Short version: Stop That watches what you do only on your own device — it never sends your activity, what you type, or what you browse anywhere. This policy covers two separate apps, the Mac app and the iPhone app. Neither sends your activity off your device. The Mac app sends only what is needed to sell and lock a license. The iPhone app sends anonymous, aggregate analytics and your subscription status (through Apple), and never sends your Screen Time selections, what you block, or how you use your phone.

Who we are

Stop That is operated by Daniel Keen, trading as Stop That, a sole trader based in the United Kingdom. We make the Stop That app for macOS and the Stop That app for iPhone. We are the “data controller” for the limited personal data described below. In this policy, “we”, “us”, and “Stop That” mean that operator. Questions, or to exercise any of your rights, email [email protected].

Two apps, one policy

The Mac app and the iPhone app are separate products, sold and delivered differently, so this policy is split into a section for each, followed by the parts that apply to both. Read the section for the app you use.

  • The Mac app is a one-time purchase, sold and activated through our own website and payment processor.
  • The iPhone app is an auto-renewing subscription, sold through Apple’s App Store, that uses Apple’s Screen Time controls on your device.

The Mac app

What the app does on your Mac

To interrupt doomscrolling, Stop That looks at a small amount of information locally, on your device, in real time:

  • The bundle identifier of the app that is currently in front.
  • For supported browsers you have approved, the URL of the active tab.
  • The blocklist, allowlist, and settings you configure.

This information is used only to decide whether the current target is “bad” and to drive the bubble, voice prompts, and Teleport to Work. It is processed on your Mac and stored in your local app settings. None of it is ever sent to us or to any third party. There is no cloud sync, no analytics, and no remote logging of your activity.

What leaves your Mac

Two things, and only when you choose to buy and activate a license:

  • Buying a license. Checkout happens with our payment processor (Stripe). When a payment completes, our server receives your email address and the order reference so it can issue and email your license key.
  • Activating a license. Each license works on one Mac. When you activate, the app sends your license key together with a one-way (SHA-256) hash of your Mac’s hardware identifier to our server, which records that the key is now bound to that device. We never send or store the raw hardware identifier, and this fingerprint reveals nothing about you, your files, or your activity — it only lets us tell “same Mac” from “different Mac” so a single license isn’t shared across many machines.

On our server (hosted on Cloudflare) we keep a small activation record for each license: the device hash, the activation date, and the purchaser’s email. We do not log your IP address for tracking, and there is no usage telemetry.

Permissions the Mac app asks for

  • Accessibility. Required to detect the frontmost app and to run Teleport to Work (activating the productive app you chose). macOS grants this only with your explicit approval, and you can revoke it any time in System Settings.
  • Automation. Optional, requested per browser, so the app can read the active tab’s URL for site-based rules. If you decline, site rules for that browser simply do not run.

These permissions are used solely for the features described above and only on your device.

The iPhone app

What the app does on your iPhone

The iPhone app uses Apple’s Screen Time framework (Family Controls) to heckle and then block the apps you choose. This all happens on your device:

  • The apps you block. You pick them with Apple’s own app picker. Apple hands our app only opaque tokens — it never tells us which apps you picked. We cannot see the names or identities of your apps, and we never receive them.
  • Your selections, shields, and usage stats. The apps you block, the shields we show, and the on-device stats (time saved, attempts blocked, time on blocked apps, your 7-day trend) are computed and stored only on your iPhone.
  • Your Stop Reason and any confession text. The reason you type for why you want to stop, and any text you enter to lift a block, stay on your device and are never transmitted.

None of your Screen Time data ever leaves your iPhone. There is no cloud sync of your selections, shields, or usage, and no Stop That account.

What leaves your iPhone

Two things, and both are anonymous — neither is tied to a name, an email, or an account, because the iPhone app has no account system:

  • Anonymous funnel analytics (PostHog). So we can see where people get stuck setting the app up and whether it holds them, we send a short, fixed list of milestone events to PostHog, our analytics processor (EU cloud): the app opening; your progress through onboarding (the step reached, the severity and goals you picked, and a rough bucket of how many apps you selected, never which ones); whether you granted or denied the Screen Time permission; paywall views and dismissals; which plan you picked; subscription starts and restore attempts; Start Watching; a one-time marker that your first block happened; whether you turned on Locked Hours; that a confession was completed (never its text); opening Manage Subscription and, if you cancel, the preset reason you tapped in the exit survey (a fixed choice, never free text) and whether you took the discounted offer; a request to show the App Store review prompt; and the subscription renewal, cancellation, and billing-issue events that Apple and RevenueCat forward for you. We also send a small number of controlled error reports that carry only short developer-written labels for what failed, plus a count of any background failures — never your data. Every event joins under one random, anonymous identifier per install; there are no accounts. There is no autocapture, no screen recording, no session replay, and no screenshots. We never send your selected apps, Screen Time tokens, Stop Reason, confession text, usage stats, blocked attempts, or activity history. The iPhone app’s own privacy policy is the authoritative description of what it collects.
  • Your subscription status (Apple + RevenueCat). The subscription is bought through Apple’s In-App Purchase. Apple processes your payment; we never see your card details. We use RevenueCat to check whether your subscription is active, using the same anonymous device identifier — no email, no name. That check is the only thing that decides whether blocking is on; if your subscription lapses, enforcement simply stops.

