PhonePact
  • Home
  • Ethos
  • Studies
  • Contact
← Back to PhonePact

Legal

Privacy Policy

Last updated: 9 September 2026

The short version. PhonePact helps you use your phone less, with support from a small circle you choose. We keep the data we collect small and we never sell it. Duration is the only usage information in a shared check-in (for example, “reached 2h today”). A member and short phone label identify it, and a short note may be added deliberately, but your circles never see the apps you use, the websites you visit, or your browsing history. You can ask us to access or delete your data at any time.

This Privacy Policy explains how PhonePact LLC (“PhonePact,” “we,” “us,” or “our”) collects, uses, and shares information when you use the PhonePact mobile application (the “App”) and related services. We are the “data controller” (GDPR) and “business” (CCPA/CPRA) responsible for your information.

1. Information we collect

Information you give us

  • Your name and email address — to create and secure your account (via Firebase Authentication) and identify you to your circle.
  • Profile photo (if you add one) — shown to members of your circle as your avatar.
  • Your hand-drawn signature — saved to personalize your “Phone Pact.” We treat this as sensitive personal information and store it only for that purpose.
  • Your pact answers & goals — the intentions and settings you enter during onboarding, used to set up your pact and personalize the App.
  • Circle & membership data — the circles you create or join and who is in them.
  • Room messages — short messages you send in a circle’s room. Ordinary messages expire after 24 hours. Any current circle member can visibly choose Keep on a member-written message, which extends that message for everyone to no more than 30 days after it was sent. Reported copies follow the safety-retention rules below.
  • Private conversation messages — text you send one-to-one to a current member of a circle you share, including a pact discussion started through Talk first. Ordinary messages expire after 24 hours. Either participant can visibly choose Keep in chat, which extends that message to 30 days. Reported copies follow the safety-retention rules below.

Screen-usage information

With your permission, PhonePact uses the screen-usage system provided by your phone. On iPhone, Apple’s Screen Time / Family Controls / Device Activity features count the scope you select during setup; that may be the whole device or selected apps, categories, and websites. On Android, PhonePact uses Usage Access and lets you choose the whole phone or individual launchable apps in a private on-device picker. Home can show you a private “Where it went” summary of up to five selected apps used for at least one minute today. Android can also show your aggregate total and pact progress in an optional home-screen widget and, on supported phones, a private live status display. PhonePact does not send app or package identities, exact per-app details, websites, or browsing history to our servers or your circle. Those details stay on your device. Coarse duration check-ins (for example, “Hank’s iPhone reached 2h today”) go to your circle when a threshold is recorded. If you use PhonePact on more than one phone, each phone has its own pact and up to seven recent recorded days of aggregate totals in its own private device record in our Firebase backend. Circle members cannot read those totals.

Supporter insights

Optional monthly and one-time PhonePact Supporter purchases unlock Deeper Insights in You → Insights. The updated supporter edition includes daily and weekly views, time-of-day patterns, private app details, and a pact journal. Available measurements depend on your phone, software version, permissions, and recorded history. Missing days are not treated as zero; comparisons use matching complete recorded days rather than assuming unavailable history.

On iPhone, app and category time, pickups, sessions, notification counts, and website domains when supplied by Apple are displayed inside Apple’s protected Screen Time report. PhonePact does not export those detailed report values to its main app or servers. On Android, after you choose to enable private summaries, PhonePact derives usage, app visits, unlocks, sessions, app switches, and screen-off breaks from on-device Android events. Those detailed summaries stay in private files excluded from Android backup. These metrics describe recorded activity, not physical intent, focus, or sleep.

Android notification counts require a separate, optional choice and Android’s notification access permission. We count notifications by app without reading or storing their text, titles, or senders. Updates, group summaries, and ongoing status notifications are excluded; counts may have gaps when permission or the counting service is unavailable. You can turn counts off and clear them inside Insights, or turn off private usage summaries and clear their files.

The private pact journal records settings received and crossings recorded on this phone. It is not a complete approval or delivery history. Deeper Insights do not analyze messages, use AI, rank members, or send app details or reports to circles, RevenueCat, or analytics services. They do not establish why your usage changed. Viewing all screen time is separate from changing what counts toward your pact.

