OffMemory ("we", "the App") is built on a single principle: your notes are none of our business. This Privacy Policy explains, in plain language, exactly what the App does and does not do with your information.
1. The Short Version
- There is no cloud and no server behind the App. Your entries are encrypted on your device, and there is nowhere on our side for them to go.
- We never collect, transmit, store, share or sell any of your personal data, notes, images, mood marks, passwords or device identifiers.
- There is no sign-up step: no email address, no phone number, no registration form, no analytics, no crash reporting and no advertising SDK.
- Your note titles, bodies and images are encrypted with AES-256 and stored only on your own device. For local search, folder names and tag names are not encrypted (they are kept in plain text on your device); they likewise never leave your device.
- You can export an encrypted backup and restore it on a new device or after reinstalling. That file is created by you, kept by you, and stays encrypted with your password — we never receive it.
- You may also choose to export plain, unencrypted files: a .zip archive of readable Markdown plus images, a plain .txt file, or a single note as .md. These are created only when you explicitly select and confirm them, and anyone holding them can read them directly.
- The App's only network activity is Apple's in-app purchase channel, which is required to process the one-time unlock. Apple handles that transaction entirely; we receive no personal data from it.
2. Information We Collect
None. The App does not collect any information whatsoever — not personal information, not usage data, not device data, not diagnostics. Because we operate no backend at all, there is no server of ours that could receive such data even if we wanted to collect it.
3. How Your Data Is Stored
- Location: All notes, folders, tags, mood marks, favourites and images are stored in a local database inside the App's private sandbox on your device.
- Encryption: Note titles, note bodies and images are encrypted using the AES-256-CBC algorithm before they are written to disk. Your master encryption key is derived from your password using PBKDF2-HMAC-SHA256 and is stored in the system Keychain.
- No server, ever: We operate no backend at all. There is no sign-in, no sync service and no place where your data could be stored on our side.
- Automatic device backups: Any backup made by your operating system (for example, an iTunes or iCloud device backup) is created and controlled entirely by Apple. Such a backup may contain the App's encrypted database files. Those files remain encrypted, and your password and encryption keys are never included.
- System search (Spotlight, off by default): you can turn on "Search in Spotlight" under Settings → Security. When it is on, note titles are written into the iOS system search index as entries, so you can find them in Spotlight and open the note directly. Bodies, images, moods, tag names and folder names are never written to that index; notes marked as locked are not indexed; and these titles are unreadable while the device is locked (the index uses iOS complete file protection). Turning the switch off immediately clears whatever was already written.
4. Backups, Exports and Moving to a New Device
Version 1.1.0 lets you export an encrypted backup and import it on another iPhone or iPad, or after reinstalling the App.
- What the file is: a single archive containing your encrypted notes, images and mood data, produced on your device.
- Optional backup passphrase: you may protect the archive with a backup passphrase. If you do, an additional copy of your master key is wrapped with a key derived from that passphrase (PBKDF2 + AES-256-CBC), which is what allows the same archive to be restored on a different device. We do not store the passphrase and cannot recover it.
- Where it goes: wherever you choose — the Files app, iCloud Drive, an external drive, or AirDrop. That choice is entirely yours. The archive remains encrypted throughout and is never uploaded to us or to any third party by the App.
- Your responsibility: a backup file is only as safe as the place you keep it and the passphrase you choose. If you lose the passphrase and the original device, the archive cannot be opened.
Plain exports (optional, unencrypted): besides the encrypted backup, the App can also produce two plain export formats — a .zip archive of readable Markdown plus images, and a plain .txt file; an individual note can also be exported on its own as a .md file. Plain files are not protected by the App's encryption, anyone who obtains them can read them directly, and the App never chooses a plain format for you: one is created only after you explicitly select and confirm it. Please store or destroy these exports with the same care you would give any unencrypted file.
5. Passwords, Recovery and Passphrases — Please Read Carefully
Your password is never transmitted, never stored on any server, and cannot be recovered by us. We do not operate any server that could hold it. This is a deliberate design decision, and it is the reason true privacy is possible.
- If you forget your password, we cannot reset it for you, and we cannot recover your notes.
- The App offers security questions as a recovery mechanism. If you configure them, an additional encrypted copy of your master key is created locally. Answering your security questions correctly lets you set a new password while keeping your data.
