Clarity OS LLC

Privacy Policy

Clarity OS helps you protect your attention. We collect only what we need to make blocking work across your devices and to show you your own focus history — and nothing is ever sold or used for advertising.

Effective date: August 25, 2026

Introduction

Clarity OS LLC (“Clarity OS”, “we”, “us”) makes a commitment enforcement app that helps you block distracting websites and apps during Protection Windows. It is available on the web at clarityos.dev, and as an iPhone app distributed by Apple — through TestFlight during the beta, and through the App Store at launch. Windows, macOS, the Chrome extension, and Android are not part of the v1 public launch.

This policy explains what information Clarity OS collects, how we use it, who we share it with, and the choices you have. It describes what the product actually does today — not what a template says it might do.

Our Privacy Philosophy

Clarity OS exists to protect your attention, not to monetize it. We collect information to operate Protection Windows, maintain accounts and subscriptions, secure and troubleshoot the service, provide delayed passcode recovery, show you your own focus history, and understand whether the product’s core features are working.

We do not sell personal information, we do not show ads, and we do not build advertising profiles. Wherever blocking decisions can happen on your device instead of our servers, they do — for example, the iOS content filter checks websites entirely on your iPhone and never reports what you visited. If you separately enable Extra Protection, your iPhone instead uses the CleanBrowsing DNS service as described below.

Information We Collect

Account information. When you sign up we collect your email address and a password. Authentication is handled by Supabase; your password is stored only in hashed form. We do not ask for your name, and we do not offer social logins today. Supabase also records authentication events, such as signups, logins, password changes, token refreshes, and logouts, together with technical information such as the time, IP address, user agent, and account id.

Protection configuration. We store the blocklists you create or select (the websites, categories, and apps you choose to block), your schedules and modes, and each Protection Window you run — including its start and end times, its block list snapshot, and any optional project or goal note you type when starting a session.

Device information. For each device you pair we store a device identifier, the device name, platform (such as iOS or Windows), app version, time zone, connection heartbeats, and a status report describing whether blocking is actually applied on that device. iOS devices also register a push notification token so we can wake the app to sync. Devices authenticate with a per-device secret, which is stored hashed on our servers. Status reports can include which blocking layers are active, the protection level, applied-rule counts, app/category selection counts, active Protection Window ids, and a technical failure reason. They do not include Apple’s private app or category tokens.

Optional Screen Time Passcode escrow. If you choose delayed passcode recovery, the iPhone sends the four-digit Screen Time Passcode you create to Clarity OS over HTTPS, together with the device id, iOS version and build, recovery delay, and setup time. The server encrypts the passcode before storing it. It can be decrypted only to return it to you after the selected recovery delay. Release, cancellation, and deletion events are recorded for security and reliability. Deleting your account destroys the encrypted passcode copy before the rest of the account is removed.

Focus and session events. To power your focus timeline and distraction metrics, paired devices send session events to our servers: when a Protection Window starts and ends, and blocked attempts. A blocked attempt records only the domain name of the blocked site (never the full page address) and any intention text you type at the block screen. We do not collect tab-switch activity, browsing history, or the titles of the apps and windows you use — our servers are configured to reject that kind of data. These events are private to your account and are used only for your own focus metrics and timeline.

Billing information. Subscriptions are sold through the App Store, and the free trial that comes with a new subscription is Apple’s. We never receive your card number or bank details on any platform.

App Store subscriptions. If you subscribe inside the iPhone app, Apple processes the payment. Your device sends us the signed receipt Apple issues, and we store only what is needed to keep your access correct: the Apple transaction identifier and original transaction identifier, the product identifier, whether the purchase came from Apple’s sandbox or production environment, the renewal date, the subscription status, and a token we generate ourselves to link the purchase to your Clarity OS account. We do not receive your Apple Account name, email address, or payment method.

Support and contact. If you use the contact form we collect the name, email address, and message you submit so we can reply.

Error diagnostics. When a server request fails we log technical details (the route, an error message, and stack trace) so we can fix problems. Clarity’s enforcement and device logs can be linked to your account or device id. Our hosting, authentication, and monitoring providers may also process the request path, status, timestamp, IP address, user agent, request or trace identifier, and performance information. These logs are designed to never include your password, passcode, authentication tokens, or device secrets.

Information We Do NOT Collect

We do not sell personal information. We do not build advertising profiles or use advertising cookies. We do not track you across other websites. We do not read your messages, photos, or contacts. We do not record keystrokes, and we never see the passwords you use on other sites.

Clarity OS does not store a list of the websites you visit. The only browsing-related data stored in your Clarity account is the domain name of a blocked attempt during a Protection Window — never the pages you visit, your tab activity, or full web addresses. If you enable Extra Protection, DNS requests from your device are sent to CleanBrowsing so it can filter adult and unsafe domains. CleanBrowsing states that its free resolver does not retain identifying DNS logs, but it does process and may retain anonymized, aggregate domain-query data to maintain, secure, research, and improve its services.

On iOS, the apps you select for blocking are stored only on your device using Apple’s privacy-preserving Screen Time technology — we cannot see which apps you chose, and we do not collect Screen Time usage data. The iOS website filter makes its block/allow decisions entirely on your device and does not send your browsing activity to us.

