Scrollmates helps two people hold each other to a shared screen-time contract. This policy explains exactly what the app stores, where it stores it, and what we can and cannot see. It covers the Scrollmates iOS app and the Scrollmates backend service, both operated by INNOV8 VENTURES COMPANY LIMITED, Yangon, Myanmar, and the scrollmates.app website, which sets no cookies, loads nothing from anyone else, and runs no analytics.
The short version
Scrollmates has no analytics SDKs, no advertising SDKs, and no third-party trackers. We do not sell, rent, or trade your data, and we do not profile you for ads. The one thing we do measure is our own subscription screens, along with a count of the days you open the app and, in aggregate over many bonds and accounts at once, how bonds are used — on our own servers, described in full below, and deleted when your account is.
In solo mode nothing about your screen time leaves your iPhone, and until you first pair there is no account of yours on our side at all. The main thing that does leave, once per setup, is a set of anonymous answers to the questions setup asks, plus which of setup's pages you reached: no identifier of any kind travels with them, and skipping those questions sends nothing at all. The only other thing that can leave a solo phone is a support report, and only if you send one. Bonding with a partner is the only thing that turns that networking on, and even then the app uploads minutes and events — never the names of the apps you chose, and never anything you did inside them.
Solo mode: your screen time stays on your device
Solo mode is the default, and it is entirely local. Your schedules, your daily pool state, your local profile, your block-list selection and its lock-in state, and your time zone are written to a private App Group container on your device, readable only by Scrollmates and its own Screen Time extensions.
While you are solo, none of it is sent anywhere. That is enforced in code by a fail-closed network gate rather than left to good intentions: with no bond, a request is refused before it is sent.
Solo mode does not create an account. If you never pair with anyone, we never receive anything about you, because there is nothing on our side to receive it — apart from the one anonymous send described in the next section, which arrives with no identifier at all and cannot be traced to you or to anybody else.
Once you have an account — because you paired at some point, even if that bond has since ended — a solo device still speaks to us for a short list of account-level things, and only those: reading your own account and whether a bond still exists, reading your bond's own state, reading your own record of past bonds so the app can explain a bond that ended overnight, deleting one of those summaries when you choose to, keeping your own display name and avatar up to date on your account, registering the address a push reaches your phone at, handing that address back so we stop reaching your phone, sending Apple's signed subscription receipt, asking whether the wording of our subscription screens has changed and recording which of them you were shown, fetching a subscription screen's design, sending or deleting a support report, and deleting your account. None of them carries a minute, an event, or an app you selected. Uploading your usage is not on the list, and stays off it until you are bonded again.
Anonymous statistics from setup
Setting up Scrollmates asks you three questions: what you want back, when you scroll most, and roughly how many hours a day you scroll. Your answers stay on your device, where the app uses them to suggest a starting budget and to order the schedules it offers you. They are never attached to an account.
Once, at the end of setup, the app sends those answers along with which of the three endings you chose — invite a scrollmate, accept an invite, or start on your own — and a list of which setup pages you reached, in the order you reached them: the page names only, never when you were on one or for how long. That is how we see in aggregate what people come to Scrollmates for, and where setup loses them. They travel with no identifiers of any kind: no name, no email, no account, no device or install identifier, no push token. The table they land in has no column for a person, and never will. It is a row in a histogram, not a record about you, and it is sent once per time you complete setup — reinstall the app, or start again after deleting your account, and a new row is sent, because the only way to make it once-per-person would be to keep an identifier for you, which is the one thing this send refuses to do.
Nothing is sent unless you answered something. Skip all three questions and there is no send at all — not even the ending you chose, and not the pages you reached. The disclosure is the caption on the first question, "Answers and the pages you saw are shared anonymously to improve Scrollmates. They are never tied to you", and going on from there is how you agree to it. Skipping the questions is how you decline.
Because the send carries no identifier, we cannot find it again either. There is no way for us to trace one of those rows back to you, show it to you, correct it, or delete it for you alone, and we would rather say so plainly than imply a control we do not have. What we can promise is what we will not do: we will never attempt to re-identify these answers, never link them to an account, and never combine them with anything else to work out who sent them.
Opting out is therefore forward-looking. Skipping the questions sends nothing; a send that has already happened cannot be recalled, by you or by us.
Screen Time data stays with Apple
Scrollmates enforces limits through Apple's Family Controls and DeviceActivity frameworks. When you choose which apps and categories to limit, iOS hands the app an opaque token for each selection — not a name, not a bundle identifier, not an icon.
This is a technical boundary, not a promise of restraint. The app cannot turn those tokens back into app names, cannot read your browsing history, cannot see notification or message content, and cannot see anything you type or view inside another app. Neither can our servers, because the tokens never leave your device.
