개인정보 보호

개인정보처리방침

시행일: 2026년 10월 1일

MomenTap은 사용자가 자신의 앱과 웹사이트 사용 습관을 관리하도록 돕습니다. 계정을 만들지 않으며 광고·분석·추적 SDK를 사용하지 않습니다.

1. 개발자가 수집하는 데이터

현재 버전의 앱 자체는 개인정보나 사용 데이터를 개발자 또는 제3자 서버로 자동 전송하거나 수집하지 않습니다. 사용자가 앱 밖에서 선택적으로 제출하는 공개 지원 이슈와 이메일 문의는 6절에서 별도로 설명합니다.

  • 계정, 이름, 이메일과 연락처를 요구하지 않습니다.
  • 선택한 앱·카테고리·웹사이트, 입력한 목적과 상세 사용 기록을 개발자에게 전송하지 않습니다.
  • 광고 식별자나 다른 앱·웹사이트의 활동을 이용한 추적을 하지 않습니다.
  • 제3자 광고·분석 서비스를 사용하지 않습니다.

2. 기기 안에서 처리하는 데이터

내부 테스트 후보에서 웹사이트 보호 화면이 임시 허용 설정 진입을 제공하는 경우, 선택한 웹사이트의 불투명 토큰 하나와 요청 식별자·시각·요청 형식 표식을 앱과 확장 프로그램 사이에 일시적으로 전달합니다. 목적과 허용 시간을 앱에서 확인한 뒤에만 임시 허용을 시작합니다. 웹사이트 주소·개별 페이지·목적 입력 내용은 이 요청에 저장하지 않으며, 요청 파일은 기기 백업에서 제외하고 소비 또는 데이터 초기화 시 정리합니다. Safari에 이 사용자 지정 화면이 표시된다는 보장은 없으며 기존 보호 탭의 웹사이트 허용 경로를 유지합니다.

진단 메뉴를 제공하는 이전 버전에서 사용자가 설정의 Shield 진단을 시작하면 5분 동안 호스트 저장 확인과 앱·웹사이트·카테고리 버튼 처리의 종류, 임의 진단 식별자와 시각만 이 iPhone의 앱·확장 전용 영역에 저장합니다. 기본적으로 꺼져 있으며 앱 이름, 웹사이트 주소, Screen Time 토큰, 입력 목적, 통계나 실제 방문·사용 횟수는 기록하거나 자동 전송하지 않습니다. 종류별 한 항목만 보관하고 수집은 시작 5분 뒤 자동 중단됩니다. 결과는 시작 24시간 이후 다음 앱 실행 또는 진단 화면 확인 때 삭제되며, 새 진단 시작·진단 결과 삭제·모든 앱 데이터 초기화로도 삭제됩니다. 파일은 기기 백업에서 제외되며 iOS Data Protection을 사용합니다. 사용자는 원할 때 결과 화면을 직접 캡처해 지원 요청에 사용할 수 있습니다. 이는 선택적 기술 진단이며 기존 선택 기록·보호 설정을 변경하지 않습니다. 내부 테스트 Build 16부터 화면 구성 호출은 파일에 기록하지 않습니다. 보호 화면의 고정 진단 표식은 5분 기록 여부와 독립적인 표시용 텍스트이며, 표식이나 화면 구성 결과를 저장·전송하지 않습니다. 이전 빌드의 구성 진단 기록은 더 이상 표시하지 않고 같은 보관·삭제 규칙으로 정리합니다.

Build 24부터는 설정의 Shield 진단 메뉴를 제공하지 않으며 새 진단을 시작하거나 결과 화면을 조회하는 기능도 제공하지 않습니다. 이전 버전에서 이미 저장된 진단은 시작 24시간이 지난 뒤 다음 앱 실행 또는 앱 복귀 때 정리하며, 모든 앱 데이터 초기화로도 삭제합니다. 기존 진단의 5분 수집 중단·백업 제외·비전송 규칙은 유지됩니다.

화면 모드를 제공하는 버전에서는 시스템 설정·라이트·다크 중 선택한 값만 이 iPhone의 표준 앱 설정 저장소에 보관합니다. 기본값은 시스템 설정이며, 모든 앱 데이터 초기화가 성공하면 시스템 설정으로 돌아갑니다. 화면 모드는 행동 기록이나 Screen Time 선택을 포함하지 않으며 앱·확장 공유 영역, 위젯, Live Activity 또는 개발자 서버에 전달하지 않습니다. 화면 모드와 마지막 선택 탭 같은 간단한 UI 환경설정은 기기 설정에 따라 운영체제의 기기 백업에 포함될 수 있습니다. 이는 아래에 명시한 선택 토큰·기록 파일의 백업 제외 및 앱 자체의 iCloud 동기화·기록 복원 미지원과 구분됩니다.

