Privacy

Privacy Policy

Faye is built so that there is very little about you to hold. No account, no email address, no password. No analytics SDK, no advertising identifier, no third-party trackers. This page says exactly what exists, where it sits, and how to delete it.

Effective 28 July 2026 · Version 1.0 · Applies to the Faye iPhone app and fayemanifest.com

The short version

  • You never create an account. There is no name, email address or password anywhere in Faye.
  • Photos and voice memos you add to your board stay on your iPhone. They are never uploaded.
  • What you type during onboarding is sent to our server encrypted, because that text is what your scenes are written from. It is never used for advertising and never sent to any analytics service.
  • There is no analytics SDK, no advertising identifier and no tracking of any kind in the app.
  • You can export every scene and erase your data in one tap, inside the app.

1. Who is responsible

Faye (fayemanifest.com) is the operator of the Faye iPhone app and of this website, and is the data controller for the processing described here.

For any privacy question, request or complaint, write to [email protected]. A person reads that address; you will get a reply.

2. What Faye holds

Everything below exists for one reason: to write your scenes and to keep your subscription working. Nothing is collected "just in case".

WhatWhy it existsWhere it lives
A device key — an anonymous cryptographic key created on your iPhone It is how the server recognises your device without a login. It replaces the account you never made. The private half never leaves your phone's Secure Enclave and is never copied to iCloud. The server stores only the public half.
What you tell Faye during onboarding — the life you are moving toward, what you are working on, what keeps you up, who matters to you This is the source text for every scene. Without it there is nothing to write from. Encrypted on our server (hosted on Railway) and cached on your phone with iOS file-level encryption.
Your board — photos, notes, voice memos, the manifests you wrote The writing draws on it, and you can see it whenever you like. Photos and voice memos never leave your iPhone. They are stored in the app's private container with complete file protection. Written notes are sent encrypted, because they are read to write scenes.
Your scenes and affirmations So they can be replayed, downloaded and exported. On our server and cached on your phone for offline listening.
Ritual times, language, time zone, notification token To deliver the morning and evening scenes at the hour you chose. Our server. The notification token comes from Apple and only Apple can deliver with it.
Subscription status To know whether your subscription is active. RevenueCat and Apple. We never see your payment card, billing address or Apple ID.
Ordinary server logs — IP address, timestamp, which endpoint was called Security, abuse prevention and debugging. This is a legal-interest necessity for running any server. Our hosting provider, deleted on a short rolling window.

3. What Faye never collects

4. Sensitive answers get special handling

Some of what Faye asks is genuinely personal — what you are afraid of, what you have not said out loud, what you are trying to change. That text is treated as a separate class of data:

Faye is not a medical or mental-health service and nothing in it is a diagnosis, therapy or clinical advice. See the support page if you need help right now.

5. Who processes data on our behalf

Faye uses a small number of service providers. Each one is contractually bound to process data only on our instructions, and none of them may use it for their own purposes.

Apple
App distribution, in-app purchases and push notification delivery (APNs). Apple's own privacy policy governs your Apple ID and payment; we never receive those details.
RevenueCat
Subscription state — whether a purchase is active, expired or restored. It receives a purchase receipt and an anonymous identifier, never your onboarding text or your board.
Railway
Hosting for the server and the PostgreSQL database that holds your encrypted profile and your scenes.
Anthropic (Claude API)
Writes the scene text from your profile. Content sent through the API is processed to return that scene and is not used to train models.
OpenAI
Turns the finished scene text into the narrated audio you hear. It receives the scene text only — not your board, not your profile. API content is not used to train models.
Google (Analytics)
This website only, and only if you allow it — never the app, and never anything you wrote in it. Details in §13.
Cloudflare
Delivers and protects this website. Aggregate traffic statistics at the network level; no cookie, no individual identification. §13.

If a device cannot get a rendered narration, the app falls back to your iPhone's own on-device speech synthesis, and nothing leaves the phone for that.

6. International transfers

The providers above operate in the European Union, the United Kingdom, the United States and other countries. Where data leaves your country, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism in the provider's terms. You may ask us for the details that apply to your case.

