Privacy Policy
Last updated 2026-09-09.
Plain-language summary
We collect the minimum needed to run a commitment device: your account email, the device commitments you create, an encrypted copy of your Screen Time passcode, and audit records of what happened. We do not track your browsing, sell ads, or share your data for marketing. We can decrypt your sealed passcode when your commitment timer expires — this is by design, so we can release it back to you.
1. Who we are + how to reach us
Screen Guardian is a consumer-facing self-restriction service. Data-protection questions: support@screen-guardian.app.
2. What we collect
- Account: email address, hashed password (managed by our auth provider). Optional display name.
- Commitment data: device nickname you enter, chosen commitment duration, timestamped lifecycle events (setup started, activated, unlocked).
- Encrypted Screen Time passcode: the passcode you never see, stored encrypted (see “How we hold your passcode” below).
- Setup ceremony state: which wizard steps you completed and when — internal audit trail so partial setups can resume.
- Audit log: timestamped record of significant events per commitment (created, activated, reveal-requested, unlocked). Retained for approximately 2 years.
- Partner data (optional feature): partner email + a PBKDF2 hash of the recovery passphrase they set (not the passphrase itself).
- Affiliate program (opt-in): application answers, hashed IP of referral clicks, referral-conversion records, payout details.
- Server logs: IP address, user agent, timestamps. Retained for approximately 30 days for security purposes.
- Rate-limit records: hashed request identifiers, retained ~24 hours.
3. What we don’t collect
- Any of your iPhone’s browsing history, app usage, or content.
- Third-party ad-tracking cookies, marketing pixels, or advertising IDs.
- Payment card numbers — the payment processor (see §7) handles those; we only see order metadata.
4. How we hold your passcode — honest read
When you complete setup, we generate a random Screen Time passcode and encrypt it at rest using envelope encryption:
- A per-lock random Data Encryption Key (DEK) encrypts the passcode with AES-256-GCM.
- The DEK itself is wrapped by a Master Key that Screen Guardian holds in server-side secret storage.
Important honest statement: because we hold the Master Key, we are able to decrypt your passcode when your commitment’s time-lock expires (or when the partner reveal ceremony completes). This is not a zero-knowledge product. If our system is breached and both the ciphertext and the Master Key are compromised, sealed passcodes could in principle be decrypted. The Master Key is stored in a secret manager separate from the application database and is rotated on incident response or material infrastructure changes.
The optional partner emergency envelope IS end-to-end (we don’t hold the passphrase your partner sets). That specific artifact is decryptable only by a party holding both the ciphertext and the partner-chosen passphrase.
5. Purpose & lawful basis
- Providing the service (contract) — commitment data, encrypted passcode, ceremony state, account.
- Security & abuse prevention (legitimate interest) — server logs, rate-limit records, audit log.
- Transactional email (contract / legitimate interest) — setup notifications, unlock releases, security alerts.
- Affiliate program (contract, opt-in) — if you enroll.
6. Retention
- Encrypted passcode: retained until commitment ends and reveal is delivered, then zeroized.
- Audit events: approximately 2 years.
- Reveal requests: approximately 90 days after terminal state.
- Server logs: approximately 30 days.
- Rate-limit buckets: approximately 24 hours.
- Account & commitment data: retained while your account exists; deleted on account deletion.
7. Processors we share data with
The following processors receive data strictly to perform the service on our behalf under a data-processing agreement:
- Supabase — database + authentication hosting. All application data (see §2) lives here.
- Vercel — web-application hosting; access logs at their infrastructure layer.
- Resend — transactional email delivery (setup notifications, reveal requests, partner invitations). Recipient email address and message content transit their service.
- OpenAI — text-to-speech for the guided passcode ceremony (see the dedicated AI Disclosure). We cache generated audio for whitelisted phrases so most users’ audio is served from our cache without a fresh OpenAI call.
- Google Translate TTS — fallback voice provider if OpenAI is unavailable.
- Dodo Payments — payment card handling, subscription lifecycle. We receive order metadata; card numbers are handled by the processor.
For personal data originating in the European Economic Area or the United Kingdom, we rely on the appropriate transfer safeguards each processor makes available (Standard Contractual Clauses, UK addendum, or an adequacy decision where applicable).
8. Your rights
Depending on your jurisdiction you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. You may also lodge a complaint with your local data-protection authority (e.g. your EU member-state DPA, the UK ICO, or Mexico’s INAI). Exercise any of these rights by emailing support@screen-guardian.app.
You can view and delete your account and associated data from Settings at any time. If you have an active commitment, we’ll require you to end it first so you’re not locked out of your iPhone.
9. Cookies
We use only strictly-necessary cookies for authentication and session management. We do not use ad-tracking or analytics cookies.
10. Children
Screen Guardian is not intended for anyone under 18. We do not knowingly collect personal data from minors. Where local law recognizes a younger digital age of consent, that local minimum applies to the collection of that user’s data.
11. Changes to this policy
We may update this policy as the product or legal landscape changes. Material changes will be announced by email and via a notice on this page at least 30 days before they take effect.