Privacy Statement — Detouched
Last updated: 30 June 2026
The short version. Detouched is a private mood and self-insight journal. We do not sell your data. We do not rent, trade, or share it with anyone for their own purposes. We do not use it for advertising, profiling, or to train any model. We use it for one thing only: to give the app's features back to you. The only parties that ever touch it are the named service providers that operate the app on our behalf, and the only time we disclose it outside that circle is when we are compelled to by valid legal process. This statement explains, in plain English, exactly what we collect, why, and the rights you have.
1. Our promise
We built Detouched to be a place you can be honest with yourself. That only works if your data stays yours. So, plainly:
- We do not sell, rent, or trade your personal data.
- We do not share it with third parties for their own purposes.
- We do not use it for advertising, behavioural profiling, or to train artificial-intelligence or machine-learning models.
- We use it only to provide the app's features to you.
- The only parties who handle it are the service providers that run the app for us (named in Section 6), acting solely on our instructions.
- We disclose it outside that circle only when compelled by valid legal process, as described in Section 7.
2. Who we are and scope
Detouched ("the App") is developed and operated by code380, a small Ukrainian mobile studio ("we", "us", "our"). This statement applies to the App on iPhone and iPad and to the cloud services that support it. It does not apply to any third-party service you reach from outside the App. For privacy questions, or to exercise any right described here, email hello@code380.com.
3. Data we collect
Detouched is local-first: your journal lives primarily on your device. The data below is what the App stores and, if you sign in, syncs to your account in our cloud backend so it is available across your devices.
- Your mood ratings and journal entries. The mood dimensions you rate (on a 1–5 scale, across up to ten axes, including a sexuality/libido axis), and any free-text notes you write.
- Life events you log. Events such as sleep, alcohol, exercise, intimacy, conflict, payday, menstruation, ovulation, and illness. This includes information about your health and your sexual health — for example libido, intimacy, menstruation, ovulation, alcohol use, and illness. Under the EU/UK GDPR this is "special-category" data (Article 9). You provide it only by choosing to enter it, and you decide what, if anything, to record.
- Account data. If you create an account, your email address and a user identifier (a UUID) used to authenticate you. Authentication is by email and password or by Google Sign-In (Sign in with Apple is planned).
All of the above is entered by you. Detouched does not infer or import this data from anywhere else.
4. What we do not collect
To be precise about what is not happening:
- No analytics, advertising, crash-reporting, or tracking SDKs of any kind.
- No advertising identifier (IDFA), no App Tracking Transparency prompt, and no cross-app or cross-site tracking.
- No access to your location, camera, microphone, contacts, photos, or HealthKit — the App declares no such permissions.
- The menstrual-phase signal the App uses is derived only from the events you log yourself, not from HealthKit or any external source.
5. How we use your data
We use your data solely to provide the App's features to you:
- To store and display your entries.
- To sync your entries across your own devices when you are signed in.
- To compute the correlations and "insights" the App shows you — relating your mood to your logged events and to external factors such as moon phase (computed on your device) and the geomagnetic Kp index (a public, global value fetched from NOAA). These results are shown only to you.
- To operate and secure your account.
We do not use your data for any other purpose. We do not profile you for advertising, and we do not use your content to train models.
6. Legal basis for processing (GDPR)
If you are in the EU/EEA or the UK, we rely on the following legal bases:
- Performance of a contract. Processing needed to deliver the core features you ask for — storing your entries, syncing them, and operating your account (Article 6(1)(b)).
- Explicit consent for special-category data. Your health- and sexual-health-related entries (libido, intimacy, menstruation, ovulation, alcohol, illness, and similar) are processed only on the basis of your explicit consent (Articles 6(1)(a) and 9(2)(a)), which you give by choosing to enter that information. You can withdraw that consent at any time by deleting the data or your account; withdrawal does not affect processing carried out before withdrawal.
- Legitimate interests. Limited to keeping the service secure and functioning (for example, preventing abuse), where these interests are not overridden by your rights (Article 6(1)(f)).
7. Service providers and sub-processors
We use a small number of providers to run the App. They process your data only on our instructions, under contractual terms that bind them to protect it, and only to operate the service:
- Supabase — cloud hosting, authentication, and database. Stores your synced account data in a Postgres database protected by Row-Level Security, so each user can access only their own rows.
- Google — Google Sign-In only, used to authenticate you if you choose that option. Google is not given access to your journal content.
- NOAA Space Weather Prediction Center — the App fetches the public, global geomagnetic Kp index from NOAA over HTTPS. This request sends no personal data and no location; NOAA receives nothing about you.
The App contacts only these hosts, and only over encrypted (HTTPS) connections.
8. Sharing and disclosure
We do not sell, rent, trade, or share your personal data with third parties for their own purposes or for marketing. The only circumstances in which your data leaves our control are these, and they are exhaustive:
- (a) Service providers acting for us. The providers named in Section 7, processing your data on our behalf to run the App.
- (b) When required by law. Where we receive a valid subpoena, court order, warrant, or other lawful legal process, or where disclosure is necessary to comply with a legal obligation, or to protect the rights, property, or safety of our users or others, or to prevent fraud or imminent harm. In every such case we will disclose only the minimum required, and where we are lawfully permitted to do so we will endeavour to notify the affected user.
- (c) Business transfer. If code380 is involved in a merger, acquisition, or sale of assets, your data may transfer to the successor entity, which will remain bound by privacy protections equivalent to those in this statement.
9. International transfers
Your data may be processed on servers located outside your country of residence. Where data is transferred out of the EU/EEA or the UK, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — where these are required by law.
10. Data retention
We keep your data for as long as you use the App or maintain an account, so that your journal remains available to you. When you delete your data or request account deletion, we remove the corresponding cloud data. Data stored only on your device is removed when you delete the App.
11. Security
We protect your data with encryption in transit (HTTPS/TLS), Row-Level Security in the database so you can reach only your own rows, and the device Keychain for session credentials. That said, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Your rights
Depending on where you live, you have rights over your data. Under the EU/UK GDPR these include the rights to access, rectification, erasure, data portability, restriction of processing, objection to processing, and to withdraw consent at any time. You also have the right to lodge a complaint with your data-protection authority.
If you are a California resident, you have the right to know what we collect, to request deletion, and to non-discrimination for exercising your rights. We do not sell your personal information.
To exercise any right, email hello@code380.com. Please note that our cloud backend is shared with our sibling app, GoSlow, which uses the same authentication system. Because your account is common to both, deleting your account may also affect your data and access in GoSlow. We will make this clear when you ask us to delete your account.
13. Data location and deletion mechanics
You can remove your data in two ways:
- Local data: deleting the App from your device removes the data stored on that device.
- Cloud account data: account deletion is currently handled by emailing hello@code380.com (in-app deletion is planned). On receiving your request we delete your account and the data associated with it.
Note the sync caveat: if you delete the App but remain signed in elsewhere, data synced to your account remains until you request account deletion.
14. Children
Detouched is not directed to children. Because it handles sensitive information, the minimum age to use the App is 16 (see our Terms of Service). We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
15. Changes to this statement
We may update this statement from time to time. When we do, we will post the revised version here with a new "Last updated" date. Your continued use of the App after a change takes effect constitutes acceptance of the updated statement.
16. Contact
Questions about your privacy, or want to exercise a right? Email hello@code380.com.