Ulyssify Privacy Policy
Effective date: September 5, 2026 Last updated: September 5, 2026
Ulyssify, Inc. ("Ulyssify", "we", "us") makes a commitment-device app that helps you block or limit distracting apps and websites on your own devices so you can build focus and better habits. This policy explains what we collect, why we collect it, who we share it with, and the choices and rights you have.
We wrote this in plain English on purpose. If anything here is unclear, write to us at privacy@ulyssify.com.
1. Quick summary
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- We use no advertising SDKs and no third-party product analytics SDKs. There is no Google Analytics, no Facebook pixel, no Mixpanel, no PostHog in our apps.
- The identities of the apps you block on iOS never reach our servers. Apple's Screen Time framework keeps that on your device.
- Our browser extensions read only the web address of the page you are on, to apply the rules you set for yourself. They talk only to your own Ulyssify app and to our own servers, and they never read page content. Section 5 explains this.
- Some of what you write in Ulyssify is personal: your chats with our AI assistant, and the notes you record for it. Section 7 explains exactly how that is handled.
- You can delete your account and your personal data from inside the app.
2. Who we are
Ulyssify, Inc. is a Delaware corporation based in the United States. For users in the European Economic Area and the United Kingdom, Ulyssify, Inc. is the data controller for the processing described here.
3. What we collect and why
3.1 Account information
| What | Why | Lawful basis (GDPR) |
|---|---|---|
| Email address | To create your account, sign you in, send transactional email, and recover access | Performance of a contract |
| Display name | To personalize the app | Performance of a contract |
| Password (stored only as a one-way PBKDF2 hash, never in readable form) | To authenticate you | Performance of a contract |
| Sign in with Google identifier, if you use it | To let you sign in without a separate password | Performance of a contract |
| Profile photo (avatar), if you upload one | To personalize the app | Performance of a contract |
| Country code, derived from your device or browser language setting | To localize the app. This is coarse and is not derived from your IP address | Legitimate interest |
| Your time zone, as reported by your device or set in your profile | To run scheduled blocks, reminders and insights at the right local time | Performance of a contract |
| Waitlist and admission record (when you joined the waitlist and when you were admitted), and an invite record if we pre-approved your email address before you signed up | To manage access while capacity is limited and to email you once when your spot opens | Performance of a contract |
When access is limited, new accounts may wait before they can use the app. We email you once when your spot opens; that message is an account message, not marketing.
3.2 Device and technical information
| What | Why | Lawful basis (GDPR) |
|---|---|---|
| A per-device API token | To keep you signed in on each device and to enforce blocking consistently across them | Performance of a contract |
| Client type (for example iOS, macOS, Windows, web) and a device identifier supplied by the app | To sync your settings to the right device and to show you your device list | Performance of a contract |
| Device name and last-used time | So you can recognize and manage your own devices | Performance of a contract |
| The IP address most recently used by each device | Security: to help you spot access you do not recognize, and to help us investigate abuse | Legitimate interest |
| Push notification tokens (Apple Push Notification service) and web-push subscriptions | To deliver blocking, reminder and account notifications | Performance of a contract |
| Crash and error reports | To find and fix bugs. Our crash reporting is configured to scrub personal data | Legitimate interest |
| A one-time anonymous status check ("the Beacon") from each device to our status service, which runs across several cloud providers | To confirm whether Ulyssify is genuinely down during an outage, so your blocks are not left stranded and you are not locked out. It carries no account data; each host sees only your IP and the request timing, which we do not store | Legitimate interest |
3.3 How you use Ulyssify
| What | Why | Lawful basis (GDPR) |
|---|---|---|
| Tasks you create: their titles and the other fields you set (the intention you attach, the proof requirements and details, and your completion history) | This is the core of the product | Performance of a contract |
| Your block lists: the website domains you choose to block, and desktop application identifiers on macOS and Windows | To apply your blocks across your devices | Performance of a contract |
| Your calendar and scheduled-blocking configuration | To start and stop blocks at the times you chose | Performance of a contract |
| Auto-track session timing: when one of your tracked apps was opened, when the session ended, and when the block was re-applied | To run the commitment mechanic, charge the correct amount of your in-app points, and give you an accurate history | Performance of a contract |
| Your Ulycoin ledger: points earned, points spent, and the timing of each | To operate the in-app economy and show you your balance and history | Performance of a contract |
| Subscription status and an opaque subscriber identifier | To unlock paid features and manage renewals | Performance of a contract |
3.4 Personal content you write
Some Ulyssify features let you write in your own words. These are optional, and they are the most personal things we hold:
- Conversations with our AI assistant: the questions you ask it and its replies.
