Back to Close Circle

Privacy policy

Close Circle, by Cottonora LLC.

Close Circle has two halves and they work differently.

Your journal is yours. It lives on your phone. It works with no account at all. We never see it — not the words, not the feeling you logged, not the photo. If you switch on backup, a copy goes to our server encrypted on your phone first, so we hold bytes we cannot open (§4a).

Your circles are shared. When you choose to share something with a circle, a copy goes to our server so the people in that circle can see it. We can see those copies. So can they, because that is what sharing means.

Nothing moves from the first half to the second unless you tap the thing that moves it.

Last updated: 15 August 2026.


1. Who we are

Close Circle is made by Cottonora LLC, ⟦ADDRESS⟧, United States.

Questions, requests, or problems: hello@ucaronur.com.

2. You can use this app without giving us anything

Close Circle works with no account. Open it, write in it, keep a journal for years, and we will never have any of it.

An account does one thing: it lets you join circles and share with them. If you never want that, you never need one.

3. What stays on your phone

Everything you write that you have not shared, and — unless you turn on backup (§4a) — it stays there and nowhere else. That means:

  • Reflections — the feeling you logged, the labels you picked, the associations you chose, and anything you wrote alongside them
  • Check-ins you kept private, including photos and songs
  • Which check-ins you attached to a reflection as evidence
  • Whether an entry came from your journal or from a circle, and whether you have hidden it from your journal
  • Your calendar, your history, and the recaps generated from them
  • A note of who responded to something you shared, and when — a name and a time, never what they said. The words stay on our server and are read from there.
  • Your app preferences: theme, language, and whether the journal lock is on

These are stored in an ordinary database file inside the app on your device. They are not encrypted at rest. Anyone with access to your unlocked phone can read them, and the optional journal lock in Settings guards the app's screens rather than the file. We say this plainly because the alternative is implying a protection that is not there.

Your phone's own backup

On iPhone, your journal is included in your iCloud backup, if you have iCloud Backup switched on. That is Apple's backup, made by your phone, under your Apple account — it does not come to us and we cannot read it. We mention it because "only on this phone" would otherwise be inaccurate, and because it is a safety net you may want to know you have.

On Android, your journal is not included in your device backup. Only app preferences are.

A copy of your circle, kept for speed

If you have an account, the app keeps a small copy of your most recent circle activity on your device so it can draw the screen before the network answers. That is content from your circle — including things other people posted — sitting on your phone. It is replaced as the app refreshes and it goes when you delete the app.

We cannot read any of this, because none of it reaches us.

4. What we hold on our servers

Only if you have an account, and only what a circle needs.

Because you signed up: your email address, your display name, and your profile photo if you set one. These are handled by Clerk (see §6).

Because you joined a circle: which circles you belong to, when you joined, your role in them, and the private nicknames you have given other members. Nicknames are visible only to you.

Because you shared something: the copy. A shared check-in's text, photo, song and mood emoji. Comments and reactions you leave, and who you mentioned in them. Answers to a circle's daily question, and votes on its polls. Custom emoji uploaded to a circle. Recaps generated for a circle from what it shared.

Because you asked for a particular kind of reply: when you share something you may attach a response request — one of a short, fixed list such as "check on me later" or "distract me". We hold that alongside the shared copy, and everyone in the circle sees it.

This is a thing about your state of mind, sitting in our database, and we would rather say so than bury it. It is not mood data — it reveals nothing your emoji did not, and it is chosen from a fixed list rather than typed. But it says something about what you wanted from people that day, and it is stored in ordinary form like the rest of the shared copy.

Because the app has to work: notification tokens for your devices, invite codes for your circles, badges and titles the app has awarded you, "thinking of you" nudges you send, who you have blocked, and basic counts about how the app is being used (installs, joins) which are not tied to individual entries.

A link back to your own entry. A shared copy carries the identifier of the private entry it came from, so your phone can tell that a reply belongs to that entry. It is an opaque identifier and it carries no content — it only means something on your device.

What never reaches us, even when you share

When you share a reflection with a circle, the circle sees the emoji, the note if you wrote one, and any labels you chose. The underlying feeling value, what the app inferred it from, and the associations you picked never leave your phone. Neither does anything from which they could be reconstructed, and neither do the check-ins a reflection carries as evidence — sharing a reflection shares the reflection.

That is a deliberate boundary in the code, enforced by the shape of what the app is able to send, not a policy promise.

4a. If you turn on backup

Backup is off until you switch it on, and it is the only thing that puts your journal on our servers. Everything in §3 stays exactly as described until you do.

When you turn it on, your phone encrypts each entry on the device, before it is sent, with a key we never receive. What arrives on our server is a block of bytes we cannot open — not the words, not the feeling, not the photo, not the labels. Decrypting requires a key that exists in two places, both of them yours: inside your phone's secure storage, and behind the recovery code we show you once.

We cannot read the backup, and unlike §5's second half, that is a statement about cryptography rather than about possession. We do hold the bytes. We cannot turn them back into your journal.

What we CAN see, even though we cannot read it

Encryption hides the contents of a thing. It does not hide that the thing exists, so the server learns some facts about the shape of your journal, and we would rather list them than let "encrypted" imply they are not there:

  • How many entries you have, because each one is a row.
  • When each entry was written or last changed, because that timestamp is what decides which version is newest when two phones disagree.
  • When you delete one, because a deletion has to travel to your other phones to take effect.
  • How big each entry is, roughly — a long note is more bytes than a short one, and a photo is much larger than either.

