Privacy Policy
Last updated: September 15, 2026
Paradox is an app about protecting your attention. Selling it would be a strange way to run the business, so we don't.
The short version. Paradox works without an account. If you do sign in, we store your name and email from Google or Apple, an anonymous device identifier, and a record of your own actions inside Paradox, such as shields shown, pauses taken and guard switched on and off. Whether or not you sign in, the app sends product analytics (the same kinds of actions, plus crash reports and recordings of your screen inside Paradox) to PostHog, so we can see what works and what breaks. This website counts its visits with the same tool, and sets no cookies to do it. If you join the waitlist, we store the email address you typed and write to it once, the day the app ships. The per-app times you see in Stats never reach us. The one thing about your time in other apps that does leave the phone is a battle you play with other people: its players, and we, see which app the battle is on and roughly how far each player got each day. There are no ads, and nothing here is used to track you across other companies' apps or websites.
1. Who we are
Paradox ("Paradox", "we", "us") is an iOS app built by Diego Sepúlveda. You can reach us at any time at support@tryparadox.app. This policy covers the Paradox iOS app and this website.
2. Using Paradox without an account
Blocking, scheduling, statistics, battles and reading all work with no account. Signed out, no name, email or account of yours exists anywhere, and your rules, your selected apps and your event history stay on the phone. A few features still talk to our server, each carrying a random identifier created on the phone for this installation rather than anything about you: the days you had a block on (they count towards your guardian's level), the articles you listened to and for how long, battles you play with other people (see section 4) and anything you write to us. The product analytics described in section 5 also run in that state, attached to a random identifier generated on the device rather than to you.
Signing in is optional and lives in the Profile tab. It lets your history follow you to a new phone, it is needed to earn guardians, and it is needed to subscribe to Paradox Premium, because a subscription belongs to your account rather than to one phone.
3. What we collect when you sign in
- Name and email address. Provided by Google Sign-In or Sign in with Apple when you authorise them. If you use Apple's "Hide My Email", we receive a relay address and never your real one. Either field may be missing, and the account works anyway.
- A provider identifier. The stable subject ID Google or Apple uses for you, so we can recognise you next time. We do not store the sign-in tokens themselves: they are exchanged once for our own session and discarded.
- A device identifier. Apple's identifierForVendor, which is specific to this app on this phone, is not shared with other developers, and is destroyed when you delete the app. We use it to count devices on an account and to keep events from being counted twice.
- Session details. Device name, iOS version and app version, so you can tell your own sessions apart and we can debug version-specific problems.
- Your actions inside Paradox. A small set of events, each with a timestamp: a shield was shown, you passed through it anyway, you took a conscious pause, you started or stopped guarding, and moments like those. This is how we measure whether the product actually helps.
- Your player name. If you choose one: a unique name of 3 to 16 characters, which is what the other players of a battle see.
- Your subscription. If you subscribe to Paradox Premium, Apple takes the payment and we never see your card. We receive the purchase record (the plan, when it started, when it renews or ends, and its status) through RevenueCat, the service that keeps track of subscriptions for us, and keep it with your account.
We never ask for a password, because there isn't one: the only way into an account is a token signed by Google or Apple.
When you write to us. The "Write to us" screen does not require an account. What you send us is the text you typed, the time, your app and iOS version, your language, and the device identifier. If you are signed in it arrives attached to your account; if you are not, it arrives anonymously.
4. What we do not collect
- Your screen time report. The per-app times you see in Stats never reach us. iOS computes them inside a sandboxed extension that is forbidden from passing them back to the app, so there is no path by which they could be sent anywhere. The screen recordings described in section 5 are masked over that part of the screen, so they do not carry them either. The only thing about your time in another app that can leave the phone is coarse, and only in a battle with other people, described below.
- Which apps you guard. Apple gives the app an opaque token for each selected app, not a name or bundle ID, so we cannot tell what you picked. Guarding events carry a short one-way fingerprint of that token, only so that two guarding sessions of the same app can be told apart. The one app we know by name is the app of a battle you play with other people, which you choose when the battle is created.
- Anything you type or read elsewhere. Paradox has no keyboard extension, no browsing history, no message access.
- Location, contacts, photos, health data, or the contents of any other app.
Battles with other people
A battle is one app, one week and one daily limit. Played alone, nothing about your usage leaves the phone; only the result, such as how many days you won, reaches our analytics. Played with other people, the battle lives on our server so that each phone can see the others, and it stores: which app the battle is on and its daily limit, and for each player a random installation identifier, platform, app version, language, player name, guardian and level, the day they joined or left, and for each day the highest step of minutes crossed on that app (a lower bound, never the exact time) and the moment the limit was reached, if it was. Everyone in the battle sees those days, and anyone with the battle's code can look up its app, its limit and the name of the person who started it. Joining a battle with other people is how you agree to share those days with them.
