Privacy policy

What we collect, and what we cannot see.

Last changed September 27, 2026. The promise page says the same thing in plain words; this is the policy.

Your recordings are transcribed on your iPhone. Backup and shared links send encrypted copies, with keys we cannot use. What we can see is set out below. We run no analytics and sell nothing.

Who we are

Trunk is made by Chase Color, Inc., a Delaware corporation, which is the controller of the data described here. Post: 350 E 400 S, STE 54472, Salt Lake City, UT 84111, United States. Email: help@trunkhere.com. The postal address is a mail suite that is checked rarely, so email is the route that reaches us.

What this policy covers

This page covers the Trunk app for iPhone, its accounts, encrypted backup and sharing by link, and trunkhere.com, including its waitlist, its contact form and its shared-memory reader. The site sets no cookies and runs no analytics.

What stays on your iPhone

Recording, transcription, the words read from photos, titles and summaries all happen on the phone, with the phone's own models. Nothing you record is sent anywhere to be transcribed, and there is no cloud AI. The app needs no account to record, transcribe, search, play or export.

The app contacts Apple for speech-model downloads and purchases, and our service if you sign in. Apple or Google handles its own sign-in when you choose it. This traffic does not send your recordings for transcription. Text/PDF sharing and exporting make readable copies at the destination you choose; sharing by link works as described below.

Because your memories live on the phone, they are included in the phone's own iCloud or computer backup the way any app's data is, under your Apple settings; video files are left out to spare the space. Apple encrypts iCloud backups at rest; a backup to a computer is encrypted only when “Encrypt local backup” is on. We do not receive those backups.

Backup, if you turn it on

Backup is part of Pro. When it is on, each memory is encrypted on your iPhone before it leaves: its audio, photos, stills, words, title and summary, under a key of its own that is in turn sealed with your account key. The account key is made on your iPhone and kept in your Apple keychain, which carries it to your other devices through iCloud Keychain. The unwrapped account key is never sent to us. Video files are not backed up.

We say: “Your private memories are encrypted on your device before backup. The key stays with you, never on our servers. We can't listen to or read them.”

We also say, plainly: we can see your email or Apple relay address and which sign-in you used, your subscription and its history with Apple, the devices you signed in from and when, how many encrypted memories and files you have, their sizes, and when they were made, changed or deleted, and the IP addresses your devices connect from. From a file's size we can guess a recording's length. We cannot see titles, words, pictures or sound.

If you choose to keep a recovery code, the app stores your account key on the server wrapped with that code. The code itself is shown once, to you, and never sent to us; without it the wrapped key cannot be opened. If every device is lost, iCloud Keychain is off and there is no recovery code, nobody can open the backup, and the app lets you start it over.

Sharing by link

When you choose Share by Link, the app encrypts a separate copy before uploading it. The key is in the link after the # sign; it is not sent to our server when the link is opened. The recipient's browser opens the copy on their device. We hold the encrypted copy and its id, owner, size, creation and expiry times, whether it was taken back, and how many times it was fetched. Network information such as IP addresses is visible to our infrastructure.

Anyone with the full link can open, save or forward it; the service you use to send the link can receive it too. Taking back or expiring a link stops new opens, but cannot recall copies already opened or saved. The reader creates no persistent content or key storage, and uses no accounts, comments, analytics or third-party resources.

Public stories, if you publish or watch them

Publishing is a separate, deliberate act that needs your sign-in and a review by a person. Only the edition you choose to publish becomes public. Anyone, including us, can view it. You can take it down, but copies others saved can't be recalled. A public edition never carries its private original, your other memories, the exact spot it was recorded or later edits by itself; it names an area, never a spot, and says whether where it was made is confirmed.

Of public stories we can see the edition itself, the public profile, the chosen place, collection membership, follows, reactions and reports, and the operational records needed to serve them. Watching needs no account, no app and no location. When the service collects viewing signals, each is about a story and never about you: which story was watched, skipped, replayed, saved, shared or followed from, on which surface, with how much of its media was visible, as a count per day; and how a shared link was reached, by a word the link carried, as a count per story and day. No name, device, address, session or private content is in any of them. Raw signals are kept a day and counts ninety days; a withdrawn story's counts leave with it. Private recordings, transcripts, searches, restricted-collection reading and movement history never feed public recommendations. Learning what you like happens on your own device, can be paused or reset there, and is never sent.

