Scratch that

Privacy

Last updated 26 July 2026

We can't read your messages and we can't see your photos. Not "won't" — can't. Here is exactly how that works.

Nothing readable reaches us

Scratch that has no accounts, no sign-in, no analytics, and no third-party SDKs. There is no profile of you anywhere, because there is nothing collecting one.

One thing does leave your phone: the encrypted photo blob, into an Apple CloudKit container we administer. We can delete those records. We can never read them. Nothing else — not your words, not your keys, not who you sent to — ever reaches us.

The words you send

A text card travels inside your iMessage thread, carried by Apple's Messages — end-to-end encrypted by iMessage the same way any of your messages are. The line is encoded in the message itself; it never touches a server of ours.

Photos behind the foil

When you hide a photo, the photo itself is encrypted on your phone with AES-256-GCM before it leaves the device. Only the encrypted result is uploaded — to Apple's CloudKit, into a public-database record carrying no name, no message and no contact: just the ciphertext and its expiry date. CloudKit itself stamps that record with the time and an anonymous per-app account identifier, which is why sending a photo needs iCloud. It tells us nothing about who you are or who you sent to.

One part does not expire. A 32-pixel thumbnail travels inside the message itself, shown blurred under the foil, so there is something to tease while the real photo downloads — and so the card still shows something once the 30 days are up. Thirty-two pixels is a smear of shape and colour, not a picture. But it lives in the message rather than the cloud, so it stays as long as the conversation does — and the blur is how we draw it, not a property of the data. iMessage encrypts it end to end the way it encrypts anything you send; our own AES-256 layer covers the full photo, not this.

Sealing

A card can be sealed shut until a moment you choose. The seal is enforced on the device; we are not told what you sealed, to whom, or when.

Said plainly: a seal is a promise, not a lock. It is your recipient's phone that keeps it, so someone determined to look early — by changing their clock, say — can. Treat it as anticipation, not as security.

Reporting a photo

If someone sends you a photo you want gone, report it from inside the card. That sends us one thing: the id of the encrypted record. No key, no image, no copy of your conversation.

We delete that record within 24 hours. We don't assess it first — we can't see it, so we act on your word alone. That removes the encrypted copy from the cloud for good, and it can never be downloaded again. What it cannot do is reach a photo that already loaded onto a phone; no app can take back a picture someone has already received. You can also block the sender directly in Messages, which stops everything from them, not only cards from us.

What is stored, and where

No third parties

We don't sell, share, or hand your data to anyone. There is no advertising, no tracking, and no analytics partner — there is no data to give.

Children

Scratch that is not directed at children under 13, and we knowingly collect no personal data from anyone.

Your rights

The app itself collects nothing about you, so there is normally nothing for us to export or delete. The one exception is if you email us — to report a photo, or for support. Then we hold what you sent: your email address and your message. Ask us and we will delete it. Under the GDPR you keep every right regardless, and the address below reaches a human.

Changes

If this policy changes, the date at the top changes with it. Material changes will be reflected here before they take effect.

Contact

Mindact Solutions AB, Sweden — mathias@mindact.ai

‹ back