- Report questions: the question you type when you ask for a report.
- Notes you record for the AI assistant: the standing context and the categorized notes (goals, values, triggers, preferences, facts about yourself) you choose to save so it remembers them.
- Insight preferences: the optional text you write in settings describing what you want your insights to focus on.
- Proof requirements: the requirement and the details you write describing what counts as proof for a task, and the labels you give your reference photos.
- Proof photos: if you use photo proof, you photograph the evidence you chose for a task (for example a place you go to work out or study, an object, or a result on a screen) to confirm you actually completed a task. We store photos you submit as task evidence and any reference photos you provide.
We collect these only because you entered them, and we use them only to provide the feature you used them for: showing your own history back to you, and generating the insights or verification you asked for.
Section 7 explains which actions send content to our AI provider and how to avoid those transfers. You can also delete your saved notes and conversations.
3.5 Judges you invite
If you appoint a Judge, you give us that person's email address so we can send them one invitation email on your behalf. We use it only to deliver and manage that invitation, including a resend you ask for, and we do not add them to any marketing list. If the invitation is not accepted it expires, and we keep the invitation record (their email address and its status) as part of your account so the invitation cannot be reused; it is removed when you delete your account. If you are the invited person and you did not expect the invitation, you can ignore it, and we keep no account for you unless you sign up.
3.6 What we do not collect
- We do not collect a list of the apps installed on your device.
- We do not collect Apple's Screen Time usage statistics.
- We do not track you across other apps or websites, and we do not build advertising profiles.
- We never receive or store your payment card details. See section 9.
4. Your app-blocking data stays on your device
This section matters, so we are stating it precisely.
On iOS and iPadOS, Ulyssify blocks apps using Apple's Screen Time and Family Controls framework. Apple designed that framework so that the apps you select are represented by opaque tokens that only your device can resolve. Concretely:
- The identities of the apps you choose to block never leave your device. They are stored on your device and in your device keychain.
- We never learn which apps you have installed, and we never learn the real names or bundle identifiers behind Apple's opaque tokens. Even we cannot resolve them.
- We do not receive Apple's Screen Time usage data: not your screen-time totals, not per-app usage, not pickup counts.
What we do sync to our servers is our own service's activity, which is the minimum needed to make blocking work across more than one device:
- when one of your block lists was applied or lifted;
- when a tracked session started and ended, and when the block was re-applied;
- your block-list configuration, including the website domains you chose to block;
- on macOS and Windows, the application identifiers you chose to block. Those platforms have no equivalent of Apple's token system, so the identifiers you select are stored in your account so they can be enforced on your other computers.
Please read the above as a description of Ulyssify's own blocking activity, not as Apple Screen Time usage data. They are different things, and we only have the former.
Keeping an outage from locking you out (the "Beacon"). Ulyssify is built to fail safe: if our servers become unreachable, your blocks keep running, so a passing network glitch can never quietly unlock you. The flip side is that a real outage on our end should not leave you stuck either. To tell those two situations apart, each device (on iOS and macOS) periodically checks a small, stateless status service of ours called the Beacon. Your enforcement pauses only on a clear, cryptographically signed confirmation that Ulyssify itself is genuinely down, and it resumes as soon as we recover; an ordinary connection hiccup never qualifies.
