Why your sex life should not live in Notes
Not because anything dramatic will happen. Because of the ordinary, boring ways a note leaves the place you put it.
Most people who track any of this track it somewhere improvised. A note on the phone, a spreadsheet, a message thread with themselves, the notes field of a period app. It works, right up until you think about where that text actually is.
What happens to a note
A note is not one file in one place. It syncs, which means it exists on every device signed into that account — including the iPad someone else uses and the laptop at work. It appears in system-wide search results, which means a name or a word can surface on a lock screen or in a shared context you were not thinking about. It gets backed up, sometimes to a provider that can read it. It shows in previews and widgets. It is included in an account export if anyone ever requests one.
None of this is a breach. It is all the software working correctly. The problem is that the design assumes the contents are unremarkable, and yours are not.
Notes, docs, spreadsheets, chat threads
- Synced to every signed-in device
- Indexed by system search
- Readable by the provider in most default configurations
- Included in account-wide exports and subpoenas
- Visible in previews, widgets and notifications
- Recoverable from backups long after deletion
- No second layer of authentication
An on-device record
- Stored locally, on one phone
- Not in system search
- No provider account, so nothing to hand over
- Backup optional, in your own encrypted container
- Nothing recognisable on the lock screen
- Deleting means deleted
- Face ID and a passcode by default
The threat model that actually applies
People imagine the risk as a hacker. It is almost never a hacker. In practice the realistic scenarios are mundane and much more likely:
- Someone picks up your unlocked phone to look at a photo
- A notification preview appears while the phone is on a table
- A shared iCloud or Google account you set up years ago and forgot about
- A work laptop signed into a personal account, and a search for something else
- A family member, a partner, a border officer, a repair technician
Each is boring. Each has ended relationships, outed people to family, and in some countries carries a much heavier cost than embarrassment. The defence against all of them is the same: the data should not be somewhere it can be casually encountered.
What "on-device" has to mean
The phrase gets used loosely, so it is worth being specific about what makes a difference:
No account. If there is no sign-up, there is no server-side record of you, no password to leak, and nothing for anyone to request. This is the single largest difference, and everything else follows from it.
No analytics. Usage telemetry is normal in software and unremarkable in most contexts. In this context, "user opened the STI testing screen" is a sensitive fact about a real person, and the safest amount of it to collect is none.
Backup under your control. If you want it on a new phone, that should go through your own encrypted storage, not a company's database.
A lock that is on by default, and ideally a second code that opens something harmless or wipes the record entirely — because the realistic threat is a person holding your unlocked phone, not a remote attacker.
Ask what the company could hand over if it were compelled to, and what it could lose if it were breached. If the honest answer is "your intimate history, attached to your email address," the app's privacy policy is not the point. The only data that cannot leak is data that was never collected.
Questions people actually ask
Is iCloud backup safe for this?
Backups go into your own private container and are encrypted by Apple. Whether that encryption is end-to-end depends on whether you have Advanced Data Protection turned on — worth checking in your Apple Account settings, and worth turning on regardless of what apps you use. Or skip backup entirely and keep the record on one device.
What if I lose my phone?
Without a backup, the data is gone. That is the genuine trade-off of this model and it should be stated plainly rather than glossed over. For a lot of people, losing a year of logs is a much smaller problem than the alternative failure mode.
Does an app like this appear on my App Store history?
Purchases and downloads are visible in an Apple Account, including a Family Sharing one. This is true of everything you install and is worth knowing if that account is shared. The app name and icon are the exposure, not the contents.
This page describes how different kinds of software handle data in general terms. It is not legal advice and not a security audit of any specific product. Candor is a personal record-keeping app; it does not diagnose, treat or prescribe.