Effective October 5, 2026

Privacy Policy

Unfry is developed by Sebastian Thorp. This policy explains how Unfry handles information when you use the app, account features, app-blocking features, proof features, notifications, subscriptions, and related services.

Contact: sebastian@rework.no.

Overview

Unfry helps you limit distracting apps, configure protection schedules, complete focus and healthy activities, earn Braincells and spend them on temporary Unwind access. Features vary by app version and platform.

Some information stays on your device. Some information is sent to our backend or service providers when needed for accounts, syncing, subscriptions, proof verification, notifications, app usage insights, or app-blocking features.

We do not sell your personal data or show third-party advertisements inside Unfry. We are preparing optional measurement of our own Unfry campaigns, described below. It remains disabled pending setup and release checks and requires a separate choice.

When Unfry asks for sensitive access that may not be obvious, such as Android Usage Access, installed-app information, foreground monitoring, camera proof, notifications, or similar platform permissions, the app should explain what will be accessed and why before that access begins. GPS/location proof is parked in the current release and is not requested unless it is re-enabled later with matching disclosures.

Earlier app versions

This policy also covers earlier versions distributed under the Task Lock, LockTok or LockIn name. Features and controls vary by version. The v2 on-device proof-storage protections described here do not describe every earlier version: earlier versions may upload proof media for verification or support. Their stated normal remote-media retention period is up to seven days, with longer retention where necessary for security, legal, dispute, or abuse-prevention purposes. Contact us about deletion of data from an earlier version.

Information We Process

Account and profile data

If you create an account, we may process your email address, name or display name, authentication identifiers, avatar URL if provided, timezone, locale, profile preferences, and subscription or entitlement status.

Unfry setup data

To run your plan, we may process Unfry start and end times, scheduled days, schedule mode, app-specific access windows, selected proof modes, selected apps, categories, or website domains to limit, local setup, settings, and proof-keepsake collection state.

App selection, screen-time, and app-blocking data

On Android, if you grant Usage Access or related native permissions, Unfry may process installed-app information, app names, package names, app categories, app icons, selected locked apps, per-app usage totals, hourly usage buckets, same-period-last-week comparisons, and foreground app state needed to enforce an active Unfry session.

Installed-app information and app usage data can be sensitive. Unfry uses this information to let you choose apps to limit, show your screen-time progress, and help keep selected apps locked during active Unfry sessions. Unfry does not sell installed-app or usage data, and does not use it for third-party advertising or advertising analytics.

During an active Android Unfry session, Unfry may run a foreground service to notice when a selected app is opened and bring you back to the Unfry proof flow. This service is intended to run only for active lock windows and may show a persistent Android notification while it is running.

On iOS, Unfry uses Apple's Screen Time, Family Controls, Managed Settings, and Device Activity APIs where available. Apple may keep exact selected app and website names privacy-limited from Unfry. Unfry may process selection tokens, selection counts, aggregate selected-app usage milestones, shield state, and Device Activity state. Unfry does not claim exact per-app iOS usage rows unless a supported native reporting layer is implemented.

Unfry does not read the contents of other apps, your messages, your emails, your browser pages, or your private files.

Unfry session and stats data

When you run or complete a Unfry session, we may process session start and end time, session status, protected focus minutes, phone or app usage before or during the session where supported, proof mode used, completed days, missed days, streaks, protected focus time, screen-time trend, and app usage summaries.

Proof photos and proof metadata

Some proof modes may ask you to take a photo, such as a book photo, notes photo, desk setup photo, laptop/Mac proof, or outdoor reset photo.

The decoded photo bytes pass transiently through a Unfry v2 Supabase Edge Function to OpenAI to check whether the visible evidence matches the selected task. The OpenAI API request disables response storage with store: false. Unfry v2 does not upload the photo to Supabase Storage and does not persist the raw photo, its base64 representation, or an OpenAI image response.

Unfry v2 persists only proof verdict metadata and a SHA-256 digest computed from the decoded photo bytes. The digest helps identify an exact-photo retry or replay; it cannot reconstruct the photo. Supabase and OpenAI still process the photo while servicing the live request and may process ordinary security or request logs under their own service terms.

Accepted non-camera tasks may create a generated, media-free completion card in the same local proof collection. These cards keep only bounded result labels such as a validated repetition count, hold duration, or breathing-cycle count. Prayer and private-reflection text is not copied into a card or retained as proof media.

Do not submit proof photos containing other people's private information, confidential documents, payment cards, government IDs, medical records, nudity, illegal content, or anything you do not want processed for proof verification.

