Privacy Policy
Last updated:
Router ("we", "us", "our") is a screen-time intervention app for iOS. This policy explains what data we collect, why, and how it's protected. We are the data controller for the purposes of UK GDPR and the Data Protection Act 2018.
Contact: aj@tryrouter.co / AJP Technologies, 1 Church Square, Leighton Buzzard, LU7 1AE, UK
1. Data We Collect
1.1 Usage Telemetry
When you interact with Router's interception flows, we collect telemetry about your interactions with intercepted apps to build a model of usage patterns and analyze the quality of our product's digital wellness impact.
This data is pseudonymised— it is linked to a confidential key derived, server-side, from your device's App Attest credential, independent of your Apple account. This key is only ever linked to your account identifier for the specific purpose of fulfilling a data subject access request (see Section 6); it is not used to combine telemetry with your account for any other purpose. Because this key allows us to re-link data back to you on request, this data is not legally "anonymous" under UK GDPR — it remains personal data, and this policy (and your rights under Section 6) apply to it.
1.2 Account Information
Signing in with Sign in with Apple is required to use Router.
We receive and store account information (your stable Apple-issued identifier, and email/display name if Apple provides them). This is held in a system entirely separate from usage telemetry. The only link between the two is your account identifier, and it is used solely to locate and act on a data subject access request (export, correction, deletion) — never to attach identity to analytics. Your email is used only for product purposes (account recovery, replying to support requests you send us); it is not used to identify or link telemetry, purchase, or crash-diagnostic activity back to you for any analytical purpose.
1.3 App/Website Catalog
Two related but distinct flows:
- Submitting a new app or link.If you submit an app or website to expand our catalog, we process it — along with your device model, OS version, app version, and device key — to validate and add it. This requires an active account (for attribution and rate-limiting) and consent given at the point of submission, where we tell you exactly what's sent.
- Searching or looking up the existing catalog.This is necessary for the app's core function of recognising apps you already use, so it isn't gated by consent — it happens regardless of your other privacy choices, the same way the app couldn't work if it declined to load your installed-apps list. It's still processing of a device-linked identifier, so it's disclosed here rather than treated as invisible.
1.4 Entitlement Records
Router does not yet sell anything through the App Store — In-App Purchase isn't wired up in this version. However, when a feature is unlocked for your account, we already record that grant against your identity in an internal entitlement ledger, so that turning on billing later doesn't require a redesign. This record is retained for 6 years, even if you delete your account, because it may be needed to resolve a future billing dispute (see Section 8).
1.5 Crash Diagnostics
We use Sentry to catch and diagnose crashes. No identity information is attached to these reports (no name, email, or account identifier), and Sentry does not receive your Apple identity. However, crash reports can include contextual detail like which app was intercepted at the time or which screen you were on — this is content-level detail, not identity, but it's still worth knowing it's there. Sentry data is hosted in the EU.
Crash diagnostics are on by default for all users, adult and under-18 alike, and can be turned off in Settings (opt-out). This is the one setting not restricted for under-18 users — everything else described in Section 7 is.
1.6 Support & Feedback
If you send us a bug report, feature request, or general feedback through the app, your message is delivered via our backend to our support inbox. We do not store the content of your message — it passes through our systems but isn't logged. We do keep a minimal record of the fact that you sent something (your account identifier, the type of message, and the time), solely to enforce a rate limit and prevent abuse; this record is deleted if you delete your account. Your email address is used only to let us reply to you. Your app version, OS version, and device model are included so we can diagnose your issue.
This requires an active account, and sending a message is unaffected by your analytics or crash-diagnostics settings — it's correspondence you've chosen to send us, not passive telemetry, so it isn't gated by those toggles.
2. Data We Do Not Collect or Process Off-Device
The following stay entirely on your device and are never transmitted to our servers:
- Authentication credentials— handled by Apple's Sign in with Apple / Face ID / Touch ID, on-device.
- Private intentions — any reflective notes, reasons, or personal context you enter during an intervention flow stay local to your device.
- Date of birth — collected for on-device age-appropriate configuration only, never transmitted off-device.
- Emotional entry point selection— which route you choose before an intervention (anxiety, boredom, dread, loneliness, killing time) is used to power your own in-app savings and behaviour dashboards, entirely on-device. It is never sent to us. If you're signed out entirely, none of your interception activity reaches our servers at all — see Section 6.
3. Legal Basis for Processing
Under UK GDPR, we rely on:
- Contract (Art. 6(1)(b)) — account creation, entitlement records, delivering core app functionality, including catalog lookups necessary for the app to work.
- Legitimate interests (Art. 6(1)(f)) — usage telemetry for wellness reporting and product improvement (adults, opt-out), and crash diagnostics for all users regardless of age (opt-out), balanced against your right to privacy, and always pseudonymised.
