Calryn for iPhone
Privacy Policy
Last updated 10 September 2026.
This policy applies to Calryn for iOS and iPadOS.
The short version
Calryn does not collect your data. There is no Calryn server, no developer-run database, and no analytics or advertising SDKs anywhere in the app. Everything you enter, meaning your watches, photos, documents and financial details, is stored locally on your device and, if you choose to enable iCloud, synced through your own private iCloud account. We structurally cannot see it.
Information we collect
We collect none. Calryn has no user accounts, no sign-up, and no email or password of any kind. There is nothing to register and nothing tied to your identity on our end.
Information you store in Calryn
Calryn stores the information you choose to enter about your watch collection, including:
- Watch details: brand, model, reference and serial numbers, case, bezel and movement specifications, straps, certifications, condition, and notes
- Photos of your watches, and scans or photos of related documents (receipts, warranty cards, service records)
- Financial details: purchase price, retail price, market value estimates, retailer, tax paid, and sale records
- Valuation history: the record Calryn keeps each time you revise a watch's estimated value, so you can see how your own figures have changed over time
- Service history: service dates, servicer, work performed, what it cost, the next service due date, your chosen service interval, and warranty dates
- Wear log: the days you record wearing a watch, and any note you add to an entry
- Timeline edits: any change you make to how a moment in your collection's story is described
- App preferences: currency and region display settings, and Showcase selections
This data lives in a local SwiftData store on your device. If you have iCloud enabled, it also syncs to your own private iCloud database, accessible only by your devices signed into that iCloud account. Apple's CloudKit private database architecture makes it structurally impossible for us to access this data. That is not just a policy we follow, but something the system does not allow.
What stays on the device and never syncs
Some things are deliberately kept on the device you are using and are never sent to iCloud, never included in a backup file, and never seen by us:
- Unfinished watch entries you have started but not yet saved
- Your recent searches
- Your Face ID and Touch ID lock preferences
- Whether you have completed onboarding, and when you last took a backup
Photos and location data
Every photo and document scan added to Calryn, whether captured with the camera or imported from your library, has EXIF and GPS metadata stripped before it is ever written to storage. Calryn never requests Location permission and it does not appear anywhere in the app.
Permissions
Calryn requests Camera and Photo Library access only at the moment you choose to use them (for example, tapping "Camera" while adding a watch), never on launch and never during onboarding. Face ID/Touch ID is used only if you turn it on in Settings, solely to lock the app or specific sections (Financial Data, Documents) on your own device. This preference is stored on that device and never leaves it.
Analytics, advertising, and third parties
Calryn contains no analytics SDK, no advertising SDK, and no third-party code of any kind. Calryn itself collects and transmits no diagnostic data whatsoever. If you have switched on Share With App Developers in iOS Settings → Privacy & Security → Analytics & Improvements, Apple may pass us anonymised, aggregated crash reports through App Store Connect. That is an iOS feature you control, it is off unless you turned it on, and we use it solely to fix bugs, never for tracking or profiling.
Buying Calryn
Calryn is free to use in full for seven days. You start the free week yourself, from a screen that appears once after you finish setting up: it is a free item in the App Store called 7-day Trial, and starting it costs nothing. After that it unlocks permanently with a single one-time purchase made through the App Store. There is no subscription and nothing renews.
The purchase is handled entirely by Apple. Calryn never sees your payment details, your name or your Apple Account, and it keeps no record of the purchase of its own: whether you have unlocked is read from the App Store's own record on your device whenever it is needed. If you reinstall, change phones or share the app through Family Sharing, Restore Purchases simply asks the App Store again. Apple's handling of purchases is governed by Apple's own privacy policy. Starting the free trial is an App Store transaction too, so Apple handles it in the same way and Calryn never sees your payment details for it either.
The start of your free week is the App Store's own record of that free item, read from your device whenever Calryn needs it. If Calryn cannot reach the App Store when you start, it falls back to storing the start date in your iCloud Keychain, next to the encryption key described under Security, so a second iPhone signed in to the same Apple Account shares the same free week. Either way it is not part of your collection, is not written to your backup file, and is never sent to us.
Sharing your information
We don't have your information to share, so we don't share it. Calryn gives you two ways to share something deliberately, and both are generated entirely on your device.
A Share PDF sends a watch's details to someone, for example for a private sale. It describes the watch: its photos, specifications, box & papers status and, if you have recorded warranty dates, whether it is still under manufacturer warranty. Calryn never adds your purchase price, serial number, service costs or documents to it. You choose whether to include the purchase date, an asking price and any comments.
Sharing a single photo hands that one image to the iOS share sheet on its own. Its location and camera metadata were already removed when you added it, so what leaves your device is the picture and nothing else.
One thing worth checking yourself, and it matters more when you share a photo directly: a photo you've added may itself show a serial number, engraved on a caseback or on paperwork you've photographed. Calryn doesn't detect or hide that, so have a look before you share.
Either way, what you share goes only through the method you pick (AirDrop, Messages, Email, and so on). It never passes through any server we operate, because we don't operate one.
Security
Your data is protected by Apple's standard device and iCloud security (device passcode/biometrics, encrypted iCloud storage and transit). Optional Face ID/Touch ID app lock adds a further layer on top, using Apple's LocalAuthentication framework exclusively, with automatic fallback to your device passcode if biometrics are unavailable.
