ClientAPT

Your Book  ·  Their Secrets

The offline appointment book built for solo service providers whose clients expect absolute discretion — tattoo artists, nail techs, stylists, cleaners, and anyone whose client list is theirs alone. Names, photos, and notes stay encrypted on your device. No cloud. No lock screen previews. Nobody else's business.

Works fully offline. Never calls home. One PIN stands between your client list and everyone else.

iPhone · iOS 17 and later · One-time purchase · No subscription · No account

ClientAPT — encrypted appointment book for solo service providers
For the studio

Tattoo artists & piercers

You hold photos of unfinished work on bodies your clients may not have told anyone about. You know which regulars can't overlap in the waiting room. ClientAPT keeps the book sealed — even when your phone is on the counter.

For the chair

Nail, beauty & lash

Your clients expect discretion when they book — about who else you see, how often, and what they ask for. A lock screen preview or a shared calendar blows that trust in seconds. ClientAPT shows nothing without your PIN.

For the home visit

Cleaners, organizers & mobile pros

You're in people's homes with your phone in your pocket. You know their schedules, addresses, and routines. That data belongs to them — not to anyone who finds or steals your device.

For private practice

Discreet & confidential services

Your clients found you through referral, word of mouth, or a trusted network. They chose you because they know their name won't appear anywhere. That promise deserves to be architectural — not just personal. ClientAPT makes it mathematical.

Real situations, not edge cases

Your phone tells more than you think.

Privacy isn't about paranoia. It's about the ordinary moments when your device is out of your hands and your clients are on the screen.

I.

The client who shows up early

Your next appointment walks in while you're still finishing. Your phone is on the counter, lit up with a notification. The name of the person currently in your chair is right there on the lock screen.

With ClientAPT: the notification reads "Appointment at 2:30." No name, no service, no note. The detail lives behind your PIN.

II.

The phone left at a client's place

You're halfway home when you realize it's missing. They text to say they found it. Lovely people — but you have no idea how long it was sitting there, or what they saw before it locked.

With ClientAPT: the app re-locks the instant it backgrounds. Every return from sleep hits a PIN gate. The data on disk is ciphertext — nothing readable without your code.

III.

The partner who asks questions

A client's ex wants to know when they were in, who else you see, how often they book. Your calendar is leverage you didn't agree to hand over.

With ClientAPT: enter the duress PIN if you need to show something. A believable decoy vault opens — a thin roster, a few sales, nothing real. The real book stays sealed.

IV.

Someone demands to see your phone

A client's partner. A controlling regular. Someone with authority they've decided to press. You hand it over — and they go straight to your appointments.

With ClientAPT: enter the duress PIN before you hand it over. A convincing second vault opens — plausible names, routine entries, nothing real. No visual tell. No loading difference. No hesitation. The real book stays sealed.

V.

The break-in

Studio gets hit overnight. Phone gone with the register. You file the report and spend the next week wondering what's being done with your client list — who has their names, numbers, home addresses.

With ClientAPT: nothing readable was on that device. The database is AES-GCM encrypted with a key derived from your PIN. Without it, they have random bytes.

The lock, explained plainly

They got into your iPhone. They still don't get your book.

Face ID worked. The phone is open. They tap ClientAPT. Here's what happens next.

01

The app opens to a PIN gate, not your calendar.

ClientAPT doesn't trust that your iPhone is already unlocked. Every launch, every return from background — it re-locks. No data has rendered. There's nothing to screenshot.

02

The data on disk is gibberish without the PIN.

Your appointments, client notes, and photos don't exist as readable bytes anywhere on the device while locked. The database is sealed with SQLCipher (AES-256), and the most sensitive columns are wrapped again with AES-GCM. Pull the file off with a forensic tool and you get noise.

03

The key is your PIN. There's no copy anywhere.

