App Security: Where Your Data Lives (It Doesn't) (2026)
Table of Contents
The shortest version of our security model: your data lives on your device, and nowhere else. This page explains what that means in practice, what the apps never do, and how you can verify it yourself in about five minutes.
The Security Model
Security is usually a list of defenses: encryption, firewalls, audits. Ours is simpler - there is nothing to protect on a server because there is no server. When an app processes a tarot spread, a sigil, or a dream log, the computation happens on your phone and the result stays there. The absence of infrastructure is the security measure.
- No servers, no cloud sync, no accounts to hack
- All processing happens locally on your device
- Data is stored only in the app sandbox on your phone
- Backups are optional exports that you create and control
- No analytics SDKs, no ad SDKs, no third-party trackers
What Stays on Your Device
The intimate stuff - your readings, your sigils, your dream journal, your ESP scores - stays in the app sandbox. That is the same private storage area every Android app gets, readable only by the app itself. If you uninstall the app, the data goes with it unless you exported it first.
- Reading history and journals: app sandbox only
- Sigils and charged intentions: app sandbox only
- Dream logs and projection notes: app sandbox only
- ESP session scores and progress: app sandbox only
- Optional exports: files you create and store where you choose
What Never Happens
It helps to state the negatives explicitly, because most apps do these things. Ours do not - by design, not by policy. The architecture makes them impossible, which is stronger than a promise.
- Never uploaded to a company server
- Never synced to a cloud account you did not create
- Never sold, shared, or used for advertising profiles
- Never read by us - we have no way to reach your device data
- Never locked behind an account that can be shut down
How to Verify It Yourself
- Open the Play Store listing and read the Data Safety section
- Check the permission list - ours request nothing sensitive
- Install the app, enable airplane mode, and use every feature
- Watch for network activity during normal use (there will be none)
- Export and delete your data to confirm you control it
Arcana Goetia is a good example of the model in practice: an offline reference for the 72 spirits, their seals, and working notes. Everything you record stays on your phone. If your practice involves names, seals, and notes you would rather keep private, that is exactly the kind of data that belongs nowhere but your pocket.
FAQ
Ready for the full experience?
These guides work with pen and paper, but a digital tool makes them faster.
Frequently Asked Questions
Where exactly is my data stored?
In the app sandbox on your own device - the private storage area Android gives each app. There is no server copy anywhere.
What happens if I uninstall an app?
The local data is removed with the app, unless you exported it first. Exports are files you create and control, so your record survives if you want it to.
Can you see my data if I email support?
No. We have no access to your device or its sandbox. If you email us about a reading or a log, only what you choose to paste into the email reaches us.
Where App Security: Where Your Data Lives (It Doesn't) (2026) sits in the library
- Arcana Goetia App Review: Summon the 72 Spirits on...goetia demons
- Goetia Seals & Sigils: How to Use the 72...goetia demons
- The True Cost of a Tarot App: Subscription vs...secret knowledge
- Why I Stopped Paying for Subscription Occult Apps (2026)mind science
- Free Spell Builder vs. Occult Apps: When to Upgrade...astral parasites
- Best Tools for Natal Chart Analysisastral parasites
- Mercury Retrograde 2026: Complete Survival Guide (2026)astral parasites
- What Is a Spirit Box? How It Works +...astral parasites
- What Actually Happens in an EVP Session: No Jump...astral parasites
- Occult Apps and Privacy: What Your Data Says (Ours...philosophy
- How We Test Occult Apps: Our Methodology (2026)chaos basics
- Our Privacy Policy Explained in Plain English (2026)secret knowledge
- Best Lunar Calendar Apps (2026)lunar
- Best Offline Tarot App for Android (2026): No Subscription...tarot
- Why We Don't Do Subscriptions (And Never Will) (2026)mind science
- Dream Machine App Review: Dream Incubation Tool (2026)astral dreams
- How to Vet an Occult App Before Buying (2026)scams skepticism
- Astral Lab App Review 2026: The Best Natal Chart...astral dreams
- Christmas Gift Guide: Occult Apps for $10 or Less...secret knowledge
- Dream Machine vs Awoken (2026): Which Lucid Dreaming App...astral dreams
- Dream Machine vs Lucid Dream (2026): Which Cha0smagick App...astral dreams
- Psi Gym App Review: Digital Sigil & Psychic Tool...sigils
- Sigil Gym App Review: Digital Sigil Maker & Tracker...sigils
- Free Digital Pendulum vs. Tarot Apps: When to Upgrade...technomancy
- The Tech-Witch Starter Pack: 5 Tools + 3 Apps...chaos basics
- Free Astrology Sign Calculator vs. Astral Lab: When to...astral dreams
- My First Year with a Digital Tarot Practice (2026)technomancy
- Free Tools vs Premium Apps: What You Actually Gain...secret knowledge
- Refund Policy: What Happens If You Don't Like It...money
- Astral Larvae: Sleep Paralysis, and Why the Entity Frame...astral parasites: Sleep paralysis, hypnagogic hallucination and the astral parasite concept, separated into what is well understood neurologically and what is a...
