Privacy Policy
Swiftfox is a productivity app with a fox companion, built local-first: your tasks, habits, notes and health data live on your device. This policy explains what data leaves the device, when, why, and how to delete it.
Without an account (default)
The app is fully functional without signing up. In this mode all data — tasks, habits, focus sessions, goals, projects, mood, fox progress — is stored only on your device in iOS protected storage. We cannot access it, and we share it with no one.
Apple Health (optional)
With your permission, Swiftfox reads workouts, steps, distance and active minutes from Health to check off your fitness habits automatically, and writes completed focus sessions as mindful minutes. Raw Health data never leaves your device: the workouts, steps and measurements themselves are never sent to our servers. If you enable cross-device sync, only the derived habit value (for example “5000” for a Running habit) is uploaded — end-to-end encrypted, so we cannot read it. You can revoke access anytime in iOS Settings → Privacy → Health.
Calendar (optional)
With your permission the app shows your calendar events next to your tasks. Events are read locally via the system calendar. If you manually import an event into Swiftfox — to link it to a task or project — that copy becomes app content and takes part in sync alongside tasks and habits, end-to-end encrypted.
Account & social (optional)
Friends, the leaderboard, accountability and challenges require Sign in with Apple. After signing in, our server receives only:
- your account identifier and display name (changeable anytime);
- activity aggregates: daily XP, whether your norm was met, streak, fox level and stage — what friends see on the leaderboard;
- an “on vacation” flag — so friends can tell a planned pause from abandoned habits;
- your time-zone offset — so notifications arrive at a reasonable local time;
- a device token for push notifications (cheers, weekly recaps, challenge events).
Sync (optional)
If cross-device sync is enabled, the contents of tasks, habits and notes are transferred and stored end-to-end encrypted (E2E, AES-256-GCM): the encryption key lives in your iCloud Keychain and is never sent to the server. We are physically unable to read this content — the server stores ciphertext only.
Sync is part of the Swiftfox Pro subscription. If you subscribe, the server additionally stores an App Store transaction identifier, the product identifier and the expiry date, linked to your account — solely to unlock Pro on all your devices. Payment is handled entirely by Apple: payment and card details never reach us. These records are deleted together with your account.
What we don't do
- No ads, no data shared with ad networks.
- No selling or sharing data with third parties.
- No tracking across apps and websites.
- No third-party analytics SDKs.
- No data collection from children: the app is not directed at children under 13.
Storage & infrastructure
Server-side data (sections 4–5) is stored in Yandex Cloud data centers. All transport is HTTPS-only. Sign-in sessions expire automatically; a stolen refresh token is detected and revokes the session.
Deleting your data
- Local data — deleted together with the app.
- Account and all server data — the “Delete account” button in Settings deletes everything immediately and irreversibly: profile, aggregates, friendships, challenges, encrypted sync content, device tokens, Pro entitlement records.
- We keep an irreversible hash of your sign-in identifier indefinitely — with no name, email or any other data. It serves exactly one purpose: so that signing up again doesn't grant the free trial period a second time. It cannot be used to restore an account or to contact you.
- Technical delivery records for notifications (no content) are automatically erased within 90 days.
Your rights
You may request a copy or deletion of your server-side data by writing to the address below. Local data is already fully under your control.
Changes
We will announce material changes in the app. The effective date of the current version is at the top of this document.