Your data stays on the device

CHA1K is designed so your records do not live on our servers. There is no cloud account to create, and no remote backup of session data.

On-device by default

Session counts, people records, notes, templates, and presets are stored on your iPhone. CHA1K does not require a CHA1K account and does not sync session data to a CHA1K cloud service.

Encryption at rest

Data is encrypted on the device using AES-GCM with a device-only Keychain key. App data is excluded from device backups. You can optionally wrap that key with a passphrase, and lock the app with Face ID, Touch ID, or device passcode.

Keeping identity off the screen

CHA1K includes tools meant for shared spaces: one-tap name codes (so a full name never reaches disk), discreet mode for display-time masking, colour labels, identifier warnings in free-text fields, and a privacy check across people, counters, notes, templates, and presets.

What leaves the device

Nothing leaves the app’s protection unless you choose to export. Exports can include session CSV, current-totals CSV, a full JSON backup, and an activity-log CSV. Each export is behind an explicit notice that the file is leaving the app’s protection.

Apple Watch collection uses an encrypted link between phone and watch. Payloads are sealed with a shared key; offline actions queue as ciphertext and sync when the phone is reachable again.

Subscriptions and Apple

CHA1K Plus is billed through Apple via StoreKit. Purchase and subscription management follow Apple’s processes. CHA1K does not receive a separate payment account from you for the subscription.

What CHA1K is not

CHA1K is a measurement and data-collection utility. It is not an electronic health record, not a diagnostic tool, and not a HIPAA-compliant product. It does not ship with a Business Associate Agreement.

Contact

Questions about this page or the CHA1K app can be sent to dev@cha1k.com.

Publisher: Kinecio LLC