Privacy Policy

Last Updated: July 16, 2026

We value your privacy. This Privacy Policy explains how the Nepsis application (hereinafter referred to as the "Application") handles user data.

1. Local-First Architecture

The Application is designed based on a "local-first" architecture. This means that:

2. Use of Screen Time API (FamilyControls)

The Application utilizes Apple's Screen Time API features to monitor and limit the time spent on other applications. All permissions are requested via standard iOS system dialogs. The data from this API is protected by Apple's built-in security mechanisms, never leaves your device, and is not used for advertising purposes.

3. iCloud Sync

When you are signed into iCloud on your device, the Application may synchronize certain rule and settings metadata between your Apple devices using Apple's iCloud Key-Value Storage. There is currently no separate on/off switch for sync inside Nepsis settings; sync follows your device iCloud availability.

Synced data may include:

The following are not synced via iCloud, and stay only on the device where they were created:

Data synced via iCloud is subject to Apple's Privacy Policy.

Important: After syncing rule metadata to another device, you may need to re-select apps and categories on that device.

4. Third-Party Services and Subscription Data Processing

To provide and manage in-app purchases and subscriptions, the Application utilizes a third-party service, RevenueCat (RevenueCat, Inc.).

RevenueCat collects and processes the following anonymized data:

This data is transmitted to RevenueCat in an encrypted and anonymous format. It is used for app functionality (verifying Premium access) and subscription analytics in the RevenueCat dashboard. It is not linked to your real-world identity and is not used for tracking (including advertising or cross-app tracking). The Application does not use advertising SDKs, IDFA, or App Tracking Transparency for advertising purposes.

You can review the service's privacy policy on their official website: RevenueCat Privacy Policy.

5. Passcode and Local Storage

If you enable Strict mode or passcode protection, a secure hash of your passcode (salted SHA-256) is stored in the iOS Keychain on your device — not the passcode itself in plaintext. The passcode and its hash are never transmitted to us, RevenueCat, or any third party.

You may optionally use Face ID or Touch ID (via Apple's LocalAuthentication) to unlock Strict passcode gates. Biometric evaluation happens locally on your device; we do not receive biometric data.

The Application may store non-sensitive preferences and local insights (such as usage summaries derived from Screen Time data) on your device only. This information is not sent to our servers.

6. Device Permissions and On-Device Processing

Depending on which features you use, the Application may request the following iOS permissions. Sensor and challenge data from these features is processed on your device only and is not stored by us or uploaded to our servers (or to RevenueCat):

Permissions are requested through standard iOS system dialogs and only when you opt into the related features.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes become effective immediately upon their publication on this page. We recommend regularly checking this page for updates.

8. Contact Us

If you have any questions regarding privacy or the operation of the Application, you can contact us via email at: nepsis.support@gmail.com