Extra encryption on your most sensitive details
Some fields are encrypted a second time, by Calryn itself, before they are ever written to your device or synced to iCloud:
- your watches' serial numbers
- what you paid: purchase price, tax, import duty, shipping, insurance, and what you sold a watch for
- what you paid for a service
- your documents: receipts, warranty cards, and their file names
These are sealed with a key that lives in two places and nowhere else: in your iCloud Keychain, which Apple end-to-end encrypts, and as one spare copy, locked with your Recovery Key, in your own private iCloud database (see Your Recovery Key below). This means Apple cannot read these fields either, not just us. Calryn uses Apple's own CryptoKit for this; there is no third-party cryptography anywhere in the app.
Fields that are not secret are left unencrypted so the app can sort and search them: brand, model, reference, your notes, the watch's specifications, where you bought it, the manufacturer's retail price, and estimated market value. A retail price is published on the manufacturer's website and a market value is public knowledge, so neither reveals anything about you. What you actually paid does, so it is encrypted.
Your Recovery Key, and where the spare key lives
Calryn gives you a Recovery Key when you first set up the app: a code that can restore your encryption key if your iCloud Keychain is ever lost, for example after a device or Apple Account change. We show it to you during setup, ask you to save it somewhere safe, and let you view it again any time in Settings → Security, behind Face ID or your passcode.
For that to work, there has to be something for the Recovery Key to unlock. So Calryn stores a copy of your encryption key, locked with your Recovery Key, in your own private iCloud database: the same place the rest of your collection syncs to. It is no more readable by us than anything else there, and without your Recovery Key it cannot be unlocked by anyone, including us. We never hold a copy of either key.
Backing up your collection, and why this file is not encrypted
Settings → Your data → Back Up Calryn Data packages your whole collection into a single .zip file and hands it straight to the iOS share sheet, so you choose where it goes: Files, iCloud Drive, AirDrop, Mail. Calryn never uploads it anywhere; there is nowhere for us to upload it to.
That file is not encrypted, and this is deliberate. Everything you can see in Calryn is readable in it: serial numbers, what you paid, your invoices and warranty cards. We considered locking it, and every way of doing so produces a backup you cannot open in the very situations a backup exists for. Sealing it with the key in your iCloud Keychain gives you a file that dies with the Keychain it was insuring you against. Sealing it with your Recovery Key gives you a file you cannot open if you mislaid that key. A backup you cannot open is not a backup.
So we tell you instead: keep the file somewhere private. The row in Settings says so every time you look at it, not once. Calryn writes the file to a temporary, device-encrypted location, and deletes it as soon as the share sheet closes, whether you shared it or cancelled, so no readable copy is left inside the app. What happens to the copy you saved is up to you and wherever you put it.
The backup deliberately does not include your Face ID/Touch ID preferences, your Recovery Key, or Calryn's encryption key. A backup is not a place to keep keys.
Restoring from a backup file
You can restore a backup file from Settings → Your data. Calryn reads the file you pick, entirely on your device, and adds what it finds to your collection. Nothing is uploaded, and the file you choose is never sent anywhere. If part of a file is damaged, Calryn restores what it can read and tells you plainly what it could not, rather than removing anything you already have.
Accessing, changing, or deleting your information
During your free week, and once you have made the one-time purchase, all of your data is accessible and editable from within the app. If the free week ends without a purchase, Calryn shows the purchase screen in place of your collection: continuing to use the app requires the purchase, but your collection is not removed. It stays stored on your device and, if you have iCloud sync enabled, in your iCloud, and you can export a complete backup from that screen at any time. There's no separate account or external system to manage.
Deleting a watch (or your entire collection) within Calryn removes that data, including related photos, documents, and history, from your device and, if iCloud sync is enabled, from your iCloud account. This cannot be undone from within Calryn. Any backup file you saved separately is not touched, and still contains whatever it held when you made it.
Because there is no developer-side copy of your data, we cannot retrieve, restore, or delete anything on your behalf. Apart from any backup files you have saved yourself, your device and, if sync is enabled, your iCloud account are the only places this data exists.
One consequence you should understand. The encryption key described under Security is held in your iCloud Keychain, and the spare copy is in your own private iCloud database. We never hold either. That is precisely what makes the encryption meaningful, and it is also why we cannot help you if both are gone.
If you lose both your iCloud Keychain access and your saved Recovery Key, the encrypted fields, meaning serial numbers, what you paid, and your documents, cannot be recovered from your device or your iCloud by anyone, including you. The rest of your collection remains readable, and a backup file you saved earlier still holds the encrypted fields in readable form, because the backup file is deliberately not encrypted (see above). Calryn also warns you if iCloud Keychain is switched off, rather than quietly writing data you may not be able to read later, and tells you when it cannot store your data durably rather than letting you type into something that will not survive.
Children's Privacy
Calryn is not directed at children and does not knowingly collect any information from anyone, regardless of age, because it does not collect information at all.
International use
Calryn performs no data transfer to us, since there is no server. Any sync of your data occurs solely between your own devices via your personal iCloud account, governed by Apple's own privacy practices and the region settings of that account.
Changes to this policy
If this policy changes, the update will be posted here and reflected in the in-app Privacy Policy screen (Settings → About). Material changes will be noted with a new "Last updated" date.
Contact us
Questions about this policy can be sent to privacy@calryn.app.
Calryn's App Store privacy label reads "Data Not Collected." This policy is written in plain English rather than legal language, consistent with Calryn's design principle of treating privacy as a first-class, easily understood feature rather than fine print.