Location proof data

GPS/location proof is not enabled in the current release, and the current release does not request location permission. If a location proof mode is enabled later and you grant location permission, Unfry may process location data only to verify that you are near the selected study or work location. The intended design is to minimize this data by storing rounded or approximate coordinates, accuracy, and capture time where possible, not continuous location history.

Notifications

If you enable reminders, Unfry may process notification preference state, scheduled reminder IDs, push notification tokens when configured, reminder timing, and delivery state.

Notifications are used for Unfry reminders, lock-session updates, proof prompts, subscription/account messages, or similar app functionality. They are not used for third-party advertising.

Purchases and subscriptions

If Unfry offers paid features, purchases are handled through the Apple App Store or Google Play. Unfry uses RevenueCat to help validate subscriptions and manage access to paid features. We may process RevenueCat customer identifiers, product identifiers, entitlement status, purchase state, renewal state, cancellation state, expiration state, and subscription event metadata. We do not receive your full payment card number.

Optional analytics

Optional product analytics uses PostHog EU in builds where it is enabled, with events retained for up to one year. Availability depends on your app version. Collection is off until you make the separate analytics choice below.

When enabled, and only with your optional consent, Unfry will use PostHog EU to understand onboarding progress, screen visits, feature starts and confirmed outcomes, permission results, checkout outcomes, and bounded failure codes. Events include timestamps, app version, platform, a session ID, and a random pseudonymous ID. After sign-in, activity may be linked to your Unfry account. Pseudonymous data is not anonymous data.

Analytics is off until you choose Allow analytics. Choosing Not now leaves every feature available. Change your choice in Settings → Privacy and data → Optional analytics. Withdrawal stops collection and clears pending uploads. Use Delete analytics history or account deletion to remove previously collected events.

Analytics does not include proof photos or recordings, personal answers, private task or reflection text, religious or health details, other-app identities, Screen Time tokens, precise location, or raw error messages. This product-analytics service does not use session recording, advertising IDs, automatic tap recording, or cross-company advertising attribution. The separate planned advertising measurement is described below. Client IP storage and location enrichment are disabled for analytics events; network providers still process connection information to deliver requests.

Events pass through our isolated backend to PostHog EU over encrypted connections. Product analytics events are retained for up to one year to compare onboarding, feature adoption, and return usage across releases and seasons. Pending consented events are stored locally for up to seven days. Minimal consent, pseudonymous account-linking, and privacy-request records support these controls. Short-lived keyed request-budget hashes protect the endpoint without storing raw addresses in those records.

Data export includes available analytics history. Deletion includes associated events and identifiers, is asynchronous, and supports status checks and retries. Account deletion queues provider deletion before removing the account. Minimal deletion receipts are retained for up to 90 days to prevent late retries from recreating deleted history. PostHog processes this data on our behalf, based on your consent. Using Unfry is not analytics consent. See Retention for backup and legal-retention exceptions.

To protect anonymous accounts and proof requests from abuse, Unfry uses Cloudflare Turnstile, Supabase Auth rate limits, private Supabase abuse budgets, Apple App Attest on iOS, and Google Play Integrity on Android. The Edge rate limiter converts the request IP, user/account ID, and installation identifier into secret-keyed pseudonymous values. The private database stores only the pseudonymous value, budget category, window, count, and expiry, not the raw source value. A private CAPTCHA exchange row holds state, a PKCE challenge, and an AES-GCM-encrypted Turnstile token. It is valid for two minutes, redeemable once, and keeps the token out of the app deep-link URL.

Optional advertising measurement — planned, production disabled

We are preparing optional AppsFlyer measurement for our own Unfry advertisements, initially on Meta. Production advertising measurement remains disabled while the revised privacy notice, provider sandbox checks and native-device testing are incomplete. Review builds may contain the controls without establishing provider delivery. This service is separate from PostHog product analytics and is not enabled by using Unfry, accepting the Terms, buying a subscription or allowing product analytics.

In a build where it is available, you can choose Optional ad measurement in Settings → Account → Privacy and data only after separately confirming that you are 18 or older. This is a declaration stored locally for the current device/account, not identity verification. We do not send your date of birth, age or eligibility declaration to advertising providers. Leaving measurement off or declining the adult confirmation does not limit app features, personal Insights or subscription access.

