Home/Cackl for iOS/Privacy Policy
Cackl — Privacy Policy (iOS)
What Cackl collects, why, and what happens to it.
Effective date: August 7, 2026
Cackl ("the app") is a group voice-messaging (push-to-talk) app published by The Incline Institute, Ltd. ("we", "us"), a Nevada limited liability company. This policy explains what the iOS app handles and why. Questions: contact@inclineinstitute.com.
Summary
Cackl lets you send short voice messages to a small, closed group. It sends audio only while you hold the talk button and relays it to the other members of your group. Messages you receive are kept on your device so you can replay them. There is no advertising, no analytics, and no third-party tracking of any kind, and the iOS app embeds no third-party code. Our relay does sit behind Cloudflare's network, which is described below.
What the app handles
- Voice recordings. While you hold the talk button, the app captures from the microphone, encodes it, and sends it through our relay to the other members of your group. Our relay passes messages through to deliver them and holds them only briefly so a member who was offline can catch up; it does not keep a durable archive.
- When the microphone is open. So that pressing the button doesn't clip the start of your first word, the app holds the microphone open the whole time you have a group screen showing — iOS displays its microphone indicator throughout, so you can always see this. Audio is only sent while you hold the button, together with roughly a tenth of a second captured immediately before you pressed. Nothing else is recorded, kept or transmitted.
- Because the app can keep running in the background for the talk button and for playback, this applies while the app is in the background too, not only on screen. Leaving the group screen closes the microphone.
- Message history, on your device. Messages you receive are stored on your iPhone so you can replay them. This is never uploaded to us. It is capped per group, and it is removed when you sign out or delete the app.
- Your sign-in credential. The access token for your account is stored in the iOS Keychain on your device, and the relay address in app settings. Most people never see a token: joining is normally done by entering a short invite code, which the app exchanges for a credential.
- Your name and account. When you accept an invitation, the relay creates an account for you consisting of a numeric user id, the display name chosen by whoever invited you, and a hashed copy of your access token. This is stored on our server and is how other members see who is speaking.
- Group membership and last-seen times. Our relay stores which groups you belong to, and the time you were last connected, so other members can see who is in the group and roughly when they were last online.
- Location — only while you are looking at a group. If you grant location permission, the app shares your position with the other members of that group while a group screen is open. It is foreground only: nothing is shared when the app is in the background or closed. Positions are live, not stored — our relay keeps only each member's most recent position while they are connected and discards it the moment they disconnect. This is optional; if you decline, you can still see other members on the map.
- Profile picture. You can choose a photo to display instead of your initials. If you do, the image is uploaded to our relay, stored there, and shown to the other members of your groups — that is the point of setting one. Nobody outside your groups is told it exists.
- The image is cropped and resized on your iPhone before it is sent, so what leaves your phone is a small square picture (256×256), not the original photo or anything attached to it. The original file, its location data and its timestamp never leave your device.
- Cackl is never given access to your photo library. iOS shows you its own picker and hands the app only the single image you chose, so there is no photo permission to grant and no way for us to see anything else.
- Setting a picture is entirely optional. Without one you appear as your initials, which is the default and works exactly as well.
- Bluetooth accessories. If you use a Bluetooth push-to-talk button, the app connects to it to learn when you press and release. It reads nothing else from the device, and Bluetooth is not used to determine your location.
- Invitations. An invite code is stored on our server only as a hash, and is deleted once redeemed or revoked.
- Connection metadata, and your IP address. While connected, the relay processes what it needs to route messages — your member id, message ordering, connection status. Your IP address is visible to our service as it is to any internet service, but what is recorded differs by activity:
- Talking and listening. Our relay's logs record the address of the network edge in front of it rather than yours, so your IP address does not appear in them.
- Redeeming an invite code. Here the relay deliberately records your real IP address, on both acceptance and refusal, to rate-limit guessing attacks against invite codes — the one place an attacker can try codes at speed. Where a code is accepted, that entry also records the account it created, so it links an address to an account.
- Cloudflare sees your IP address for all traffic, as any network provider must.
These logs live on our own server in a file that rotates as it fills, so entries are overwritten in the ordinary course rather than kept for a fixed period. They are not used for analytics, advertising or profiling.
What the app does NOT do
- It contains no third-party code. No analytics, no crash reporting, no advertising network, no attribution SDK. Its only external dependency is an audio codec compiled into the app, which has no network access. (That is about the app; our relay sits behind Cloudflare — see "Who receives what".)
- It does not track you, and never accesses the advertising identifier.
- It does not receive messages while it is closed. iOS wake notifications are not implemented yet, so Cackl for iPhone only receives messages while it is open. When that changes, this policy will be updated first.
- We do not sell your data, and we do not use it for advertising.
Who receives what
- The other members of your group receive the voice messages you send, your display name, your profile picture if you have set one, and — if you enable it — your live location. That is the purpose of the app.
- Our relay server routes messages and stores the account information described above.
- Cloudflare, Inc. operates the network our relay is served through, and TLS is terminated at its edge, so Cloudflare handles traffic between your device and our server — including voice — and necessarily sees your IP address. Cloudflare acts as a data processor on our behalf. We have not enabled request logging, and because voice traffic uses a persistent WebSocket connection, Cloudflare's connection records identify the connection rather than its contents. Any data Cloudflare retains at its edge is governed by Cloudflare's own privacy policy.
- Nobody else.
Storage and retention
- On your device: message history (capped per group), your access token in the Keychain, and app settings. Removed when you sign out or delete the app.
- On our server: your user id, display name, hashed access token, group membership, the time you were last connected, and your profile picture if you set one — kept until your account is removed. Messages are held only transiently to deliver them. Locations are not stored.
- Profile pictures stay on the relay until you change or remove them. Removing yours deletes it from the relay and other members' devices stop showing it. A copy already downloaded onto someone else's phone is outside our control — we cannot reach into their device to erase it.
Security
- All communication with the relay is encrypted in transit (TLS,
wss://). That encryption terminates at Cloudflare's edge, which is where our relay is reached from, and is re-encrypted from there to our server — so Cloudflare handles the traffic in the clear at that point, as is the case for any service behind a network provider. - Access tokens are stored on our server only as a hash and cannot be read back out.
- On your device the token is held in the iOS Keychain.
Permissions and why
- Microphone — to capture your voice for push-to-talk. See "When the microphone is open" above for exactly when it is active.
- Location (While Using the App) — to show your position on the group map and share it with your group, only while a group screen is open. Optional.
- Bluetooth — only to connect to a Bluetooth push-to-talk button, if you use one. Optional.
The iOS app requests no other permissions. In particular it never asks for photo-library access, because the system picker hands it only the one image you choose.
Children
Cackl is not directed to children under 13.
Deleting your data
- On your device: sign out, or delete the app. This also clears your cached copies of other members' profile pictures.
- Your profile picture: remove it in the app. It is deleted from our relay and other members' devices stop showing it. A copy already downloaded onto someone else's phone is outside our control.
- On our server: because you now have an account, contact us at contact@inclineinstitute.com and we will delete your identity, its group membership, and your last-seen record.
Changes to this policy
We may update this policy. The effective date above reflects the current version.
Contact
The Incline Institute, Ltd. contact@inclineinstitute.com