Plain-language policy

Privacy, without the fog.

Offramp is designed to keep sensitive content on your iPhone. This policy explains what the current app stores, what can leave the device, and where deletion has limits.

Effective August 11, 2026Operator: ElseBranch Inc.

1. Scope and the short version

This policy applies to the Offramp iPhone app and this website. The current app does not require an account and does not contain an app backend, advertising SDK, analytics SDK, or third-party tracking SDK. It does not automatically upload Tomorrow Box notes, voice recordings, Screen Time selections, or beta study diagnostics.

Offramp’s own app code has two deliberate sharing paths: using the iOS share sheet to send an optional diagnostic export, or contacting support through your own email service. Device backups, keyboards, dictation, Apple system services, TestFlight, and the website host are separate and are explained below.

2. Data the app handles

Tomorrow Box notes

Tomorrow Box lets you save a short typed note or a voice note for later. Typed content and note metadata are stored through iOS secure storage. Voice recordings are local files in the app’s temporary cache. The app does not transcribe, analyze, answer, or upload those recordings. Voice files do not have additional app-layer encryption beyond protections provided by iOS and the device.

Offramp keeps no more than 12 Tomorrow Box items. Note content is not added to Screen Time shared state, notifications, or optional diagnostics. The morning reminder uses generic text and does not include your note.

Preferences and local notifications

Offramp stores local settings such as its Quiet guidance preference, reminder recovery state, and Screen Time setup state. If you allow notifications, the app schedules one quiet, generic reminder on the device for the next local 8:30 a.m. after a Tomorrow Box save. The current app does not register for marketing push notifications.

Apple Screen Time choices

If you enable the Screen Time feature, Apple’s Family Controls picker provides opaque selection tokens for the apps, categories, and websites you choose. Offramp displays selection counts; it does not receive their names or identities. The tokens, nightly schedule, enabled state, same-night pause state, and a short-lived rescue trigger are stored in an iOS App Group so the app and its Screen Time extensions can coordinate. The current code does not collect browsing activity or Screen Time usage reports.

Microphone, motion, and local audio

Microphone access is requested only when you choose to record a voice note. Motion access lets the app recognize a face-down phone during an active Rescue; raw motion samples are used for that interaction and are not saved as a history. Typed and manual alternatives are available. This internal TestFlight build is Quiet-only and contains no generated spoken-guidance files. If you record a Tomorrow Box voice note, playback uses that local, user-created recording; the app does not stream guidance audio.

Optional beta study diagnostics

Study diagnostics are off by default. If you explicitly turn them on, Offramp stores a small local attempt record: trigger source; start time rounded to a second; study date and attempt number; the first two route choices and their completion or skip outcomes; whether more steps followed; phone-down method; dark-phase result and duration; exit reason; and whether an interrupted attempt was recovered after restart.

These records do not include Tomorrow Box content, voice recordings, selected-app identity, browsing activity, or a device or install identifier. They are not described as anonymous because timing and behavioral fields may still be distinctive when you choose to share them.

3. When information can leave the device

  • Diagnostic sharing: Offramp creates a JSON export only after you tap Share and opens the iOS share sheet. You choose the destination. The app deletes its temporary export after the share sheet closes, but it cannot delete copies held by the destination, recipient, or another app.
  • Support email: If you email support, the operator receives your email address and whatever you include. Your email provider and the operator’s email provider process that message under their own terms and policies.
  • Keyboards and dictation: Offramp disables autocorrection and spellcheck for typed Tomorrow Box capture, but system dictation and third-party keyboards are governed by your iOS and keyboard settings.
  • Apple services and backups: iOS handles permissions, Screen Time, notifications, secure storage, and device backup behavior. App documents and settings may be included in a device backup. Voice files are kept in the cache, which iOS generally excludes from ordinary iCloud backups and may clear early.
  • TestFlight beta testing: If you install a beta through Apple’s TestFlight, Apple provides the developer operational beta metrics such as installs, sessions, and crashes. Feedback you submit through TestFlight can include your comments, a screenshot, and technical details about the build, device, iOS, and app activity; depending on the testing relationship, it may also identify your tester account or email. Avoid including Tomorrow Box content or other private information in feedback screenshots or comments. Apple processes TestFlight data under its own terms and privacy policy.

The current app code does not sell data, use it for advertising, or share it with data brokers. If that product design changes, this policy and the App Store privacy details must be updated before the change is released.

4. Retention and deletion

Tomorrow Box

You can delete one note or use Delete all in the app. Items become eligible for removal after 36 hours and are removed when Offramp next reads the Tomorrow Box; this is not a background timer that runs while the app is closed. iOS may remove cached voice files earlier. Missing voice files are cleaned from the list the next time it is read.

Study diagnostics

The local log is bounded to 64 attempts and 128 KiB. Records older than 14 days are removed when the app next runs its diagnostic retention cleanup. Turning collection off stops future collection but does not erase existing attempts. Use Erase diagnostic log for that. If Offramp cannot verify deletion, it reports the problem and keeps collection off until cleanup succeeds.

Screen Time and preferences

Screen Time configuration remains locally available until you change, disable, or clear it, or iOS removes the app’s data. You can also revoke Screen Time, microphone, motion, or notification permissions in iOS Settings. Other local preferences remain until you change them or their storage is removed.

Uninstall and backup caveats

Uninstalling usually removes files in the app sandbox, but iOS Keychain items used by secure storage can survive uninstall and reinstall. When practical, delete Tomorrow Box and diagnostic content inside Offramp before uninstalling. A reinstall marker prevents an old diagnostic-consent setting from silently turning collection back on. Offramp cannot remove copies already included in a device backup, sent through the share sheet, or included in support email.

5. This website and support

The website’s own code does not intentionally set cookies and does not include analytics, advertising trackers, account sign-in, or a contact form. Its hosting and security providers may set cookies that are necessary to deliver and protect the site and may process ordinary request information such as IP address, browser details, and request time for delivery, security, and operational logging under their own policies.

Support messages are used to understand and respond to your request. Do not send Tomorrow Box content, voice recordings, Screen Time selections, or a diagnostic export in an ordinary support email. Until a support-email retention schedule is adopted, messages may remain in the support mailbox until they are manually deleted. You may request deletion, but provider backups and obligations that require retaining a message may limit or delay removal.

6. Security

Offramp uses iOS storage and permission controls and limits the data it keeps. No method of storage or transmission eliminates all risk. Keep your iPhone and iOS account protected, and use non-sensitive content if you are not comfortable with the device, backup, keyboard, or email protections available to you.

7. Changes to this policy

This policy may change as Offramp changes. A revised version will show a new effective date. Material changes to app data handling should be reflected here and in the App Store privacy information before release.

8. Contact

Questions about this policy or privacy requests can be sent to ElseBranch Inc. at legal@elsebranch.com. Product support remains available at iserican@gmail.com. Most app data exists only on your device, so ElseBranch Inc. cannot remotely view or delete it; the support page explains the in-app controls.