The planned integration uses the standard iOS AppsFlyer SDK. Only after the adult confirmation, separate ad-measurement choice and Apple's App Tracking Transparency permission may it access the iOS advertising identifier (IDFA) or link information across RevenueCat, AppsFlyer and Meta. ATT denial or restriction leaves this per-user measurement off. On Android, access to the available Google advertising identifier (AAID/GAID) similarly requires the adult confirmation and separate choice, and respects the device's advertising-ID settings and required platform permissions. A missing, deleted or restricted advertising ID is not replaced with another identifier to bypass the user's choice. Vendor-ID (IDFV) and Android ID collection remain disabled in this measurement integration. No OAID collector, supporting OAID plugin or manual OAID value is configured. Native review must verify these restrictions in the resulting binaries and provider payloads.

With the adult confirmation, separate choice and required permission, AppsFlyer may process the permitted advertising identifier, install and app-launch information, available campaign/reporting data, timestamps, app/device/platform and network information, an AppsFlyer installation identifier and a random Unfry measurement identifier. Connection IP addresses can be used to infer approximate region; this is separate from GPS location permission. This measurement is pseudonymous, not anonymous: advertising and installation identifiers and RevenueCat-linked subscription outcomes can relate to a customer.

The app sends only a contemporaneous onboarding-completion event, without personal answers or custom event properties. It does not replay earlier onboarding history. When per-user measurement is permitted, we also link the AppsFlyer identifier to your RevenueCat subscription customer so RevenueCat can send confirmed subscription outcomes, such as purchases, trial conversions, renewals and refunds, with product, amount, currency and event timing. Subscription functionality continues independently when advertising measurement is off. The app does not send a second purchase-revenue event to AppsFlyer.

Without the adult confirmation, separate choice or required permission, the app does not initialize or start per-user AppsFlyer measurement or establish a RevenueCat advertising-attribution link. We are separately preparing an operating-system-only iOS install-attribution path using Apple's SKAdNetwork; AdAttributionKit compatibility and campaign reporting require separate verification. This path remains disabled until testing is complete, uses platform postbacks without user- or device-specific identifiers, and has no purchase or revenue conversion mapping. It is not a permission bypass for cross-company user matching. On Android, the fallback is limited to available Meta-reported campaign totals and permitted first-party totals, including PostHog aggregates only for people who separately allow product analytics. The app does not collect raw Google Play Install Referrer data for this fallback. These reporting paths do not establish a per-user AppsFlyer or RevenueCat-to-AppsFlyer sharing path for people who have not consented. Aggregate report availability and accuracy have not yet been verified.

AppsFlyer and RevenueCat may pass only permitted information to the configured Meta integration for measuring Unfry campaigns. Cross-company per-user sharing requires the separate choice and required permission. We do not promise device-level Meta acquisition or subscription-revenue matching, or aggregate campaign delivery, from this configuration; those capabilities must be separately established. We do not send proof photos or videos, exercise-camera frames, private reflections, prayer or feeling text, personal onboarding answers, sensitive habit details, protected-app names/packages, Screen Time tokens or precise location to advertising providers. We do not send your email or name through this app measurement integration.

Turning the choice off, withdrawing the adult declaration or losing the required permission stops new per-user device measurement and requests removal of the RevenueCat AppsFlyer link and restriction of partner sharing. Remote updates may remain pending while offline or if an earlier subscription identity is inaccessible. New per-user device measurement stays off during pending reconciliation. Already accepted or previously shared events are not recalled by switching off; server-side subscription events can continue until the remote change is confirmed. Withdrawal is not deletion of provider history. Contact us for access or deletion of advertising-measurement data; the app's analytics-history deletion/export controls cover PostHog, not AppsFlyer history. Separately configured platform install attribution and campaign totals may still be available without user matching; turning off product analytics also stops new PostHog collection.

Before enabling production measurement, we will complete provider retention, data-rights and audience/territory checks, publish the revised notice and verify provider sandbox/native receipts. The one-year PostHog retention period does not apply to AppsFlyer or Meta. Advertising measurement remains disabled in production until these checks are complete.

Health data

Unfry does not currently collect HealthKit or Health Connect data. If a future feature uses health data, the app will ask for permission and this policy will be updated before that data is collected or transmitted.

How We Use Information

  • Create and manage your Unfry account.
  • Save your Unfry setup across devices.
  • Run schedules, app selections, task pools, and proof flows.
  • Enforce app-blocking behavior where supported by the operating system and permissions.
  • Verify proof submissions.
  • Show session summaries, streaks, insights, app usage, proof stickers, and history.
  • Send reminders and notifications you enabled.
  • Manage subscriptions, trials, entitlements, and restores.
  • Maintain security, debug problems, prevent abuse, and operate the service.
  • Improve Unfry using optional product analytics only with your consent, when enabled.

