Longhand ("Longhand", "we", "us", "our") is a family memoir app published by Digital Sauce ("the Company"). This Privacy Policy explains what information the app collects, how we use it, and the choices you have.
Longhand stores the questions you choose, the handwritten pages a family member photographs, and the typed copies of those pages, so your family can read and keep them. Your handwriting photos are transcribed using Google's AI. We don't sell your data, we don't show ads, and your contacts never leave your device. You can delete everything at any time.
Contact: development@digitalsauce.io
1. Who this app is for
Longhand is intended for adults (18+) who want to collect a family member's life stories. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
2. Information we collect
We only collect what's needed to run the service and to understand how it is used. We do not collect your real name, address, or precise location, we do not show ads, and we do not track you across other companies' apps and websites. We do use analytics and install-attribution tools, described in Section 2(d) and Section 5.
a. Information you provide
- Names/labels you set up (for example a recipient label such as "Dad" and your own first name). These can be anything you choose.
- Questions you select or write for the family member to answer.
- Stories — the photographs of handwritten pages, any optional extra photo you attach, and the typed (transcribed) copy of each page.
- Notes you optionally add to tailor question suggestions ("about the recipient"). These are used only to generate suggestions and are not shown to the recipient.
- Delivery and notification preferences.
b. Information collected automatically
- Account identifiers. When you first open the app you are signed in anonymously (a random ID). If you choose to sign in with Apple or Google to back up your family across devices, we store the resulting account identifier and, if provided, your email address, so you can sign back in.
- A family invite code used to connect the two people in a family.
- Push notification token (if you enable reminders) so we can send a gentle reminder when a question is waiting.
- Device/diagnostic data generated by our infrastructure providers (e.g. crash and delivery logs) to keep the service working and secure.
c. Contacts (only if you use "Call")
If you tap to call the recipient, the app requests read-only access to your device contacts to find a matching name. Contact data is matched on your device and is never uploaded to our servers or shared with anyone. You can decline or revoke this permission at any time in your device settings.
d. Analytics and install attribution
To understand how Longhand is used, and where new families come from, we collect:
- Product interaction events — fixed labels for actions such as opening a screen, adding a question or saving a story, together with simple counts. These events never contain a name, a question, a story, a transcript, a photograph, an email address or an invite code.
- A device identifier provided by the operating system or by our attribution provider, used to group those events into a session and to attribute an install to the invitation or campaign that led to it.
This information is processed by Google Firebase Analytics and AppsFlyer (Section 5). Where an event relates to the pairing of a family, it carries a one-way cryptographic hash of the invite code rather than the code itself, so the two sides of a family can be matched without the code leaving our systems.
We do not use Apple's advertising identifier (IDFA). That is why Longhand never asks for App Tracking Transparency permission and declares no tracking in its App Store privacy information.
3. How we use your information
- To provide the core service: storing, delivering, displaying, and exporting the questions and stories.
- To transcribe handwriting into typed text (see Section 4).
- To suggest questions tailored to the notes you provide.
- To send reminders you've opted into.
- To restore your family's data when you sign in on a new device.
- To protect against abuse and keep the service secure.
- To understand how the app is used — which steps people complete and where they get stuck — so we can improve it.
- To measure which invitations and marketing campaigns bring new families to Longhand.
We do not sell your personal information, and we do not use your stories or photographs to train advertising profiles.
4. AI processing of handwriting
To turn a photographed page into typed text, the image is sent to Google's Gemini models (via Google's Firebase AI service). If that service is unavailable, an on-device text-recognition engine (Google ML Kit) is used as a fallback. Transcription is provided to make your stories searchable and readable; the original photograph is always kept as written. Google processes this data as our service provider and, per Google's terms for these APIs, does not use it to train its general models. See Google's privacy terms for details.
5. Where your data is stored (service providers)
We use the following providers to operate Longhand. Your data may be processed by them on our behalf:
- Google Firebase / Google Cloud — authentication, database (Firestore), file storage (your photos), messaging (reminders), and abuse protection (App Check). Stories and photos are stored here.
- Google Gemini (Firebase AI) — handwriting transcription and question suggestions (see Section 4).
- Apple / Google Sign-In — only if you choose to link an account.
- RevenueCat — only if and when in-app purchases are enabled, to manage subscriptions and purchases. (No purchases are offered while this feature is turned off.)
- Google Firebase Analytics — product interaction events and a device identifier, used to understand how the app is used (Section 2d).
- AppsFlyer — install attribution and marketing measurement, using the same events and device identifier (Section 2d). AppsFlyer runs with the advertising identifier disabled, so it cannot be used to track you across other companies' apps or websites.
These providers may store data on servers outside your country. We rely on their respective safeguards for international transfers.
6. Sharing
Stories and questions are shared only between the two members of a family (the person who set it up and the person who answers). We do not share your personal information with anyone else except the service providers above, or where required by law.
The analytics and attribution events described in Section 2(d) are shared with Google and AppsFlyer as set out above. They contain no stories, photographs, transcripts, names, email addresses or invite codes.
7. Data retention and deletion
We keep your data for as long as your family's archive exists. You can delete your data at any time:
- Delete individual questions or stories from within the app.
- To delete your entire family archive and account, use the in-app option or our account deletion page, or contact development@digitalsauce.io and we will permanently delete it.
When you delete a story, its photograph and transcript are removed from storage.
8. Security
Access to your family's data is restricted to the signed-in members of that family. Photos cannot be listed or browsed by others, and our database rules enforce members-only access. We use Apple's App Attest / App Check to help block abuse. No system is perfectly secure, but we work to protect your information.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to certain processing. To exercise these, contact development@digitalsauce.io. We will respond within a reasonable time and in line with applicable law.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where appropriate, notify you in the app.
11. Contact
Questions about this policy or your data:
Digital Sauce — development@digitalsauce.io
This document is provided as a starting template for Longhand and should be reviewed by qualified legal counsel and tailored to the Company's legal entity, registered address, and governing jurisdiction before publication.