Calmatte

Privacy Policy

Calmatte is a journal for things you might not say out loud. This page tells you exactly where those things go, who can read them, and how to take them back.

Effective 19 August 2026. Last updated 19 August 2026. Applies to the Calmatte iOS app and calmatte.app.

1. The short version

In plain terms We do not sell your data, show you ads, or run any analytics or tracking in the app — there is no advertising SDK, no attribution SDK, no crash reporter and no analytics library in it at all. Your journal is stored in your own account so it can sync between your devices. Your voice recordings never leave your phone. The AI runs on your phone. A brief you share with a therapist is encrypted so that we cannot read it.

One thing the summary should not bury: the app reads your entries on your phone to notice writing about self-harm or about hurting someone, and records the date so a brief you choose to send can tell your therapist. It never records what you wrote, we never see it, and nobody is alerted. Section 9 sets out exactly what happens and how to switch it off.

That is the summary. Everything below is the detail, and the detail is what actually binds us.

2. Who we are

Calmatte is made by Appè Latte, based in Alberta, Canada. For anything in this policy, including a request to see or delete your data, write to support@appe-latte.ca. Appè Latte is the data controller for the information described here.

3. What we collect

We collect only what the app needs to work. There is no hidden collection, and nothing is gathered for advertising or profiling.

Your account

When you create an account we store your email address, the display name you choose, and an account identifier. This is handled by Firebase Authentication (Google). Your device registers a push token with Apple at launch, which we pass to Firebase Authentication so it can verify sign-in requests silently. This happens whether or not you turn on reminders; it is used for account security, not for sending you marketing.

What you write and log

Stored in your account so it can sync between your devices and be restored if you lose your phone:

Some of this is health information about your mental state. We treat it that way: it is never used for advertising, never sold, never shared with anyone for their own purposes, and never analysed to build a profile of you.

Purchases

If you subscribe, Apple processes the payment. We never see your card details. Our subscription provider, RevenueCat, receives your account identifier and the App Store receipt so the app knows whether your subscription is active.

What we do not collect

4. What never leaves your phone

Stays on the device Voice recordings. AI processing. Crisis detection. Your app passcode.
WhatWhere it lives
Voice note audioYour phone's app storage. The audio file is never uploaded — only a reference to it is synced, so your other devices know a recording existed.
Voice transcriptionApple's on-device speech recognition. We require on-device recognition, so the audio is not sent to Apple's servers for transcription.
Matte's repliesApple's on-device language model. See section 8.
Crisis detectionLocal text matching in the app. Nothing is sent anywhere to decide whether to show you crisis resources.
App passcodeStored in the iOS Keychain as a salted hash. We never see it and it cannot be recovered from what is stored.
Your safety planKept on your device, and included in your end-to-end encrypted iCloud backup so it survives a lost phone — the one moment you would least want to have lost it. It is not sent to our servers, and the backup's key is yours; we cannot read it.
The name of the person you share briefs withKept on your device and never written to your account. If you create a share link, their name is placed inside the encrypted brief, which we host as ciphertext we cannot read — so it reaches our servers only in a form that is unreadable to us, and only because you chose to share.

5. Why we hold it

Under Canadian privacy law we rely on your consent. If you are in the UK or the European Economic Area, our lawful bases under the UK GDPR / GDPR are:

6. Who else touches it

We use a small number of providers. Each is contractually limited to processing data on our instructions. None of them is permitted to use your content for their own purposes.

ProviderWhat they processWhy
Google (Firebase)Account details; your moods, journal entries, photos, thought records and questionnaire scoresSign-in and cloud storage so your journal syncs and survives a lost phone
AppleYour encrypted iCloud backup; App Store payments; on-device AI and speech (no content sent)Backup, purchases and system features
RevenueCatYour account identifier and App Store receiptTo know whether your subscription is active
Supabase & VercelOnly the encrypted blob of a session brief you choose to share, plus its expiryTo host a shared link. See section 7 — they hold ciphertext they cannot read

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.

7. Sharing a brief with a clinician

How the link works The brief is encrypted on your phone. The key is put in the link itself, after the #, and browsers never send that part to a server. We store something we cannot open.

If you create a link to share a session brief:

Anyone you send the link to can read the brief while it is live, and can save or print it. Send it only to someone you mean to give it to.

8. Matte and on-device AI

Matte answers questions about your own journal. It runs on Apple's on-device foundation model. Your entries are not sent to us, to Apple, or to any AI provider for processing, and they are not used to train any model. When the on-device model is unavailable, Matte falls back to text the app composes locally from your entries.

