Privacy policy
Last updated 22 August 2026
The short version. Scrappy has no account, no sign up, and no server of ours anywhere. Your screen time never leaves your iPhone, and neither do the names of the apps you guard. Two things do leave: your purchase, so the app knows you are subscribed, and a record of what you did inside the app, so we can find the screens people give up on and fix them. Both travel under an anonymous id that is not you and cannot be tied to you. Nothing here tracks you anywhere else.
This policy explains how the Scrappy iPhone app ("Scrappy", "the app") and this website handle information. Both are provided by Scrappy ("we", "us"), based in India. We are the data fiduciary for the purposes of India's Digital Personal Data Protection Act, 2023, and the data controller for the purposes of UK and EU data protection law.
1. Information we collect
Nothing that identifies you. There is no account, so we never ask for and never receive your name, email address, phone number, date of birth, contacts, location, photographs or payment details. We run no server of our own and keep no database of users. We could not pick a single person who uses Scrappy out of a crowd.
Two things leave your phone. One is your purchase; the other is a record of what you did inside the app. Sections 6 and 7 set out exactly what each involves and, more usefully, what neither of them contains. Everything else described in this policy stays on your device.
2. Information the app stores on your phone
Scrappy needs to remember things in order to work. All of it is written to storage that belongs to the app on your device, and none of it is readable by us or by other apps:
- The rules you create, and which apps or categories each rule guards.
- How many times you tried to open a guarded app, and when.
- Your treat balance, walks completed and streaks.
- Your settings and preferences, including whether the removal lock is on.
- Whether you have a Pro subscription, so the app knows what to unlock.
This is kept in your app's private container and in a shared container used by Scrappy's own Screen Time extensions. It is included in your device backup if you back your iPhone up to iCloud or a computer, in the same way every app's data is. That backup is controlled by Apple and by you, not by us.
3. Screen Time data
Scrappy uses Apple's Screen Time frameworks, Family Controls, Device Activity and Managed Settings, to see your usage and to shut apps. This deserves a plain explanation because it sounds alarming and is not.
When you choose apps to guard, iOS hands Scrappy an opaque token for each one rather than its name. The app cannot read your full app list, cannot tell what most of those tokens refer to, and cannot export them anywhere meaningful. Your usage figures are drawn on screen by a sandboxed Apple extension that the operating system deliberately prevents from making network requests. Apple designed it this way so that apps like Scrappy can be useful without ever seeing your data. The numbers you see in Scrappy are rendered on your phone and stay there.
You grant this access explicitly through an Apple system prompt, and you can revoke it at any time in Settings on your iPhone.
4. Health and motion data
Treats are earned by walking, so Scrappy needs to count steps. With your permission it reads your step count from Apple Health and from the motion coprocessor in your iPhone. It reads this figure only, it reads it only on your device, and it never writes anything back to Health.
Your step count is used to work out whether you have earned a treat and for nothing else. It is not stored beyond what the app needs to track today's progress, and it is never transmitted. If you decline this permission, Scrappy still works, and you can earn treats by completing walk sessions instead.
5. Notifications and Live Activities
Scrappy can send notifications and show a Live Activity on your lock screen while a walk is running. These are scheduled and drawn locally by your phone. There is no push server, so no notification content ever passes through us.
6. Purchases
Subscriptions and the lifetime unlock are sold and paid for through Apple's App Store. Apple handles the money. We never see your payment details, your Apple Account, your billing address or your name, and Apple's own privacy policy governs that part.
To know whether your subscription is still active, Scrappy uses RevenueCat, a subscription management service. When you buy, restore or renew, RevenueCat receives the App Store transaction and an anonymous identifier that RevenueCat itself generates. It exists to answer one question: is this person subscribed.
Nothing else travels with it. No screen time figures, no list of the apps you guard, no rules, no step counts, and nothing you have typed. The identifier is not your name, your email or your device's advertising id, it is not linked to your identity, and it is not used to track you across other apps or websites.
RevenueCat processes this in the United States, so if you are elsewhere your purchase record is transferred there.
7. How the app gets better
Getting into Scrappy takes eighteen screens, and until now we had no way of knowing which one people gave up on. We could see how many downloaded the app and how many subscribed, and nothing whatsoever about the distance between. The next release changes that. It records what happens inside the app and sends it to Mixpanel, a product analytics service. This page is being updated before that release rather than after it, which is what section 13 promises.
What is recorded is a fixed list of things the app does: a screen of the introduction was reached, a permission was granted or refused, a rule was made, the guard turned you back, a treat was thrown, the price was shown. Each carries a few facts about the app's own state, such as how many rules you have, how long you spent on a screen, and whether you are subscribed.
What is not recorded is the part worth reading. The names of the apps you guard never leave your phone. Neither do the hours your rules cover, nor any figure Apple's Screen Time gave us, nor anything you have typed. A guarded app is counted, never named, and the hours a rule covers are usually somebody's sleep, which is nobody's business but theirs.
