← SimplePosts

Privacy Policy

Last updated: 3 September 2026

SimplePosts is a messaging app where you share notes with the people that matter most. Your privacy matters to us. Here's how it works.

Our principles

Data we don't collect

Data the app uses

To work, SimplePosts needs to use:

How shared boards work

When you share a board, your iCloud creates a CloudKit "share". The other person's device gets access to the board's notes through Apple's iCloud sharing system. Notes you post sync to your iCloud first, become accessible to other participants through Apple's sharing, and don't pass through any servers we run.

What you write, draw, photograph and name is stored in iCloud using CloudKit's encrypted fields. The keys live in your own iCloud Keychain, which means Apple cannot read your notes — not with Advanced Data Protection switched on, and not without it. We cannot read them either, and not as a matter of policy: we run no servers for your notes to pass through.

Apple can still see metadata — that a board exists, that it is shared, and the network requests that carry it. Timestamps, positions and paper colours are stored unencrypted, because sync and ordering need them and they say nothing about what a note says.

Boards are shared by link. Anyone you send the link to can join, and so can anyone they forward it to. You can see everyone who has joined in the board's People list, and stop sharing at any time.

Saved notes (scrapbook)

Saving a note creates a snapshot in your private iCloud database. It's a copy, independent of the original: removing the original from a board doesn't affect your saved copy, and removing your copy doesn't affect the board.

Pass a Note

Passing a note to someone nearby sends it as a file directly to their device using Apple's AirDrop. It travels peer to peer through Apple's share sheet — it never touches our servers, your iCloud, or anyone else's iCloud, unless the recipient chooses to save it.

The recipient's device stores a received pass locally only. After 24 hours it expires and is deleted unless saved.

Connections you make through Pass a Note

The app keeps a list of people you've connected with, used by the "Connections only" setting that decides whose passed notes you accept. This list is stored on your device and synced through your iCloud.

Sensitive content scanning

SimplePosts uses Apple's Sensitive Content Analysis framework to detect explicit imagery in incoming notes. Scanning happens entirely on your device using Apple's on-device machine learning. Apple does not see your content, and neither do we. It respects your iOS settings: if you've turned off "Sensitive Content Warning" in Privacy & Security, scanning doesn't run.

For users under 18 with Family Sharing configured, Apple's Communication Safety applies through our use of standard Apple frameworks — warning before sending sensitive content and offering resources, all on device.

Reports of concern

When you report a concern about a note, the app blocks that user locally for you and hides their content. You can optionally email us a report containing only metadata: a category you choose, timestamps, and anonymised hashes of the user IDs involved. The note's content is never included. We use these only to spot patterns of abuse. For serious concerns, the app offers direct paths to Apple's safety team or NCMEC.

You can review your report history any time in Settings → Privacy → Report history.

Notifications

If you enable notifications, the app uses Apple's UNUserNotificationCenter to schedule local notifications. We don't send push notifications from a server — Apple's CloudKit silent push triggers them, and the notification itself is generated on your device.

Notification content appears on your lock screen unless you disable that in Settings.

Account ownership

You own your iCloud account. We have no database of users. There are no SimplePosts accounts, passwords or logins.

If you delete your iCloud account or the app, your data is removed through Apple's standard processes.

Data deletion

You can delete:

Children

SimplePosts isn't designed for children under 13, and we don't knowingly collect data from them. If you're a parent and believe your child is using SimplePosts, please get in touch — we'd like to know how to make it more appropriate.

Third-party services

We use:

We don't use analytics services, advertising networks, third-party authentication, data brokers, or any "we anonymise and sell" service.

Cloudflare Pages serves this static site. Cloudflare may log basic web traffic such as browser type and IP for routing. That's standard web hosting; it isn't linked to anything you do in the app.

Updates to this policy

If we update this policy, we'll show a banner in the app explaining what changed before the new policy applies.

Contact

Have a question about your privacy or data? Email azeltzdev@gmail.com.