Privacy policy

Last updated 3 August 2026 · Applies to version 1.0 of the iOS app, its widget, and its Apple Watch app.

The short version

The app has no server. Nothing you log reaches me, because there is nowhere for it to go.

Mood Minute is made by Nathan Kettles, an individual developer based in South Africa, who is the data controller for the purposes of the UK GDPR, the EU GDPR and South Africa's Protection of Personal Information Act.

There is no account to create, no email address to hand over and no password. Your moods are written to Apple Health, on your device, under your Apple account. Everything Apple Health cannot hold — your notes, your settings, your record of purchase — is stored in your own iCloud account, in a private database only your devices can reach.

The app collects no analytics. It contains no analytics SDK, no crash-reporting SDK and no third-party SDK of any kind. Its App Store privacy label is Data Not Collected, and that stops being true the moment any such SDK is added, which is why none is permitted.

Apple Health data

One type of health data is requested — Apple's State of Mind — and no others.

The app asks for permission to read and write exactly one HealthKit type:

  • HKStateOfMind

That is Apple's own State of Mind type, the record behind the mood check-in built into the Health app. Both read and write access are requested.

  • Write. Each mood you log is saved as a State of Mind sample in Apple Health.
  • Read. The app reads State of Mind samples so moods you logged elsewhere — in Apple's Health app, or on your Watch — appear in your history rather than being invisible to it.

No other health data is requested, read, written or inferred. The app does not ask for sleep, steps, activity, heart rate, weight, cycle tracking, mindful minutes, or any other type. It cannot see them.

The only information the app attaches to a sample is a private identifier and a version number, so that correcting an entry updates the existing sample instead of creating a second one. No note text and no free text is ever written into Apple Health.

Health data in Apple Health is governed by Apple's protections and your device's settings, not by this app. The app never sends health data anywhere, and never shares it with the developer or with any third party.

What the app stores itself, and where

Apple Health has no field for free text, so notes, settings and a few device details are the app's own.

Synced through your private iCloud database — reachable only by your own Apple devices, never by the developer:

WhatNotes
Your notesEncrypted before they are stored. See below.
Your settingsReminder preferences, scale granularity, region override.
Your record of purchaseWhether the paid features are unlocked.

Stored only on the device, never synced anywhere:

WhatNotes
Emotion and context labels on an entryDevice-local by design.
Queued Apple Health operationsWrites that have not yet succeeded, retried on the next launch.
Device stateWhether this device is connected to Apple Health.

How notes are protected

Note text is encrypted on your device under a key held in your own iCloud Keychain — and this is deliberately not an end-to-end-encryption claim.

The key is generated on your device, never transmitted to the developer, never escrowed anywhere, and never shown to you.

Being direct about the limits of that, because it matters:

  • The encryption is applied to the note field itself, on top of Apple's own protection of the database. It is not a claim that the whole system is end-to-end encrypted.
  • Whether Apple itself can access data in your iCloud account depends on whether you have Advanced Data Protection turned on in your Apple account settings. With it on, Apple states it cannot read the contents. Without it, Apple can decrypt iCloud data after authenticating you. The app has no way to detect which applies to you — Apple exposes no such signal — so no unconditional claim is made in either direction.
  • Health data in Apple Health has its own protections, which are Apple's and are stronger than anything this app applies. Nothing here should be read as a claim that the app's protection is better than Apple Health's. It is the weaker copy, applied only to the parts Apple Health cannot carry.

Using the app without Apple Health

Connecting is optional, and every free feature works either way.

If you decline, the app runs in a standalone mode where entries are held in the app's own storage and nothing is written to Apple Health. If you later choose to connect, moving existing entries into Apple Health is a deliberate act you initiate. It never happens automatically.

What the app does not do

No account, no analytics, no location, no server, and no assessment of your mental health.

  • No account. No sign-up, no email address, no password, no profile.
  • No analytics, no tracking, no advertising. No SDK, no identifier for advertisers, no attribution, no fingerprinting.
  • No location. Regional helpline routing uses your device's region setting, which you can override manually in the app. It never uses Location Services, never uses IP geolocation, and never uses your App Store storefront.
  • No server of ours. The app has no backend. Outside of Apple's own iCloud and StoreKit services it makes no network requests at all — including on the path that saves a mood, and including on the path that shows you support contacts.
  • No data sold or shared. There is no third party to sell it to.
  • No assessment of your mental health. The app records what you tell it and shows it back to you. It does not detect, diagnose, screen, assess or monitor anything, and nothing you log causes the app to react to you.

The clinician report

It makes a PDF of what you logged, on your device, and the app sends it nowhere.

The paid clinician report covers a date range you choose, so you can hand it to a GP or a therapist. It is a record of your own entries and counts, and it offers no interpretation of them.

The file is written into a private folder inside the app, protected so it cannot be read while your device is locked. That folder is emptied before each report is made and again when you close the review screen, so at most one file exists and only while you are looking at it. The PDF carries no author name.

Handing it over uses Apple's own share sheet, and every choice about where it goes is yours.

This website

The app and this website are two different things, and this section is about the website.

moodminute.shyp.fyi is served through Cloudflare, which counts page views and keeps aggregate traffic figures — how many people loaded a page, roughly where from, and which browser. It sets no cookie and does not follow you to other sites.

The app is not this website. Nothing in the app talks to Cloudflare, or to any server at all.

Notifications

Reminders are scheduled locally by iOS. There is no push notification capability at all.

The app sends nothing to Apple's push service and holds no push token. Reminder settings never leave your iCloud account.

Purchases

Apple handles payment. The app learns only whether a purchase exists on your Apple account.

It never sees your name, your payment card, your billing address or your purchase history. Tips unlock nothing and are recorded nowhere. Apple's own privacy policy governs the transaction: apple.com/legal/privacy.

Support contacts

The helpline list is bundled with the app, works offline, and is only ever opened by you.

It requests no permission and makes no network request. Choosing a contact hands the phone number, message or web address to iOS, which opens it in the Phone, Messages or browser app. From that point you are dealing with that organisation, not with this app, and their privacy practices apply.

Getting your data out, and deleting it

Export and deletion are free, they are in the app, and they do not depend on anyone answering an email.

  • Export is free and staying free. It produces a complete machine-readable file of everything the app holds, with a check you can recompute yourself confirming nothing was left out or altered.
  • Deletion is available in the app and produces a written record of what was deleted, from where, and anything that could not be reached.
  • Apple Health samples can also be deleted directly in Apple's Health app, independently of this app, at any time.
  • Removing the app removes its device-local data. Data in your private iCloud database is removed by deleting it in the app, or by removing the app's data from your iCloud account in iOS Settings.

Because the developer holds none of your data, there is no request to make of him to retrieve or erase it — the controls are in your hands and in Apple's, and they work whether or not he is reachable.

Your rights

Access, correction, erasure, portability and objection — exercised directly through the app's own export and deletion features.

Those rights arise under the UK and EU GDPR and under POPIA. Exercising them in the app is faster than any request process and does not depend on anyone answering an email.

If you believe something here is wrong, or you want to raise a complaint, use the address below. UK users may complain to the Information Commissioner's Office; EU users to their national supervisory authority; South African users to the Information Regulator.

Who to contact

Nathan Kettles is the data controller.

info@shyp.fyi

The app is not directed at children and collects nothing that would identify anyone, of any age.

If this policy changes, the date at the top changes with it and the updated version is published at this address. The policy is also kept in the app's source repository, so its history is a matter of record rather than a claim.