Privacy Architecture
How Your Privacy is Protected
A detailed look at how Remain Faithful processes content without compromising your privacy — from device to partner notification.
What Always Runs — and What You Opt Into
The credible core is always-on. Deep Scan is optional. Screenshots, OCR text, and raw screen content never leave the device. Partners may receive a short system-generated summary string in addition to category, severity, and timestamp.
Always-on
Family Controls filtering
Selected apps and categories stay blocked through lock screen, reboot, and app restarts. Partners are notified when a blocked category is attempted.
Always-on
Usage as category events
DeviceActivity monitors usage as category-level events — not screen content, not which specific app, and not page content.
Always-on
Time-window shielding
You can restrict chosen apps to hours you set — evenings, travel, or a season of struggle. Shielding uses the same Family Controls stack. It does not see screen content.
Opt-in
Deep Scan cannot see DRM
If you start Deep Scan, on-device AI classifies non-DRM frames only. Netflix, Disney+, Hulu, Prime Video, Apple TV, HBO, and banking apps render as black frames. That is Apple FairPlay / platform DRM — unbypassable, not a bug.
Deep Scan Classification (Opt-In Only)
When you start a Deep Scan session, frames from non-DRM apps are classified entirely on your device. This is not always-on, and it cannot see DRM-protected video or banking apps.
Deep Scan Captures a Screen Frame (Opt-In)
If you start a Deep Scan session, Apple's ReplayKit creates a sandboxed broadcast extension process. All classification happens on-device. When a frame is flagged, alert metadata is uploaded: category, severity, timestamp, and a short system-generated summary string. Screenshots, OCR text, and raw screen content are never transmitted. DRM apps render as black frames.
Rules: URL Blocklist + Keyword Matching
Known adult domains are checked against a local blocklist. Visible text is pattern-matched against regex rules. Fast, deterministic, 100% on-device. No AI required.
On-Device AI: Apple SensitiveContentAnalysis + Vision OCR + Text Classifier
Apple Vision OCR extracts text; SensitiveContentAnalysis detects explicit imagery; a local keyword classifier scores the result. All three run on the device's Neural Engine — the dedicated AI chip in modern iPhones. No server involved at any stage.
Discreet Alert Delivered to Partners
Partners may receive a short system-generated summary string in addition to category, severity, and timestamp. Never which app. Never a screenshot. Never your browsing history. Never raw OCR text or screen content. The open-source code lets anyone verify exactly what is uploaded.
What We Can See vs. What We Cannot See
The architecture enforces these limits, not just our policies.
| Data type | Remain Faithful server | Your partners |
|---|---|---|
| Screenshots / screen frames | ✗ Never | ✗ Never |
| Raw screen content or text | ✗ Never | ✗ Never |
| Browsing history or URLs | ✗ Never | ✗ Never |
| Usage category events | ✓ Encrypted metadata | ✓ Category + timestamp + severity + short summary |
| Which specific app (bundle ID) | ✗ Never | ✗ Never |
| Passwords or financial data | ✗ Never | ✗ Never |
| Message content | ✗ Never | ✗ Never |
| Photos and videos | ✗ Never | ✗ Never |
| Alert category (e.g. "Adult Content") | ✓ Encrypted metadata | ✓ Yes |
| Severity level (Low / Medium / High) | ✓ Encrypted metadata | ✓ Yes |
| Timestamp | ✓ Encrypted metadata | ✓ Yes |
| Short system-generated summary | ✓ Encrypted metadata | ✓ Yes |
| Your name and email (account info) | ✓ Encrypted at rest | ✗ No |
Data Flow Diagram
How a flagged event travels from your device to your partner's notification — with encryption at every step.
Your Device
On-device classification; no screen content uploaded
Alert Metadata
Category, severity, timestamp, short summary
RF Server
Encrypted at rest (AES-256)
APNs
Apple Push (TLS 1.3)
Partner's Device
Notification received
All communication between the app and server uses TLS 1.3. Data at rest is AES-256 encrypted. Always-on layers and optional Deep Scan upload alert metadata — category, severity, timestamp, and a short system-generated summary — never screenshots, OCR text, or raw screen content.
Threat Model
What happens in the worst-case scenarios? We've thought through them.
What if your servers are hacked?
We do not store screenshots or browsing content. The database contains encrypted alert metadata (category, severity, timestamp, and a short system-generated summary) and account information (name, email, bcrypt-hashed password). A breach would expose that metadata, not your screen content.
What if data is intercepted in transit?
All communication between the app, server, and Apple Push Notification Service uses TLS 1.3. Interception would yield only encrypted ciphertext. All data in transit is encrypted end-to-end.
What if a partner is malicious?
Partners may see category, severity, timestamp, and a short system-generated summary — never raw content, screenshots, OCR text, or browsing history. A malicious partner cannot share your screen. You can remove a partner instantly at any time.
What if the app itself is compromised?
The entire codebase is open source and auditable by anyone. We run pre-commit secret scanning on every contribution. Anyone can read the source and confirm that classification is fully on-device and that what is transmitted is alert metadata (category, severity, timestamp, and a short system-generated summary) — never screenshots, OCR text, or raw screen content.
Open Source Commitment
The entire Remain Faithful codebase — iOS app, Go backend, and this website — is publicly available on GitHub. This is not optional for an app that handles sensitive behavioral data.
Our privacy architecture is not a policy claim. It is verifiable in the code. Anyone can confirm that classification happens entirely on-device and that what is transmitted is alert metadata (including a short system-generated summary) — never screenshots, OCR text, or raw screen content.
Security researchers and privacy advocates are invited to review, test, and report findings. We take responsible disclosure seriously.
View Source on GitHubWhy open source matters for trust
- Anyone can verify our privacy claims by reading the code
- Security researchers can find and report vulnerabilities
- The community can audit every update before it ships
- No "trust us" black boxes when handling intimate behavioral data
- Pre-commit secret scanning prevents credential leaks
How We Compare to Other Tools
Privacy dimensions compared across the most common accountability apps.
| Privacy Dimension | Remain Faithful | Provider A | Provider B |
|---|---|---|---|
| On-device AI processing | ✓ Yes | ✗ No (cloud) | ✗ No (cloud) |
| Open source codebase | ✓ Yes | ✗ No | ✗ No |
| Screenshots stored on server | ✗ Never | ✓ Yes | ✓ Yes |
| Partners see raw content | ✗ Never | ✓ Yes | ✓ Yes |
| Cloud dependency for classification | Zero — fully on-device | Always | Always |
| Cost | 100% Free | Paid subscription | Paid subscription |
| Auditable by security researchers | ✓ Yes | ✗ No | ✗ No |
Competitor information based on publicly available documentation. All claims are verifiable via our open-source codebase.
Questions About Our Privacy Model?
Read the source code, open a GitHub issue, or contact us directly. Transparency is not just a commitment — it is a practice.