5D

Privacy policy

What is encrypted, what is not, what we can read, and what happens when you seal a pairing.

Last updated 7 September 2026

The short version

Your messages, photographs, video, voice notes, call transcripts, letters and the description the two of you write of yourselves are encrypted on your device before they reach us. We store the encrypted bytes.

Unless you have sealed your pairing, we also hold a wrapped copy of its key — which means we can open that content for the features that need it: describing a photograph, answering an /ai question, writing your weekly insights, transcribing a call. Nothing else opens it, and every opening is recorded.

That is encryption at rest with per-couple keys. It is not end-to-end encryption, and this policy will never call it that. Vault mode — where the two of you destroy our copy of the key — is the one configuration that is end-to-end, and it is free on every tier.

Some things are never encrypted, because the server has to act on them. They are listed below, in full, rather than summarised.

Who this is

5D is made and operated by SpringVibe. This policy covers the 5D iOS app, the 5D web sign-in, and the servers behind them at 5d.springvibe.cafe.

For anything in this policy, including a request to see or delete what we hold, write to springvibe77@gmail.com.

What is encrypted, and where the keys are

Each pairing has a key of its own, generated on a phone when the two of you pair. It never leaves a device in the clear. It is stored only as wrapped copies: one for each of you, sealed to a key held in your phone's Secure Enclave, and one sealed to a service key we hold in a managed key store.

Content is encrypted under per-object keys, wrapped by the pairing key, before it is uploaded. This covers:

Either of you can open your pairing's content alone. Decryption never requires both keys — if it did, a pairing that ended would lock out the partner who stayed.

A team works the same way, one level up. A team is one person and the people they invite, sharing one space — the chat, the album, the calendar and the rest — that everybody in it can open. There are no separate private channels inside a team: what is said there is said to the whole team. The team has a key of its own, generated on the phone of the person who runs it and stored only as wrapped copies — one for each member's phone, handed across by a phone that already holds it, and one sealed to our service key. What a team says and shares is encrypted on your device under that key before it reaches us. That is encryption at rest with a per-team key; it is not end-to-end encryption, and there is no sealed mode for a team. Leaving a team withdraws your phone's copy of the key; what already reached your phone stays there.

What we can read, and what we cannot

While our wrapped copy of your key exists, our servers can decrypt your content. We do so only to run a feature you asked for:

Every one of those openings writes a line into a record kept for your pairing — what was opened, why, which model, and when. Ask us and we will send you yours. A service key is only honest if you can audit what it was used for.

We do not read your content for advertising, for training a model, for product analytics, or out of curiosity, and we do not sell or rent it. The app contains no advertising and no third-party analytics or tracking SDK.

Vault mode changes the arithmetic rather than the promise. The two of you agree to seal the pairing; our copy of the key is destroyed; from that moment nothing of yours can be opened by us, ever again, on either side. Vault mode is the one configuration this policy calls end-to-end encrypted. It is free, and it is irreversible — sealed, a key lives only on your own devices, a new phone is given it by a phone that already has it, and if every one of those devices is lost the content stays encrypted for good.

What is not encrypted

A server that can read none of it cannot deliver a message in order, cannot tell you a call lasted nine minutes, and cannot referee a game. So some facts are held in the clear, and the honest thing is to list them:

This matters more than it first looks, so it is worth saying twice: from this metadata alone, without any key, we can see that the two of you talk, how often, when, for how long, and that you have a plan on Thursday. We cannot see a word of what you said, or what the plan is.

Photographs, and the AI that reads them

Every new photograph is analysed on your phone, by Apple's on-device Vision framework, for basic tags. Nothing leaves the phone for that.

Richer photo tags — which the two of you agree to, and which is on unless you turn it off — adds a second pass. Your phone sends a small copy of the picture to our server, which passes it to Anthropic's Claude for a description and fuller tags. The stored photograph is never opened for this; the copy your phone sends is what is looked at. The words that come back are encrypted before they are stored. Turn it off and no picture ever leaves your phone for tagging.

A sealed pairing keeps this. Its phone sends the picture, gets the words back, and seals them — we never hold the plaintext at all.

A story works differently, because it is written from weeks of your conversation rather than from one picture. Unsealed, it is written on our side: when either of you asks for one, our server uses its copy of your pairing's key to open that stretch of weeks — up to 150 of its most recent messages, its letters, your plans, your photographs' tags and the profile the two of you wrote — and sends them to Anthropic's Claude, which writes the story. The story is encrypted before it is stored. Asking for a story does not need the other's agreement.

A sealed pairing cannot be read that way, so it is asked separately: the two of you may turn on Write Storybook from the iPhone, which lets your own phone open a fortnight of your messages and send it up for the single request that writes the story. Nothing from that request is stored, and it applies to nothing else the two of you do. Leaving it off breaks nothing else in the app.

Anthropic processes what we send under its commercial terms, which do not permit training on it.

Nothing that widens your privacy changes on one person's word

Every setting below is agreed by both of you. One proposes; it does nothing at all until the other opens their own app and approves. Neither of you can quietly turn something on for the pairing, and neither can turn something off without the other seeing it happen.

What the two of you write about yourselves — your pair name, and the description that shapes anything written for you — is agreed the same way.

One setting is deliberately not on that list. Whether the app's features are gated behind what you have unlocked is a switch either of you may set alone: it governs what the app shows you, never what leaves it, and a way back out of gating that needed the other's agreement is a state one of you could be left in and could not leave.

