The Doommate mobile application (the “App” or the “Service”) is developed and operated by Levente Bokor, a private individual residing at Siófoki utca 7, 8621 Zamárdi, Somogy, Hungary (“we”, “us”, or “our”).
This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service. We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
By using the Service, you consent to our data practices as described below.
1. Lawful Basis and Transparency
We process personal data based on:
- Contract: To provide the Service (account management, synchronisation of your data across devices, and subscription entitlement).
- Consent: For device permissions you grant separately through iOS, namely Screen Time (Family Controls) access and notification delivery.
- Legitimate Interests: For product analytics used to improve the Service, balanced against your rights.
- Legal Obligation: To comply with applicable laws.
We inform you of data collection via this Privacy Policy, which is linked from the App’s Settings screen. Processing is fair, and is not detrimental, unexpected, or misleading.
2. Information We Collect
We minimise data collection for specific purposes. We collect the following information to provide and improve the Service.
a. Account Registration
Data: Sign in with Apple is the only authentication method offered. The App requests your name and email address from Apple and transmits the resulting Apple identity token to our authentication provider. Our authentication provider stores the Apple-issued account identifier, the email address contained in that token, and a user identifier it generates for your account. If you use Apple’s “Hide My Email” feature, the address we receive is an Apple relay address and we do not receive your actual address.
Purpose: Account creation, authentication, and restoring your data on a new device.
Legal Basis: Contract.
Note: The App does not read, display, or transmit your name or email address. It uses only the user identifier. Sign-in is not required to use the Service; if you do not complete sign-in, the App operates in offline mode and no data is transmitted to us.
b. Operation and Activity Data
Data: Where you are signed in, the following records are stored against your user identifier:
- Onboarding status: Which onboarding pages you have completed, whether onboarding is complete, and whether you have completed the first-run tutorial.
- Settings: Your daily summary time, and whether haptic feedback and directive reminders are enabled.
- Active operation: The randomly generated operation codename, the encoded Screen Time selection (see section 2c), a count summary of what is blocked, duration in days, intensity ratio and name, daily activity goal in minutes, daily free clearance allowance, start date, current clearance balances earned, spent and granted, and a per-day record of clearance earned and spent.
- Completed operations: Codename, outcome (completed or abandoned), grade, start and end dates, duration, days completed, days on which the goal was met, minutes of logged activity, clearance earned and spent, intensity ratio and name, a count summary of what was blocked, and a per-day record of goal attainment.
- Directive log: For each activity logged during the current operation, its name, icon identifier, duration in minutes, clearance earned, whether it was an instant directive, and the time it was logged.
- Custom directives: Activities you create, comprising the name you enter, the icon you select, the directive type, any bonus and cooldown values, the number of times logged, and the cooldown expiry. The name is free text supplied by you.
- Built-in directive state: For built-in activities you have used, an identifier for the activity, the number of times logged, and the cooldown expiry.
Purpose: To deliver the Service and to restore your data when you install the App on a new device or reinstall it.
Legal Basis: Contract.
c. Screen Time Selections
Data: When you select applications or categories to block, iOS presents its own system picker and returns opaque tokens. These tokens are references issued by iOS; they do not contain application names, bundle identifiers, or icons, and cannot be resolved to them by us. The encoded selection is stored on our servers so that your configuration is restored on a new device.
Purpose: To apply and restore the blocking configuration you chose.
Legal Basis: Contract.
Note: Because application names are not available to the App, the record of a blocked selection is stored as a count, for example 4 apps and 2 categories, and not as a list of applications. The App does not request or receive Screen Time usage reports, and therefore does not collect any measurement of how long you spend in any application. Where iOS supplies the identity of an application to the App’s shield extension in order to display a block screen, that information is compared against the App itself and is otherwise discarded; it is not stored or transmitted.
d. Behavioural Metrics
Data: Ten measures derived from the records in section 2b: completion rate, intensity preference, daily consistency, effort profile, grade trajectory, routine stability, abandon pattern, directive diversity, return velocity, and clearance spending. Each is stored only as a value from 1 to 4, together with its previous value and a pending transition indicator.
Purpose: To adapt the App’s in-app messaging to your usage.
Legal Basis: Contract.
Note: Each metric has a minimum-data threshold below which no value is produced or stored.
e. Analytics Data
Data: A fixed set of product events, each recorded with your user identifier and the time it occurred on your device:
| Event | Accompanying data |
|---|---|
| onboarding_page_view | The onboarding page reached. |
| onboarding_page_complete | The onboarding page completed. |
| reauth_completed | None. |
| activation_shown | Operation duration in days; number of targets selected. |
| activation_cta_tapped | None. |
| directive_logged | Directive name; whether instant; duration in minutes. |
| op_started | Intensity name and ratio; duration in days; daily goal; daily free clearance. |
| op_ended | Outcome; grade; days completed. |
| metric_bucket_changed | Metric identifier; previous and new value; direction of change. |
Purpose: To analyse onboarding completion and Service performance, and to improve the App.
