Privacy Policy
Poeia (“the App”) is a creative writing tool developed by Cognitales LLC. It helps poets and writers find emotionally resonant words through AI-assisted suggestions. This Privacy Policy describes what data the App handles, how it is used, and your rights.
By using Poeia you agree to the practices described in this policy. If you do not agree, please do not use the App.
1. Account & Authentication
Sign-in is optional. You do not need to create an account or sign in to use Poeia. The App is fully usable — searching for words, saving them, writing poems, and purchasing a Poeia Premium subscription — as an anonymous user. When you first open the App, we create an anonymous session for you. This session has no name, email, or Apple identifier attached; it exists only to associate your device with your subscription entitlement and to enforce fair-use limits.
Sign in with Apple is available at any time, but never required. You may optionally choose to sign in with Apple — for example, to use your Premium subscription on another device, or to recover your account. Only if you choose to sign in does Apple provide us with:
- A unique user identifier (Apple “sub”) — used as your account identity once you link. This is an opaque, app-scoped string that Apple generates; it is not your Apple ID.
- Your email address — only if you choose to share it. You may use Apple’s private relay (“Hide My Email”) to receive a unique, random address instead.
- Your name — only if you choose to share it during sign-in. We do not require it.
An anonymous user profile carries only a random fraud-prevention identifier (described below) and your subscription record — no Apple identifier, name, or email. If you later sign in with Apple, your existing anonymous account is linked to your Apple identity so your subscription and data carry over.
Your profile is stored on our servers (hosted on Supabase, a cloud database provider) for the sole purpose of identifying your account, managing your subscription, and enabling account deletion. We do not use it for marketing or advertising.
Session metadata. When your anonymous session is first created (and again if you later sign in), the App sends a small amount of technical metadata to our authentication server:
- App version — the version of Poeia you are running (e.g. “1.2.3”), used to diagnose version-specific issues.
- Operating-system version — a general OS identifier (e.g. “iOS 26.0”), used for compatibility and support.
- A fraud-prevention identifier — to protect our service from abuse, our authentication system may use a fraud-prevention identifier: a random value generated by the App and stored in your device’s iOS Keychain. It is not the IDFA, IDFV, or any hardware-derived or advertising identifier, and it is not used to track you across apps or websites. When used, it serves only to detect and prevent abuse of account creation (for example, automated or fraudulent creation of many anonymous accounts). It is sent only to our own authentication server, never to advertisers or AI providers, and it is removed when you delete your account.
2. Data Processed Off-Device
To generate word suggestions, Poeia sends each query to a cloud backend operated by Cognitales LLC. Our backend forwards the query to a third-party AI inference provider, returns the suggestions to your device, and briefly logs the request for operational purposes (see Section 6).
What is sent off your device:
- Your seed word or search term.
- Any refinement text you provide (e.g., “but darker”).
- If you have an active poem project, its title and up to 20 of your most recent word selections from that poem — used to tune suggestions to your poem’s tone.
- Your suggestion-count preference and similar request settings.
What is NOT sent to AI providers: your name, email address, Apple user identifier, device identifiers, location, contacts, or photos. Queries sent to the AI inference provider do not contain your identity.
Recipients of off-device data:
- Supabase (database provider) — stores your account profile and subscription status. Hosted on AWS infrastructure.
- Cognitales’ cloud infrastructure (Google Cloud Platform) — hosts the AI proxy used for routing, rate-limiting, and prompt construction.
- Third-party AI inference providers — used to generate the word suggestions. Data sent to these providers is governed by their own privacy and data-handling policies and by data-processing agreements we maintain with them.
We reserve the right to change AI and infrastructure providers at our discretion as the technology evolves. Material changes to the categories of data we send, the purposes of processing, or our retention practices will be reflected in a published update to this policy.
3. Data Stored on Your Device
The following data is created and stored on your device using Apple’s SwiftData framework. It is never uploaded to our servers. Some of it is also mirrored to your own private iCloud storage when iCloud Sync is turned on, as described under iCloud Sync below.
- Poem projects — titles and creation dates for your poem workspaces.
