Privacy policy
Last updated 2 August 2026.
True2You is a self-managed screen-time app with an optional shared-status feature that two people turn on together. This policy explains what we collect, why, who processes it, and how you delete it. It is written to be read, not to be survived.
The short version
- No analytics or advertising SDKs. Ever. There is no tracker, no advertising identifier and no third-party analytics in the app.
- We never learn which apps are on your phone. The app checks that on-device to decide what to block, and the result never leaves the device.
- We do not keep an activity log. There is no browsing history, no record of which sites were blocked, and no timeline either person can page through.
- The shared status is symmetric. Both people see the same kind of summary about each other. There is no one-way view and no hidden mode.
- You can delete everything without opening the app at true2you.app/delete.
What we collect, and why
We collect the minimum needed to sign you in, to protect your devices, and to keep the shared status honest. Every purpose below is one of: making the app work, managing your account, or preventing fraud and abuse. Never analytics, never advertising, never personalisation.
| What | Why | Required? |
|---|---|---|
| Email address | Signing you in, and sending the one-time code that confirms account deletion. | Required |
| Display name | Shown to the person you are paired with, so they see a name rather than an identifier. You choose it, and you can leave it blank. | Optional |
| Account and device identifiers | Telling your enrolled devices apart, addressing a notification to one of them, and detecting tampering. Includes a per-device hardware-backed identity and a push token. | Required |
| Protection status and regular check-ins | The shared status itself: whether protection is on, and a periodic check-in so a device that goes dark is noticed. This is a current state, not a history. | Required |
| Consent records | Proof that both people agreed to pair, and to any later change. This is what makes the feature consensual rather than imposed. | Required |
| Subscription entitlement | Whether your account is entitled to the paid features. We never receive your card or payment details — the app store handles payment. | Required if you subscribe |
What we never collect
- Location. Approximate or precise. The product has no location feature.
- Which apps are installed on your phone. The app needs to know this to decide what to block, so it checks on the device. The answer is never transmitted to us and never reaches the person you are paired with. This matters: what someone has installed can imply things about them that are nobody else's business.
- Browsing history. The DNS filter decides on the device. Blocked-domain events are not stored and not transmitted.
- Messages, photos, video, audio, files, calendar or contacts. There is no messaging feature, and pairing uses an invite code rather than reading your contacts.
- Health or fitness data, a phone number, a postal address, or any special-category information such as race, beliefs or sexual orientation.
What the person you are paired with can see
A summary, and only a summary: whether protection is currently on, whether your devices are checking in, and whether you have declared a planned offline period. They do not see which apps or sites were blocked, when, or how often — because we do not keep that. Both of you see the same kind of information about each other.
Either person can end the pairing at any time without the other's approval. When a pairing ends — by dissolving it, by deleting an account, or by turning protection off — the other person is told promptly. They are told that it happened, not why, not where you are, and nothing about your reasons. We are explicit about this because a feature that let one person leave silently would be a feature that let the other be deceived, and a feature that let one person block the other from leaving would be worse than either.
Who else processes your data
These companies process data on our behalf, under contract, for the purposes below. They are service providers, not recipients who may use your data for their own purposes. We do not sell your data, and we do not share it for advertising.
| Provider | What they do for us |
|---|---|
| Google (Firebase Authentication and Firebase Cloud Messaging) | Verifies your sign-in and delivers notifications to your Android devices. Firebase Analytics is not included in the app and is explicitly switched off. Firebase generates a per-installation identifier so it can address notifications; we never read or store it, and it resets if you uninstall or clear app data. |
| Apple (Apple Push Notification service) | Delivers notifications to your Apple devices. |
| RevenueCat | Manages subscription entitlement. It receives an opaque account identifier only — never your email address or your name. |
| Microsoft Azure | Hosts our servers and stores our data. |
Where your data is stored
Our servers and storage are hosted in the United States (Azure, East US). If you are outside the United States, your data is transferred there and processed under our provider's standard contractual protections for international transfers.
How it is protected
- All traffic between the app and our servers is encrypted in transit. There are no cleartext endpoints.
- Each device holds its own hardware-backed key. Check-ins are signed by that key, so a check-in cannot be forged or replayed by something that is not the enrolled device.
- Our observability and error reporting deliberately exclude user-identifying content — we keep our servers healthy without reading your data to do it.
Deleting your data
You can delete your account from inside the app, or from true2you.app/delete without unlocking your phone or opening the app. Deleting ends any pairing, removes every device you enrolled, and purges your identity and your consent records.
One thing is kept: a pseudonymised record that consent once existed. It holds a one-way identifier and timestamps — no name, no email, no content, and nothing about what you did. It is stored apart from everything the deletion purges, as a single current row that is overwritten rather than appended to, so it can never become a usage or activity record. We keep it only so we can prove, if we are ever required to, that consent was properly given for a feature that affects two people. Records we are required by law to keep, such as billing records, are kept for as long as that law requires.
Deleting your account does not cancel a subscription or issue a refund. Manage or cancel a subscription through the store you bought it from.
Your rights
Depending on where you live, you may have the right to access the data we hold about you, to correct it, to delete it, to object to or restrict how we use it, and to receive a copy of it. You can exercise deletion yourself at any time using the link above. For anything else, contact us and we will respond. You also have the right to complain to your local data protection authority.
Children
True2You is not directed at children and is not a Families-policy app. It is intended for adults who choose to use it together. We do not knowingly collect data from children.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how we handle data you have already given us, we will tell you in the app before it takes effect.
Contacting us
Email earlylightlabs@gmail.com with any privacy question or request.