GrateGuard Privacy Policy

This Privacy Policy explains how GrateGuard ("we", "us", or "our") handles information when you use the GrateGuard mobile app and website.

What GrateGuard Does

GrateGuard helps you place a short gratitude ritual before selected distracting apps. You can choose protected apps, set a lock window, and complete three gratitude entries to unlock a session.

Data Stored On Your Device

The app is designed to work locally. The following information is stored on your device:

Your operating system may include this local data in an encrypted device backup or device-to-device transfer if you enable those system features. GrateGuard does not operate or receive those backups.

Voice Input

If you use voice mode, GrateGuard asks for microphone and speech-recognition permission. Voice starts only when the operating system confirms that on-device recognition is available; on Android, the selected offline language model must also be installed. GrateGuard does not store or upload the recording, and it does not allow the speech-recognition library to fall back to network recognition. If offline recognition is unavailable, voice stays disabled and text entry remains available.

Sharing A Progress Card

If you choose Share progress card, GrateGuard generates a temporary image on your device and opens the operating system share sheet. The card contains coarse progress totals and an invitation code, never your gratitude text. GrateGuard does not browse, collect, or upload photos from your library. The temporary card is handled locally and is shared only with the destination you select.

Notifications

If you enable reminders, the app schedules local notifications on your device. You can disable reminders in the app settings or through your operating system.

App-Lock Permissions

On supported devices, GrateGuard may ask for Screen Time or Accessibility permissions to apply local app restrictions. These permissions are used to detect or restrict selected protected apps on your device. GrateGuard does not upload your selected apps or the identity of foreground apps. Coarse permission and gratitude-gate milestones described below never identify which app was involved.

No Accounts, Ad Tracking, Or Sale Of Data

GrateGuard does not require an account, does not use advertising identifiers or cross-app tracking, and does not sell personal data. We do not use your gratitude entries, speech, or protected-app choices for advertising or profiling.

Purchase Analytics And Optional Product Analytics

RevenueCat assigns a random app user ID and automatically records hosted-paywall presentation events and purchase status when GrateGuard loads or shows its optional Plus purchase flow. This supports offer delivery, entitlement access, purchase restoration, and measurement of the purchase flow. These events do not contain gratitude text, speech content, protected-app names, contacts, or advertising identifiers.

Separately, GrateGuard asks you to allow or decline its optional product analytics. If you explicitly allow it, GrateGuard attaches additional coarse product milestones to the same random RevenueCat app user ID. These can include onboarding completion, permission state, successful gratitude-gate count ranges, paywall-view count ranges, trial or purchase status, whether a review was requested or a share sheet was opened, an allowlisted acquisition or referral source, coarse reminder prompt, enablement, and open-count state, and UTC calendar-day buckets for first open, onboarding, permission, first or latest successful protected reset, later-day app return, a retained reset, and first successful reminder enablement. Reminder time and notification content are not sent. Because repeated milestones are associated with a stable random ID, we describe this data as pseudonymous rather than anonymous.

These milestones never include gratitude text, speech content, the names or identifiers of protected apps, contacts, advertising identifiers, or data used to follow you across other apps and websites. They are used only to improve activation, reliability, and purchase presentation.

You can withdraw analytics consent at any time in Settings. GrateGuard then stops sending optional milestones and requests deletion of its custom analytics attributes from the RevenueCat record. RevenueCat may still process purchase history, entitlement state, and hosted-paywall presentation events needed to operate and measure the optional purchase flow. Reset Local Data also clears local analytics consent, attribution, referral identifiers, reminders, saved app restrictions, and gratitude history. Purchase records that Apple, Google, or RevenueCat must retain for transaction validation, restoration, fraud prevention, or legal compliance are not deleted by that local reset.

Purchases

If you buy a subscription or lifetime purchase in the app, Apple or Google Play processes the payment depending on where you installed the app. GrateGuard uses RevenueCat to present purchase options, manage purchase status, and provide GrateGuard Plus access. RevenueCat may process hosted-paywall presentation events, purchase history, product identifiers, transaction identifiers, entitlement status, consented coarse product attributes, acquisition or referral source, and a random app user identifier so offers can be shown, purchases validated and restored, and the purchase flow measured.

We do not connect RevenueCat's pseudonymous app user identifier to a GrateGuard account because GrateGuard does not require an account.

You can read more in RevenueCat's Privacy Policy.

Website And Support

The GrateGuard website does not run an analytics or advertising script and does not set analytics cookies, use local storage for visitor profiling, or fingerprint your browser. The website host may process standard logs such as IP address, browser information, requested URL, timestamp, and referrer for security and operation.

Download links contain a short campaign label and may select a matching custom store page. Apple and Google may process that label after you continue to their store under their own privacy policies. The label does not contain gratitude text, protected-app choices, or an advertising identifier.

An invitation URL may contain a pseudonymous referral code. Your browser uses it to open the installed app or pass it to the selected app store; the static website does not save it in a cookie or visitor profile. Because the code is part of the requested URL, it may also appear in standard hosting logs. If you contact us by email, we process the information you send so we can respond to your request.

Retention And Deletion

Local app data remains in the app's local storage until you delete it, reset local data in the app, or uninstall the app, subject to any operating-system backup copies you control. Consented pseudonymous product-milestone attributes remain with RevenueCat until they are replaced, consent is withdrawn and deletion is requested, or RevenueCat removes them under its retention rules. Purchase records are retained according to the app stores' and RevenueCat's service and legal requirements. Website security logs and support emails are retained only as long as reasonably needed for operation, security, or answering and documenting the request.

Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data. Because most app data is stored locally on your own device, you can usually manage it directly in the app.

For a request concerning RevenueCat's pseudonymous service record, include the selectable Pseudonymous support ID shown in GrateGuard Settings. This lets support locate the correct record without requiring an account, name, or advertising identifier.

Contact

For privacy questions or data requests, contact: hello@grateguard.app.