Privacy Policy
Effective date: April 22, 2026 · Last updated: August 24, 2026
CalmMessage is an iMessage extension that helps you rewrite emotionally charged text messages before you send them. This policy explains exactly what data we collect, what we never collect, who we share it with, and how long we keep it.
At a glance
WE COLLECT
- Identifiers: Email address or Apple private relay address (via sign-in)
- Usage Data: Rewrite counts, mode & timestamps
- Account Status: Subscription tier
WE DON'T KEEP
- Your message text (discarded right after each rewrite)
- Message history or archives
- Payment or card details
- Advertising or tracking data tied to your identity
We do not sell, rent, or share your personal data with advertisers or third-party marketers.
What we collect and why
Account Identifiers
When you sign in, Firebase Authentication (operated by Google) verifies your identity and provides us with your Firebase user ID and email address. We store these in our database to manage your account and subscription.
If you sign in with Apple and choose Hide My Email, Apple generates a private relay address (ending in @privaterelay.appleid.com) unique to you and this app. We store that relay address in place of your real email — we never see your actual Apple ID email. The relay address functions as your account identifier within CalmMessage and is subject to the same retention and deletion rights as any other email address we store.
Usage Data
We record how many rewrites you have performed, which rewrite mode was used (de-escalate, shorten, or set-boundary), and when each rewrite occurred. This is used to enforce free-tier limits and provide usage summaries.
Message Content
We do not store the text of your messages or their rewrites in our database. Your text is held in memory only long enough to generate a rewrite, and is then discarded. We do not keep any fingerprint, hash, or other derived copy of your message content.
| Data Category | Storage Location | Retention | Reversible? |
|---|---|---|---|
| Firebase UID / Email (or Apple private relay address) | Our database (VPS) | Until account deleted | N/A |
| Rewrite counts / Mode | Our database (VPS) | Until account deleted | N/A |
| Full Message Text | Not stored (processed in memory) | Discarded after rewrite | Not retained |
| Full Rewrite Text | Not stored (returned to your device) | Discarded after rewrite | Not retained |
Diagnostic & Operational Logs
For stability monitoring, our server keeps short-lived operational logs containing usage metadata — such as rewrite counts, which mode was used, response timing, and error traces. These logs do not contain your stored message history. They are kept only on our private VPS, are never transmitted to other parties, and are automatically deleted on a rolling 7-day basis.
Third-party data processors
The following services process your data. We have no control over their own internal data retention policies — please review them directly.
The CalmMessage app contains no advertising networks, analytics SDKs, or tracking pixels, and your in-app activity is never used for advertising. We do plan to add advertising and analytics tools on our marketing site (calmmessage.com) later in 2026, covered in the Cookies section below. Those tools will never have access to your in-app activity, message content, or account data.
Cookies
This section explains whether and how CalmMessage uses cookies and similar tracking technologies, across the CalmMessage iOS app and this website.
The CalmMessage app
- No cookies. No tracking pixels.
- No advertising SDKs. No analytics SDKs.
- Your messages and in-app behavior are never used for advertising, ever.
calmmessage.com
- Today: strictly necessary cookies only (Cloudflare security).
- Coming: limited advertising and analytics cookies, with your consent via a cookie banner.
- Never: cookies that connect to your in-app activity, messages, or account.
We do not sell, rent, or share your personal data with advertisers or third-party marketers.
The CalmMessage iOS app
CalmMessage is a native iOS iMessage extension. It does not use a browser and therefore cannot set browser cookies. Authentication is handled entirely through the Firebase Authentication SDK, which stores a secure token in the iOS Keychain, not a cookie. That token is sent directly to our API over HTTPS and verified server-side on every request.
This website
The marketing site you're reading right now is a separate surface from the app. Today, it loads no analytics, no advertising pixels, and no marketing trackers. The only cookies present are strictly necessary cookies set by our hosting provider (Cloudflare) for security and bot protection. These don't identify you and aren't shared with us in any usable form.
This will change in the coming months. We plan to add advertising and analytics tools to this website (for example, Meta Pixel, Google Analytics, LinkedIn Insight Tag) to measure how people find us. When that happens, this page will be updated first, a cookie consent banner will appear on first visit, declining won't affect your ability to use the site or app, and EU, UK, and California users will receive the additional controls their laws require.
| Technology | Used? | Purpose |
|---|---|---|
| Strictly necessary (security) | Yes | Set by Cloudflare for bot protection. Doesn't identify you. |
| Analytics cookies | Coming, with consent | To measure how people find us (e.g. Google Analytics) |
| Advertising cookies | Coming, with consent | To reach similar audiences with our marketing (e.g. Meta Pixel) |
| iOS Keychain (app only) | iOS only | Firebase stores your auth token here. Not a cookie, not web-accessible. |
Data retention
- Account & Usage Data: Kept for as long as your account is active.
- Diagnostic Logs: Automatically purged every 7 days.
- Account Deletion: All associated records are permanently deleted from our database within 30 days of a deletion request.
Your rights
Access and export
You can request a copy of the data we hold about you (email, tier, usage counts). Requests are fulfilled within 30 days.
Deletion
You may delete your account and all associated data at any time via the "Delete Account" option in the app settings, or by emailing us (see below). We will permanently delete your records within 30 days. Deletion also notifies Firebase and RevenueCat so your account is closed out on their end as well.
Regional Rights (GDPR / CCPA)
Depending on your location, you have the right to access, rectify, erase, and port your data. We process your personal data as necessary to perform our contract with you. This means we use your information to fulfill our obligations, including delivering products or services you have requested, processing payments, and managing your account. This processing is essential for the establishment and performance of our contractual relationship.
We do not "sell" personal information as defined by the CCPA. To exercise any of these rights, contact us below.
Security
All communication between the CalmMessage app and our server is encrypted in transit via HTTPS/TLS (TLS 1.2 or 1.3). The app additionally uses certificate pinning, so it will only connect to our genuine server and rejects any intercepted or tampered connection. Our database is stored on a private VPS with restricted access, and Firebase Authentication tokens are verified server-side on every request.
No system is perfectly secure. In the event of a data breach, we will notify affected users within 72 hours of discovery.
Children's privacy
CalmMessage is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, please contact us and we will delete it promptly.
Changes to this policy
If we make material changes to this policy, we will update the effective date above and notify users via the app or email. Continued use of CalmMessage constitutes acceptance of the updated policy.
Contact us
For privacy questions, data requests, or account deletion:
Email: support@calmmessage.com
We aim to respond to all privacy inquiries within 2 business days.