iPhone & iPad
Privacy Policy
Last updated: 25 July 2026
Effective date: 25 July 2026
The short version
Fluid Friction for iPhone and iPad does its work on your device. There is no Fluid Friction account and no sign in, we run no analytics and no tracking, and we never link data to you. The only thing that can leave your device to us is an anonymous referral identifier, used purely so a friend's invite can be credited.
- Your screen time, the apps you choose to limit, your blocking rules, your alarms, your NFC tags, and your settings all stay on your device. We never receive them.
- Apple's Screen Time system gives the app only anonymous, on-device tokens. We cannot see which apps you pick or your real usage numbers. Only you can.
- When you open a calm version of a site like Instagram, you sign in on that site's own page, inside the in-app browser. We never see your password, and your session stays on your device.
- Referrals are the one exception. If you take part in referrals, the app creates an anonymous identifier (with no name and no email) and syncs a little referral data so an invite can credit a friend. It is never linked to your identity and never used for ads or tracking.
- A couple of features make a direct, anonymous request to a site (for example, fetching a site's own icon when you add it). We explain each one below.
- We do not run ads, we do not profile you, and we never sell or share your personal information.
On the App Store, the Fluid Friction privacy label reads Data Not Linked to You: the only data we handle off your device is the anonymous referral identifier, and it is never tied to your name, email, or identity. The rest of this page is the complete version, written so that an Apple reviewer, a regulator, or you can check that the label is true. It also covers your rights under the GDPR, UK GDPR, and the CCPA / CPRA.
Who we are
This privacy policy is issued by Manfred Mjengwa, trading as "Fluid Friction" (referred to here as "we", "us", or "Fluid Friction"). We are the data controller for any personal data processed through the Fluid Friction app for iPhone and iPad (App Store bundle identifier com.mjengwa.fluidfriction) and this website (fluidfriction.app).
For any privacy question, request, or complaint, contact us at [email protected]. We aim to respond within 30 days.
What this policy covers
This privacy policy applies to:
- The Fluid Friction app for iPhone and iPad distributed on the Apple App Store, and any TestFlight or preview build we share.
- The fluidfriction.app website and its subdomains.
It does not cover the third-party sites and services you open through the app (such as Instagram, TikTok, YouTube, or Reddit), which have their own privacy policies, nor the separate Fluid Friction app for Android, which has its own policy.
Almost everything stays on your device
Fluid Friction is built around a simple idea: the app should help you use your phone less without becoming one more company that watches what you do. So there is nothing to sign up for, and almost nothing about you ever leaves your phone. The single exception is the anonymous referral identifier described in its own section below; nothing else here is sent to us.
The following all live only on your device, in Apple's standard app storage (app group preferences, the on-device database, and the iOS Keychain), and are never transmitted to us:
- Your screen-time figures and usage patterns.
- The apps and categories you choose to block or add friction to.
- Your blocking rules, schedules, focus profiles, and sessions.
- Your alarms and the wake and wind-down times you record.
- The identifiers of any NFC tags you set up, and the labels you give them.
- Your themes and your insights.
- Your parental PIN, if you set one. It is stored only as a salted cryptographic hash in the iOS Keychain, marked so that it never leaves the device and is excluded from iCloud and device backups. We never see your PIN.
When you delete the app, this on-device data is removed with it.
What we do not collect
To be explicit, Fluid Friction does not:
- Collect or store your screen-time numbers or app-usage history on any server.
- Read the contents of your messages, posts, or direct messages.
- See, store, or transmit your social-media passwords.
- Read your contacts, your calendar, your photos, or your health data.
- Use the advertising identifier (IDFA), ad networks, or cross-app tracking.
- Embed any third-party analytics, attribution, or crash-reporting SDK.
- Link data to your identity, build a profile of you, sell your data, or share it for advertising.
The only personal data we handle off your device is the anonymous referral identifier, and even that is never linked to who you are.
