ExcerLock

Privacy policy

Effective 8 September 2026. Applies to the ExcerLock iPhone app and to excerlock.com.

1. Who is responsible

ExcerLock is made and operated by Johan Sardar, an individual developer based in the United States. For the purposes of the GDPR, Johan Sardar is the data controller for the personal data described here.

Privacy questions and requests: privacy@excerlock.com. Everything else: support@excerlock.com.

2. The short version

3. What never leaves your iPhone

These are processed on the device and are never transmitted to us or to anyone acting for us.

4. What we collect, and why

This table is the complete list of what leaves your iPhone. It matches the App Privacy details filed for ExcerLock on the App Store.

DataWhy we have itWhere it goes
Email address To sign you in with an emailed code, and so a human can reply to a support request you send. Supabase (authentication), our own server (support reply address only)
Health data — minutes or distance from running and cycling workouts read from Apple Health To measure progress against a condition, and to keep a backup so a new phone can restore your history. Our own server. Never to analytics, crash reporting or subscription services.
Fitness data — daily step totals and walked minutes from the iPhone's motion sensors Same as above: progress against a condition, and a restorable backup. Our own server. Never to analytics, crash reporting or subscription services.
Your account identifier — one pseudonymous id To connect your account across sign-in, our server, your subscription and product analytics. It is the same id in all four. Supabase, our own server, Adapty, PostHog
A device identifier generated by our analytics tool To keep feature experiments consistent on one device. It is linked to your account once you sign in. An install that never signs in creates no profile. PostHog. Our crash reporting service receives no device or installation identifier.
Purchase history — subscription status, renewals, trials, refunds To know whether your subscription is active and to unlock the app for you. Adapty, mirrored to our own server; subscription lifecycle events reach PostHog through Adapty's own integration
Product interaction — which screens you opened and a fixed list of in-app events To see where the app is confusing and what people actually use. Every event is checked against an allowlist of property names and a closed list of allowed values, so free text cannot get through. PostHog, unless you turn analytics off
Shielded-app usage minutes — how many minutes per day you spent in the locked apps, as a single daily number To show you your own history and to keep it restorable. No app is ever identified. Our own server
Crash reports To find and fix crashes. These are not linked to your account: we never attach a user to a crash report, and the report is stripped of the error message, tags, request data, breadcrumb contents and source lines before it is sent. Sentry
Diagnostics attached to a support request — app version and build, iOS version, device model, permission statuses, entitlement status, how many conditions you have, and the result of the last enforcement run So a support reply can be useful without twenty questions. Sent only when you submit a support request. Our own server
Your conditions — activity, goal and schedule A backup so a new phone can restore your setup. Nothing here drives the locking, which runs on the device. Our own server
Four onboarding answers — age band, occupation, what you want to improve first, and your main reason for using ExcerLock To understand who the app is for and to group analytics. Each is a short value chosen from a fixed list of options, never free text. PostHog, unless you turn analytics off

We do not collect your precise or coarse location, your photos or videos, your contacts, your browsing history, financial information, or any content you write outside of a support message.

5. The permissions the app asks for

Screen Time (Family Controls)
Required. It is what lets ExcerLock shield the apps you chose. Apple gives the app an opaque handle to your selection, never the names.
Motion and fitness
For step counts and walked minutes, so walking conditions can be measured.
Apple Health
Read-only, and only for the workout types your conditions need. ExcerLock never writes to Health.
Location
Only if you create a gym condition. "While using the app" is enough for the manual version. "Always" is optional and only used to detect arriving at a saved gym automatically.
Camera
Only for the treadmill check, and only while that check is on screen. Frames are analysed live and never recorded or sent.
Notifications
Optional, and local to the device: a reminder before a trial ends and a warning before a live walking session lapses. ExcerLock has no push infrastructure and sends no marketing notifications.

6. Who processes data for us

Each of these companies handles a specific slice of the data above, on our instructions, under its own agreement with us.

