Effective date: July 12, 2026
Summary
The Version 1.0 iPhone app has no HMTI account, backend, cloud synchronization, remote analytics, advertising SDK, or remote push provider. Goals, recordings, reflections, settings, and check-in history are stored on the iPhone where they were created. Apple's opaque selected-app tokens stay in a protected local App Group shared only by HMTI's app and Screen Time extensions.
Local does not mean recoverable everywhere. Version 1.0 does not synchronize to another device. Depending on your Apple settings and available backup, Apple may include eligible goals, recordings, reflections, and history in a device backup and may restore them through Apple's device-restore process. HMTI does not operate, inspect, or guarantee Apple backups. Screen Time authorization and selected-app tokens are device-specific, excluded from HMTI's backup-eligible data, and must be set up again on a new or replacement device.
Data stored on this iPhone
- Local profile and settings
- Adult attestation, setup progress, protection health, notification decision, reminder settings, and pause settings.
- Age-eligibility state
- If you choose “I’m under 18,” HMTI stores one local eligibility decision redundantly so a failed write cannot reopen adult features. It contains no birth date, numeric age, identity, or app selection. The app and its Screen Time extensions use it only to disable adult features and remove HMTI restrictions until completed Delete All or app removal.
- Screen Time protection state
- Apple's opaque application tokens for the individual apps you select, plus short-lived local shield-action and 15-minute pass state. These values are protected, excluded from backup, and never exported. Selection, handoff, and pass state is removed when authorization is revoked. Completed Delete All removes every App Group user, content, token, selection, eligibility, handoff, pass, pause, and repair value.
- Deletion-epoch UUID
- One backup-excluded, non-identifying deletion-epoch UUID remains locally after Delete All solely to reject an app action that was suspended before deletion. It contains no user identity, app identity, selection, activity, or content and is removed when the app is removed.
- Goals
- Your active goal and its local revision history.
- Recordings
- An optional personal check-in recording and optional audio reflections, stored as protected files. Recordings never autoplay from a notification or app launch.
- Check-in history
- Times when HMTI received a supported local trigger or current shield-button handoff, grouped risk episodes, check-in responses, optional urge ratings, and bounded setup events. App identity is not stored in this history.
- Reflections
- Optional text or audio that you choose to save. Version 1.0 does not analyze, diagnose, transcribe, upload, or score reflection content.
Dates are stored in a standard time format and displayed using the iPhone’s current locale and time zone. Local events are used to power your on-device history, insights, setup recovery, and explicit exports.
What the app does not collect
Version 1.0 does not collect or store:
- The name, icon, or bundle identifier of another app. It stores only Apple's opaque tokens for individual apps you explicitly select.
- Your general installed-app list, raw Screen Time usage history, picker search terms, browsing history, location, contacts, email content, or advertising identifiers.
- Bank, brokerage, payment, purchase, deposit, wager, or loss information.
- A remote account identifier, name, email address, password, or telephone number.
- Remote analytics, advertising attribution, session replay, or third-party crash reports.
A shield display, shield-button action, or HMTI check-in does not prove that gambling, shopping, posting, or any other behavior happened. The app cannot see what happened inside another app and does not claim to prevent a relapse, wager, purchase, post, or loss.
Permissions
Screen Time
After you confirm the adult/privacy notice, HMTI asks Apple for individual Family Controls authorization. If you approve, Apple shows its private app picker. HMTI receives opaque tokens only for what you select and uses them locally to apply a reversible Managed Settings shield. HMTI does not request access to raw app-and-website usage data.
You may deny or revoke access. HMTI then clears its shields, monitoring, selected-app tokens, pending handoff, and temporary pass. Manual check-ins and your other local content remain available. Reauthorization requires selecting apps again.
Notifications
Notification permission is optional and used only for private local alerts and any daily goal reminder you explicitly enable. Risk-episode notifications use generic wording and do not show gambling language, your goal, a recording, or another app’s identity. Version 1.0 does not register for remote push notifications.
Microphone
Microphone permission is optional and requested only when you choose to record. If you decline, text check-ins, goals, reflections, and manual check-ins remain available.
Local device authentication
When available, the app may ask iOS to confirm your identity before preparing a readable export or completing a sensitive local action. HMTI receives the result of that device check, not biometric data.
Screen Time protection and shields
Version 1.0 commits individual app selections only. Category and website selections are discarded. The opaque tokens and a small amount of recovery state are shared locally with HMTI's Shield Configuration, Shield Action, and Device Activity Monitor extensions. They are not synchronized, backed up, exported, logged, or sent to HMTI.
When a selected app is opened, iOS may show HMTI's reversible shield. The shield's copy is generic and does not include your goal, recording, history, or a behavior label. A 15-minute continue choice temporarily exempts only the triggering opaque app token after a recovery schedule is armed; other selected apps remain shielded.
On iOS 26.5 or later, Apple's shield response can open HMTI for a check-in. On iOS 17 through iOS 26.4, Apple provides no equivalent response, so the selected app closes and you must open HMTI manually. HMTI cannot reopen or deep-link back into an arbitrary selected app.
Apple's Family Controls, Managed Settings, Device Activity, and picker services are governed by Apple's own terms and privacy practices. Device Activity is used for bounded local recovery, not as a raw app-launch or usage-history feed.
Export and deletion
You can choose to create a readable local export. The app lets you decide whether to include reflection text or audio. The export is prepared in a temporary directory and presented through the iOS share sheet. Once shared, the destination you choose controls the exported copy.
You can delete individual content or delete all local HMTI data. Delete All remains available from Age Eligibility after an under-18 choice. It first clears HMTI's shields and Device Activity monitoring, then removes the eligibility flag, opaque selections, pending shield actions, temporary passes, notifications, audio, temporary exports, app records, and setup state before returning to first launch. It does not manage copies retained by Apple device backup or by a destination you previously chose through the share sheet. There is no account-deletion request because Version 1.0 has no HMTI account.
Website, email, and external links
This static site contains no advertising scripts, analytics scripts, tracking pixels, remote fonts, account forms, or cookies set by HMTI site code. Cloudflare Pages serves this site. When you request a page, Cloudflare may process network and request information such as an IP address, traffic-routing data, system-configuration information, and other traffic data to deliver, operate, and protect the service. Cloudflare handles that information under its privacy policy. HMTI does not add site analytics or receive your in-app goals, history, app selections, or recordings through website requests.
If you email admin@holdmetoit.info, Google Workspace processes the message and any information you choose to include. Do not email sensitive recordings or reflection content. Support email is not emergency monitoring.
Links to Apple, the National Council on Problem Gambling, the 988 Lifeline, or another outside website leave HMTI. The destination receives the request and applies its own privacy policy. HMTI does not transmit your in-app goals, history, or recordings through those links.
Changes and contact
This notice must be reviewed whenever a release changes data transmission, third-party code, accounts, synchronization, analytics, billing, or other privacy-relevant behavior. The effective date will change when the notice changes materially.
Privacy questions may be sent to admin@holdmetoit.info.