Meddendum — Privacy Policy
Effective date: 2026-08-04 Applies to: Meddendum 3.9.0 Publisher: Backshear Studios LLC
Meddendum is a private reflective journal for medical students. Every feature works offline, and out of the box the app makes no network requests at all. This policy explains what the app does and does not do with your information. In short: Meddendum collects nothing about you automatically, stores your journal encrypted on your device, and sends nothing anywhere unless you ask it to — the exceptions are iCloud sync, which you turn on, and a bug report, which you write and send. Both are named below.
Meddendum has no account system and no server that collects anything about you. There IS one server involved, and it is worth naming plainly: a small relay that forwards a bug report to the developer’s inbox — but only when you write one and press send. Things leave your device by your own choice, and these are the ways that happens:
- the optional iCloud sync — off by default, and it moves only the already-encrypted vault;
- any backup or export you create, which goes wherever you save it;
- your recovery key, if you copy it or download it;
- your passphrase, if you let a password manager keep it;
- the passkey, if you use the browser’s biometric unlock and your platform syncs passkeys;
- a feedback report you write and press Submit on — your own words and your app version, never a journal entry (see Feedback you choose to send, below).
Each of these is described below, in its own words.
Meddendum is free to download, and your journal — capturing, editing, searching, printing, exporting and backing it up — is free forever. On iOS, one screen is a one-time purchase: the Apply tab, the residency-application toolkit. Apple handles that purchase through the App Store; nothing about it reaches Backshear Studios LLC, and nothing about it is stored in your encrypted journal — see Buying the Apply tab below.
What we collect
Nothing. Meddendum has no analytics, no accounts, no advertising, and no third-party SDKs. Backshear Studios LLC receives no data from your use of the app — we cannot see your journal, your usage, your device, or anything else.
Buying the Apply tab does not change that. Apple processes the purchase and tells us nothing that identifies you; what we can see in App Store Connect is the same aggregate sales reporting every developer sees — how many units sold, in which countries — with no way to connect any of it to a person, a device, or a journal.
What the app stores, and where
Everything you write is held in an encrypted vault on your device. What follows is what that vault holds and how it is protected, and — in the last bullet — the few small things kept outside it. The records the application-season tools keep get their own section, People and programs you record, below. – Your entries are encrypted with a key derived from your passphrase (PBKDF2-HMAC-SHA256, 600,000 iterations) and a random 256-bit master key, using AES-GCM-256 through the platform’s own Web Crypto implementation. On the iOS/Mac app the vault file is written with iOS Complete File Protection and is excluded from device backups — which also means a new phone restored from an iCloud or Finder backup does not bring your journal with it. The copies of the vault that exist are the ones you make: an exported backup, or the optional iCloud sync. Meddendum sends the vault to iCloud only if you turn that sync on, and then only as ciphertext Apple cannot read. A backup you export yourself goes wherever you save it — including iCloud Drive, if that is the destination you pick. – Your writing in progress and your study material sit in the same encrypted vault: the quick capture on Home, the editor draft the app autosaves so a crash or an auto-lock cannot lose your work, your ERAS draft, your Tips, Tricks, & Tests, and the optional private note on an entry (which is deliberately left out of every de-identified export). The application-season tools keep their own records in there too — programs, people, rotations, interviews, your cycle configuration, and a per-season decision log of your signal choices and any export overrides, capped at the most recent 500. What those records contain is set out in People and programs you record below. – If you turn on Face ID / Touch ID unlock in the iOS or Mac app, the key that unlocks your journal is wrapped by a non-exportable key held in that device’s Secure Enclave. That enclave key cannot be extracted or copied: it never leaves the device, and no copy of it is synced or backed up. The wrapped bundle it produces does sit in the vault file, so it travels with a sync — but only the device that made it can use it. On a device where that hardware key cannot be created, Meddendum falls back to storing the passphrase itself in the device Keychain behind the same biometric check — marked this-device-only, so that copy is never synced and never enters a device backup. – In a browser, the same switch uses a passkey instead. Meddendum asks your browser to create one for the address you run it from — labelled “Meddendum vault”, or your username if you set one — and derives the unlock key from it. Where passkeys are kept is your platform’s decision, not ours: if your device syncs passkeys (iCloud Keychain, a password manager), that one syncs with them. Meddendum cannot delete a passkey — a web page is given no way to. Turning the switch off, or erasing all data, makes the passkey useless to Meddendum but leaves it in your passkey settings; delete it there if you want it gone. – On devices