Privacy

App privacy.

Sounds from Beyond is a story you read on your phone. It has no accounts, no sign-in, no social features, and no advertising. This policy explains the small amount of information the app does handle, and the rather larger amount it deliberately does not.

It is written to be read, not to be survived. If something here is unclear, please ask — the contact address is at the bottom.

The short version

What the app collects

The technical details in that last row are added automatically by PostHog’s software. We removed the ones we had no use for, so the app does not send your time zone, screen dimensions, or whether you are on Wi-Fi or cellular.

If the app crashes

When the app stops unexpectedly, it records a technical report — the point in the code where it failed, your device model and iOS version, and the part of the story you were reading. That report is sent the next time you open the app, not at the moment of the crash.

It exists so a crash can be found and fixed. It contains no personal information and no part of the story’s text, and it is not used to measure anything about you. Deleting the app discards any report still waiting to be sent.

Apple separately provides crash reports to developers under its own settings, which are controlled in iOS Settings under Privacy & Security → Analytics & Improvements, and are nothing to do with this app.

What the app does not collect

No name, email address, phone number, contacts, photos, location, health data, biometrics, or files. No advertising identifier (IDFA), and no device serial number. No microphone or camera access. Nothing you type. No part of the story’s text is ever sent anywhere — the reading data above refers to chapters and scenes by internal identifiers such as ch02, not by their words.

One identifier is worth being exact about rather than silent on. iOS gives every app developer a per-device value called the identifier for vendors (IDFV). Our purchase provider, RevenueCat, attaches it to the technical requests it makes when it checks or restores a purchase. We do not ask for it, we do not store it, we do not use it to measure anything, and it is never attached to the reading data described above or sent to PostHog. It is the same value every app from the same developer sees on your device, it resets when you delete all of them, and it cannot be used to identify you across other companies’ apps.

The identifier

To tell one reading session from another — to know whether one person read three chapters or three people read one each — the app creates a random identifier for the installed copy of the app.

Being accurate about what this is: the identifier is not anonymous, and we would rather not use that word for it. Its whole purpose is to tell one installation apart from another, which means the reading data is pseudonymous — not linked to your name, but still capable of distinguishing your copy of the app from someone else’s. Under EU law that counts as personal data, and the sections below treat it as such.

The practical consequence: there is no name, email address, or account attached to it, so we cannot look up “your” data from a request alone. We have nothing to search by. If you have your identifier and send it to us, we can act on it — see “Your choices” — and if you simply want the collection to stop, that section explains what achieves it immediately.

Your choices

There is no analytics switch inside the app, and it would be misleading to imply otherwise. Deleting the app is the control that works. It stops everything at once and removes the identifier with it, and because a reinstall creates a new identifier that cannot be connected to the old one, nothing survives to be picked back up.

If you would rather object without deleting anything, write to the address at the bottom of this page. You should know what that can and cannot achieve. The reading data carries no name or email address, so a request on its own gives us nothing to search by, and we would rather say that than offer a process that quietly does nothing. If you are able to tell us which identifier is yours, we will find that data and delete it.

Purchase records are separate and are not affected by any of this — they are how your purchase stays valid, and losing them would lock you out of a story you paid for.

Apple’s own controls are also yours, in iOS Settings under Privacy & Security.

Who else is involved

Apple sells you the app and processes the payment. It does that as the store, under its own privacy policy and its own terms with you, not on our behalf — we never see your payment details.

Two other companies process data on our behalf, and are bound by contract to use it only to provide their service to us and to protect it to at least the standard described in this policy. Neither is an advertising company, and neither is permitted to sell this data or combine it with data from other apps.

Where the data is held, and for how long

Reading data is processed on servers in the European Union. It is kept for up to twelve months and then deleted. Purchase records are kept for as long as the purchase is valid, because restoring a purchase depends on them.

Children

The app is rated for older readers and is not directed at children. It does not knowingly collect information from anyone under the age required by the rating shown on its App Store page.

If you are in the EU or UK

The lawful basis for the reading data is legitimate interest — understanding how a story is read in order to improve it — balanced against a deliberately minimal design: no identity, no name or email address, no tracking, no advertising, no sharing, no profiling, no combining with anything else, and an identifier that reaches no other app and dies with the install. The lawful basis for purchase records is performance of a contract: you bought something and it has to keep working.

You have the right to object to the reading data being collected, and deleting the app gives that immediate effect. You also have the right to complain to your data protection authority.

On access, correction, and deletion, the position is the one Article 11 of the GDPR describes. We hold no information that identifies you, and we are not required to acquire any in order to create a way of finding you. So a bare request gives us nothing to act on. But those rights do not disappear: if you supply the identifier for your installation, we can locate that data and act on it, and we will. We simply cannot work backwards from a name we never had.

Changes

If this policy changes, the date at the top of this page changes with it, and the previous wording stays in the project’s version history. A change that affects what the app collects will always ship as part of an app update, so the App Store release notes for that version will say so.

Who we are, and how to reach us

Sounds from Beyond is an independent studio of one, and is the data controller for everything described in this policy. Questions, objections, or anything unclear: use the address above. It reaches a person, not a queue.

The developer’s legal name and postal address are held by Apple and shown on the App Store listing for this app, which is where the EU Digital Services Act requires them to appear.