Scrollmates helps two people hold each other to a shared screen-time contract. This policy explains exactly what the app stores, where it stores it, and what we can and cannot see. It covers the Scrollmates iOS app and the Scrollmates backend service, both operated by the developer of Scrollmates.
The short version
Scrollmates has no analytics SDKs, no advertising SDKs, and no third-party trackers. We do not sell, rent, or trade your data, and we do not profile you for ads.
In solo mode nothing about your screen time leaves your iPhone, and until you first pair there is no account of yours on our side at all. Bonding with a partner is the only thing that turns that networking on, and even then the app uploads minutes and events — never the names of the apps you chose, and never anything you did inside them.
Solo mode: your screen time stays on your device
Solo mode is the default, and it is entirely local. Your schedules, your daily pool state, your local profile, your block-list selection and its lock-in state, and your time zone are written to a private App Group container on your device, readable only by Scrollmates and its own Screen Time extensions.
While you are solo, none of it is sent anywhere. That is enforced in code by a fail-closed network gate rather than left to good intentions: with no bond, a request is refused before it is sent.
Solo mode does not create an account. If you never pair with anyone, we never receive anything about you, because there is nothing on our side to receive it.
Once you have an account — because you paired at some point, even if that bond has since ended — a solo device still speaks to us for a short list of account-level things, and only those: reading your own account and whether a bond still exists, reading your own record of past bonds so the app can explain a bond that ended overnight, handing your push token back so we stop reaching your phone, sending Apple's signed subscription receipt, and deleting your account. None of them carries a minute, an event, or an app you selected. Uploading your usage is not on the list, and stays off it until you are bonded again.
Screen Time data stays with Apple
Scrollmates enforces limits through Apple's Family Controls and DeviceActivity frameworks. When you choose which apps and categories to limit, iOS hands the app an opaque token for each selection — not a name, not a bundle identifier, not an icon.
This is a technical boundary, not a promise of restraint. The app cannot turn those tokens back into app names, cannot read your browsing history, cannot see notification or message content, and cannot see anything you type or view inside another app. Neither can our servers, because the tokens never leave your device.
What we store once you bond
Bonding is opt-in: you have to sign in and pair with a partner before any of this exists. Once you do, the Scrollmates backend stores:
- • Account. An account created through Sign in with Apple or Sign in with Google. We receive the identifier your provider gives us and, if you allow it, your name and email address. We never receive your password.
- • Profile. Your display name, avatar emoji, and accent color.
- • Bond details. Your bond's moniker, the partnership type, and the shared vision you and your partner chose.
- • Contract settings. Your daily pool size, pacing thresholds, reset time, focus schedules, and the bond's time zone.
- • Usage aggregates. Per-day totals in minutes, plus individual events recording a duration and an event type.
- • Block-list summary. How many items are in your block list, and an opaque hash of the selection — enough to tell you and your partner that the list changed, never the list itself.
- • Push token. An Apple Push Notification service device token, so your partner's actions can reach your phone.
- • Subscription status. Apple's original transaction identifier, the product identifier, and the expiry date for your bond's subscription.
What we never see
We never see which apps or websites you selected. We never see app names, bundle identifiers, URLs, page titles, search terms, keystrokes, screenshots, message content, contacts, photos, precise location, or anything else from inside the apps you use.
Usage reaches our servers as durations and event types only. "38 minutes" is the whole of it — there is no field in which an app name could travel.
We never see your payment details. Subscriptions are purchased and billed entirely by Apple; we only learn that a subscription exists, which product it is, and when it expires.
How we use it
We use the data above to run the features you turned on, and for nothing else:
- • To compute your shared daily pool and keep both phones showing the same numbers.
- • To show you and your partner each other's usage totals and bond events — see "Shared with your partner" below.
- • To send the push notifications the app depends on to stay in sync.
- • To determine whether your bond is inside its free trial, subscribed, or lapsed.
- • To keep the service working and secure — for example rate limiting, and error logs that record a request identifier rather than your content.
We do not use your data to train machine-learning models, to build advertising profiles, or to market other products to you.
Shared with your partner
By design, your bonded partner can see your daily usage totals, your share of the pool, your bond events such as a broken contract, and your profile. That mutual visibility is the product, not a side effect. If you do not want someone seeing those numbers, do not bond with them.
Your partner still cannot see which apps you chose or what you did in them. Nobody can — see "What we never see" above.
Shared with anyone else
Nobody. We do not share your data with advertisers, data brokers, or analytics vendors, and we do not sell it.
Two Apple services sit in the path because the app cannot work without them: the App Store handles purchases and billing, and Apple Push Notification service delivers pushes. Both are Apple's, governed by Apple's own privacy policy, and neither receives your usage data from us.
We may disclose data if the law requires it. If that ever happens we will tell you, unless we are legally prevented from doing so.
How long we keep it
While you are bonded, we keep the data described above so that the bond can function.
When a bond is broken, collection stops immediately — the network gate shuts on both phones — and your account is scheduled for deletion 30 days later. The delay exists so an accidental or temporary break is recoverable: pairing again within those 30 days cancels the deletion. If you do nothing, the account and its data are deleted when the window closes.
An ended bond is deleted after 30 days, however it ended — broken on purpose, lapsed, or ended because somebody stayed signed out. For those 30 days the bond is kept so that pairing with the same person restores it: the shared pool history, the Journal and the settings come back, while the level and the streak start again from zero. After that, everything belonging to it is permanently deleted: the shared pool, the daily records, the Journal history and the quest progress. The only thing that survives is a summary of the bond — its final level and title, its best streak, the total time you focused, and the dates it ran between — which is kept for the person it belonged to and is deleted with the account.
Nothing outlives a deleted account. There is no record we keep about you afterwards — not even an anonymous one. The free trial is Apple's introductory offer: Apple grants one per Apple Account, decides who is eligible, and tracks it on their side, so there is nothing about it for us to remember. When your data goes, it goes.
When you use Delete Account, your server-side data is deleted immediately and the app wipes its App Group container on your device. There is no grace period and no undo.
Routine server backups and error logs may hold incidental copies for a short period before they age out.
Your choices
Stay solo. Do not pair, and nothing ever reaches us.
Break the bond. Collection stops the moment the bond ends.
Delete your account. Settings → Delete account removes your server-side data immediately and wipes local state.
Remove the app. Deleting Scrollmates from your iPhone removes its local App Group container with it.
Ask us. Write to privacy@scrollmates.app for a copy of the data held against your account, a correction, or a deletion you cannot perform in the app. We will respond within 30 days.
Depending on where you live, you may have further rights over your personal data — access, correction, deletion, portability, or objection among them. The same address reaches us for all of them.
Children
Scrollmates is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, write to privacy@scrollmates.app and we will delete it.
Changes to this policy
If we change what we collect or what we do with it, we will update this document and move the "Last updated" date shown above. Material changes will be surfaced in the app rather than left for you to find.
Contact
Questions about privacy, or a request about your data: privacy@scrollmates.app.