Privacy Policy for Ravelo
Last updated: July 27, 2026
This Privacy Policy explains how Ravelo ("Ravelo," "we," "us," or "our") handles information when you use the Ravelo iOS application, the ravelo.app website, optional account and Social features, early-access forms, support channels, diagnostics, and related services (together, the "Service").
Ravelo is local-first, but it is not entirely local-only. The core Screen Time selection and blocking features can be used without a Ravelo account. Optional account, profile, Social, cross-device activity sync, subscription, product analytics, error tracking, support, and website features involve data processing as described below.
1. Summary
- A Ravelo account is optional for the core app. Sign in with Apple is required for features such as profiles, the leaderboard, friends, invite attribution, and syncing selected activity data across devices.
- Screen Time selections and raw FamilyControls tokens are handled on your device. We do not sell them or use them for advertising.
- If you sign in, selected Ravelo activity history and settings are saved on Ravelo's servers so analytics and Social features can work across your devices.
- Ravelo uses PostHog for device-scoped product analytics, error tracking, lifecycle events, feature flags, and update configuration. PostHog analytics are not identified with your Ravelo account ID in the current app configuration.
- Ravelo does not sell personal information or use App Tracking Transparency to track you across other companies' apps or websites for advertising.
2. Information stored on your device
Ravelo stores core product data locally using Apple-supported app storage, the app's shared container, Keychain, and related system storage. This may include:
- Apps, categories, and web domains you select as productive or distracting, represented using Apple's privacy-preserving Screen Time tokens and available labels.
- Time Currency balance; earned, spent, invested, reversed, or adjusted minutes; daily allowance; activity history; market purchases; Quick Peeks; focus sessions; streaks; weekly goals; Growth Contract state; blocked-list removal counts; and derived analytics such as the Ravelo Index.
- App configuration, onboarding state, language, appearance, themes, reminder preferences, notification state, and other settings.
- Optional profile information, such as display name, gender, birth date, expectations, and profile photo. These fields remain local while you are signed out and may synchronize after you sign in.
- Authentication session information stored in Keychain after you sign in.
- Diagnostic logs and state summaries used to investigate Screen Time, balance, focus, market, synchronization, and blocking issues.
Local information remains on the device until it is cleared through available in-app controls, removed by the operating system, or the app is uninstalled. Some Keychain or iCloud key-value information may follow Apple's own storage behavior.
3. Apple Screen Time APIs
Ravelo uses Apple's FamilyControls, DeviceActivity, and ManagedSettings frameworks to let you choose apps, categories, or domains; monitor configured activity; and apply system-level restrictions.
These APIs are privacy-preserving. Ravelo cannot read your messages, passwords, photos, files, browsing history, content inside other apps, or an unrestricted list of every app installed on your device. Ravelo works with the selections you explicitly make and the tokens or labels Apple makes available for those selections.
The private identifiers Apple uses for your Screen Time selections, including selected web domains, are not uploaded to PostHog or Ravelo's servers by the current app. If you sign in, activity records tied to your account may contain an app or category label associated with an earning or spending event, along with the event details described in Section 6.
You control Screen Time authorization through iOS. If you revoke it, blocking, monitoring, earning, and spending features may stop working or become limited.
4. Optional Ravelo account and Sign in with Apple
When you choose Sign in with Apple, the app sends the information needed to verify the sign-in securely to Ravelo's servers. This includes an Apple identity token, a one-time authorization code, and a security value. We use them to verify the sign-in, create or find your Ravelo account, keep you signed in, and obtain an Apple authorization token used to disconnect Sign in with Apple when you delete your account.
The account records may include:
- Apple's stable account identifier for Ravelo and a Ravelo-generated user ID.
- Sign-in information used to keep you signed in securely. Ravelo stores only protected, unreadable versions of its session renewal tokens. Apple's authorization token is stored so Sign in with Apple can be disconnected when you delete your account.
- Account creation and update timestamps.
- Your display name, if you provide one. Ravelo requests the full-name scope from Apple, but Apple usually provides a name only during the first authorization. Ravelo does not request your email address as a Sign in with Apple scope in the current app.
