Persona, an Aligned app

Privacy Policy

Effective 26 July 2026 · Last updated 26 July 2026

The short version. Persona is a local-first app. Your posts, captions, briefs, media, and brand names live on your own device and in your own iCloud Drive — they are never uploaded to us and we cannot read them.

What we do collect is small and deliberate: anonymous usage events so we can tell which features are actually used, and — only if you choose to sign in — the minimum needed to hold an account. You can turn usage data off, and you can delete your account from inside the app.

This policy explains exactly what Persona collects, why, where it goes, and how long it is kept. It describes what the app does today. We have tried to make it specific rather than comprehensive-sounding; where something is a limitation, we say so.

Persona is made by Kam Studios, LLC ("we", "us").

1. What stays on your device

Persona stores your content as ordinary folders and files in a location you choose — by default in your iCloud Drive. That includes:

None of this is sent to our servers. If your content syncs between your own devices, it does so through your Apple iCloud account, under Apple's terms — we are not a party to it and have no access. Persona works fully offline and fully signed-out.

2. Anonymous usage data

Persona sends a small stream of usage events so we can see which features get used and where people get stuck. This is events and metadata only — never your content.

What is sent

ItemWhat it is
install_idA random identifier the app generates for itself on first launch. It is not your device ID, advertising ID, serial number, or Apple ID, and it is not derived from your hardware. It exists only to tell one install's events apart from another's.
App versione.g. 1.10.4
OS versione.g. macOS 15.4
Platformmacos, ios, or ipados
EventsA name and a timestamp — see the full list below

The complete list of events

This is all of them. There are no others.

EventMeaningExtra detail
app_launchThe app started
update_installedThe app updated itselfVersion before and after
post_createdA post was created
media_attachedMedia was attached to a post
export_doneAn export finished
feature_openedA section of the app was openedWhich section (e.g. schedule)
brand_createdA brand was createdWhether it came from onboarding
errorSomething failedA one-word area label only — no error message, no stack trace

Notice what these events do not include: not the post, not the caption, not the filename, not the brand's name, not how many characters you typed. A post_created event records that a post was created and nothing about the post.

We enforce that in two places. The app only ever attaches fixed, pre-written labels to an event. Independently, our server rejects an entire batch of events if it spots a field name that looks like content — caption, brief, title, body, hashtags, filename and others. The second check exists so that a future bug in the app cannot quietly start leaking content.

Approximate location

When your app contacts our server, our infrastructure provider (Cloudflare) derives a country and region from the connecting IP address and records it alongside the event. The app never asks for location permission and never sends your location. This is coarse, network-level geography — country and region, not a place — and we use it only to understand roughly where testers are.

Turning it off

Settings → Usage & Privacy. It is on by default during the private beta. When you turn it off, the app stops recording events immediately — nothing is queued and nothing is sent.

3. Your account, if you create one

Persona is fully usable without an account. If you do sign in, here is everything we hold.

Sign in with Apple

Apple gives us an opaque user identifier (a sub) that is unique to Persona — it is not your Apple ID and cannot be used to identify you in any other app. If you choose Hide My Email, we receive Apple's relay address and never your real one. We store the identifier, and your display name only if the app supplied one.

Email sign-in

We store your email address and send you a six-digit code. The code itself is stored only as a salted hash, is valid for ten minutes, allows five attempts, and is deleted the moment it is used. This method is built but not yet switched on.

What an account record contains

StoredDetail
AccountA random user ID, when it was created, your display name if provided, and your beta status
Sign-in methodThe provider (Apple or email), its identifier, and when it was first and last used
Beta invitationThe email address, Apple identifier, or invite code that granted you access
SessionStored under a hash of your session token, so our store never holds a usable credential. Sessions last 30 days. On your device the token is kept in the system Keychain, tied to that device and excluded from backups.

We also record that a sign-in happened — the method used, and whether it was a new or returning account. Never a token, an email address, or an Apple identifier.

We keep one Apple refresh token so that deleting your account can also revoke Persona's access with Apple, as Apple requires. It is used for nothing else.

4. Feedback you send us

This is the one place where text you wrote leaves your device. It only happens when you open Send Feedback and press submit — never automatically.

When you submit feedback we receive the name you type, the subject and description you write, and your app and OS version. If you file a bug report, it also includes a technical report containing:

We are telling you this plainly because it is the honest description of what a bug report contains. If you would rather not send it, use the Feature Request or General type instead — those do not include the technical report — or describe the problem to us directly. Feedback is stored in our own systems and in a Notion workspace we use to track issues.

5. What we never collect

6. Why we collect what we collect

DataPurpose
Usage events, app/OS version, countryUnderstand which features are used and where people get stuck, so we can improve the app
Account and sign-in recordsSign you in, keep you signed in, and control access to the private beta
Feedback and bug reportsDiagnose and fix the problem you reported

We do not use any of it for advertising, profiling, or automated decision-making, and we do not sell it. If you are in the UK or EEA, our lawful basis is our legitimate interest in maintaining and improving the app, except where you have given consent — and for usage data you can withdraw that at any time with the opt-out in Settings.

7. Who else touches this data

ProviderRole
CloudflareHosts our servers, database, and analytics. All usage and account data is processed here.
AppleProvides Sign in with Apple, and (separately, under your own Apple account) iCloud Drive storage for your content.
NotionWhere submitted feedback is tracked.

These are service providers acting on our behalf. We do not sell or rent your data to anyone, and there is no advertising network involved. Our servers run on Cloudflare's global network, so data may be processed outside your country.

8. How long we keep it

DataRetention
Usage eventsThree months, then automatically deleted
Install record (version, OS, platform, first/last seen)Kept until you delete your account or ask us to remove it
Account and sign-in recordsUntil you delete your account
Sessions30 days, or until you sign out
Email sign-in codes10 minutes, or immediately once used
FeedbackKept while we work through it; no fixed schedule yet

9. Deleting your account

You can delete your account from inside Persona — you do not need to email us or wait. It takes effect immediately and it is not reversible.

When you do, we:

Two consequences worth knowing in advance: deleting your account also removes your beta access, so you would need a fresh invitation to come back; and your content is untouched, because it was never ours — it stays in your own folders exactly as it was.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your data, to object to or restrict processing, and to complain to your data protection authority. Account deletion is built into the app; for anything else, contact us and we will respond.

11. Children

Persona is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us personal information, contact us and we will delete it.

12. Changes to this policy

If we change what we collect, we will update this page and move the "last updated" date. Persona is under active development, and some planned features — such as optional cloud storage of your library, and shareable preview links — would be the first time your content leaves your device. Those are not built yet. If and when they ship, they will be opt-in, they will apply only to items you explicitly choose, and we will update this policy before they do.

13. Contact

Questions about this policy, or to exercise any of the rights above:
kamren@kamstudios.com
Kam Studios, LLC