Matte is not a therapist and does not diagnose. It quotes your own words back to you. If something you write suggests you may be in crisis, the app detects that locally and shows you real-world help.

9. Entries the app flags

In plain terms Calmatte reads your entries on your phone to notice writing about self-harm, about hurting someone else, or of a sexual nature. It notices two things: Matte refuses to discuss those subjects, and — for the first two only — it records that an entry on that date looked concerning. Not what you wrote. The date and the category, nothing else.

This is the one place the app forms an opinion about your writing, so here is exactly what it does.

What it looks at, and where

The check runs entirely on your phone, using pattern matching built into the app. No entry is sent anywhere to be assessed, and no AI service is involved. It reads only the words you wrote in an entry.

What Matte does

Matte will not discuss, encourage, rehearse or help you plan self-harm, suicide, harming another person, or sexual activity — and it will not quote entries of yours on those subjects back to you. If what you write suggests you may be in danger, it stops and offers real help instead of a reply. That hand-off costs you nothing from your daily message allowance.

What gets recorded

When an entry clearly describes thoughts of self-harm, or of harming someone else, the app writes down three things: the date, the category, and how sure it is. It never stores the sentence, the entry, or a quote. That record is encrypted and stays on your device — it is not sent to us, not put in your account, and not included in your iCloud backup's readable form.

Sexual content is not recorded at all by default. Matte declines to discuss it, but nothing is written down and nothing is disclosed, unless you deliberately turn that on yourself. Your private life is not a clinical concern, and we are not going to treat it as one.

Who can see it

Only you, unless you choose otherwise. The record exists so that if you create a session brief for a clinician, that brief can carry a short note — "3 entries between 4 and 19 August looked concerning" — so they know to ask. You see that note, in full, on the brief screen before you send anything, and you can turn it off. Nothing about this is silent, and no link is created without you tapping to create it.

What it is not

Turning it off and erasing it

You can stop the brief disclosing anything, and you can clear the record, in Settings. Deleting your account deletes it along with everything else. Editing an entry so it no longer reads that way removes its flag — if you take something back, the app takes it back too.

10. Permissions we ask for

PermissionWhat it is for
MicrophoneRecording a voice note for a journal entry. Only when you start a recording.
Speech recognitionTurning that recording into text, on your device.
Photo libraryAttaching a photo you pick to an entry. We do not read your library otherwise.
Face ID / Touch IDUnlocking the app, if you turn on the app lock. Biometrics are handled by iOS; we never receive them.
NotificationsReminders you set up. Optional.

Declining any of these leaves the rest of the app working.

11. How long we keep it

12. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. Depending on your location you may also have the right to restrict or object to processing, to data portability, and to complain to a regulator — in Canada, the Office of the Privacy Commissioner; in the UK, the ICO; in the EEA, your national authority.

You do not have to ask us for most of it:

To make a request in writing, email support@appe-latte.ca. We will respond within 30 days. We will not charge you or treat you differently for exercising a right.

13. Deleting your account

In the app: Settings → Delete everything. This permanently removes your entries, journal text, photos, thought records, questionnaire results, voice recordings, your iCloud backup of them, any generated reports on the device, and your account itself. Any live share link is revoked.

Any live share link is revoked as part of this. If your device happens to be offline at that moment, the link cannot be reached to kill it — but it still expires on its own within seven days at the latest, and that limit is enforced by the database, not by the app. Deletion is otherwise immediate and cannot be undone. Export first if you want a copy. Purchases are handled by Apple; deleting your account does not cancel a subscription — manage that in your App Store account settings.

14. Security

No system is perfect. If we ever discover a breach affecting your data, we will tell you and the relevant regulator as required by law.

15. Children

Calmatte is not intended for children under 13, and we do not knowingly collect their information. In the EEA and the UK, if you are under 16 you need a parent or guardian's consent to use it. If you believe a child has given us information, email us and we will delete it.

16. Where your data lives

We are in Canada. Our providers process data in facilities that may be in Canada, the United States or the European Union. Where data leaves the UK or EEA, transfers are covered by the providers' Standard Contractual Clauses. The database holding shared briefs is in Canada.

17. Changes to this policy

If we change this policy in a way that materially affects you, we will tell you in the app before it takes effect, and update the date at the top. Continuing to use Calmatte after that means you accept the new version.

18. Contact

Questions, requests, or complaints: support@appe-latte.ca.

Appè Latte, Alberta, Canada.

Calmatte is not a medical device. It does not diagnose, treat, or prevent any condition, and nothing in it is a substitute for professional care. If you are in crisis, contact your local emergency number or a crisis line — the app keeps a list under the First Aid Kit.