Location

Location is used in four ways, and each is separate.

Live location is a personal setting, not the pairing's, and it is on by default for a new account. It is in My settings, and switching it off deletes the position we hold.

Your location is shared with your partner. It is never shared with anyone else, and never with us in a form we keep beyond the single current point — except that a place search you ask for sends where you chose to search from to us and to Anthropic for the length of that search.

Community features

5D has a design for a noticeboard other pairs can post to, and for an inner circle of pairs you link with by hand. Both would mean keeping an approximate area for your pairing — roughly five kilometres across — somewhere it can be read.

Both are switched off in this version of the app, and neither can be turned on. Nothing about where you live leaves your pairing today. If that changes, it will be by the same both-of-you agreement as everything else, and this policy will change first.

Where your data lives, and who else touches it

We use a small number of processors, and no more than the app needs:

Everything at rest with those providers is encrypted content or metadata as described above. Data may be processed in the United States and in the European Union; where personal data of people in the EEA or the UK is transferred, it is under the providers' standard contractual clauses.

How long we keep it

Your content stays while your pairing does. From inside the app, under your pairing's Data tab, you can pause a pairing, secure its vault, or delete everything the two of you share.

Pausing stops both of you reaching anything until you both agree to resume, and keeps your keys, so resuming brings all of it back. Whoever paused can undo it on their own, up until the other asks to come back.

Either of you can ask for a pairing's shared data to be deleted — it is called “Break up for good” in the app. Both of you lose access to it immediately, both of you are told, and the deletion itself happens 14 days later. Whoever asked can call it off at any point before then, and everything comes straight back for both of you if they do; the other one can ask them to call it off, and is told whether they have. It works that way round on purpose: if either of you could cancel it, the one who wanted the record kept could cancel every request for ever, and the one trying to end it would have no way to. On the day, it is removed from our live systems and its keys are destroyed, which makes any leftover ciphertext unopenable. One thing to know so it is not a surprise: we keep encrypted backups of the whole database so a failure cannot lose anybody's history. A nightly backup is kept for 30 days; one backup a month is kept for 2 years. A deleted pairing remains inside those backups until they age out — up to 2 years for the monthly one — and its keys are inside them too, so it is not unopenable there the way it is everywhere else. Those backups are encrypted to a key that exists only offline, on paper, away from our servers; nobody restores one except to recover from a failure, and if that ever happened after your deletion we would apply it again. We cannot reach into a backup to remove one pairing; what we can do, and do, is let it expire.

Separately from those backups, once a month — and whenever either of you asks, under the Data tab — we take a snapshot of your pairing on its own: your messages, pictures, plans, places, letters, notes and games exactly as they are stored, encrypted on your phones before they reached us and still encrypted inside the snapshot. A snapshot holds none of your keys. It exists so that the two of you can put your history back if it goes missing: either of you can ask, the other has to agree, and what has gone missing since that snapshot is put back without touching anything you have added or changed since. A snapshot is only ever restored into the pairing it was taken from — or, if that pairing itself has gone wrong, into a new pairing for the same two people that is built from it and uses the same key. It can never be opened by anyone else. We keep your newest 6 monthly snapshots, and the ones you take yourselves for 5 years or until either of you removes one. Deleting a pairing deletes all of its snapshots on the same day.

A photograph or video you delete is removed from our live storage and our own archive at that moment. Our cloud archive keeps a deleted file for up to 30 days before it ages out, so that a deletion made by mistake can still be undone in that time by writing to us; after that it is gone from everywhere. No snapshot and no database backup contains a photograph or video — they only name the file.

Deleting your account works the same way: you ask for it in the app, your pairings are paused straight away, and the account itself is removed 14 days later. Signing in again before then calls the whole thing off, pairings included. What goes is your login, your device tokens, your keys and your membership of any pairing. It also asks for the shared data of every pairing you are in to be deleted, on the same 14-day clock. Your partner is told and can ask you to keep it, but only you can answer that — so if you never do, which is what usually happens when somebody has left, the shared record goes with your account. There is one key per pairing rather than one per person, so there is no way to remove only your half of a conversation: the only thing that removes your side is removing the conversation, and that is their copy too.

Your rights

Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for the record of every time your content was decrypted, or object to a particular use. Most of it you can do yourself in the app; for the rest, write to us and we will answer within 30 days.

If you are in the EEA or the UK: we process your account data to provide the service you asked for (contract), the optional AI features on the agreement the two of you gave (consent, which either of you can withdraw at any time by turning the setting off), and a small amount of operational logging to keep the service running and secure (legitimate interests). You may complain to your local supervisory authority.

If you are in California: we do not sell or share personal information, and we do not use it for cross-context behavioural advertising. We have never done either.

To exercise any of this, write to springvibe77@gmail.com from the address on your account.

Children

5D is for adults. It is not directed at children, and we do not knowingly collect anything from anyone under 18. If you believe a child has an account, write to us and we will remove it.

Security

Everything in transit runs over TLS. Content is encrypted before it is uploaded, under keys as described above. Each pairing's data is isolated in the database at the row level, enforced by the database itself rather than by application code remembering to filter. Backups are encrypted before they leave the machine that makes them.

No system is perfect, and we would rather hear about a flaw than not. If you find one, write to springvibe77@gmail.com and we will work with you on it.

Changes to this policy

When this policy changes we update the date at the top of the page. If a change affects what we can read or what leaves your phone, we will say so in the app before it takes effect, not after.