Privacy
The short version is the whole version.
An app for two people does not need much about you, so we did not build anywhere to put it, and what you write is sealed on your phone before we ever hold it. Last updated 7 October 2026.
We ask for a name
No email, no password, no phone number, no contacts.
Notes are sealed on your phone
We store the envelope and hold no key that opens it.
Leaving deletes it
Disconnect clears the history for both of you. Delete clears the account.
Nobody is watching
No analytics SDK, no ad identifiers, no third-party trackers.
What we hold
Your name, because the other person needs something to see. A user ID we generate. A sign-in token and a private key, both of which live in the iOS Keychain or the Android Keystore on your phone and are never shown to you or printed anywhere by us. The public half of that key, which we publish to the one person you are paired with so their phone can work out the key that opens your notes.
The notes between you and that person, each one sealed before it leaves your phone, with the time it was sent. A push token for each of your devices, so a note can wake the widget. If you send a picture, the current one, sealed the same way. The next picture replaces it.
What the encryption covers
Every note, and every photo or drawing attached to one. The key is derived on both phones from your private key and your partner's public one; it is not sent to us, it is not in the pairing code, and it is not recoverable by anybody, us included, if both phones lose it.
Four things travel beside the sealed note rather than inside it, because a surface that cannot open a note still has to draw something: who sent it, when, which face and ink it was written in, and whether an attached picture is a photo or a drawing along with its size. The words and the picture itself are never among them.
Push notifications carry no message text at all. A push is a trigger; your phone then fetches the sealed note and opens it locally. Nothing you write passes through Apple's or Google's push service in a readable form.
What we never ask for
An email address. A password. A phone number. Your contacts, your location, your photo library beyond the single picture you choose to send, your calendar, or your microphone.
There is no sign-in with Google, Apple or anyone else, because there is nothing to sign in to beyond this one pairing.
Where it lives
On our server, sealed, so the widget on the other phone can fetch it without your phone being awake, and in a small cache on each of your devices so the widget still draws something when the network is gone.
Traffic between the app and the server is encrypted in transit on top of the note's own seal. The server is in the EU. We use Apple's push service and Firebase Cloud Messaging to wake the other device, and because the push carries no text, those two services never handle anything you wrote.
How long it stays
The current note stays until it is replaced. The history sits on your own phones and lasts as long as the pairing does: the last seven days of it on the free plan, all of it on a paid one. A picture is kept only while it is the current one.
When either of you disconnects, the shared history is deleted for both of you at once. Neither person needs the other's agreement, and there is no copy kept for recovery.
Deleting things
Disconnect, in Settings, ends the pairing and deletes the shared history for both of you. Both accounts survive it. Either person can do it, and the app lands them back on the Connect screen.
Delete my account, also in Settings, is the larger of the two: the account itself, its sessions, its devices and the shared history, deleted everywhere, and the person you were paired with is disconnected by it. It asks twice. There is no sign-in and no backup, so nothing is kept for recovery and we cannot restore an account once it is gone.
If you no longer have the phone the account is on, write to us at hello@usapp.co and say so. We do it by hand, within thirty days, and we tell you when it is done.
Who can see a note
The person you are paired with. That is the list, and it is not a policy we are keeping. It is what the encryption leaves us able to do.
We do not read your notes, sell them, show you advertising against them, or use them to train anything, and we could not start doing so without the key your phone keeps. If a court ever compelled us to hand something over we would hand over sealed envelopes, and we would tell you unless we were legally forbidden from doing so.
Tracking and analytics
Crash reports, so we learn when the app falls over, and nothing else. No analytics SDK, no advertising identifier, no attribution network, no session recording, no pixel on this website.
Children
Us is not built for children and we do not knowingly hold data from anyone under thirteen. If you believe a child has an account, tell us and we will remove it.
When this page changes
We will date the change at the top and, if it is a change that matters, say so in the app before it takes effect rather than after.
Asking us things
Write to hello@usapp.co. If your question is really about how the app behaves rather than what we keep, the questions page is probably faster.