top of page

OUR PRIVACY PROMISE

We believe privacy should be straightforward — and respectful.

 

At a fundamental level, the Bigger Blacker Book is designed so your data stays yours. The app is built to work primarily with data stored locally on your device, and you decide what information to enter, what to keep, and what — if anything — to share.

 

Adding more information can make the app more useful, but that choice is always yours.

 

 

Your Data & Backups

 

If you choose to enable backups or syncing, your data can be securely backed up to your own cloud account, including iCloud, Dropbox, OneDrive, or Google Drive, depending on your preference and device platform. These backups are managed through your personal accounts and are subject to each provider’s privacy and security policies.

 

We do not manage, view, or control the contents of these backups.

 

Our servers are used only to facilitate encrypted data transfer and app functionality. They are not designed to read, analyze, or retain the contents of your personal health data.

 

 

Partner Notifications

 

If you use the app to notify a partner about a possible exposure, that message is sent anonymously between two profiles that have already connected within the app.

 

We do not read the contents of these messages. Delivery requires basic technical metadata (such as routing information), but the app is designed so messages are not stored or tracked beyond what is necessary to deliver them.

 

 

Public Health & Research (Opt-In Only)

 

We may partner with local public health organizations to support research and prevention efforts.

 

If — and only if — you explicitly opt in, the app can share anonymous, aggregated statistics such as encounter counts, averages, or screening summaries. These reports:

 

  • Contain no names, identifiers, notes, or personal content

  • Are combined across many users

  • Are used solely for public health or research purposes

 

You can choose whether to participate, and opting out does not limit your use of the app.

 

 

What We Don’t Do

 

We do not sell, trade, or monetize your personal health data.

We do not access your stored encounters, notes, or media.

We do not use your information for advertising.

 

Because the app is designed to minimize what we can see or store, we simply don’t have access to most of your data in the first place.

Deleting Your Data

 

Because of how the app is built, everything there is to delete is already in your hands. Here is where each kind of data lives and how you remove it.

  • On your device. Your encounters, screenings, notes, and media are held in an encrypted database inside the app's own private storage. Uninstalling the app deletes that database and everything in it. There is no copy on our servers to remove afterwards.

  • Backups you made. If you turned on backups, the encrypted backup sits in your own iCloud, Dropbox, Google Drive, or OneDrive account. Delete it the way you would delete any other file in that account. We cannot see it or reach it.

  • Recovery. If you set up recovery, our server holds a random lookup value, a salt, an optional encrypted hint, and a copy of your database key that only your recovery code can unwrap. Disconnecting your backup in the app deletes that record from our server and the copy in your cloud account in a single step.

  • Partner notifications and shared profiles. Messages between connected profiles are encrypted end to end and pass through our relay only long enough to be delivered. Share links can be set to expire, or to work only once. What the relay holds is an opaque profile identifier and a delivery target — never a name, an email address, or a phone number.

  • Analytics and crash reports. Anonymous usage analytics are switched off unless you turn them on, and you can turn them off again at any time in Settings. Crash reports are stripped of personal content before they are sent.

 
 
Is there a data deletion request process?

No — and that is a deliberate consequence of the design rather than an oversight. We do not issue accounts. We do not ask for a login, an email address, or a phone number, and we do not store any identifier that would let us work out which records belong to which person. The values our servers hold are opaque, and they mean something only when combined with the database and the recovery code that you alone hold.

So if you wrote to us and asked us to delete your data, we would have nothing to search for and no way to confirm that any particular record was yours. Uninstalling the app, deleting your own backups, and disconnecting recovery are the complete set of steps — and all three are entirely under your control.

The one exception is anything you deliberately send us. A support request submitted from inside the app carries no account or profile identifier — only your description, the operating system version, and whichever logs or screenshots you chose to attach. A contact email address is optional, and supplying one is the single moment where you tell us who you are. The same applies if you write to us at [email protected]. In either case, ask us to delete that correspondence and we will.

 

A Final Word

 

No system is perfect, and no digital tool can promise zero risk. But the Bigger Blacker Book is intentionally built to reduce exposure, minimize data collection, and put control in your hands.

 

Your data is yours.

Your choices matter.

And we respect your privacy — always.

bottom of page