without Face ID / Touch ID, you may instead turn on quick unlock, which stores your unlock secret in the device Keychain behind your device-owner authentication (Mac login password, Apple Watch, or device passcode). It is opt-in, off by default, and set separately on each device: the Keychain item is marked this-device-only, so that secret is never synced and never enters a device backup. The on/off preference itself lives inside your encrypted vault, so it travels with a sync or a restored backup — but a device that adopts a vault from elsewhere is asked the question again rather than inheriting the answer. Your passphrase always still works. – A recovery key can also open the vault if you forget your passphrase. Meddendum never stores it — you save it yourself, and the app offers two ways to do that. – Copy puts the key on the clipboard. In the iOS and Mac app that is a local-only pasteboard the system expires after about a minute and does not sync between devices. In a browser it is the ordinary clipboard: Meddendum tries to clear it after about a minute, and only where the browser lets it confirm the key is still there, so it never wipes something else you copied. A clipboard that has already synced to your other devices cannot be un-synced. Paste it into your password manager straight away. – Download .txt writes the key to a plain, unencrypted file. Anyone who reads that file can open your journal. Keep it the way you would keep a spare key to your flat — not in the folder with your backups. – Your password manager, if you let it. Meddendum’s passphrase fields are marked up so your browser or device can offer to generate and save the passphrase for you (on Apple devices, “Use Strong Password”). If you accept, the passphrase is then held by that password manager, under its rules, and syncs wherever it syncs. It is set up that way deliberately — a forgotten passphrase and a lost recovery key mean a lost journal — but the choice, and the storage, are yours rather than ours. – An optional, non-secret passphrase hint is stored in the clear so it can be shown on the lock screen. Do not put anything sensitive in it. It travels with the vault: it stays readable, without your passphrase, in an exported backup and in the synced copy. – An optional username you may set is a display-only label for your device’s sign-in / passkey prompt. It lives in your vault, is never treated as patient data, and never appears in a de-identified export. One thing to know: if you use the browser passkey unlock, this is the name Meddendum puts on that passkey, so it goes wherever your platform keeps passkeys. Pick a label you are content to see there. – Private well-being reflections — the few lines you write in the weekly check-in on Home, or in the Settings well-being card, about how you are doing. They sit in the same encrypted vault, the most recent 200 are kept, and they never appear in a de-identified export, the way the activity log and deleted entries do not. They run through the same identifier check before they are saved, even though no export ever carries them. Being in the vault, they do ride an encrypted backup and the optional iCloud sync — encrypted, like everything else in it. Settings shows the ten most recent and lets you delete any of those; Erase all data removes them all. – A short activity log of security-relevant actions — unlocks, entry added / edited / deleted, exports and export overrides, passphrase and recovery-key changes, and turning Face ID / Touch ID or quick unlock on or off — is kept inside the same encrypted vault, capped at the most recent 250. It records the action and a short non-identifying label (for example an export filename), never the content of an entry. It never appears in a de-identified export. Settings shows the most recent entries and lets you clear the whole log. – Deleted entries go to a “Recently deleted” buffer inside the vault so you can undo a mistake, then purge themselves — after 30 days, or once 50 newer deletions have pushed them out, whichever comes first. They never appear in a de-identified export. A small marker (an id and a date, never any text) stays in the vault for up to 180 days, so a deletion on one device also takes effect on your others. – Outside the encrypted payload, the app keeps only small non-content items: your display preferences (theme, accent colour, text size), so the right ones apply before the vault is unlocked; the readable part of the vault file itself — your passphrase hint, the schema version, the salts and iteration count the key derivation needs, and, if you turned biometric unlock on, the device-bound wrap of your key, which in a browser carries the passkey’s credential id and the address you enrolled it from; and three housekeeping markers — which storage the vault is kept in, whether the app has already asked your browser not to evict its data, and a counter that spots a stale restore. None of it is journal content, and erasing all data removes every one of them. The device-bound wraps are stripped out of an exported backup; the iCloud sync does not strip them, which the iCloud sync section says again. – On the iOS app, one more small file sits beside the vault rather than inside it, and it has its own section below: the one-word answer to the grandfathering question (Buying the Apply tab). It holds nothing you wrote and never travels in a backup or a sync. A second such file is described under Encouragement features — the counts a home-screen widget would read — but this release writes no widget file at all; that section says why.
