Plural Star
Privacy Policy
Last updated: September 2026
Renamed from Plural Space. The app, repository, and subreddit were renamed to Plural Star for community clarity — another app was also using the Plural Space name. Your installation, data, backups, and any links continue to work; the app behavior and privacy practices described below have not changed as part of the rename.
Plural Star is a private front-tracking, journaling, and system-management application for plural systems. Your privacy is fundamental to how this app is built. This policy explains what data the app handles, how it is used, and how it is stored, including our optional decentralized networking features.
1. Data the App Handles
All content you enter in the app is stored exclusively on your device. Depending on the features you enable, this includes:
- System information — system name, description, system-level banner and avatar
- Member profiles — names, pronouns, roles, colors, markdown descriptions, profile pictures, 900×300 banners, tags, group assignments
- Front history — timestamped records of who fronted across Primary, Co-Front, and Co-Conscious tiers, with mood, location, energy level, and notes per tier
- Journal entries — text entries with optional authors, hashtags, and per-entry or whole-journal passwords
- Chat — local-only system chat with channels, text messages, images and file attachments (stored on your device), replies, and reactions
- Custom fields — user-defined per-member fields and values
- Noteboards — per-member note threads written by other headmates
- Polls — system polls with options, votes, and voter tracking
- Settings and preferences — theme, language, notification toggles, front-check interval, custom palettes, custom moods, saved locations
- Approximate location — only when GPS is explicitly enabled in Settings (off by default). Your device's coordinates are reverse-geocoded to a neighbourhood or city name via OpenStreetMap Nominatim. Raw GPS coordinates are never stored.
- Network and Sync Data (optional) — when using Friends & Syncing, the app handles cryptographic Peer IDs, friend lists, connection metadata, and encrypted sync payloads.
- Push delivery data (optional, iOS) — if you turn on friend notifications or the Dynamic Island front display, the app registers an Apple push token and the list of friend Peer IDs you have chosen to watch, and announces the names of who is currently fronting so those notifications have something to say.
- Cloud vault (optional, experimental) — if you turn on Cloud Services, an encrypted copy of everything the app stores (the same set of data as a full Export, plus your network identity and friend list, and optionally full-size images and chat attachments) is kept on the Plural Star node under a password only you know. See Section 3 for exactly what the node can and cannot see.
2. How Your Data Is Used
All data is used solely to provide app features — tracking fronting sessions, maintaining a system journal, managing custom fields and noteboards, running polls, generating history and insights, and facilitating secure peer-to-peer synchronization and friend interactions when explicitly enabled. Your data is never used for advertising, analytics, profiling, or any purpose beyond what you see in the app.
3. Data Storage and Transmission
All data is fundamentally stored locally on your device. Plural Star does not hold readable system data on any server, does not require an account, and does not transmit your data to any third party, with six narrow exceptions:
- Decentralized Sync & Friends (optional): If you enable online features, your device communicates through our Decentralized LibP2P Relay Node Network (Plural-Star-Node, now running as the Plural Star Cloud Node). Your data is transmitted using end-to-end encryption (E2EE) and is only accessible to the specific peers (your other devices or explicitly approved friends) you authorize. Relay nodes facilitate the connection and NAT traversal and cannot read or decrypt your system data. The one thing that is not end-to-end encrypted is your current front status (the fronter names you share, your system name, and which friends may read it): it is sent to the Plural Star gateway in the clear so your friends can see it. One thing changed in September 2026: when the peer you are sending to is offline, the node now keeps the encrypted packet in a store-and-forward inbox and delivers it the next time that peer connects, instead of dropping it. The inbox holds ciphertext only, at most 50 MB per recipient, for at most 30 days, and a packet is deleted once delivered. The node also keeps the last front record each system announces to its friends (the same short record the push gateway holds, described below) so friends who were offline still see it. The node runs on a rented server at a hosting provider; the provider has physical access to that server and therefore to the node's own keys, but not to your encryption keys, which never leave your devices.
- Push notifications for friends (optional, iOS): Apple does not allow an app to be woken by another phone, so iOS friend alerts and the Dynamic Island front display are delivered through a small push gateway operated by the developer, and then by Apple's push service (APNs). This lane is separate from your synced data and carries far less: the gateway holds your device's push token, the friend Peer IDs you chose to watch, and a short-lived cache of the fronter names, system name and front start time each system announces. It never receives your journal, chat, history, medical data or any other synced content, and it cannot read the encrypted traffic on the relay network. Names sent down this lane are visible to the gateway and to Apple in order to be displayed, so the app deliberately sends only what the notification needs, and only the names every friend you are sharing with is permitted to see. Turning off friend notifications stops the registration; removing a friend stops them being announced to that friend.
