What we collect
As little as possible. Lavendr is a focus app. Almost everything it needs to work happens entirely on your device. There is no Lavendr account, no profile, no sign-in.
Lavendr does not run its own analytics server. The only product analytics we have access to are the anonymous, aggregated metrics that Apple's App Store Connect surfaces to every developer: downloads, sessions, retention buckets, and the like, plus the onboarding and subscription-screen signals described below. Apple collects these anonymously and you can opt out at any time in iOS Settings → Privacy & Security → Analytics & Improvements.
Beyond that, the only data that ever reaches us is crash reports, handled by Apple, described below.
What we never collect
- The list of apps you've blocked
- The names or contents of tasks you've added
- Your earned minutes, balances, or streak count
- When you start, pause, or finish a session
- Your exact screen time figures or app-usage breakdowns
- Your location, contacts, photos, or microphone
- Your name, age, or anything tying the app to your identity
- Advertising IDs (IDFA, IDFV beyond Apple's own use, etc.)
Screen Time data
Lavendr is built on top of Apple's Screen Time / Family Controls system. It's what lets Lavendr block the apps and websites you choose, run focus sessions, and keep track of the minutes you earn. Here's how each piece works, in plain language:
Family Controls authorization
Before Lavendr can do anything with your Screen Time, iOS shows you a system prompt asking permission. The authorization is granted to the app by you, and you can revoke it any time in iOS Settings → Screen Time.
FamilyActivitySelection
When you pick the apps you want to block, iOS hands Lavendr an opaque token. Not the names, not the bundle IDs, not the icons. Just a reference Apple can resolve on its own. That token is stored locally on your device. Lavendr never sees which apps it refers to.
ManagedSettings
During a focus session, Lavendr uses ManagedSettings to ask iOS to enforce the block locally on your device. The enforcement happens at the OS level. Nothing about which apps you blocked, or when, leaves the phone.
DeviceActivityMonitor extension
Lavendr ships an extension that runs in its own sandboxed process, separate from the main app. iOS wakes it up when a usage limit is hit so it can quietly enforce the appropriate block. The extension has no network access. It cannot phone home, even if we wanted it to.
On-device storage
Lavendr's extensions and main app share a private App Group container on your device. Your blocked-apps selection, focus session records, and earned minutes are computed and stored there, locally. None of it is transmitted to us.
Family Sharing. If you're a parent who wants to use Lavendr alongside a child's device, all of the parental setup happens through Apple's Family Sharing system, not through Lavendr. We never see who is in your family, who is supervising whom, or anything else about that relationship.
App blocking
Blocking, unblocking, and changing your selection all happen locally, using the FamilyActivitySelection and ManagedSettings APIs described above. Nothing about your blocked-apps list is sent to our servers. We don't have servers that store it.
Your tasks & minutes
Every task you add, every Pomodoro timer you run, every minute you earn or spend is stored locally on your iPhone in the app's private storage. Nothing syncs to other devices, nothing syncs to our servers. If you delete the app, the data is gone.
If you reset your task progress or delete all tasks from Settings, that data is gone immediately and permanently from your device.
Crash & bug reports
Lavendr uses Apple's built-in TestFlight and Xcode Organizer crash reporting only. When the app crashes, the report is sent to Apple, anonymized per Apple's policies, and we may receive aggregated, anonymized summaries through Apple's developer tools.
We do not operate our own crash collection endpoint, and we do not use third-party services like Sentry, Bugsnag, or Crashlytics. A crash report can include technical diagnostic information, such as device model, OS version, and the app's state at the time of the crash, but not your tasks, minutes, or blocked-apps list.
Subscription management
Lavendr uses RevenueCat to manage your Lavendr Pro subscription, specifically to validate App Store receipts, confirm your entitlement status across devices you sign into with the same Apple ID, and prevent subscription fraud.
When you start a trial or purchase a subscription, Apple sends RevenueCat a receipt that includes the product you purchased, the price, the purchase date, and an anonymous identifier (your device's vendor identifier). RevenueCat does not receive your name, email address, Family Controls data, focus sessions, or blocked apps list.
Beyond subscription events, the app sends RevenueCat a small set of anonymous signals about onboarding and the subscription screen (for example that the paywall was shown, which plan was selected, and whether a purchase or restore succeeded), attached to the same anonymous identifier. We use these only to understand where onboarding loses people. They are not linked to your identity and are not used for advertising or tracking.
We use RevenueCat because building subscription validation correctly is hard, and outsourcing it to a specialized provider is more secure than handling it ourselves. RevenueCat's own privacy policy is at revenuecat.com/privacy.
Kids & teens
Lavendr is not directed at children under 13 and we don't knowingly collect data from them. The app is appropriate for teenagers and older with parental guidance. If you're a parent and want to use Lavendr alongside Apple's Screen Time controls and Family Sharing for your child's device, that works exactly as you'd expect. All setup happens through Apple's system, not ours.
Your rights
Lavendr has no user accounts and no first-party server storing your personal data, so there is no remote copy of it for us to access or delete on your behalf. Everything lives on your device instead:
- Access: open the app. It's all there.
- Delete your tasks: Settings → Delete All Tasks removes your task and minute history.
- Delete everything: uninstalling the app removes all of its data from your device.
- Opt out of Apple's analytics: iOS Settings → Privacy & Security → Analytics & Improvements.
We do not sell or share personal information as defined under the California Consumer Privacy Act.
If you're in the EU, UK, California, or anywhere with formal data rights (GDPR, CCPA, etc.) and have a question about this policy, email ceo@lavendr.so.
Changes to this notice
If we ever change how Lavendr handles your data, we'll update this page and the "last updated" date at the top. For material changes, we'll mention it in the next release notes too, so you don't find out by accident.
Contact
Questions, comments, second thoughts? Write to ceo@lavendr.so. There's a real person reading.
Lavendr is a product of Domino Effect Labs LLC.
Terms of use
The full Lavendr Terms of Service are available at lavendr.so/terms. By using Lavendr, you agree to those terms.