put in your account, and not included in your iCloud backup's readable form.
Sexual content is not recorded at all by default. Matte declines to discuss it, but nothing is written down and nothing is disclosed, unless you deliberately turn that on yourself. Your private life is not a clinical concern, and we are not going to treat it as one.
Only you, unless you choose otherwise. The record exists so that if you create a session brief for a clinician, that brief can carry a short note — "3 entries between 4 and 19 August looked concerning" — so they know to ask. You see that note, in full, on the brief screen before you send anything, and you can turn it off. Nothing about this is silent, and no link is created without you tapping to create it.
You can stop the brief disclosing anything, and you can clear the record, in Settings. Deleting your account deletes it along with everything else. Editing an entry so it no longer reads that way removes its flag — if you take something back, the app takes it back too.
| Permission | What it is for |
|---|---|
| Microphone | Recording a voice note for a journal entry. Only when you start a recording. |
| Speech recognition | Turning that recording into text, on your device. |
| Photo library | Attaching a photo you pick to an entry. We do not read your library otherwise. |
| Face ID / Touch ID | Unlocking the app, if you turn on the app lock. Biometrics are handled by iOS; we never receive them. |
| Notifications | Reminders you set up. Optional. |
Declining any of these leaves the rest of the app working.
Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. Depending on your location you may also have the right to restrict or object to processing, to data portability, and to complain to a regulator — in Canada, the Office of the Privacy Commissioner; in the UK, the ICO; in the EEA, your national authority.
You do not have to ask us for most of it:
To make a request in writing, email support@appe-latte.ca. We will respond within 30 days. We will not charge you or treat you differently for exercising a right.
In the app: Settings → Delete everything. This permanently removes your entries, journal text, photos, thought records, questionnaire results, voice recordings, your iCloud backup of them, any generated reports on the device, and your account itself. Any live share link is revoked.
Any live share link is revoked as part of this. If your device happens to be offline at that moment, the link cannot be reached to kill it — but it still expires on its own within seven days at the latest, and that limit is enforced by the database, not by the app. Deletion is otherwise immediate and cannot be undone. Export first if you want a copy. Purchases are handled by Apple; deleting your account does not cancel a subscription — manage that in your App Store account settings.
No system is perfect. If we ever discover a breach affecting your data, we will tell you and the relevant regulator as required by law.
Calmatte is not intended for children under 13, and we do not knowingly collect their information. In the EEA and the UK, if you are under 16 you need a parent or guardian's consent to use it. If you believe a child has given us information, email us and we will delete it.
We are in Canada. Our providers process data in facilities that may be in Canada, the United States or the European Union. Where data leaves the UK or EEA, transfers are covered by the providers' Standard Contractual Clauses. The database holding shared briefs is in Canada.
If we change this policy in a way that materially affects you, we will tell you in the app before it takes effect, and update the date at the top. Continuing to use Calmatte after that means you accept the new version.
Questions, requests, or complaints: support@appe-latte.ca.
Appè Latte, Alberta, Canada.