- Consent — usage telemetry is never offered to under-18/unknown-age users, full stop (see Section 7). Catalog submissions also rely on consent given at the point you submit. We do not currently collect any Article 9 special category data — the emotional entry point field stays on-device only (see Section 2) — so no Art. 9 basis is presently engaged; if that changes, this policy will be updated before it does.
4. Data Separation & Security
- PII (account data) is stored separately from usage telemetry. The only link between them is your account identifier, used exclusively to fulfil data subject access requests — not for routine analytics.
- Data is encrypted in transit and at rest.
- Access to systems capable of re-linking telemetry to identity is restricted to personnel who need it to operate or support the service.
5. International Data Transfers
Data is primarily stored on servers located in the UK/EU. Sentry (crash diagnostics) is confirmed EU-resident, so no transfer occurs for that processor. For our other US-based managed infrastructure providers, data may still be transferred to, or transit through, servers in the United States. Where this occurs, transfers are governed by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent recognised mechanism such as the EU-US Data Privacy Framework's UK extension, incorporated into our agreements with each processor below.
6. Your Rights
Subject to UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction or deletion
- Object to or restrict certain processing
- Data portability
- Withdraw consent at any time (where processing is consent-based)
- Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk
To exercise these rights, contact us at aj@tryrouter.co. In practice: if you've never been signed in, or you're currently signed out, your activity is recorded only on your device and never reaches our servers at all, so there's nothing server-side for us to locate. The one exception is a small window of historical data from an earlier beta period, collected before this design was in place, which cannot be attributed to any individual and is scheduled for deletion rather than being held indefinitely. Once you're signed in, we use your account identifier — never a raw telemetry key — to locate everything associated with you.
7. Children
Router may be installed and used by children, and no data specifically identifying or sensitive to children is knowingly created, processed, or delivered through the app.
Because Router is "likely to be accessed by children" in the ICO's terms, it falls in scope of the UK Age Appropriate Design Code (Children's Code), regardless of whether it's marketed at children. In practice this means:
- For adults: usage analytics and crash diagnostics are both on by default, and each can be individually turned off in Settings (opt-out).
- For under-18 and unknown-age users: usage analytics is never offered and nothing is ever collected or transmitted about app usage — there is no toggle, because there is nothing to toggle. Crash diagnostics remains on by default and can be turned off, the same as for adults — the reasoning is that an app whose crashes we can never see for a child specifically gives that child a worse, buggier experience, which cuts against their interests rather than protecting them.
- No profiling or telemetry-driven "nudging" is used to encourage engagement beyond the wellness purpose of the app.
- No use of usage data for advertising, and no sharing with data brokers.
- Geolocation is not collected.
- Parental-control context (FamilyControls) is used only for its intended screen-time purpose.
8. Data Retention
- Account data: retained while your account is active, and for 90 days after deletion to allow for recovery and to complete any in-progress dispute or support request, after which it is permanently erased.
- Usage telemetry: retained on a rolling basis for 24 months from creation, after which granular records are deleted.
- Device pseudonymisation key (attest key): not linked to your account. The key itself lives in the device's Secure Enclave and is destroyed when you uninstall the app; a reinstall is issued a fresh key.
- Entitlement records: retained for 6 years following account deletion, for the purpose of resolving billing disputes — the same statutory basis as ordinary financial recordkeeping (Companies Act 2006 / HMRC guidance).
- Consent receipts: retained for 6 years on the same dispute-resolution and lawfulness-evidence basis as entitlement records, even past account deletion — this is what lets us demonstrate that processing was lawful if it's ever questioned.
- Catalog submission metadata (app version, OS version, device model): retained indefinitely to support long-term product quality. The device key attached to a submission is redacted after 24 months, so what remains is not linked back to a specific device.
- Support send-stamps: deleted on account deletion; no independent retention window needed since no message content is stored.
- Apple credential retry window:if the deletion process's required call to revoke your Apple credential fails, we retain it for up to 30 days to retry before giving up and purging it regardless.
9. Third-Party Processors
We use the following third parties to operate Router, each acting as a data processor under contract:
- Apple (Sign in with Apple, FamilyControls/DeviceActivity, In-App Purchase — not yet live)
- Vercel — hosting/functions
- Neon — database
- Resend — delivers the support/feedback messages you send us to our inbox; note that sent messages also sit in Resend's own dashboard/logs, so their retention practices apply alongside ours
- Sentry — crash reporting and bug diagnostics, EU-hosted
9a. Cookies & Similar Technologies
The Router app and the tryrouter.co website do not currently use cookies or similar tracking technologies. If this changes in future (e.g. website analytics), we'll update this policy and, where legally required, request your consent via a cookie banner before any non-essential cookie is set.
10. Changes to This Policy
We'll update the "last updated" date above and, for material changes, notify you via the app or email.