- Word selections — words you save, with their definitions and the poem they belong to.
- Query history — your past search terms and refinements, for easy re-use.
- Preferences — settings such as result count, theme, and cached subscription tier, stored via UserDefaults.
- Authentication tokens — session credentials for your account (anonymous or signed-in), stored in the iOS Keychain (encrypted, hardware-backed).
iCloud Sync: Poeia can keep your work in step across your Apple devices. This setting is on by default, and you can turn it off at any time in Settings; a change takes effect the next time you launch the App.
When iCloud Sync is on, your poem projects, word selections, query history, and in-App settings such as your banned word list and result count are mirrored from your device into the private database of your own iCloud account, using the Apple ID already signed in on your device. That storage is in your own iCloud account, under your control, and governed by Apple’s terms. No Poeia account and no Sign in with Apple is involved, and your creative content still never reaches our servers. We cannot read the contents of your private iCloud database and have no access to it. Apple’s handling of data stored in iCloud is governed by Apple’s privacy policy. Authentication tokens are not part of iCloud Sync; they remain in your device Keychain.
If you turn iCloud Sync off, the App stops mirroring further changes and your data remains on your device. Content that was already synced stays in your iCloud account until it is removed. You can delete it from within the App while sync is still on, which also removes the synced copy, or manage it through your device’s iCloud storage settings. Because we have no access to your private iCloud database, we cannot delete that content for you.
4. Usage Analytics
To understand how people use the App and to improve the experience, Poeia collects a small number of first-party usage events. These events record that an action occurred — they do not contain the content of your writing or the words you searched for.
Events collected:
- Onboarding completed — recorded when you finish the introductory walkthrough, so we can measure whether the onboarding is effective.
- Free quota reached — recorded when you reach your daily free-query limit, so we can evaluate whether the free tier is appropriately sized.
- Paywall viewed — recorded when the upgrade screen is shown, so we can understand conversion and whether the offering is clear.
- Trial started — recorded when you begin a free trial of Poeia Premium, for subscription-health monitoring.
Each event is tied to your account (anonymous or signed-in) for product-improvement purposes. It is declared in the App Store as “Product Interaction” data, linked to your identity.
What analytics NEVER include:
- Your search terms, seed words, or refinement text.
- The word suggestions you receive.
- Your poems, word collections, or any creative content.
- Your name, email address, or Apple identifier.
- Your location, contacts, or photos.
These events are collected by our own first-party system — no third-party analytics SDK, advertising framework, or crash reporter is used. Events are sent only to servers operated by Cognitales LLC, never to advertisers, data brokers, or any third party. We do not use analytics events to track you across other companies’ apps or websites. Privacy is a product value for a writer’s tool — we collect the minimum needed to make Poeia better, and nothing more.
5. Data We Do NOT Collect
- No advertising identifiers. We do not collect the IDFA, IDFV, or advertising identifiers, and we do not use any identifier to track you across other companies’ apps or websites. The only device-stored identifier our authentication system may use is the random fraud-prevention identifier described in Section 1 — generated by the App, kept in your device Keychain, and used exclusively for abuse prevention, never for advertising or tracking.
- No third-party analytics or tracking. The App uses only the first-party usage analytics described in Section 4. It contains no third-party analytics SDKs, advertising frameworks, or crash reporters. We do not track you across apps or websites.
- No location data. The App does not access your location.
- No contacts or photos. The App does not read your address book or photo library. (The App can save images you create to your Photos library at your request, but does not read from it.)
- No poem content on our servers. Your poems, word collections, and query history stay on your device. We never receive your creative content on our servers. When iCloud Sync is on, your device mirrors that content to your own private iCloud storage, which we cannot access (see Section 3).
6. Third-Party Data Sharing
We do not sell your data. We do not share your data with third parties for advertising or marketing purposes. Off-device data transfers are limited to those described in Sections 1, 2, and 4: account management (Supabase), the word-suggestion queries sent to our cloud proxy and AI inference providers (operating on our behalf under data-processing agreements), and first-party usage analytics sent to our own servers. The iCloud Sync described in Section 3 is not a transfer to us or to a third party: it moves your content between your device and your own iCloud account.
