Privacy Policy
Last updated: August 7, 2026
Paradox is an app about protecting your attention. Selling it would be a strange way to run the business, so we don't.
The short version. Paradox works fully without an account. If you do sign in, we store your name and email from Google or Apple, an anonymous device identifier, and a count of your own actions inside Paradox — shields shown, pauses taken, guard switched on and off. We never see how long you spend in other apps, or even which apps you chose. There are no ads and no third-party trackers.
1. Who we are
Paradox ("Paradox", "we", "us") is an iOS app built by Diego Sepúlveda. You can reach us at any time at support@tryparadox.app. This policy covers the Paradox iOS app and this website.
2. Using Paradox without an account
Blocking, scheduling, statistics and reading all work with no account and no network connection. In that state nothing about you leaves your device: your rules, your selected apps and your event history are stored only on the phone.
Signing in is optional and lives in the Profile tab. Its only purpose is to let your history follow you to a new phone.
3. What we collect when you sign in
- Name and email address. Provided by Google Sign-In or Sign in with Apple when you authorise them. If you use Apple's "Hide My Email", we receive a relay address and never your real one. Either field may be missing, and the account works anyway.
- A provider identifier. The stable subject ID Google or Apple uses for you, so we can recognise you next time. We do not store the sign-in tokens themselves: they are exchanged once for our own session and discarded.
- A device identifier. Apple's identifierForVendor, which is specific to this app on this phone, is not shared with other developers, and is destroyed when you delete the app. We use it to count devices on an account and to keep events from being counted twice.
- Session details. Device name, iOS version and app version, so you can tell your own sessions apart and we can debug version-specific problems.
- Your actions inside Paradox. Five kinds of event, each with a timestamp: a shield was shown, you passed through it anyway, you took a conscious pause, you started guarding, you stopped guarding. This is how we measure whether the product actually helps.
We never ask for a password, because there isn't one — the only way into an account is a token signed by Google or Apple.
4. What we do not collect
- Your screen time. How long you spend in any app never reaches us. This is not only a policy choice: iOS hands those numbers to a sandboxed extension that is forbidden from passing them back to the app, so there is no path by which they could be sent anywhere.
- Which apps you guard. Apple gives the app an opaque token for each selected app, not a name or bundle ID. We could not tell you what you picked, let alone tell anyone else.
- Anything you type or read elsewhere. Paradox has no keyboard extension, no browsing history, no message access.
- Location, contacts, photos, health data, or the contents of any other app.
5. No tracking, no advertising
Paradox contains no advertising SDKs and no third-party analytics products. We do not combine your data with data from other companies, we do not build advertising profiles, and we do not sell or rent your personal information to anyone. Because nothing is used for tracking, the app does not ask for App Tracking Transparency permission.
6. Where your data lives
Account and event data is stored in a PostgreSQL database hosted by Neon, reached through an API hosted by Vercel. Both are processors acting on our instructions and neither is permitted to use your data for their own purposes. Data may be processed in the United States. Sign-in is handled by Google and Apple under their own privacy policies.
Session tokens are stored on your device in the iOS Keychain, and on the server only as a one-way hash — a leak of our database would not let anyone sign in as you.
7. How long we keep it
- On your device: events older than 90 days are deleted automatically.
- On our servers: your account and events are kept while the account exists, so your statistics stay meaningful over time. Sign-in sessions expire after 90 days.
- After deletion: everything linked to your account is removed from the live database within 30 days, and from encrypted backups within 90.
8. Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it and close your account. Write to support@tryparadox.app from the address on the account and we will answer within 30 days. See Delete your account for the deletion process specifically.
Deleting the app removes everything stored locally, including the device identifier. If you never signed in, that is the whole of it — there is nothing left anywhere else.
If you are in the European Economic Area or the United Kingdom, the legal bases we rely on are performance of a contract (running your account) and our legitimate interest in understanding whether the product works. You also have the right to complain to your local data protection authority.
9. Children
Paradox is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, write to us and we will delete it.
10. Changes to this policy
If we change what we collect or why, we will update this page and change the date at the top. Material changes will also be announced in the app before they take effect.
11. Contact
Questions, requests, or something here that doesn't match what you see in the app: support@tryparadox.app.