Legal

PRIVACY POLICY.

Last updated: September 30, 2026

Blocking runs on this iPhone. Untilt makes the covered apps and sites unavailable without seeing what you do. This page explains optional product analytics and diagnostics, purchase processing, install and advertising attribution, reminders, the widget, and a migrated plan's schedule request.

01

What we collect

Lock settings, local lock history (including the days-locked count), reminder choices, and onboarding answers are stored on your iPhone. Optional product analytics can include lock timing and duration, as described below. Where version 1.1.0 changes something, this page says so; everything else applies to every current version.

What the app can send:

  • Purchase history and subscription entitlement status, linked to a random app-installation identifier through Apple and our subscription provider (RevenueCat). RevenueCat uses these records for subscription analytics and app functionality, including receipt validation, purchase restoration, and Pro entitlements. These records are pseudonymous. Subscription events may also be forwarded for advertising measurement as described below.
  • For an installed user who still has an automatic plan migrated from an earlier build: the saved sport selection, a date range, and the iPhone’s IANA time-zone identifier, so the existing schedule can be refreshed. No Untilt account or installation identifier is attached.
  • Product analytics through PostHog: app and onboarding steps, permission and purchase outcomes, lock start times, local hour and weekday, planned duration, extensions, and observed lock endings. Starting with version 1.1.0 this also includes the length band of the first lock you choose; whether a purchase started a free trial; subscription status changes the app observes, such as a trial converting or being cancelled, renewal being turned off, or a subscription lapsing, sent with the plan and billing period but no amounts, dates, product or customer identifiers; requests to end a lock early and whether they were withdrawn; offer-code outcomes; and, when Screen Time access fails, a short category such as declined, no_passcode or restricted, never Apple's error text. A random installation identifier and random lock identifiers let us measure conversion and repeat use. These records are pseudonymous, rather than identifier-free. We do not send names, email addresses, setup questionnaire answers, bets, balances, browsing history, or text you write. Session replay and screen recording are disabled.
  • Separate optional block research: if you choose to submit it, your selected sports or betting types and optional reason are attached to that block's analytics record. These answers are not inferred from the time you block. You can skip the research entirely. To share it, open Settings > Help improve Untilt; only Share answers submits your choices.
  • Crash and performance diagnostics through Sentry, including app version, device and operating-system information, failures, and selected product events. Screenshots, session replay, touch logs, and network-request capture are disabled. Optional sport and reason answers are excluded from diagnostic breadcrumbs.
  • Identifier-free aggregate product milestones through Cloudflare, such as first-run steps, plan views, and whether a reminder was accepted or declined. These requests contain an approved event name and app build; they are counted in build-level totals without an installation or lock identifier. Onboarding answers are not included. Starting with version 1.1.0, only App Store installs send them; TestFlight and development builds do not.
  • Install attribution, through AppsFlyer’s Strict SDK. When Untilt opens, the SDK reports the install and app session to AppsFlyer with an identifier that AppsFlyer generates for this installation, basic device information such as model, iOS version, app version, and language. AppsFlyer also uses the network IP address to derive approximate city, region and country. If you installed from a creator or campaign link, it records the opaque campaign code carried by that link. Untilt reports product events to AppsFlyer without values: the first lock started and, starting with version 1.1.0, a free trial started (the event af_start_trial). Neither carries lock details, a price, or revenue, and the trial event is sent only while app analytics are on in Settings. AppsFlyer uses the trial event to set Apple's SKAdNetwork conversion value on your iPhone, so advertising networks, including Meta, can count trial starts in Apple's aggregated SKAdNetwork reports. Starting with version 1.1.0, the app also asks Apple to send AppsFlyer a copy of those SKAdNetwork reports. The app uses the Strict SDK without the advertising identifier (IDFA) or your device name, and disables AppsFlyer's vendor-identifier (IDFV) collection. Current versions also disable RevenueCat's automatic device-identifier collection. Versions before 1.0.3 may have supplied IDFV through that integration; updating does not erase previously retained records. Untilt does not request App Tracking Transparency. RevenueCat forwards subscription events (start, renewal, cancellation) to AppsFlyer under the same installation identifier so we can see which campaigns lead to subscriptions. AppsFlyer also sends privacy-preserving install and app-open postbacks to our configured TikTok advertising integration to measure our marketing. Its Advanced Privacy setting is enabled; additional personal-data and advanced-data-sharing settings are off. For Meta, we measure advertising only through Apple's SKAdNetwork. Meta receives Apple's aggregated SKAdNetwork reports, which show that an install or a free trial came from a campaign but carry no device identifier or information about you. AppsFlyer may share with Meta the conversion configuration needed to read those reports and aggregate SKAdNetwork revenue. AppsFlyer's advanced data sharing with Meta is off, and AppsFlyer does not send Meta installation, app-session, in-app event or revenue data about your iPhone. Advanced matching is not enabled.
  • Reminders, starting with version 1.1.0. If you accept a heads-up before kickoff, or ask for a reminder before a free trial ends, Untilt schedules those notifications on your iPhone with Apple's local notifications, from a weekly kickoff schedule built into the app. Reminder times are not sent to us; only whether you accepted or declined, and how many reminders were scheduled, reach the identifier-free counts above.
  • The widget, starting with version 1.1.0 and only if you add it. The Lock Screen or Home Screen widget reads the running lock's end time from storage the app shares with it on your iPhone. It sends nothing and has no Screen Time access.