Core Ravelo features remain available without signing in. Account features require a network connection and may be unavailable while you are signed out.
5. Profile, leaderboard, friends, and invites
Profile information is optional. If you save profile fields while signed in, Ravelo may store and synchronize:
- Display name.
- Gender selection.
- Birth date.
- Free-text expectations you choose to enter.
- Cropped profile photo and an associated storage key.
Your birth date is saved on Ravelo's servers as a calendar date when you are signed in. PostHog receives only a broad age range, not your full birth date. Your free-text expectations are saved with your account and are also sent to PostHog without your Ravelo account ID in the current app configuration. Do not enter information you do not want processed for these purposes.
When you participate in Social features, your display name, profile photo, Ravelo Index, tier, rank, percentile, weekly score change, and friendship indicator may be shown to other signed-in Ravelo users in leaderboard or profile surfaces. Ravelo also processes friend relationships, permanent or temporary invite codes, invite redemption, and invite-related timestamps.
6. Syncing activity data across devices
After you sign in, Ravelo saves selected activity history on its servers. This lets Ravelo restore your analytics on another device, avoid showing incorrect zero values after a new installation, calculate trends for your account, and support leaderboard features.
The data saved for this purpose may include:
- A pseudonymous device ID and Ravelo user ID.
- Ledger events: event type and source, minutes, sign, timestamps, local day, time zone and UTC offset, source or purchase identifiers, and associated app/category labels where present.
- Completed or cancelled focus-session timing, planned timing, state, and earned minutes.
- Productive-day aggregates and reversals.
- Growth Contract events and state, including duration, start/end timing, completions, breaks, and forgiveness state.
- Daily allowance, streak-goal settings, scoring version, and aggregate blocked-list removal counts.
- Ravelo Index reports used for ranking and Social features.
The private identifiers Apple uses for Screen Time, your complete app selections, active Time Market purchases, and active focus sessions are not included in this sync by the current app.
7. PostHog analytics, error tracking, and remote configuration
Ravelo uses PostHog to understand product usage, detect failures, control feature rollout, and deliver update configuration. PostHog processing may include:
- Onboarding progress; acquisition source and optional source detail; permission outcomes; and counts of selected apps, categories, or domains.
- Focus, Time Market, Quick Peek, allowance, Weekend Bank, weekly-goal, Growth Contract, paywall, subscription, restore, guided-tour, settings, navigation, profile-update, invite, and lifecycle events.
- Event properties such as durations, minute totals, feature names, result states, plan status, language, locale, app version, build, operating-system version, device model/type, timestamps, and TestFlight status.
- Profile properties such as gender, broad age range, whether a name or photo exists, and free-text expectations when you provide them.
- Automatically captured crashes, uncaught exceptions, stack traces, and related technical diagnostics.
- Network-derived information normally processed when a device communicates with an online service, such as IP address.
PostHog uses a device-scoped distinct identifier. The current app does not call PostHog's account-identification API with your Ravelo user ID. Before sending events, Ravelo removes known property keys for app names, category names, domains, and selection names. We do not intentionally send selected app or domain names to PostHog. The current iOS configuration does not enable session replay or screen recording.
8. Subscriptions and purchases
Ravelo Platinum is offered through Apple's In-App Purchase system and RevenueCat.
Apple processes billing and payment information under Apple's own terms and privacy policy. Ravelo does not receive your complete payment-card details.
RevenueCat may process purchase receipts, product and transaction identifiers, subscription and entitlement status, offering interactions, restore results, device/app metadata, and a RevenueCat App User ID that may be anonymous or tied to your Ravelo account. When you sign in, Ravelo may connect the RevenueCat customer record to your Ravelo user ID so your subscription access can follow your account. Signing out or deleting the account detaches the current app session, but does not erase Apple's transaction history or records RevenueCat must retain for purchase administration or legal compliance.
9. iCloud, notifications, and Live Activities
Ravelo uses Apple's iCloud key-value services for limited subscription and RevenueCat identity state across Apple devices. Core Screen Time selections are not uploaded through this iCloud mechanism by the current app.
