Legal
Privacy Policy
Effective date: 18 August 2026
TL;DR
Your Screen Time data is processed entirely on your device by Apple’s framework and never reaches us, and 碌夠未 technically cannot see which apps you block — Apple hands the app opaque tokens, not app names.
The app does use product analytics, including session recording. We record how you move through the app — which onboarding step you reached, whether you finished a focus session, and screen recordings of the app while you use it. Your one-time sign-in code and your typed unlock reasons are hidden from those recordings; the rest of the screen, including the icons of the apps you block, is not. This is the part of this policy worth actually reading — section 4.
There is now a feedback form in Settings. What you write there, and the reply address you choose to give, are stored on our server — the only text you write that is. We use it to read what you said and to reply to you, and nothing else. Deleting your account deletes it. Section 5.
No advertising, no ad SDKs, no data sold or shared for marketing, and no analytics or cookies at all on this website.
1. Introduction & scope
This Privacy Policy explains how Kwok Hei Iden Tang, an individual developer based in Hong Kong (“we”, “us”), handles personal data in connection with the 碌夠未 (formerly Look7) iOS app and this website. By using 碌夠未 or this site, you acknowledge the practices described here. If you have any questions, contact us at look7.support@protonmail.com.
The app and the website are different. Everything in sections 3 to 6 describes the iOS app. This website has no analytics, no tracking pixels, no advertising, and sets no cookies — it does not store anything in your browser or profile your visit.
2. Data we collect
Account
When you sign in, we process your email address (if you use email sign-in with a one-time code), or an identity token from Sign in with Apple or Google sign-in, together with a randomly generated account ID (UUID). Authentication is handled by Supabase.
Purchases
If you subscribe to 碌夠未 Pro, we process your subscription status and history through the Apple App Store and RevenueCat. This includes receipt data, a pseudonymous app user ID linked to your account ID, and your device type. We never receive your payment card details.
Feedback you send us
If you send us feedback from Settings, we store the message you wrote, the reply address you give us (optional), the category you chose, and a small amount of technical context. Section 5 sets out exactly what.
Product analytics and session recordings
The app sends usage events and screen recordings to PostHog. Section 4 sets out exactly what is captured, what is hidden, and what is not.
Stored on your device
The following are held locally on your device and are never transmitted to us as data:
- your chosen display name;
- your onboarding answers (daily phone hours, habit apps, age);
- which apps you block — held as Apple opaque tokens, so we technically cannot see the app names;
- your quotas and mode settings;
- your usage statistics;
- your typed unlock reasons;
- your focus schedules;
- a copy of the feedback you have sent, which is what 「我嘅建議」 shows. That list is read from your device, never from our server, so it is empty on a new phone or after a reinstall even though the submission itself still exists.
One important qualification.“Never transmitted as data” means we hold no database column containing these values and no event carries them. It does not mean they can never be visible on a screen we recorded. Session recording captures the app’s screen, so a screen that displays your statistics or the icon of an app you block can appear in a recording. Your typed unlock reason and your sign-in code are the exceptions: they are masked out of recordings entirely. See section 4.
3. Screen Time data
碌夠未 relies on Apple’s Screen Time framework (FamilyControls / DeviceActivity / ManagedSettings). Your Screen Time data is processed on-device by that framework. Apple’s platform rules prohibit transmitting this data off the device, and 碌夠未 complies: we have no server that receives it, and no analytics event contains it.
The apps you select are represented as Apple opaque tokens. These are device-bound and meaningless outside your device. We never send those tokens, the app names behind them, their bundle identifiers, or any hash derived from them. Where the app reports on your selection it sends a count and an outcome, never an identity.
4. Analytics and session recording
We use PostHogto understand how people actually move through the app — in particular where onboarding loses people and whether the blocking friction helps or just irritates. PostHog is a product analytics provider acting as our processor. Data is sent to PostHog’s United States cloud region.
4.1 Events we record
The app sends a fixed, named set of events. Each carries only the properties listed:
- onboarding_step, onboarding_completed — which onboarding step you reached.
- screentime_granted, screentime_denied — whether you granted the Screen Time permission.
- notifications_answered — your answer to the notification permission prompt.
- apps_picked — how many apps you selected and whether the selection was accepted. Never which apps.
- paywall_shown — what triggered the paywall.
- override_started — the mode, and how many unlock sessions you had already used that day.
- override_completed — the mode, sessions remaining, and the character count of your typed reason. The text itself is never sent — only its length, which tells us whether the minimum-length requirement is doing anything.
