Privacy policy
Draft — not yet reviewed. This document was written from the app's source code and is accurate to what the software does, but it has not been reviewed by a lawyer and contains placeholders in square brackets. Delete this box before publishing.
The short version
Jolt watches how long you spend in the apps you choose to track. By default that information is read by your phone, stored on your phone, and never sent anywhere. There is no account to create and no server involved.
Two optional features change that, and only because they cannot work otherwise: sync, which copies your settings between your own devices, and supervision, which lets one person you invite manage your limits and see your usage. Neither is on unless you turn it on.
Who we are
Jolt is provided by [YOUR ENTITY], [YOUR ADDRESS]. For anything in this policy, contact [YOUR SUPPORT EMAIL]. [If you have an EU/UK presence or representative, name them here.]
What the app reads on your device
Jolt asks for each of the following separately, and explains why before it does. It works, with reduced function, if you decline any of them.
| Permission | What it is used for |
|---|---|
| Usage access | Reading how long each app has been in the foreground. This is the measurement the entire app is built on. |
| Accessibility service | Knowing which app is in front of you right now, so a nudge or a block can be timed to it. Jolt reads only the package name of the foreground window. It does not read screen contents, text fields, or anything you type. |
| Draw over other apps | Showing the block screen on top of an app that has hit its limit. |
| Notifications | Check-in nudges, lockout alerts, and the ongoing notification Android requires for a background service. |
| Installed app list | Offering you a list of apps to track. While supervised, this list is also shared with your supervisor so they can set limits for apps you have not configured yourself. |
| Vibration, run at startup, battery exemption | Buzzing for nudges, restarting tracking after a reboot, and not being killed mid-day by power management. |
| Modify system settings (optional) | Turning the whole phone greyscale during a lockout. This can only be granted from a computer over adb; without it, only the block screen goes grey. |
What stays on your phone
With no account, everything Jolt knows is held in your phone's local app storage and is removed when you uninstall the app:
- Which apps and categories you track, and the limits and schedules you set
- Today's per-app minutes and your recent daily totals
- Your relax sessions, and how many you have started today
- Your settings, including language and theme
None of this is transmitted. Jolt has no advertising identifiers, no crash reporting, and no third-party SDK that reads your usage. The one thing it does send is anonymous product analytics, described next, which you can switch off.
Anonymous usage statistics
To understand which parts of Jolt are used and where it breaks, the app sends anonymous events to PostHog, an analytics service. An event contains:
- What happened — "app opened", "limit set", "relax session started", "lockout shown". Never the name of an app you track, never how long you spent in it, never a limit you set.
- A random identifier created on first launch. It is not tied to your name, phone number or device identifiers, and it is replaced if you reinstall.
- Device model, operating system version, app version and language.
- A coarse location — country or region — that PostHog derives from the network address of the request. We do not store the address.
Autocapture, screen views, session replay and person profiles are all switched off. You can turn the whole thing off in Settings → Privacy → Share anonymous usage statistics; when it is off, the SDK itself is opted out and nothing is sent. Usage data is kept for 12 months and then deleted.
On a supervised device this is off entirely, whatever the switch says. A supervised phone is often a young person's, and the person who set it up is not the person whose consent it would be — so we do not ask for it and do not collect.
What leaves your phone, and when
If you turn on sync
Signing in creates an account identified by your phone number. The following is stored in Google Firebase on your behalf so your own devices agree with each other:
- Your phone number, and an email address and display name if you add one
- Your settings, tracked apps, limits, schedules and categories
- Per-day, per-app minutes, and your device's UTC offset so a day is counted in your local time
If you accept supervision
Supervision links your account to one supervisor, by a code they give you. Before you accept, the app lists exactly what this shares. From then on, and until you leave, your supervisor can see:
- Which apps you use and for how long, by day
- Apps you install and apps you remove
- Whether your phone is still reporting — the app checks in roughly every 15 minutes, and a gap of about a day and a half raises an alert
- How many relax sessions you have used against the allowance they set
- Your display name and the last four digits of your phone number — never the whole number — and the list of apps installed on your phone
Your supervisor can also receive a daily or weekly summary of the above by email, if they have a verified email address on their account.