Untilt has no account system. It does not read page content, keystrokes, messages, bets, balances, browsing history, or Screen Time activity. Apple's Screen Time permission is used to apply restrictions, not inspect what you do in other apps.

Optional analytics and diagnostics are enabled by default. Turn off analytics in Untilt Settings to stop future product analytics, research submissions, Sentry diagnostics and the trial-start event to AppsFlyer, and clear pending aggregate requests. Turning this off does not delete previously received records or cancel your block or subscription. AppsFlyer install attribution and purchase processing have separate purposes and are not controlled by this switch. Network providers process requests to deliver these services; we do not attach an IP address to our product analytics properties.

New users cannot create an automatic sports plan. For a migrated plan, Untilt first requests schedule boundaries from its calendar service and may fall back to ESPN’s public scoreboard service. Those requests are used to answer in real time; Untilt stores no per-user request record, scores, odds, bets, or precise location.

Separately, this website (not the app) uses anonymous, cookieless Vercel analytics to count page views, referrers, campaign tags, and which on-site install button was clicked. It sets no cookies, and we do not attach an account, search term, invite code, or device identifier to those events. The visitor hash it uses resets every 24 hours. For a session that arrives through our paid Google Search campaign, the site also loads Google Ads conversion measurement and reports whether an App Store button was clicked. Google Consent Mode is initialized with advertising, analytics, user-data, and personalization storage denied, so Untilt does not grant Google permission to place those identifiers. Google can still receive a limited cookieless conversion request, including the page and ad-click context supplied by the browser, for measurement and modeling. Website analytics are separate from the optional app analytics described above.

02

How we use it

  • Complete, load, and restore your Untilt Pro subscription.
  • Refresh the dates of an existing automatic plan migrated from an earlier build.
  • Measure app setup, purchases, free trials, subscription status, lock duration, and repeat use through pseudonymous product events and separate build-level totals.
  • Measure which creator links and ad campaigns lead to installs, first locks, free trials, and subscriptions, through AppsFlyer and Apple's SKAdNetwork.
  • Deliver the reminders you ask for, scheduled on your iPhone.
03

Who we share it with

We do not sell your data. We do not sell advertising profiles.

  • Apple, for App Store purchases, system permissions, notifications you allow, and SKAdNetwork advertising reports.
  • RevenueCat, for purchase history linked to a random app-installation identifier and subscription entitlement status used for subscription analytics and app functionality.
  • AppsFlyer, for install and campaign attribution as described above. AppsFlyer processes that data on our behalf and does not receive the advertising identifier.
  • Meta, only through Apple's aggregated SKAdNetwork reports and the conversion configuration AppsFlyer shares to read them, as described above.
  • PostHog, for optional product analytics and submitted block research.
  • Sentry, for optional crash and performance diagnostics.
  • Vercel, for cookieless website analytics, and Google, only for storage-denied conversion measurement in sessions that arrive through our paid Google Search campaign.
  • Cloudflare, which hosts the calendar response for a migrated automatic plan and the identifier-free aggregate counters. ESPN is used if the real-time calendar lookup needs its public scoreboard fallback.
04

Screen Time

Blocking is enforced by Apple’s Screen Time technology, on this iPhone. The permission works one way: it lets Untilt restrict the covered apps and websites, and it does not let Untilt read your Screen Time activity, app usage, or web history. Apple does not expose that data to us, and we collect none of it.

One documented side effect, disclosed rather than discovered: applying the web filter turns off Safari private browsing for the life of a lock. It returns when the lock ends. If Screen Time access fails, analytics record only the failure category described above.

05

Your rights

You can turn optional analytics and diagnostics off in Untilt Settings. This stops future collection through that setting; it does not erase events already received. You can ask us to access, correct, export, or delete data we hold. Because the app has no account and analytics use random identifiers, we may need information that helps us locate the relevant records without collecting unnecessary data. Email support@tryuntilt.com.

06

Children

Untilt is for people 18 and older. We do not knowingly collect data from anyone under 18.

See also: Terms of Service