기능 제공을 위해 다음 최소 상태를 사용자의 기기 안에 저장할 수 있습니다.

  • Apple Screen Time이 제공하는 불투명한 앱·카테고리·직접 선택 웹사이트 token
  • 재부팅 뒤 권한 재승인 시 보호 복원 여부를 판단하는 마지막 보호 ON/OFF Boolean. 이 설정에는 선택 token, 대상 이름, 시각과 행동 기록이 없습니다.
  • 정확한 앱 하나 또는 사용자가 MomenTap에서 직접 고른 정확한 웹사이트 하나의 임시 허용과 Shield 복원에 필요한 불투명 application/WebDomain token, 요청·세션 식별자와 시각
  • 늦게 도착한 시스템 복원 callback이 종료·권한 상실·초기화 뒤 이전 대상을 다시 변경하지 못하게 하는 무작위 세대 식별자·순번·처리 상태와 callback 소유권을 조정하는 단조 증가 시스템 가동 시간 snapshot. 이 안전 메타데이터에는 앱·웹사이트 token, 평문 도메인·URL, 입력 목적이 없습니다.
  • 잠금 화면과 Dynamic Island 카운트다운에 필요한 세션 상태와 시각
  • 사용자가 기기 내 기록을 켠 뒤 발생한 의도적 임시 허용과 습관적 실행 중단의 임의 식별자, 시각, 계획 만료 시각과 종료 사유
  • 사용자가 앱별 기록도 켠 뒤 새로 발생한 선택을 구분하기 위한 무작위 로컬 앱 참조와 Apple Screen Time의 불투명 application token
  • 사용자가 웹사이트별 기록도 켠 뒤 MomenTap에서 새로 시작한 웹사이트 임시 허용을 구분하기 위한 무작위 로컬 웹사이트 참조와 Apple Screen Time의 불투명 WebDomain token

선택 기록은 기본적으로 꺼져 있습니다. 최초 기기 내 기록 시작은 대상 식별 정보가 없는 전체 선택 기록만 켭니다. 앱별 기록과 웹사이트별 기록은 각각 별도의 기본-off 기능이며, 동의 뒤 새로 생긴 선택만 구분하고 이전 전체 기록을 소급 연결하지 않습니다. 행동 이벤트에는 무작위 대상 참조만 저장하고, 그 참조와 불투명 application 또는 WebDomain token의 연결은 기기 안의 별도 파일에 보관합니다. 앱은 token을 앱·웹사이트 이름으로 해석하지 않으며 Apple의 시스템 화면 요소가 표시 정보를 렌더링합니다.

목적 분류 기록

목적 분류 기록을 제공하는 버전에서는 이 설정이 신규·기존 사용자 모두 기본으로 켜져 있습니다. 전체 기록의 기존 설정은 유지되며, 전체 기록이 켜져 있을 때에만 임시 허용 시작 시 선택한 연락하기·정보 확인하기·할 일 처리하기·잠깐 쉬기·직접 적기 중 하나의 분류를 이 iPhone의 앱 저장 공간에 보관합니다. ‘직접 적기’를 선택해도 입력한 문장은 현재 화면에서만 사용하며 저장·공유하지 않습니다. 목적 분류로 기간별 허용 횟수와 Shield 해제 시간을 보여주며 실제 사용 시간이나 목적 달성 여부를 측정하지 않습니다. 이전 기록의 목적을 추정하지 않습니다.

설정에서 목적 분류 기록을 끄면 확인 후 저장된 분류만 삭제하고 전체·앱별·웹사이트별 기록은 유지합니다. 다시 켜도 삭제된 분류는 복원되지 않습니다. 전체 기록을 끄면 새 목적 기록도 중단되지만 기존 분류는 선택한 보관 기간까지 유지됩니다. 기록 삭제·모든 앱 데이터 초기화·보관 기간은 목적 분류에도 적용됩니다. 목적 분류는 위젯·Live Activity·앱과 확장 프로그램의 공유 저장 공간(App Group)에 공유하거나 개발자 서버로 전송하지 않습니다. 전체 기록의 기본 꺼짐과 앱별·웹사이트별 기록의 별도 동의는 유지됩니다.

