Privacy Policy

Last updated: 3 September 2026

Crystalo (“the App”, “we”, “us”) is a personal focus and digital wellbeing app for iPhone, iPad, Mac and Apple Watch. This policy explains what data the App handles and how. Everything the App does for you alone works without an account: your focus history, your specimens and your settings live on your device and sync through your own iCloud, where we cannot see them. Two features are shared by nature, teams and invite rewards, and using either one means signing in and sending a limited set of data to our backend. That part is described in full below. We use no analytics, advertising or tracking SDKs anywhere in the App.


1. Summary (the short version)


2. Data the App handles, and why

a. On-device app content (focus sessions, specimens, settings, streaks)

Created and used by the App on your device and stored locally with Apple’s on-device storage (SwiftData). None of it reaches us in this form. The single exception is the summary of a completed session while you are signed in, described in section f, and that is a handful of numbers rather than a copy of your history.

b. iCloud sync (Apple CloudKit)

If you are signed into iCloud and have iCloud Drive enabled, your crystals, sessions, and settings sync across your own devices through your private iCloud database. This is operated by Apple under Apple’s iCloud terms and privacy policy. The developer of Crystalo has no access to your iCloud data.

c. Apple Health (HealthKit) — optional, on‑device only

With your explicit permission:

Health data is used only to provide these in‑app features. It is processed on your device, is never transmitted to us or any third party, is never used for advertising or marketing, and is never sold. You can revoke Health access at any time in iOS Settings → Privacy & Security → Health. (Required by Apple’s HealthKit policy.)

d. Screen Time / app blocking (Family Controls) — optional, on‑device only

To let you block distracting apps during focus sessions and on schedules, the App uses Apple’s Family Controls / Managed Settings / Device Activity frameworks in individual mode (you manage your own device). When you choose which apps to limit, iOS returns only opaque tokens — the App does not receive the names or identities of your apps, and these tokens never leave your device. On‑device screen‑time summaries shown inside the App are rendered locally and are not transmitted.

e. The optional Crystalo account

You can use the App indefinitely without one. Creating an account is required only for team leaderboards and for invite rewards, and the App asks for it at the moment you open one of those, not at launch. Sign-in works through Sign in with Apple, Google or an email magic link, and the session is held by our authentication provider, Supabase.

What the account itself stores:

Signing in with two different methods creates two separate accounts, because Apple’s private relay address never matches the Google one. There is no way for us to merge them.

f. Completed focus sessions, while signed in

When you are signed in and a focus session finishes, the App sends a summary of it to our backend so team leaderboards have something to rank: the length, the species, the rarity, the clarity figure, the start time and a session identifier used to reject duplicates.

Sessions you abandon are not sent. Nothing about your blocking is sent, because the App does not have it in the first place (see section d). Meditation content, Health data and anything from your Grotto stay on the device. Signed out, no session summary leaves the device at all.

g. Teams

Creating or joining a team stores the team name, its invite code, who owns it and who is in it. Members of a team can see each other’s handle, display name and focus totals through that team’s leaderboard, and nothing else. There is no public profile directory and no global leaderboard in the App. If you report a team, we store the report so it can be reviewed.

h. Invites and Pro days

Your invite code, the accounts that redeem it and the Pro days each side has earned are recorded on our backend, because the reward is worth money and has to survive a reinstall. Both sides have to be signed in for a redemption to count. The days themselves are delivered through RevenueCat, which is told your account identifier and the entitlement to extend.

i. Subscriptions (Crystalo Pro)

Purchases and the free trial are processed by Apple through the App Store using your Apple ID. Apple does not share your payment details with us, and we receive only Apple’s standard sales and subscription reports.

Subscription state itself is handled by RevenueCat, which receives the purchase and receipt information from Apple along with an identifier for you: your Crystalo account identifier if you are signed in, otherwise an anonymous device-scoped one that RevenueCat generates. This is what lets Pro follow you to your other Apple devices and survive a reinstall, and it is also how gifted Pro days are applied. Managing or cancelling a subscription happens in iOS Settings → your Apple ID → Subscriptions.


3. Data we do not collect

The App’s App Store privacy label reflects the account: signed in, contact information (your email), an identifier and usage data (completed session summaries) are collected and linked to you, and purchases are handled as described above. None of it is used for tracking. Signed out, nothing is collected by the developer.


4. Who processes data for us

We keep the list short on purpose, and every one of these is a processor acting on our instructions rather than a party we sell anything to.

If you are in the EEA or the UK, this means account data is transferred to the United States. We rely on the European Commission’s standard contractual clauses as offered by these providers. Data that never leaves your device or your iCloud, which is most of what the App holds, is not part of any such transfer.

5. How long we keep it

Account data, team membership and session summaries are kept while your account exists. Deleting the account deletes them, including the invite records and Pro day ledger keyed to it. Records that Apple or RevenueCat keep for tax and accounting reasons are governed by their own retention rules, not ours. Waitlist addresses are kept until launch or until you unsubscribe, whichever comes first.

6. Your rights and choices

Our legal basis for handling account data is the contract you enter by using teams or invites, and consent for notifications. Everything else runs on your device without a legal basis being needed from us.

7. Children

Crystalo is not directed to children under 13, and we do not knowingly collect personal data from them. Where local law sets a higher age for consenting to data processing, that age applies to creating an account. The App uses Screen Time in individual mode, meaning you limit your own device; it is not a parental control product.

8. This website, and its cookies

The sections above describe the App. This one describes crystalo.app, which is a different thing with far less in it.

Nothing is written to your device before you choose on the banner. If you accept analytics, the site loads Cloudflare Web Analytics: it counts page views and reports which pages are read, sets no cookie, builds no profile, and cannot follow you to another site. If you refuse, that script is not loaded at all rather than merely silenced. There are no advertising or social network trackers here, and none are planned.

Two entries record the choice itself, and only once you have made it: a cookie named crystalo_consent and, in local storage, crystalo.consent with the date and the version of the text you agreed to. Both last twelve months, after which the banner asks again — consent that never expires is not consent. The Cookie settings link in the footer of every page reopens the banner with your current choice, and a new choice applies immediately.

The waitlist form on the front page stores your email address in our own database on Cloudflare and nowhere else. It stays there until you ask for it to be removed; the address in the contact section below is enough for that.

9. Changes

We may update this policy as the App evolves. Material changes will be reflected by the “Last updated” date above and, where appropriate, noted in the App.

10. Contact

Questions about privacy, or a request under any of the rights above: hi@crystalo.app.


The waitlist form on the home page is separate from the App and needs no account. Submitting it stores the address you type, plus the language your browser asks for and the site it came from, in our own database, where it sits until we write to announce the launch. Every message we send carries an unsubscribe link, and you can ask us to remove the address sooner at the contact address above.