Legal Basis: Legitimate interests.
Note: These events are stored in our own database. No third-party analytics software development kit is integrated into the App. Events are queued on your device, up to a maximum of 300, and transmitted when a connection and a signed-in session are available. Events generated during onboarding, before sign-in is complete, are transmitted under your user identifier once the account is created; if you do not sign in, they are never transmitted. Where a custom directive is logged, the directive_logged event includes the name you supplied for it.
f. Subscription Data
Data: Paid access is sold as an Apple in-app subscription. Payment is processed by Apple. Subscription state is managed by RevenueCat, to which the App transmits your user identifier so that entitlements follow your account rather than a single device. RevenueCat receives purchase and entitlement information from Apple.
Purpose: To determine and restore your access to paid features.
Legal Basis: Contract.
Note: We do not receive or store your payment card details, billing address, or Apple Account credentials. The App does not transmit your name, email address, or any record described in section 2b to RevenueCat, and does not enable RevenueCat’s device-identifier or advertising-attribution collection features.
g. Data Stored Only on Your Device
The following is retained locally by the App and is not transmitted to us:
- The name you enter during onboarding, used to address you within the App.
- The average daily screen time range you select during onboarding. This figure is self-reported by you and is used solely to calculate the projections shown on the diagnostics and activation screens. Only the fact that you completed the page is transmitted.
- A record of which in-app dialogue lines have been shown to you.
- A rolling 14-day record of directive names and times, used to calculate one behavioural metric.
- The blocking configuration and scheduled block expiry times, shared with the App’s extensions so that blocking continues when the App is not running.
- Reminder times and the notification preference switches not listed in section 2b.
- Your authentication session, held in the device keychain, and the queue of changes awaiting transmission.
h. Information We Do Not Collect
- We do not track you across apps and websites owned by other companies. The App does not request App Tracking Transparency permission, does not access your device’s advertising identifier (IDFA), and contains no advertising, attribution, or measurement software development kit.
- We do not use your data to target or measure advertising, and we do not share it with advertising networks. Should we introduce advertising measurement in the future, we will update this Policy before doing so.
- We do not collect Screen Time usage statistics, application usage duration, or the identity of applications you block or attempt to open.
- We do not collect location data, contacts, calendar data, health data, photographs, camera or microphone input, or motion data.
- We do not collect device identifiers, device model information, or IP-based location.
- We do not use cookies or any similar tracking technology.
- We do not operate push notifications. The App does not register for remote notifications and we hold no push token, so we cannot send messages to your device.
3. Purpose and Data Minimisation
We collect only data necessary for the declared purposes. Records that can be derived on your device are not stored on our servers. Screen Time selections are stored in the encoded form issued by iOS and are not resolved into application names. Behavioural metrics are stored only as bucketed values and not as the underlying calculations. We do not process data beyond the purposes stated in this Policy, and we do not process any of it for advertising.
4. Data Accuracy and Security
Accuracy: Your data is generated by your own use of the App and can be corrected or removed through the controls described in section 8. Contact [email protected] to correct inaccuracies.
Security: We implement technical and organisational measures to protect your data, including:
- Encryption of all traffic between the App and our servers in transit.
- Row-level security on every database table, so that a request authenticated as you can read and modify only records belonging to your user identifier. No unauthenticated access to any record is permitted.
- Server-side verification of your session before an account deletion request is executed.
- Storage of authentication tokens in the device keychain rather than in general application storage.
No system is fully secure, and we cannot guarantee absolute security.
5. Storage Limitation
We retain personal information as follows:
- Directive log entries are deleted from our servers whenever an operation is started or ended. Only the summary record of the completed operation is retained.
- The active operation record is deleted when the operation ends and is replaced by that summary record.
- Completed operations, custom directives, built-in directive state, behavioural metrics, settings, and onboarding status are retained until your account is deleted.
- Product events are retained until your account is deleted.
- Account records are retained until your account is deleted, unless longer retention is required for legal compliance or dispute resolution.
Data held only on your device, as described in section 2g, is removed when you delete the App.
6. Privacy by Design
We embed privacy by design through:
- Authentication limited to Sign in with Apple, with support for Apple’s email relay.
- A local-first architecture in which the Service is fully functional without an account and without a network connection.
- Storage of Screen Time selections in an opaque form that cannot be resolved to application identities by us.
- No collection of Screen Time usage measurement.
- Analytics limited to a fixed and enumerated set of events, recorded in our own database.
- Deletion controls available within the App that require no contact with us.
7. Controller–Processor Contracts
We maintain contracts with the following processors:
- Apple Inc.: Handles Sign in with Apple and processes subscription payments. Screen Time functionality is provided by the operating system under Apple’s control (see apple.com/legal/privacy).
- Supabase, Inc.: Provides authentication, database hosting, and the server-side function that performs account deletion. All records described in sections 2a, 2b, 2d and 2e are stored with this processor (see supabase.com/privacy).
- RevenueCat, Inc.: Processes subscription and entitlement state, receiving your user identifier and purchase information (see revenuecat.com/privacy).