- If you forget both your password and your security answers, the only remaining option is to erase all local data and start over. This erasure is permanent and irreversible.
6. Biometric Unlock (Face ID / Touch ID)
If you enable biometric unlock, the App asks iOS to store a credential in the device Keychain that can be released after a successful Face ID or Touch ID match. Biometric authentication is performed entirely on your device by the operating system. We never receive your face or fingerprint data, and no biometric information ever leaves your device.
7. Photos and Files
The App requests access to your photo library only in two situations, and only after you explicitly grant permission:
- Inserting an image: the selected image is encrypted and copied into the App's private storage.
- Exporting a backup or a plain export: the encrypted backup file, or a plain export file you explicitly chose (
.zip/.txt), is written to the location you choose.
You may deny or revoke these permissions at any time in iOS Settings. Denying them does not affect any other feature.
8. Purchases
OffMemory offers a single one-time purchase that permanently unlocks writing. There is no subscription, no auto-renewal, no trial period and no advertising. All payment processing is handled by Apple through the App Store. We do not receive your name, email address, payment card number or any other personal information from Apple in connection with your purchase.
9. Third-Party Services and SDKs
The App contains no third-party analytics, advertising, crash-reporting, social or attribution SDKs. The only third-party component that makes any network request at all is Apple's StoreKit framework, which exists solely to process the one-time purchase described above.
10. Children's Privacy
The App is not directed to children under the age of 13 and does not knowingly collect any information from anyone. Because the App collects no data at all, no information from any user — including children — is ever obtained, stored or shared.
11. Data Retention and Deletion
Because we hold no data, there is nothing for us to retain or delete. You are in complete control of your local data at all times:
- Deleting a note moves it to the in-app Trash, where it is permanently deleted automatically after the retention period stated in the App (currently 7 days).
- Using "Erase All Data" in Settings permanently destroys all local notes, folders, tags, mood marks, images, backups held inside the App and encryption keys.
- Uninstalling the App removes all of its local data from your device. Any encrypted backup file you exported elsewhere remains wherever you saved it, and remains your responsibility.
- There is no cap on the number of entries you can store — the only limit is your device's free space. An encrypted backup you export can later be imported after reinstalling the App or on a new device, restoring your notes, images and moods.
These actions are irreversible.
12. Security
We protect your data with the following measures, all of which run locally on your device: AES-256-CBC encryption of note titles, bodies and images; PBKDF2-HMAC-SHA256 key derivation; storage of keys in the iOS Keychain; mandatory password unlock with brute-force protection (progressive lockout after repeated failures); optional Face ID / Touch ID; automatic re-lock when the App enters the background; an optional screenshot-blocking mode on note detail pages; and PBKDF2 + AES-256-CBC wrapping of the master key for passphrase-protected restore on a new device. No method of electronic storage is perfectly secure, and we cannot guarantee absolute security; however, we operate no server and cannot read your local data or an encrypted backup that you keep yourself.
13. This Website
This website is a static product page. It sets no cookies, runs no analytics, advertising or tracking scripts, and loads no third-party resources — all fonts and images are served from this domain. The only information stored in your browser is your language preference, which is kept in localStorage and never sent anywhere.
14. Changes to This Policy
If we update this Privacy Policy, the revised version will be posted on this page and included in the next release of the App, and the "Last updated" date above will change. Continued use of the App after an update constitutes acceptance of the revised policy.
15. Contact
If you have questions about this Privacy Policy, please reach us through the support information listed on this App's App Store page.
Remember: your password, security answers and backup passphrase exist only in your own memory. Guard them carefully, especially any passphrase needed for cross-device restore. If every recovery path is lost, your data is gone permanently — there is no exception.