로컬 기록은 기록 기능을 켠 시각과 끈 시각도 선택 기록과 같은 보관 기간 동안 함께 보관합니다. 이는 달력에서 선택 횟수 0회와 기록이 꺼져 있던 구간을 구분하기 위한 기기 내 상태이며 앱·웹사이트 token이나 대상 이름을 포함하지 않습니다. 보관 기간 설정을 추가한 schema v6으로 이관할 때 기존 기록과 동의를 보존하고 보관 기간은 90일로 유지합니다. 과거의 빈 기간을 기록된 0회로 추정하지 않습니다.

홈 화면 위젯이 제공되는 버전에서는 오늘의 전체 의도적 허용·습관적 멈춤 횟수, 기록 상태·기록된 구간 여부, 날짜 범위·시간대와 마지막 집계 시각을 담은 최소 요약을 앱과 위젯이 함께 접근하는 이 iPhone의 저장 공간에 저장합니다. 위젯을 추가해도 기본적으로 꺼져 있는 선택 기록이 자동으로 켜지지 않습니다. 기록 OFF 상태의 새 요약에는 기존 기록의 횟수를 담지 않습니다. 앱·웹사이트 이름, 선택 토큰, 입력한 목적, 개별 행동 기록과 실제 사용 시간은 위젯 요약에 포함하지 않으며, 원본 기록은 앱 내부 저장 공간에 유지합니다.

위젯은 앱이 마지막으로 집계한 내용을 표시하므로 최근 행동이 아직 반영되지 않을 수 있습니다. 기록을 끄거나 기록 삭제·모든 앱 데이터 초기화·보관 기간 변경을 실행하면 이전 요약을 정리하고 표시 갱신을 요청합니다. 요약 정리 실패가 원본 기록 중단·삭제를 막지 않도록 정리를 재시도하며, 오류가 남으면 앱에서 알립니다. 변경 뒤 현재 설정과 남은 기록에 맞춘 요약을 다시 만들 수 있습니다. iOS가 이미 저장해 표시 중인 위젯 화면은 즉시 없어지지 않을 수 있습니다. 요약 파일은 iCloud·기기 백업에서 제외하며 서버로 전송하지 않습니다. 앱 자체는 위젯을 위해 새로운 네트워크 전송이나 클라우드 동기화를 하지 않습니다.

총 허용 시간과 최근 7일 요약을 제공하는 위젯 버전에서는 오늘의 총 허용 시간과, 오늘을 포함한 연속 7일의 날짜별 허용·멈춤 횟수 및 기록 범위를 같은 iPhone의 앱·위젯 공유 공간에 보관합니다. 기존에 동의하여 저장한 로컬 기록을 집계하며 새 행동 데이터를 수집하지 않습니다. 총 허용 시간은 마지막 집계 시점까지의 Shield 해제 시간이며 실제 앱·웹사이트 사용 시간이나 절약한 시간이 아닙니다. 미기록·부분 기록은 확인된 0회와 구분하고, 시간 정보가 없는 이전 요약은 0으로 추정하지 않습니다. 앱을 열지 않은 동안의 변화는 아직 반영되지 않을 수 있습니다. 기록 기능이 꺼져 있으면 횟수·시간 숫자를 표시하지 않고 과거 7일 요약도 공유하지 않습니다. 요약에는 원시 이벤트, 앱·웹사이트 이름이나 token을 넣지 않으며 기기 백업에서 제외하고 서버로 전송하지 않습니다. 기존 동의, 삭제·초기화 때의 요약 정리·재시도와 iOS 표시 캐시의 한계는 그대로 적용됩니다.

기록을 켠 상태에서 Shield의 습관적으로 열었어요를 선택하면 앱과 extension 사이의 전용 공유 영역에 기록 동의 상태, 임의 이벤트 식별자와 시각을 잠시 저장합니다. 앱별 기록에도 동의한 경우에만 해당 application token을 이 일회성 항목에 추가하며, 앱이 기록 파일과 별도 token 인덱스로 가져온 뒤 삭제합니다.

앱 이름, 평문 도메인, URL 경로·개별 페이지, Screen Time 앱 카테고리 이름, 사용자가 자유롭게 입력한 목적 문장과 원시 Screen Time 사용 기록은 저장하지 않습니다. 앱별 통계는 MomenTap에서 선택한 허용·멈춤 횟수이고 실제 앱 사용 시간이 아닙니다. 웹사이트별 통계는 MomenTap에서 시작한 임시 허용 횟수·종료 상태와 Shield가 해제된 경과 시간이며, 실제 방문 여부나 브라우저 사용 시간이 아닙니다. 총 허용 시간도 실제 앱이나 웹사이트를 사용한 시간이 아니라 Shield를 잠시 풀어 둔 시간입니다. 사용자가 자유롭게 입력한 목적은 화면에 표시되는 동안만 메모리에 두며 파일에 저장하지 않습니다.