That is not something we are asking you to take on trust. The app carries a fixed list of the facts it is allowed to send, and anything not on that list is thrown away before it goes anywhere. A test checks that list every time we change the app, and the app will not build if it has stopped being true. We did it that way because a promise a machine keeps is worth more than one a person made sincerely and then forgot.
You are identified by a random id the app invents the first time it runs. It is not your name, not your email, not your device's advertising id, and not anything Apple gave us. It exists so that eighteen screens can be read as one person's path through them instead of eighteen unrelated numbers. It is not linked to your identity and it is not used to recognise you anywhere else. Deleting the app destroys it, and a fresh install invents a new one with no way of knowing it is you again. Records already sent stay until they age out or until you ask us to delete them, which section 11 explains.
Mixpanel's software also attaches, to each record, the model of iPhone you have, its iOS version, the screen size and the version of Scrappy. Your IP address reaches Mixpanel's servers in the ordinary way that it reaches any server you send a request to; we have switched off the setting that would turn it into a city and a region, so no location of yours is worked out or stored. Mixpanel processes this in the United States.
Our lawful basis for this is our legitimate interest in understanding where the app is confusing so that we can fix it. If you would rather we did not, section 11 says how to tell us.
8. Advertising measurement
If we advertise Scrappy, we need to know whether the advertising worked. Scrappy uses Apple's AdAttributionKit and SKAdNetwork for this. It is worth being precise about what that does, because it sounds worse than it is.
The app registers a single number between 0 and 3, meaning installed, finished onboarding, started a trial, or subscribed. Your iPhone's operating system, not the app, may later send that number to the advertising network that showed you the ad. Apple designed these frameworks so that the postback carries no identifier for you or your device, is delayed and aggregated, and cannot be tied back to an individual. We receive counts, never people.
This is not tracking as the App Store defines it. Scrappy does not use the Advertising Identifier, does not ask for App Tracking Transparency permission, and does not link anything to your identity.
9. What Scrappy does not do
- No session recording, no screen replay, no heatmaps and no crash reporter. Nobody watches you use the app. Section 7 is the whole of what is measured, and it is a list of things that happened, not a recording of you doing them.
- No third party software development kits other than RevenueCat and Mixpanel, which see only what sections 6 and 7 describe.
- No advertising identifier and no App Tracking Transparency prompt, because nothing in Scrappy follows you into another company's app or website.
- No advertising inside the app.
- No selling or renting of personal information, and no sharing of it beyond the two purposes in sections 6 and 7.
- No cookies on this website, and no visitor analytics.
10. Children
Scrappy is not directed at children under 13 and we do not knowingly collect information from anyone, of any age. Because the app requires no account and collects nothing that identifies a person, there is no children's data for us to hold, disclose or delete.
11. Your rights and your control
Data protection law gives you rights to access, correct, export, delete and restrict the use of your personal information, and to object to it being used at all. We hold nothing that identifies you, so in most cases there is nothing for us to hand over or erase.
For the two things that do leave, write to us and we will act on it. We will ask RevenueCat to delete the purchase record in section 6, and we will delete the record in section 7 and stop collecting it for you. The id in section 7 is a random string, so please send it to us: open Settings inside Scrappy, look under "Your data", and tap "Anonymous id" to copy it. Without it we can find your record no better than you can, which is rather the point of it.
Everything Scrappy knows lives on your phone and is under your control:
- Deleting the app removes all of its data from your device permanently.
- Screen Time access can be withdrawn in the Settings app.
- Health access can be withdrawn in Settings or in the Health app.
- Notification permission can be withdrawn in Settings.
One note on deletion: if you have turned the removal lock on, uninstalling Scrappy takes a day by design, so that a bad evening cannot undo a good decision. You are never permanently stuck, and the delay applies to the app itself, never to your data rights.
12. Data retention and transfers
What is on your phone stays there until you delete the app, and then it is gone.
The purchase record in section 6 is held by RevenueCat for as long as it is needed to tell the app whether you are subscribed. The records in section 7 are held by Mixpanel only for as long as they serve the purpose that section describes: they are about particular screens, and once a screen has been rebuilt its old records stop meaning anything, so they are deleted. Both are processed in the United States, and those two are the only international transfers Scrappy makes, because they are the only data that leaves.
13. Changes to this policy
If Scrappy ever starts collecting something, this page will say so clearly and in advance, the date at the top will change, and the app's App Store privacy label will be updated to match. We will not quietly add something to a future version and leave this page as it is.
On 22 August 2026 we added section 7. Before that date the app measured nothing at all, and this page said so. We are telling you here rather than letting you find it, because the paragraph above was a promise and this is what keeping it looks like.
14. Contact
Questions about privacy, or about anything else, go to [email protected] and a person will answer.
If you believe we have handled your information improperly, you can complain to a regulator. In India that is the Data Protection Board of India. In the UK or the EU it is your local supervisory authority.