| Account identity | Can the core app-blocking flow start without email, phone number, social login, or a profile? | GrateGuard says no account is required for the core app experience. |
| Reflection text | Does personal journal or gratitude text leave the device, enter backups, or appear in analytics? | GrateGuard says gratitude entries stay on-device and are not included in optional analytics. |
| Protected apps | Are selected app names or per-app usage histories uploaded, sold, or used for advertising? | GrateGuard says protected-app choices stay on-device and it does not use advertising IDs for the optional coarse milestone flow. |
| System permission | Why is Screen Time or Accessibility access needed, and does the app explain the platform-specific difference? | GrateGuard documents Apple Screen Time controls on iPhone and local Accessibility-based app-open detection on Android. Apple Platform Security ↗ |
| Optional analytics | Is analytics off until consent, limited to coarse milestones, and reversible from settings? | GrateGuard describes optional consent for coarse lifecycle and feature-state signals and says consent can be withdrawn. |
| Purchases and deletion | Which store or subscription provider processes purchases, and can locally stored data be reset without contacting support? | GrateGuard separates store-managed purchase services from local habit data and provides an in-app local data reset. |