Hangar · Privacy
Privacy Policy
What stays on the device, what a live authored flight sends, and how long service providers retain it. Raw voice never leaves the device.
Available on the App Store · last updated 2026-09-06.
The short version
- No account. You do not sign in. We do not ask for your name, email, contacts, or location.
- No advertising or cross-app tracking. Hangar has no advertising or third-party marketing-analytics SDK.
- Voice stays on the device. Audio is held temporarily in memory for on-device transcription, then discarded. It is not saved as a recording or uploaded.
- Live-flight text scripts the characters. After the in-app consent step, the authored scenario state and settings, practice goal, current turn text, and prior turn text go to OpenAI through our AWS service. Hangar attaches no profile name, email, or account; personal details you include in your words travel with those words.
- Retention has clear boundaries. OpenAI’s abuse-monitoring logs may retain API request and reply content for up to 30 days, or longer where law requires. Our content-free CloudWatch diagnostics expire after 30 days.
- Private practice history stays local. Goals, saved Tomorrow’s Moment plans, flights, and the logbook are stored on-device.
- Anonymous limits protect the service. A random install identifier supports a short-lived daily service limit; short network-address rate-limit rows also expire automatically.
- Purchases are handled by Apple. No payment information touches us.
Apple’s current App Privacy summary: Data Not Linked to You — Diagnostics, Identifiers, and User Content. The detailed flow below explains what that means in practice.
Who we are
Hangar is made by KindAbilities, a family of affirming assistive apps. For any privacy question, email robin@kindabilities.com.
Information Hangar does not ask for or attach
Hangar has no user accounts and no login. It does not request the following details or attach them to practice requests. If you include personal details in live-flight text, those details follow the text-processing flow below:
- your name, email address, phone number, or contacts;
- your location;
- advertising identifiers or any cross-app / cross-site tracking data;
- advertising profiles or third-party marketing-analytics data tied to you;
- payment or card details.
Voice — recognised on-device, then discarded
When you speak, Hangar converts speech to text on your iPhone or iPad. Audio is held temporarily in memory while it is captured and transcribed; it is not saved as a recording or uploaded. An on-device transcription already running may keep that take in memory until processing finishes, even after you cancel or stop waiting. Cancelled or expired results are not used. Hangar does not create a voiceprint or diagnosis. Typing is an equal path. Microphone access can be turned off in device Settings.
The text that scripts the characters
Before the first live flight, Hangar’s consent screen explains the text-processing flow and asks you to agree. To make live practice characters respond, Hangar sends the authored scenario state and settings, the practice goal, and the current and prior turn text (typed or transcribed on-device) to our server in the Amazon Web Services Sydney region, which relays what is needed to OpenAI. This is text and authored settings only — never raw audio. Hangar attaches no profile name, email, or account, but any personal details you include in those words are sent with them.
- OpenAI’s default abuse-monitoring logs may retain API request and reply content for up to 30 days, and longer where law requires.
- OpenAI states that API inputs and outputs are not used to train its models by default unless a customer opts in. We have not opted in.
- Practice text and character replies are not written to our own CloudWatch diagnostics or retained by us as a personal profile.
Anonymous service limits
A random per-install identifier accompanies live turns so an account-free service can apply a daily service limit. It is not tied to a name, email, or account, and the server row expires after the UTC-day window plus a short cleanup period. Our API also receives network information such as an IP address for a short anti-abuse limit; those rows expire after roughly two minutes. Neither is used for advertising, cross-app tracking, or a user profile.
Content-free operational metrics
Amazon CloudWatch records content-free reliability, performance, and cost measurements such as request outcome, processing-stage timing, model usage, token or byte counts, and projected compute cost. These diagnostics contain no practice text, character replies, or raw audio and are retained for 30 days.
What stays on the device
Goals, saved Tomorrow’s Moment plans, flights, and the logbook are saved locally on the device, with no server copy. Tomorrow’s Moment notes are not copied into live-flight requests. That means private practice history belongs to the device — and keeping the device secure matters.
About the 1.3 update. Hangar 1.2 is available on the App Store. The 1.3 update is still being tested and has not been released. Sections marked “1.3 update” describe behavior in that update and apply when you have that version.
1.3 update: offline rehearsal records
Everyday Rehearsals use authored choices and responses on your device. Their saved records include your goal, chosen variation, wording and choices, scene progress, previous and alternative paths, and carry-card lines. These records let you return to a practice. The offline rehearsal does not send this content to Hangar’s server or OpenAI. Saved Tomorrow’s Moment plans also stay local and are not copied into live-flight requests.
Hangar does not operate a cloud copy of this practice history. Device backups may contain app data according to your Apple settings. Keep your device and any backups secure.
1.3 update: sharing is your choice
Saving a card or plan does not share it. When you choose Share, the iOS share sheet lets you choose a destination. A carry card shares only the lines shown in its editor, not your goal or practice history. A Tomorrow’s Moment summary shows a preview and asks what details you want to include before sharing. A recipient or another app may keep its own copy under its own practices.
Purchases
Hangar Premium is an optional subscription processed by Apple through the App Store. Apple handles billing under its privacy policy; we receive only purchase entitlement information. No card number or payment detail reaches us.
Children’s privacy
Hangar is designed primarily for teens, roughly ages 13–17, with parent or guardian involvement. There is no account, advertising, or cross-app tracking, and raw voice never leaves the device. Live-flight text follows the service and retention flow above. Contact robin@kindabilities.com with a concern.
How to delete local data
Open Settings inside Hangar, choose Clear my data, then confirm Yes — delete everything. This removes local goals, saved plans, flights, and the logbook. Deleting Hangar also removes its local app data. Neither action erases exported files, copies held by recipients, or existing device backups. Anonymous service-limit rows expire automatically; the separate OpenAI and CloudWatch retention boundaries are described above.
1.3 update: clearing local data also removes offline rehearsal histories and carry cards. Hangar returns to the start only after the local deletion is saved. If it reports that your data could not be cleared, use Try clearing again; do not assume deletion succeeded.
Changes to this policy
If Hangar changes how it handles information, we will update this page and revise the date above.
Contact
Questions about privacy? Email robin@kindabilities.com. See also Support and the Terms of Use.
Last updated 2026-09-06.