Worldfork Privacy Policy
Effective date: September 15, 2026 Updated: September 15, 2026 Support: fork@worldfork.app Reviewed source: dce4cab1c856481b0d88f4d3a5cfb379b6ba823b
1. What Worldfork is on your phone
Worldfork is a local-first binary-fork tool on iPhone. You name two sides of a choice (or photograph a filled stay/leave list), talk through a short kitchen-table interview about what is stuck, hear a nested agent draft a pair of playable next-Tuesday mornings on the same Fork, Accept both, play them, and pick. Worldfork does not create a Worldfork account. Forks, side names, stuck points, accepted mornings, voice clips, generated stills, and picks stay on this phone unless you Allow the nested agent to leave for cloud help.
2. What you create
You may create or keep Fork records (stay/leave labels, weekday anchor, stuck points from the living interview), MorningScene drafts, Accept / Edit / Reject outcomes, optional filled-list stills, spoken or typed labels and answers, accepted Utterance audio, generated morning stills, Pick choices, and local learning summaries (Observation / Decision / Outcome / Correction / Preference). An App Intent may replay a Tuesday on device. Worldfork does not require a Worldfork account and does not run an account-backed cloud backup of your forks.
3. Permissions and media
When you choose the related feature, Worldfork may use:
- Camera to photograph your filled stay/leave list so this fork can hear both sides
- Photos so you can pick a list photo already on this phone, and optionally save an accepted morning still back to Photos
- Microphone so you can talk the two side names or your own-words interview answers
- Speech recognition to turn talk into words on this phone (Apple Speech may process the audio briefly)
- Local notifications for optional unplayed-Tuesday nudges and Tuesday-morning replay reminders (no remote push account)
You can deny a permission and keep using features that do not need it — for example, typing instead of talking or snapping.
4. No In-App Purchases in this build
The reviewed build does not include StoreKit purchases, subscriptions, consumable credits, or Restore. There is no Worldfork paywall in the inspected source.
5. Tracking, ads, and optional cloud AI
Worldfork’s PrivacyInfo declares tracking off (NSPrivacyTracking false) with no tracking domains listed. Collected types PhotosorVideos and AudioData are declared for App Functionality only, not linked for tracking. Worldfork does not display third-party ads. The reviewed sources do not wire App Tracking Transparency, Adjust, or similar advertising attribution SDKs.
Optional cloud inference runs only after you tap Allow on the first-use kitchen-table consent card (or later re-enable Settings → AI data sharing). A per-fork Allow this fork to leave card can also appear as a safety net before a morning-pair send. Decline / Skip keeps the fork local — no outbound nested-agent HTTP. Turning AI data sharing off stops every outbound AI path immediately; local tiles, names, stuck points, accepted mornings, and picks still work on device.
Before Allow, the first scripted interview question can speak on this phone with Apple’s on-device voice (no DeepSeek or MiniMax request). After Allow, live interview turns, morning-pair drafting, synthetic speech, and morning stills may leave the phone.
When allowed, Worldfork may send what the feature needs:
- Stuck points and interview answers you give at the kitchen table
- Stay/leave labels, spoken or typed labels, and related fork context the nested agent packs
- Optional filled-list photo pixels when a still is attached (list page style reference — not a face profile)
- Live interview question text generated for the nested agent’s next ask
- Accepted morning text for speech synthesis
- Prompts needed to draw an accepted morning still
Those requests go to DeepSeek (api.deepseek.com) for chat/vision and interview turns and to MiniMax (api.minimax.cn) for speech synthesis and morning still generation. Worldfork does not collect face data for a face profile. Raw microphone buffers are not uploaded as memory; on-device speech becomes text first. Worldfork does not pack contacts, precise location, HealthKit data, or undeclined consent state into those requests.
DeepSeek’s policy is linked in-app as Provider policy: https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
6. Network and third parties
Network access may be used for consent-gated DeepSeek and MiniMax calls and for loading the provider policy page and these legal pages. There is no Worldfork account backend. Apple may process Speech, Photos, Camera, Microphone, on-device AVSpeech, local notification delivery, and App Intents under Apple’s terms.
7. Retention and deletion
Forks, mornings, stills, Utterance files, picks, stuck points, consent choice, and related local records remain on your device until you delete them in-app or remove the App. Removing the App removes on-device App data. Data already sent to DeepSeek or MiniMax after you Allowed sharing is handled under those providers’ retention practices.
8. Advice boundary
Worldfork is a Lifestyle / Utilities tool for a felt rehearsal of two ordinary next-Tuesday mornings. It is not medical, legal, financial, or emergency advice and does not guarantee a life outcome.
9. Changes
We may update this policy; the effective and updated dates and reviewed source marker above will change when we do.
10. Contact
Email fork@worldfork.app.