Information collected automatically

  • Push notification token — via Firebase Cloud Messaging, so we can send remote circle, pact-request, private-conversation, and shared-check-in notices. Private-conversation notifications identify the sender but do not include the message text. Private notices and Moment prompts are scheduled locally on your phone and do not use this token.
  • Diagnostics & crash data — via Firebase Crashlytics, to find and fix bugs. This may include device model, operating-system version, and technical details about a crash.
  • Basic device & log data — such as app version and general device information used to operate and secure the service. PhonePact also creates a random installation identifier and a short label such as “iPhone A1B2” so two phones on one account keep separate pacts and histories. This is not a hardware serial number, advertising identifier, or device fingerprint.

Purchases

PhonePact offers optional Supporter purchases that help fund the core service and unlock personal insights. Purchases are sold through the applicable app store and managed using RevenueCat. The store processes your payment; we do not see or store your credit-card or payment details. PhonePact and RevenueCat process an account-linked purchase identifier, product and transaction records, purchase dates, subscription or entitlement status, and relevant app/device information to validate purchases, restore access, handle billing support, and understand supporter purchases. Screen-usage totals, pact history, insights, messages, and app-selection details are not sent to RevenueCat. PhonePact's core service remains free.

2. How we use your information

  • To provide, operate, and maintain the App and your pact.
  • To show your private recent usage history and, when unlocked, provide the supporter insights described above.
  • To validate and restore supporter access and provide billing support.
  • To enable your circle features — check-ins, rooms, one-to-one private conversations, and change requests.
  • To send remote circle and pact notices, and to schedule the private notices you turn on locally.
  • To keep the service secure and prevent abuse.
  • To diagnose problems and improve the App.
  • To comply with law and enforce our Terms of Use.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. PhonePact contains no advertising SDKs and does not track you across other companies’ apps or websites.

Legal bases (for EU/UK users)

  • Performance of a contract — to give you the App and features you sign up for.
  • Consent — for screen-usage access, notifications, and the optional Android timing, live-status, and Do Not Disturb exceptions you choose (you can withdraw these in your device settings at any time).
  • Legitimate interests — to secure, maintain, and improve the service.
  • Legal obligation — where we must retain or disclose data by law.

3. How we share information

  • With your circle — your name, avatar, each registered phone’s short label and pact point, coarse duration check-ins attributed to the phone that measured them, and any room messages you send are visible to members of the circle you choose. PhonePact does not share a live presence signal.
  • With a private-conversation participant — a one-to-one message and its pact context, if any, are visible only to you and the current shared-circle member in that conversation. Other members of either circle cannot read it.
  • With service providers — Google (Firebase Authentication, Cloud Firestore, Cloud Messaging, and Crashlytics) processes data on our behalf as a “data processor.” Apple provides Sign in with Apple and Screen Time. Apple or Google Play processes supporter payments, and RevenueCat processes the purchase-related information described above. See Firebase’s privacy information, Apple’s Privacy Policy, Google’s Privacy Policy, and RevenueCat’s Privacy Policy.
  • For legal reasons — if required by law, or to protect the rights, safety, or property of our users or us.
  • Business transfers — if we are involved in a merger, acquisition, or sale of assets, your information may be transferred, subject to this Policy.

