O Onefold
Privacy

Private by design

Onefold stores relationship state by couple and edition. Exchanged answer and note bodies are sent as client-encrypted payloads. We do not run ads or sell intimate data.

Data We Handle

We process Sign in with Apple identifiers, couple membership, encrypted answers, app interaction records, purchase status, reports, and blocks. To stop code guessing we also count pairing attempts per account and per network address for up to a day.

What your spouse sees, and what is not end-to-end encrypted

Once you are paired, your spouse sees your display name: the name you shared through Sign in with Apple, if you shared one. Milestone titles and the feeling you choose on a repair request are stored on our servers without end-to-end encryption, so treat them like a label rather than a private note. Your answers, notes and check-ins are encrypted on your phone before they are sent.

Anything you write while you are waiting for your spouse to join is kept to yourself: it is deleted from our servers at the moment your spouse joins, so they never see it.

Pairing codes

Your pairing code is made on your phone, and the key that encrypts your answers is derived from it on your two phones. We receive only a one-way fingerprint of the code, never the code itself, and every code expires after 48 hours or as soon as it is used. (Versions 1.1 and earlier asked our server to make the code.)

No AI

Onefold does not use AI. Nothing you read in the app is generated while you use it, and nothing you write is sent to an AI service.

Deletion

Account deletion is available in the app. You can also request help at support@keenshift.ai.