Apple Screen Time (Family Controls)
To block and add friction to apps, Fluid Friction uses Apple's Screen Time API, specifically the Family Controls, Device Activity, and Managed Settings frameworks. You are asked for access during setup, and again at any blocking tool you open without it. Granting is your choice: the friction browser works without it, and you can revoke access at any time in iOS Settings › Screen Time.
By design, this API never hands the app your real usage data or the real identities of the apps you choose. Instead it gives the app opaque tokens that only mean something on your device. Your actual screen-time figures are calculated inside a sandboxed Apple extension and shown back to you on screen; those numbers never enter the part of the app we could read, and they are never sent anywhere. As Apple puts it, no specific app or web-usage data is gathered by Apple either, and if you sync Screen Time across your own devices, Apple does that with end-to-end encryption.
In short: we cannot see which apps you limit or how long you use them. Only you can.
The in-app browser and your social logins
Some of Fluid Friction's tools open a "calm version" of a site, such as Instagram, TikTok, YouTube, Reddit, X, Snapchat, Facebook, or LinkedIn, or any site you add yourself. These open in an in-app web browser built on Apple's WebKit, the same engine as Safari.
- You sign in directly with that site. The login form belongs to the site, not to us. WebKit handles the sign-in and keeps the session. We never see or store your username or password.
- Your sessions stay on your device. The cookies that keep you logged in are stored locally by WebKit, in the same protected storage Safari uses. We do not read them or send them anywhere. You can sign out inside each site as usual.
- We do not scrape your feed. The app changes the layout of a page (for example, hiding an endless feed) using code that runs inside the browser sandbox. The only things that come back to the app are simple counts, such as how many items were hidden. We do not read your posts, messages, or page content into the app.
- The third-party site still sees its own activity. We remove our data collection, not theirs. When you use Instagram through Fluid Friction, Instagram still sees your Instagram activity under its own privacy policy.
Referrals and your anonymous identifier
Fluid Friction has an optional referral feature so that, if a friend invites you (or you invite a friend), the invite can be credited. There is still no account and no sign in, and we never ask for your name or email.
- An anonymous identifier. To make referrals work across devices, the app can create an anonymous identifier for your install using Google Firebase Anonymous Authentication. It is a random identifier. It is not your Apple ID, and it carries no name, email, or contact details.
- What syncs. Only the anonymous identifier, your referral code, and referral records (for example that an invite was redeemed) are stored in our referral backend, which runs on Google Firebase. This is the only personal data we handle off your device.
- Not linked, never tracked. Because the identifier is anonymous, this data is not linked to you. We do not use it for advertising, profiling, or cross-app tracking, and we do not combine it with the data described elsewhere in this policy (which stays on your device).
- You can reset it. You can clear your referral data at any time from inside the app (look for "Reset referral data" in settings), and deleting the app removes the on-device part.
Google processes this data as our service provider under Firebase's privacy and security terms.
Everything that leaves your device
For honesty and completeness, here is every way the app contacts the outside world. Apart from the anonymous referral identifier, none of these carry your identity, and several only happen if you turn the feature on.
| What | Goes to | When, and what is sent |
|---|---|---|
| Referrals (optional) | Google Firebase | If you take part in referrals: an anonymous identifier, your referral code, and referral records, so an invite can be credited. No name, no email; never used for ads or tracking. |
| Site icon for a custom site | The site you added | When you add a custom site, the app fetches that site's own icon from that site. No data about you is sent. |
| Browsing a calm-version site | That site (Instagram, etc.) | Normal web browsing. Your own login and cookies go to that site through WebKit, exactly as in Safari. |
| Fluid Pro subscription | Apple | Purchases are processed by Apple. Apple, not us, handles your payment. We receive only your subscription status from Apple on your device. |
If you do not take part in referrals, the only things that leave your device are the sites you choose to browse and, if you subscribe, the purchase that Apple processes.