These checks are deliberately anonymous. Your device sends an unauthenticated request that carries no account, no device identifier, no login token, no cookies, and none of your content. The only thing it includes is a random one-time value used to prevent replay. The Beacon is our own service, and we run it across several cloud providers (currently Cloudflare, Amazon Web Services, and Microsoft Azure) so that it stays available even when our main servers are not and does not depend on any single provider. Each provider, as a host, sees only the technical details that every internet request carries, namely your device's IP address and the timing of the check; none of them receives your account data, your blocks, or anything you write in Ulyssify, and we do not store the IP addresses behind these checks. We rely on our legitimate interest in keeping the app reliable and making sure an outage on our side cannot lock you out of your own device.
5. Browser extensions
Ulyssify offers optional browser extensions that work together with the Ulyssify app to apply the website rules you set for yourself. The app is the enforcer; an extension is its cooperative helper inside the browser: it applies the block decisions the app has already made, and it lets a metered site open once you have chosen to spend your earned time on it. An extension has no function independent of your own signed-in Ulyssify account, and it never invents rules of its own.
Two different extensions exist, with genuinely different data flows, so we describe them separately.
5.1 Desktop browser extension
What it reads. The extension looks at the web address (the URL and domain) of the page you are visiting, for one purpose: to decide whether that address matches a website you placed on your own block or meter list in the Ulyssify app. It does not read the content of the pages you visit: no page text, no images, no form entries.
Who it talks to. Exactly two parties:
- The Ulyssify desktop app running locally on your own computer, over the browser's native messaging channel, to read your current block and meter state and to obtain the per-request permissions that let a metered page load.
- Ulyssify's own servers (the same first-party backend the app uses, for your own signed-in account), to start, keep alive, and end a metering session when you spend earned time on a metered site. The extension authenticates those requests with a token relayed to it by the local Ulyssify app. It never contacts any third-party endpoint.
What it stores. The extension keeps a small amount of enforcement state (for example, whether metering is configured and which site is currently being metered) in the browser's extension storage, only so that state survives the browser restarting the extension in the background. It does not build or keep a log of your browsing history.
What it never does. It does not sell or share your browsing data, it does not use your data for advertising or analytics, and it does not use any data for purposes beyond enforcing the rules you set for yourself.
5.2 Safari extension on iPhone and iPad
On iOS and iPadOS, website blocking works through a local VPN configuration that runs entirely on your device. It acts as an on-device filter for the sites you chose to block or meter. It is not a remote VPN service: your page traffic (the content of the sites you visit) is never routed through Ulyssify's servers, and we do not see it. To decide whether a site is allowed, the filter resolves domain names through well-known public DNS resolvers (currently Cloudflare, Google, and Quad9). Those DNS lookups are the only part of your activity that leaves your device through the filter, they carry a domain name and not the page content, and they go to those resolvers, not to Ulyssify.
The Ulyssify Safari extension is the piece that lets you open a metered site on purpose:
- When you navigate to a website, the extension checks the site's address against your own metered-site list. That check happens on your device, inside Ulyssify's own components; an address that is not on your list is discarded, not stored, and not sent off your device.
- When the site is one you metered, the extension records your request on your device and sends the tab to a Ulyssify-hosted page where you choose whether to start metering. That page is built so the address of the site you were visiting stays on your device: it is not transmitted to our servers as part of loading the page.
- If you choose to start metering, the site opens, and the time it stays open is charged against the balance you earned in the app. The timing of that session (when it opened and when the site was re-blocked) syncs to your account, exactly as described in section 3.3.
The same principle as section 4 applies here: your lists and block state are used only to apply your own rules on your own devices. The Safari extension reads no page content, keeps no browsing history, talks only to the Ulyssify app on your device and to Ulyssify's own servers, and never involves a third party.
6. Notifications
We send push notifications through Apple Push Notification service and, on the web, through your browser's push service. These are used for blocking and re-blocking events, reminders you set, and account and security messages. You can turn off notifications in your operating system settings, though doing so may make some blocking behavior less responsive.
