Time Pact Privacy Policy
Effective date: August 6, 2026
Time Pact is built so that your data stays on your device. There are no accounts, no analytics, no ads, no trackers, and no server of ours holding your data. This policy explains, in plain language, exactly what the app touches and the only three ways any data ever leaves your phone — each one started by you.
The short version
- Everything you do in Time Pact — your activities, pacts, and logged time — is stored in a local database on your device. We can't see it.
- The app never collects analytics or telemetry, shows no ads, and uses no third-party trackers.
- Data leaves your device only when you choose: sending a bug report, exporting your data, or (on iOS) turning on iCloud sync to your own iCloud account.
- Health and app-usage data never leave your device at all — they're excluded from every off-device path by design.
What the app stores on your device
Activities you create, pacts between them, time you log (by timer or manual entry), your settings, and — if you enable the relevant features — imported sleep sessions (iOS) and app-usage sessions for apps you chose to block (Android). All of it lives in a local database that ships with the app. Deleting the app deletes it; Settings → Delete all data wipes it in place.
Data the app reads with your permission — and where it goes (nowhere)
Apple Health (iOS, optional). If you connect sleep import, the app reads sleep sessions from Apple Health, on the device, with the permission you grant in Health. Imported entries are labeled, are not editable in the app, and are excluded from iCloud sync, from bug reports, and from any other transmission to us. Disconnecting the source stops the imports.
App usage (Android, optional). If you turn on app blocking, the app uses the Usage Access permission to see which app is in the foreground so it can hold the door on apps you explicitly added to your blocklist, and to record how much time you spent in them. This usage data is only about the apps you chose, stays on the device, and is excluded from bug reports and every other off-device path. Turning enforcement off (or revoking the permission) stops the reading; the app never reads usage for apps you didn't blocklist.
The three ways data can leave your device — all started by you
1. Bug reports (optional). When you write and send a report from Settings, we receive: the text you wrote, your app version and platform (iOS/Android), and a copy of your Time Pact data — your activity and pact names and logged time entries — excluding everything imported (no health data, no app-usage data, ever). The report travels over HTTPS to a Cloudflare Worker we operate and is delivered to a private Discord channel read by the developer. Cloudflare, Inc. and Discord, Inc. process it on our behalf; it is kept until manually deleted and is used only to investigate your report. Email us (contact below) to have a report deleted.
2. Your own exports (optional). Settings → Export creates a JSON file of your data and hands it to your device's share sheet. It goes wherever you send it — to your files, your email, another app. We never receive it.
3. iCloud sync (iOS, optional, off by default). If you turn it on, your activities, pacts, and user-entered logs sync through your own iCloud account's private database so your other Apple devices can see them. This is between your device and Apple — we operate no server in that path and cannot read your iCloud data. Apple's terms and privacy policy govern iCloud. Imported health data does not sync.
Purchases
Subscriptions are handled entirely by Google Play or the App Store. We never see your payment details; the app only learns whether an active subscription or trial exists, from the store, on your device.
What we never do
No analytics or behavioral telemetry. No advertising or ad SDKs. No trackers. No selling or renting data — there is nothing to sell. No accounts, so nothing to breach. No background transmission of any kind: if you never tap Send or Export and never enable iCloud sync, no byte of your data reaches anyone.
Android permissions, and why
- Usage access — detect the foreground app and count time, only for apps on your blocklist. Stays on device.
- Display over other apps — show the block screen over an app whose earned time is spent.
- Notifications — the persistent "blocking is on" notice and the optional daily reminder. All notifications are generated locally; there is no push server.
- Run at startup — re-arm app blocking after a reboot.
Retention and deletion
Your data lives on your device for as long as you keep it. Settings → Delete all data erases it in place; uninstalling the app removes it. Bug reports are the only data we hold, and we delete them on request.
Children
Time Pact is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes
If this policy changes, the updated version is published at this address with a new effective date. Material changes will be noted in the app's release notes.
Contact
Time Pact is made by DFM Studio LLC. For anything in this policy — questions, complaints, or a deletion request — email contact@dfm.studio.