If you are near a place you chose to be reminded at, the phone notices the arrival itself; the service is asked only what is nearby when you ask for that, keeps no reading of where you are, and never holds a trail of your movements.

Your account

An account is made when you sign in for backup, Pro or Share by Link. It holds your sign-in addresses and methods, the provider's identifier, device names and identifiers, sign-in times, and your subscription records. Signing in alone does not turn backup on. There are no passwords: email sign-in uses a six-digit code that works for ten minutes. Apple and Google sign-in give us a stable identifier and an address; when you delete the account, we ask Apple to end that sign-in.

In Settings, Account you can manage your sign-in methods, see your devices, sign out here or everywhere, and delete the account.

Payments

Pro is sold through the App Store as an auto-renewing subscription. Apple runs the purchase, renewal and cancellation under Subscriptions in your Apple Account settings, and card numbers go to Apple and never to us. Apple sends signed subscription records, including transaction identifiers, purchases, renewals, expiry and refund events, so Pro can be turned on and off. These records carry no card details.

The waitlist

When you join the waitlist on this site we collect your email address, which part of the page you signed up from, and the campaign labels carried by the link you arrived on, if any. We use them to email you when Trunk is on the App Store, and for nothing else.

Resend, our email provider, stores the list and sends the mail on our behalf. Every email carries an unsubscribe link, and unsubscribing stops the mail. Once an address has unsubscribed, submitting the form again changes nothing: nobody can put you back on the list against your wishes. To re-join, email help@trunkhere.com. Unsubscribing keeps your address on the list marked as unsubscribed, which is what makes it stay unsubscribed. Ask us to delete it and we delete it.

The contact form

A note sent from the support page goes by email, through Resend, to help@trunkhere.com, with your address as the reply address. It is kept as ordinary mail for as long as the conversation needs, and deleted on request.

Who processes what

Our service and its backup providers receive encrypted memory files without a key that can open them. The phone's own iCloud or computer backup is separate, as described above. We do not sell your data or share it for advertising. If we are required to disclose what our service holds, it is encrypted files and the readable account, subscription, device and file details described here, not decrypted memories.

Logs

Our server keeps ordinary request logs, with IP addresses, the time and the route, for a short time, to keep the service running and to look into abuse. The logs never contain your content, your keys or your sign-in tokens; account ids in them are masked. The site keeps whatever request logs its host keeps.

What we do not do

We run no analytics and no advertising trackers in the app or on the site, load no third-party scripts, and set no cookies on the site. We do not use your content to train or tune anything, and nobody here reads it, because nobody here can.

How long we keep things

Ending your account, and deletion

You can delete your account in the app under Settings, Account. Account access and new opens of its shared links stop, and removal of its backup, shared copies and records begins. If file removal or ending Apple sign-in cannot finish because a service is unreachable, the app says so and the server retries. The limited records and deadlines above still apply. Your memories on the phone stay. Cancel an Apple subscription separately in your Apple Account settings.

We will not claim more than that. Copies that are out of our reach stay where they are: files you exported or shared, and records a provider or the law requires us to keep.

Your rights

You can ask to see what we hold about you, to correct it, to receive a copy, or to have it deleted, and you can withdraw consent at any time. In the UK and EU you also have the rights to restriction, portability and objection under the GDPR, and you can complain to your supervisory authority. Where the GDPR applies, our legal basis for account data and for the backup you turn on is performing our contract with you, and for the waitlist it is your consent. Email help@trunkhere.com and we will act on it. There is no charge and no form.

Children

Trunk is not for anyone under 13, or under the higher minimum age your country sets.

Where your data is processed

We are a United States company, and the providers named above process data in the United States.

Changes to this policy

The date at the top of this page is the date of its last change. If a change affects what we collect or who processes it, we will say so here before it takes effect.