People and programs you record
The application-season tools do store the names of people you work with: letter writers, program directors, coordinators. That is what a letter tracker is for, and it is worth stating plainly rather than leaving it to be discovered.
- Every person you add is classed as professional or patient-adjacent. An unset, unknown or tampered value fails closed to patient-adjacent.
- A professional name can be included in an export only in a context where naming them is the point — a letter packet addressed to that writer — and only after the app shows you the name it is about to include and asks you to confirm.
- A patient-adjacent name can never be allowlisted. There is no mechanism for it, by design.
- Programs, interviews and rotations store what you type about them — institution, city, dates, your own notes. These are your records and your schedule, not a patient’s.
Who holds this data
You do. The records live on your device, encrypted with a key only you have. Backshear Studios LLC runs no server and receives nothing, so there is no copy of your journal for us to hand over, correct or delete — not as a policy, but as a fact about how the app is built. That includes the names of the people you record: they exist only in your vault, and you add, edit and delete them yourself, in the app. If your school or your jurisdiction places obligations on you for records you keep about other people, those obligations are yours. The identifier check and the export gate are tools for meeting them, not a substitute for them.
Dates
Meddendum stores calendar dates only where they are yours: shelf-exam dates, rotation start and end dates, interview dates, the timestamps of when you wrote something. There is no calendar-date field for a clinical encounter — the entry editor asks for relative timing (“IM week 3”, “hospital day 2”) and lints that field like any other. Per-entry timestamps are stripped from every de-identified export.
Exports, backups and printing
Backups and exports you create are written only where you choose (the Files app, or a share-sheet destination you pick). The de-identified formats — Markdown, plain text, JSON, CSV, and print / Save-as-PDF — are produced entirely on your device.
An encrypted backup stays encrypted: the journal inside it can only be opened with your passphrase or recovery key. It carries a small readable header — the date, the app and schema version, how many entries there are, and a checksum of the encrypted block — so the app can tell you a file is damaged before it tries to restore it. That header contains no journal content. Two other things in that file are readable without your passphrase, and you should know before you decide where to keep it: your passphrase hint, if you set one, travels with every backup, as do the salts and iteration count the key derivation needs. The device-bound biometric wraps are stripped out before the file is written. Everything you wrote stays encrypted.
Every export that can carry something you wrote runs the same identifier check before anything is written — Markdown, plain text, JSON, CSV, the letter packet, the ERAS draft, the procedure summary, the rank worksheet, and print / Save-as-PDF. If it flags something, you have to read each finding in context and type an acknowledgement to continue; a checkbox is not enough, and the override is written to the activity log. Those exports also re-ask for your passphrase before the file is written.
Three files the app can write are not scanned, and you should know which:
- The encrypted backup, deliberately. It is written from your already-unlocked journal without a second prompt and without an identifier check, because nothing readable leaves — the file is the same ciphertext, openable only with your passphrase or recovery key.
- Your recovery key, which you have just authenticated to see, and which contains no journal content.
- The one-page privacy summary for faculty, which is the same fixed text for every user.
The procedure log can be exported as a .csv for schools that ask for one. It contains counts and your own goals — no dates and no patient details.
Reading a calendar file (.ics)
You can import interview invitations from a calendar file. This is not calendar sync: there is no account, no subscription URL, no CalDAV and no network of any kind.
You pick a .ics file; your device reads it locally. The parser looks at four fields only — event
name, start date, location and UID — and ignores everything else in the file, including organiser and
attendee details. Nothing is written to your journal until you tick the events you want, and only the
name, date and location of the events you tick are saved. The UID is discarded. Nothing is uploaded.