5. Product analytics, and the tracking we don't do
Paradox uses PostHog for product analytics. It runs whether or not you are signed in, and it is how a small team finds out that a screen confuses people or that the app crashes on a particular iOS version. It collects:
- Events. The same actions listed in section 3 (a shield was shown, a pause was taken, guarding started), plus which screens you opened, and counts describing your setup: how many apps you guard, how many rules you made, whether you signed in. Never the names of your apps: guarding events carry only the fingerprint described in section 4.
- Crash reports. The type of error and the stack trace when the app closes unexpectedly.
- Session recordings. A recording of your screen while you are inside Paradox, so we can see where a flow goes wrong. App icons, the Screen Time app picker and the statistics card are masked out of the recording before it leaves the phone, and no recording is ever made of anything outside Paradox.
- Identifiers. An identifier for this installation, and your account identifier once you sign in, so that a history does not split in two the day you do. If you sign in, your name and email are attached to that profile so we can recognise the account.
This website
www.tryparadox.app uses PostHog too, to count its visits: which pages you open, the page or search that sent you here, your country, browser and device type, and whether you pressed the waitlist button. It sets no cookies and stores nothing in your browser, which is why there is no banner to click through, and also why every visit starts from zero: we cannot tell that you came back. As with any website, your IP address reaches PostHog with each request; it is used to look up the country. The requests travel through our own domain rather than PostHog's.
Paradox contains no advertising SDKs. We do not combine your data with data from other companies, we do not build advertising profiles, and we do not sell or rent your personal information to anyone. Nothing here follows you into other companies' apps or websites, which is why the app does not ask for App Tracking Transparency permission. If you would rather not be included in analytics at all, write to us and we will delete your analytics profile.
The waitlist
If you leave your email address on the waitlist page, we store that address, the link or button that brought you there, the two-letter country our CDN assigns to your connection and your browser's language. That is the whole record: no name, no profile, nothing joined to your analytics. We will write to that address once, on the day Paradox is released, and you can ask us to delete it before or after that by writing to support@tryparadox.app. We do not sell or share the list, and it is not a newsletter.
That page carries no analytics of its own: it is a single file with no tracking script in it. The form is protected by Cloudflare Turnstile, which checks that a person and not a script is submitting it. To do that, Cloudflare receives your IP address and some signals from your browser. Cloudflare acts as our processor for that check and does not use it to build an advertising profile; it sets no tracking cookie for it. We never store your IP address ourselves.
6. Where your data lives
Account and event data is stored in a PostgreSQL database hosted by Neon, reached through an API hosted by Vercel. Subscriptions are tracked by RevenueCat, and guardians, backgrounds, music and articles are downloaded from Cloudflare. Analytics data is stored by PostHog on its US cloud. Waitlist addresses live in that same Neon database. Cloudflare runs the anti-spam check on the waitlist form. All of them are processors acting on our instructions and none is permitted to use your data for their own purposes. Data may be processed in the United States. Sign-in is handled by Google and Apple under their own privacy policies.
Session tokens are stored on your device in the iOS Keychain, and on the server only as a one-way hash: a leak of our database would not let anyone sign in as you.
7. How long we keep it
- On your device: events older than 90 days are deleted automatically.
- On our servers: your account and events are kept while the account exists, so your statistics stay meaningful over time. Sign-in sessions expire after 90 days.
- On the waitlist: your address is kept until the release email has been sent, and deleted within 90 days after that. Ask us sooner and it goes sooner.
- In analytics: session recordings are deleted automatically after 30 days, and events and crash reports after 12 months. Both are deleted sooner on request.
- After deletion: everything linked to your account is removed from the live database within 30 days, and from encrypted backups within 90.
8. Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it and close your account. Write to support@tryparadox.app from the address on the account and we will answer within 30 days. See Delete your account for the deletion process specifically.
Deleting your account from inside the app removes your account, your provider identity, your sessions and every event stored against them, permanently and with no grace period. From that moment the app stops attaching anything to you and starts over with a fresh anonymous identifier. The analytics profile already held by PostHog is not deleted by that action; ask us and we will delete it too.
Deleting the app removes everything stored locally, including the device identifier. If you never signed in, that is the whole of it: there is no account anywhere else, only the anonymous analytics described in section 5.
If you are in the European Economic Area or the United Kingdom, the legal bases we rely on are performance of a contract (running your account) and our legitimate interest in understanding whether the product works. You also have the right to complain to your local data protection authority.
9. Children
Paradox is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, write to us and we will delete it.
10. Changes to this policy
If we change what we collect or why, we will update this page and change the date at the top. Material changes will also be announced in the app before they take effect.
11. Contact
Questions, requests, or something here that doesn't match what you see in the app: support@tryparadox.app.