Local first, shared deliberately

Privacy Policy

Effective August 7, 2026

What stays on your device

Your Packs, saved text, links, images, files, search activity, and local product-usage evidence stay in Packboard's app container or shared App Group on your device. Packboard has no account system and does not upload this private library for ordinary save, search, keyboard, or Share extension use.

Encrypted portable backups

If you choose Create Encrypted Backup, Packboard verifies the private library and its referenced files, removes public-link state and publishing credentials, then encrypts the complete bounded backup on device with AES-256-GCM. The app displays a separate random recovery key and does not upload or escrow the file or key. Save them in different secure locations. Packboard, RevenueCat, Apple, and support cannot reset a lost key. An incorrect key or modified backup is rejected before any local library data is replaced.

When you publish a Pack

Packboard sends only the items you explicitly publish, plus the title and optional summary. Public text and link details are checked against deterministic safety rules and an automated content-safety model before a draft is stored. Supported uploaded images and documents stay private as drafts until their type and integrity are verified, their contents are converted to bounded text, and that text passes the same safety review. If required scanning is unavailable or cannot safely read a file, publication fails closed. Automated review can make mistakes; use the report link on every public Pack for human review.

Purchases

Apple's App Store processes payments. Packboard uses RevenueCat to offer purchases, validate purchase status, and restore entitlements. Packboard does not receive your full payment-card details. Apple's and RevenueCat's own privacy policies govern the information they process.

Service operations

The public-Pack service processes security data such as request identifiers, rate-limit signals, and installation-scoped publishing credentials. Credentials are stored as one-way keyed hashes, expire after 180 days, and can be revoked. A stable opaque publisher identifier is derived with a keyed hash for safety enforcement; the raw installation identifier is never exposed or logged. Logs exclude Pack contents, raw tokens, and user identifiers.

Safety reports and moderation

A report contains only the public Pack identifier, opaque publisher identifier, one fixed reason, receipt identifier, and time received. The report form accepts no comments and the moderation queue stores no Pack contents, IP address, or credential. Browser forms use a short-lived signed token and same-origin checks. Rate-limit signals are used to reduce abuse but are not placed in the report. Confirmed violations may result in removal of a Pack or blocking of its opaque publisher identifier. Resolved report and privacy-safe action records are retained for up to 180 days, then purged in bounded operational batches. Separate Pack and publisher safety blocks may remain to prevent removed material from being republished.

Public Pack growth measurement

To help a publisher understand whether a public Pack is useful, the service counts successful preview, Open in Packboard, and App Store button requests. These are raw request counts, not unique people, downloads, or installs. After a recipient imports a public Pack, the app may send only a fixed event name, that Pack's public identifier, a random per-import measurement identifier, and an idempotency key for completed import, first successful text/link copy, and return-day measurement. The same random identifier is reused for later revisions of that source Pack and authentication renewal. Image/file sharing is not included in that copy metric. The service authenticates the installation and immediately replaces the random identifier and idempotency key with one-way keyed hashes. Both stored hashes are scoped to one public Pack, differ across Packs, and are not co-located with other Packs' metric activity; the raw identifier is never logged, stored, or exported. The service never receives the imported Pack's contents, email address, IP address in the event record, advertising identifier, or RevenueCat purchase data.

One authentication credential can bind only one recipient hash for each public Pack and at most 1,000 public Packs; changing that identifier is rejected. The authentication safety object stores only opaque keyed binding references and a count, not public Pack IDs or recipient hashes. Each isolated binding object contains one Pack-scoped recipient hash without Pack ID, installation ID, or activity. Revocation or authentication expiry attempts to delete child bindings, and every child has its own 180-day deletion alarm if immediate cleanup fails. This is pseudonymization, not anonymity: a trusted service operator holding the secret pepper could theoretically recompute a reference. Per-Pack recipient measurement is capped at 50,000 imported-Pack identifiers. D1 and D7 are exact UTC calendar-day foreground or cold-launch returns after the service first observed an import; they are not general app-install retention. Dated cohort detail is limited to 93 days. Publisher exports use the private per-Pack owner credential and contain only aggregate counters and cohort rows, never raw import identifiers, recipient hashes, or credentials. These counters support product analysis but are not fraud-proof unique-person, store-download, or revenue evidence. Unpublishing makes the Pack and its metrics export inaccessible, attempts to erase its metrics state, and permanently rejects later writes to a successfully deleted metrics object.

Control and retention

You can delete local Packs in the app and unpublish a public Pack from its Pack screen. Unpublishing removes the public manifest and assets and permanently blocks that public identifier from being reused. Removing the app removes its local data subject to Apple's device and backup behavior.

Deletion and credential recovery

Use Packboard's in-app Privacy Controls to erase local data only after unpublishing every public Pack. If a private deletion credential is lost, email support@claude-world.com with the public Pack URL. Packboard will review abuse and deletion requests, but may not be able to verify ownership or remove a link without sufficient evidence.

Children and changes

Packboard is a general productivity tool and is not directed to children under 13. Material policy changes will be posted here with a new effective date.