Microphone & speech (optional dictation)
If you choose to dictate a note, Meddendum uses the microphone and Apple’s on-device speech recognition,
which is forced to run entirely on your device (requiresOnDeviceRecognition). Audio is
transcribed locally and is never sent to Apple or any server, and the audio itself is discarded —
only the text you keep is saved, encrypted, in your journal. The app requests microphone and speech
permission only at the moment you first tap to dictate.
Local reminders (optional, off by default)
If you turn on Settings → Reminders in the iOS or Mac app — a browser has no reliable background scheduler, so the setting is not offered there — Meddendum schedules a small number of local notifications on your device: a nudge when your last backup is getting old, and a heads-up before a shelf exam you’ve dated in Tips, Tricks, & Tests. These are scheduled entirely on this device (Apple’s local-notification system): there is no server, no push service, and nothing about a reminder leaves your device. Notification text is deliberately generic — it never contains journal content, rotation names, or anything about a patient. The system permission prompt appears only when you turn the setting on, and turning it off removes every scheduled reminder.
One detail worth naming, since almost everything you type stays inside the vault: so the app does not schedule the same reminder twice, each shelf reminder is filed with the system under a name that includes the rotation it belongs to. That name is never displayed, and it does not go into the notification a person would see — it is an internal label the operating system holds so the app can find and replace its own reminders. Turning reminders off removes it with the reminder. (The other things you type that end up outside the vault are the passkey label and, on the fallback path, the passphrase in the Keychain — both described above.)
Encouragement features (all optional, all on your device)
Meddendum 3.8.0 adds sixteen small prompts meant to make it easier to keep writing: progress through the application checklist, a count of pearls due for review, coverage rings, a look back at your week and at each rotation you close, your own records, a weekly rhythm you set yourself, and one of your own earlier entries resurfaced. Every one of them is computed on your device from your own journal, and every one has its own switch in Settings, so any of them can be turned off individually.
They add nothing to what the app transmits — the app still transmits nothing of its own. Three of them put a number where you can see it without opening the app, and those three are worth naming exactly:
- The app-icon badge receives one integer, the count of pearls due, capped at a single digit. That is the whole message; no text of yours ever reaches it.
- The home-screen widget does not exist yet in this release, so no file is written for it. The code that would write one ships, but it is inert: the shared container it writes into is not registered on this build, so the write is skipped and nothing is created. Described here anyway, because it is the shape a future release would use and you should be able to check it against the code before it arrives: a handful of counts — pearls due, your weekly rhythm, which checklist step you are on and how many there are — plus the date you last wrote. No entry, no pearl, no rotation name, no title. Nothing about your purchase, and nothing that decides what you may see.
- The optional nudges, if you turn them on, are the same local notifications described above: fixed wording chosen when the app was built, never assembled from anything you wrote, and scheduled on your device with no server and no push service. They are the one part of this that is off until you enable it; everything else here draws inside the app’s own window.
Network use
None by default. Out of the box, Meddendum makes zero network requests — enforced structurally by a
Content Security Policy (connect-src 'none') and a navigation guard in the app shell. The HTML file
that is the app contains no fetch, no XHR, no WebSocket and no beacon — you can search it yourself.
You can also just turn on Airplane Mode; the app works fully. The one feature of Meddendum that sends or
fetches anything you wrote is the optional iCloud sync below. You can verify the app’s build checksum
and its live no-network policy at any time in Settings → Privacy you can verify.
Feedback you choose to send. The bug icon opens one feedback form — Problem, Idea, or Something else. Nothing about it is automatic: you type it, you press Submit, and what leaves is exactly what the form shows you — your own words, the app version, the device description and a short tail of code-level error messages. It never contains a journal entry, an entry title, or anything derived from one, and the same de-identification check that guards every export runs over the assembled report before it can go anywhere. If a build has no relay configured, Submit copies the report to your clipboard instead and says so; the app never claims to have sent something it did not send. Where a build does have one, the report goes to the developer through a small relay that keeps no copy — no database, no log line carrying your words — and forwards it to one inbox. Settings → Privacy you can verify lists every network exception the copy in your hands actually has, computed from that build rather than from this sentence; that list is the authority, not this paragraph.