Safari에서는 선택 웹사이트가 Apple의 기본 제한됨 화면과 확인 버튼으로 표시되며 MomenTap의 사용자 지정 동작은 표시되지 않습니다. 웹사이트 임시 허용은 이 제한 화면에서 시작하지 않고, MomenTap의 보호 탭에서 사용자가 직접 선택한 웹사이트 하나를 골라 5·10·15분 중 하나로 시작합니다. 브라우저를 자동으로 열지 않으며, 허용 중에도 다른 선택 웹사이트와 카테고리는 계속 보호합니다. 이때 복원에 필요한 정확한 불투명 WebDomain token 하나와 세션 식별자·시각·상태만 허용 세션 동안 기기 안의 앱·extension 전용 영역에 저장합니다. 기기 내 기록이 켜져 있으면 대상 식별 정보 없는 전체 의도적 허용 기록에 포함될 수 있습니다. 웹사이트별 기록도 켠 경우에만 그 뒤 MomenTap에서 시작한 허용을 무작위 로컬 참조와 별도 불투명 WebDomain token 인덱스로 구분합니다. 평문 도메인, URL·경로·개별 페이지, 사용자가 자유롭게 입력한 목적 문장, Safari Shield의 습관 중단, 실제 방문·체류 시간은 기록하지 않습니다. 이전 시험 빌드가 만든 웹사이트별 동의와 token 연결은 schema v4 이관에서 전체 기록과 앱별 연결을 보존한 채 삭제하므로 새 웹사이트별 기록이 자동으로 켜지지 않습니다.

3. Apple 시스템 서비스

앱·카테고리·웹사이트 선택, Shield, Device Activity, Live Activity와 홈 화면 위젯은 Apple이 제공하는 시스템 기능을 사용합니다. 사용자는 Screen Time 권한을 직접 승인하고 iPhone 설정에서 철회할 수 있습니다. Apple의 공개 API는 모든 서브도메인이나 모든 브라우저에서 동일한 보호를 보장하지 않으며, URL 경로·개별 페이지를 앱이 저장하거나 보호 단위로 취급하지 않습니다. Apple의 시스템 처리에는 Apple의 개인정보 보호정책과 기기 설정이 적용됩니다.

앱에서 선택적으로 제공하는 일회성 개발자 후원은 Apple의 StoreKit과 App Store 결제 시스템이 처리합니다. 개발자는 결제 카드나 결제 수단 정보에 접근하지 않습니다. 앱은 거래 식별자, 영수증, 후원 내역이나 후원자 프로필을 파일 또는 개발자 서버에 저장하지 않으며, 후원 여부에 따라 기능·콘텐츠·고객지원을 다르게 제공하지 않습니다.