We may disclose data if required to do so by law, a valid legal process, or to protect the rights, property, or safety of Cognitales, our users, or others.
7. Data Retention & Deletion
On your device: All locally-stored data (poems, word selections, query history) is removed when you delete the App. Authentication tokens stored in the iOS Keychain may persist after app deletion depending on your iOS version; signing out before uninstalling clears them.
In your iCloud account: If you used iCloud Sync, deleting the App does not by itself remove the copy held in your private iCloud storage. That copy stays under your control until you remove it, either by deleting the content in the App before you uninstall, or through your device’s iCloud storage settings. We cannot delete it for you, because we have no access to it.
Account data on our servers: Your profile and subscription record are retained for as long as your account exists. For an anonymous account, this profile contains only a random fraud-prevention identifier and your subscription record — no Apple identifier, name, or email. If you sign in with Apple, the profile also holds your Apple user identifier and optional email. When you delete your account (see Section 8), this data is permanently removed.
Operational logs: Logs of API requests are retained for no longer than 90 days for security, debugging, abuse-prevention, and rate-limit enforcement. After that window they are automatically expired.
Analytics events: The first-party usage events described in Section 4 are retained for no longer than 90 days for product-improvement analysis. After that window they are automatically expired.
At third-party providers: Data forwarded to third-party AI inference providers is subject to those providers’ own data-retention policies and the data-processing agreements we maintain with them.
8. Account Deletion
You can delete your Poeia account at any time:
- In the App: Open Settings → Account Management → Delete Account. This works for both anonymous and signed-in accounts — signing in with Apple is not a precondition for deletion. If you have signed in with Apple, your Apple token is revoked as part of the deletion. Upon confirmation, your server-side profile (including any linked Apple identity) is permanently deleted.
- Without the App: If you no longer have access to the App, visit poeia.app/delete-account or email support@cognitales.com to request account deletion. We will process requests within 30 days.
Account deletion removes your profile and subscription record from our servers. It also purges the fraud-prevention identifier described in Section 1 — the random device value is cleared from both your account profile and our fraud-prevention records, so it does not persist after your account is deleted. Deleting your account from within the App also wipes that device’s local data, including your poems, word collections, query history, and preferences. If iCloud Sync is on, those deletions propagate to your private iCloud storage and to your other devices. If you instead request deletion without the App, content already stored on your device is not affected and remains until you delete it or uninstall the App.
9. Subscriptions
Poeia offers optional paid subscriptions (“Poeia Premium”) managed entirely through Apple’s App Store in-app purchase system. You can purchase Premium without creating an account or signing in — the subscription is associated with your anonymous session and your App Store purchase, and can be restored on a new device (via Apple’s “Restore Purchases”) without signing in. We store a record of your subscription status (product identifier, expiration date) on our servers to enforce entitlements. We do not have access to your payment information — all billing is handled by Apple.
10. Children’s Privacy
Poeia is not directed at children under 13 and we do not knowingly collect personal information from children under 13. The App is intended for general audiences who can use a creative writing tool appropriately.
11. Security
All communication between the App and our servers, and between our
servers and our processors, uses encrypted HTTPS/TLS connections.
Requests to our backend are authenticated with user-scoped tokens,
rate-limited, and audited for abuse. Authentication tokens stored on
your device use iOS Keychain protection (kSecAttrAccessibleWhenUnlockedThisDeviceOnly), meaning they are encrypted at rest and accessible only while the
device is unlocked.
No system is perfectly secure. We use industry-standard practices and continually review our controls, but cannot guarantee absolute security of data transmitted over the internet or stored on any device.
12. International Users
Our cloud infrastructure and AI inference providers may process data in the United States or other countries where our providers operate. By using the App you understand that your data may be transferred to and processed in jurisdictions whose data-protection laws may differ from those of your country of residence.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The “Effective Date” at the top reflects the most recent revision. Material changes will be noted in the App’s release notes. Continued use of the App after a material change constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy, contact us:
Cognitales LLC
Email:
support@cognitales.com