Privacy

Privacy Policy

Effective: October 1, 2026

MomenTap helps people manage their own habits when using apps and websites. It does not create user accounts and does not include advertising, analytics, or tracking SDKs.

1. Data Collected by the Developer

The current version of the App itself does not automatically transmit personal information or usage data to the developer or third-party servers, nor does it collect that data for them. Optional public support issues and email inquiries submitted outside the App are described separately in Section 6. The App does not require an account, name, email address, or contacts. It does not send your selected apps, categories, or websites, your written purpose, or detailed usage records to the developer. It does not use advertising identifiers, track activity across other companies’ apps or websites, or use third-party advertising or analytics services.

2. Data Processed on the Device

In the internal test candidate, when a website protection screen offers a way to open temporary access settings, one opaque website token, a request identifier, a timestamp, and a request-format marker are temporarily shared between the app and its extensions. Temporary access starts only after you confirm your purpose and duration in the app. This request does not store a website address, individual page, or purpose text. Request files are excluded from device backups and removed when consumed or when app data is reset. This does not guarantee that Safari displays the custom shield; the existing option for temporary website access in the Protection tab remains available.

In earlier versions that provide the diagnostics menu, when you start Shield diagnostics in Settings, host storage checks and app, website or category button callback types, a random diagnostic identifier and timestamps are stored in the app-and-extension shared area on this iPhone for a five-minute recording window. Diagnostics are off by default. App names, website addresses, Screen Time tokens, purpose text, statistics and actual visit or usage counts are not recorded or automatically transmitted. Only one entry per event type is retained. Recording stops five minutes after starting. Results are deleted on the next app launch or diagnostic refresh after 24 hours, or when you start a new diagnostic, delete diagnostic results or reset all app data. Files are excluded from device backups and use iOS Data Protection. You may choose to capture the results screen for a support request. This optional technical diagnostic does not change existing choice history or protection settings. Starting with internal test Build 16, shield configuration callbacks are not recorded to files. Fixed diagnostic markers on shields are display-only text, independent of five-minute recording; neither markers nor configuration results are stored or transmitted. Configuration diagnostic records from earlier builds are no longer displayed and follow the same retention and deletion rules.

Starting with Build 24, Settings no longer provides the Shield diagnostics menu, and you cannot start a new diagnostic or view its results in the App. Diagnostic records already saved by earlier versions are cleaned up on the next app launch or return to the foreground after 24 hours from their start, or when all app data is reset. The existing five-minute recording limit, backup exclusion and no-automatic-transmission rules still apply.

In versions with appearance settings, only your choice of System, Light or Dark is kept in this iPhone's standard app preferences. The default is System, and a successful reset of all app data restores that default. The appearance preference contains no behavior history or Screen Time selection and is not passed to shared app-and-extension storage, widgets, Live Activities or developer servers. Simple UI preferences, such as appearance and the last selected tab, may be included in operating-system device backups depending on device settings. This is separate from the backup exclusion for selection-token and history files described below and does not provide app-managed iCloud synchronization or history restoration.

The App may store opaque application, category, and directly selected website tokens supplied by Apple Screen Time; the last protection on/off Boolean used to decide whether protection should be restored after authorization is granted again following a reboot; an opaque application or WebDomain token, request and session identifiers, and timestamps needed for temporary access and restoration of Shield protection for one exact application or one exact website directly chosen in MomenTap; state needed for the Lock Screen and Dynamic Island countdown; and random identifiers, timestamps, planned expiration time, and end reason for intentional temporary access and choices not to open an app out of habit after the user enables on-device choice history. The protection-intent setting contains no selection token, target name, timestamp, or behavior history.

Random generation identifiers, sequence values, dispositions, and a monotonic system-uptime snapshot coordinate callback ownership and prevent a late system restoration callback from changing an earlier target after completion, authorization loss, or reset. This safety metadata does not contain an application or website token, plaintext domain or URL, or typed purpose.

On-device history is off by default. The first Start On-Device History action enables aggregate choice history without target identities. Per-app and per-website history are separate opt-ins available in History or Settings and apply only to choices recorded after each opt-in; earlier aggregate records are not retroactively linked to a target. Behavior events contain only a random target reference, while the link between that reference and an opaque application or WebDomain token is kept in a separate on-device file. The App does not interpret a token as an app or website name; Apple's system label renders the display information.

Purpose category recording

In versions with purpose category recording, this setting is on by default for both new and existing users. Your existing overall recording setting is preserved. Only while overall history is enabled, the App saves one category selected when starting temporary access—contact someone, look something up, get something done, take a short break, or write my own—in the App's storage on this iPhone. Even when you select Write My Own, written text is used only on the current screen and is never saved or shared. These categories summarize how often you allowed access and how long protection was lifted. They do not measure actual usage or whether a task was completed. Past purposes are not inferred.