What we store once you bond
Bonding is opt-in: you have to sign in and pair with a partner before any of this exists. Once you do, the Scrollmates backend stores:
- • Account. An account created through Sign in with Apple or Sign in with Google. We receive the identifier your provider gives us and, if you allow it, your name and email address. We never receive your password.
- • Profile. Your display name, avatar emoji, and accent color.
- • Bond details. Your bond's moniker, the partnership type, and the shared vision you and your partner chose.
- • Contract settings. Your daily pool size, pacing thresholds, reset time, focus schedules — each with the title you typed for it, its emoji and its times — whether Discipline Mode is on and the date any turn-off was queued on, and the bond's time zone.
- • Usage aggregates. Per-day totals in minutes, plus individual events recording a duration and an event type, and the time of your most recent activity — which is what tells your partner whether you are scrolling right now.
- • Quest progress. Your bond's level and the XP behind it, its current streak and its best one, the passes it has banked, and — for each day the bond runs, for as long as the bond exists — whether that day counted and whether it was broken.
- • Block-list summary. How many items are in your block list, and an opaque hash of the selection — enough to tell you and your partner that the list changed, never the list itself.
- • Push token. An Apple Push Notification service device token, so your partner's actions can reach your phone.
- • Notifications. The alerts your bond generates — their title and text, which can name your scrollmate and carry a minute count — kept for seven days so the app can show you what you missed, along with which categories you have switched on.
- • Subscription status. Apple's original transaction identifier, the product identifier, and the expiry date for your bond's subscription, which of you is paying, whether it is set to renew and the plan it will renew onto, and the price and currency Apple reported for the purchase.
Support reports
Help & Feedback in the app sends us a report about a problem you hit. You pick what it is about and write what happened; the app adds its own version and build, your iPhone's model and iOS version, and — if you turn that toggle on — a diagnostic log. You do not have to be signed in to send one: a report about a sign-in that will not work is the one we most need to receive.
- • What you wrote. The category you picked and the description you typed, up to 2000 characters. It is free text, so it holds whatever you choose to put in it.
- • Your email address, but only if you ask for a reply. "Email me about this report" is off by default. Leave it off and the report still reaches us — we just cannot follow up. Turn it on and we use the address to reply to that report and for nothing else. It travels inside the sealed report and is deleted with it.
- • A diagnostic log, only if you turn it on. A record of what the app did over the last seven days: launches and foregrounds, sync results, timings and error codes. Every event is drawn from a fixed vocabulary compiled into the app, so there is no field for an app name, a web address, a display name, or anything you typed elsewhere in the app to travel in. No app names, no minute counts and no block list. While you are bonded it also records the moments a shield went up and the pool ran out — facts your bond's server already holds; while you are solo those are stripped out before the report is sealed. "Review what will be sent" shows you the actual log before you send it. Turning the toggle on attaches it; it is off unless you choose it.
- • Your account, if you have one and are signed in. The report is stored against it, which is what lets us look at the other side of the problem you are describing. Sent while signed out, it arrives with no account attached to it.
Your iPhone encrypts the report before it leaves, to a key whose other half we hold and our server does not. What arrives here is a sealed envelope: the server stores it and hands it back to us, and cannot read a byte of it. That is a technical boundary rather than a promise of restraint — your description, your email address and the log are readable only with the key on our side, and nobody outside Scrollmates ever reads a report.
Subscription screens and app activity
Once you have an account, we record how Scrollmates' subscription screens are used, so that we can tell whether they explain the thing they are asking you to pay for. Sometimes two people are shown different wording for the same screen; when that happens we record which of them you saw.
- • The screen, and what you did with it. Which subscription screen appeared, which wording it carried and which design drew it, when it appeared, whether you closed it or started a purchase, and which subscription followed if one did. Each showing of the screen gets its own reference so that what you did can be matched to what you were shown, and the record notes which version of the app you were running. Where a design could not be drawn, we record that it could not, and which of a handful of reasons it was — the app shows you its own subscription screen instead, and this is the only way we would ever know.
- • The days you opened the app. A count against each date: that Scrollmates was opened that day, and how many times. Not when, not for how long, and not what you did once it was open.
None of it contains screen time — no app names, no minutes, no events, no block list, and nothing you have typed anywhere in the app. We keep it because wording we cannot measure is wording we have to guess at, and we would rather change it on evidence than on instinct. Improving the offer and understanding how much the app gets used are the only things it is for; the legal basis is our legitimate interest in both.