- focus_started, focus_ended — planned minutes, focused seconds, number of cycles, whether hard mode was on, the number of apps involved, and how the session ended.
- feedback_opened, feedback_submitted — that you opened the feedback form and sent something: the category, the outcome, whether you were signed in, whether you supplied a reply address, and the character count of your message. Neither the message nor the address is ever sent to PostHog.
- Application Installed / Updated / Opened / Backgrounded — captured automatically by the PostHog SDK when you launch or leave the app.
Every event also carries standard technical context added automatically by the SDK: app version and build, iOS version, device model and type, screen dimensions, locale, time zone, network type, whether the build is a TestFlight build, a randomly generated device identifier, and a session ID. PostHog receives your IP address and uses it to derive an approximate location (typically country or region level). We do not collect precise location, and the app does not use the advertising identifier (IDFA) or ask to track you across other companies’ apps or websites.
Once you sign in, the app links this activity to your account ID — the same identifier used for Supabase and RevenueCat — so that activity from before sign-in connects to your account. That means analytics data is pseudonymous but not anonymous: we can associate it with you.
4.2 Session recording
PostHog session replay is enabled, and it works by capturing screenshots of the app while you use it. Those screenshots are stitched into a replay of your session that we can watch back, together with your taps and navigation. We use it to diagnose confusing or broken moments in the flow. We do not record audio, camera, or anything outside the 碌夠未 app, and recording stops when you leave the app.
Hidden from recordings. These are masked out before the screenshot leaves your device, and we never see them:
- your one-time email sign-in code;
- the unlock reason you type — in 困難 mode this is a written confession of at least twenty characters, and it is the most personal text the app holds;
- the message you type in the feedback form, and the reply address you enter with it;
- the 「我嘅建議」 list, which would otherwise put every message you have ever sent into a single recorded frame;
- Apple’s system app picker, which would otherwise expose your entire installed-app inventory rather than just the apps you chose to block.
Visible in recordings.The rest of the app’s interface is not masked. In practice this means a recording can show:
- the names and icons of the apps you block, wherever the app displays them. This is a deliberate choice: knowing which app a moment of friction was about is the single most useful thing a replay tells us. The rule that app identity is never sent as event data is unchanged, and recordings expire (section 9) while events do not;
- your statistics screen, including your usage figures, quotas, and streaks;
- your display name, your goals, your schedules, and the preset reason chips you tap.
If you would rather none of this were recorded, section 11 explains how to opt out.
5. Feedback you send us (意見同建議)
碌夠未 has a feedback form in Settings. You choose a category — a feature idea, a bug report, feedback on how the app works today, or something else — write a message, and optionally give an email address so we can reply. Nothing leaves your device until you tap send.
This is the only place in the app where text you wrote is stored on our server. Everything else above is counted, categorised, or kept on your device. A paragraph you wrote is none of those things, so this section is specific about it.
5.1 What a submission contains
- your message, exactly as you typed it;
- a reply address, if you give one. Signed in, it is prefilled from your account and you can change it to any address you like; signed out, you can leave it blank and send anonymously. A signed-in submission also carries the email address on your account, which our server reads from your session rather than from the form — that is the only field on the record we can trust to identify you;
- the category you chose;
- context for triage: the app version and build, your iOS version, your device model (a hardware string such as “iPhone16,2”, shared by millions of devices), the language the app is set to, the pet you picked, and whether your Pro subscription is active. This exists so a bug report can be read as one — which build, which iOS, which language.
Nothing else travels with it. No Screen Time data, no blocked-app tokens or anything derived from them, and no session recording or analytics identifier is attached to a submission.
One qualification, in the spirit of section 4.2. A signed-in submission carries your account ID, and that is the same account ID that identifies you in analytics. We do not join the two, and nothing in the app or our tooling does it for us — but the key exists, and saying so is more useful to you than a promise that reads cleaner. A submission sent while signed out carries no account ID at all.
5.2 What we use it for
To read what you said and to reply to you. That is the entire purpose. Feedback is not used for advertising, is not sold, is not shared with anyone else, and is not used to profile you.
Submissions are stored in our Supabase database (Postgres). The app can only write to it: there is no way for the app, for you, or for any other user to read submissions back out — which is also why 「我嘅建議」 is a copy kept on your own device rather than a view of our records. Access to the stored submissions is limited to Kwok Hei Iden Tang.
So that the form cannot be abused, we count how many submissions a caller has sent today. Signed in, that counter is keyed on your account ID; signed out, it is keyed on a one-way hash of your IP address. The counter holds a number and a date — never the address itself, and never your text.
