What leaves your phone
The app itself sends none of your record anywhere. This page lists every way data from the app leaves the phone today, who receives it, and what they can see.
What leaves, and to whom
| Your record | |
|---|---|
| What leaves | Nothing |
| To whom | No one |
| What they can see | Nothing |
| How we check | At every release, a test scans all of the app's own code for ways it could reach the network, and allows only the links you open and the calls you place. Another reads every web address in the app's built code and fails if the app could open or request one that this page doesn't account for. The web page the app runs in also carries a security policy that refuses the requests the reference data row lists. |
| iPhone and iCloud backups | |
| What leaves | Your record is excluded from backups, and You shows whether that worked. If it didn't, a backup holds only the encrypted record, and its key can be unlocked only by this iPhone. The app's settings are included, and hold no record data. |
| To whom | Apple, if you use iCloud Backup; your computer, if you back up to it |
| What they can see | The encrypted record, only if exclusion failed; otherwise the settings |
| How we check | The You tab shows whether the record is excluded from backups, as iOS reports it. The record's key is kept in the iPhone's Keychain, set so that iOS restores it only to this iPhone. A test lists what the app's own code stores, and fails on anything new it finds until it is reviewed. It also checks that, apart from the encrypted record, nothing a backup can include holds record data. |
| A backup file or readable copy you make | |
| What leaves | Only the file, only where you send it |
| To whom | Whoever receives it |
| What they can see | A backup: nothing without the passphrase. A readable copy: everything in it. |
| How we check | A test checks that the app deletes the copy it makes for sharing afterwards, and that every launch and the quick wipe delete any left behind. |
| Reference data (the public dataset) | |
| What leaves | Nothing. The reference data is built into the app, and updates when the app does. |
| To whom | No one |
| What they can see | Nothing |
| How we check | At every release, a test scans the app's own code and fails if it finds a way to request data from the network. If that code tried one anyway, a security policy on the web page the app runs in would refuse network requests and connections, images and scripts from elsewhere, audio, embedded frames and objects, and form posts to another address. A test shows each of those refusals at every release. |
| The lock-screen card | |
| What leaves | Nothing to Psychedex. iOS shows the card on a paired Watch, the Mac menu bar and CarPlay. Names appear only if you turn them on. They never appear on the Watch or CarPlay, and may appear on the Mac. |
| To whom | Whoever sees those screens |
| What they can see | The card |
| How we check | The card is updated on the phone, with no network and no push. Names are off until you turn them on, and the Watch and CarPlay views never show them. |
| Calls and texts from Help | |
| What leaves | An ordinary phone call or text. An emergency call may share your location with the emergency service, as any emergency call does. |
| To whom | Your carrier and the line you contact |
| What they can see | What any call or text shows |
| How we check | A test checks that every call and text link in Help is an ordinary phone or text link to a line Help lists. |
| Links to psychedex.org | |
| What leaves | An ordinary web visit, in your browser |
| To whom | Psychedex, its host Vercel, and Plausible, which counts page views without cookies |
| What they can see | The page address, which can name a substance, and what any web visit shows |
| How we check | A test fails if the website loads its page-view counter and this row doesn't name it, or the reverse. |
| AI | |
| What leaves | Nothing. The app sends nothing to any AI model; the check is fixed code. How Psychedex uses AI |
| To whom | No one |
| What they can see | Nothing |
| How we check | At every release, a test fails if the built app holds the address of a known AI or analytics service, or code from one. |
What we collect
No account, and the app itself makes no request: it sends nothing from your record, and asks for nothing. Anything that reaches us is in the table above.
What we count
The app counts nothing. It contains no analytics and no crash-reporting code. The website counts page views with Plausible, without cookies.
How long anything is kept
- Your record: none of it leaves, so we keep none of it.
What we can't protect
- An unlocked phone, a screenshot, someone looking over your shoulder. That is why details summarize on a schedule you set, and why there is a quick wipe.
- What iOS itself does with dictation, Siri and screenshots.
The app refuses third-party keyboards, and turns off Writing Tools in its fields.
If someone asks us
We can't read your record. What we can see is in the table.
Check it yourself
Watch the app's traffic with any proxy. Apart from the links you open and the calls you place, the app itself asks for nothing.
Deleting your data
Your record is on your phone. The wipe deletes it, and so does deleting the app.