Two smaller points, so a careful reader who goes looking is not caught out.
Meddendum can hand you to the App Store. If your journal was last written by a newer version of the app — on another of your devices, or in a backup you restored — Meddendum notices from a version stamp inside the vault, not from any lookup, and can offer to open its App Store page. That happens only on your tap, and it opens the App Store app rather than fetching anything itself. Nothing about you or your journal goes with it.
Meddendum’s application code is one HTML file, and that is the file the published checksum covers.
Two small same-origin scripts ship alongside it, published with their own checksums so you can check
the whole thing rather than most of it: a service worker that lets the app keep working offline in a
browser, and a helper for the optional stronger key derivation you can turn on in Settings. If you grep
the release for fetch, the service worker is where you will find a real call — that is what a service
worker does. It re-fetches its own file, from the same origin that served it, and answers any
cross-origin request with an error instead of fetching it. The App Store app never registers it.
Neither script can read your vault, and neither sends anything anywhere.
Buying the Apply tab
Meddendum is free to download, and everything you do with your own record — write, read, search, review, print, export, back up — is free forever, with no tier, no subscription, no licence key and no metering. One thing is a purchase: the Apply tab (the ERAS experience composer, Letters, Interview, Application Season and the cycle guidance), sold through the App Store as a one-time non-consumable in-app purchase. It never expires, it restores on your other devices, and it is not required to keep, read, print or leave with your journal. Gap Check is free, including its procedure summary and procedure-log exports, and so are Knowledge Pearls, rotation close-out and the weekly school log. Students who were already using those tools before 3.2.0 — the version at which the Apply tab was first gated in code — keep them free, permanently, on that device. 3.2.0 was frozen but never released, and 3.6.6 is the first published version with the gate, so every version published before 3.6.6 falls on the free side of that line. That cutoff is fixed at 3.2.0 and does not move with later versions. Apple handles the payment: your payment method, billing address and Apple ID go to Apple, never to Backshear Studios LLC, and nothing about the transaction is stored in your journal.
- Apple handles the payment. Your payment method, billing address and Apple ID are given to Apple, never to us and never to the app. Backshear Studios LLC never sees, stores or transmits any payment detail. Apple’s handling of that data is governed by Apple’s privacy policy, not this one.
- The transaction happens in Apple’s flow, not ours. Meddendum contains StoreKit code for exactly two purposes: to ask Apple for the localized price to show you, and to ask Apple whether this Apple ID owns the unlock. It reads no receipt of its own, verifies no signature of its own, and contacts no server of ours — the only network use is StoreKit’s own conversation with the App Store, and nothing you wrote is in it.
- Nothing about the purchase is stored in your journal. The entitlement answer comes from Apple, fresh, each launch; it is never written down. The only access-related thing kept on the device is the answer to one question — was this device already using the application tools before they became a paid feature? — recorded as a plain yes or no in a small file beside the encrypted vault, never inside it. The question is asked once, the first time you unlock your own journal on this device under a paid build, and the answer is then final: a yes is never taken away, and a no is never re-opened. That is what makes access a property of the device rather than of whichever file you happened to open — importing someone else’s backup cannot transfer access, and restoring your own cannot change it. Because it lives outside the vault it never rides an export, a backup or iCloud sync, and there is no receipt, no licence key, no expiry and no payment state anywhere in your journal.
- Nothing you have written is ever behind the purchase. Writing, reading, searching, printing, exporting and backing up your own record are free forever. Locking the Apply tab hides screens; it never deletes, edits or withholds a word you wrote, and everything those tools hold — your drafts, programs, letter writers and interviews — still leaves in the free encrypted backup and export.
- Refunds are handled by Apple.
