Privacy Policy
Aeon runs entirely on your iPhone. There is no account, no Aeon server, and no cloud sync. Every frame, scene, film and caption you make stays in the app's own storage on your device.
Two things do leave the device: anonymous usage counts and anonymous crash reports. Both are on when you install the app, both are disclosed when you first open it, and either can be switched off at any time in Settings › Photo & Data. Neither ever includes your photos, videos, captions, or your name.
Aeon does not track you across other apps or websites, does not use the advertising identifier, and shows no ads.
Who this policy is from
Aeon is an independent iPhone app made by Vaishak Kaippanchery. This policy covers the Aeon iOS app and this website. Questions about anything on this page can go to vaishak.kaippanchery@gmail.com.
What stays on your device
All of the content you create in Aeon is written to the app's private storage on your iPhone and is never uploaded anywhere by Aeon.
| What | Where it lives | Does it leave the device? |
|---|---|---|
| Frames (your daily photo and its details) | The app's private storage | No, unless you export it or save it to Photos |
| Scenes (short videos and their captions) | The app's private storage | No, unless you export it or save it to Photos |
| Films and time-lapses you export | The app's private storage | No, unless you share it or save it to Photos |
| Your settings (reminders, framing, the privacy toggles) | Standard iOS app preferences | No |
| Home Screen widget data (streaks, today's capture times, the last seven days) | A protected file shared between the app and its widget | No |
Backups and file protection
None of your media is included in an iCloud or iTunes backup. The folders holding your frames, scenes and exports are marked as excluded from backup and are written with iOS file protection, so they are readable only while your device is unlocked.
The widget data is also excluded from backup, and it is stored as a protected file rather than in ordinary shared settings, which are backed up. Its protection level is deliberately one step weaker than your media: it has to stay readable while the phone is locked, or the widget could not refresh after midnight. It holds only your streak counts, today's capture times and which of the last seven days you captured on, never any image.
Your app settings are ordinary iOS preferences and are included in a device backup, as with any app.
Deleting your data
Settings › Photo & Data › Delete All Data permanently removes every frame, scene and exported film on that device, and starts the introduction over. Records of what you captured are cleared with it, including which milestones you have already been congratulated on and your display name.
Your preferences are deliberately kept, on the reasoning that deleting your photos is not a request to reconfigure the app. Deleting also cannot reach anything you had already saved to your Photo Library or shared out of the app, because those copies are no longer Aeon's to manage.
Deleting the app itself removes the app's storage and everything in it.
Anonymous usage data
Why: to answer one question, how many people use each main feature, so the app can be improved without anyone reading your diary.
Who processes it: TelemetryDeck, a company based in Germany, on servers in the European Union.
Exactly what is sent
Aeon sends four events and nothing else. There is no free-form text channel, so no message can carry anything not listed here.
| Event | When it happens | What comes with it |
|---|---|---|
| A frame was saved | You successfully save a frame | Whether it came from the camera or your library |
| A time-lapse was exported | A time-lapse finishes encoding | The frame rate you chose, and a rough size band for how many days it covered |
| A scene was saved | You successfully save a scene | Front or back camera, and whether it has sound |
| A film was made | A film finishes encoding | Whether it covered a single day, and a rough size band for how many scenes it used |
Counts are deliberately blurred before they leave your device. Instead of an exact number, Aeon sends a band: 0, 1, 2–5, 6–15, or 16+. An exact count could help single someone out; a band cannot.
Failed and cancelled exports send nothing at all.
What the analytics service adds on its own
Alongside those events, TelemetryDeck's software may attach technical context designed not to identify you:
- A scrambled, one-way installation identifier. It is not your Apple ID, email or name, and it cannot be reversed back to you.
- A session identifier
- The app version and build
- Your iOS version, device model, and language or region
- Whether the app came from the App Store or TestFlight
It also records basic lifecycle events, such as a session starting or a new installation being detected.
Crash and error reports
Why: to find out which step broke when a capture, an alignment or an export fails, including quiet failures such as face detection giving up and falling back to a simple centre crop.
Who processes it: Sentry.