Put this into practice
Nothing in this domain is verifiable from the inside, which is why a camera, a recorder and a timestamp are the honest instruments.
NOCTEM: Professional Paranormal Investigation Suite, $14.99. The SLS camera, the EVP recorder and the environmental sensors, all offline. Android app, one-time purchase, no subscription and no account.
Get it for $14.99 on Google Play Lucid Dream: Astral Projection, $3.99 What is inside
Related Resources
References
- OWASP Mobile Application Security Verification Standard (2024)
- Google Play Data Safety policy (2025)
- GDPR Article 5: Principles relating to processing of personal data (2016)
A practical app-security review for occult and astrology tools
An app can be useful for journaling, generating a reading, calculating a chart, or keeping a practice log while still collecting more information than the feature requires. “Where your data lives” has several answers: the device, the app’s local storage, a server, an analytics provider, a payment processor, an advertising partner, or a backup system. The privacy policy may name vendors, but the most useful review also checks the app’s permissions and the actual settings you control.
Start with a data inventory
List the information you enter: birth details, names, journal text, location, device identifiers, payment data, and support messages. For each item, ask whether the feature needs it, whether it is stored or only processed, whether it is sold or shared, and how long it is retained. Birth data and intimate journal entries can be identifying even when a service says it does not sell personal information.
Check the permissions separately. A calculator may not need contacts, microphone, camera, or precise location. Revoke permissions that are not necessary and use the operating system’s privacy controls when available. The site privacy draft is a useful vocabulary reference, but it does not replace the privacy terms of an independent app or store.
Review the provider chain
- Identify the app developer, website, store listing, and privacy contact.
- Look for a data deletion or export path that is usable without sending a support request.
- Check analytics and crash-reporting providers, including whether a free tier uses advertising identifiers.
- Read the permissions and data-safety labels again after major updates; a changed SDK can alter the answer.
- Export or delete old journal entries when they are no longer needed.
For a journal app, the safest default is local or encrypted storage. For an astrology chart, minimize identifying details and avoid sending a full birth chart to a service that only needs a calculation. For an AI feature, treat the prompt as potentially retained by the provider unless the terms clearly say otherwise. Do not paste passwords, health records, or private contact lists into an experimental tool.
Evidence and uncertainty
Security claims should be dated and scoped. A store badge, privacy policy, or encrypted connection is evidence about one feature or system, not proof that every page and vendor is safe. Keep a small review log with the date, version, permissions checked, and unresolved question. If an app’s behavior conflicts with its documentation, document the conflict and avoid sending more sensitive data until it is explained.
You can use an app without treating it as a trusted adviser. The PSI GYM app page, for example, is a product description, not a security certification. Verify the current store listing and terms yourself before entering sensitive information.
Frequently asked questions
Does a privacy policy prove that an app is safe?
No. It describes stated practices, but permissions, SDK behavior, retention, and future changes still need to be checked.
Should I enter my full birth details into every astrology app?
Only if the feature needs them. Use the minimum information required, avoid sharing a full birth chart when a calculation is all that is needed, and review retention.
What should I do if I find an unexpected permission?
Do not grant it by habit. Deny it, check whether a less sensitive alternative works, and contact the developer if the requirement is unclear.
How do I reduce risk without leaving an app?
Use a strong device lock, keep the app updated, remove unnecessary permissions, disable unneeded notifications, and delete local data when you stop using it.
Discussion & Comments
Tried this practice? Tell us what happened below. Reader results are the most useful feedback we get — they show other practitioners what to expect and tell us which guides to write next.