4. 보관과 삭제

  • 활성 세션 상태는 세션 종료 또는 만료 정리가 끝나면 삭제됩니다.
  • 임시 허용의 대상 token을 포함한 상태와 callback 조정 파일은 요청 소비, 만료 복원, 수동 종료, 권한 상실 또는 전체 초기화의 안전한 정리 절차가 성공하면 삭제됩니다. 정리가 중단되거나 진행 중 callback을 안전하게 구분할 수 없으면 접근을 열어 두지 않기 위해 필요한 상태를 일시 보존하고 다음 실행에서 정리를 재시도할 수 있습니다. 늦은 시스템 callback을 차단하는 데 필요한 최소 무작위 terminal epoch·순번·처리 상태 tombstone은 전체 초기화 뒤 새 값으로 교체해 기기에 유지하며 앱·웹사이트 token, 도메인·URL, 목적과 행동 기록을 포함하지 않습니다.
  • 보호를 켠 기존 구성에서 재부팅 뒤 시스템이 권한을 요청 전 또는 거부됨으로 일시 표시할 수 있으므로, 앱의 passive 권한 확인만으로 앱·카테고리·웹사이트 선택을 삭제하지 않습니다. 사용자가 앱 안의 권한 요청에서 명시적으로 거부하거나 선택 초기화·전체 초기화를 실행하면 선택과 보호 의도 설정을 삭제합니다. 재승인에 성공하면 보호 의도가 켜져 있던 선택을 다시 적용합니다.
  • 선택 기록의 기본 보관 기간은 90일입니다. 보관 기간 설정이 제공되는 버전에서는 설정에서 180일, 1년(365일), 영구(사용자 삭제 시까지)를 선택할 수 있습니다. 전체·앱별·웹사이트별 기록, 참조되는 token 연결과 기록 기능 ON/OFF 구간에 같은 기간이 적용됩니다. 기존 사용자는 90일을 유지하며 더 긴 보관은 직접 선택해야 합니다.
  • 보관 기간을 줄이면 확인 후 오래된 기록과 해당 기록에만 연결된 식별 정보를 삭제합니다. 기간을 늘려도 이미 삭제된 기록은 복원되지 않습니다. 유한 보관 기간은 기록을 꺼도 적용되며 앱이 기록을 불러오거나 추가할 때 지난 기록을 정리합니다. 앱이 실행되지 않는 동안 정확한 시각의 삭제는 보장하지 않습니다.
  • 영구 보관은 기간에 따른 자동 삭제만 비활성화합니다. 앱별·웹사이트별 기록 기능 해제와 확정된 권한 상실에 따른 식별 연결 삭제, 기록 삭제와 모든 앱 데이터 초기화의 기존 삭제 규칙은 유지됩니다. 기록 삭제는 선택한 보관 기간을 유지하며 모든 앱 데이터 초기화는 기본 90일로 되돌립니다.
  • 기록은 이 iPhone에만 보관하며 iCloud 동기화나 앱 삭제·기기 분실 이후 복원 기능은 제공하지 않습니다. 기록 파일은 iCloud·기기 백업에서도 제외됩니다.
  • 기록 일시중지는 기존 전체 기록을 유지하고 새 기록을 중단합니다. 앱별 또는 웹사이트별 기록만 끄거나 Screen Time 권한 상실이 확정되면 해당 token 연결과 구분만 삭제하고 대상 식별 정보 없는 전체 횟수는 유지합니다.
  • Screen Time 선택 토큰, 선택 기록·대상별 토큰 인덱스, 임시 허용 공유 상태·복원 조정 메타데이터, 진단 및 위젯 요약 파일은 백업에서 제외되고 iOS Data Protection을 사용합니다. 간단한 UI 환경설정의 OS 백업 가능성은 2절을 따릅니다.

모든 앱 데이터 초기화는 앱 소유 데이터와 Shield 요청을 정리합니다. 초기화 뒤에는 과거 시스템 callback이 이전 보호 대상을 되살리지 못하게 하는 대상 비식별 안전 tombstone만 유지됩니다. 이 동작은 시스템 Screen Time 권한 자체를 철회하지 않습니다.

5. 공유와 판매

앱은 사용자 데이터를 개발자 서버나 제3자에게 전송하지 않으므로 판매하거나 광고 목적으로 공유하지 않습니다.

6. 웹사이트와 선택적 지원 요청

이 회사 소개·지원·개인정보 페이지는 Cloudflare Pages에서 호스팅됩니다. Cloudflare는 웹페이지 제공과 보안을 위해 IP 주소와 요청 정보 같은 기술 데이터를 자체 방침에 따라 처리할 수 있습니다. 이 사이트에는 별도 분석·추적 스크립트나 입력 양식을 추가하지 않았습니다. Cloudflare의 처리에는 Cloudflare Privacy Policy가 적용됩니다.

사용자는 도움이 필요할 때 외부 서비스인 GitHub의 공개 이슈를 선택적으로 이용할 수 있습니다. 이 경우 GitHub 계정명, 사용자가 작성한 내용과 작성 시각이 공개되고 개발자가 고객지원 목적으로 확인할 수 있습니다. 앱은 이 정보를 자동으로 전송하지 않습니다. 공개 이슈에 개인정보, 앱·카테고리·웹사이트 이름, URL, Screen Time 선택 정보, token, Apple 계정과 기기 식별자를 작성하지 마세요.

이메일로 문의하면 회신에 필요한 발신 이메일 주소와 사용자가 작성한 내용을 개발자가 확인할 수 있습니다. 문의 메일은 iCloud Mail을 통해 수신하며 Apple 개인정보 처리방침도 적용됩니다. 앱은 문의 메일이나 지원 정보를 자동으로 전송하지 않습니다. 이메일에도 Screen Time token 등 민감한 정보를 보내지 마세요.

GitHub에서 처리되는 정보에는 GitHub General Privacy Statement가 적용됩니다.

7. 아동의 개인정보

앱은 부모·자녀 감독 서비스가 아니라 사용자가 자신의 사용 습관을 관리하는 도구입니다. 사용자 계정이나 개인정보를 수집하지 않습니다.

8. 방침 변경

서버 동기화, 분석 SDK 또는 새로운 데이터 처리가 추가되면 기능을 배포하기 전에 이 방침과 App Store 개인정보 표시를 갱신합니다. 중요한 변경은 이 페이지의 시행일을 변경해 알립니다.

