Privacy
Last updated 26 July 2026
We can't read your messages and we can't see your photos. Not "won't" — can't. Here is exactly how that works.
Nothing readable reaches us
Scratch that has no accounts, no sign-in, no analytics, and no third-party SDKs. There is no profile of you anywhere, because there is nothing collecting one.
One thing does leave your phone: the encrypted photo blob, into an Apple CloudKit container we administer. We can delete those records. We can never read them. Nothing else — not your words, not your keys, not who you sent to — ever reaches us.
The words you send
A text card travels inside your iMessage thread, carried by Apple's Messages — end-to-end encrypted by iMessage the same way any of your messages are. The line is encoded in the message itself; it never touches a server of ours.
Photos behind the foil
When you hide a photo, the photo itself is encrypted on your phone with AES-256-GCM before it leaves the device. Only the encrypted result is uploaded — to Apple's CloudKit, into a public-database record carrying no name, no message and no contact: just the ciphertext and its expiry date. CloudKit itself stamps that record with the time and an anonymous per-app account identifier, which is why sending a photo needs iCloud. It tells us nothing about who you are or who you sent to.
- The key that can decrypt the photo rides only inside the message you send, and nowhere else. It never touches the cloud. So only someone holding that message can open it — the person you sent it to, and anyone they choose to pass the card on to. Photos can only ever be sent into a one-to-one conversation, never a group.
- We cannot decrypt it — we never see the key, and there is no copy of it on any server we run. The key lives inside the message, which means it is exactly as protected as your Messages are. Turn on Apple's Advanced Data Protection and Apple cannot reach it either.
- The encrypted photo expires after 30 days — the app refuses to download it past that — and a sweep runs every day to delete expired blobs from Apple's servers, so the cloud copy is gone within about a day of expiring. Expiry protects the copy in the cloud; it never takes back what someone already received. Their phone keeps the last 100 photos they have opened, and keeps them for good: neither the 30 days running out nor deleting the message removes that copy. Deleting the app does.
One part does not expire. A 32-pixel thumbnail travels inside the message itself, shown blurred under the foil, so there is something to tease while the real photo downloads — and so the card still shows something once the 30 days are up. Thirty-two pixels is a smear of shape and colour, not a picture. But it lives in the message rather than the cloud, so it stays as long as the conversation does — and the blur is how we draw it, not a property of the data. iMessage encrypts it end to end the way it encrypts anything you send; our own AES-256 layer covers the full photo, not this.
Sealing
A card can be sealed shut until a moment you choose. The seal is enforced on the device; we are not told what you sealed, to whom, or when.
Said plainly: a seal is a promise, not a lock. It is your recipient's phone that keeps it, so someone determined to look early — by changing their clock, say — can. Treat it as anticipation, not as security.
Reporting a photo
If someone sends you a photo you want gone, report it from inside the card. That sends us one thing: the id of the encrypted record. No key, no image, no copy of your conversation.
We delete that record within 24 hours. We don't assess it first — we can't see it, so we act on your word alone. That removes the encrypted copy from the cloud for good, and it can never be downloaded again. What it cannot do is reach a photo that already loaded onto a phone; no app can take back a picture someone has already received. You can also block the sender directly in Messages, which stops everything from them, not only cards from us.
What is stored, and where
- On our servers: nothing readable. We run no server your messages pass through. The CloudKit container holding encrypted photos is ours to administer — we can count and delete those records, and we can never open one.
- In Apple's CloudKit: the encrypted photo blob, unreadable without the key, until its 30-day expiry.
- In the message itself: the line you wrote, the decryption key, and the 32-pixel thumbnail. None of it expires — it stays as long as the conversation does. Deleting the message removes your copy of it; the other person's copy is theirs.
- On your device: any photo that has loaded on your phone — one you sent, one you opened, or one waiting in an unfinished draft — each written with iOS complete file protection, unreadable whenever your phone is locked. Your text drafts sit in standard app storage: encrypted, but readable by the app any time after you have unlocked your phone once.
- In your own iCloud: if you keep lines under “yours”, those lines — up to fifteen short ones you wrote yourself — are mirrored to your personal iCloud key-value store, so they survive reinstalling the app and reach your other devices. That is Apple’s storage on your account, not a server of ours. We never receive it and cannot read it.
- In your iPhone backup: those photos, the way your Messages attachments are. If you back up to iCloud, Apple encrypts it; if you back up to a Mac, tick “Encrypt local backup”.
No third parties
We don't sell, share, or hand your data to anyone. There is no advertising, no tracking, and no analytics partner — there is no data to give.
Children
Scratch that is not directed at children under 13, and we knowingly collect no personal data from anyone.
Your rights
The app itself collects nothing about you, so there is normally nothing for us to export or delete. The one exception is if you email us — to report a photo, or for support. Then we hold what you sent: your email address and your message. Ask us and we will delete it. Under the GDPR you keep every right regardless, and the address below reaches a human.
Changes
If this policy changes, the date at the top changes with it. Material changes will be reflected here before they take effect.
Contact
Mindact Solutions AB, Sweden — mathias@mindact.ai
‹ back