密匣笔记(以下简称"本应用")建立在一个唯一的原则之上:你的笔记与我们无关。 本隐私政策以通俗语言说明本应用对你的信息做了什么、以及绝不做什么。
一、简短版
- 我们没有任何服务端:没有云端,也没有服务器。你的内容只在本机加密存放。
- 我们绝不收集、传输、存储、共享或出售你的任何个人数据、笔记、图片、心情标记、密码或设备标识。
- App 里没有「注册」这一步:不需要邮箱、不需要手机号,也没有任何统计分析、崩溃上报或广告 SDK。
- 你写下的笔记标题、正文与图片均以 AES-256 加密后,仅保存在你自己的设备上。为便于本地检索,文件夹名与标签名不参与加密(以明文存储在你的设备内),但它们同样从不离开你的设备。
- 你可以导出加密备份,并在新设备上或重装应用后恢复。该文件由你创建、由你保管,全程以你的密码加密 —— 我们不会收到它。
- 你还可以选择导出不受加密保护的明文文件:内含可读 Markdown 与图片的 .zip 归档、纯文本 .txt,单篇笔记还可导出为 .md。此类文件仅在你主动选择并确认后才会生成,任何拿到它的人都能直接阅读。
- 本应用唯一的联网动作是 Apple 应用内购买通道,仅用于处理一次性买断。该交易完全由 Apple 处理,我们不会从中获取任何个人信息。
二、我们收集的信息
不收集任何信息。 本应用不收集任何形式的信息,包括个人信息、使用行为、设备信息、诊断数据等。由于我们没有任何服务端,即便我们想要收集,也没有任何一台属于我们的服务器能够接收这些数据。
三、你的数据如何存储
- 位置: 全部笔记、文件夹、标签、心情标记、收藏与图片均保存在本应用在设备上的私有沙盒数据库中。
- 加密: 笔记标题、正文与图片在写入磁盘前均使用 AES-256-CBC 算法加密。主加密密钥由你的密码经 PBKDF2-HMAC-SHA256 派生,并存放于系统钥匙串(Keychain)中。
- 没有服务器: 我们不运营任何后端。没有登录、没有同步服务,也就不存在你的数据被存放在我们这一侧的可能。
- 系统级设备备份: 由操作系统发起的整机备份(例如 iTunes 或 iCloud 设备备份)完全由 Apple 创建与控制。此类备份可能包含本应用的加密数据库文件;这些文件始终保持加密状态,且其中绝不包含你的密码与密钥。
- 系统搜索(Spotlight,默认关闭): 你可以在「设置 → 安全」中主动开启「在系统搜索中查找」。开启后,笔记的标题会以索引形式存入 iOS 系统搜索数据库,因此你可以在 Spotlight 中搜到并直接打开对应笔记。正文、图片、心情、标签与文件夹名绝不会写入该索引;标记为锁定的笔记不会被索引;这些标题在设备锁屏时不可读(索引使用 iOS 的完整文件保护级别)。关闭该开关会立即清空已写入的索引。
四、备份、导出与更换设备
1.1.0 版起,你可以导出加密备份,并在另一台 iPhone 或 iPad 上、或重装应用后导入。
- 这个文件是什么: 一个在你自己设备上生成的压缩包,内含加密后的笔记、图片与心情数据。
- 可选的备份口令: 你可以为这份备份设置备份口令。设置后,系统会额外生成一份由该口令派生密钥(PBKDF2 + AES-256-CBC)封装的主密钥副本,这正是同一份备份能够恢复到另一台设备的原因。我们不保存该口令,也无法帮你找回。
- 保存在哪里: 完全由你决定 —— 「文件」App、iCloud 云盘、移动硬盘,或用隔空投送传走。整份备份全程保持加密,本应用绝不会将它上传给我们或任何第三方。
- 你的责任: 一份备份的安全程度取决于你把它放在哪里、以及你设置了什么口令。如果口令与原设备同时遗失,这份备份将无法打开。
明文导出(可选,不受加密保护): 除加密备份外,本应用还提供两种明文导出格式 —— 内含可读 Markdown 与图片的 .zip 归档,以及纯文本 .txt;单篇笔记还可单独导出为 .md 文件。明文文件不受本应用加密保护,任何拿到它的人都能直接阅读;本应用绝不会替你选择明文格式,只有在你主动选择并确认后才会生成。请像对待任何未加密文件一样妥善保管或销毁这些导出物。
五、密码、找回与备份口令 —— 请务必仔细阅读