9. 문의

개인정보 문의는 contact@ianji.net로 보내주세요. 공개 지원 이슈도 이용할 수 있으나, 공개 이슈에 개인정보나 Screen Time 선택 정보를 작성하지 마세요.

Privacy

Privacy Policy

Effective: October 1, 2026

MomenTap helps people manage their own app and website-use habits. It does not create user accounts and does not include advertising, analytics, or tracking SDKs.

1. Data Collected by the Developer

The current version of the App itself does not automatically transmit or collect personal information or usage data to the developer or third-party servers. Optional public support issues and email inquiries submitted outside the App are described separately in Section 6. The App does not request an account, name, email address, or contacts; use advertising identifiers; track activity across other companies’ apps or websites; or use third-party advertising or analytics services.

2. Data Processed on the Device

In the internal test candidate, when a website shield offers entry to temporary-allowance settings, one opaque website token, a request identifier, a timestamp, and a request-format marker are temporarily shared between the app and its extensions. An allowance starts only after you confirm your purpose and duration in the app. This request does not store a website address, individual page, or purpose text. Request files are excluded from device backups and removed when consumed or when app data is reset. This does not guarantee that Safari displays the custom shield; the existing website-allowance route in the Protection tab remains available.

In earlier versions that provide the diagnostics menu, when you start Shield diagnostics in Settings, host storage checks and app, website or category button callback types, a random diagnostic identifier and timestamps are stored in the app-and-extension shared area on this iPhone for a five-minute recording window. Diagnostics are off by default. App names, website addresses, Screen Time tokens, purpose text, statistics and actual visit or usage counts are not recorded or automatically transmitted. Only one entry per event type is retained. Recording stops five minutes after starting. Results are deleted on the next app launch or diagnostic refresh after 24 hours, or when you start a new diagnostic, delete diagnostic results or reset all app data. Files are excluded from device backups and use iOS Data Protection. You may choose to capture the results screen for a support request. This optional technical diagnostic does not change existing choice history or protection settings. Starting with internal test Build 16, shield configuration callbacks are not recorded to files. Fixed diagnostic markers on shields are display-only text, independent of five-minute recording; neither markers nor configuration results are stored or transmitted. Configuration diagnostic records from earlier builds are no longer displayed and follow the same retention and deletion rules.

Starting with Build 24, Settings no longer provides the Shield diagnostics menu, and you cannot start a new diagnostic or view its results in the App. Diagnostic records already saved by earlier versions are cleaned up on the next app launch or return to the foreground after 24 hours from their start, or when all app data is reset. The existing five-minute recording limit, backup exclusion and no-automatic-transmission rules still apply.

In versions with appearance settings, only your choice of System, Light or Dark is kept in this iPhone's standard app preferences. The default is System, and a successful reset of all app data restores that default. The appearance preference contains no behavior history or Screen Time selection and is not passed to shared app-and-extension storage, widgets, Live Activities or developer servers. Simple UI preferences, such as appearance and the last selected tab, may be included in operating-system device backups depending on device settings. This is separate from the backup exclusion for selection-token and history files described below and does not provide app-managed iCloud synchronization or history restoration.

The App may store opaque application, category, and directly selected website tokens supplied by Apple Screen Time; the last protection on/off Boolean used to decide whether protection should be restored after authorization is granted again following a reboot; an opaque application or WebDomain token, request and session identifiers, and timestamps needed for a temporary allowance and Shield restoration for one exact application or one exact website directly chosen in MomenTap; state needed for the Lock Screen and Dynamic Island countdown; and random identifiers, timestamps, planned expiration time, and end reason for intentional temporary allowances and habitual launches stopped after the user enables on-device history. The protection-intent setting contains no selection token, target name, timestamp, or behavior history.

Random generation identifiers, sequence values, dispositions, and a monotonic system-uptime snapshot coordinate callback ownership and prevent a late system restoration callback from changing an earlier target after completion, authorization loss, or reset. This safety metadata does not contain an application or website token, plaintext domain or URL, or typed purpose.

On-device history is off by default. The first Start On-Device History action enables aggregate choice history without target identities. Per-app and per-website history are separate opt-ins available in History or Settings and apply only to choices recorded after each opt-in; earlier aggregate records are not retroactively linked to a target. Behavior events contain only a random target reference, while the link between that reference and an opaque application or WebDomain token is kept in a separate on-device file. The App does not interpret a token as an app or website name; Apple's system label renders the display information.

