Back to home
Privacy policy

Privacy Policy

Effective: January 1, 2026 · Last updated: January 1, 2026 · Version 1.0

Privacy Policy Terms of Service EULA

Do ("we", "the app") is an iOS app for recording your personal sex life and intimate relationships. We know this information is deeply private and highly sensitive, so privacy has been a first principle since day one: no account is required, your records stay on your device by default, protected by iOS, and our servers never receive, store, or can read any of your record content.

This Privacy Policy explains in detail what information we do (and do not) process, for what purposes, on what legal bases, how long we keep it, and what rights and controls you have over your data. Please read it in full before using the app, and contact us if you have any questions.

Contents

1. Overview and scope

This policy applies to your use of the Do iOS app and its companion Apple Watch app, widgets and related features. It does not apply to any third-party product or service, even if you access it through the app.

The app is built local-first: unless you actively enable iCloud sync or couple sharing, your data never leaves your device.

2. Our privacy principles

We designed the whole product around the following principles, which run through every section of this policy:

  • ·Data minimization: process only what is necessary for functionality, on the device.
  • ·No account: no sign-up; no email, phone number, social login or account identifier collected.
  • ·Local-first: records stay on your device by default, protected by iOS Data Protection.
  • ·No servers of ours: even with iCloud sync on, the data goes to your own private iCloud database. We run no servers of our own and never receive it.
  • ·No ads, no tracking: no advertising or third-party analytics SDKs.
  • ·Never sold: we will never sell or rent your personal information.

3. Categories of information we process

For clarity, we group information into the categories below. Unless stated otherwise, all of it stays on your device (and any private iCloud you choose) and is inaccessible to our servers.

  • ·Record content: the intimate/sex-life records you create — dates and duration, protection, positions and behaviors, location, climax and related counts, ratings, mood text, photos and Live Photos, and nicknames, gender or avatars you set for a partner.
  • ·Preferences and settings: theme and colors, app icon, language, default record mode, app-lock toggle, etc.
  • ·Health data (with permission): heart rate, calories and similar from Apple HealthKit, plus optional workout data written back to Health.
  • ·Location and environmental data (with permission): your location when you create a record, and a weather snapshot from WeatherKit.
  • ·Support communications: the email address and content you provide when you contact us.

4. Sensitive personal information

The content recorded in this app qualifies under most legal frameworks as "sensitive personal information" or a "special category of personal data," and may relate to your sex life, sexual orientation and health.

We process this information only when you enter it, only on your device, and only to provide you the recording feature. We do not transmit it to our servers, do not use it for analytics, profiling, advertising or any commercial purpose, and do not share it with any third party. You can further protect it with an app lock (Face ID / Touch ID / passcode).

5. How we use information

We process your information on your device, only for the following purposes:

  • ·to present, edit and manage your records;
  • ·to generate statistics, trends and heatmaps as insights only you can see;
  • ·with your permission, to read health data to enrich records or write workout data back;
  • ·when you enable it, to sync across your devices via your private iCloud or share with a paired partner;
  • ·to remember your preferences;
  • ·to provide support when you contact us.
  • ·We do not use your information for advertising, profiling or sale.

6. Legal bases for processing

Where laws such as the EU General Data Protection Regulation (GDPR) apply, our legal bases for processing your information include:

  • ·Consent: for processing sensitive information (such as sex-life and health data) and for using system permissions like Health and Location — you can withdraw consent anytime.
  • ·Performance of a contract: as necessary to provide the app features you request.
  • ·Legitimate interests: to keep the app secure and functioning, without harming your rights.
  • ·Because the vast majority of processing happens on your device under your direct control, these bases relate mainly to optional cloud features.

7. Storage and security

We take technical and organizational measures proportionate to the sensitivity of the information:

  • ·On-device protection: records are held in app storage and encrypted at rest by iOS Data Protection.
  • ·App lock: optional Face ID / Touch ID or passcode required to open the app.
  • ·Device-level protection: data is protected by iOS sandboxing and data-protection mechanisms.
  • ·iCloud transport: if sync is on, data is transmitted over encrypted channels and stored in your private iCloud database.
  • ·No method of storage or transmission is completely secure; since data lives mainly on your device, keeping your device and backups safe matters too.

8. iCloud sync in detail

iCloud sync is optional and off by default. If you enable it, the app stores your data via Apple CloudKit in a "private database" tied to your Apple ID. That database is hosted by Apple and accessible only to you; as the developer we cannot read its content.

You can turn off sync anytime, after which data stays local only. Turning off sync does not delete data already synced to your iCloud — use the in-app wipe to remove it.