你的密码从不被传输、从不被存放在任何服务器上,我们也无法帮你找回。 我们不运营任何可能持有密码的服务器。这是经过深思熟虑的设计抉择,也正是真正隐私得以成立的原因。
- 如果你忘记密码,我们无法为你重置,也无法帮你恢复笔记。
- 本应用提供密保问题作为找回机制。设置密保后,系统会在本地额外生成一份由密保答案加密的主密钥副本。正确回答密保问题即可在保留全部数据的前提下设置新密码。
- 若密码与密保答案双双遗忘,唯一剩下的选择是清空全部本地数据并重新开始。该清空操作永久且不可逆。
六、生物识别解锁(面容 ID / 触控 ID)
若你开启生物识别解锁,本应用会请求 iOS 在设备钥匙串中存放一枚凭证,该凭证仅在面容 ID 或触控 ID 验证通过后释放。生物识别验证完全由操作系统在你的设备上完成。我们不会收到你的人脸或指纹数据,任何生物特征信息都不会离开你的设备。
七、相册与文件
本应用仅在以下两种情形下申请相册权限,且必须获得你的明确授权:
- 插入图片: 所选图片经加密后复制到本应用的私有存储空间。
- 导出备份或明文导出: 将加密备份文件、或你主动选择的明文导出文件(
.zip/.txt)写入你选择的位置。
你可以随时在 iOS 设置中拒绝或撤销这些权限,拒绝不会影响其他任何功能。
八、购买
密匣笔记仅提供一次性买断,永久解锁书写。不存在订阅、自动续期、试用,也不含任何广告。所有支付均由 Apple 通过 App Store 处理。对于你的购买行为,我们不会从 Apple 处获得你的姓名、邮箱、银行卡号或任何其他个人信息。
九、第三方服务与 SDK
本应用不含任何第三方统计分析、广告、崩溃上报、社交或归因 SDK。唯一会发起网络请求的第三方组件是 Apple 的 StoreKit 框架,其存在目的仅为处理上文所述的一次性购买。
十、儿童隐私
本应用并非面向 13 岁以下儿童,也不会有意收集任何人的任何信息。由于本应用完全不收集数据,因此不存在获取、存储或共享任何用户信息(包括儿童信息)的可能。
十一、数据保留与删除
由于我们不持有任何数据,因此不存在需要我们保留或删除的内容。你始终完全掌控自己的本地数据:
- 删除笔记会先移入应用内回收站,并在应用内标注的保留期限届满后自动彻底删除(目前为 7 天)。
- 在设置中使用"清空全部数据"将永久销毁本地全部笔记、文件夹、标签、心情标记、图片、应用内保留的备份与加密密钥。
- 卸载本应用将移除其在本设备上的全部数据。你此前导出到别处的加密备份文件仍保留在你保存的位置,并由你自行负责。
- 本应用对你保存的笔记篇数不设上限,唯一限制是设备的可用空间。你导出的加密备份,可在卸载重装后或新设备上重新导入,完整恢复笔记、图片与心情数据。
上述操作均不可撤销。
十二、安全措施
我们通过以下全部在设备本地执行的措施保护你的数据:笔记标题、正文与图片的 AES-256-CBC 加密;PBKDF2-HMAC-SHA256 密钥派生;密钥存放于 iOS 钥匙串;强制密码解锁并具备暴力破解防护(连续失败后延长锁定时间);可选的面容 ID / 触控 ID;应用进入后台自动重新锁定;笔记详情页可选的防截屏模式;以及使用备份口令对新设备恢复密钥进行的 PBKDF2 + AES-256-CBC 封装。任何电子存储方式都无法做到绝对安全,我们也无法作出绝对安全的保证;但本应用没有服务器,无法读取你的本地数据或你自行保存的加密备份。
十三、关于本网站
本网站是一个纯静态的产品页面:不设置任何 Cookie,不运行任何统计分析、广告或追踪脚本,也不加载任何第三方资源 —— 全部字体与图片均由本站域名提供。浏览器中唯一保存的信息是你的语言偏好,存放在 localStorage 中,且不会发送到任何地方。
十四、本政策的变更
若我们更新本隐私政策,修订后的版本将发布于本页面并随下一次应用发布一同提供,同时更新上方的"最近更新"日期。更新后继续使用本应用,即视为接受修订后的政策。
十五、联系方式
如对本隐私政策有任何疑问,可通过本应用在 App Store 页面上列出的支持信息与我们联系。
请牢记:你的密码、密保答案与备份口令只存在于你自己的记忆中。务必妥善保管,尤其是需要跨设备恢复的备份口令。一旦遗失且没有其他可用恢复路径,数据将永久丢失 —— 没有任何例外。