Exactly what is sent
- Which step failed, chosen from a fixed list, such as export setup, loading a frame, encoding, or configuring the camera
- The same blurred count bands described above
- Your device model, iOS version and app version
- A short trail of what the app was doing beforehand, drawn from a fixed list of app events: an export started or finished, a capture started, an alignment succeeded or fell back, the app moved to the foreground or background
- Crash reports, if the app terminates unexpectedly
That activity trail is worth explaining, because it is the part most likely to leak something by accident. Crash reporting tools normally record it automatically, and in doing so they copy screen titles and interface labels into the report. In Aeon those labels contain identifiers for individual frames, and one screen title shows an exact lifetime day count. So the automatic version is switched off entirely and replaced with a fixed list of app events that carry no personal values.
What is never included in either channel
- Photos, videos, audio, thumbnails or screenshots
- Captions, titles, or anything else you typed
- File names, storage paths, or the internal identifiers of your media
- The exact dates or times of your captures
- Pictures of the app's screens, or a copy of its interface layout
- Location or GPS data. Aeon never asks for location: the changing sky in the app is calculated from the calendar date, not from where you are
- Contacts, health data, or anything else from elsewhere on your phone
- The advertising identifier, or any cross-app or cross-site tracking data
- Your name, email or Apple ID. Aeon has no accounts, so it has nothing to attach them to
Your controls
Settings › Photo & Data holds two independent switches. Both start on, and both are explained on a screen you pass through when you first open the app.
Share anonymous usage stats
Turning it off stops all usage data immediately, including the automatic lifecycle events, for the rest of that session and every session afterwards. Nothing further is sent unless you turn it back on.
Share crash reports
Turning it off stops crash and error reporting immediately, and anything still waiting to be sent is discarded rather than delivered.
Turning either switch off stops further collection from your device. It does not retroactively delete aggregate data already received, because that data is anonymous and is not tied to any identity that could be used to find and remove your share of it. This is a real limit, and it is the honest consequence of collecting nothing that identifies you in the first place.
How long data is kept
Content on your device is kept until you delete it, either individually, through Delete All Data, or by removing the app.
Anonymous usage and crash data is retained by TelemetryDeck and Sentry under their own retention schedules, in aggregate form, for product and stability analysis. Because none of it is linked to an identity, there is no per-person record to look up, export or erase.
Permissions Aeon may ask for
Each is requested at the moment you first need it, after the app has explained why, and each is optional.
| Permission | What it is for |
|---|---|
| Camera | Taking frames and recording scenes |
| Microphone | Optional sound on scenes |
| Photo Library (add only) | Saving or sharing your work to Photos. Aeon can add photos, and cannot read your library |
| Notifications | Optional reminders, streak alerts, milestones and recaps |
Aeon does not ask for permission to track you, because it does not track you.
Children
Aeon is not directed at children under 13, and it does not knowingly collect personal information from them. It has no accounts, no sign-in, no messaging, no user-to-user features and no advertising, so there is nothing for a child to publish and no way for anyone to contact them through the app. Everything a child created in Aeon would stay on that device.
Who your data is shared with
Aeon does not sell your data, and it has nothing to sell: there is no personal data collected to trade. Your content is never shared with anyone, because it never leaves your phone unless you export it yourself.
The only two third parties involved are the anonymous analytics and crash reporting services named above, acting as processors on Aeon's behalf. Both can be switched off.
Your rights
Depending on where you live, you may have rights to access, correct, export or erase personal data held about you, and to object to its processing.
In Aeon's case those rights are mostly satisfied by the design rather than by a request process. Your personal content is already in your sole possession on your own device, so you can view, export and delete it yourself at any time without asking. For the anonymous usage and crash data, there is no identifier that links any of it to you, so there is no individual record that could be retrieved or deleted on request. You can stop that collection at any time using the switches described above.
If you believe personal data about you is being handled incorrectly, write to vaishak.kaippanchery@gmail.com.
Security
Your content is stored inside the app's private storage, which iOS isolates from other apps. The media folders use iOS file protection, so they can only be read while the device is unlocked, and they are excluded from device backups. Anything Aeon sends over the network uses standard encrypted HTTPS connections. Aeon uses no custom cryptography.
Changes to this policy
If this policy changes in a way that affects what leaves your device, the date at the top will be updated and the change will be described in the app's release notes. Material changes will be surfaced in the app rather than only posted here.
Contact
Aeon is made by Vaishak Kaippanchery. For any question about privacy, or to exercise a right described above, email vaishak.kaippanchery@gmail.com.