9. Health data (HealthKit)

With your permission, the app can read data such as heart rate and calories from Apple HealthKit to enrich your records, and with your consent write related workout data back to the Health app.

Data obtained through HealthKit is used only on your device, never uploaded to our servers, and never used for advertising or sold, fully in line with Apple’s HealthKit privacy requirements. You can review or revoke access anytime in Settings › Health › Data Access & Devices.

10. Location and weather

Location recording is optional and off by default. If enabled, the app reads your current location when you create a record to tag the place and logs a weather snapshot via Apple WeatherKit.

Location and weather data are saved only as part of that record, locally and in your private iCloud, and never sent to our servers. You can turn off location recording or revoke the permission in system settings anytime.

11. Couple sharing in detail

Couple sharing is optional. When you pair with a partner, relevant records sync between your devices via Apple CloudKit’s shared-database mechanism, and each of you can write your own perspective.

Data moves between your iCloud and your partner’s; we cannot read shared content. Note: once shared, your partner can see the corresponding records on their device. You can unpair anytime; afterward new records are no longer shared and already-shared data is handled per CloudKit’s rules. Only record information about another person with their informed consent.

12. Third-party and Apple services we use

The app integrates no third-party ad or analytics platforms. To function, we rely only on the following Apple system services, each governed by Apple’s privacy policy:

  • ·Apple iCloud / CloudKit — optional sync and couple sharing;
  • ·Apple HealthKit — heart rate and health data (with permission);
  • ·Apple WeatherKit — weather at the time of a record (needs location);
  • ·Apple MapKit and Location Services — place tagging and reverse geocoding (with permission);
  • ·Apple StoreKit — subscriptions and in-app purchases (payment handled by Apple; we never touch your payment details).

13. Sharing and disclosure

We do not sell or rent your personal information, nor share it for third parties’ marketing. Because we generally cannot access your record content, in the vast majority of cases we have no data to disclose.

In the rare cases required by law (e.g. a valid court order), we can only provide the limited information we actually hold — which typically does not include your record content, as it is not on our servers.

14. Data retention and deletion

Your data stays on your device (and any iCloud you choose) until you delete it. We set no fixed retention period because we do not hold your records.

  • ·You can delete individual records or wipe all data in one tap in Settings;
  • ·uninstalling removes local data; to delete iCloud data, use the in-app wipe before uninstalling;
  • ·deletion is permanent;
  • ·we delete email support correspondence within a reasonable period after resolving your request.

15. Your rights and choices

Wherever you are, you have meaningful control over your data, and most rights can be exercised directly in the app:

  • ·Access & export: view and export all your records anytime;
  • ·Rectification: edit any record anytime;
  • ·Deletion: delete some or all data anytime;
  • ·Restriction & withdrawal of consent: turn off iCloud sync, couple sharing, or revoke Health/Location permissions anytime;
  • ·Objection: since we do no profiling or targeted marketing, no extra action is needed.

16. Regional rights

Depending on where you live, you may have additional rights:

  • ·EEA / UK (GDPR): rights of access, rectification, erasure, restriction, data portability and objection, and the right to complain to your local data-protection authority.
  • ·Mainland China (PIPL): rights to access, copy, correct and delete personal information, to withdraw consent and to deactivate; processing sensitive personal information requires your separate consent.
  • ·California, USA (CCPA/CPRA): rights to know, delete and correct, and not to be discriminated against for exercising rights; we do not "sell" or "share" your personal information as defined by law.
  • ·Most rights can be exercised in-app; for the rest, contact us at support@xiaoyehua.dev and we will respond within the period required by applicable law.

17. International data transfers

Because data stays on your device by default, cross-border transfers usually do not occur. If you enable iCloud features, storage and transmission are handled by Apple per its infrastructure and privacy policy, which may involve Apple data centers in different regions.

18. Children’s privacy

The app is designed for adults, rated 17+ on the App Store, and requires users to be at least 18 (or the age of majority where they live). We do not offer the service to minors and do not knowingly collect their information. If you believe a minor has provided us information, contact us and we will delete it.

19. Data security incidents

Although we hold almost none of your personal information on servers (greatly reducing breach risk), if a security incident affecting information we do hold occurs, we will notify affected users and relevant regulators within the period required by applicable law.

20. Changes to this policy

We may update this policy from time to time to reflect changes in features, law or practice. For material changes, we will update the "Last updated" date and version at the top of this page and, where appropriate, notify you in-app. We recommend reviewing this page periodically. Continuing to use the app after changes take effect means you are aware of the updated policy.

21. Contact us

If you have any questions, requests or complaints about this policy, your data or your rights, contact us at:

Email: support@xiaoyehua.dev. We will respond within a reasonable period and as required by applicable law.