User guide — all chapters
What Selfish holds, and what it doesn’t
Worth stating plainly, because it shapes how the app behaves in a lot of places.
| What | Where it is |
|---|---|
| Your writing | On your device, and in your own iCloud account if you use iCloud. We never receive it. There is no Selfish account and no Selfish server. |
| Your passwords, keys and tokens | In the Apple Keychain, read fresh at each publish. With iCloud Keychain on they sync between your own devices, end-to-end encrypted. They are never in the site’s data, an export, a log, or anything we could see. |
| Your photos’ details | Stripped when a photo comes in. Location never reaches the web. Camera settings are kept only so you can choose to show them. |
| Your readers | The site Selfish builds carries no analytics and no tracking. Nothing watches them on your behalf. |
| Your way out | The published site is plain HTML, and the export is plain Markdown. Delete the app and your site keeps serving. |
When the app uses the network
Selfish has no server of its own to talk to. It connects only to places you have chosen, and only when you ask.
| When | What it connects to |
|---|---|
| You publish, or test a connection | The place your site lives: your server, your storage, or Netlify, Cloudflare or GitHub. Opening the publish screen reads Selfish’s record from there too. |
| A publish finishes | Your own site’s address, to check it shows the new version. |
| You sign in with GitHub | GitHub. |
| You import a site, or a Markdown file | The old site or the address you typed, and any other site a post’s pictures are on, to download them. |
| You ask for a link card | The page the link points to, once, and the site its picture is on. |
| “Tell sites you link to” is on | The sites your new and changed posts link to, after a publish, or the Webmention service a site has named to receive them. |
| You check your own domain | Nothing new: this device’s own resolver is asked, so the domain isn’t sent to anyone else to look up. |
| You use iCloud | Your own iCloud account, through Apple. With Handoff, your other devices are told which post is open. |
| You open the theme gallery, or buy or restore a theme | Apple’s App Store, for the premium themes’ prices and your purchases. |
Three things use no network at all: suggestions, which Apple’s on-device model writes; Writing Stats; and system search, whose index stays on your device.
What the app asks permission for
- Photos. You pick photos through the system’s own picker, so Selfish sees only the ones you choose.
- The microphone, only if you record audio in a post, and only while you are recording.
- Notifications, for the reminder on the morning a scheduled post is due.
What your readers’ browsers are asked for
A site as Selfish makes it runs no scripts, sets no cookies, and loads nothing from any other site: no fonts, no icons, no embeds. Every publish from the publish screen checks this and reports it. See the privacy report.
Two things can change that, and both are your choice.
- Search, if you add it to your menu, is one small script on the search page, reading only your own site.
- Videos and audio are files on your own site. They are not embeds from a video service.
Site Settings → Site → Privacy → Block scripts and other sites’ files has browsers enforce all of this.
The Selfish directory
If you would like your site listed publicly among sites made with Selfish, there is Submit to the Directory in Site Settings → Site. It opens a form on this website in your browser, with your site’s address, title and theme already filled in, so that much reaches selfpubli.sh when the page opens. Nothing is submitted for review unless you send the form, and entries are reviewed by hand. It is opt-in and easy to ignore. See the directory →
The full privacy policy says the same things in more formal words.