5.3 Deleting it
Deleting your account deletes your feedback. Every submission matching your account ID or your email address is permanently deleted — including anything you sent as a guest from that address before you had an account — and that deletion runs before the account itself is removed. There is no anonymised remnant kept: you cannot anonymise a sentence, because a sentence can name a person, an employer, or a place, so the whole record goes.
If you have never had an account, email us at look7.support@protonmail.comfrom the address you sent it with, or quote the message, and we will delete it. Note that clearing the app’s local data or reinstalling only removes 「我嘅建議」 from your device; the submission on our server is removed by one of the two routes above.
6. What we do not do
We do not show advertising, and there is no ad SDK in the app. We do not sell or share your personal data, and we do not use it to build advertising profiles or to target you. We do not track you across other companies’ apps or websites, and we do not use the advertising identifier. This website has no analytics and sets no cookies. The analytics described in section 4 exist so we can improve the app, and for no other purpose.
7. Notifications
All notifications are local — generated on your device by the app. There are no push servers involved.
8. Service providers
We rely on a small number of providers to run the service. Each processes only what is described above:
- Supabase — authentication, account data hosting, and storage of the feedback you send us. Privacy policy
- RevenueCat — subscription management. Privacy policy
- PostHog — product analytics and session recording, hosted in the United States. Privacy policy
- Apple — payments and App Store distribution. Privacy policy
9. Data retention
Account data is kept for as long as your account exists. When you request account deletion, we delete the account data associated with you.
Session recordings are deleted automatically after 30 days. Analytics events are retained for 12 months and then deleted. If you ask us to delete your analytics data sooner, we will.
Feedback submissions are kept until you delete your account, at which point they go with it (section 5.3). They are not on a timer, because a bug report is often worth re-reading a year later. If you would rather a particular submission were gone sooner, email us and it will be.
10. Legal bases & purposes
We process the limited data above to operate your account, to deliver the Pro entitlement you purchase, and to comply with our legal obligations. Where applicable law requires a legal basis, we rely on the performance of our agreement with you and our legitimate interest in providing and securing the service.
For the feedback described in section 5, we process your message and your reply address in order to answer you: our legitimate interest in supporting the people who use the app, and yours in getting a reply. You decide whether to send anything at all, and whether to include an address.
For the analytics and session recording described in section 4, our legal basis is our legitimate interest in understanding and improving how the app works. Where you are in the EEA or UK, you have the right to object to processing based on legitimate interest — see section 11, and we will act on it.
11. Opting out of analytics
Email us at look7.support@protonmail.com and say you want out of analytics. We will delete the events and session recordings associated with your account and exclude you going forward. Deleting your account also removes this data.
碌夠未 does not yet have an in-app switch for this. We are adding one; until it ships, the request above is how we honour an objection, and we will not make you justify it.
12. Your rights
Under the Hong Kong Personal Data (Privacy) Ordinance (PDPO), you may request access to, and correction of, your personal data. You may also request deletion. If you are in the EEA or UK, you additionally have GDPR rights, including access, rectification, erasure, portability, and objection.
To exercise any of these rights, email us at look7.support@protonmail.com. You can sign out in the app at any time, and you can request account deletion by contacting us (and in-app where available).
13. International transfers
The providers listed above store or process data outside Hong Kong. In particular, analytics data and session recordings are processed in the United States by PostHog. We rely on the safeguards in our agreements with those providers to protect your data when it is transferred.
14. Children
碌夠未 is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Security
We protect data in transit with HTTPS/App Transport Security, keep session credentials in the iOS Keychain, and minimise what we collect by design. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data.
16. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app or on this site.
Change on 18 August 2026: we added the in-app feedback form (意見同建議). Section 5 is new and sets out what a submission contains, what it is used for, and how it is deleted; sections 2, 4.1, 4.2, 8, 9 and 10 were updated to match, and the section numbers from 5 onwards each moved up by one to make room. This is the first user-written text and reply address we store on a server. Nothing changed about Screen Time data.
Change on 1 August 2026: we added PostHog product analytics and session recording to the iOS app. The version of this policy before that said we used no analytics SDKs; that is no longer true, and sections 4, 8, 9, 11 and 13 are new or rewritten to describe what actually happens. Nothing changed about Screen Time data, which is still processed only on your device.
17. Contact us
For any privacy question or request, contact Kwok Hei Iden Tang at look7.support@protonmail.com.