There's no stored master key to lift. The database key is re-derived from your PIN on every unlock using Argon2id — memory-hard, calibrated for modern iPhones. Fast for you (~250 ms). Ruinously slow for a brute-force rig.

04

Flagged clients sit behind a second PIN.

The clients you've marked sensitive are encrypted with a separate key from a separate PIN. Even if someone gets your everyday code, those records look like an empty list. Two locks, two keys, one device.

An unlocked iPhone is a key to the iPhone. It is not a key to ClientAPT. The boundary is mathematical — and it runs on every screen, every time, whether you remembered to lock it or not.

Composite cases

What a glance at your screen actually costs.

The following are composite accounts drawn from the kinds of situations solo service providers share in peer forums. Names and details are illustrative. The pattern is not.

"One of my regulars came in while I was finishing someone she knew — someone she definitely wasn't supposed to know was my client. My phone was on the counter, app open. She saw the name before I could turn it over. Lost both of them inside two weeks."
— Tattoo artist, independent studio
"I clean for two people in the same building going through a divorce. Neither knows the other hired me. Got a weird DM from one of them asking who else I work with in the building. I pieced it together: I'd left my phone on the kitchen counter with the schedule visible. I ghosted both jobs that day."
— Independent home cleaner
"A client's boyfriend called asking for 'her appointment history.' I said we don't share that. He said he'd already seen most of it from a screenshot on her feed — turned out to be my phone in the background of a group photo. I couldn't see what was in frame until I watched it back. My whole week was there."
— Nail tech, independent suite
"Shop got broken into on a Friday night. They took my laptop, the register, and my phone. The phone had iCloud backups on — four years of client photos, addresses, and appointment notes synced to an account I couldn't remotely wipe in time. Never again."
— Body artist, street-level shop
"A client's partner showed up during an appointment and demanded I open my schedule — wanted to see how often she'd been there, who else was in the book. I opened the app, entered the duress PIN, handed it over. Completely convincing. They looked through it and left. The real book was never touched."
— Independent service provider
How the seal holds

Protection that doesn't require you to remember it.

The defaults are the defenses. Nothing to enable, no toggle that flips back on after an iOS update.

Two-tier vault

Everyday PIN for the whole book. Optional second PIN for flagged clients — their records are sealed behind a distinct key. Argon2id wrapping, AES-GCM at rest.

Duress PIN

A second code opens a convincing decoy vault — plausible names, routine entries, nothing real. No visual tell, no loading difference, no hesitation. Hand it over with confidence. The real book doesn't exist to whoever is looking.

Notifications that say nothing

Lock screen banners show only "Appointment at HH:MM." No name, no service, no address. The reminder gets you to the chair; the detail waits behind your PIN.

Privacy overlay

The moment the app backgrounds, a curtain drops over the view. The iOS app-switcher snapshot shows nothing recognizable. The app re-locks on every return.

No cloud. No Calendar. No Spotlight.

Doesn't sync to iCloud, hand off to the iOS Calendar, or expose anything to Spotlight or Siri. Your client list doesn't exist on any server. There is no server.

Photos that never leave the app

In-app camera capture. Photos encrypt with AES-GCM before they touch disk. Nothing ever appears in your Camera Roll, iCloud Photos, or any backup that leaves the device.

Open source

The entire codebase is published. The cryptography is documented and mutation-tested. Discretion you can't inspect is just a promise. This one you can read.

Your clients trusted you before they trusted anyone else.

Some of them trusted you with things they haven't told anyone. Their name on your schedule, the note you wrote about what they need, the appointment they keep private — that's their story. It should stay with you.

Built quietly, in Swift, for the iPhone you already own.

Bring the seal to your practice

A one-time purchase. No subscription. No account.

No web version, no admin console, no team plan, no free tier that asks for your email. A single signed binary from the App Store. Once. Yours.

  • Works fully offline. Makes no network calls.
  • iPhone, iOS 17 and later.
  • Source published on GitHub. Audit before you trust.