Purpose category recording

In versions with purpose category recording, this setting is on by default for both new and existing users. Your existing overall recording setting is preserved. Only while overall history is enabled, the App saves one category selected when starting an allowance—contact someone, check information, take care of a task, take a short break, or write my own—in the App's storage on this iPhone. Even when you select Write My Own, written text is used only on the current screen and is never saved or shared. Categories summarize allowance counts and time unshielded, not actual usage or task completion. Past purposes are not inferred.

Turning purpose recording off in Settings deletes only saved categories after confirmation, preserving overall, app and website history. Turning it back on does not restore deleted categories. Turning overall recording off also stops new purpose records but keeps existing categories for the selected retention period. History deletion, full app-data reset and retention apply to categories as well. Purpose categories are not shared with widgets, Live Activities or shared app-and-extension storage (App Group), or transmitted to developer servers. Overall recording remains off by default, and app and website history remain separate opt-ins.

Local history also keeps the times when recording was turned on and off for the same retention period as choice history. This device-only state distinguishes a true zero from a period when recording was off; it contains no app or website token or target name. Migration to schema v6, which adds the retention setting, preserves existing history and consent and keeps the 90-day default. Earlier empty periods are not inferred to be recorded zeros.

In versions that provide a Home Screen widget, a minimal summary is stored in an area on this iPhone accessible to the app and widget. It contains today’s overall intentional-allowance and habitual-stop counts, recording status and coverage, the date range and time zone, and the last aggregation time. Adding a widget does not enable choice recording, which is off by default. A new summary made while recording is off does not retain counts from existing history. The widget summary does not contain app or website names, selection tokens, entered intentions, individual behavior records, or actual usage duration. Original history remains in the app’s own storage.

The widget reflects the app’s last aggregation and may not include recent actions. Turning recording off, deleting history, resetting all app data, or changing retention clears the previous summary and requests a display update. If summary cleanup fails, the app continues the requested stop or deletion of original history and retries summary cleanup; it reports an error if cleanup still fails. A new summary may be generated from the resulting settings and remaining history. Immediate removal of a widget display already cached by iOS is not guaranteed. Summary files are excluded from iCloud and device backups and are not sent to a server. The app itself does not add network transmission or cloud synchronization for the widget.

Widget versions with total allowed time and recent seven-day summaries keep today's total allowed time, daily allowance and stop counts, and recording coverage for seven consecutive days including today in shared app and widget storage on the same iPhone. They aggregate existing local records saved with your consent without collecting new behavior data. Total allowed time is the time Shield protection was lifted up to the last aggregation, not actual app or website usage or time saved. Unrecorded and partially recorded days are distinguished from confirmed zero counts, and older summaries without a time value are not assumed to be zero. Changes while the app is not opened may not yet be reflected. When recording is off, counts and time values are not displayed and the previous seven-day summary is not shared. Summaries exclude raw events, app or website names, and tokens; they are excluded from device backups and are not sent to a server. Existing consent, summary cleanup and retry behavior after deletion or reset, and iOS display-cache limitations continue to apply.

When history is enabled and the user chooses I opened it out of habit on a Shield, a dedicated area shared by the App and its extension briefly stores consent state, a random event identifier, and a timestamp. It adds the exact opaque application token only while per-app history is also enabled, and deletes the item after import.

The App does not store app names, plaintext domains, URL paths or pages, Screen Time app category names, written purpose text, or raw Screen Time usage records. Per-app statistics are counts of Allow and Stop choices made in MomenTap, not actual time spent in each app. Per-website statistics are the count and end state of temporary allowances started in MomenTap and the elapsed time while the Shield was removed, not proof of a visit or browser-use time. Total allowance time is the time a Shield was temporarily removed, not actual app or website use. A purpose typed by the user remains in memory only while the relevant screen is active and is not saved to a file.

In Safari, selected websites remain displayed with Apple's standard Restricted page and OK button; MomenTap's custom actions are not shown there. A website temporary allowance is started separately in MomenTap's Protection tab, where the user chooses one directly selected website and a 5-, 10-, or 15-minute duration. The App does not open a browser automatically, and other selected websites and categories remain protected during the allowance. The App stores only the exact opaque WebDomain token and session identifiers, timestamps, and state required to restore protection in an App-and-extension-only area on the device. If aggregate on-device history is enabled, the allowance may be included without a target identity. Only when per-website history is also enabled does the App distinguish later allowances started in MomenTap using a random local reference and a separate opaque WebDomain-token index. It does not record a plaintext domain, URL, path, individual page, typed purpose, habitual-stop action from Safari's Shield, actual visit, or browsing duration. Website consent and token links created by earlier test builds are deleted during the schema-v4 upgrade while aggregate and per-app history remain intact, so the new per-website history opt-in is not enabled automatically.

