YOLOIT

Privacy Policy

YOLOIT for iOS and Android · Last updated 2026-09-20

DRAFT — not for publication. Replace BM NODEX SRL, {{COMPANY_ADDRESS}}, privacy@yoloit.app, yoloit.app and 2026-09-20, resolve every CONFIRM, and have a lawyer review before this goes live.

Source of record: docs/legal/privacy_policy.md. Keep the two in step.

On this page

  1. Who we are
  2. The short version
  3. What stays on your device
  4. What does leave your device
  5. Who else sees it
  6. How long we keep it
  7. Children
  8. Your rights
  9. If we add accounts
  10. Deleting your data
  11. Changes
  12. Contact

1. Who we are

YOLOIT is published by BM NODEX SRL, {{COMPANY_ADDRESS}}. We are the data controller for the limited data described below.

CONFIRM The Apple Developer account the app ships under is BM NODEX SRL (Romania), Team ID 768R7DDJL8. Confirm whether BM NODEX SRL is the controller or publishes on the client's behalf, and name the controller here.

Questions, requests and complaints: privacy@yoloit.app.

2. The short version

YOLOIT turns real-world challenges into screen time: you do a small thing in the real world, you earn minutes, and the app you chose to block opens for those minutes.

3. What stays on your device and never leaves it

The following is written to the app's private storage on your phone. It is not transmitted to us or to anyone else, and we have no way to read it.

WhatWhereWhy
The apps you chose to blockiPhone: an opaque Apple Screen Time token per app, in the app group group.com.yoloit.app. Android: the package name and display name, in the app's private preferences and database.So the app knows what to block and what to release.
Your unlock session — when it ends, an internal idDevice storageSo the block returns on time even if you close the app or restart the phone.
Challenges you completed, when, and the minutes each earnedThe app's private database on the deviceYour history, your streak and your balance.
Your minute balance and every change to itSame databaseSo the balance survives restarts.
Your chosen categories, difficulty, reminder settings, reduce-motion preferenceApp preferencesSo the app behaves the way you set it.

Uninstalling YOLOIT removes all of it. You can also wipe it from inside the app — see section 10.

3.1 Screen Time on iPhone and iPad

On iOS, YOLOIT uses Apple's Screen Time (Family Controls) framework to block apps. This matters, so it is worth being precise:

3.2 Usage Access and the block overlay on Android

Android has no Screen Time framework, so blocking works differently:

A background service keeps this running while YOLOIT is closed. Android requires it to show a permanent notification, so you can always see when it is on.

3.3 Other Android permissions

PermissionWhat it is for
Foreground service (special use)Keeps the block running while YOLOIT is in the background.
Post notificationsThe permanent "blocking is on" notification, and your optional daily reminder.
Schedule exact alarmRe-locks your apps at the exact minute your earned time runs out.
Receive boot completedRestores the block after you restart the phone.
App-list visibilityLets the in-app picker list your launchable apps so you can choose which to block. YOLOIT does not request the broad "query all packages" permission.

4. What does leave your device

4.1 Crash reports — Google Firebase Crashlytics

When YOLOIT crashes or hits an unexpected error, a crash report is sent to Firebase Crashlytics so we can fix it.

4.2 App analytics — Google Firebase Analytics

Firebase Analytics lets us see, in aggregate, how the app is used.

CONFIRM Analytics consent is the one open decision. The app contains a switch that turns analytics collection off, but nothing calls it yet, so in a released build collection is on from first launch. Before publication the client must choose: collection off until the user opts in, a single consent question during onboarding, or a documented legitimate-interest position — and this section must then say exactly which.

4.3 Challenge content — Google Firebase Firestore

YOLOIT ships with a built-in set of challenges and can download an updated set. The app reads two public documents and nothing else. This is a one-way read: the app sends none of your data with the request, writes nothing, and the documents are the same for every user. If the download fails, the built-in set is used and the app works normally.

4.4 Optional reminder notifications

The daily reminder is scheduled locally by your own device — you can turn it off or change its time in Profile. There is no push server; we send you nothing and cannot see whether you opened a reminder.

4.5 What we do not do

5. Who else sees this data

ProcessorWhat they get
Google (Firebase) — Crashlytics, Analytics, FirestoreCrash reports and the automatic analytics measurements described in section 4. CONFIRM the Firebase data region and the data-processing terms accepted for the project.
Apple (iOS) / Google Play (Android)The app-store relationship, and any crash data you separately choose to share with Apple or Google in your own device settings.

No one else. We use no other analytics, attribution, advertising or support tool.

6. How long we keep it

7. Children

YOLOIT is not designed for or directed at children. CONFIRM the minimum age to state here; it must agree with the store age ratings.

YOLOIT uses Apple's Family Controls framework — the same framework parental-control apps use — but YOLOIT is a self-control app. It blocks the user's own apps at the user's own request on the user's own device. There is no parent/child pairing, no remote supervision and no way for one person to restrict another's device.

8. Your rights

If you are in the EU or the UK you have the right to ask for access to your personal data, its correction or deletion, a copy in a portable form, restriction of or objection to processing, and to withdraw consent where processing is based on consent. You can also complain to your national data protection authority. CONFIRM the supervisory authority once the controller is fixed.

In practice, for this version of YOLOIT: the data that identifies you is almost entirely on your phone and only on your phone, so you exercise these rights yourself with the in-app reset or by uninstalling. For the crash and analytics data held by Firebase, write to privacy@yoloit.app. Because it is not tied to a name or an account, we may need you to provide the identifier we would use to find it, and where we genuinely cannot identify you from it we will say so rather than guess. We answer within one month.

9. If we add accounts later

Accounts, cloud sync and push notifications are designed but not built in this version. Nothing in the app signs you in, and no account exists. If and when accounts ship:

Until then, this section describes nothing that exists.

10. Deleting your data

You want toDo this
Wipe everything on the phone but keep the appProfile → Reset. It clears your settings, your minute balance, your completed challenges, your chosen categories and your block list, and cancels your reminder.
Remove everything, completelyUninstall YOLOIT.
Stop the blocking without deleting anythingClear your block list in the app, or withdraw the Screen Time permission (iOS Settings → Screen Time) or Usage Access / Display over other apps (Android Settings).
Ask about the crash and analytics dataWrite to privacy@yoloit.app.

11. Changes to this policy

If this policy changes materially we will update the date at the top, publish the new version at https://yoloit.app/privacy, and — where the change affects what we collect — tell you in the app before the change takes effect.

12. Contact

BM NODEX SRL
{{COMPANY_ADDRESS}}
privacy@yoloit.app