Privacy Policy

Brief Sketch Sprint

Effective date: 2026-09-29

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Brief Sketch Sprint stores the project type, keywords, creative constraints, task text, sketch images, notes, selected sketch, and session dates for the sprints you create. A current unfinished sprint, its drawing strokes, completed sessions, language choice, and default duration are stored on your device. A random installation secret is stored in your device Keychain on a signed device build. If Keychain is unavailable in an unsigned development Simulator build, the app stores the secret in its private Application Support container so test installations keep a stable secret. When the app contacts the service, it sends that secret in a request header; the service stores only its SHA-256 hash as the namespace for your sessions. The service stores completed session details and sketch images in its database. Network requests also expose technical information such as IP address and request headers to the hosting infrastructure. The app has no account, password, contacts upload, analytics SDK, advertising SDK, or email delivery feature.

How we use information

We use brief details to generate relevant sketch tasks, the timer and optional local notification to support a sprint, and stored sketches, notes and selections to show your Concept Board and history. The installation secret limits access to your own server records without requiring an account. Technical request information is processed to deliver and operate the service.

Service providers and sharing

The backend and its database run on Railway, which processes requests and hosts stored session data and operational infrastructure logs. Apple processes the app's on-device storage, Keychain and local notification functions as part of iOS. We do not send sprint content to an analytics, advertising, email or social sign-in provider. We do not sell personal data. Railway infrastructure may receive IP addresses, headers and operational logs when requests are made; the application server does not intentionally log brief content or the installation secret.

Data retention

Completed sessions remain on the device and in the Railway database until you delete a session or use Delete all data. An unfinished sprint remains locally until completed or removed by deleting all data. Language and duration choices remain in device preferences until changed or the app's data is removed. The installation secret remains in Keychain, or the private app container for a development Simulator fallback, until Delete all data succeeds or iOS removes it. Device backups managed by iOS or by you may contain copies of the app's local sprint files; deleting data in the app does not itself erase earlier device backups, whose retention depends on your backup settings. Deleted database rows may remain temporarily in SQLite journal files, storage snapshots or hosting backups; their exact physical erasure time and Railway infrastructure-log retention are controlled by the hosting service and are not fixed here. If you lose the installation secret, prior server records cannot be recovered through an account.

Deleting your information

Delete a sprint from its details to remove that session from the server and this device after the server confirms deletion. Delete all data in Settings requests removal of all server sessions associated with this installation, then clears local sprints and the installation secret from Keychain or the development Simulator fallback file after server confirmation. If the device is offline or the server rejects the request, the app reports failure and keeps the secret so deletion can be retried. Earlier device backups may still contain older local copies until those backups expire or are deleted through your device backup provider. You can also contact honoria.bowditch@icloud.com about a privacy request, but without the installation secret we may be unable to locate an installation's private records.

Permissions and your choices

The app may ask for notification permission to alert you when a sketch timer ends while the app is away from the screen. You can deny or later withdraw that permission in iOS Settings; drawing, saving and the visible in-app timer still work. The app does not request location, camera, photos, contacts or microphone access.

Your privacy rights

You can review your brief, sketches, notes and selected direction in the app, edit notes and selection, and delete individual sprints or all installation data. For questions or applicable privacy-right requests, email honoria.bowditch@icloud.com. The app has no account-based recovery, and the installation secret is required to access or delete server records through the app.

Security

The app uses HTTPS for server communication, stores the random installation secret in iOS Keychain on signed device builds (with private app-container storage only if Keychain is unavailable in a development Simulator build), and sends it only as an authorization header. The server validates the secret and isolates records by its hash. Session data is stored on a Railway volume; local sprint data is stored in the app's iOS container. No system can guarantee absolute security. Anyone who obtains the installation secret could access that installation's server records, so it is not displayed in the app.

Children’s privacy

Brief Sketch Sprint is designed for designers and illustrators and is not directed at children. It does not offer child accounts, social features or targeted advertising. If you believe a child has provided data through an installation, contact honoria.bowditch@icloud.com so the available deletion options can be discussed.

Changes to this policy

If these practices change, this page will be updated with a new effective date. Changes to collection, storage, sharing or deletion will be reflected in the app and this policy before the updated behavior is deployed.