7. AI features and your personal content
Ulyssify offers three AI features. How each one sends your content differs, so we describe them separately:
- Insights are sent only when you ask for them or turn on a schedule. The weekly insight schedule is off by default. Your activity is sent to our AI provider to prepare an insight in three situations: during scheduled weekly generation, if you have enabled it; when you press Generate now; and when you ask for a report. What is sent is your tasks (their titles, category, type, due date, completion state, and intention text), your calendar entries, your Ulycoin activity and coin-economy settings, and your timezone. For insights, the insight preferences you wrote in settings are sent as well, if any. For a report, the question you typed is sent with it. Turning the schedule off stops the scheduled insights; a Generate now or a report you request still sends this content for that one request.
- The AI chat assistant can read the data in your account to help you. It can see your tasks (their titles and other task fields, the proof requirements and details you set, and the labels on your reference photos), your calendar entries, your Ulycoin activity and coin-economy settings, and your timezone. It can also see your blocking configuration and settings (your block lists, scheduled blocks, and any pending changes), your device names, device identifiers and platform details, your usage history, and the notes you have recorded for it. Each chat turn sends your conversation history, the notes you have saved for the assistant, and an automatic snapshot of your account to our AI provider. The assistant can request more account details through its read tools. We also send an early conversation message to generate its title. It only does this when you chat with it.
- Photo proof sends content at two moments. When you set up photo proof for a task and press the setup check, it sends your reference photos and their labels and the proof requirement and details you wrote, before your proof setup is saved. When you submit a photo for task verification, it sends the photo you submit together with those same reference photos, labels, requirement, and details.
Nothing you write is sent to our AI provider as long as you leave the insight schedule off, do not press Generate now or ask for a report, do not chat with the assistant, and do not set up or complete photo proof.
Our AI provider is Google Cloud (Vertex AI). When you use an AI feature, we send Google Cloud only what that feature needs, which may include:
- your tasks (their titles, category, type, due date, completion state, and intention text), your calendar entries, your Ulycoin activity and coin-economy settings, and your timezone, for insights and reports, plus the insight preferences you wrote, for insights, and the question you typed, for a report;
- your conversation history (your questions and the assistant's replies), the notes you have recorded for the assistant, and an automatic snapshot of your account, together with your tasks (titles and other task fields, proof requirements and details, reference-photo labels), calendar entries, Ulycoin activity and coin-economy settings, blocking configuration and settings, device names, device identifiers and platform details, usage history, and timezone, when you chat with it;
- your reference photos and their labels and the proof requirement and details you wrote, for the photo-proof setup check, and those same items plus your proof photo, for photo verification.
Our commitments about that content:
- We do not permit our AI provider to train any model on your content. Google's Vertex AI does not use your prompts or your photos to train its models, and our configuration and agreement with Google reflect that.
- Our AI provider does not retain your content after processing it. We use Vertex AI with zero data retention configured, so your prompts and photos are processed to produce the result you asked for and are not stored by Google afterward. They are not cached, and they are not retained for abuse monitoring. They are handled transiently, only to generate the response you requested.
- We do not send your AI content to anyone else for these features.
- We do not use your notes or chats to build advertising profiles, because we do no advertising at all.
If you would rather no personal content go to an AI provider, leave the insight schedule off, do not press Generate now or ask for a report, do not chat with the assistant, and do not set up or complete photo proof. The rest of Ulyssify, including all blocking, works without them.
8. Images you upload
Your avatar and your photo-proof images are stored privately in Google Cloud Storage. Images are served through signed links that expire after 15 minutes. Anyone with a valid link can access the image until it expires. These images are not publicly listed or browsable. For photo proof, our automated verification described in section 7 also reads them.
9. Payments and subscriptions
Ulyssify offers paid subscriptions.
- On iOS, purchases go through Apple In-App Purchase. Apple processes the payment and holds your payment details. We receive only whether your subscription is active and its renewal state.
