Mindful Privacy Policy
Last updated: September 2, 2026
1. Introduction
Nexus Kairos LLC (“we,” “us,” or “our”) makes Mindful, an iOS app that blocks the apps that pull your attention away. This policy explains what Mindful collects, what it never collects, and what you can do about it. It covers the Mindful iOS app and this page.
2. The short version
- Blocking runs on your iPhone, with no network. Which apps you block never reaches your account.
- Which apps you block, and how long you use them, never leaves your iPhone. Apple’s Screen Time API makes it impossible for us to see it.
- We do not sell data, we do not run ads, and we do not track you across other apps or websites.
- Mindful asks you to sign in with Apple or Google. The account does exactly two things: it carries Pro to a new phone, and it restores the shape of your setup.
- You can switch anonymous statistics off in Settings, and delete your account and its backup from inside the app.
3. Screen Time and Family Controls
Mindful blocks apps through Apple's Screen Time framework: Family Controls, ManagedSettings and DeviceActivity. When you pick apps, categories or websites to block, iOS hands Mindful an opaque token for each one. A token carries no name, no icon and no address, and it works only on the iPhone that created it. We cannot read from a token which app you chose. Tokens stay in the app's local storage and its App Group container on your device.
Your usage figures work the same way. The Тунгалаг (clarity) score and the Top Offenders list are computed inside an Apple-sandboxed report extension that has no network access at all. That extension writes one number into on-device storage: your blocked minutes for the day. Per-app minutes never leave the extension, and the main app never sees them.
Mindful is for your own device and your own attention. It is not a parental-control app: it does not monitor another person, and it sends no report to anyone.
4. What stays on your iPhone
The following is stored on the device and is never transmitted:
- Blocklists and the tokens inside them
- Schedule windows, focus sessions and per-app limits
- The reason you type when you ask to unlock an app
- Proverbs and collections
- Daily counters: windows completed, unlock confirmations and abandonments, scheduled minutes, unlocked minutes, shield encounters, focus minutes and emergency passes. These roll off after 90 days.
Deleting the app deletes all of it.
5. Your account
Mindful asks you to sign in when you start. Once you are in, shields, schedules, sessions, limits and statistics all run on your iPhone with no network. The account does exactly two things: your Pro subscription follows you to a new phone, and Mindful can put the shape of your setup back after a reinstall. Which apps you block never reaches the account.
Sign-in uses Sign in with Apple or Google, through Firebase Authentication. If you sign in we receive: a Firebase user ID, the email address the provider gives us, and a display name if the provider supplies one. Apple's Private Relay is fully supported. If you hide your email, we only ever see the relay address.
What the backup contains
One document, keyed to your user ID: schema version, last update time, your daily goal in minutes, and for each blocklist its name and the number of apps in it; and for each schedule window its name, start and end time, weekdays, mode and which blocklist it points to.
What the backup never contains
No Family Controls token of any kind. A restored blocklist arrives with its name and no apps, and you pick the apps again once. Also absent: the reasons you typed, proverbs, session history, and any usage figure.
You reach only your own document. Our database rules refuse every other read, and refuse any field the app does not send.
6. Purchases and subscriptions
Mindful Pro is sold through Apple In-App Purchase. Apple processes the payment; we never see your card and we never receive your Apple ID. We use RevenueCat to check whether your subscription is active. Signed out, you are an anonymous ID to RevenueCat. When you sign in, that ID becomes your Firebase user ID. That link is what carries Pro to a new phone.
7. Crash reports and anonymous statistics
Crashes go to Sentry so we can fix them. Sentry is configured with personal identification switched off, and every report passes through a filter that clears the user object and drops outright anything that looks like Family Controls data.
Mindful also reports a small, fixed set of anonymous product events, such as “onboarding completed”, “paywall shown”, “purchase completed”. The event list is a closed set in the source code, so the app has no way to send free-form text. The only details attached are a mode, a number of minutes, which screen triggered a paywall, and which plan. Never attached: what you typed, which apps you block, how long you used anything, or any identifier. The four account events carry no properties at all.
You can switch anonymous statistics off in Settings. Crash reporting stays on so the app can be fixed; it carries no identity either.
The three Screen Time extensions send nothing. They cannot: they contain no analytics or crash SDK at all.
8. Notifications
Notifications are local and scheduled by your iPhone. Mindful has no push server and sends you nothing remotely.
9. What Mindful never collects
No advertising identifier (IDFA), no device fingerprint, no location, no contacts, no photos, no microphone, no health data, no browsing history, no session recording. Mindful does not track you across other companies’ apps or websites, and we do not sell or rent personal data to anyone.
10. Who processes data for us
- Apple: In-App Purchase, Sign in with Apple, the Screen Time framework. apple.com/legal/privacy
- Google (Firebase): authentication, backup document storage, Google sign-in. firebase.google.com/support/privacy
- RevenueCat: subscription status. revenuecat.com/privacy
- Sentry: crash reports and anonymous events. sentry.io/privacy
There is no one else.
11. Where your data is stored
Backup documents are held in Google Firestore in Singapore (asia-southeast1), the closest region to Mongolia. Sentry and RevenueCat process data on their own infrastructure in the United States. Everything else stays on your iPhone. Using Mindful with an account means your account data is transferred to those countries.
Every transfer is encrypted with TLS. We never hold a password: Apple or Google authenticates you and we receive only a token. A backup document can be read only with your own signed-in credentials. No system is perfectly secure; if a breach ever affects your data, we will tell you within the time the law requires.
12. How long we keep data
- On-device counters roll off after 90 days.
- The backup document lives until you delete your account.
- Crash and event data are deleted on Sentry’s retention schedule; we do not extend it.
- Subscription records stay with Apple and RevenueCat for as long as billing and tax rules require.
13. Deleting your data
- Delete the app: everything local goes with it, every token and every counter. Shields stop.
- Delete the account: the delete option in Settings removes your backup document first, then your Firebase account. This cannot be undone.
- Or write to founder@nexuskairos.com and we will do it for you.
Deleting your account does not cancel your subscription. Cancel that in Settings → Apple ID → Subscriptions.
14. Your rights
You have the right to access, correct or delete your data, to receive a copy of it, to withdraw consent, and to object to processing. Write to founder@nexuskairos.com and we will answer within 30 days. We handle personal data in line with Mongolia's Law on Personal Data Protection, and we honour GDPR and CCPA rights where they apply to you. We do not sell personal information as those laws define it. Where the GDPR applies, we process account data to perform our contract with you, and crash reports and anonymous statistics on our legitimate interest in keeping the app working.
15. Children’s privacy
Mindful is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has given us personal data, write to us and we will delete it.
16. Changes to this policy
We will post any change on this page and move the date at the top. If a change is material, we will say so in the app.