Last updated 19 August 2026
Matria is for people aged 16 and over. Reading and theme matching work locally without an account. Your journal, saves and follows are stored on your device. Optional AI finding sends a question only after a separate confirmation for that question. Letters, the optional correspondence between readers, uses an account and our servers. These are different sharing choices.
Your journal notes, saves, follows and private constellation are stored locally. They are not part of an AI finding request. Ask history may also be saved on this device. Asking and opening a result do not send the question to AI. Only a separate confirmation sends that question for optional finding. A confirmed request does not remove its local history entry.
In updated builds, optional AI exploration uses the whole eligible archive. Your confirmed question and public editorial records are processed by Anthropic to generate an explanation and run a second automated support check. Each explanatory paragraph points to exact archive text. This does not certify historical accuracy or mean the original books were retrieved. Unverified quotations and restricted records are excluded. When evidence is insufficient, Matria says so. It does not use historical biographies to give personal medical advice. No external search or private database is connected. Your journal, saved notes and Letters are not included. Older installed builds without purchase verification need an update to use AI.
AI finding requires an active paid Apple membership and sign-in through our existing Supabase account service. Signing in for finding does not create a Letters profile or publish anything. Matria's Cloudflare service verifies the account before contacting Anthropic. Your sign-in token and account ID are not sent to Anthropic. Your device supplies an Apple-signed purchase proof to Matria. Matria verifies it and checks the current subscription status with Apple. Purchase proofs and transaction identifiers are not sent to Anthropic or stored in the usage ledger. Coded account and membership identifiers, request identifiers, times and cost records enforce three attempts per rolling seven days and a shared service budget. Follow-ups and failed provider attempts count. These records contain no question text and are automatically cleaned up within 40 days during normal service operation. Clearing local data does not reset this allowance.
To limit abusive sign-in verification traffic, Cloudflare processes your network address. The finding service derives a coded, daily-changing rate-limit key from that address. It does not add the address to the usage ledger or send it to Anthropic. Shared networks may occasionally encounter a temporary limit. Verified accounts have a separate short-term request limit.
Matria does not use these requests for advertising or training its own models. Our finding code does not log questions, and Cloudflare invocation logging is disabled. Anthropic's standard commercial API policy normally deletes inputs and outputs within 30 days, with exceptions for safety enforcement, legal requirements or a different agreement. This is not zero retention. API content is not used for model training unless otherwise agreed. See its retention policy and API data policy. Do not include information you want to keep on this device.
The account-free writing practice, where available, keeps its draft and sealed letters only on this device. Naming an addressee does not contact that person. Its optional 90-day opening date sends neither a message nor a reminder. This local storage is not an encrypted vault against someone with access to your device.
Unsent correspondence drafts stay on this device, separated by signed-in account and audience. They are not uploaded automatically. A send attempt is recorded locally before transmission so an uncertain response cannot trigger an accidental resend. You can export a draft, delete an unsent or completed draft, or clear local data. Account separation is an app boundary, not encryption against someone with access to this device.
Letters lets you write pen-name correspondence to other readers. It uses a separate account and our servers. To use it you sign in with Apple, and you may use Apple's Hide My Email. We store what is needed to deliver your letters:
This data is held by our hosting and database provider, Supabase, on servers in the European Union, acting as our processor under our instructions, and is used only to provide Letters, never for advertising or tracking. Private Letters show a pen name and a country only when its owner enabled sharing. If Open Letters is available, a letter you explicitly publish is visible to signed-in members under your pen name until you close it, it is removed, or you delete your account. Replies to Open Letters are private requests. Every letter passes an automated safety filter. You can report a letter or block a reader, and we remove abusive content and readers. You can unsend a private letter before it is delivered, and you can delete your Letters account and stored letters from inside the app.
If you buy a premium membership, the purchase is handled entirely by Apple through your Apple Account. Apple tells the app whether your membership is active. We never see or store your card, your Apple ID password, or your billing address.
Matria can show places where women in the archive are remembered near you. This is optional. If you grant permission, your approximate location is used once, on your device, to choose a nearby city. The coordinate is not stored and is not sent to us or to any third party. You can decline, and Matria still works fully.
Speaking is optional. iOS or your browser's speech service converts speech to text and may process audio remotely. Matria's dictation code receives text, not an audio recording. Transcribed text follows the same sharing choices as typed text: a confirmed AI request or a letter you send can leave the device. Your journal is not included in AI finding.
We do not run advertising. We do not sell your personal data. We do not use third-party analytics or tracking SDKs. We do not build an advertising profile of you. Outside Letters and the limited AI-assisted finding request described above, we do not collect your reflections. Within Letters, we hold only what is needed to deliver your correspondence.
Choose Local-only under Archive finding in Settings to keep using local finding. Changing this preference does not withdraw a request already sent or delete provider records. Clear local data in Settings to remove archive activity from this device. For Letters, you can unsend undelivered letters, block readers, and delete your Letters account and stored letters from Settings. If that fails, contact feedback@matria.life.
If this policy changes, we will update this page and the date above.
Questions about privacy: feedback@matria.life.
Matria · made by luana.systems
This page describes Matria's privacy practices in plain language. It is provided for transparency and App Store review and should be confirmed by counsel before public release.