Privacy Policy
Last updated: 19 July 2026
OffLimits is a screen-time and content blocker built on a simple promise: it measures your product usage, never you. There are no ads, no trackers, no data sold, and nothing is placed on your photos or exports. This page explains exactly what the app does and does not collect.
The short version: The blocking runs entirely on your device through Apple Screen Time. We never see which apps or websites you use. We collect no account, no name, no email, no location, and no advertising identifiers. The only data that leaves your device is anonymous, aggregate usage counts that cannot be tied back to you.
1. What stays on your device
- Your list of blocked apps, websites and categories — stored on your device and, for enforcement, in Apple’s Screen Time system. We cannot read these; Apple provides them to the app only as opaque tokens.
- Your settings, PIN (stored only as a slow, salted hash in the device Keychain), streak, schedules and history.
- Photos you take are unaffected — OffLimits never watermarks, renames, or adds notes to anything you create.
2. Anonymous usage analytics
To understand how the app is used and where people get stuck, we record a small set of anonymous product events — for example “paywall viewed”, “blocking started”, “settings opened”. These are sent to our own server (Cloudflare) and stored only as aggregate totals.
- No user ID, no device ID, no advertising identifier (IDFA).
- Your IP address is never stored.
- Country is derived from your device’s region setting, not from your location or network.
- The data is not linked to your identity and is not used to track you across apps or websites.
3. Sign in with Apple (optional)
You may optionally link Sign in with Apple so a forgotten PIN can be reset. If you do, we receive only a random, per-app Apple identifier — never your name, email, or contacts. You can remove this at any time in Settings.
4. Accountability sharing (optional)
If you choose to share your status with a friend, the app publishes an encrypted status blob (your streak and whether blocking is on) to Apple’s CloudKit, readable only by someone who has the pairing code you share. It never contains your apps, websites, or any identity. Turning sharing off removes the published status.
5. Purchases
Subscriptions and one-time purchases are processed entirely by Apple. We receive your subscription status from Apple to unlock Pro features — never your card number, name, or billing address.
6. Children & parental use
OffLimits can be used to set limits on a child’s device. Even in this mode, the app collects no personal information about the child or the parent beyond the anonymous, aggregate analytics described above.
7. Data processors
We use Apple (Screen Time, CloudKit, App Store purchases) and Cloudflare (anonymous analytics hosting). They process data on our behalf under their own terms; we never share personal data with them because we don’t collect any.
8. Your choices & deletion
- “Delete all app data” in Settings erases everything the app stores, including your PIN, recovery details and pairing.
- Deleting the app removes its data from your device.
- Because analytics are anonymous aggregates with no identifier, there is no per-user record to request or delete.
9. Europe (GDPR / UK GDPR)
OffLimits is designed so that European data-protection law has almost nothing to bite on — not as a loophole, but because we genuinely do not collect personal data.
- No personal data, so no profiles. The usage events described in section 2 carry no user ID, no device ID, no IDFA, and no stored IP address. They cannot be linked to you or to each other, which means they are anonymous information rather than personal data (GDPR Recital 26). There is no profile to access, correct, export, or erase — because none is ever created.
- No consent banner, no tracking. We do not use cookies for tracking, we do not run advertising, and we do not track you across other apps or websites. Under Apple's App Tracking Transparency we do not track, so we never show the tracking prompt.
- Legal basis. Where we process the limited data we do handle — your subscription status from Apple, and an optional Sign in with Apple identifier — the basis is performance of our contract with you (Art. 6(1)(b)): it is what makes Pro features and PIN recovery work. The anonymous usage counts fall outside the GDPR because they are not personal data.
- Your rights. You keep every right the GDPR gives you (access, rectification, erasure, restriction, objection, portability). In practice they are satisfied on the device: Settings → Delete all app data erases everything the app holds, immediately and permanently, without asking us. If you ever believe we hold personal data about you, email us and we will answer within 30 days. You also have the right to complain to your national supervisory authority.
- International transfers. The anonymous counts are handled by Cloudflare on our behalf; Apple handles purchases, Screen Time and the optional CloudKit status. Because no personal data is transferred, no transfer mechanism is required for it. Apple and Cloudflare operate under their own published terms and safeguards.
- Children. We do not knowingly collect personal data from anyone, including children. The parental mode described in section 6 stores its settings on the device only.
10. Turkey (KVKK)
Turkish users have the same protection under KVKK (Law No. 6698), and for the same reason: we process no personal data through the app. Your rights under Article 11 — to learn whether your data is processed, to request correction or deletion, and to object — are met on the device through Settings → Delete all app data, or by emailing us at the address below.
11. Changes
If this policy changes, we will update the date above. Material changes will be reflected in the app.
12. Contact
Questions about privacy, or any request under the GDPR or KVKK? Email support@getmarkpix.com. We answer within 30 days.