Turning purpose recording off in Settings deletes only saved categories after confirmation, preserving overall, app and website history. Turning it back on does not restore deleted categories. Turning overall recording off also stops new purpose records but keeps existing categories for the selected retention period. History deletion, full app-data reset and retention apply to categories as well. Purpose categories are not shared with widgets, Live Activities or shared app-and-extension storage (App Group), or transmitted to developer servers. Overall recording remains off by default, and app and website history remain separate opt-ins.

Local history also keeps the times when recording was turned on and off for the same retention period as choice history. This device-only state distinguishes a true zero from a period when recording was off; it contains no app or website token or target name. Migration to schema v6, which adds the retention setting, preserves existing history and consent and keeps the 90-day default. Earlier empty periods are not inferred to be recorded zeros.

In versions that provide a Home Screen widget, a minimal summary is stored in an area on this iPhone accessible to the app and widget. It contains today’s overall counts of choices to allow access or not open an app out of habit, recording status and coverage, the date range and time zone, and the last aggregation time. Adding a widget does not enable choice recording, which is off by default. A new summary made while recording is off does not retain counts from existing history. The widget summary does not contain app or website names, selection tokens, entered intentions, individual behavior records, or actual usage duration. Original history remains in the app’s own storage.

The widget reflects the app’s last aggregation and may not include recent actions. Turning recording off, deleting history, resetting all app data, or changing retention clears the previous summary and requests a display update. If summary cleanup fails, the app continues the requested stop or deletion of original history and retries summary cleanup; it reports an error if cleanup still fails. A new summary may be generated from the resulting settings and remaining history. Immediate removal of a widget display already cached by iOS is not guaranteed. Summary files are excluded from iCloud and device backups and are not sent to a server. The app itself does not add network transmission or cloud synchronization for the widget.

Widget versions with total access time and recent seven-day summaries keep today's total access time, daily counts of choices to allow access or not open an app, and recording coverage for seven consecutive days including today in shared app and widget storage on the same iPhone. They aggregate existing local records saved with your consent without collecting new behavior data. Total access time is the elapsed time with Shield protection lifted, as of the last aggregation. It is not actual app or website usage time or time saved. Unrecorded and partially recorded days are distinguished from confirmed zero counts, and older summaries without a time value are not assumed to be zero. Changes while the app is not opened may not yet be reflected. When recording is off, counts and time values are not displayed and the previous seven-day summary is not shared. Summaries exclude raw events, app or website names, and tokens; they are excluded from device backups and are not sent to a server. Existing consent, summary cleanup and retry behavior after deletion or reset, and iOS display-cache limitations continue to apply.

When history is enabled and the user chooses I opened it out of habit on a Shield, a dedicated area shared by the App and its extension briefly stores consent state, a random event identifier, and a timestamp. It adds the exact opaque application token only while per-app history is also enabled, and deletes the item after import.

The App does not store app names, plaintext domains, URL paths or pages, Screen Time app category names, written purpose text, or raw Screen Time usage records. Per-app statistics count choices made in MomenTap to allow access or not open an app. They do not measure the time actually spent in each app. Per-website statistics show the number and end status of temporary access sessions started in MomenTap, along with the elapsed time while protection was lifted. They do not establish that a website was visited or measure browsing time. Total access time is the time Shield protection was temporarily lifted, not actual app or website usage time. A purpose typed by the user remains in memory only while the relevant screen is active and is not saved to a file.

In Safari, selected websites remain displayed with Apple's standard Restricted page and OK button; MomenTap's custom actions are not shown there. Temporary website access is started separately in MomenTap's Protection tab, where the user chooses one directly selected website and a 5-, 10-, or 15-minute duration. The App does not open a browser automatically, and other selected websites and categories remain protected while temporary access is active. The App stores only the exact opaque WebDomain token and session identifiers, timestamps, and state required to restore protection in an App-and-extension-only area on the device. If aggregate on-device history is enabled, temporary access may be recorded without a target identity. Only when per-website history is also enabled does the App distinguish subsequent temporary access sessions started in MomenTap using a random local reference and a separate opaque WebDomain-token index. It does not record a plaintext domain, URL, path, individual page, typed purpose, habitual-stop action from Safari's Shield, actual visit, or browsing duration. Website consent and token links created by earlier test builds are deleted during the schema-v4 upgrade while aggregate and per-app history remain intact, so the new per-website history opt-in is not enabled automatically.

