Privacy Policy
Last updated: 3 September 2026
Crystalo (“the App”, “we”, “us”) is a personal focus and digital wellbeing app for iPhone, iPad, Mac and Apple Watch. This policy explains what data the App handles and how. Everything the App does for you alone works without an account: your focus history, your specimens and your settings live on your device and sync through your own iCloud, where we cannot see them. Two features are shared by nature, teams and invite rewards, and using either one means signing in and sending a limited set of data to our backend. That part is described in full below. We use no analytics, advertising or tracking SDKs anywhere in the App.
1. Summary (the short version)
- The account is optional. Focus sessions, blocking, schedules, limits, meditation and the whole collection work signed out. Signing in enables exactly two things: teams and invite rewards.
- Your data stays with you. Your specimens, focus sessions and settings are stored on your device and synced through your private iCloud account (Apple CloudKit). We cannot see or access this data.
- Signed in, some of it is also sent to us. Your email address, the name and handle you choose, and a summary of each completed focus session (its length, species, rarity, clarity and start time). Nothing about what you blocked, ever.
- Health data is on-device. With your permission, the App reads and writes Apple Health data on your device only. It is never transmitted off your device to us or anyone else.
- Screen Time data is private by design. App blocking uses Apple’s Family Controls framework, which gives the App only opaque tokens. The App never learns which specific apps you chose, and that selection never leaves your device, signed in or not.
- No tracking. We do not track you across apps or websites, do not show ads, and do not sell data. There is no third-party analytics in the App.
- Deletion is one tap. Deleting your account inside the App removes your account row and everything keyed to it from our backend, and revokes the Sign in with Apple grant we hold.
2. Data the App handles, and why
a. On-device app content (focus sessions, specimens, settings, streaks)
Created and used by the App on your device and stored locally with Apple’s on-device storage (SwiftData). None of it reaches us in this form. The single exception is the summary of a completed session while you are signed in, described in section f, and that is a handful of numbers rather than a copy of your history.
b. iCloud sync (Apple CloudKit)
If you are signed into iCloud and have iCloud Drive enabled, your crystals, sessions, and settings sync across your own devices through your private iCloud database. This is operated by Apple under Apple’s iCloud terms and privacy policy. The developer of Crystalo has no access to your iCloud data.
c. Apple Health (HealthKit) — optional, on‑device only
With your explicit permission:
- Write: completed meditation and breathing sessions are saved to Apple Health as Mindful Minutes.
- Read: if you choose to connect Health, the App reads Sleep Analysis to display sleep context alongside your wellbeing data.
Health data is used only to provide these in‑app features. It is processed on your device, is never transmitted to us or any third party, is never used for advertising or marketing, and is never sold. You can revoke Health access at any time in iOS Settings → Privacy & Security → Health. (Required by Apple’s HealthKit policy.)
d. Screen Time / app blocking (Family Controls) — optional, on‑device only
To let you block distracting apps during focus sessions and on schedules, the App uses Apple’s Family Controls / Managed Settings / Device Activity frameworks in individual mode (you manage your own device). When you choose which apps to limit, iOS returns only opaque tokens — the App does not receive the names or identities of your apps, and these tokens never leave your device. On‑device screen‑time summaries shown inside the App are rendered locally and are not transmitted.
e. The optional Crystalo account
You can use the App indefinitely without one. Creating an account is required only for team leaderboards and for invite rewards, and the App asks for it at the moment you open one of those, not at launch. Sign-in works through Sign in with Apple, Google or an email magic link, and the session is held by our authentication provider, Supabase.
What the account itself stores:
- The email address attached to the sign-in method. With Sign in with Apple this is whatever Apple passes on, including a private relay address if you chose to hide your real one.
- An account identifier, and the provider you used.
- The handle and display name you type when you first open teams. These are chosen by you and are visible to other members of any team you join, so pick something you are comfortable showing them.
- Running totals shown on team leaderboards: your total focus seconds and longest streak.
- A device notification token, if you allow notifications, so a team push can reach you.
Signing in with two different methods creates two separate accounts, because Apple’s private relay address never matches the Google one. There is no way for us to merge them.
f. Completed focus sessions, while signed in
When you are signed in and a focus session finishes, the App sends a summary of it to our backend so team leaderboards have something to rank: the length, the species, the rarity, the clarity figure, the start time and a session identifier used to reject duplicates.
Sessions you abandon are not sent. Nothing about your blocking is sent, because the App does not have it in the first place (see section d). Meditation content, Health data and anything from your Grotto stay on the device. Signed out, no session summary leaves the device at all.
g. Teams
Creating or joining a team stores the team name, its invite code, who owns it and who is in it. Members of a team can see each other’s handle, display name and focus totals through that team’s leaderboard, and nothing else. There is no public profile directory and no global leaderboard in the App. If you report a team, we store the report so it can be reviewed.
h. Invites and Pro days
Your invite code, the accounts that redeem it and the Pro days each side has earned are recorded on our backend, because the reward is worth money and has to survive a reinstall. Both sides have to be signed in for a redemption to count. The days themselves are delivered through RevenueCat, which is told your account identifier and the entitlement to extend.
i. Subscriptions (Crystalo Pro)
Purchases and the free trial are processed by Apple through the App Store using your Apple ID. Apple does not share your payment details with us, and we receive only Apple’s standard sales and subscription reports.
