SaySpace · Legal
SaySpace Privacy Policy.
Last updated: 19 June 2026 · applies to SaySpace v1.2.2026 and later.
Operated by: Alderframe LTD, London, United Kingdom. Privacy contact: [email protected]. This policy is written in plain English. Headings are for navigation, not legal definitions.
Our approach
SaySpace is built to be privacy-first. We collect only what we need to run the service. We do not show third-party advertising, we do not use third-party advertising trackers or SDKs, we do not use Apple’s advertising identifier (IDFA), and we do not sell personal information. You are not the product.
This does not mean SaySpace collects no data. To run the service we have to store the account you create, the content you post, and a small amount of operational information. This page explains exactly what.
Sign-in
SaySpace uses Sign in with Apple. When you sign in, Apple provides SaySpace with a stable user identifier and (depending on your choice) either your real email or a private-relay address that Apple manages on your behalf. If you choose the private relay, your real email is never shared with SaySpace; replies routed through the relay are forwarded by Apple to your real inbox.
What we collect and process
- Account & profile: the email or relay address from Sign in with Apple, your chosen display name, handle, bio, and avatar.
- Content you create: posts, replies, voice notes, photos you attach, communities you create, direct messages, and topics you follow.
- Interactions: follows, saves, reposts, reactions, mutes, blocks, hides, reports, and similar signals needed to operate features and discovery.
- Push notification token: if you allow notifications, a device-issued token used only to deliver the notifications you have enabled.
- Privacy-preserving telemetry: sanitised performance, error, and category-level usage signals (for example, "the News tab failed to load"). We do not include message or post content in telemetry, and we do not include identifiers that would let us reconstruct what a specific user said.
We do not collect precise or coarse location, your contacts, calendar, health data, browsing history from other apps, advertising identifiers, biometric data, or device fingerprints.
Where your data is stored
The account, profile, content, and interaction data above are stored on SaySpace’s backend, which is hosted on Supabase (a managed PostgreSQL platform). Supabase acts as a data processor on Alderframe LTD’s instructions and does not have an independent right to use your data. Apple’s push notification service is used as a processor to deliver notifications you have enabled. We do not use any other third-party processors for the core product.
On-device data (never sent to us)
The following stay on your device, encrypted at rest by iOS, and are cleared when you sign out:
- Your on-device interest graph (the personalisation signals SaySpace uses to tailor your discovery on the device).
- Local cache of feeds, images, and audio.
- Your local search index for posts and messages.
- Composer drafts.
- Your sign-in token.
News and external links
The News tab inside SaySpace shows live world headlines aggregated server-side by SaySpace from publicly available RSS feeds of reputable outlets (for example BBC, The Guardian, NPR, Al Jazeera and others), organised by topic. Aggregation runs on our backend; your device only ever talks to SaySpace, so simply reading the News tab does not expose you to news publishers.
SaySpace shows only the headline, a short excerpt, the source name, and a link. SaySpace never reproduces full articles and is not the source of the news. When you tap Read at <source>, you leave SaySpace and visit the publisher’s website — at that point, that publisher’s privacy policy applies (which may include their own cookies, analytics, and advertising).
How we use what we collect
To provide and secure your account; to display and deliver your content to the people you choose; to power your personalised discovery feed based on your interests and activity; to operate the News, Trending, and Fresh Voices surfaces; to keep the community safe (moderation, reporting, blocking, mute, hide); to send notifications you have enabled; and to diagnose and fix problems.
How we share — and how we don’t
- With other users: content you post is shared according to its visibility and the people you interact with.
- With our processors: Supabase (backend hosting and database) and Apple (push notifications), each on our instructions.
- For legal or safety reasons: where required by law, valid legal process, or to protect users from imminent harm.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. There are no advertising or third-party analytics SDKs in the app.
Your rights
- Export: request a complete, open archive of your account, profile, content, and interactions at any time from the app (Settings → Data Export). The archive is delivered as a downloadable file.
- Delete: permanently delete your account and associated data at any time from the app (Settings → Account → Delete Account). See Account Deletion.
- Permissions: control microphone, notifications, and photo access in iOS Settings; the in-app Privacy & Permissions Center explains each permission honestly.
- Local rights: depending on where you live, you may have additional rights (access, correction, portability, restriction, objection, or complaint to a supervisory authority). Email the privacy contact above and we’ll help.
App Store "App Privacy" declaration
We declare the following data types as collected: Name, Email Address, Photos or Videos, Audio Data, Other User Content, User ID, Device ID, Product Interaction, Crash Data, Performance Data, and Other Diagnostic Data. All are linked to the user’s identity, and none are used to track across other companies’ apps or websites.
Data retention
We keep your information while your account is active and delete it on account deletion, except where retention is required for legal, security, or safety reasons. Telemetry is retained for a limited period and then purged. Backup snapshots may persist for a short, defined period before being overwritten.
Children
SaySpace is rated 16+ and not directed to children under 16. We do not knowingly collect data from anyone under that age.
International transfers
Alderframe LTD is based in the United Kingdom. Our processors (Supabase and Apple) operate globally and may process data outside the UK and the EEA. Where required, we rely on appropriate safeguards (for example, the UK International Data Transfer Addendum or EU Standard Contractual Clauses, or recognised adequacy regimes).
Security
SaySpace uses HTTPS in transit and managed infrastructure security at rest via Supabase. We do not claim end-to-end encrypted messaging; direct messages are server-stored so they can be retrieved across devices and moderated when reported. No system is unhackable; we work to keep your data safe and will notify users and regulators in the event of a personal-data breach as required by law.
Changes to this policy
We’ll post changes here and update the "Last updated" date. Material changes will be highlighted in the app or by email.
Contact
Alderframe LTD, London, United Kingdom. Privacy contact: [email protected].
Template note. This Privacy Policy is published in good faith and aligned with the live App Store Connect record for SaySpace (App ID 6778415283, bundle com.sayspace.app, v1.2.2026). It is intended as a clear, plain-language statement, not legal advice. Alderframe LTD recommends having a qualified UK solicitor review this policy before relying on it for any specific situation. Any items requiring jurisdiction-specific verification — for example a registered company number or formal data-protection representative — should be confirmed with counsel.