Overview
Cabin Talk is designed to keep conversation content end-to-end encrypted while supporting nearby delivery, an optional CloudKit relay, and an optional private iCloud backup. Cabin Talk is a general-audience app and is not directed to children. Brent Gaddis provides Cabin Talk and is the data controller for the app information described here. The monitored privacy contact is support@brentgaddis.com. This policy also describes Trip Board and optional Help & Feedback reports introduced in version 1.1.
Information Cabin Talk handles
Cabin Talk handles group display names, memberships, invitations and group secrets, signed messages, selected photos, delivery and read state, blocks, preferences, device public keys, and local diagnostics. Version 1.1 adds shared Trip Board text such as gates, seat assignments, hotel details, meeting points, and itinerary notes. These details are voluntarily entered by group members; the app does not automatically collect location for the board. Selected photos are prepared without ordinary embedded metadata. The visible content of a photo can still reveal information.
Encryption, CloudKit, and backups
Text sent through the public CloudKit relay is sealed end-to-end. Starting with version 1.1, photos and Trip Board updates can also use the encrypted relay as well as nearby delivery. Apple processes sealed payloads and service metadata; the developer does not hold the group key needed to read the content. Sensitive group secrets and identity keys are stored in the Keychain. Retained conversations and room-recovery records are encrypted or protected with Apple file protection. The current Trip Board has its own encrypted per-group local store and can be included in an optional private iCloud backup. Apple processes iCloud and CloudKit data under its terms.
Permissions and sharing
Nearby communication uses Local Network access. QR invitation scanning uses the camera. Adding a photo uses Apple’s system photo picker. iCloud features require an available iCloud account. Anyone who receives a valid group invitation or message may keep what they receive, so share secrets and content only with people you trust.
Retention and your controls
Local data remains until you erase it or remove the app. Cabin Talk can keep up to 20 local archives. The public relay is designed around a 30-day delivery window, although records can remain longer when creator-only CloudKit permissions limit cleanup. A private iCloud backup remains until it is replaced or deleted with the in-app control. Erasing this device does not delete a recipient’s copy, and backup or relay deletion can take time to propagate through Apple services.
Optional Help & Feedback reports
Help & Feedback lets you prepare a problem report, general feedback, or a feature request for the developer. Nothing is sent by opening the form or preview. Each report has an ID and includes your written feedback, the app version/build, and report time. Technical diagnostics and recent app events are optional and off by default. If selected, diagnostics include the device model code, OS/platform, fixed feature/error categories and times, and available numeric Apple MetricKit crash, hang, CPU, disk-write, or performance summaries. The app never automatically adds message or Trip Board text, conversation names, participant or account identifiers, invitations, CloudKit records, network addresses, file paths, raw errors, or raw call stacks. An image is attached only when you select one; resizing removes original filename and embedded camera/location metadata, but visible image content can still identify people or places. You review the exact report and attachment before choosing email, sharing, copying, or saving. Your chosen mail or sharing service processes the content and may include your sender address or account name. Reports sent to the developer are used for support and reliability, not advertising or tracking, and follow the support retention practices below.
Local diagnostics, review timing, and controls
Cabin Talk keeps limited on-device usage counts to avoid asking for reviews or feedback too early or too often. These counts are not uploaded. Local diagnostic storage is bounded to 40 approved error entries and 20 numeric diagnostic windows retained for up to 30 days. A selected report includes at most five recent diagnostic windows and, only when you also enable recent events, up to 20 fixed-code error entries. Apple supplies MetricKit summaries asynchronously; missing summaries do not prove that no crash occurred. Delete Local Diagnostics clears retained local summaries, and Erase All App Data also resets local App Care counters. Neither action removes copies you already sent, exported, or saved with another app. Cabin Talk adds no advertising tracking, session replay, or third-party analytics SDK.
Website, support, privacy requests, children, and policy changes
Cabin Talk’s app-data practices are described above and are separate from its pages on brentgaddis.com. Those pages use first-party aggregate analytics operated through Cloudflare. The site counts page views and allowlisted actions and keeps coarse source, country, device, browser, operating-system, engagement, performance, and reliability totals. It does not store raw analytics events, visitor or session identities, raw or hashed IP addresses, cookie or local-storage visitor IDs, full user agents, full referrers or URLs, form contents, arbitrary text, or a person’s raw click history. Country and source cells below five are suppressed, and aggregates are retained for up to 24 months. Cloudflare still processes request and network metadata to deliver and protect the site. If you contact support, the website, Cloudflare Turnstile, Cloudflare’s delivery services, and the email provider process the app selection, request type, reply email, subject, message, security signals, and delivery metadata you submit. Form contents are delivered to Brent’s monitored mailbox and are not written to website analytics or a website message database. Support email is retained only as reasonably needed to respond, maintain security and support records, resolve disputes, and meet legal obligations, then deleted or de-identified when no longer needed. Do not submit passwords, recovery keys, government identifiers, payment-card data, or unrelated sensitive content. The website does not use cross-site behavioral advertising or sell or share personal information for that purpose, so browser Do Not Track and Global Privacy Control signals do not change its behavior. Cabin Talk is offered to a general audience and is not directed to children under 13. If Brent learns that a child supplied personal information through a developer-controlled channel without required consent, he will take reasonable steps to delete it. Depending on where you live, applicable law may provide access, correction, deletion, or appeal rights; use the privacy-request form or email support@brentgaddis.com. Identity may be verified, and requests will be handled as applicable law requires. Material changes will be posted on this page with a new effective date, with additional notice or consent when required.
Relay identity, delivery, and backups
Public CloudKit relay records can include sealed content, signatures, delivery state, opaque device or creator identifiers, timestamps, and Apple service metadata. Relay content is signed and encrypted for the group, but Apple still handles those opaque records and network metadata. Relay catch-up requires the app to be open and uses a 30-day fetch window; best-effort deletion is limited by CloudKit creator ownership. Optional private iCloud backup can contain retained messages, photos, the current Trip Board, invitations, group secrets, and preferences until replaced or deleted with the separate in-app backup control. Unconfirmed Trip Board conflict copies remain local. Deleting a conversation permanently also removes its local board. Avoid sharing a group secret with anyone you do not trust.
Questions
Contact Brent Gaddis with privacy questions about Cabin Talk.