It is stored against your account for 400 days and then deleted. Deleting your account deletes it immediately along with everything else of yours, and none of it is shared with anyone, sold, or used to build a profile of you.
What we never see
We never see which apps or websites you selected. We never see app names, bundle identifiers, URLs, page titles, search terms, keystrokes, screenshots, message content, contacts, photos, precise location, or anything else from inside the apps you use.
Usage reaches our servers as durations and event types only. "38 minutes" is the whole of it — there is no field in which an app name could travel.
We never see your payment details — no card number, no bank, no billing address. Subscriptions are purchased and billed entirely by Apple; what reaches us is the record described under "Subscription status" above: that a subscription exists, which product it is, when it expires, which of you is paying, whether it renews, and the price and currency Apple reported for the purchase.
How we use it
We use the data above to run the features you turned on, and for nothing else:
- • To compute your shared daily pool and keep both phones showing the same numbers.
- • To show you and your partner each other's usage totals and bond events — see "Shared with your partner" below.
- • To send the push notifications the app depends on to stay in sync.
- • To determine whether your bond is inside its free trial, subscribed, or lapsed.
- • To see how our subscription screens are working, and how much the app is being opened — see "Subscription screens and app activity" above.
- • To tune the mechanic itself — what pool sizes people settle on, how contracts, quests and schedules are actually used, and how long bonds last — so that what the app suggests is drawn from evidence rather than from our guesses. These are counts over many bonds and many accounts; we never look at one bond or one person this way. The legal basis is our legitimate interest in making Scrollmates work.
- • To keep the service working and secure. Our servers keep an ordinary access log of the requests they answer — the IP address a request came from, the time, the route it asked for and the result — which is what rate limiting and diagnosing a fault run on, and it is deleted after 30 days. It never records what you wrote, what you chose, or anything from inside another app, and the anonymous setup send is deliberately left out of it altogether. Error logs record a request identifier rather than your content.
Running your bond is an agreement between you and us, and performing that agreement is the legal basis for everything in that list. The two exceptions name their own basis above: measuring our subscription screens and counting how bonds are used both rest on our legitimate interest instead.
We do not use your data to train machine-learning models, to build advertising profiles, or to market other products to you.
Shared with your partner
By design, your bonded partner can see your profile — your display name, avatar and accent colour — your daily usage totals, your share of the pool, whether you are scrolling right now, how many apps are on your block list (never which ones), your focus schedules with the names, emoji and times you gave them, whether Discipline Mode is on, and your bond events, which include a broken contract, the fact that your block list changed, and the day you queue Discipline Mode off. That mutual visibility is the product, not a side effect, and it runs both ways: you see exactly the same about them. If you do not want someone seeing those numbers, do not bond with them.
Your partner still cannot see which apps or websites you chose or blocked, or what you did in them, or anything else on your phone. Nobody can — see "What we never see" above.
Before a bond exists. Creating an invite makes your display name, avatar and accent colour visible to whoever opens that code or link — anyone holding it, whether or not they accept, and whether or not they are the person you meant to send it to. Nobody should be asked to bond with a stranger, so the person deciding is shown who is asking. The only other thing they are shown is whether a subscription already covers the bond, so they know whether they will be asked to pay. Nothing else about you is shown, and none of your usage is shared, until a bond actually forms. You have one live invite at a time: it lasts seven days, can be accepted once, and getting a new code revokes the old one immediately.
Shared with anyone else
Nobody buys or receives your data. We do not share it with advertisers, data brokers, or analytics vendors, and we do not sell it. What follows is everybody else who is in the path at all, and why.
Two Apple services sit in the path because the app cannot work without them: the App Store handles purchases and billing, and Apple Push Notification service delivers pushes. Both are Apple's, governed by Apple's own privacy policy, and neither receives your usage data from us.
Google is in that path too, but only if you sign in with Google. That button runs Google's own sign-in SDK, so Google sees the request — your IP address, your device details, and the Google account you pick — and hands us back the identifier we build your account from. Google is governed by Google's own privacy policy, and like Apple's services it never receives your usage data from us. Sign in with Apple does not go through Google.
Our own servers are in that path too, because they are where all of this happens. Scrollmates runs on machines we rent from Amazon Web Services, currently in Virginia in the United States, and Cloudflare sits between your phone and those machines: it terminates the connection and absorbs abuse, so it sees your traffic in transit. Both are processors acting on our instructions — they hold what passes through them in order to deliver it, and neither is given your data for any purpose of its own. Wherever in the world you are, your data is processed in whichever country our servers are in at the time, which today is the United States; if we move them again we will say so here and move the date at the top.
We may disclose data if the law requires it. If that ever happens we will tell you, unless we are legally prevented from doing so.