What We Do Not Do

  • We do not sell personal data.
  • We do not use proof, protected-app identities or sensitive habit content for advertising.
  • We do not start optional advertising measurement without its separate choice and required permission.
  • We do not read the contents of locked apps.
  • We do not read messages, emails, documents, browser content, or private files.
  • We do not share proof photos publicly.
  • We do not monitor another person's device without their consent.

When We Share Information

We share information only as needed to run Unfry and provide the features you use. Current or planned service providers may include Supabase for backend operations and private abuse/CAPTCHA records, Cloudflare Turnstile for CAPTCHA, RevenueCat for subscriptions, Apple for App Attest and App Store services, Google for Play Integrity and Google Play services, OpenAI for proof-image verification, PostHog EU for optional analytics, and Expo services. The planned optional advertising measurement uses AppsFlyer and RevenueCat, with Meta receiving permitted campaign-measurement information. This integration remains disabled.

We may also disclose information if required by law, to protect rights and security, or as part of a merger, acquisition, financing, or sale of assets, with appropriate notice where required.

Retention

Local advertising-choice state, the account/device-local adult declaration and pending revocation records support consent, withdrawal and reconciliation. Pending records do not mean a provider deletion is complete. Final AppsFlyer/Meta retention must be confirmed before this planned integration is enabled; the one-year PostHog period does not apply to advertising measurement.

We keep information for as long as needed to provide Unfry, maintain your account, comply with legal obligations, resolve disputes, handle refunds, prevent fraud, and enforce agreements.

Account data, setup, schedules, app selections, sessions, stats, and proof records generally remain until deleted by you or your account is deleted. Local proof media remains on your device unless you delete it, uninstall the app, clear app data, or the app removes it. Unfry v2 does not retain raw proof media remotely. Proof verdict metadata and the decoded-byte SHA-256 digest remain with the proof record until that record or account is deleted, subject to legitimate security, legal, backup, and dispute obligations. Pseudonymous abuse budgets stop affecting requests within 24 hours and are removed by recurring cleanup. CAPTCHA exchanges are valid for two minutes and are deleted on redemption or cleanup. Earlier database states may remain in provider backups for the configured backup-retention period.

Your Choices and Controls

When available, you can decline or withdraw Optional ad measurement in Settings → Account → Privacy and data, withdraw the adult declaration, and review iOS tracking permission or Android advertising-ID settings in device Settings. Contact us for access or deletion of advertising-measurement history. The PostHog analytics-history controls do not erase or export AppsFlyer/Meta history. Account deletion does not establish immediate provider erasure; remote withdrawal and erasure are separate operations.

  • Choose which apps, categories, or website domains Unfry should limit.
  • Change your schedule, task pools, proof modes, and notifications.
  • Grant or revoke camera, location, notification, Screen Time, Family Controls, Usage Access, or related permissions in device settings.
  • When available, decline optional analytics or withdraw consent in Settings without losing app functionality, personal Insights, or subscription access.
  • Request deletion of analytics history through the app control when available or by contacting us.
  • Export your Unfry data where the app provides an export control.
  • Delete your account where the app provides account deletion.
  • Contact us to request help with access, correction, deletion, or privacy questions.

Legal Basis, Security, and Children

Optional product analytics and the separate optional advertising measurement rely on their separate choices when enabled. Device permissions do not authorize unrelated analytics or advertising measurement. You can withdraw consent without affecting the lawfulness of earlier processing. Depending on applicable law, you may request access, correction, deletion, portability, restriction, or object to processing. Contact us to exercise these rights. You may complain to your local data-protection authority, including Datatilsynet in Norway.

PostHog EU processes optional product analytics in enabled builds. Other providers may process information outside your country. Where required, appropriate safeguards must apply to international transfers; EU hosting alone does not prevent all international processing.

If you are in the EEA, the UK, or a similar jurisdiction, our legal bases may include contract, consent, legitimate interests, and legal obligations. We use reasonable technical and organizational measures to protect information, including authenticated access controls, row-level security for user-owned backend data, and encrypted transport where supported.

Unfry is not intended for children under 13, and it is not designed for monitoring children without proper consent.

Changes

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. If changes are material, we will provide notice as required by law or store rules.

Contact

For privacy questions or requests, contact sebastian@rework.no. You can also review the account deletion instructions.