Privacy

The short version: we collect what the service needs to work — account details, your rules, aggregate screen-time minutes, and (if you use app limits) which apps are on a managed device and for how long each is used, plus a device's location if you switch that on. If you block websites, that happens entirely on the device: we never see which sites were visited or blocked. Never browsing content or history, no ads, no trackers.

1. Who we are

Scrintime is operated by IERO, United Kingdom ("we", "us"). We are the data controller for the personal data described here. Contact us any time via the contact form.

2. What we collect

Your account: name, email address, a securely hashed password (or your Google sign-in), your device PIN (stored hashed), and your appearance preferences. Your devices and rules: the device names you choose, the rules and schedules you configure, child profile names you add, device online status, the platform each device runs (Windows, Android or iOS) and the app version. Screen-time data: the ScrinTime app reports minutes of use per rule per day — aggregate counters only. Installed apps: where you use app limits, the app on a managed device reports the list of apps installed on it (name and package identifier) and the number of minutes each was used per day, so you can choose which apps to limit. This list excludes ScrinTime itself, the device's home screen and its phone app, which can never be limited. Apple does not allow apps to share which apps are installed on an iPhone or iPad, so no app list is collected from iOS devices. Location: only if you turn location on for a device, and only from Android and iOS devices. The app then reports that device's position (latitude, longitude and an accuracy figure) with the time it was recorded, so you can see where your child's device is. It is off unless you enable it, the child's device asks for the permission in the usual system prompt, and turning it off stops collection. Website blocking: where you block websites, presets or categories on an Android device, the app runs a local VPN connection on that device so it can stop those sites loading. The connection is a technical device only: it goes nowhere, no traffic is sent to us or to anyone else, and it carries no remote server. To decide whether to allow a site, the app has to look at the name of the site being requested (for example example.com) and compare it with the list you chose. That check happens on the device, in memory, and the result is discarded — we do not record, store or receive which sites were requested, allowed or blocked. What the device does report back is only whether blocking is running and how many addresses are on its list, so you can see whether your settings are actually being applied. Blocking a site makes it fail to load; nothing is redirected anywhere. The child's device must allow the connection through Android's own prompt, and it can be turned off again in Android settings. We do not collect browsing history, page content, messages, screenshots or keystrokes. Billing: handled by Stripe; we store your subscription status and plan, never card numbers. Support: messages you send through the contact form.

3. Children's data

The screen-time minutes, installed-app lists and any location data above may relate to your children when you assign devices to them. We designed the service to collect the minimum needed: which apps exist on a device and aggregate daily minutes for each, never content or activity detail — no messages, no browsing history, and nothing about what happens inside an app. As the parent or guardian you control this data — you can rename or delete child profiles and devices at any time, which removes the associated records, app lists are removed automatically once a device stops reporting them, and location can be switched off per device at any point. We think a child old enough to carry a phone is old enough to be told it reports where they are, and the same goes for website blocking: while it is on, Android shows a VPN indicator in the status bar, and the ScrinTime app on the device explains what that connection is for. We encourage you to tell your children that their screen time is managed; every ScrinTime app is visible while active — an icon on Windows, and an ongoing notification on Android.

4. Why we process it (lawful bases)

We process account and device data to provide the service you signed up for (contract); billing records to meet tax and accounting duties (legal obligation); and service telemetry such as client versions and error logs to keep the service secure and working (legitimate interests). We do not sell personal data, run advertising, or use tracking cookies — the only cookies are the one that keeps you signed in and the one that remembers your preferences.

5. Who processes data for us

We use a small set of processors to run Scrintime: Vercel (hosting, plus cookieless aggregate page analytics that cannot identify you), Supabase (database, EU region), Stripe (payments), Resend (transactional email), Google reCAPTCHA (abuse prevention on public forms) and DiceBear (generating your avatar image from a random seed). Each receives only what its role requires. Where a processor is outside the UK/EEA, transfers are covered by standard contractual clauses or an adequacy decision.

6. How long we keep it

Your data is kept while your account is active. Screen-time and activity records, including per-app usage, are automatically deleted after 90 days, including location history. An app that a device stops reporting — because it was uninstalled — is removed from our records on the same 90-day clock. Deleting a device or child profile removes its rules, app list and usage history. If your account is deleted — by you, or after termination — it is retained for a 30-day grace period (so an accidental deletion can be undone) and then permanently erased. Contact-form messages are kept for as long as needed to handle your enquiry.

7. Your rights

Under UK GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Write to us via the contact form and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

8. Changes

If we change this policy we will post the new version here and, for significant changes, tell you by email. This version is effective 5 September 2026.