- On other platforms, purchases go through our web checkout. The payment processor handles your card details directly.
- We never see, receive or store your full payment card number.
- We use RevenueCat to manage subscription state. RevenueCat receives an opaque identifier for your account. It does not receive your email address.
10. Who we share your information with
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share it only with service providers who process it on our behalf under contract, and only for the purposes listed:
| Provider | Location | What they receive | Why |
|---|---|---|---|
| Google Cloud | United States | Hosting, database, and file storage. This includes avatars and proof photos | To run the service |
| Cloudflare | United States and global edge locations | The technical connection data of a Beacon status check: your device's IP address and request timing. No account data and no content | To host our outage-resilience status service (the Beacon), which we run across several clouds so it stays available even if one provider is unavailable |
| Amazon Web Services | United States | The technical connection data of a Beacon status check: your device's IP address and request timing. No account data and no content | To host our outage-resilience status service (the Beacon), which we run across several clouds so it stays available even if one provider is unavailable |
| Microsoft Azure | United States | The technical connection data of a Beacon status check: your device's IP address and request timing. No account data and no content | To host our outage-resilience status service (the Beacon), which we run across several clouds so it stays available even if one provider is unavailable |
| Google Cloud (Vertex AI) | United States and other Google Cloud regions (global endpoint) | Your tasks (titles and other task fields, intention text, proof requirements and details), calendar entries, Ulycoin activity and coin-economy settings, blocking configuration and settings, device names, device identifiers and platform details, usage history, timezone, insight preferences, report questions, your conversation history and the notes you record for the assistant, an automatic snapshot of your account, and proof and reference photos with their labels, only when you use an AI feature | AI insights and reports, AI chat, conversation titles, photo-proof setup check and verification |
| Apple | United States | Push notification tokens; In-App Purchase transaction data for iOS subscriptions | Notification delivery and iOS billing |
| Postmark | United States | Your email address, the email address of a Judge you invite, and the content of transactional messages | Account, security and receipt email |
| RevenueCat | United States | An opaque subscriber identifier and subscription state, not your email | Subscription management |
| Sentry | United States | Crash and error diagnostics, configured to scrub personal data | Reliability and bug fixing |
Separately, the on-device VPN filter described in section 5.2 resolves domain names through well-known public DNS resolvers (currently Cloudflare, Google, and Quad9). These are not Ulyssify subprocessors: they receive DNS lookups directly from your device as public internet infrastructure, they receive a domain name and not the page content, and Ulyssify neither sends them your data nor receives anything back from them. This DNS-resolver role is separate from Cloudflare's role hosting our Beacon status service, described in the table above, where Cloudflare is one of the cloud providers we run the Beacon on.
We may also disclose information if we are legally required to, to enforce our Terms, or to protect the rights, safety or property of our users, the public or Ulyssify. If our business is transferred to another entity, your information may transfer with it, and we will tell you before it becomes subject to a materially different policy.
11. International data transfers
Ulyssify is operated from the United States, and our providers listed above process data primarily in the United States. There is one exception: when you use an AI feature, Google's Vertex AI may process that request in the United States or in another Google Cloud region, because we use Google's global AI endpoint. If you use Ulyssify from the European Economic Area, the United Kingdom or Switzerland, your information is transferred to the United States, and for AI features it may also be processed by Google in other regions.
For those transfers, and for the AI-feature processing that Google performs in any region, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses with our providers and, where applicable, our providers' certification under the EU-US Data Privacy Framework and its UK and Swiss extensions. Google Cloud, which provides both our hosting and our AI processing, is certified under that framework, and these safeguards follow your data wherever Google processes it. You may request a copy of the relevant safeguards by writing to privacy@ulyssify.com.
12. How long we keep your information
- While your account is open, we keep your information so the product works: your history, ledger, blocks and entries are the product.
- When you delete your account, we delete your personal data from our production systems, subject to the safety delay described in section 13.
