Skip to content
Privacy policy

What Pebbles knows about you

Last updated August 7, 2026

The short version: Pebbles has no account and no sign-up, collects no analytics, and runs no servers of its own. Your paths, pebbles, and photos live on your iPhone and in your own iCloud. The one thing that leaves that circle is an invite you choose to create, and it is described in full below.

Who this applies to

This policy covers the Pebbles iPhone app, its widgets, and this website. Pebbles is made by one independent developer, reachable ateesoymilk@gmail.com.

What is collected

Nothing. There is no account to create, no email address to hand over, and no profile. The app contains no analytics, no advertising, no tracking, no crash-reporting service, and no third-party SDKs of any kind. Nothing you write in Pebbles is sent to the developer.

The App Store privacy label for Pebbles is Data Not Collected. If you have chosen in iOS to share crash and usage data with app developers, Apple may provide the developer with its own aggregated, anonymous reports; that data comes from Apple, not from the app, and does not identify you.

Where your paths and pebbles live

Everything you create - path titles and dates, pebbles, photos, places, and words - is stored on your device and, if you are signed in to iCloud, synchronised through Apple's CloudKit into your own private iCloud database. That storage is your Apple Account's, governed by Apple's terms and encryption. The developer has no access to it and no way to read it.

Pebbles works without iCloud too. In that case everything stays on the one device, and sharing is unavailable.

Photos and places

Photos you attach are copied into Pebbles's own storage, downscaled, and kept with the pebble. The app uses the system photo picker, which hands over only the pictures you select and never gives the app your photo library.

Adding a place is optional. When you open the place picker, Pebblesasks iOS for your current location so that the map starts somewhere useful. The place name and coordinates you choose are saved with that pebble, in the same private iCloud storage as everything else. Your location is never sent to the developer or to any third party.

Sharing a path with one person

When you share a path, Apple's CloudKit sharing places that path in a shared area of iCloud that both people can reach. The person you invite can see that path's pebbles, photos, places, words, and the display name you picked for yourself on it. They cannot see any of your other paths. Stopping the share, or removing that person, ends their access.

Invite codes are published for 30 days

This is the one part of Pebbles that is not private, so it is spelled out plainly.

When you create an invite for a path, Pebbles writes one record to thepublic database of its iCloud container, keyed by the six-character code. That record contains the path's title, the display name you entered for yourself, the path's anchor date, a small thumbnail of the path's cover photo, and the iCloud link that lets someone join.

That database is Apple's infrastructure, not a server the developer runs, and the record is looked up by its code: someone would have to hold your six-character code to fetch it. It is not indexed or searchable, and no pebbles, photos beyond that one cover thumbnail, words, or places are in it. The record carries a 30-day expiry, after which it stops working, and creating a fresh code for the same path replaces the old record.

If a path's title or cover photo is something you would rather not publish even that briefly, change them before you create the invite, or do not create one - a path is never shared, and no record is ever written, unless you ask for an invite.

Notifications

Reminders for hollows are scheduled by iOS on your own device. On a shared path, notifications about your partner's activity are generated by Apple's CloudKit and delivered through Apple's push service; they carry the path title and the display name your partner chose. No push service belonging to the developer exists, and notification preferences are kept on your device rather than synchronised.

Purchases

Endless Paths is bought through Apple's in-app purchase system. Apple handles the payment; the developer never sees your payment details, your name, or your address. The app asks Apple only whether the purchase exists for your Apple Account.

This website

This site is static. It sets no cookies, includes no analytics, and loads no fonts, scripts, or images from third parties. The join page reads the invite code from the address in your own browser; the code is not sent anywhere by the page.

The site is hosted on Vercel, which - like any web host - processes standard request information such as your IP address and browser type to serve the page and keep the service running. The developer does not use that information to identify or profile anyone.

Children

Pebbles is not directed at children under 13 and collects no personal information from anyone, children included.

Deleting your data

Pebbles and paths can be deleted inside the app at any time. Deleting the app removes its data from that device. If iCloud sync was on, the iCloud copy remains and returns if you reinstall; to erase that copy as well, open the system Settings, tap your name, then iCloud, then Manage Account Storage, and delete Pebbles's data.

Invite records expire on their own after 30 days. To retire one sooner, create a new invite for that path, which replaces it.

Changes to this policy

If the app's behaviour changes in a way that affects this policy, this page is updated and the date at the top changes with it.

Contact

Questions about anything here go toeesoymilk@gmail.com.