Sidle · Privacy
Privacy Policy
Your task is not our business model. Here is what stays local, what optional AI sends to a provider in China, and exactly how long each record lives.
Available on the App Store · last updated 2026-07-29.
Short version: Sidle has no login, advertising, or cross-app tracking. The free loop and the local Pro tools stay on your device. Optional provider-backed AI is the one part that leaves it: only after you confirm you are 18 or older and accept the current China-processing and sensitive-data disclosure, it sends task text to DeepSeek, an AI provider operated in the People’s Republic of China.
App Store privacy label
Apple’s current App Privacy summary for Sidle is Data Linked to You — Purchases, User Content, Identifiers, and Usage Data, all for App Functionality, with no tracking. “Linked” here means records are associated with Sidle’s assigned anonymous user identifier. It does not mean Sidle asks for your real-world name, and none of it is used for advertising.
What stays on your device
Free sessions work without any server identity. Moments — the task, first move, start and end times, and an optional mood word — are stored in the app on your device, along with companion style, hello timing, adult confirmation, AI consent, and a local purchase-state cache. The widget copies the two most recent task names and the Moment count into an App Group preferences container.
The Pro “For next time” Return Bridge is written by you and saved only on this phone. It is not a provider memory note and is not sent to our server or to DeepSeek. The in-app hello and optional voice are generated on-device, and an optional background hello uses an iOS notification. Sidle does not record or upload microphone audio.
Sidle does not provide account-based or cross-device sync of Moments or Return Bridges. Apple’s device-backup behaviour is controlled by your Apple settings, not by Sidle.
Live Activity is visible to anyone who can see your phone. If you enable it, Sidle can place task text on the Lock Screen and in the Dynamic Island. Avoid Live Activity for private tasks.
What optional provider AI sends and stores
If you explicitly connect provider AI — and only after you confirm you are 18 or older and accept the current China and sensitive-data disclosure — Sidle can send or store:
- the task and first physical move you type;
- session start, reply, landing, state, and timing records;
- your chosen companion name;
- one clearable note derived from the latest eligible session, which replaces the prior note rather than building a note history;
- an assigned anonymous user identifier;
- Apple-signed purchase product, transaction, status, and expiry information; and
- monthly AI usage and cost counters linked to that anonymous identifier.
The local Return Bridge is not included. A device region code can be sent to choose a static crisis resource, but it is not stored with the session. Sidle does not request a name, email address, contacts, photos, advertising identifier, or precise location.
The DeepSeek transfer, stated plainly
Sidle’s AWS-hosted service sends the task, companion name, and the relevant latest-session note for the co-start, then the task and first move for the follow-up, to DeepSeek, an AI provider operated in the People’s Republic of China. DeepSeek returns the generated co-start and follow-up text. The landing line and the replacement factual note are created deterministically by our own service from the session fields above; those two outputs are not model-generated.
DeepSeek’s public documents do not give Sidle an API-specific no-training or fixed-retention promise. DeepSeek offers API context caching, and its provider-side handling sits outside Sidle’s own 90-day database schedule. Sidle therefore does not claim provider-side zero retention or exclusion from model improvement. Avoid entering health, identity, financial, legal, workplace-confidential, or other sensitive information.
A deterministic crisis-language check runs before any provider use or session storage and returns a static regional care card. A separate dangerous-task check returns a static refusal for violence, weapons, intrusion, and other dangerous wrongdoing. Matched text is not sent to DeepSeek and is not stored as a provider session.
Provider-backed AI is enabled for eligible connected adults who accept the current disclosure, and it remains fail-closed: missing consent, safety rules, outages, metering limits, or the service ceiling make a session stay silent instead. Free sessions and local Pro features continue either way.
How the anonymous identity works
Sidle has no user login. It creates a separate anonymous provider profile for each device, and only when provider-backed AI is explicitly connected. Fresh registration requires a verified Apple purchase and Apple App Attest proof bound to a one-time server challenge and Sidle’s app identity. The app keeps a short-lived signed access token and a separate opaque rotating refresh credential in this device’s iOS Keychain; the server stores only a one-way hash of the refresh credential, and each successful refresh rotates it. This is not account-based or cross-device sync: profiles, provider notes, local Moments, and Return Bridges do not move between devices.
Retention
- Raw provider-session records are scheduled for deletion after 90 days; database expiry removal can occur later.
- The latest eligible session note is replaced by each new eligible note — there is no note history. The current note remains until it is cleared or this device’s profile is deleted.
- An unused free server profile expires after 30 days if no verified entitlement is attached.
- Purchase-level monthly provider-cost totals are shared across device profiles using the same verified Apple customer transaction and remain, without task text, until 45 days after the billing month ends. The content-free fleet daily cost tally expires after about three days.
- A minimal deletion tombstone remains for up to 48 hours so that delayed writes cannot restore deleted profile rows.
- A content-free deletion and recovery ledger remains for 40 days, beyond the database’s 35-day point-in-time-recovery window, so that an offline restore can be scrubbed before it serves traffic. It contains no task, first move, companion note, provider response, or contact detail.
- Permanent credential-revocation fences — content-free opaque identity and one-way device-derived identifiers — remain solely to prevent a deleted credential from becoming valid again.
- Apple transaction identifiers and notification records may remain separately where needed to validate purchases, prevent duplicate grants, handle refunds, or meet legal and accounting obligations. They contain no task text.
- Support messages are retained only as needed to answer the request and keep an appropriate business record.
Delete this device’s Sid memory
Open Settings → Delete this device’s Sid memory. The server first replaces this device’s provider profile with the minimal tombstone, then deletes the latest-session note, raw session rows, device-owned legacy cost rows, and active credential material; the app clears its Keychain credentials. Separate profiles on other devices are not deleted.
The tombstone, the 40-day content-free ledger, the permanent revocation fences, Apple purchase records, and the bounded content-free purchase-level totals remain within the purposes and periods described above. DeepSeek-side request copies or caches are outside this endpoint, and Sidle does not promise that it erases provider-side data. Your Apple purchase and your on-device Moments remain; to remove local Moments and the Return Bridge too, delete Sidle’s local app data from the device.
Who helps provide Sidle
- Amazon Web Services — API processing and encrypted database hosting in the United States.
- DeepSeek — processes optional provider-AI requests as described above, including processing in the People’s Republic of China. Its API caching and privacy terms are separate from Sidle’s database retention.
- Apple — distributes the app, processes purchases, reports entitlement status, and supplies device services such as Keychain, notifications, and Live Activities.
We do not sell personal information and do not use Sidle data for cross-app advertising. We may disclose information when legally required or reasonably necessary to protect users and the service.
Provider AI is for adults
Sidle’s provider-backed AI may be used only by people aged 18 or older, and requires adult confirmation and the current DeepSeek and China disclosure before task text can be sent. People under 18 should keep sessions local and must not connect provider-backed AI.
Questions or privacy requests
Sidle is published by KindAbilities and KeenShift, in Australia. Email robin@kindabilities.com — we may need device and request-timing information to investigate, but please do not send sensitive task text.
You may ask to access, copy, correct, object to, restrict, or erase server records we can authenticate and locate; ask about retention or DeepSeek processing; or make a privacy complaint. Keeping sessions local or withdrawing the current consent marker prevents a provider call, but does not by itself undo earlier processing or erase existing records. We assess complaints and aim to respond within 30 days; if you are not satisfied you may contact the Office of the Australian Information Commissioner or another regulator available to you. Access, correction, export and erasure can be limited where we cannot safely link an anonymous record to the requester — we will explain the result rather than claim a control worked. See also Support and the Terms of Use.
Last updated 2026-07-29.