Privacy policy

Last updated [DATE] · Applies to the Jolt Android app and this website.

Draft — not yet reviewed. This document was written from the app's source code and is accurate to what the software does, but it has not been reviewed by a lawyer and contains placeholders in square brackets. Delete this box before publishing.

The short version

Jolt watches how long you spend in the apps you choose to track. By default that information is read by your phone, stored on your phone, and never sent anywhere. There is no account to create and no server involved.

Two optional features change that, and only because they cannot work otherwise: sync, which copies your settings between your own devices, and supervision, which lets one person you invite manage your limits and see your usage. Neither is on unless you turn it on.

Who we are

Jolt is provided by [YOUR ENTITY], [YOUR ADDRESS]. For anything in this policy, contact [YOUR SUPPORT EMAIL]. [If you have an EU/UK presence or representative, name them here.]

What the app reads on your device

Jolt asks for each of the following separately, and explains why before it does. It works, with reduced function, if you decline any of them.

PermissionWhat it is used for
Usage access Reading how long each app has been in the foreground. This is the measurement the entire app is built on.
Accessibility service Knowing which app is in front of you right now, so a nudge or a block can be timed to it. Jolt reads only the package name of the foreground window. It does not read screen contents, text fields, or anything you type.
Draw over other apps Showing the block screen on top of an app that has hit its limit.
Notifications Check-in nudges, lockout alerts, and the ongoing notification Android requires for a background service.
Installed app list Offering you a list of apps to track. While supervised, this list is also shared with your supervisor so they can set limits for apps you have not configured yourself.
Vibration, run at startup, battery exemption Buzzing for nudges, restarting tracking after a reboot, and not being killed mid-day by power management.
Modify system settings (optional) Turning the whole phone greyscale during a lockout. This can only be granted from a computer over adb; without it, only the block screen goes grey.

What stays on your phone

With no account, everything Jolt knows is held in your phone's local app storage and is removed when you uninstall the app:

None of this is transmitted. Jolt has no advertising identifiers, no crash reporting, and no third-party SDK that reads your usage. The one thing it does send is anonymous product analytics, described next, which you can switch off.

Anonymous usage statistics

To understand which parts of Jolt are used and where it breaks, the app sends anonymous events to PostHog, an analytics service. An event contains:

Autocapture, screen views, session replay and person profiles are all switched off. You can turn the whole thing off in Settings → Privacy → Share anonymous usage statistics; when it is off, the SDK itself is opted out and nothing is sent. Usage data is kept for 12 months and then deleted.

On a supervised device this is off entirely, whatever the switch says. A supervised phone is often a young person's, and the person who set it up is not the person whose consent it would be — so we do not ask for it and do not collect.

What leaves your phone, and when

If you turn on sync

Signing in creates an account identified by your phone number. The following is stored in Google Firebase on your behalf so your own devices agree with each other:

If you accept supervision

Supervision links your account to one supervisor, by a code they give you. Before you accept, the app lists exactly what this shares. From then on, and until you leave, your supervisor can see:

Your supervisor can also receive a daily or weekly summary of the above by email, if they have a verified email address on their account.

You can leave at any time, from the app, without their permission. Your supervisor is notified when you do, your shared app list is deleted, and your device stops reporting. Your supervisor can likewise remove you.

What Jolt never collects

Not in any mode, with or without an account:

Who else processes your data

Only when you use an account feature:

Two more, which apply whether or not you have an account:

We do not sell your data, share it with advertisers, or use it to train anything.

Children and supervised users

Jolt is designed to be used by one person on their own phone, or by a parent or guardian supervising someone in their care.

You must be at least [13 / 16 — the age of digital consent where you live] to create a Jolt account. If you supervise someone who is under that age, you confirm you are their parent or legal guardian, or that you have that person's guardian's consent.

A supervisor must confirm, before an invite code can be created at all, that they are the supervised person's parent or guardian or that the person has agreed; the rule is enforced on our servers, not just in the app. A supervised person is always shown what is shared before they accept, and can end supervision at any time from their own device. We do not knowingly collect data from a child without a guardian's involvement. If you believe we have, contact [YOUR SUPPORT EMAIL] and we will delete it.

How long it is kept

Local data lives on your phone until you delete it in the app or uninstall Jolt.

Account data is kept while your account exists. Daily usage records are deleted automatically after 90 days — nothing in Jolt reads further back than that, so there is no reason to keep them. Invite codes expire after seven days and are deleted when the link they created ends. Deleting your account removes everything immediately.

Your choices

If you are in the UK or EU, you also have the right to object to processing, to restrict it, and to complain to your data protection authority. Our legal basis is your consent for account features, and legitimate interest in providing the app you installed for the rest.

This website

takeajolt.app is a static site on Firebase Hosting, which logs requests — including network addresses — for operational purposes under Google's terms. The site counts page views and clicks on the store button with Umami, an open-source analytics tool we host ourselves. It sets no cookies, stores no network addresses, and cannot follow you to other sites; it records the page, the referrer, your browser and your country, and nothing that identifies you.

Security

Account data is protected by Firebase security rules that restrict each account to its own records and give a supervisor access only to the wards who accepted their invite. Traffic to Firebase is encrypted in transit. No system is perfect, and you should not store anything in Jolt you would be harmed by losing.

Changes

If this policy changes in a way that affects what we collect or who sees it, we will say so in the app before the change takes effect.

Contact

[YOUR SUPPORT EMAIL] — questions, requests, or anything that looks wrong.