Privacy, in plain language

Your task is not our business model.

Sidle has no login, advertising, or cross-app tracking. The free loop and local Pro tools stay on your device. Optional AI sends text to DeepSeek only after current adult and China-processing consent.

Effective 14 July 2026 · Describes the v1.3 release candidate · Production provider AI is enabled

AccountNo name, email, or login required
TrackingNo ads or cross-app tracking
Raw provider sessionsScheduled to delete after 90 days
Provider AI18+ and separately consented

App Store privacy label

Sidle has published Data Linked to You for App Functionality, with no tracking, in App Store Connect:

  • Purchase History;
  • Other User Content;
  • User ID;
  • Product Interaction; and
  • Other Usage Data.

Apple's public US product page can temporarily show only Purchases, User Content, and Identifiers while its cache refreshes. Product Interaction and Other Usage Data are nevertheless included in our current published declaration and in this policy.

“Linked” here means records are associated with Sidle's assigned anonymous user identifier. It does not mean Sidle asks for your real-world name or uses the data for advertising.

What stays on your device

Free sessions work without a Sidle server identity. Moments—including the task, first move, start and end times, and an optional mood word—are stored in the app on your device. Companion style, hello timing, adult confirmation, AI consent, and a local purchase-state cache also stay on the device. The widget copies the two most recent task names and the Moment count into an App Group preferences container.

In v1.3 Pro, the “For next time” Return Bridge is written by you and saved only on this phone. It is not a provider memory note and is not sent to Sidle's server or DeepSeek. The in-app hello and optional voice are generated on-device. An optional background hello uses an iOS notification. Sidle does not record or upload microphone audio.

Sidle does not provide account-based or cross-device Moment or Return Bridge sync. Apple's device-backup behaviour is controlled by your Apple settings, not Sidle.

If you enable Live Activity, Sidle can place task text on the Lock Screen and Dynamic Island. That can expose a sensitive task to anyone who can see your phone. Avoid Live Activity for private tasks.

What optional provider AI sends and stores

If you explicitly connect production provider AI, and only after you confirm that you are 18 or older and accept consent version 2's China and sensitive-data disclosure, Sidle can send or store:

  • the task and first physical move you type;
  • session start, reply, landing, state, and timing records;
  • your chosen companion name;
  • one clearable note derived from the latest eligible provider session, replacing the prior note rather than building a note history;
  • an assigned anonymous user identifier;
  • Apple-signed purchase product, transaction, status, and expiry information; and
  • monthly AI usage and cost counters linked to that anonymous identifier.

The local Return Bridge is not included. A device region code can be sent to choose a static crisis resource, but it is not stored with the session. Sidle does not request a name, email address, contacts, photos, advertising identifier, or precise location.

AI processing and the China transfer

Current production status: provider AI passed live silent-mode, generated-response, landing, and deletion checks on 14 July 2026 and is enabled. It remains fail-closed: missing consent, safety rules, outages, metering limits, or the service ceiling can make a session stay silent. Free sessions and local Pro features continue.

Sidle's AWS-hosted service sends the task, companion name, and relevant latest-session note for the co-start, then the task and first move for the follow-up, to DeepSeek, an AI provider operated in the People's Republic of China. DeepSeek returns generated co-start and follow-up text. Sidle's AWS service creates the landing line and replacement factual note deterministically from the session fields described above; those two outputs are not model-generated.

DeepSeek's public documents do not give Sidle an API-specific no-training or fixed-retention promise. DeepSeek offers API context caching, and its provider-side handling is outside Sidle's 90-day database schedule. Sidle therefore does not claim provider-side zero retention or exclusion from model improvement. Avoid entering health, identity, financial, legal, workplace-confidential, or other sensitive information.

The v1.3 client sends the current consent marker only after explicit adult confirmation and acceptance of the China and sensitive-data disclosure. The server requires consentVersion 2 at start, reply, landing, and retry boundaries. Old, missing, or withdrawn consent markers stay silent and do not authorize a provider call.

A deterministic crisis-language check runs before provider use or session storage and returns a static regional care card. A separate dangerous-task check returns a static refusal for violence, weapons, intrusion, and other dangerous wrongdoing. Matched text is not sent to DeepSeek or stored as a provider session.

You can ask us for the current processor details or make an access, correction, retention, or erasure request using the contact information below. AI output can be wrong or unsuitable. Sid is not a person, clinician, or professional service.

How the v1.3 anonymous identity works

Sidle has no user login. It creates a separate anonymous provider profile for each device only when provider-backed AI is explicitly connected. Fresh registration requires a verified Apple purchase and Apple App Attest proof bound to a one-time server challenge and Sidle's app identity. When iOS supplies Apple's signed validation-category and bundle-version extensions, Sidle also verifies the accepted distribution category and exact installed build. Older supported systems do not supply those two extension signals; Sidle still verifies the certificate chain, challenge nonce, app identity, environment, key, and initial counter. Unsupported devices keep local Pro but cannot connect provider-backed AI.