You can leave at any time, from the app, without their permission. Your supervisor is notified when you do, your shared app list is deleted, and your device stops reporting. Your supervisor can likewise remove you.
What Jolt never collects
Not in any mode, with or without an account:
- Your location
- The contents of messages, emails, calls or notifications
- Anything you type, including passwords — Jolt does not read text fields
- Screen contents, screenshots or recordings
- Photos, files, contacts, calendar, microphone or camera
- Web browsing history or activity inside other apps beyond the time spent in them
Who else processes your data
Only when you use an account feature:
- Google (Firebase) — authentication, database and server functions. Data is held in Google Cloud in [REGION]. Google acts as our processor.
- Resend — delivery of summary and alert emails to supervisors.
- Google Play — distribution of the app. Google's own handling of your Play account is covered by Google's privacy policy, not this one.
Two more, which apply whether or not you have an account:
- PostHog — the anonymous usage statistics described above, unless you have switched them off.
- Umami — page views on takeajolt.app, described under "This website" below. It is self-hosted, sets no cookies and stores no network addresses.
We do not sell your data, share it with advertisers, or use it to train anything.
Children and supervised users
Jolt is designed to be used by one person on their own phone, or by a parent or guardian supervising someone in their care.
You must be at least [13 / 16 — the age of digital consent where you live] to create a Jolt account. If you supervise someone who is under that age, you confirm you are their parent or legal guardian, or that you have that person's guardian's consent.
A supervisor must confirm, before an invite code can be created at all, that they are the supervised person's parent or guardian or that the person has agreed; the rule is enforced on our servers, not just in the app. A supervised person is always shown what is shared before they accept, and can end supervision at any time from their own device. We do not knowingly collect data from a child without a guardian's involvement. If you believe we have, contact [YOUR SUPPORT EMAIL] and we will delete it.
How long it is kept
Local data lives on your phone until you delete it in the app or uninstall Jolt.
Account data is kept while your account exists. Daily usage records are deleted automatically after 90 days — nothing in Jolt reads further back than that, so there is no reason to keep them. Invite codes expire after seven days and are deleted when the link they created ends. Deleting your account removes everything immediately.
Your choices
- Stop all sharing — sign out, or leave your supervisor. Both are in the app and neither needs anyone's approval.
- Delete everything local — uninstall the app.
- Delete your account — Settings → Account → Delete account, in the app. If you no longer have it installed, request deletion here. It removes your profile, your synced settings, your usage history and the account itself, releases anyone you supervise, and cannot be undone.
- Access, correct or export your account data — write to [YOUR SUPPORT EMAIL] and we will action it within [30] days.
- Withdraw a permission — Android settings, at any time. Jolt degrades rather than breaks.
If you are in the UK or EU, you also have the right to object to processing, to restrict it, and to complain to your data protection authority. Our legal basis is your consent for account features, and legitimate interest in providing the app you installed for the rest.
This website
takeajolt.app is a static site on Firebase Hosting, which logs requests — including network addresses — for operational purposes under Google's terms. The site counts page views and clicks on the store button with Umami, an open-source analytics tool we host ourselves. It sets no cookies, stores no network addresses, and cannot follow you to other sites; it records the page, the referrer, your browser and your country, and nothing that identifies you.
Security
Account data is protected by Firebase security rules that restrict each account to its own records and give a supervisor access only to the wards who accepted their invite. Traffic to Firebase is encrypted in transit. No system is perfect, and you should not store anything in Jolt you would be harmed by losing.
Changes
If this policy changes in a way that affects what we collect or who sees it, we will say so in the app before the change takes effect.
Contact
[YOUR SUPPORT EMAIL] — questions, requests, or anything that looks wrong.