Trueday
  • Pricing
Download app
HomeSecurity
Security

Security

How Trueday protects your data on the device, in transit, and in the database — and the things it deliberately does not contain.

Last updated: 24 August 2026
The short version

Your data lives in an encrypted store on your device. Sync is optional, encrypted in transit, and isolated per account in the database. The app ships no analytics or advertising SDKs, and personal content is kept out of logs.

01

On your device

Trueday stores your tasks, events, locations, goals and profile in a SwiftData database protected by iOS Data Protection, which ties decryption to your device passcode. Authentication tokens are held in the iOS Keychain with a protection class that keeps them on this device only and unavailable until after the first unlock following a restart.

  • Encrypted local database under iOS Data Protection.
  • Tokens in the Keychain, device-only, never in plain files.
  • App Lock optionally gates the whole app behind Face ID or your passcode.
  • Biometrics are evaluated by iOS. Trueday receives a yes or no, never biometric data.
02

In transit

All network traffic uses TLS. That covers sync, authentication, and every API this website talks to. There are no plaintext endpoints.

03

In the database

Optional cloud sync is backed by Postgres with row-level security enabled. Every row carries the identifier of the account that owns it, and the database itself refuses to return rows to any other account — the isolation is enforced by the database, not only by application code, so an application-layer bug cannot expose another user’s data.

04

What is deliberately absent

Some of the strongest security properties come from what is not there:

  • No third-party analytics SDK in the iOS app.
  • No advertising SDK, and no advertising identifier collection.
  • No session-replay or heat-mapping tooling.
  • No plaintext task content in logs — titles and personal fields are redacted.
  • No payment data — purchases are handled entirely by Apple’s StoreKit.
05

Accounts

Sign-in is available with Apple, with Google, or with an email address and password. Passwords have complexity requirements, support reset, and can be paired with one-time codes. Core planning requires no account at all, which remains the most private way to use Trueday.

06

The website is a separate system

This website uses Google Analytics and Intercom, loaded only after you consent to them. The iOS app does not, and the two are not connected. We keep this distinction explicit so that the app’s claim stays exactly as narrow as it should be.

07

Reporting a vulnerability

Email security@truedayapp.com with enough detail to reproduce the issue. We will acknowledge your report and keep you updated while we investigate. Please give us a reasonable window to ship a fix before disclosing publicly, and please do not access, modify, or retain any other user’s data while testing.

Security

Found something?

Report suspected vulnerabilities directly to the security address.

security@truedayapp.com
AI SCHEDULING✦ENERGY MATCHING●LOCATION AWARE✦PRAYER INTEGRATION●ABSOLUTE PRIVACY✦
AI SCHEDULING✦ENERGY MATCHING●LOCATION AWARE✦PRAYER INTEGRATION●ABSOLUTE PRIVACY✦

DESIGNED FOR LIFE

TruedayTrueday

OWN YOUR RHYTHM. PLAN YOUR LIFE WITH CLARITY.

Download appPricing

01Product

  • Features
  • Pricing
  • How it Works
  • Compare
  • Changelog

02Company

  • About
  • Success Stories
  • Press
  • Blog

03Help Center

  • Help Center
  • Sitemap
  • Contact

04Privacy

  • Privacy
  • Terms
  • Subscription
  • Refunds
  • Delete Account
  • Health Data
  • Voice & Microphone
  • Security
  • Cookies

© 2026 Trueday Inc.

XLinkedInInstagram

Apple, iPhone, iPad, Siri, Face ID, HealthKit and App Store are trademarks of Apple Inc., registered in the U.S. and other countries. Trueday is not affiliated with or endorsed by Apple Inc.

TRUEDAY