Privacy policy

Your hours are yours.

— “I watch the clock, not you.”

Last updated: August 2026

Your screen-time data never leaves your iPhone.

Sage Fox is built on Apple's Screen Time framework (FamilyControls, DeviceActivity, and ManagedSettings). All usage measurement happens on your iPhone, inside Apple's system. Those totals are never uploaded, synced, or shared — not with us, not with anyone. No analytics service sees them, and the numbers you watch in the app are rendered by Apple's own component, out of our reach.

We can't see which apps you guard.

When you choose apps for Sage to watch, Apple hands the app opaque tokens — not app names or identifiers. This is a deliberate property of the Screen Time API: even Sage Fox itself cannot tell which apps you selected, and neither can we.

Game results stay local too.

Your duels against the fox — wins, losses, attempts per day — are counted only on your device, so the app can show you today's record. These counters never leave your phone.

We do measure how the app itself is used.

To learn which parts of Sage work and where people get stuck, the app collects anonymous product analytics. This is deliberately narrow, and it never touches anything above.

What we collect:

  • Which screens you reach and finish, and where you stop.
  • Whether you granted Screen Time and notification permission — the outcome, never what you chose to guard.
  • How many apps you selected: a count, never their identities.
  • The daily limit you set, in minutes.
  • Paywall views, and which plan you subscribe to.
  • App opened, installed, or updated.
  • With each event: your device model (for example “iPhone16,2”), iOS version, app version, and install date.

What we don't collect: your name, your email, any account (there isn't one), which apps you guard, anything you do inside them, your screen-time totals, your game history, screen recordings, or automatic capture of your taps and screen names. Those are switched off by design, or impossible for us to see in the first place.

You stay anonymous. Events are tied to a random identifier created on your phone — never to you. We never ask our analytics provider to attach an identity to it. Before anything is sent, a filter on the device drops any property whose name looks identifying.

Where it goes. Our processor is PostHog, on their EU Cloud, under a data-processing agreement. The data stays in the EU. As with any request over the internet, the connection carries your IP address; it is not stored against a name or an account, because there is no account. We keep these events no longer than we need them for the product decisions above.

Why we're allowed to. Our lawful basis is legitimate interest — improving a product you're actively using — and you can withdraw at any time, in one tap.

We measure whether our ads work.

We tell people about Sage Fox with ads — today, on TikTok. To know whether those ads bring anyone in, the app includes TikTok's measurement SDK, which reports a handful of moments back to TikTok: that the app was installed and opened, and that a subscription started — which plan, its price, and the currency. Each report carries basic facts about the device (model, iOS version, language), a device-level identifier Apple scopes to this app alone (the “identifier for vendor”), and — as with any request over the internet — your IP address.

What it never carries: the same things as everything above. Your screen-time totals, your guarded apps, and your game history never leave the phone, and your name and email can't be sent because we don't have them.

No tracking permission, no advertising identifier. We never show Apple's “allow tracking” prompt and never touch the cross-app advertising identifier (IDFA). Campaign results reach us through Apple's SKAdNetwork, which reports in aggregate.

The honest difference from our analytics. PostHog acts only on our instructions. TikTok does not: it also processes these events for its own purposes — measuring our campaigns and improving its advertising products — as an independent controller, under the TikTok Business Products (Data) Terms and TikTok's privacy policy. That processing can happen outside the EU.

Why we're allowed to. Legitimate interest again — measuring advertising we pay for — and the same one-tap switch below withdraws it.

This website, too. sagefox.app can carry TikTok's web pixel, which tells TikTok that a page here was viewed. That report includes the page address, your IP address, and browser details, and the pixel sets a TikTok cookie (named a TikTok cookie (_ttp) in your browserldquo;_ttpa TikTok cookie (_ttp) in your browserrdquo;) in your browser so a visit can be connected to an ad you saw. TikTok processes this under the same terms linked above. The pixel sees nothing from the app: it runs only in your browser on this site, and it never learns your screen-time data.

We ask first. If you visit from the EEA, the UK, or Switzerland, the pixel does not run — and nothing is sent to TikTok — until you choose Allow in the banner; No thanks is one tap and changes nothing about the site. Your choice is kept in your browser's local storage for up to a year, and you can change it any time via Cookie settings in the footer of every page — withdrawing consent stops the pixel and removes its cookie. Elsewhere the pixel runs by default and the same footer link switches it off. We also honor the Global Privacy Control signal: if your browser sends it, the pixel never starts. Where the pixel runs by consent, that consent is the legal basis; where it runs by default, it is our legitimate interest in measuring advertising we pay for.

Turning it all off.

Open Sage → SettingsPrivacy & supportShare anonymous analytics. Switch it off and both SDKs — product analytics and TikTok's ad measurement — aren't merely silenced: they are never started. From that moment nothing is collected and nothing is sent.

Subscriptions go through Apple.

Purchases are processed by the App Store, and subscription status is managed through RevenueCat, our billing provider. That involves an anonymous app-user identifier and your purchase state — never your screen-time data, your guarded apps, or your game history. We don't receive your name, email, or payment details.

So we can tell which parts of the app lead people to subscribe, your anonymous analytics identifier is attached to your anonymous RevenueCat record. That links two anonymous identifiers to each other; it does not attach a name to either. Opting out of analytics stops this too.

Notifications are quiet and local.

Sage sends at most a gentle local reminder — for example, a morning nudge to set today's limit. These are scheduled on your device; there is no push-notification server.

Your choices and your rights.

The switch described above is the main one, and it takes effect immediately. Beyond that: Sage Fox has no accounts, so there is no profile to log into, export, or close, and deleting the app ends all collection permanently.

If you are in the EU or UK, the GDPR gives you rights of access, correction, erasure, and objection. Write to hello@sagefox.app and we'll help. One honest caveat: because analytics events carry only a random identifier and nothing that points back to you, we usually cannot tell which stored events are yours. Where we genuinely can't identify you, the GDPR does not require us to guess (Article 11) — so the reliable remedy is the opt-out switch, which stops collection at once. You can also complain to your local data protection authority.

Children.

Sage Fox is not directed at children under 13, and we don't knowingly collect data from them.

If this policy changes.

We'll update the date at the top and describe what changed. Material changes will be called out in the app before they take effect.

Questions?

Write to us at hello@sagefox.app — that address reaches the people responsible for this policy, and we'll answer plainly.