Contracts stipulate processor responsibilities, security measures, and the return or deletion of data upon termination.
8. Data Subject Rights
You have the following rights:
- Informed: This Policy details our data practices.
- Access: Request a copy of your data.
- Rectification: Correct inaccurate data.
- Erasure: Delete your data.
- Restriction: Limit processing.
- Portability: Export data in a machine-readable format.
- Object: Oppose processing carried out on the basis of legitimate interests, including analytics.
- Automated Decisions: No decisions producing legal or similarly significant effects are made by automated means. The behavioural metrics described in section 2d affect only the wording of in-app messages.
- Withdraw Consent: Withdraw consent at any time where applicable, including by revoking Screen Time or notification permissions in iOS Settings.
The App provides the following controls in its Settings screen:
- Sign Out: Transmits any pending changes, then ends the session on that device only. Data held on the device is cleared; data on our servers is retained and is restored when you sign in again with the same Apple Account.
- Clear All Data: Deletes your operation history, directive log, custom directives, built-in directive state, behavioural metrics, and settings from both the device and our servers. Your account and previously transmitted product events are retained.
- Delete Account: Permanently deletes your account and all associated records, including product events, from our servers, and clears all data from the device. This action cannot be undone.
Subscriptions: Deleting your account does not cancel an Apple subscription. Subscriptions must be cancelled through Apple, either from the Manage Subscription screen in the App or in iOS Settings.
You may also exercise your rights by contacting [email protected]. We respond within one month, which may be extended where a request is complex. Requests may be refused where legally permitted, for example where identity cannot be verified.
9. Data Protection Inquiries
For data protection inquiries or supervisory authority interactions, contact us at [email protected].
10. International Data Transfers
Your data is stored with Supabase, Inc. on servers located in Ireland, within the European Union. If the hosting location changes, we will update this Policy. Where a third-party service processes data outside your jurisdiction, including transfers to the United States, we rely on appropriate safeguards such as Standard Contractual Clauses. Apple and RevenueCat process data in accordance with their own published privacy policies.
11. Data Breach Reporting
If a breach presents a risk to your rights and freedoms, we will notify the competent supervisory authority, the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), within 72 hours, and affected users without undue delay. Processors are required to notify us without delay.
12. How We Use Your Information
We process your information on the legal bases set out in section 1. Uses include:
- Service Delivery: Maintaining your account, applying and restoring your blocking configuration, recording operations and logged activity, calculating clearance balances, and determining subscription entitlement.
- Synchronisation: Mirroring the records in section 2b so that your data is restored on a new device or after reinstallation.
- Personalisation: Selecting in-app messages according to the behavioural metrics described in section 2d.
- Improvement: Analysing the product events described in section 2e to identify where onboarding is abandoned and how features are used.
- Communication: Reminders are generated and delivered locally by your device according to your settings. We cannot send you messages remotely.
- Compliance: Meeting legal requirements and preventing harm.
13. Sharing Your Information
We share information as follows:
- Apple Inc.: Processes Sign in with Apple and subscription payments.
- Supabase, Inc.: Hosts authentication and all server-stored records described in this Policy.
- RevenueCat, Inc.: Receives your user identifier and purchase and entitlement information.
- Legal Compliance: We may disclose data to comply with applicable law, respond to lawful requests from authorities, or protect our rights or the safety of others.
No Sale: We do not sell personal information as defined by the CCPA, and we do not share personal information for cross-context behavioural advertising. We do not disclose any personal information to advertising networks or data brokers.
14. Child Users
The Service is not directed at children under 13, and we do not knowingly collect their personal information. You must be at least 13 years old to use the Service. If we learn that a user is under 13, we will terminate the account and delete the associated data.
15. Updates to This Policy
We may update this Policy to reflect changes to the Service or legal requirements. Updates will be published at the address linked from the App’s Settings screen before taking effect, with in-app notice for material changes where required. Continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.
16. Contact
Levente Bokor is the data controller under GDPR.
Contact us at:
Levente Bokor
Siófoki utca 7
8621 Zamárdi
Somogy, Hungary
Email: [email protected]
For EU users, you may lodge a complaint with the NAIH (naih.hu) or with the supervisory authority of your country of residence. For UK users, you may contact the Information Commissioner’s Office at ico.org.uk. For California residents, you may contact the California Attorney General.
17. Additional Information for California Residents
Under the CCPA, California residents have specific rights:
- We collect the categories of personal information described in section 2, namely identifiers (a user identifier and an Apple account identifier), an email address held by our authentication provider, and internet or other electronic network activity information (the product events in section 2e and the usage records in section 2b).
- We do not sell your personal information and we do not share it for cross-context behavioural advertising.
- In the preceding 12 months, we have disclosed personal information for business purposes to the processors named in section 7.
- We do not collect or process sensitive personal information as defined by the CCPA.
- To exercise your CCPA rights, use the Delete Account control in the App or contact [email protected].
see also → Terms of Use