Device permissions we ask for, and why
iOS asks your permission before the app can use any of the following. Each one is tied to a specific feature, each is optional, and you can change your mind in iOS Settings at any time.
- NFC. So you can tap a tag or card to start or stop a focus profile, or to switch off an alarm. The app reads only the tag's identifier and any link we wrote to it, never the data, balance, or personal details on a payment or ID card.
- Notifications. For alarms, bedtime reminders, focus-session timers, and free-trial reminders. These are scheduled locally on your device. We operate no push server and collect no push tokens.
- Alarms. So an alarm you set can ring reliably, including through Silent and Focus. The alarm is scheduled by iOS on your device; nothing about it is sent anywhere.
- Camera. To scan QR codes and barcodes you choose (to start or stop focus profiles and to dismiss alarms), and for camera-based sites you open in the in-app browser, such as Snapchat for web.
- Microphone. Only for camera-based sites you open in the in-app browser, such as video and calls on Snapchat for web.
Fluid Friction does not use HealthKit, Motion data, Contacts, the Calendar, your photo library, Face ID or Touch ID, your location, or the advertising identifier. It does not ask for App Tracking Transparency because it does not track you.
Subscriptions and payments
Fluid Pro is an optional subscription sold through Apple's In-App Purchase system. Apple processes the payment. We never receive or store your card number, billing address, or other payment details. On your device, the app checks your subscription status with Apple's StoreKit so it knows whether to unlock Pro features. We run no payment or receipt server, and we send no identifier to anyone as part of this. Apple's handling of your purchase is governed by Apple's privacy policy.
How we use information
Because the app processes data on your device, that data is used only to run the features you ask for: to apply your blocking and friction rules, show your insights, ring your alarms, switch profiles when you tap a tag, and unlock Pro if you subscribe. The anonymous referral identifier is used only to credit referrals. We do not use any of it for advertising, profiling, or behavioural analytics. If you email us for support, we use your message only to help you.
Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the limited processing we do relies on the following Article 6(1) bases:
- Contract (Art. 6(1)(b)). Providing the app and, if you buy it, your Fluid Pro subscription entitlement.
- Consent (Art. 6(1)(a)). Optional features you switch on that need a device permission, such as the camera for scanning a code, NFC for tapping a tag, or notifications. You can withdraw consent at any time by turning the feature off or revoking the permission in iOS Settings.
- Legitimate interests (Art. 6(1)(f)). Running the referral feature with an anonymous identifier (so invites can be credited without us identifying you), responding to your support emails, and keeping the app secure and working.
- Legal obligation (Art. 6(1)(c)). Meeting tax and accounting duties for paid subscriptions (which Apple administers).
Who we share data with
We do not sell, rent, or trade your personal information, and we do not share it for advertising. We have no data-broker relationships and no advertising partners. The only companies involved in running the app are:
- Apple. As the App Store operator and through StoreKit, Apple processes your purchase of Fluid Pro and provides the Screen Time frameworks the app runs on. Apple acts under its own privacy policy.
- Google Firebase (Google LLC). If you take part in referrals, the anonymous referral identifier and referral records are stored in Google Firebase (Anonymous Authentication and our referral database) so an invite can be credited across devices. No name, email, or identifying information is attached. Governed by Firebase's privacy and security terms.
If Fluid Friction is ever sold or merged, any data would remain subject to this policy or one materially equivalent. We will disclose data if strictly required by a valid legal request, and only the minimum necessary.
How long data is kept
- On your device. Your settings, rules, insights, alarms, and other on-device data stay until you change them, reset them in the app, or delete the app. Recorded wake and wind-down times are capped at a rolling window of roughly the last 120 entries.
- Referral data. The anonymous referral identifier and referral records are kept while the feature is in use and until you reset referral data in the app or they are no longer needed to credit an invite.
- Support email. A support email you choose to send is kept for up to 24 months so we can follow up, then deleted.
- With Apple. Your purchase records are retained by Apple under Apple's policies and applicable law.