The app keeps a 30-minute KMS ECDSA-signed access token and a separate opaque rotating refresh credential in this device's iOS Keychain. The server stores a one-way hash of the refresh credential. Each successful refresh rotates it and issues a new 30-minute access token for the same device-scoped profile. A bounded idempotency receipt lets only the exact lost-response request converge; a different replay is refused.

This is not account-based or cross-device sync. Profiles, provider notes, local Moments, and Return Bridges do not move between devices. Legacy HMAC access-token verification and random v1.2 registration stop at 2026-08-15 00:00:00 UTC; eligible legacy adoption requires a verified Apple transaction and its existing customer identity pointer, not merely a purchase binding.

Retention in the v1.3 candidate

  • Raw provider-session records: are scheduled for deletion after 90 days. DynamoDB TTL removal can occur later.
  • Latest eligible provider-session note: a new eligible note replaces the prior one; Sidle does not keep a note history. The current note remains until it is cleared or this device's profile is deleted.
  • Unused free server profile: expires after 30 days if no verified entitlement is attached.
  • Purchase-level monthly provider-cost totals: are shared across device profiles using the same verified Apple customer transaction and remain, without task text, until 45 days after the billing month ends. The content-free fleet daily cost tally expires after about three days.
  • Minimal deletion tombstone: remains for up to 48 hours so delayed writes cannot restore deleted profile rows.
  • Content-free deletion and PITR ledger: remains for 40 days, beyond DynamoDB's 35-day point-in-time-recovery window. It contains the opaque identity; deletion, retry, tombstone-purge, retention, and cleanup scheduling fields; a request identifier and one-way deletion-proof hash; and the device-registration identifier and one-way device-fence hash when available. It contains no task, first move, companion note, provider response, or contact detail.
  • Permanent credential-revocation fences: content-free opaque identity and one-way device-derived identifiers remain solely to prevent a deleted credential or deterministic registration request from becoming valid again. They contain no task, first move, companion note, purchase content, or contact details.
  • Apple transaction identifiers and notification records: may remain separately where needed to validate purchases, prevent duplicate grants, handle refunds, or meet legal and accounting obligations. They do not contain task text or the latest-session note.
  • Support messages: are retained only as needed to answer the request and keep an appropriate business record.

A restored DynamoDB point-in-time copy is kept offline until the separate 40-day ledger has been replayed against it. The scrub removes deleted user partitions and ownership pointers, writes the required permanent identity and device fences, and fails closed if any deleted reference or required fence is missing. The restored table must not serve traffic until that verification passes.

Delete this device's Sid memory

In the v1.3 candidate, open Settings → Delete this device's Sid memory. The server first replaces this device's provider profile with the minimal tombstone, then its durable worker deletes the latest-session note, raw session rows, device-owned legacy cost rows, and active credential material. The app clears its Keychain credentials. Separate profiles on other devices are not deleted.

The tombstone, 40-day content-free deletion/PITR ledger, permanent opaque revocation fences, Apple purchase records, and bounded content-free purchase-level fair-use totals remain only within the purposes and periods described above. DeepSeek-side request copies or caches are outside this endpoint, and Sidle does not promise that the endpoint erases provider-side data.

Your Apple purchase and on-device Moments remain. Restore Purchases can restore local Pro, but after deletion it stays local-only and does not recreate a provider profile. Only a later explicit provider reconnect—after fresh confirmation that you are 18 or older and acceptance of the current AI disclosure—creates a blank profile for this device. It does not restore the deleted provider note.

To remove local Moments and the Return Bridge too, delete Sidle's local app data from the device. You can email us if the in-app control is unavailable. Include the Sidle version, iOS version, approximate attempt time, and timezone, but do not send task text.

Who helps provide Sidle

  • Amazon Web Services: API processing and encrypted database hosting in the United States.
  • DeepSeek: processes optional provider-AI requests as described above, including processing in the People's Republic of China. Its API caching and privacy terms are separate from Sidle's database retention.
  • Apple: distributes the app, processes purchases, reports entitlement status, and supplies device services such as Keychain, notifications, and Live Activities.

We do not sell personal information or use Sidle data for cross-app advertising. We may disclose information when legally required or reasonably necessary to protect users and the service.

Provider AI is for adults

Sidle's provider-backed AI may be used only by people aged 18 or older. The v1.3 candidate requires adult confirmation and the current DeepSeek/China disclosure before task text can be sent. People under 18 should keep sessions local and must not connect provider-backed AI.

Questions or privacy requests

The data controller is Mitaanshu Agarwal, trading as Uptrail, Australia. Email robin@kindabilities.com. We may need device and request-timing information to investigate, but do not send sensitive task text.

You may ask to access, copy, correct, object to, restrict, or erase server records we can authenticate and locate; ask about retention or DeepSeek processing; or make a privacy complaint. Keeping sessions local or withdrawing the current consent marker prevents a provider call but does not undo earlier processing or erase existing records by itself.

We will assess a complaint and aim to respond within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner or another regulator available to you. Access, correction, export, and erasure can be limited where we cannot safely link an anonymous record to the requester; we will explain the result rather than claim a control worked.

Support messages are retained only as needed to investigate and respond, and then for any period reasonably required for security, dispute, accounting, or legal obligations. No shorter fixed deletion period is promised.