Privacy Policy
Last updated: 25 July 2026
The short version. Screen Time Machine has no user accounts and keeps no database of you. The apps you pick, your schedules, your limits and your screen time figures are stored on your device and are never sent to us or to anyone else.
Three things do leave your device, and none of them carries your screen time: anonymous product analytics that tell us which features are used (section 5), purchase validation if you buy Pro (section 4), and feedback if you choose to send some (section 2). We show no ads, include no advertising or attribution SDKs, and sell nothing to anyone.
1. Who we are
Screen Time Machine ("the app") is provided by Steven Freville ("we", "us"). You can reach us at support@screen-time-machine.com. This policy explains what the app does with information on your device, and what (very little) reaches anyone else.
2. Information we collect
We do not collect personal information. There is no account system, we never ask for your name or email, and we hold nothing that identifies you. The anonymous analytics described in section 5 are the only routine transmission the app makes, and they are not tied to any identity we can trace back to a person.
The app does create and read the following on your device only:
- Your settings — which apps you've chosen to track, your daily limits, your schedules, focus session settings, and your onboarding answers.
- Screen time figures — how long the apps you selected have been used, read from the operating system's own usage statistics so the app can total your day and know when a limit is reached.
- The list of apps installed on your device — read only to populate the picker where you choose which apps to track. It is displayed to you and never leaves the device.
All of it lives in the app's private local storage, in the app's own sandbox, where other apps cannot read it. Uninstalling the app deletes all of it.
Feedback you choose to send is the one exception, because it only works by leaving your device. When you submit the in-app feedback form, we receive your message and your thumbs-up or thumbs-down, together with basic context for support: the app version, platform and OS version, device model, which of the app's permissions are granted, roughly how many days you've had the app, and the same anonymous purchase identifier described under Purchases — that identifier is what lets us send a reply back to your app, and nothing else can be looked up from it. It is stored in our database (Google Cloud Firestore), read by us, used only to read and answer your message, and never sold or shared. No screen-time figures and no list of your tracked apps are ever included. To have a submission deleted, email us at support@screen-time-machine.com.
3. Permissions, and why the app asks
Screen Time Machine needs several sensitive Android permissions to do its job. Each is requested only when the feature that needs it is set up, each is explained in the app before it is requested, and none of them are used to gather information about you.
Accessibility Service Prominent disclosure
Screen Time Machine uses Android's Accessibility Service API for one purpose only: to detect which app has just come to the foreground, so that it can step in the instant an app you've blocked or limited is opened. This is the only mechanism Android offers an app for that purpose.
The service does not read the content of your screen, log what you type, collect your messages, or record anything about what you do inside other apps. The foreground app's identifier is evaluated on the spot against the rules you configured and is not stored, profiled, or transmitted. We do not use the Accessibility Service to collect any data, and we do not share or sell any data obtained through it.
Usage access
Lets the app read how long each app has been in the foreground, via Android's
UsageStatsManager. This is what makes daily totals and per-app limits
possible. The figures are read on your device, shown to you, and stay there.
Notifications
Used to show the ongoing block or focus-session notification and to tell you when a session starts or ends.
Ignore battery optimization
Optional. Asks Android not to put the app's enforcement service to sleep, so that blocking keeps working in the background. Declining it makes blocking less reliable but is otherwise fine.
Package visibility
The app queries the list of launchable apps so you can pick which ones to track. It uses
Android's targeted <queries> mechanism rather than the broad
"query all packages" permission.
Screen Time (Family Controls) — iOS
On iOS, blocking is performed through Apple's Screen Time (Family Controls) framework. Apple deliberately gives apps only opaque tokens representing your selections — Screen Time Machine never learns the real names or identifiers of the apps you choose, and Apple does not permit that information to leave your device.
4. Purchases
Screen Time Machine Pro is sold as an in-app purchase. Payment is handled entirely by the Google Play Store or the Apple App Store — we never see your card details, billing address, or any payment information.
To check whether a purchase is active, the app uses RevenueCat, a purchase infrastructure provider. When you open the paywall or make a purchase, RevenueCat receives a randomly generated anonymous identifier along with purchase and device information (such as platform, app version, and store receipt) in order to validate the receipt and report back whether Pro is unlocked. This identifier is not linked to your name or email, and none of your usage data, app selections, limits or schedules are sent to RevenueCat or anyone else. See RevenueCat's privacy policy for how they handle it.
