Privacy Policy

August 6, 2026

OffPal is an iPhone bedtime wind-down companion. This policy explains what information the OffPal iOS app handles, where it goes, and the choices you have. The app is local-first: the core experience works without an account, without a backend, and without syncing your data to a server.

Local data stays on your device

OffPal stores your bedtime, preferences, wind-down plans, session and morning-feedback history, resolved stage copy, and HealthKit-derived summaries in SwiftData on your device. This data is not uploaded to OffPal and is not stored in iCloud (the local database has CloudKit disabled). A small local App Group container holds projection state used by notifications and the Live Activity; it also stays on your device. Uninstalling the app removes this local data.

HealthKit (optional, read-only)

HealthKit access is optional. If you allow it, OffPal reads Sleep Analysis only — it never writes HealthKit data. Sleep Analysis is used on-device for a morning recap and a conservative completion credit. It is never uploaded, never stored in iCloud, never sent to the AI feature, and never used for advertising, marketing, or data mining. Denying or revoking access does not block the wind-down flow. You can manage or revoke access at any time in iOS Settings → Health.

AI Copy (optional, off by default)

AI Copy is off by default and only starts after you review a disclosure and turn it on in Settings. When enabled, the app sends a minimized routine context to generate short stage copy: phase, tone, character mood, locale, delay and streak counts, coarse time-to-bedtime, weekday, coarse recent wind-down outcomes, your preferred name if you provided one, and a few style examples.

The request path is: OffPal app → OffPal Egress (a Vercel-hosted function in the United States) → DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd., People's Republic of China). Prompts and outputs therefore transit to China and are processed under PRC law. DeepSeek's terms do not specify retention, training use, processing region, or subprocessors, so we disclose the worst case: prompt and output content may be retained and may be used for training.

OffPal never sends HealthKit or Screen Time data, exact app names, browsing content, location, advertising identifiers, contacts, or account data. The Egress keeps prompt and output bytes only for the duration of the request and does not log request or response bodies. Vercel platform logs retain request metadata, including IP addresses, for up to 30 days.

You can turn AI Copy off at any time in Settings; turning it off stops new requests.

App Attest security records

To protect each AI request, the app uses Apple's App Attest. The Egress database (Supabase, United States) stores a pseudonymous record per app installation: a random per-install ID (not a hardware ID), the App Attest key ID and public key, a monotonic assertion counter, validation category, bundle version, a hashed authorization, timestamps, and an optional disabled state. One-time challenge rows store hashes and expiry/consumption state, never raw bytes. These records are not accounts or profiles and are not joined to AI content.

Cleanup is best-effort: consumed challenges become eligible for cleanup after 24 hours, disabled device records after 30 days, and inactive device records after 90 days. Cleanup runs when a subsequent challenge is created; this is not a guaranteed wall-clock deletion for an idle service.

What the app collects (App Privacy)

The App Store's App Privacy label for OffPal reflects this policy:

  • Device ID — collected, linked to the installation, not used for tracking — App Functionality (the App Attest device record described above).
  • Other Diagnostic Data — collected, linked, not used for tracking — App Functionality (request IDs, status, latency, error categories, attestation and token fingerprints).
  • Name — collected, linked, not used for tracking — Product Personalization (your preferred name, only when you provide it and AI Copy is enabled).
  • Product Interaction — collected, linked, not used for tracking — Product Personalization (delay and streak counts and recent wind-down outcomes used in AI Copy prompts when enabled).
  • Other User Content — collected, linked, not used for tracking — App Functionality (prompt and output content if retained by the provider or platform, as described above).
  • Health & Fitness — not collected (processing happens only on your device).

Tracking

Tracking: No. OffPal does not use advertising identifiers, does not show ads, does not sell data, and does not share data with data brokers.

Notifications and Live Activity

Notifications are scheduled locally on your device. The Live Activity renders a local projection of your wind-down session; nothing is sent to a server.

Screen Time and app blocking

Screen Time, DeviceActivity, and App Blocking are not included in the current version (v0.1).

Your choices and deletion

  • AI Copy: turn it off in Settings to stop new requests.
  • Preferred name: clear it in Settings at any time.
  • HealthKit: manage or revoke access in iOS Settings → Health.
  • Server-side records: to request deletion of App Attest device records or diagnostic metadata held by the Egress, email lukemyself.app@gmail.com.
  • Uninstalling the app removes its local data.

Contact

Questions or privacy requests: lukemyself.app@gmail.com. Support page: https://www.offpal.top.

OffPal is a wind-down companion, not a medical device. It does not diagnose, treat, or guarantee sleep.