- Where it comes from. The App Store is the only place Meddendum is distributed today. Because the application code is one HTML file, it can also run as a plain web page; if you are running it that way, the paragraphs above that mention a browser are the ones that apply to you. Nothing about the purchase changes either way.
iCloud sync (optional, off by default)
Meddendum offers an optional iCloud sync you can turn on in Settings → iCloud sync. When it’s on: – Your journal is synced across your own Apple devices through your iCloud account (Apple’s CloudKit private database). We do not operate any server and never receive your data. – Only the already-encrypted vault is synced, plus the same small readable parts an exported backup carries — your passphrase hint, the schema version, the key-derivation salts — and, unlike a backup, the device-bound biometric wraps, which the sync does not strip. Your entries are encrypted on your device with a key derived from your passphrase. Meddendum never transmits or stores that passphrase, so Apple (and Backshear) only ever hold opaque ciphertext and cannot read your journal. – Use the same passphrase on each device. Your entries merge across devices: an entry written on one device is not lost because another device also wrote. If you edit the same entry on two devices while both are offline, the later edit of that entry replaces the earlier one. – Turning sync off stops Meddendum sending or fetching anything, and returns it to making no network requests at all. It does not remove the encrypted copy already in your iCloud — the switch only stops future ones. To remove that copy, use Erase all data while sync is still on, or delete it yourself from your iCloud storage settings.
Protected Health Information (PHI)
Meddendum is designed to hold no patient identifiers. The entry model never asks for a patient’s name, date of birth, record number, address, phone number or email; ages are recorded only as broad bands, and encounters carry no calendar dates. There is no way to attach a photo or any other file to an entry in this build. The names Meddendum does hold are the professionals you choose to record — see People and programs you record above.
A built-in check assists you in catching identifiers — it runs as you type, and again before every export that can carry something you wrote — but it is an assist, not a guarantee. You are responsible for keeping your entries de-identified and for following your school’s and hospital’s policies, which may be stricter than the law. Meddendum is not a covered entity’s system and is not, by itself, “HIPAA compliant”; HIPAA compliance is a property of an organization’s program, not of an app.
Children
Meddendum is intended for adult medical students and is not directed to children.
Data deletion
You can erase all data at any time from Settings → Erase all data on this device. It requires your passphrase, deletes the encrypted vault from every store the app uses, clears the icon badge, cancels every reminder and encouragement nudge it had scheduled, and removes the small counts file a home-screen widget would read — which in this release is never created in the first place, so that step has nothing to delete and is there for the version that does. If iCloud sync is on and the app has confirmed this session that the copy in iCloud is yours, that copy is deleted too.
One thing it deliberately leaves alone, and it is named here rather than buried: the one-word grandfathering answer described under Buying the Apply tab. It holds nothing you wrote, and “erase my journal” must never quietly also mean “and now pay again.”
If it has not confirmed that, the erase still finishes on this device but the encrypted copy stays in iCloud, and this device cannot go back for it — its vault is gone. There are two ways that happens, and they have different remedies:
- You were offline. Run Erase all data from another of your devices that still holds this journal, online and with sync on. That erase deletes the iCloud copy.
- A different Meddendum journal is in that iCloud slot. Meddendum will not delete a record it cannot open, on any device — that record is another journal’s only cloud backup, and deleting it would destroy someone’s data. Remove it from your iCloud storage settings yourself.
Three things are outside the app’s reach in every case, and you have to deal with them yourself: the backups and exports you saved, wherever you saved them; a browser passkey, in your passkey settings; and a passphrase you gave to a password manager. Once those are dealt with, and the iCloud copy if you ever turned sync on, deleting the app removes the rest — nothing else is stored off your device.
Your responsibility & disclaimer
Meddendum is a personal reflective journal — not an electronic health record, not clinical decision support, and not a substitute for any patient-encounter log your institution requires. It is provided “as is,” without warranty. To the fullest extent permitted by law, Backshear Studios LLC is not liable for any loss or disclosure of information you choose to enter or export.
Changes
We may update this policy as the app evolves. Material changes will be reflected by an updated effective date.
