Privacy Policy
Kayis · Last updated: 9 September 2026
Kayis helps you spend less time on your phone. This policy explains exactly what we collect, why, and what we never collect.
What we collect
| Data | Why | Where it is stored |
|---|---|---|
| Your email address | To create your account, sign you in, and reset your password | Supabase servers |
| Your name | To address you inside the app | Supabase servers |
| Onboarding answers: your persona, goals, self-reported screen time, daily goal | To tailor the app to you | Supabase servers |
| The pledge you wrote | To show it back to you in the app | Supabase servers |
| Your focus sessions, points, and day streak | To run sessions and track your progress | Supabase servers |
| Your blocking rules, daily limits, and protection routines, including their names, days, and hours | To sync and enforce the protection you configure | Supabase servers + your device |
| One-way hashes of the opaque app and category tokens you selected. Names and icons stay on your device. | So a rule can be tied to an app without us learning which app it is | Supabase servers + your device |
| Your subscription product, expiry, verification time, and a one-way hash of Apple's original transaction identifier | To verify Kayis Plus, prevent duplicate rewards, and unlock it across your devices. We do not receive card details. | Supabase, Apple, and your device |
| Your referral code, how many times it has been redeemed, and by whom | To run the referral programme and stop a code being redeemed more than 6 times | Supabase servers |
| Your social ID, friends list, leagues, and nudge messages | To run friend requests and leagues | Supabase servers |
| An APNs device token | To deliver a friend's nudge when Kayis is closed | Supabase servers and Apple |
What we do not collect
- We do not collect your screen-time figures. Not your daily total, not your pickups, not your minutes per app, not a category breakdown, and not any score derived from them. None of it is uploaded, and none of it is stored in your account.
- We do not receive app names or bundle identifiers. Apple hands Kayis opaque tokens. One-way hashes of those tokens are stored with your account so a rule can be tied to the app it belongs to, but they do not reveal the app or category name.
- We do not collect your location, your contacts, your photos, or any content inside your apps.
- We do not track you across other apps or websites, and we use no advertising or tracking tools.
- We do not sell your data, and we never share it with anyone for marketing purposes.
Screen Time permission
Kayis uses Apple's Screen Time APIs (FamilyControls, ManagedSettings, and DeviceActivity). The permission you grant does two things: it lets Kayis apply blocks to the apps you chose, and it lets iOS show you your usage inside the app.
Those are separate paths, and only the first one involves us. When you look at your usage in Kayis, you are looking at a DeviceActivityReport — a view rendered by a separate Apple-controlled extension that runs in its own sandbox. That extension has no network access and no shared storage with the rest of the app. It draws the numbers on screen and nothing else. Kayis itself never receives them, so there is nothing for us to upload.
App and category names, bundle identifiers, icons, and the content of your apps stay inside Apple's protected frameworks at all times. Nothing about apps you did not select ever leaves your device.
Notifications
The daily reminder is optional and you turn it on yourself from the Account tab. It is a local notification your device schedules by itself.
Friend nudges are optional and use Apple Push Notification service. If you allow them, we store a device token linked to your account and send it to Apple only to deliver a short message from a friend. You can turn notifications off in iOS Settings, and deleting your account removes the token.
Who processes your data
- Supabase — database hosting and authentication. Data is protected by Row Level Security policies, so no user can read another user's rows.
- Apple — supplies the Screen Time frameworks that run on your device, and processes payment and subscription verification, including App Store Server API reconciliation. We never receive your card details.
- Vercel — hosts these pages only (privacy, terms, support). Visiting the page passes through ordinary server logs. Vercel has no connection to the app or to your data inside it.
There are no other providers. No analytics, no advertising, no tracking tools, and no crash-reporting tools.
Where your data is stored
Your data is stored on Supabase servers in Australia — Sydney (region ap-southeast-2), which is outside the Kingdom of Saudi Arabia. By using the app you consent to your data being transferred there and processed in that region.
Supabase acts as a data processor on our behalf only, and does not use your data for any purpose of its own. If we move the data to another region in future, we will update this page.
Retention
We keep your data for as long as your account exists.
If you delete your account, its active database rows are deleted immediately — including your profile, points, focus sessions, blocking rules, protection routines, and referral records — and are no longer available to Kayis. Residual encrypted backup copies may remain until Supabase's backup-retention cycle overwrites them; they are not used to restore individual accounts. Apple retains App Store transaction records under its own policy.
Your rights
- Access and correction: your data is shown inside the app and you can edit most of it from the Account tab.
- Deletion: Account → "Delete my account permanently". Deletion is immediate, subject to the exception above.
- A copy of your data: request it at the address below and we will send it to you.
- Withdrawing consent: by deleting your account, or by turning off the Screen Time permission in your device settings.
- Complaints: if you are unhappy with how we handle your data, you have the right to complain to the competent data protection authority in Saudi Arabia (the Saudi Data and AI Authority — SDAIA).
Security
Traffic between the app and the server is encrypted over HTTPS, and row access is governed by Row Level Security policies at the database level. If a breach affecting your personal data occurs, we will notify you and the competent authority as required by law.
Children
Kayis is intended for people aged 13 and over. We do not knowingly collect data from anyone younger. If you become aware that a child has created an account, contact us and we will delete it.
Changes to this policy
If we change anything, we update the date at the top of this page. If the change is material — meaning we collect a new kind of data, or use it in a different way — we will notify you inside the app before it takes effect.
Contact us
For any question about your privacy, or any request concerning your data: app.kayis@gmail.com