- GPS location (optional): If you enable the GPS feature, your device's coordinates are sent over HTTPS to Nominatim (OpenStreetMap) to resolve a neighbourhood or city name. Only coordinates are sent — no identifiers, no account information, no system data.
- Simply Plural / PluralKit token import (optional): If you use the import feature with a token, the token is used for one-time API requests to those services to fetch your data. The token is not stored by Plural Star after the import completes.
- Simply Plural file import (optional): If you import a Simply Plural JSON export file, the file is read from your device's local storage only. No network traffic occurs during file import.
- Cloud Services (optional, experimental): If you turn on Cloud Services in Network Settings and choose a vault password, your app data is encrypted on your device and the encrypted copy is stored in a vault on the Plural Star node, so your other devices can link to it with the same password and so your data survives a lost or reset device. The password never leaves your device; it is turned into a vault identifier, an access secret and an encryption key on the device itself, and the node receives only the first two. The node stores ciphertext and an encrypted index. What the node (and therefore the developer) can see is: that a vault exists, its identifier, the sizes and hashes of the encrypted objects in it, when they were uploaded and downloaded, and a label and short device identifier for each linked device. What it cannot see is any of the content: no member names, journal entries, history, chat, images, friend list or settings, because it does not hold the key. Nobody can recover a vault whose password is forgotten, including the developer; the app says so before you set one. Full-size images and chat attachments are only uploaded if you turn on "Include full-size images". Cloud Services and device-to-device syncing never run at the same time. Deletion rules are in Section 7.
4. Data Sharing
Plural Star does not sell, share, or transmit your personal data to any third parties for any purpose beyond what is described in Section 3. When utilizing the Friends & Syncing network, you retain absolute control over which cryptographic peers receive your encrypted data.
5. Notifications
Almost every notification Plural Star shows is generated entirely on your device and is not transmitted anywhere. The one exception is friend notifications on iOS, described at the end of this section and in Section 3.
- Front status notification: A persistent notification showing who is currently fronting across all three tiers. Displays when someone is fronting and updates when the front changes.
- Front-check reminders (optional): If you set a front-check interval in Settings (1, 2, 4, 8, 12, or 24 hours), the app schedules a recurring local reminder to prompt you to update the front. Notifications can be disabled at any time by clearing the interval or turning off notifications in Settings.
- Noteboard notifications (optional): When a new noteboard entry is created for a member, the app can surface a local notification. Disabled by turning off notifications in Settings.
- Friend front alerts and the Dynamic Island (optional, iOS): The only notifications that are not purely local. When a friend's front changes, their device announces the fronter names to the developer's push gateway, which asks Apple to deliver a notification to yours. Android friend notifications are built on your own device from data already received over the encrypted connection and use no push service. See Section 3 for exactly what the gateway holds.
6. Export & Backup
Plural Star includes optional export features you control entirely. JSON exports are reimportable; HTML exports are for offline viewing or upload to services like Google Drive; email exports open your device's native mail app with pre-filled content (the app does not send email directly). All exports offer per-category toggles so you choose exactly what leaves your device. Avatars and banners are encoded as base64 inside the payload so images travel with the backup.
7. Data Deletion
You can permanently erase all app data at any time using Share → Delete All Data. Uninstalling the app also removes all locally stored data from your device.
The push gateway's copy is cleared separately. Turning friend notifications off removes your registration, and uninstalling invalidates the push token at Apple, after which the gateway discards it. Each new front you announce replaces the previous cached one, and a cached front is dropped entirely after 30 days without a new announcement. That window exists so a friend who has not opened the app for a while still learns what they missed; nothing older than it is kept or served.
The node's store-and-forward inbox deletes each encrypted packet when it is delivered, and any packet that is not delivered within 30 days.
A cloud vault is deleted on its own schedule. Unlinking a device never deletes the vault and never touches the data on the device. Delete All Data on a linked device unlinks that device first and then erases the device; it does not empty the vault or affect your other devices. When no device is linked to a vault at all, a 30-day grace period starts; linking any device again cancels it, and only after the full 30 days is the vault and every object in it removed from the node. Encrypted objects that no version of the vault refers to any more are removed by a daily clean-up. There is no way to ask for a vault's content without its password, so there is nothing the developer could hand over or read in the meantime.
8. Children's Privacy
Plural Star is not directed at children under 13. We do not knowingly collect information from children under 13.
9. Changes to This Policy
If we make material changes to this policy, the updated version will be published at this URL with a revised date at the top.
10. Contact
Questions about this privacy policy can be directed to:
the1hanyou@gmail.com