Subscription state itself is handled by RevenueCat, which receives the purchase and receipt information from Apple along with an identifier for you: your Crystalo account identifier if you are signed in, otherwise an anonymous device-scoped one that RevenueCat generates. This is what lets Pro follow you to your other Apple devices and survive a reinstall, and it is also how gifted Pro days are applied. Managing or cancelling a subscription happens in iOS Settings → your Apple ID → Subscriptions.
3. Data we do not collect
- We do not collect your contacts, your precise location, your photos or your address book.
- We do not receive the list of apps you blocked, or any event telling us that a shield appeared.
- We do not use analytics, crash-reporting, advertising, attribution or tracking SDKs. There is no product analytics in the App at all.
- We do not track you across other companies’ apps and websites, and we do not sell or rent personal data.
- We do not read your Health data anywhere except on your own device.
The App’s App Store privacy label reflects the account: signed in, contact information (your email), an identifier and usage data (completed session summaries) are collected and linked to you, and purchases are handled as described above. None of it is used for tracking. Signed out, nothing is collected by the developer.
4. Who processes data for us
We keep the list short on purpose, and every one of these is a processor acting on our instructions rather than a party we sell anything to.
- Apple (iCloud sync, App Store payments, push delivery, Sign in with Apple), under Apple’s privacy policy.
- Supabase hosts the account, teams and invite data described in section 2. The database runs in the United States (AWS us-east-1).
- RevenueCat handles subscription state and delivers gifted Pro days (United States).
- Google, only if you choose Google as your sign-in method.
- Cloudflare serves this website and stores the waitlist email addresses collected on it, in a database of ours that no third party reads.
If you are in the EEA or the UK, this means account data is transferred to the United States. We rely on the European Commission’s standard contractual clauses as offered by these providers. Data that never leaves your device or your iCloud, which is most of what the App holds, is not part of any such transfer.
5. How long we keep it
Account data, team membership and session summaries are kept while your account exists. Deleting the account deletes them, including the invite records and Pro day ledger keyed to it. Records that Apple or RevenueCat keep for tax and accounting reasons are governed by their own retention rules, not ours. Waitlist addresses are kept until launch or until you unsubscribe, whichever comes first.
6. Your rights and choices
- Delete your account: in the App, under You → account. This removes the account row and everything that cascades from it, hands over any team you owned so it does not vanish for the other members, and revokes the Sign in with Apple grant. Your local data and your iCloud copies are deliberately left alone: they were never part of the account.
- Access, correction, portability, objection: if you are covered by the GDPR, the UK GDPR, the CCPA or a similar law, write to the address below and we will act on the request. The handle and display name are editable in the App at any time.
- Withdraw consent: signing out stops any further session summaries from being sent. Deleting the account removes what was already sent.
- Revoke Health access: iOS Settings → Privacy & Security → Health → Crystalo.
- Revoke Screen Time access: iOS Settings → Screen Time, or in the App’s Focus Shield.
- Stop iCloud sync: iOS Settings → your Apple ID → iCloud.
- Delete the local data: deleting the App removes its on-device data, and iCloud copies can be removed via iOS Settings → your Apple ID → iCloud → Manage Account Storage.
Our legal basis for handling account data is the contract you enter by using teams or invites, and consent for notifications. Everything else runs on your device without a legal basis being needed from us.
7. Children
Crystalo is not directed to children under 13, and we do not knowingly collect personal data from them. Where local law sets a higher age for consenting to data processing, that age applies to creating an account. The App uses Screen Time in individual mode, meaning you limit your own device; it is not a parental control product.
8. This website, and its cookies
The sections above describe the App. This one describes crystalo.app, which is a different thing with far less in it.
Nothing is written to your device before you choose on the banner. If you accept analytics, the site loads Cloudflare Web Analytics: it counts page views and reports which pages are read, sets no cookie, builds no profile, and cannot follow you to another site. If you refuse, that script is not loaded at all rather than merely silenced. There are no advertising or social network trackers here, and none are planned.
Two entries record the choice itself, and only once you have made it: a cookie named
crystalo_consent and, in local storage, crystalo.consent with the date and
the version of the text you agreed to. Both last twelve months, after which the banner asks again —
consent that never expires is not consent. The Cookie settings link in the footer of every
page reopens the banner with your current choice, and a new choice applies immediately.
The waitlist form on the front page stores your email address in our own database on Cloudflare and nowhere else. It stays there until you ask for it to be removed; the address in the contact section below is enough for that.
9. Changes
We may update this policy as the App evolves. Material changes will be reflected by the “Last updated” date above and, where appropriate, noted in the App.
10. Contact
Questions about privacy, or a request under any of the rights above: hi@crystalo.app.
The waitlist form on the home page is separate from the App and needs no account. Submitting it stores the address you type, plus the language your browser asks for and the site it came from, in our own database, where it sits until we write to announce the launch. Every message we send carries an unsubscribe link, and you can ask us to remove the address sooner at the contact address above.