Ravelo may request notification permission for focus completion, weekly digests, streaks, Weekend Bank, and Time Market actions. Most notifications are scheduled locally through Apple's notification system.
Live Activities may display focus or market session timing, remaining time, and related state on supported iOS surfaces. You can manage notifications and Live Activities through iOS settings.
10. Diagnostics and support
If you choose to send diagnostics from an available in-app diagnostics control, Ravelo uploads a report to a Ravelo diagnostic endpoint. A report may include:
- App version, build number, iOS version, timezone, export timestamp, and diagnostic report identifier.
- Permission, configuration, balance, ledger, focus, market, synchronization, monitoring, and enforcement summaries.
- Runtime logs generated by the app and its extensions.
Diagnostic reports can contain detailed information about how you configured and used Ravelo. Only send a report if you are comfortable sharing it for troubleshooting.
If you contact us, we process your email address, phone number if used, message content, attachments, and other information you provide to respond, investigate problems, protect the Service, and improve Ravelo.
11. Website and early access
The ravelo.app website does not currently include advertising trackers or analytics cookies in its own application code. Website hosting, routing, and security providers may still process ordinary request information such as IP address, browser/device information, requested URL, referrer, timestamps, and security logs.
If early access is enabled and you submit the form, Ravelo processes your email address and request IP address. The IP address is forwarded for rate limiting and abuse prevention and may also appear in infrastructure logs. Early-access records may include the submitted and normalized email address, signup status, TestFlight link, timestamps, email-delivery status and attempts, release-email status, and assigned offer code. An email delivery provider processes the email address and delivery information needed to send early-access and release messages.
The website may expose early-access signup to compatible browser AI tools through the browser's Model Context API. Such a tool acts only when invoked in a compatible browser; information you provide through that tool is submitted to the same Ravelo early-access endpoint.
12. How we use information
We use information to:
- Provide, secure, maintain, synchronize, and troubleshoot Ravelo.
- Verify accounts, maintain sessions, revoke Apple authorization during account deletion, and prevent abuse.
- Operate profiles, leaderboards, friendships, invites, subscriptions, and customer support.
- Calculate balances, analytics, rankings, and other features requested by users.
- Understand feature adoption and failures, improve reliability and usability, and control safe feature rollout.
- Manage early access and send requested operational, beta, launch, or release communications.
- Comply with law, enforce our Terms, and protect users, Ravelo, and third parties.
Where applicable law requires a legal basis, we rely on performance of the Service you request, your consent where required, our legitimate interests in operating and improving a secure Service, and compliance with legal obligations. You may withdraw consent where processing is based on consent, but this does not affect earlier lawful processing.
13. Service providers and disclosures
We disclose information only as needed to operate the Service, comply with law, protect rights and safety, or complete a business transaction subject to appropriate safeguards. Current categories of providers include:
- Apple: App Store, In-App Purchase, Sign in with Apple, Screen Time APIs, iCloud key-value services, notifications, and Live Activities.
- PostHog: product analytics, error tracking, lifecycle analytics, feature flags, and remote update configuration.
- RevenueCat: subscription offerings, receipt and entitlement processing, customer-center features, and purchase restoration.
- Cloud hosting, storage, and security providers: operation and protection of Ravelo's online account and Social features, synced activity data, profile photos, diagnostics, and the ravelo.app website.
- Email delivery providers: early-access, TestFlight, release, and other requested operational messages.
These providers process information under their own terms and privacy notices. We require providers that receive user data from Ravelo to protect it to the same or an equivalent standard as described in this Policy and required by applicable law.
We may disclose information when reasonably necessary to comply with a lawful request, enforce our agreements, investigate fraud or security incidents, protect rights or safety, or support a merger, financing, acquisition, reorganization, or sale of assets. If ownership changes, personal information may transfer subject to this Policy and applicable law.
14. No sale, advertising sharing, or cross-app tracking
Ravelo does not sell personal information. Ravelo does not share personal information for cross-context behavioral advertising and does not use Screen Time selections or account analytics to serve third-party ads. Ravelo does not use App Tracking Transparency identifiers to track you across other companies' apps or websites.
15. Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described above, including providing the Service, maintaining security and backups, resolving disputes, and meeting legal obligations.
- Device-local data remains until you clear it using available controls, iOS removes it, or you uninstall the app, subject to Apple's Keychain and iCloud behavior.
- Ravelo account, profile, Social, friendship, invite, and synced activity records remain while the account exists. Deleting the account also deletes data tied to it from Ravelo's active server records.
- Profile-avatar objects are deleted when you remove the photo or delete your account on a best-effort basis. A failed storage deletion may leave an orphaned object until operational cleanup.
- Early-access records remain while needed to administer beta/release access, delivery history, and offer codes, or until a valid deletion request is completed, subject to legal and backup requirements.
- Support and diagnostic information is retained while needed to resolve the request, maintain security and reliability, and meet legal obligations.
- PostHog, RevenueCat, Apple, hosting providers, and email providers retain information according to their configured retention, contractual duties, and legal obligations.
Backup copies and security logs may persist for a limited period after deletion before being overwritten or isolated from ordinary use.
16. Your controls and account deletion
You can:
- Revoke Screen Time authorization and manage notifications or Live Activities in iOS Settings.
- Change or clear optional profile fields and profile photo in Ravelo.
- Sign out of your Ravelo account without deleting device-local Time Currency and activity history.
- Delete your Ravelo account through the in-app Account screen. A successful deletion removes the account and the profile, Social, friendship, invite, and synced activity data tied to it from Ravelo's servers. Ravelo also attempts to disconnect the associated Sign in with Apple authorization and delete the profile photo stored on its servers.
- Clear available local data through in-app reset controls or uninstall Ravelo.
- Manage or cancel subscriptions through your Apple App Store account settings.
- Contact us to request access, correction, deletion, restriction, portability, or other privacy assistance where applicable.
Deleting a Ravelo account does not automatically erase device-local history, cancel an App Store subscription, remove Apple's transaction history, or delete independent records held by Apple, RevenueCat, PostHog, website/early-access systems, support systems, or diagnostic infrastructure. Use the relevant controls or contact us for those requests. Because PostHog analytics are device-scoped rather than identified with your Ravelo account, we may need additional information and may not always be able to associate anonymous events with you.
17. Privacy rights
Depending on where you live, you may have rights to request information about our processing; access, correct, or delete personal information; restrict or object to processing; receive portable data; withdraw consent; or appeal or complain to a data-protection authority. California residents may also have applicable rights to know, correct, or delete information and to receive non-discriminatory treatment for exercising privacy rights.
We do not sell personal information or share it for cross-context behavioral advertising, so Ravelo does not offer a "Do Not Sell or Share" mechanism for practices it does not perform.
To exercise a right, contact us using Section 21. We may need to verify your identity and may deny or limit a request where permitted by law. Authorized agents may submit requests where applicable, subject to verification.
18. International processing
Ravelo and its providers may process information in countries other than your own. Those countries may have different data-protection laws. Where required, we use contractual or other lawful safeguards for international transfers.
19. Security
We use administrative, technical, and organizational measures designed to protect information. These include Apple's privacy-preserving Screen Time APIs, secure connections to Ravelo's servers, Keychain storage for sign-in information, protected session renewal tokens, validation and rate limits, and access controls. No storage or transmission system is completely secure, and we cannot guarantee absolute security.
20. Children
Ravelo account, profile, and Social features are not intended for children under 13. The current profile interface does not accept a birth date indicating an age under 13. If you are below the age at which you can consent to online services in your jurisdiction, use account or Social features only with authorization from a parent or legal guardian where permitted.
If you believe we collected personal information from a child contrary to applicable law, contact us so we can investigate and delete it as appropriate.
21. Changes and contact
We may update this Privacy Policy when Ravelo's features, providers, infrastructure, or legal obligations change. We will update the date above and provide additional notice where required.
For privacy questions or requests, contact us:
- Email: contact@ravelo.app
- Support phone: +380954713621