mast privacy policy

Last updated 26 August 2026

This policy covers the Mast app for iPhone and Apple Watch, made by Tissue Systems ("we"). Mast has no accounts, no analytics, and no advertising, so this document is short. The platform that Mast's servers run on has its own privacy policy; this one describes what the app itself stores and why.

01 What Mast stores

02 What Mast never collects

No analytics or crash-tracking SDKs, no advertising identifiers, no location, no contacts, no cross-app tracking of any kind. We do not sell any of the data above, and we do not use your message content to train machine-learning models.

03 Where messages travel

A message posted to your channel address travels to our servers over HTTPS and is delivered to your phone through the Apple Push Notification service, which is how any iOS notification arrives. Apple processes the notification payload to deliver it; Apple's handling is described in its own privacy documentation. Message content is otherwise stored only on infrastructure we operate — see the platform security page for where and how.

04 The channel address is a key

Anyone who has a channel's send address can post to that channel. That is the design — it is what lets a shell script page you with one line — so treat the address like a password. You can rotate a channel's key in the app at any time; the old address stops working after a short grace period.

05 Purchases

The one-time purchase is processed entirely by Apple through the App Store. We receive a receipt that marks your copy as purchased; we never see your payment details.

06 Connecting a Tissue account

Connecting a Tissue account is optional and nothing in Mast requires it. If you connect one, we store the link between your device and that account, and the account's data is covered by the platform privacy policy. Disconnecting in the app forgets the account credential on the device; to remove the stored link as well, email privacy@tissue.systems.

07 Deleting your data

Deleting a channel in the app removes it and stops its address. Messages delete themselves after 30 days. Unlinking a device removes its record from our servers, and deleting the app from your phone invalidates its push token, after which nothing further can be delivered or stored. For anything beyond that — including removing every trace of a device immediately — email privacy@tissue.systems from any address, naming the channel or device, and we will delete it.

08 Changes and contact

Material changes to this policy move the date at the top. Questions about privacy reach privacy@tissue.systems; anything else about Mast reaches support@tissue.systems.