Privacy
App privacy.
Last updated August 15, 2026
Sounds from Beyond is a story you read on your phone. It has no accounts, no sign-in, no social features, and no advertising. This policy explains the small amount of information the app does handle, and the rather larger amount it deliberately does not.
It is written to be read, not to be survived. If something here is unclear, please ask — the contact address is at the bottom.
Looking for the website instead? The website privacy notice covers this site; this page covers the iPhone app.
The short version
- The app never asks who you are, and cannot find out.
- It does not track you, in the App Store’s sense or any other. There is no advertising identifier, no ad network, no data broker, and no App Tracking Transparency prompt — because there is nothing to prompt about.
- It records that a purchase happened, so the story you bought stays unlocked.
- It records how the story is read — which chapter, how far, where people stop — so it can be made better. That carries no name or account, only a random identifier for the installed app, and deleting the app ends it completely.
- Nothing you type, and no part of the story text, ever leaves your device.
What the app collects
| What | Why | Leaves your device? |
|---|---|---|
| Your reading position, choices, and settings | So you can put the phone down and pick up where you left off | No. Stored only on your device |
| That the story was purchased or restored | So what you paid for stays unlocked, including on a new phone | Yes — to Apple and RevenueCat |
| Which chapter and scene you reach, and where you stop reading | To find the places the story loses people, and fix them | Yes — to PostHog |
| Whether you use the narration, and the settings you change | To know whether the spoken version is worth what it costs to make | Yes — to PostHog |
| Your device model and type, iOS version, language, app version and build, and whether the app is a TestFlight or simulator build | To know which devices to test on and which languages to support | Yes — to PostHog |
| If the app crashes: what it was doing when it stopped | So the crash can be found and fixed, rather than guessed at | Yes — to PostHog |
The technical details in that last row are added automatically by PostHog’s software. We removed the ones we had no use for, so the app does not send your time zone, screen dimensions, or whether you are on Wi-Fi or cellular.
If the app crashes
When the app stops unexpectedly, it records a technical report — the point in the code where it failed, your device model and iOS version, and the part of the story you were reading. That report is sent the next time you open the app, not at the moment of the crash.
It exists so a crash can be found and fixed. It contains no personal information and no part of the story’s text, and it is not used to measure anything about you. Deleting the app discards any report still waiting to be sent.
Apple separately provides crash reports to developers under its own settings, which are controlled in iOS Settings under Privacy & Security → Analytics & Improvements, and are nothing to do with this app.
What the app does not collect
No name, email address, phone number, contacts, photos, location, health data, biometrics, or files. No advertising identifier (IDFA), and no device serial number. No microphone or camera access. Nothing you type. No part of the story’s text is ever sent anywhere — the reading data above refers to chapters and scenes by internal identifiers such as ch02, not by their words.
One identifier is worth being exact about rather than silent on. iOS gives every app developer a per-device value called the identifier for vendors (IDFV). Our purchase provider, RevenueCat, attaches it to the technical requests it makes when it checks or restores a purchase. We do not ask for it, we do not store it, we do not use it to measure anything, and it is never attached to the reading data described above or sent to PostHog. It is the same value every app from the same developer sees on your device, it resets when you delete all of them, and it cannot be used to identify you across other companies’ apps.
The identifier
To tell one reading session from another — to know whether one person read three chapters or three people read one each — the app creates a random identifier for the installed copy of the app.
- It is generated on your device and is a random number. It is not derived from anything about you or your phone.
- It is not Apple’s advertising identifier, and not the identifier for vendors. It is used by this app and nothing else, and it cannot be matched against any other app, on this phone or anywhere.
- Deleting the app deletes it. Reinstalling creates a new one, and the two cannot be connected.
Being accurate about what this is: the identifier is not anonymous, and we would rather not use that word for it. Its whole purpose is to tell one installation apart from another, which means the reading data is pseudonymous — not linked to your name, but still capable of distinguishing your copy of the app from someone else’s. Under EU law that counts as personal data, and the sections below treat it as such.
The practical consequence: there is no name, email address, or account attached to it, so we cannot look up “your” data from a request alone. We have nothing to search by. If you have your identifier and send it to us, we can act on it — see “Your choices” — and if you simply want the collection to stop, that section explains what achieves it immediately.
Your choices
There is no analytics switch inside the app, and it would be misleading to imply otherwise. Deleting the app is the control that works. It stops everything at once and removes the identifier with it, and because a reinstall creates a new identifier that cannot be connected to the old one, nothing survives to be picked back up.
If you would rather object without deleting anything, write to the address at the bottom of this page. You should know what that can and cannot achieve. The reading data carries no name or email address, so a request on its own gives us nothing to search by, and we would rather say that than offer a process that quietly does nothing. If you are able to tell us which identifier is yours, we will find that data and delete it.
Purchase records are separate and are not affected by any of this — they are how your purchase stays valid, and losing them would lock you out of a story you paid for.
Apple’s own controls are also yours, in iOS Settings under Privacy & Security.
Who else is involved
Apple sells you the app and processes the payment. It does that as the store, under its own privacy policy and its own terms with you, not on our behalf — we never see your payment details.
Two other companies process data on our behalf, and are bound by contract to use it only to provide their service to us and to protect it to at least the standard described in this policy. Neither is an advertising company, and neither is permitted to sell this data or combine it with data from other apps.
| Who | What they do | Their policy |
|---|---|---|
| RevenueCat | Keeps track of whether the story has been bought, so it can be restored on a new device | revenuecat.com/privacy |
| PostHog | Receives the reading data described above. Hosted in the European Union | posthog.com/privacy |
Where the data is held, and for how long
Reading data is processed on servers in the European Union. It is kept for up to twelve months and then deleted. Purchase records are kept for as long as the purchase is valid, because restoring a purchase depends on them.
Children
The app is rated for older readers and is not directed at children. It does not knowingly collect information from anyone under the age required by the rating shown on its App Store page.
If you are in the EU or UK
The lawful basis for the reading data is legitimate interest — understanding how a story is read in order to improve it — balanced against a deliberately minimal design: no identity, no name or email address, no tracking, no advertising, no sharing, no profiling, no combining with anything else, and an identifier that reaches no other app and dies with the install. The lawful basis for purchase records is performance of a contract: you bought something and it has to keep working.
You have the right to object to the reading data being collected, and deleting the app gives that immediate effect. You also have the right to complain to your data protection authority.
On access, correction, and deletion, the position is the one Article 11 of the GDPR describes. We hold no information that identifies you, and we are not required to acquire any in order to create a way of finding you. So a bare request gives us nothing to act on. But those rights do not disappear: if you supply the identifier for your installation, we can locate that data and act on it, and we will. We simply cannot work backwards from a name we never had.
Changes
If this policy changes, the date at the top of this page changes with it, and the previous wording stays in the project’s version history. A change that affects what the app collects will always ship as part of an app update, so the App Store release notes for that version will say so.
Who we are, and how to reach us
Sounds from Beyond
[email protected]
Sounds from Beyond is an independent studio of one, and is the data controller for everything described in this policy. Questions, objections, or anything unclear: use the address above. It reaches a person, not a queue.
The developer’s legal name and postal address are held by Apple and shown on the App Store listing for this app, which is where the EU Digital Services Act requires them to appear.