None of that says what you wrote or how you felt. All of it says something about your rhythm, and you should know it before you turn this on.

The recovery code

The code is generated on your phone, shown once, and never sent to us. We store only the salt and the wrapped key — never the code, and never anything we could turn back into it.

This means we cannot reset it. If you lose the code and lose the phone, the backup cannot be opened by anyone, including us. That is what makes the encryption real, and it is the one part of this feature that is unforgiving. We would rather say it here, twice, than have you discover it on the worst day.

5. What we can actually see

We can read the copies you share. Text, photos, comments and reactions on our servers are stored in ordinary form so the app can display them, search them and moderate them. If we needed to look — to investigate a report, or to fix a serious bug — we could.

We do not sell this, use it for advertising, use it to train anything, or share it with anyone outside the third parties in §6.

We cannot read your journal. If you have not turned on backup, that is because we do not have it at all. If you have, we hold it only as bytes we cannot open (§4a). Either way the answer to "can you read my journal" is no — but the two reasons are different, and we would rather give you the exact one.

6. The companies that help run this

  • Clerk — sign-in, and your email, name and profile photo
  • ⟦HOSTING PROVIDER⟧ — our servers and database
  • ⟦OBJECT STORAGE PROVIDER⟧ — photos and custom emoji you shared
  • Upstash — rate limiting and caching, which sees request patterns and not content
  • Expo — the push service our server hands notifications to. It holds your device's push token and passes the notification on to Apple or Google, so the text of a notification goes through it
  • Apple (APNs) and Google (FCM) — delivering notifications
  • Sentry — crash reports, so we can fix what breaks. Configured not to send personal information, and invite codes are stripped before anything is sent.
  • Apple (iTunes Search) — searching for a song to attach. Your phone never contacts Apple for this. The search runs through our server, so Apple sees our request and not you.

⟦PROCESSING REGION — the country or region where our servers and database run. Needed for GDPR transfer disclosures.⟧

7. Notifications

If you turn them on, we send a device token to Expo's push service, which passes the notification to Apple or Google so it can reach your phone. Notification text can include a person's name and a short line about what happened.

Reminders for your morning and evening reflections are generated on your phone and never involve our servers.

You can turn any of them off in Settings, and turning the master switch off stops all of them.

8. Deleting your account

Settings → "Your journal, your call" → Delete account. It is immediate, and it is not a deactivation.

What goes: everything you authored. Shared check-ins, photos, comments, reactions, votes, answers, badges, nudges, your blocks, your profile, your notification tokens, and any reports about you. If you own a circle, ownership passes to the longest-standing member so nobody else loses their history; if you were its only member, the circle goes too.

What does not go, because we never had it: your journal, if you never turned on backup. It is on your phone and it stays there. Delete the app to remove it, and remember your phone's own backup may still hold a copy (§3).

If you did turn on backup, the encrypted copies go with your account, in the same immediate deletion — the bytes are removed, not merely marked. Deleting a single entry does the same for that entry: the stored block is overwritten rather than annotated, so "deleted" means the content is gone from our servers and not just hidden from you.

Export first. The delete flow offers it, and you should take it. Export works with or without an account.

9. Reports and moderation

You can report a check-in, a comment, or someone's profile photo. You can only report or block someone you actually share a circle with.

Blocking is mutual and quiet. If you block someone, you stop seeing their content and they stop seeing yours. Nobody is told they have been blocked, and neither side can tell who blocked whom.

When something is reported, we keep a copy of what was reported so it can be reviewed after the fact — otherwise deleting and re-posting would defeat review. For a photo we keep the reference to the stored image, not a second copy of it.

  • Once a report is resolved, the copy is deleted after 30 days. The record that a report happened, and its outcome, is kept.
  • If the author deletes the original while a report is still open, the copy is deleted after 7 days. A pending review is not a reason to hold something you asked us to remove for longer than a human needs to look at it.
  • When a copy is deleted for either reason, the report itself survives without its evidence. A report that has outlived what it was about is a fact we would rather state than hide.
  • If you delete your account, reports about you go with it, copies included. Moderation is not an exception to §8.

10. Age

You must be 16 or older to use Close Circle.

We do not knowingly collect anything from anyone under 16. If we find out that someone under 16 has an account, we delete it and everything they shared.

If you believe someone under 16 is using Close Circle, write to hello@ucaronur.com and we will act on it.

11. If you are in a closed test

Close Circle is sometimes given to a small number of people as a closed test build, and you would know if you were in one, because we would have asked you.

A test build keeps a short log on your device recording that one of five things happened and when — you saved a private entry, you shared one, you accepted an invitation, someone responded, or you looked back at something. Each record holds a timestamp and a random identifier for the phone, and nothing else. No content, no feeling, no text, no names, and the identifier is not connected to your account, your circles or your journal.

It stays on your phone. It reaches us only if you send it to us, as part of the export in §8, and only if you choose to. Ordinary builds of the app record nothing at all.

12. Your rights

You can get a copy of everything (§8's export), correct it in the app, or delete it (§8). If you are in the EU or the UK you have further rights, including objecting to processing and complaining to a supervisory authority — in the EU that is your national data protection authority, and in the UK it is the Information Commissioner's Office.

Write to hello@ucaronur.com and we will answer within 30 days.

13. Changes

If this policy changes in a way that affects what we hold or who sees it, we will tell you in the app before it takes effect rather than quietly updating a date at the top.