We do not collect payment card or bank details anywhere — Apple handles those and does not pass them to us. We do not run marketing email lists, and we do not use information for targeted advertising or tracking across other companies’ apps and websites.

How We Use Information

We use your information to run your Protection Windows across your paired devices, to tell you truthfully whether you are protected right now, to show you your own focus history and distraction metrics, to maintain your subscription, to provide delayed passcode recovery when you choose it, to keep your account secure, to respond when you contact us, to fix bugs, and to measure whether core product features are working reliably.

That is the complete list. We do not use your data for advertising, and we do not share it with third parties except the service providers described below.

Analytics

Our website uses Vercel Web Analytics to understand page visits in aggregate. It is cookie-less and does not track you across other websites. Before any analytics data leaves your browser, Clarity OS strips sensitive values (such as tokens or email addresses that might appear in a link) from page URLs.

Clarity OS also records a small first-party product funnel tied to your account: iPhone installation registration, a device becoming ready, Protection Window activity, whether enforcement was live on distinct days, and subscription conversion and retention. During onboarding you may optionally tell us where you heard about Clarity OS; skipping the question records no source. We use these events to understand whether acquisition, setup, blocking, and billing work. They do not contain blocklist contents and are not used for advertising or cross-app tracking.

We do not use Google Analytics, session recording, heatmaps, ad ad-network attribution, or advertising analytics in the iPhone app. The optional first-party source question described above is not used to track you across apps or websites. Service providers may use limited technical or anonymized aggregate data to secure and improve the services they provide, as described below.

Cookies and Browser Storage

We use only strictly necessary cookies — the session cookies that keep you signed in. The web app also keeps a small local cache in your browser so sessions feel instant; signing out clears it.

For full details, see our Cookie Policy.

Third-Party Services

We share information only with the service providers we need to run Clarity OS:

Supabase hosts our database and authentication, and sends account emails such as verification and password-reset messages. Your account, devices, blocklists, schedules, and focus events are stored there. Vercel hosts our website and API and provides the aggregate website analytics described above. It processes and temporarily retains network and request information such as IP addresses, approximate location derived from IP, user agents, paths, status codes, request identifiers, and performance information to deliver and troubleshoot the service. Cloudflare Turnstile protects signup and login from automated abuse and processes signals such as IP address, TLS fingerprint, user agent, site origin, a short-lived device signal, and challenge outcome. CleanBrowsing provides optional Extra Protection DNS filtering. Its free resolver processes domain requests and retains anonymized aggregate query data, which is not tied to an identifiable user, for security, research, reliability, and service improvement. Resend delivers contact-form email and receives the name, email, and message you submit, and may deliver transactional account emails sent through Supabase. Sentry may receive sanitized server error and performance information when our production monitoring is enabled; we configure it not to receive default personal information and remove account, device, token, passcode, and blocklist fields before sending an event. Apple receives your device’s push token so we can send silent sync notifications to the iOS app — these pushes contain no personal content — and processes payments for subscriptions bought inside the iPhone app, sending us signed transaction and renewal notices so we can keep your access current.

None of these providers are permitted to use your data for their own advertising, and we never sell or rent your information to anyone.

Data Retention

We keep your information for as long as your account exists so your history, schedules, and paired devices keep working.

When you delete your account (available in the app, with a typed confirmation), your account and the data tied to it — devices, blocklists, schedules, Protection Window history, and focus events — are deleted from our systems. Any encrypted Screen Time Passcode copy is destroyed as part of that process. We retain only a minimal deletion record for legal and security auditing, and it intentionally contains no email address, tokens, secrets, passcode, or blocklist contents.

Service-provider security, authentication, delivery, and runtime logs may remain for each provider’s normal retention period. Because CleanBrowsing’s free-resolver aggregate DNS data is not linked to a Clarity account or identifiable user, it cannot be located or deleted as part of an individual Clarity account deletion request.

Your Rights

You can view and edit your blocklists, schedules, devices, and focus history directly in the app, remove or revoke paired devices at any time, and delete your account entirely from account settings.

Depending on where you live, you may also have legal rights to access, correct, export, or delete your personal information, or to object to certain processing. Email privacy@clarityos.dev and we will honor these requests regardless of your location. A self-serve data export is not built into the current version — email us and we will provide your data.

Security

All traffic between your devices and our servers uses HTTPS. Passwords are hashed by Supabase Auth and are never visible to us. Device pairing secrets are stored hashed on our servers and compared using timing-safe checks. Database access is protected by row-level security so your data is only readable by your account.

On Windows, service credentials are kept in a file readable only by system administrators, and diagnostic exports automatically redact secrets. Support diagnostics never include your password, tokens, or device secrets.

No system is perfectly secure, but we design Clarity OS so that a breach of any single layer exposes as little as possible. If we ever learn of a breach affecting your personal information, we will notify you as required by law.

Children's Privacy

Clarity OS is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us at privacy@clarityos.dev and we will delete it.

International Users

Clarity OS LLC is based in the United States, and your information is processed and stored on servers in the United States by the providers listed above. If you use Clarity OS from outside the United States, you understand that your information is transferred there. We apply the same protections described in this policy to everyone, everywhere.

Changes to this Policy

We may update this policy as the product evolves — for example, when paid subscriptions launch or Android support arrives. We will post updates on this page and revise the effective date. For material changes, we will also notify you in the app or by email.