- Encrypted backups roll off on a routine schedule, so deleted data may persist in backups for a short period after deletion before being overwritten.
- Records we must keep by law, such as billing and tax records, are retained for the period the law requires.
- Crash and error diagnostics are retained on a short rolling window and are scrubbed of personal data.
13. Deleting your account
You can delete your account and its associated personal data from within the app.
One thing to know, because it follows directly from how Ulyssify works: deleting your account does not instantly remove active blocks. Ulyssify is a commitment device. If deleting the account were an instant escape hatch, the commitment would be worthless. So account deletion is subject to a short safety delay consistent with any cooldown you configured, exactly like the other actions that reduce enforcement. Once that delay elapses, the deletion proceeds and your personal data is removed.
If you would rather not wait, or the in-app flow is not working for you, write to support@ulyssify.com and we will process your request.
14. Your rights
Everyone
You can access, correct, export and delete your information from inside the app, and you can write to us at privacy@ulyssify.com for help with any of it.
If you are in the EEA, UK or Switzerland (GDPR)
You have the right to: access your data; correct it; delete it; restrict or object to processing, including processing based on our legitimate interests; data portability; and, where we rely on consent, to withdraw that consent at any time (withdrawal does not affect processing already carried out). You also have the right to lodge a complaint with your local supervisory authority.
If you are in California (CCPA/CPRA)
You have the right to know what personal information we collect and how we use and disclose it; to delete it; to correct it; to opt out of sale or sharing; and to limit the use of sensitive personal information. You also have the right not to be discriminated against for exercising any of these rights.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.
To exercise any right, use the in-app controls or email privacy@ulyssify.com. We will verify your request against your account, usually by confirming control of your registered email address, and we will respond within the time the law requires. You may use an authorized agent where the law allows it.
Other US states
If you live in a state with its own comprehensive privacy law (for example Colorado, Connecticut, Virginia, Utah, Texas, Oregon or Montana), you have broadly similar rights of access, correction, deletion, portability and opt-out. Use the same contact and we will honor them.
15. Security
We protect your information with encryption in transit, one-way hashing of passwords (PBKDF2), per-device tokens you can revoke individually, access controls on our production systems, and vendors chosen for their security posture. We keep a device list in the app so you can see where your account is signed in.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant regulators as required by law.
16. Children
Ulyssify is a general-audience product and is not directed to children under 13. When you create an account, you confirm that you are at least 13 (see our Terms of Service). We do not knowingly collect personal information from anyone under 13.
If you believe a child under 13 has created an account, write to privacy@ulyssify.com and we will delete the account and its data. In some countries the minimum age for consent to online services is higher than 13, and where that is the case the local minimum applies to you.
17. Marketing communications
If you opt in, we may send you marketing or promotional emails about Ulyssify, such as product news and offers. Every marketing email includes an unsubscribe link, and you can opt out at any time in your settings or by contacting privacy@ulyssify.com. We do not send marketing email without your consent, and account and security messages are not marketing, so we send those regardless of your marketing choice.
18. Cookies
We use a small number of essential first-party cookies to run the website: a session cookie that keeps you signed in, and a CSRF cookie that protects your account against cross-site request forgery. These are strictly necessary to operate the service, so they do not require a consent banner, and they cannot be turned off while you are signed in.
We do not use cookies for advertising, analytics, or tracking, we do not set third-party tracking cookies, and we do not use web beacons or tracking pixels.
19. Changes to this policy
We may update this policy. When we make a material change we will update the "Last updated" date above, and we will notify you in the app or by email before the change takes effect. Where the law requires your renewed consent, we will ask for it.
20. Contact us
Questions, requests, or anything that looks wrong in this policy:
Email: privacy@ulyssify.com Postal: Ulyssify, Inc., 400 Corporate Pointe, Suite 300, Culver City, CA 90230
If you are in the EEA or UK and you are not satisfied with our response, you may complain to your local data protection authority.