Privacy Policy
Effective date: September 7, 2026
One Island is operated by 唐西良 (Tang Xiliang, “we”). For requests about personal information, accounts or content, contact imseantang@gmail.com.
This policy covers the One Island iOS app and its supporting website and services. Apple's own policies also apply to services it provides, including Sign in with Apple and App Store purchases.
1. Information we process
On-device content
You can use local journals, mood records, focus and plant features without signing in. These records are stored on your device. Installing or opening the app does not itself automatically upload these private records to our servers.
Journal text, titles, moods, tags, photos, letter drafts, focus and plant-care records, island profiles, contacts and collection folders may contain personal information you choose to provide. Be careful when recording or sending information about other people.
Accounts and sign-in
When you use Sign in with Apple, we process the identifier, email address and any name information Apple actually supplies to create your account and maintain sign-in. If you choose Hide My Email, we receive Apple's relay address instead of your real email address.
We retain credentials needed to maintain sessions and revoke Apple authorization. We do not receive your Apple Account password. Island IDs, names, receiving language and letter-receiving preferences identify islands and support communication.
Cloud synchronization
When you enable Pro synchronization or initiate it manually, we receive the relevant journals, photo references, drafts, focus, plant and care records, contacts, folders and island profile. Subsequent synchronization primarily transfers changed records; photos are uploaded separately. We also process record IDs, versions, update times, deletion markers and file-integrity hashes.
Pro synchronization is enabled by default while your subscription is active and can be disabled in the app. The app checks for changes after edits and while active in the foreground; iOS may suspend these checks in the background. Active focus timers, system biometric information, the device's privacy-lock setting and device preferences such as language, sound and appearance are not included in business-data synchronization.
Synchronization coordinates data between devices; it is not an unlimited historical backup. If there is a conflict, you need to choose which version to keep.
Letters
After you confirm sending a letter, the server processes its text, sender and recipient island identifiers, delivery mode, language, times, delivery and read status, and reply references. Recipients see the letter and island details needed for communication, but do not thereby receive your Apple sign-in email address.
Direct delivery uses the island ID you enter. Random delivery matches among islands that allow incoming letters. Blocking and receiving preferences limit communication.
Reports include the reason, relevant letter evidence and information needed for review. Evidence may contain letter text and is reviewed by authorized personnel for investigation and action.
Subscriptions
Apple processes payments. We process product, transaction and subscription identifiers, purchase and expiry times, verification results, subscription status and the identifier linking a purchase to your One Island account to validate access and restore purchases. We do not receive your full bank-card details or Apple payment password.
Operations and support
The website and APIs may generate IP addresses, request times and paths, client or browser information, session records and error logs for security, troubleshooting and operation. When you contact support, we also process the email address, problem description and attachments you provide.
2. Purposes and disclosures
We use this information for local features, sign-in, synchronization, letter delivery, membership verification, content safety and support. We do not sell personal information. The current product does not display third-party advertising or perform cross-app advertising tracking.
Apple provides sign-in and purchasing services. Cloudflare provides infrastructure for the website, APIs, database, file storage and security. Providers process relevant information as needed to deliver their services; their roles and independent processing are also governed by their own policies.
Letters enter delivery only when you send them. Private journals are not published to other islands. Routine administrative lists show dates, status and necessary summaries. Controlled access to text requires permission, a recorded reason and a declaration of user authorization, with an access audit. Report evidence is accessed through the reporting process.
Where law, valid legal process or a necessary measure to protect users or the service requires disclosure, we assess its lawful basis and scope.
3. Storage and security
Local records use iOS app storage and file-protection mechanisms. When the privacy lock is enabled, the system handles authentication; we do not obtain Face ID or Touch ID templates or your device passcode.
Cloud records use account-controlled databases and private file storage, with HTTPS transmission. We implement session verification, access controls, integrity checks and necessary audits.
Cloud synchronization and letters are not currently end-to-end encrypted: servers process content, and personnel with the appropriate permissions following the access process may access it. The privacy lock restricts access on your device; it does not mean only you can decrypt cloud content.
Infrastructure may process information outside your country or region. We do not currently promise storage exclusively in any one country or region. Where applicable law requires additional arrangements for international processing, we must implement the required measures.
4. Retention and deletion
Local records remain until you delete them, clear local data or uninstall the app. Exported files, backups and copies you save elsewhere must be managed in their respective locations.
Cloud records are retained while providing account and synchronization services. Membership expiry does not automatically delete them, and you can currently download existing cloud data after expiry. Changes made only on your device, including deletions, reach the cloud after successful synchronization.
Moving a journal to Recently Deleted is not permanent deletion; its text and photos remain available for recovery. After permanent deletion and synchronization, the server removes the current record text and retains the minimum deletion and version information needed to prevent an old device from uploading it again.
Deleting a letter from your list may only hide your side of the record. It does not guarantee deletion of recipients' copies, screenshots or previously submitted report evidence. Account deletion removes the associated account and relevant business records. Necessary report evidence and payment-verification records unlinked from the account may remain for complaints, prevention of incorrect purchase reassignment or legal obligations.
Unreferenced photos and old files are reclaimed by cleanup jobs; physical deletion is not instantaneous with every interface action. Operational logs, audits and necessary transaction information are retained for the period needed for their purpose or applicable legal requirements.
Deleting an account does not automatically remove offline archives, exports or backups on your device, or cancel App Store auto-renewal. Manage these separately.
5. Your choices and requests
You can choose not to sign in, synchronize or send letters, and can manage photo, notification and biometric-related permissions in system settings. This may disable the relevant feature without affecting unrelated local features.
You can view, edit and export your records, manage receiving and blocking preferences, and request account deletion through the account settings. Deletion may require signing in with Apple again.
For access, correction, deletion or other rights available under applicable law, email imseantang@gmail.com. We may request proportionate identity verification and will handle requests within applicable legal time limits. Do not email Apple passwords or payment passwords.
6. Minors
We do not intentionally ask children for personal information beyond what the service requires. Minors must meet local requirements regarding age and parental consent. Guardians who believe a minor has improperly provided personal information can contact us.
7. Changes and contact
We will update this policy when features or processing materially change, and provide notice or obtain consent where applicable law requires it. This policy does not restrict your statutory rights.
Operator: 唐西良 (Tang Xiliang)
Email: imseantang@gmail.com