Curfew is an alarm app. It needs very little about you, so it takes very little.
This policy describes the Curfew iOS app and the getcurfew.app website. It is written to match what the code actually does; where a section says something does not happen, that is a statement about the software, not a promise about intentions.
The short version. Your alarms and the list of apps you chose to block never leave your iPhone, and push-up and squat counting happens entirely on your device. Three things do leave: if you use the Object Hunt mission, the single photo you take is sent to be checked and is then kept by nobody; anonymous usage analytics — which screens you use, how the app is set up, and your answers to the setup questions in rounded form — go to our analytics provider under a random identifier that is not your name, email or Apple ID; and your subscription status goes through RevenueCat. No advertising, no tracking across apps, no account.
What stays on your device
All of the following is stored on your iPhone and is never transmitted to us:
- Your alarms — times, repeat days, labels and sounds. (Analytics sees how many alarms you have and which missions they use, never when they ring or what they are called.)
- Your app selection for blocking. Curfew uses Apple’s Screen Time (Family Controls) framework. Apple deliberately gives apps only opaque tokens for your selections, not names — we could not tell you which apps you picked even if we wanted to, and those tokens are meaningless outside your device. Analytics sees only whether blocking is switched on.
- Push-up and squat analysis. Body-pose detection runs on your device using Apple’s Vision framework. The camera feed is analysed frame by frame in memory to count repetitions and is never recorded, never stored, and never uploaded.
- Your mission history. Your current streak number is part of the analytics profile described below; the history behind it is not.
The one thing that leaves: an Object Hunt photo
The Object Hunt mission asks you to photograph a named object. To judge whether the photo shows that object, the single captured frame is sent over an encrypted connection to our verification service, which forwards it to Google’s Gemini vision model and returns a verdict.
- The photo is used for that one check and for nothing else.
- It is not stored — not on our server, not by us, and not in your photo library.
- It is not linked to your name, your email, or any account. Curfew has no accounts. The request does carry the same random identifier and a per-morning session id that analytics uses (below), so we can see how often the judge fails — but never the photo.
- It is not used to train any model by us.
Google processes the image as our service provider under their API terms. If you would rather no image ever left your device, use any other mission: Math, Push-Ups and Squats all work with no network connection at all, and Math needs no camera either.
Purchases
Subscriptions are sold through Apple’s App Store and processed by Apple. We use RevenueCat to tell whether a subscription is active. RevenueCat receives a random, app-generated identifier and the purchase information Apple provides, and forwards subscription events (started, renewed, cancelled, expired — never payment details) to our analytics provider under that same identifier. We never see your card details, your Apple ID, or your name — Apple does not share them with us.
Usage analytics
Curfew uses PostHog, an analytics service hosted in the United States, to understand how the app is used and where it breaks. This is what it receives:
- What you do in the app — an onboarding step viewed, an alarm saved or switched off, a mission started, completed or abandoned, the paywall shown, the app launched. Each event carries the app version, iOS version and device model.
- How the app is set up — how many alarms you have, which missions they use, your current streak, whether app blocking is on, which permissions you granted, and the dates you first saved an alarm, first won a morning, and first saw the offer.
- Your answers to the setup questions, stored in the rounded form the app uses to pick a mission for you — for example “hits snooze four or five times”, not free text.
- Object Hunt outcomes from our verification service — whether the judge answered, how long it took, and which object was asked for. Never the photo.
All of it is keyed to a random identifier generated by the app — the same one RevenueCat uses. It is not your name, email, phone number, Apple ID or advertising identifier, and we do not join it to data from any other app or website. PostHog derives an approximate location (country and city) from the IP address of the request; Curfew never uses your device’s location services. There is no session recording and no screen capture. Debug builds send nothing.
We keep these events for as long as we are actively improving the app and delete them when we no longer need them. Deleting Curfew stops all collection; a reinstall starts with a new identifier.
The support form
If you write to us through the support page, we store the email address, subject and message you send, along with any app version, iOS version or device model you choose to include and the browser user-agent string of the request. We use this only to answer you and to fix what you reported. You can ask us to delete it at any time.
What Curfew does not do
- No tracking. Curfew does not track you across apps or websites and requests no advertising identifier.
- No advertising, and no data is ever sold or shared with data brokers.
- No advertising SDK is embedded in the app.
- No account, so there is nothing to sign in to and no profile with your name on it.
- No use of location services. The only location-shaped data is the approximate country and city PostHog infers from an IP address, described above.
- No microphone access is requested.
Permissions, and why
- Alarms / Notifications — so an alarm can ring. Without this Curfew cannot do its job.
- Camera — only for Object Hunt and the exercise missions, and only while a mission is running. Curfew never picks images from your photo library; for Object Hunt that would defeat the point.
- Screen Time (Family Controls) — only if you choose to use app blocking. Skip it and the rest of the app works.
Each of these can be revoked in iOS Settings at any time.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to or restrict its processing. In practice we hold two kinds: what you sent us through the support form, and the analytics events described above. Write to bizhanash@gmail.com and we will act on your request; because the analytics identifier is random and not linked to your name, tell us roughly when you installed the app and we will delete every event we can match. You may also complain to your local data protection authority.
Everything else lives on your device and is deleted when you delete the app.
Children
Curfew is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has sent us something through the support form, write to us and we will delete it.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change is significant, say so in the app.