WristFeed Privacy Policy
Who operates WristFeed
WristFeed is published by Morphantic, an independent app-publishing label operated by Wes Lagarde. Questions about this policy can be sent to wes@glassbox-bio.com.
Account-optional use and on-device data
You can use WristFeed without completing Sign in with Apple. In that mode, WristFeed can show sample content and keep app state on your devices without associating it with your Apple account.
WristFeed uses iOS and watchOS storage for settings and app state. Authentication tokens are stored in the Apple Keychain when present. Feed items, thumbnails, short media clips, preferences, saved-item state, and pending actions may also be cached on the iPhone or Apple Watch for app functionality and offline use. Removing the app removes data in its app container; Keychain items can persist through reinstall until they are removed by the app or the operating system.
Data handled when you sign in
If you choose Sign in with Apple, WristFeed sends the Apple identity token to the WristFeed API for verification. The server stores the Apple account subject, a derived WristFeed account identifier, access and refresh tokens, device and platform identifiers, and token expiration times.
To provide and synchronize the service, the server can also store feed preferences, connected-source settings, RSS feed URLs and titles you add, saved-item content and timestamps, muted authors or sources, feed-session records, item reports and reasons, and account-deletion request status.
The iPhone and Apple Watch privacy manifests declare User ID, Product Interaction, and Other User Content data as linked to the user, used for app functionality, and not used for tracking. Other User Content covers RSS feed URLs and optional titles that a signed-in user chooses to add.
How data is used
Account identifiers and tokens authenticate and pair your devices. Preferences, source settings, saved items, product interactions, and reports are used to deliver feeds, synchronize app state, remember your choices, operate safety controls, provide exports, and respond to support or deletion requests.
Content and service providers
WristFeed uses Apple for Sign in with Apple. The WristFeed API is hosted at wristfeed-api.vercel.app. When you open or connect an external source, that source may receive the request under its own terms and privacy policy.
This release can display built-in WristFeed sample content and content from RSS or Atom feeds chosen by the user. Feed content remains subject to the source publisher policies.
Tracking and advertising
The shipping privacy manifests declare that WristFeed does not track users and has no tracking domains. WristFeed does not use account or interaction data for advertising and does not sell personal information.
Retention and deletion
The current server keeps account-linked records until they are removed; its code does not define an automatic expiration period for preferences, saved items, source settings, reports, or account records.
Choosing Delete account in WristFeed signs the app out and sends an authenticated deletion request to the server. The current endpoint records that request as pending; it does not itself remove every account-linked database row in the same request. Email wes@glassbox-bio.com after requesting deletion to have the request completed or to verify removal. You can also remove individual saved items and source connections in the app.
Security
WristFeed uses Sign in with Apple verification, bearer tokens, and the Apple Keychain for authentication state on the device. No storage or transmission method is completely secure.
Changes and contact
This policy will be updated when WristFeed data handling changes. Privacy questions, data-export questions, and deletion help can be sent to wes@glassbox-bio.com.