Privacy Policy
The short version. ScreenSitter stores the least it can: who the grown-ups are, your children’s first names, the rules you set, and how many minutes each set of apps was used per day. It never sees which apps your child actually opened or for how long, never reads their messages, and never asks for anyone’s location. There is no advertising, no analytics and no third-party tracking.
And the part most parents ask about first: which apps your child uses never leaves their device — not as names, not as times. Details in what the device sends about apps.
Who we are
ScreenSitter is made by PhiSeC Ltd, a company registered in the United Kingdom. We are the data controller for the information described here. You can reach us at [email protected].
Where the work actually happens
Limits are enforced on your child’s device by Apple’s Screen Time frameworks (Family Controls, Device Activity and Managed Settings). The device holds its own copy of the rules and keeps them running with no signal and with no app open. Our server’s job is to carry your decisions between the grown-ups’ phones and the child’s device — not to watch anybody.
What we store, and why
- Grown-ups’ accounts
- An email address and display name, plus what the children call you (“Mum”, “Dad”) so their device can say “15m from Mum”. If you sign in with a password we store only an Argon2 hash of it, never the password. If you use Sign in with Apple we store the identifier Apple gives us and the address it passes on — which is all we ever hold if you chose Apple’s private relay.
- Your household
- A household name, invitation codes for adding a second grown-up, and the household PIN — kept as a one-way hash, never as digits. That hash is also sent to your child’s device so the PIN can be checked when there’s no signal. It is a convenience PIN for the family, not a password: please don’t reuse one that guards anything else.
- Your children
- A first name (or nickname — anything you like), a time zone, and optionally the first name Apple shows for them in Screen Time, so the on-device report can be matched to the right child. We never ask for surnames, ages, birthdays, schools or photographs.
- The rules you set
- Hours, daily allowances, per-day exceptions, app-set names, party modes and locks — with which grown-up set them and when.
- Minutes used
- One number per app set per day: how many minutes that set was used. Totals only. No app-by-app breakdown, no timestamps, no sessions.
- Requests and decisions
- When a child asks for more time: the minutes asked for and the short reason they typed, if they typed one (up to 500 characters). Then what was decided, by whom, and when. Time added on the child’s own device with the household PIN is recorded without a name, and shown as “via PIN”.
- The activity log
- Locks, unlocks, party mode starting and ending, and the fact that the household PIN was entered on a child’s device. Each entry has a time and, where there is one, the grown-up responsible.
- Devices
- For each paired iPhone or iPad: whether it is a grown-up’s or a child’s, its Apple push notification token, when it was paired and when we last heard from it. Pairing codes are short-lived and single-use.
- Sessions
- A random sign-in token per device. We store only a hash of it, and it expires.
We hold all of this to provide the service you asked for, and — for sign-in throttling and pairing-code protection — to keep the household secure.
What the device sends about apps
This is the part most policies fudge, so here it is in full.
- The app selection itself is opaque. When a grown-up picks apps on the child’s device, Apple hands the app a sealed token for each choice. We store that selection as Apple encoded it, so the device can restore its own rules and both grown-ups’ apps stay in step. Those tokens mean nothing outside that device: we cannot turn them back into app names, and neither can anyone else.
- App names stay on the device too. When ScreenSitter’s block screen appears, iOS tells the app which app it is covering — and that name is used right there, on the child’s device, and goes no further. (If your child asks for more time from a blocked app, the ask they send can say which app it came from — that single name travels inside their request, and only because they sent one.)
- The per-app breakdown never leaves the device. The “where the time went” screen is drawn by Apple’s own component inside the app, from data Apple only makes available on the device. None of it is sent to us, and we could not ask for it if we wanted to.
What never reaches us
- Which apps your child has installed, opened, or was blocked from — no names, no times
- Location, at any time — the app never requests it
- Messages, photos, contacts, calls or browsing history
- Screenshots or recordings of anybody’s screen
- Advertising identifiers — there is no advertising in ScreenSitter
- Analytics or crash-reporting from third parties — we don’t use any
Children’s data
Children never create an account. A grown-up sets everything up and decides what to enter, and we deliberately need very little: a name to show on their screen and a paired device. We do not build profiles of children, do not target them with anything, do not advertise to them, and do not share their information with anyone. The app is free and contains nothing to buy.
Who else touches it
Nobody, beyond the suppliers that run the service for us under contract:
- Vercel — runs our API, in its London region. Like any host, it keeps short-lived request logs.
- Supabase — hosts the database. Only our own server can read it; the automatic public data API is disabled and access is revoked at the database level.
- Apple — delivers push notifications, and handles Sign in with Apple if you use it.
We do not sell data, do not share it for advertising, and do not use it to train anything.
Keeping it safe
Everything travels over HTTPS. Passwords are Argon2-hashed, sign-in tokens are stored only as hashes, and the household PIN never leaves your devices in the clear. Repeated sign-in and pairing attempts are rate-limited; your device’s IP address is used in memory for that and is not stored in our database.
How long we keep it
Your household’s history — usage totals, grants, requests and the activity log — is kept while the household exists, so you can look back over past weeks. We do not currently delete old entries automatically. If you would like a shorter retention period for your household, ask us and we will do it.
Deleting things
- A child. Deleting a child in the app removes their name, schedules, app sets, usage totals, requests, grants and history, and unpairs their device. It happens immediately and cannot be undone.
- A grown-up. Removing another grown-up deletes their account and ends their sessions at once. Their past actions stay in the log, but stop being attributed to them.
- Everything. In the app, under Settings, choose Delete my account. If you are the only grown-up, this deletes the whole household at once — every child, their schedules, usage totals and history — and it cannot be undone. If another grown-up remains, only your account is removed and the household carries on without you. Prefer email? Write to [email protected] from your registered address and we will do it within 30 days.
Your rights
Under UK GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email us and we will reply within one month. If you are unhappy with our answer you can complain to the Information Commissioner’s Office (ico.org.uk).
Changes
If anything here changes materially we will update this page, change the date at the top, and flag it in the app. We will not start collecting something new without saying so first.
Something here not matching what you see in the app? Tell us — that is a bug in one of the two, and we would like to fix it: [email protected].