Your store account relationship is with Apple or Google, and their privacy policies govern it.
5. Anonymous product analytics
The app sends anonymous usage events to PostHog, a product analytics provider, so we can see which features people actually use and where the app is confusing. These events are hosted on PostHog's EU Cloud, so the data stays in the European Union.
What is sent:
- Which screen you opened — the app's own screen name, such as the paywall or the settings screen. Never the content of the screen.
- That a feature was used — for example that a schedule was created, a daily limit was switched on, a focus session was started or stopped, a permission was granted, a slip was issued or shared, or the paywall was opened.
- A few plain figures about those actions — how many apps you have selected (the number, never which ones), the length of a limit or a focus session, which Pro plan was chosen, whether a purchase succeeded, and whether a day came in over or under your cap as a true/false.
- Opening and closing the app, and standard technical context the analytics library attaches by itself: your device model and type, operating system and version, app version, language and time zone. Your device's IP address is visible to PostHog when an event is sent and may be used to infer an approximate location, usually no finer than a city.
What is never sent: your screen time figures, the names or identifiers of the apps you track or block, the contents of your schedules, anything the Accessibility Service observes, and anything that identifies you as a person.
It is anonymous. The analytics library generates a random identifier that stays on your device and groups that device's events together. We never call PostHog's identify function, attach no name, email or account, and build no profile of you. We cannot tell who a device belongs to, and neither can we connect it to a purchase or a feedback message.
Turning it off. The app does not currently offer a switch for this, which we would rather be plain about than bury. Uninstalling the app stops it, and blocking the app's network access at the system level stops it while keeping the app installed — blocking and limits are enforced entirely on your device and keep working offline. We intend to add an in-app opt-out; when it ships, this section will say so.
Development builds never send anything. Analytics are disabled in the app's code unless it is a release build with an analytics key configured.
Under the GDPR our basis for this processing is our legitimate interest in understanding how the app is used well enough to maintain and improve it, balanced against the fact that the data is anonymous, minimal, and never used to target or profile you. PostHog acts as our processor. See PostHog's privacy policy for how they handle it.
6. What we don't do
- We do not sell or rent your data, to anyone, ever.
- We do not share your data with advertisers or data brokers.
- We include no advertising, attribution or ad-tracking SDKs, and show no ads.
- We do not send your screen time figures, your tracked apps, or anything the Accessibility Service sees off your device.
- We do not build profiles of you or use your data for automated decision-making.
- We do not track you across other apps or websites.
- We run no session recording and capture no screenshots of your use of the app.
7. Your rights over your data
Everything the app records about your screen time stays on your device, so you already have complete control of it without asking us. You can change or delete your selections, limits and schedules at any time in the app, and uninstalling the app erases everything it stored.
Depending on where you live, you may have rights to access, correct, delete or export personal data an organisation holds about you, and to complain to a data protection authority. We hold no data that identifies you: the analytics in section 5 are anonymous, so we have no way to find the events belonging to a particular person, and honesty requires us to say that rather than promise a deletion we cannot perform. What we can act on is any feedback you sent us, which is stored against an identifier your app knows — email us and we will delete it. For purchase records, see section 4.
If you want to stop contributing analytics altogether, section 5 explains how.
If you are in the European Union, the GDPR gives you those rights and the right to lodge a complaint with your national supervisory authority. In France that is the CNIL — www.cnil.fr.
For purchase records, requests should be directed to Apple, Google, or RevenueCat, who process that data as described above.
8. Children
Screen Time Machine is not directed at children under 13, and we do not knowingly collect any information from anyone — including children. The app can, of course, be installed on a young person's device by a parent or guardian.
9. Security
Your data is held in the app's private storage area, protected by the operating system's own app sandboxing and by your device's lock screen and encryption. We keep no server-side database of your screen time, your tracked apps or your rules, so there is no such database to be breached. What does leave the device — anonymous analytics, purchase validation and any feedback you send — is sent over encrypted connections and held by the providers named in sections 2, 4 and 5.
10. Changes to this policy
If the app ever changes in a way that affects this policy — for example if a genuinely optional feature required sending something off-device — we will update this page and change the date above before that feature ships. Material changes will be surfaced in the app.
11. Contact
Questions about this policy: support@screen-time-machine.com. This policy is governed by the laws of France.