7. Legal bases for processing

For people in the European Economic Area, the United Kingdom and Switzerland, we rely on:

8. How long it is kept

9. Deleting everything

Open Faye, go to Settings → Erase account. The server deletes your row and everything attached to it, and the app then wipes its local copy — in that order, so nothing can be stranded on the server with nobody able to remove it.

Deleting the app alone does not erase the server-side data, because the device key that identifies you survives in the iOS Keychain. Use the in-app option, or write to [email protected] and we will do it for you.

Cancelling a subscription is separate and happens in iPhone Settings — see the terms.

10. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or receive it in a portable form. Write to [email protected]. We answer within 30 days and never charge for it.

Because there is no account, we verify a request through the app itself rather than by asking you for identity documents — we would rather not hold those either.

EEA and UK

You have the rights in Articles 15–22 GDPR, including the right to lodge a complaint with your local supervisory authority. You do not have to come to us first.

Türkiye (KVKK)

Under Article 11 of Law No. 6698, you may learn whether your personal data is processed, request information about it, ask for correction or erasure, and object to results produced solely by automated analysis. Requests go to [email protected].

California and other US states

You have the right to know, delete, correct and to opt out of "sale" or "sharing" of personal information. Faye does not sell or share personal information, and has never done so, including for cross-context behavioural advertising. We do not use sensitive personal information for inferring characteristics. Exercising these rights will never get you worse service.

11. Children

Faye is not directed at children. You must be at least 16 years old, or the minimum age of digital consent in your country if that is lower and a parent or guardian agrees. We do not knowingly collect data from children below that age; if you believe a child has used Faye, write to us and we will erase it.

12. Security

Device identity rests on a hardware-backed key that cannot be extracted from the phone. Requests are signed, so a request that was tampered with is rejected rather than served. Sensitive fields are encrypted at rest, and on-device data uses iOS complete file protection, which means it is unreadable while the phone is locked. No system is perfect, and we will not claim otherwise — but there is deliberately very little here worth stealing.

13. This website

The app and the website are separate. Nothing in this section touches your board, your scenes or anything you told Faye — those live in the app and are covered above.

Nothing loads until you say so

fayemanifest.com asks once, in a bar at the bottom of the page, whether it may count your visit. Until you answer Allow:

Declining costs you nothing: every page behaves identically either way. Your answer is kept in your browser's local storage, on your device, so you are not asked again. Clearing this site's data brings the question back.

One measurement does run either way, and it is fair to name it plainly: our delivery network adds a small Cloudflare Web Analytics script to the page. It counts page views and page-speed timings. It sets no cookie, stores no identifier, and builds no profile — Cloudflare states it does not track individuals across sites and does not sell this data — which is why it is not put behind the consent bar. A tracker blocker stops it, and the page is unaffected. See Cloudflare's description of what it measures.

If you allow it

The site loads Google Analytics 4 through Firebase. It records which pages are read, roughly where in the world the visit came from, the referring site, and the browser and device type. It sets analytics cookies and receives your IP address, which Google truncates before storing. It measures pages, not people: there is no account for it to attach to, no advertising audience is built from it, and it is never joined to anything from inside the app.

Google acts as our processor here, under its data processing terms, and the transfer safeguards in §6 apply. Its own handling is described in Google's privacy policy. You can withdraw consent whenever you like: clear this site's data and choose No thanks when the bar returns, or use Google's opt-out add-on. A tracker blocker also simply works — the page is built to survive one.

Fonts and images are served from this domain in every case, so they reveal nothing to anyone else.

Delivery and network

The site is served through Cloudflare, which sits in front of the origin and keeps aggregate traffic statistics — request counts, countries, which paths were fetched. That happens at the network level for every visitor, consent bar or not, because it is how the site is delivered and protected at all; it sets no cookie and identifies no individual. The same applies to the Web Analytics script described above. See Cloudflare's privacy policy. Short-lived access logs are kept as described in §2.

14. Changes

If this policy changes in a way that affects what we do with your data, the effective date at the top changes and the app tells you before the change applies. Previous versions are available on request.

15. Contact

Privacy questions, data requests, corrections, complaints: [email protected].