3. Apple System Services

Application, category, and website selection, Shields, Device Activity, Live Activities, and Home Screen widgets use system features provided by Apple. The user grants Screen Time authorization directly and can revoke it in iPhone Settings. Apple’s public APIs do not guarantee identical protection for every subdomain or browser. The App does not store or treat URL paths or individual pages as protection units. Apple’s privacy policy and device settings apply to Apple’s processing of these system features.

Optional one-time payments to support the developer are processed by Apple’s StoreKit and App Store payment system. The developer cannot access payment-card or other payment-method details. The App does not save transaction identifiers, receipts, a history of support payments, or a supporter profile in files or on the developer’s servers. Choosing whether to support the developer does not affect the features, content, or customer support you receive.

4. Retention and Deletion

Active session state is deleted after the session ends or expiration cleanup succeeds. Temporary access state that contains a target token and callback-coordination files are deleted after safe cleanup for consumption, expiration restoration, manual ending, authorization loss, or reset succeeds. If cleanup is interrupted or an in-progress callback cannot be distinguished safely, the App may temporarily retain the state and retry cleanup on a later run instead of reopening access. A minimal random terminal epoch, sequence, and disposition tombstone is replaced and retained on the device after reset solely to reject late system callbacks; it contains no application or website token, domain, URL, purpose, or behavior history.

After a reboot, the system may temporarily report authorization as Not Determined or Denied for an existing protection-on configuration. The App therefore does not delete application, category, or website selections based only on a passive authorization check. It deletes the selection and protection-intent setting when the user explicitly denies an authorization request inside the App, clears the selection, or resets all App data. After authorization succeeds again, the App reapplies a saved selection whose protection intent was on. Choice history is kept for 90 days by default. Versions with the retention setting let you choose 180 days, one year (365 days), or forever (until you delete it) in Settings. The same window applies to overall, app and website history, referenced token links, and recording on/off intervals. Existing users keep 90 days unless they choose a longer period.

Shortening the window deletes older records and identity links used only by those records after confirmation. Extending it cannot recover deleted history. Finite retention still applies while recording is off; expired records are cleaned up when the app loads or adds history, not at a guaranteed background deadline.

Forever only disables age-based deletion. Existing rules for removing identity links when per-app or per-website history is disabled or authorization loss is confirmed, deleting history, and resetting all app data still apply. Clearing history keeps the selected retention period; resetting all app data restores the 90-day default. History remains on this iPhone. iCloud sync and restoration after app deletion or device loss are not available, and history files are excluded from iCloud and device backups.

Pausing history keeps existing aggregate records while stopping new records. Disabling only per-app or per-website history, or confirmed loss of Screen Time authorization, removes the corresponding token links and attribution while preserving aggregate counts. Screen Time selection-token files, choice history and target-token indexes, shared temporary access state and restoration-coordination metadata, diagnostic files and widget summaries are excluded from backup and use iOS Data Protection. Section 2 explains the separate possibility of operating-system backup for simple UI preferences. Resetting App data leaves only the target-free safety tombstone described above and does not revoke the system Screen Time authorization itself.

5. Sharing and Sale

Because the App does not transmit user data to the developer or third parties, it does not sell or share user data for advertising.

6. Website and Optional Support Requests

These company, support, and privacy pages are hosted on Cloudflare Pages. Cloudflare may process technical data such as IP addresses and request information to serve and protect the website under its own policy. No separate analytics or tracking scripts or input forms have been added to this site. Cloudflare processing is governed by the Cloudflare Privacy Policy.

Users may optionally request help through public issues on the external GitHub service. A GitHub username, submitted content, and submission time will be public and may be accessed by the developer for customer support. The App does not transmit this information automatically. Do not include personal information, app, category, or website names, URLs, Screen Time selections or tokens, Apple account information, or device identifiers in a public issue. GitHub processing is governed by the GitHub General Privacy Statement.

If you contact the developer by email, the developer can access your sender email address and the message you submit to respond to your inquiry. Mail is received through iCloud Mail and the Apple Privacy Policy also applies. The App does not send email or support information automatically. Do not email sensitive information such as Screen Time tokens.

7. Children’s Privacy

The App is a self-management tool, not a parent-child supervision service. It does not collect user accounts or personal information.

8. Changes to This Policy

If server sync, analytics SDKs, or new data processing are added, this policy and the App Store privacy disclosure will be updated before those features are released. Material changes will be reflected by updating the effective date.

9. Contact

For privacy questions, email contact@ianji.net. You may also use a public support issue. Do not include personal information or Screen Time selections in a public issue.