How long we keep it
While you are bonded, we keep the data described above so that the bond can function.
Collection stops the moment a break is confirmed — the server stops recording usage from that moment — and the network gate shuts on both phones once the bond actually ends. Once the bond ends, your account is scheduled for deletion 30 days later. The delay exists so an accidental or temporary break is recoverable: pairing again within those 30 days cancels the deletion. If you do nothing, the account and its data are deleted when the window closes.
An ended bond is deleted after 30 days, however it ended — broken on purpose, lapsed, or ended because somebody stayed signed out. For those 30 days the bond is kept so that pairing with the same person restores it: the shared pool history, the Journal, the settings and the level it reached come back, while the streak starts again from zero. After that, everything belonging to it is permanently deleted: the shared pool, the daily records, the Journal history and the quest progress. The only thing that survives is a summary of the bond — its final level and title, its best streak, the total time you focused, and the dates it ran between — which each of you keeps on your own account, and which is deleted with that account.
Two things of yours outlive a deleted account. Your own records go on the spot: your profile, your sign-in identities, your device tokens, your usage events, your schedules, your block-list count and hash, your notifications, your preferences, your support reports, your subscription-screen and app-activity records, and your own bond summaries.
The first is your ex-scrollmate's summary of the bond you shared. Its level, its best streak, its total focused time and the dates it ran between are the bond's figures rather than yours, and they stay on their account — but your name is not theirs to keep, so it is replaced there by "a former scrollmate". The second is the ledger of subscription notifications Apple sends us, which records Apple's identifier for the subscription and never your name or your email address. It exists so that a notification Apple redelivers cannot be applied twice, and a row is deleted once it is 90 days old. The free trial is an introductory offer delivered through the App Store: Apple grants one per Apple Account, decides who is eligible, and tracks that on their side, so there is nothing about it for us to remember.
Two more things carry on, and neither was ever attached to you in the first place: an anonymous setup row, and a support report you sent while signed out. Both are described above, and neither can be found from your account, because neither was ever joined to it. The shared bond's own rows are a third case — they are not yours alone, and they keep the same 30 days described below.
When you use Delete Account, your own server-side data is deleted immediately and the app wipes its App Group container on your device. There is no grace period and no undo. It does not cancel a subscription either: that belongs to your Apple Account, and only you can cancel it there. If you were bonded at the time, the bond's own rows — its pool history, the settings you agreed, its moniker — are not yours alone, and they stay for the same 30 days described above so that your scrollmate's side of it still works. They are deleted when that window closes.
And we hand your sign-in back. If you signed in with Apple, deleting your account tells Apple to revoke the credential you used, so Scrollmates disappears from Settings → your name → Sign in with Apple; Apple may email you to say so, and that email is the deletion working rather than anything going wrong. If you signed in with Google, we revoke that grant the same way. Either way, signing up again later starts a genuinely new account — we do not keep a way back to the old one.
A support report is kept for 180 days, then deleted. You can delete one sooner yourself: Help & Feedback lists the reports you sent from this iPhone, and deleting one there removes it from our server as well. A report you sent while signed out was never attached to your account, so deleting your account cannot reach it — delete it from that list, or let it age out.
The access log described above is kept for 30 days and then deleted. Routine server backups and error logs may hold incidental copies for a short period before they age out too.
Your choices
Stay solo. Do not pair, and apart from the one anonymous statistics send described above, nothing reaches us unless you choose to send a support report. To send nothing at all, skip the setup questions.
Break the bond. Collection stops the moment you confirm it — an hour before the bond ends.
Delete your account. Settings → Delete account removes your own server-side data immediately and wipes local state.
Remove the app. Deleting Scrollmates from your iPhone removes its local App Group container with it.
Ask us. Write to privacy@scrollmates.app for a copy of the data held against your account, a correction, or a deletion you cannot perform in the app. We will respond within 30 days.
Depending on where you live, you may have further rights over your personal data — access, correction, deletion, portability, or objection among them. The same address reaches us for all of them. If you think we have got any of this wrong, you can complain to your local data-protection authority as well as to us.
Children
Scrollmates is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, write to privacy@scrollmates.app and we will delete it.
Changes to this policy
If we change what we collect or what we do with it, we will update this document and move the "Last updated" date shown above. A material change is called out in the app's release notes as well, so a version that changes this is a version that says so.
Contact
Questions about privacy, or a request about your data: privacy@scrollmates.app.
Post: INNOV8 VENTURES COMPANY LIMITED, Ngu War (2) Street, Malikha Housing, 16-18, Thingangyun, Yangon, Myanmar.