Permissions the iPhone app asks for

  • Screen Time (Family Controls). Required to heckle and block the apps you choose. iOS grants this only with your explicit approval, and you can revoke it any time in Settings. The app sets no Screen Time passcode and holds nothing you can’t undo — Stop Everything lifts every shield and stops all monitoring, by default after a short typed confession. The way out always exists; it just makes you type for it.
  • Notifications. Used to deliver the heckle prompts (with voice-clip sounds) before a block. If you decline, you simply won’t get those notifications.

Our lawful bases (UK GDPR)

  • Selling and delivering your Mac license — performance of our contract with you. Without your email we cannot send or support your purchase.
  • Binding a Mac license to one device — our legitimate interest in preventing a single license from being shared across many Macs, which is core to how the product is sold.
  • Anonymous iPhone analytics — our legitimate interest in understanding and improving how people set up the app, balanced against your privacy by keeping the data anonymous, aggregate, and stripped of any Screen Time or usage content.
  • Support and refunds — performance of our contract and our legitimate interest in answering you and honouring the guarantee.

Who we share data with

We do not sell or rent your data. We use a few trusted providers (“processors”) purely to run the service:

  • Stripe — processes your payment for the Mac app. You enter your card details with Stripe, not us; we never receive or store your full card number.
  • Cloudflare — hosts our website and stores the Mac license and activation records described above.
  • Resend — sends you your Mac license-key email after purchase.
  • Apple — sells and processes the iPhone subscription through the App Store. Your payment is handled by Apple under its own terms; we never see your card details.
  • RevenueCat — checks the iPhone subscription’s status for us, keyed to an anonymous device identifier with no email or name.
  • PostHog — receives the anonymous iPhone funnel events described above, in its EU cloud.

Each handles your data under its own privacy policy and only on our instructions.

International transfers

Some of these providers process data on servers outside the UK, including in the European Economic Area and the United States. Where that happens, the transfer is covered by UK-approved safeguards — such as UK adequacy for the EEA, the UK extension to the EU–US Data Privacy Framework, or the ICO’s International Data Transfer Agreement / Addendum to the standard contractual clauses.

How long we keep it

We keep your Mac activation and order records for as long as your lifetime license is active, so we can support you and let you re-activate on the same Mac, and as long as we need to meet legal and accounting obligations. The iPhone app’s anonymous analytics are retained by PostHog under our retention settings and are not linkable back to you. We keep support emails only as long as needed to deal with your query, then delete them.

What we do not collect

  • No account, login, or profile for either app.
  • No browsing history, keystrokes, screenshots, or screen recordings.
  • On the Mac app, no in-app usage analytics or telemetry at all.
  • On the iPhone app, no Screen Time selections, app identities, Stop Reason, confession text, usage stats, blocked attempts, or activity history — only the anonymous milestone events listed above.
  • No advertising identifiers, no cross-app or cross-site tracking, and we never sell or rent data.

Email and support

If you email us, for support or a refund, we keep that correspondence and your email address so we can reply and honour the guarantee. We use it only for that purpose.

This website

The Stop That website does not set advertising or cross-site tracking cookies. If we add privacy-respecting analytics in the future, we will update this policy first.

Your rights

Your in-app activity data lives only on your own device, so you stay in control of it: on the Mac, clear your settings or uninstall the app; on iPhone, delete the app to remove all local data (selections, stats, Stop Reason and confession text all go with it). For the limited data we do hold — your Mac activation record, order records, and support emails — under UK GDPR you can ask us to access, correct, delete, or restrict it, or object to our use of it — just email [email protected]. The iPhone app’s analytics are anonymous and not linked to your identity, so we cannot single out your events; deleting the app stops any further ones. If you ever move to a new Mac and need your license released, contact us and we will reset the activation.

If you think we have mishandled your data, you can complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk. We would appreciate the chance to put things right first.

Children

Stop That is not directed at children and is not intended for use by anyone under 16. The iPhone app is a self-control tool for your own device; it is not a parental control product.

Changes

We may update this policy as the apps evolve. When we do, we will change the “Last updated” date above. Material changes will be highlighted on this page.

Contact

Questions about privacy? Email [email protected].