Contents
1. Who we are
This Privacy Policy describes how the Aperture Protocol mobile application ("Aperture Protocol," "the app," "we," "us," or "our") handles information. Aperture Protocol is an independently published wellness and reflection app for iPhone. It is offered for personal use only and is not a medical device or a healthcare service.
2. What we collect
We do not collect any personal data. Aperture Protocol has no user accounts, no login, and no backend servers operated by us. We do not run analytics, advertising, crash-reporting, or tracking software of any kind, and the app performs no background network transmission of your information. We cannot see your sessions, your logs, your heart-rate readings, or anything else you enter, because none of it ever reaches us.
Because the app does not transmit data off your device or link any data to your identity, its App Store privacy label is "Data Not Collected."
3. Information stored on your device
The app saves your practice information in a private database on your device so the experience works and your progress is remembered. This may include:
- Session records (which day of the protocol, durations, a computed coherence value, and an estimated model value);
- Logs you choose to create, such as intrusion entries (type, an intensity rating, a timestamp, and any optional note you write);
- Your preferences (haptics and audio toggles, baseline selection);
- The status of the in-app environmental checklist and any reframe scripts you save.
This information is stored locally using the device's standard app storage. It is not uploaded to us or to any third party. If you delete the app, this data is removed from your device by the operating system. You can also clear it at any time using the in-app reset.
4. Device permissions we request
To provide its features, the app may ask your permission to use certain device capabilities. You can grant or deny each of these, and change them later in your system settings. Denying a permission only disables the related feature.
- Health (Apple HealthKit) — used optionally, with read-only access, to read heart rate from your paired Apple Watch as the live biofeedback signal during a session. Heart rate is the only Health data type the app requests. See section 5 for full details.
- Camera (optional pulse sensor) — used optionally, on iPhone, to read your heart rate from your fingertip when you don't have an Apple Watch: you rest a finger over the rear lens during a session and the app derives a live pulse from it. The sensor runs only when you start it yourself — it needs the flash, so the camera never turns on quietly or in the background. Frames are analyzed on your device for brightness only, and no photo or video is ever recorded, saved, or transmitted. See section 5 for full details.
The app requests no other device permissions — no Bluetooth, no microphone, no location, and no notifications.
5. Health & heart-rate data
On iOS, you may optionally allow the app to read your heart rate from a paired Apple Watch through Apple HealthKit, to use as a biofeedback signal during a session. When you use this feature:
- Access is read-only: heart rate is the only Health data type the app requests, and the app never writes anything to Apple Health;
- Heart-rate readings are processed entirely on your device to compute a live coherence value during your session — raw readings are never stored; the only thing saved is the derived per-session coherence score, kept in the app’s local database;
- If you decline Health access, or no recent Apple Watch data is available, no health data is read at all — the session automatically uses a clearly labeled simulated signal instead, unless you choose to start the optional camera pulse sensor described below;
- We do not use any health data for advertising or marketing, we do not sell it, and we do not share it with any third party;
- Health data obtained through HealthKit is never transmitted off your device by us.
You can review and revoke the app's Health permissions at any time in the iOS Settings → Privacy & Security → Health screen, or within the Health app.
The camera pulse sensor. On iPhone, you can instead derive a live heart rate from your fingertip, without an Apple Watch, by resting a finger over the rear camera during a session. When you use this feature:
- It runs only when you start it, from within a session. The sensor lights the camera flash to read your finger, so it cannot run in the background or without your knowledge;
- The app looks at the camera frames for average brightness only — specifically the red channel of a small patch at the centre of the frame — which is what lets it see the pulse in your fingertip. It is not doing image recognition, and it is not looking at anything else in view;
- No photo or video is ever recorded, saved, or transmitted. Frames are examined as they arrive and discarded; nothing is written to your photo library, to the app's storage, or to us;
- As with the Apple Watch signal, the only thing saved is the derived per-session coherence score, kept in the app's local database;
- Heart rate derived this way is not written to Apple Health, and never leaves your device;
- You can revoke camera access at any time in the iOS Settings → Privacy & Security → Camera screen. Denying it only disables the pulse sensor.
6. Notifications
The app currently sends no notifications and does not request notification permission. We do not operate a push-notification service. If a future update adds an optional practice reminder, it will be scheduled locally on your device and will remain entirely under your control.
7. Exporting & sharing
The current version of the app has no export or sharing feature: your practice data stays in the app’s local database and is never sent anywhere. Deleting the app deletes all of its data. If a future update adds an export, it will only ever run when you actively choose it, using your device’s standard share sheet.
8. Third parties
We do not share data with third parties because we do not collect it. The app does not embed third-party analytics, advertising, or tracking SDKs. The only third parties inherently involved are:
- Apple, as the App Store through which you download the app and which may collect its own information under its privacy policy. The current version does not ship on other stores.
The app also includes a privacy manifest declaring its use of certain standard, "required-reason" device APIs (such as reading available disk space and file timestamps) used purely for normal on-device operation — not for tracking.
9. Children
Aperture Protocol is intended for a general adult audience and is not directed to children. We do not knowingly collect personal information from children (and, in fact, we do not collect personal information from anyone). The app's themes are best suited to mature users; please review the App Store age rating before allowing a minor to use it.
10. Your choices & rights
Because your data lives only on your device, you are in direct control of it at all times. You can:
- Use the in-app reset to erase your stored practice data;
- Delete the app to remove all of its locally stored data from your device;
- Grant or revoke the Health permission at any time in your system settings.
We do not hold any copy of your data, so there is nothing for us to access, correct, or delete on your behalf. Depending on where you live (for example, under the GDPR or the CCPA/CPRA), you may have additional rights regarding personal data — but since we neither collect nor process your personal data, these rights are satisfied by the on-device, no-collection design described above.
11. Security & retention
Your information is protected by your device's own security model and stays in the app's private storage area. We retain nothing on our side. Your data remains on your device for as long as the app is installed, or until you reset it or delete the app. As with any locally stored information, we recommend using a device passcode and keeping your operating system up to date.
12. Changes to this policy
We may update this Privacy Policy from time to time — for example, if we add a feature. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here before they take effect in a new app version.
13. Contact
Questions about this policy or your privacy? Reach us at [email protected]. We're a small independent project and will respond as soon as we can.