4. Data retention

  • Private aggregate usage history on our servers — up to seven recent recorded days per phone. Older entries are removed as newer days replace them; this is a limited number of records, not a promise that an inactive phone’s records disappear after seven calendar days. Server-side device histories are deleted with your account. Deeper Insights does not extend this server history.
  • Private on-device insights — In the updated tester edition, Android usage summaries can accumulate up to 365 days on this phone after you choose to enable them. Older editions retain up to 28 days; expanding retention requires a fresh choice in the app. Missing history cannot always be recovered from Android. Optional notification counts still cover a rolling 28-day window. Older entries are pruned when Insights next runs or records new data; files on an inactive phone cannot be removed until the app runs again. Turning off private summaries clears these files and stops that optional collection. Signing out clears them as well. iPhone’s detailed report history is supplied and retained by Apple, not copied into a PhonePact history store. The local pact journal on both platforms is limited to 28 recent days and 300 entries, prunes on access, and clears at sign-out. Subscription expiry closes access to paid reports; it does not itself delete history or revoke device permissions.
  • Source check-in events — coarse duration events used to operate shared check-ins are retained until account deletion, separately from the short-lived messages displayed in the Room. They do not contain app identities or exact per-app usage and are not a complete daily usage history.
  • Room messages — ordinary rows expire after 24 hours. A member-written message visibly kept by at least one current circle member expires no later than 30 days after it was sent; releasing the last Keep restores its ordinary expiry without reviving an already expired message. Deleting your account immediately deletes room notes and check-in rows attributed to you, and scrubs reply excerpts, reactions, Keep attribution, and names tied to those rows.
  • Private conversations — ordinary messages expire after 24 hours. A message visibly kept by either participant expires 30 days after it was sent. Empty conversation records are later removed. Deleting either participant’s account immediately deletes the entire private conversation and its messages.
  • Reported messages — if someone reports a message, a copy of that message is kept with the report so we can review it. This copy does not disappear after 24 hours, because a report we cannot read is a report we cannot act on. It is deleted 90 days after we finish reviewing it. A report that is still open is kept until it has been looked at. If the reported author deletes their account, their copied text is scrubbed from the retained report.
  • Reports you make — deleted when you delete your account.
  • Reports about you — kept as safety records, but your account identifier is replaced with an anonymous value and copied text attributed to you is scrubbed when you delete your account. This is deliberate: otherwise deleting an account would erase the existence of complaints made about it.
  • Account & profile data (name, email, photo, signature, pact settings, circles) — kept while your account is active, and deleted when you delete your account, subject to any short backup or legal-retention period.
  • Diagnostics — retained by Crashlytics for a limited period per Google’s defaults.
  • Purchase records — supporter purchase records may remain after account deletion for transaction, refund, fraud-prevention, or legal requirements. The applicable store and RevenueCat may retain records under their policies and obligations. Deleting a PhonePact account does not erase store transaction records or cancel a subscription.

5. Your choices and rights

  • Access, correct, or delete your personal information.
  • Delete your account from within the App, under You → Your Profile → Delete account. Account data, private conversations, ordinary room notes and check-in rows attributed to you, and reports you filed are deleted. Reply excerpts, reaction attributions, and block-list references tied to your account are scrubbed. Reports about you may be retained as anonymized safety records, with copied text attributed to you scrubbed. You can also email us to request deletion.
  • Turn off screen-usage access, notifications, exact-alarm access, live-status display, or PhonePact’s optional Do Not Disturb exception in your phone settings at any time.

Turning off screen-usage permission stops new measurement; it does not by itself delete previously saved history. Use the access or deletion options above for that history. If subscriptions are introduced, canceling one will stop its renewal under the store’s terms; it will not itself delete your account or history. Deleting your account or uninstalling the App will not itself cancel a store subscription.

EU/UK (GDPR): you also have the right to portability, to object to or restrict processing, to withdraw consent, and to lodge a complaint with your local data-protection authority.

California (CCPA/CPRA): you have the right to know, access, correct, and delete your personal information, to opt out of “sale”/“sharing” (we do neither), to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.

To exercise any right, email support@getphonepact.com. We will respond within the time required by applicable law.

6. Children’s privacy

PhonePact is intended for people 13 years of age and older, and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact support@getphonepact.com and we will delete it.

7. Security

We use reasonable technical and organizational measures to protect your information, including encryption in transit and access controls on our Firebase backend. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

8. International users

We are based in the United States and process data in the United States. If you use PhonePact from outside the U.S., you understand your information will be transferred to and processed in the U.S., where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.

9. Changes to this Policy

We may update this Policy from time to time. We will post the new version here and update the “Last updated” date, and, for material changes, provide additional notice in the App.

10. Our website and testing signups

This Policy also covers getphonepact.com. If you previously joined Android testing or our launch waitlist, or send feedback on the website, we collect the email address you submit (and, only if you opt in to SMS updates, your mobile number and consent) along with any message you send. These submissions are processed on our behalf by Google Apps Script, which records them to a Google Sheet; if your browser has JavaScript disabled, or if the primary submission cannot be confirmed and you choose the displayed backup form, Formspree processes that submission instead. Google Fonts may receive basic request information when your browser loads the site’s fonts. We use this only to manage Android testing and prior waitlist records, send updates you asked for, and respond to you — never for advertising, and we never sell it. You can unsubscribe from emails at any time, and reply STOP to opt out of SMS. To access or delete anything you submitted on the website, email support@getphonepact.com.

11. Contact us

PhonePact LLC
Email: support@getphonepact.com

© 2026 PhonePact LLC. All rights reserved.

Privacy Policy · Terms of Use · Support · Questions: support@getphonepact.com.