3. Apple System Services

Application, category, and website selection, Shields, Device Activity, Live Activities, and Home Screen widgets use system features provided by Apple. The user grants Screen Time authorization directly and can revoke it in iPhone Settings. Apple’s public APIs do not guarantee identical protection for every subdomain or browser. The App does not store or treat URL paths or individual pages as protection units. Apple’s privacy policy and device settings apply to Apple’s processing of these system features.

Optional one-time developer support is processed by Apple’s StoreKit and App Store payment system. The developer does not have access to payment-card details. The App does not save transaction identifiers, receipts, support history, or a supporter profile, and support does not change access to features, content, or customer service.

4. Retention and Deletion

Active session state is deleted after the session ends or expiration cleanup succeeds. Target-bearing temporary-allowance state and callback-coordination files are deleted after safe cleanup for consumption, expiration restoration, manual ending, authorization loss, or reset succeeds. If cleanup is interrupted or an in-progress callback cannot be distinguished safely, the App may temporarily retain the state and retry cleanup on a later run instead of reopening access. A minimal random terminal epoch, sequence, and disposition tombstone is replaced and retained on the device after reset solely to reject late system callbacks; it contains no application or website token, domain, URL, purpose, or behavior history.

After a reboot, the system may temporarily report authorization as Not Determined or Denied for an existing protection-on configuration. The App therefore does not delete application, category, or website selections based only on a passive authorization check. It deletes the selection and protection-intent setting when the user explicitly denies an authorization request inside the App, clears the selection, or resets all App data. After authorization succeeds again, the App reapplies a saved selection whose protection intent was on. Choice history is kept for 90 days by default. Versions with the retention setting let you choose 180 days, one year (365 days), or forever (until you delete it) in Settings. The same window applies to overall, app and website history, referenced token links, and recording on/off intervals. Existing users keep 90 days unless they choose a longer period.

Shortening the window deletes older records and identity links used only by those records after confirmation. Extending it cannot recover deleted history. Finite retention still applies while recording is off; expired records are cleaned up when the app loads or adds history, not at a guaranteed background deadline.

Forever only disables age-based deletion. Existing rules for removing identity links when per-app or per-website history is disabled or authorization loss is confirmed, deleting history, and resetting all app data still apply. Clearing history keeps the selected retention period; resetting all app data restores the 90-day default. History remains on this iPhone. iCloud sync and restoration after app deletion or device loss are not available, and history files are excluded from iCloud and device backups.

Pausing history keeps existing aggregate records while stopping new records. Disabling only per-app or per-website history, or confirmed loss of Screen Time authorization, removes the corresponding token links and attribution while preserving aggregate counts. Screen Time selection-token files, choice history and target-token indexes, shared allowance state and restoration-coordination metadata, diagnostic files and widget summaries are excluded from backup and use iOS Data Protection. Section 2 explains the separate possibility of operating-system backup for simple UI preferences. Resetting App data leaves only the target-free safety tombstone described above and does not revoke the system Screen Time authorization itself.

5. Sharing and Sale

Because the App does not transmit user data to the developer or third parties, it does not sell or share user data for advertising.

6. Website and Optional Support Requests

These company, support, and privacy pages are hosted on Cloudflare Pages. Cloudflare may process technical data such as IP addresses and request information to serve and protect the website under its own policy. No separate analytics or tracking scripts or input forms have been added to this site. Cloudflare processing is governed by the Cloudflare Privacy Policy.

Users may optionally request help through public issues on the external GitHub service. A GitHub username, submitted content, and submission time will be public and may be accessed by the developer for customer support. The App does not transmit this information automatically. Do not include personal information, app, category, or website names, URLs, Screen Time selections or tokens, Apple account information, or device identifiers in a public issue. GitHub processing is governed by the GitHub General Privacy Statement.

If you contact the developer by email, the developer can access your sender email address and the message you submit to respond to your inquiry. Mail is received through iCloud Mail and the Apple Privacy Policy also applies. The App does not send email or support information automatically. Do not email sensitive information such as Screen Time tokens.

7. Children’s Privacy

The App is a self-management tool, not a parent-child supervision service. It does not collect user accounts or personal information.

8. Changes to This Policy

If server sync, analytics SDKs, or new data processing are added, this policy and the App Store privacy disclosure will be updated before those features are released. Material changes will be reflected by updating the effective date.

9. Contact

For privacy questions, email contact@ianji.net. You may also use a public support issue. Do not include personal information or Screen Time selections in a public issue.