Security
- On the device. Data is stored in Apple's standard app storage. Your parental PIN is stored only as a salted hash in the iOS Keychain, marked device-only so it is excluded from iCloud and backups.
- In transit. The referral sync, the few anonymous utility requests, and all browsing use HTTPS. The app contains no cleartext-HTTP exceptions.
- By design. We keep almost nothing about you: the only off-device data is an anonymous referral identifier that is not tied to your identity, so there is no profile of you to breach.
No method of storage or transmission is ever completely secure. If you have a security concern, email [email protected].
Children
Fluid Friction is not directed to children under 13, and we do not knowingly collect personal information from them. You must be at least 13 to use the app, or 16 in countries where the GDPR sets a higher age for consent without a parent or guardian. The app is rated for a mature audience because it can open unfiltered third-party websites.
The parental PIN is a self-control lock you set for yourself; it is not a child account and the app does not collect any age or identity information. If you believe a child has provided personal information to us, email [email protected] and we will help.
Your privacy rights
Because we hold almost no data about you, and what we do hold (the referral identifier) is anonymous, there is usually little for us to show, correct, or delete on our side. Your data is in your hands: you can view and change it in the app, reset your referral data, and remove everything on your device by deleting the app. Even so, depending on where you live you have formal rights you can exercise by emailing [email protected]. We will respond within 30 days and will not charge a fee for a reasonable request. Note that because the referral identifier is anonymous, we may be unable to connect it to you without additional information from you.
EEA, UK, and Switzerland (GDPR)
You have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, and the right not to be subject to solely automated decisions (we make none). You may withdraw consent for any optional feature at any time. You may also lodge a complaint with your local data-protection authority; for UK residents this is the ICO (ico.org.uk).
California (CCPA / CPRA)
You have the right to know what personal information we collect and how we use it, to delete it, to correct it, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. To be clear: we have not sold or shared any personal information in the preceding 12 months, and we never will. We collect no sensitive personal information. We will not discriminate against you for exercising your rights.
Other regions
Residents of other US states (such as Virginia, Colorado, Connecticut, and Utah) and of countries with comparable laws have analogous rights. Use the same contact email to exercise them.
Tracking and Do Not Track
Fluid Friction does not track you across apps or websites, does not use the advertising identifier, and does not respond to any cross-context advertising signal because it never participates in one. The anonymous referral identifier is first-party and is never used for advertising or shared with a data broker, so it is not "tracking" in the App Store sense. The app does not show the App Tracking Transparency prompt because it does not track.
International data transfers
Your on-device data stays on your device. The anonymous referral identifier is processed by Google Firebase, which may process data in the United States and other countries; Google relies on its own lawful transfer mechanisms, including the Standard Contractual Clauses where they apply. Your own browsing, and the icon a custom site serves when you add it, may also reach servers outside your country, but they carry no identifying information about you. Where Apple processes your purchase, Apple uses its own lawful transfer mechanisms.
No account, and how to delete your data
There is no Fluid Friction account and no sign in. You do not register, and a Fluid Pro subscription is simply a purchase tied to your Apple ID, not an account with us. The only thing stored off your device is the anonymous referral identifier described above, which carries no name or email.
To remove the data the app stores on your device, you can reset individual features inside the app, or delete the app, which removes all of its on-device data. To clear your referral data, use Reset referral data in the app, or email us. To manage or cancel a Fluid Pro subscription, use iOS Settings › your name › Subscriptions.
Changes to this policy
We may update this policy to reflect new features or new legal requirements. When we make a material change, we will update the "Last updated" date above and, where appropriate, show a notice in the app. If a future version of the app ever collects data differently, we will update this policy and the App Store privacy label before that change ships.
Contact
Privacy questions, rights requests, or complaints: [email protected]. We aim to respond within 30 days.
Developer of record: Manfred Mjengwa, trading as Fluid Friction. For a postal address for a formal legal notice, request it by email and we will provide it.
See also our Terms of Service for iPhone and iPad.