What changed for 3.3.0. No new features, and nothing about the model changed: the Apply tab is still the only purchase, the cutoff for keeping it free is still 3.2.0, and no data moved. This release exists because the app was audited end to end before it was submitted, and 68 findings were fixed (one more was declined, with its reasoning recorded). Several of them are the reason parts of this policy now read differently. The de-identification checks got stricter: a patient name could previously ride out of a letter packet addressed to a writer whose stored name shared a word with it; an ALL-CAPS chart header pasted from a records system scanned clean when it should not have; and one invisible character pasted into an identifier could defeat the numeric checks entirely. Two paths that move text off the app now run the same identifier check as everything else — the bug-report email and its Copy button. The hint shown on the lock screen, before any passphrase, is now length-capped and scanned for identifiers before it is drawn, because a hint can arrive from an imported backup. And Erase all data now also cancels the optional encouragement nudges and removes the widget’s counts file: before this release a nudge computed from an erased journal could still arrive days later, and the widget’s file would have survived the erase as well.
What changed for 3.2.0. The residency-application toolkit — the Apply tab — became a one-time in-app purchase on iOS. Gap Check did not: it stays free, with its procedure summary and procedure-log exports. The optional “coffee” tip that 3.1.0 added is removed entirely. Students who were already using the paid tools in a build older than 3.2.0 keep them free, permanently, on that device — that cutoff is pinned to 3.2.0, the version at which the gate was added in code, and later versions do not move it. 3.2.0 was frozen but never released; 3.6.6 is the first published version in which anyone meets the paywall, so every build the public has ever run falls on the free side of the cutoff. (3.6.6 is a historical fact like the 3.2.0 cutoff itself — later releases of this document must not sweep it forward with the version they apply to.) Nothing that was already written became inaccessible: every entry, draft, program, letter writer and interview is still readable in the app and still leaves in the app’s own backup and export paths, which remain free. Apple handles the payment; it never reaches Backshear Studios LLC and nothing about it is stored in the journal. This release also added the optional encouragement features described in their own section above — all of them local, all of them individually switchable, and none of them adding anything the app transmits.
What changed for 3.1.0. The app was described as free, and added one optional “buy a fellow med student a coffee” tip, sold as a consumable in-app purchase, which unlocked nothing. That tip was removed in 3.2.0 and is described here only as history. A public build-verification page was also published so anyone can confirm a release matches the source.
What changed for 3.0.0. An earlier draft of this policy described an optional “Season Pass” — a non-renewing subscription bought inside the app, and a licence key for use outside the App Store. That described a build that was never released. That build’s purchase layer, licence verifier and paywall were removed before shipping. The 3.2.0 model is different and much narrower: no licence verifier at all (Apple is asked directly), no tiers, no subscription, and the only gated surface is the Apply tab. Those passages are deleted rather than softened, because they described mechanisms the app does not have. Sections on the people and programs the application-season tools store, on calendar-file import, on the activity log, and on dates were added at the same time, because those are things the app does that the policy had not said.
Corrections in this revision. Earlier drafts said more than the app had earned, and the fix in each case was to finish the sentence rather than soften it. They said Meddendum “sends nothing” and “stores everything encrypted,” when optional iCloud sync exists and a few small items are readable without a passphrase. They described biometric unlock as a Secure Enclave key without saying that in a browser the same switch creates a passkey the app cannot delete. They said “every export path” is scanned for identifiers, and re-asks for your passphrase, without naming the files that are not. They did not mention the recovery key’s Copy and Download buttons, what stays readable inside an exported backup and the synced copy, the private well-being space, or that keeping the vault out of device backups means a restored phone arrives without your journal. All of that is stated above now.
A second read of that corrected draft found the same fault repeated in new places, and those are fixed too. The opening said the encrypted vault was the only thing that could leave your device, which the rest of the policy then contradicted four times; the well-being section said those reflections never leave the app, when they ride the vault into a backup or a sync; two sections said Settings lets you review or delete records that Settings only shows the most recent of; the deletion section offered a remedy — re-running the erase on the same device — that a just-erased device cannot perform; and turning sync off was described as returning the app to fully offline without saying that the copy already in iCloud stays there. The policy also now names what it had left out: the drafts and study material the vault holds alongside your entries, the biometric wrap inside the vault file, the passkey label, the App Store hand-off, the two helper scripts that ship beside the HTML file, and the fact that the Reminders setting exists only in the iOS and Mac app.
Contact
Questions about this policy: email support@backshear.com. Please don’t paste anything from your journal into an email; describe the problem instead. Meddendum itself still has no accounts, and receives nothing from your email · Backshear Studios LLC.