Last updated 15 August 2026
Privacy policy
Everything you write stays on your phone, encrypted, and we cannot read it. There is no advertising in Calma and there never will be.
Stays on your phone
Worries, journal entries and breathing sessions are stored in an encrypted file on your device. The key lives in the phone’s own secure storage. Nothing is uploaded, because there is nowhere to upload it to.
No advertising, ever
No advertising identifiers, no third-party trackers, no analytics on what you write, and no data sold or shared with anybody. That is true of this website as well as the app.
1 · What we collect
Nothing. Calma has no accounts, no sign-up, no login and no servers of its own. There is no analytics SDK reading your content and no crash reporter sending it anywhere.
Everything the app knows about you was typed into it by you and stays on the device it was typed on. In full, that is:
Your worries. The text of each one, when you captured it, whether it is still pending, worked through or let go, and any small action you decided on.
Your journal entries. The situation, the thought, the feeling and how strong it was, the evidence for and against, the balanced thought you landed on, and how strong the feeling was afterwards. Drafts are saved continuously as you type, so an entry exists on disk before its first full sentence does.
Your breathing sessions. Which rhythm, how long, how many cycles, where in the app you started from, how you rated things beforehand if you chose to, and whether you felt better, the same or worse afterwards. Skipping the rating is recorded as having skipped it rather than as a zero.
Your settings. The name you gave, the three answers you gave when you set it up, your language, your worry window time and length, your usual breathing rhythm and any custom one, your theme, whether sound and haptics are on, whether you have been asked about notifications, and whether the lock is on.
None of it is sent anywhere, and there is no version of Calma in which any of it could be — the app contains no code that uploads content, and a test scans the whole source tree on every run and fails if one appears.
2 · What we never see
Your writing. All of it is stored in an encrypted database on your phone, with the encryption key held in the operating system’s own secure storage — Keychain on iOS, Keystore on Android. We do not have a copy of the key and cannot obtain one.
The key is generated on your phone the first time you open the app, from the operating system’s own randomness, and is marked as belonging to that device alone. It is deliberately not synced to iCloud and not restored onto a new phone. That is why a new device starts empty, and it is the trade for nobody else ever holding it.
Two small things are stored unencrypted, and neither is anything you wrote: whether you have finished setting the app up, which version you last opened, and whether this installation has an active subscription. Nothing sensitive touches that file, by rule.
If your phone has no secure storage available — a phone with no passcode set can legitimately have none — Calma opens anyway, works normally, and tells you plainly that nothing will be saved this session. It keeps everything in memory for that session and writes none of it to disk. We would rather say so than quietly pretend to save someone’s writing.
You can put Face ID, Touch ID or your device passcode in front of your journal from Settings. It is off unless you turn it on, it covers the writing rather than the whole app so breathing is never behind it, and the fact that you have unlocked is held in memory for that launch only — never written down.
3 · Notifications
Calma can send four notifications and no others: a note before your worry window opens, a note when it does, an occasional gentle nudge about a journalling streak, and a weekly check-in. The last two are Plus. There are no re-engagement messages, no “we miss you”, no streak-loss alerts and no promotional notifications, and there is no badge count on the app icon.
They are scheduled locally by your own phone. Calma has no push service and requests no push token, and it never will — a push token is a device identifier, and a test asserts across the whole source tree that none is ever requested.
No notification can contain anything you wrote. A body can interpolate a number — worries waiting, days in a streak — and nothing else. There is no template anywhere that accepts a piece of text, which is the mechanism by which a worry cannot reach a lock screen where anyone holding your phone would see it.
Nothing is sent between 22:00 and 07:00, without exception and regardless of your settings. Permission is asked for once, only after you have said yes on a screen inside the app, and declining that screen never reaches the operating system at all.
4 · Who the app talks to
Three parties, all of them at arm’s length, and none of them ever receiving a word you have written.
RevenueCat, if you buy Calma Plus. The purchase is handled by RevenueCat, which talks to Apple’s or Google’s billing service. It is used anonymously: we never identify you to it and never create an identifier for you, so what it holds is a random installation identifier and whether that installation has an active subscription. It never receives your name, your email address, or anything you have written. Because there are no accounts, a purchase belongs to your App Store or Google Play account rather than to Calma, and restoring the purchase is how it comes back on a new phone.
Expo, for app updates. Calma is built with Expo, and a released build checks Expo’s update service when it launches to see whether a newer version of the app’s code has been published. Expo sees what any server sees when a device contacts it: an IP address, and a description of the build asking — platform, app version and runtime version. It receives nothing from inside the app, and the check is for our code rather than your data. If it fails, or you are offline, the app opens normally with the version already on your phone.
Expo, for install and session counts. The same build includes Expo’s insights component, which reports that an install exists and that the app was opened, along with the platform and app version. It counts launches. It does not know what you did in the app, cannot see a worry, an entry, a breathing session or a setting, and carries no advertising identifier. It is the one piece of telemetry in the product, it is disclosed here rather than folded into a sentence about “service providers”, and if it is removed from a later build this paragraph goes with it.
That is the complete list. There is no analytics on your content, no attribution SDK, no advertising network, no crash reporter that uploads your writing, and no social login.
5 · This website
No analytics, no cookies, no trackers, and nothing to accept. There is no consent banner on this site because there is nothing to consent to.
The two typefaces are downloaded when the site is built and served from this domain, so no request ever reaches Google from your browser. That is a privacy decision rather than a performance one: a page that promises nothing leaves your device should not phone a third party to render its own heading.
Our host keeps ordinary server logs, as every web server does, and we do not use them to build a picture of anybody. If you email us, we have your email — that is unavoidable and it is the only way we could ever come to hold anything about you.
6 · Deleting everything
Settings › Your writing › Delete everything removes every worry, entry and session from the device, cancels anything scheduled, and destroys the encryption key with them. It is immediate and it is final: we keep no copy anywhere to restore from, which is the other side of never having had one.
Deleting the app does the same thing. There is no account left behind to close and nothing of yours on any server to request.
Because nothing about you leaves your phone, the usual data rights — access, correction, portability, erasure, objection — resolve on the device itself: everything we could possibly hand you is already in your hands, and deleting it is a button rather than a request. If you would rather ask us anyway, please do; the answer will be this paragraph, and we will say so honestly.
7 · Children
Calma is not directed at children and collects no information from anybody, including them.
8 · Changes, and how to reach us
If this policy changes, the date at the top changes with it. A change that affected what leaves your device would be announced in the app before it took effect — though the plan is that there is never anything to announce.
Calma is published by Wyven Incorporated, Zimbabwe, which is the data controller for the very little described above. The terms of service sit alongside this policy.
Questions go to hello@calma.app. A reply may take a few days. Please do not send us anything you have written in the app — an email is the one place it would stop being private.