Supabase
Accounts and sign-in. Holds your email address if you sign in with a code, or the address Apple or Google returns, which may be one of Apple's private relay addresses.
Adapty
Subscription management. Holds your subscription status and transactions, keyed to your account identifier.
PostHog
Product analytics and feature experiments. Configured so that no location is derived from your network address. You can switch it off, as described below.
Sentry
Crash and error reporting, with reports scrubbed of user identity and message content before they are sent. Performance tracing, profiling and session replay are all disabled.
Apple
Distributes the app, processes every payment, runs Sign in with Apple, and runs the Maps search used to find a gym. Apple's own privacy policy governs what Apple does with that.
Google
Only if you choose Sign in with Google, and only to establish that sign-in.
Email delivery
Sign-in codes are sent through Supabase. Support replies and any service email are sent through our email provider, Resend. We send no marketing email.
Our own server
A single virtual machine we operate, hosted with Google Cloud in the United States, running the backup and support endpoints described above.

7. Analytics, and how to turn them off

Open Settings in the app and turn off Share usage analytics. From that moment the app sends no screen views, no events and no onboarding answers, and the analytics tool itself is opted out. Nothing about the app stops working.

The subscription lifecycle events that Adapty forwards on our behalf, and crash reports, are separate from that switch. Crash reports carry no identity.

8. Tracking and advertising

ExcerLock does not track you across apps or websites owned by other companies. There is no advertising identifier, no App Tracking Transparency prompt, and no advertising or attribution SDK in the app. We do not sell personal information and we do not share it for cross-context behavioural advertising.

9. How long we keep things

10. Deleting your account and your data

In the app, open Settings and choose Delete account. That single action:

  1. deletes your profile, your synced conditions, your daily progress, your usage days, your earned unlocks and your support requests from our server;
  2. asks Adapty to erase your subscription profile;
  3. asks PostHog to erase your person record and its events;
  4. deletes your sign-in account at Supabase, last, once the steps above have confirmed.

You can also write to privacy@excerlock.com and we will do it for you. Include the email address you signed in with so we can find the account.

Deleting your account does not cancel your subscription. Apple owns that relationship. Cancel in iOS Settings under your Apple Account, then Subscriptions, before deleting.

11. Children

ExcerLock is for adults managing their own habits. It is not a parental-control app, it is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, write to privacy@excerlock.com and we will delete it.

12. If you live in California

Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we have collected about you, to request a copy of it, to have it corrected, and to have it deleted. You also have the right not to be discriminated against for exercising these rights, and there is nothing to discriminate with: ExcerLock behaves identically either way.

In the twelve months before the effective date of this policy we collected the categories listed in section 4: identifiers, health and fitness information, commercial information in the form of subscription history, internet or other electronic network activity in the form of in-app product interaction, and inferences limited to the four onboarding answers. Every category is collected for the business purposes stated beside it.

We have not sold or shared personal information, and we do not. We do not use or disclose sensitive personal information for any purpose other than providing the app, which under the CPRA means no right to limit its use applies.

To exercise any of these rights use Delete account in the app, or write to privacy@excerlock.com. We verify a request by confirming control of the account's email address. An authorised agent may act for you with written permission.

13. If you are in the EU, EEA, UK or Switzerland

You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to withdraw a consent you gave, and to receive your data in a portable form. Write to privacy@excerlock.com to exercise any of them.

Our legal bases are:

You have the right to complain to your local supervisory authority. We would rather you told us first.

14. Where your data is processed

ExcerLock is operated from the United States and our server and our processors are based there. If you use the app from outside the United States, the data described in section 4 is transferred there. Where a transfer of personal data out of the EEA, the UK or Switzerland requires a safeguard, it is made under the European Commission's Standard Contractual Clauses in our agreements with the processors named in section 6.

15. Security

Traffic between the app and our server is encrypted in transit with TLS. Sign-in tokens are held in the iPhone's Keychain. Access to our server and to each processor's dashboard is limited to the operator. The design choice that protects you most is the one in section 3: the most sensitive material, your app selection, your location and your camera, is never transmitted at all, so there is nothing there to breach.

No system is perfect. If we ever discover a breach affecting your personal data we will notify you and the relevant authority as the law requires.

16. Changes to this policy

If this policy changes we will update the effective date at the top and publish the new version here. For a change that materially affects how we handle your personal data, we will tell you in the app before it takes effect. Continuing to use ExcerLock after a change means the updated policy applies.

17. Contact

Johan Sardar, United States.
Privacy: privacy@excerlock.com
Support: support@excerlock.com