Privacy policy
Last updated 19 August 2026
The short version. Scrappy has no account, no sign up, and no server of ours anywhere. There is no analytics and no tracking of any kind. Your screen time never leaves your iPhone. The one thing that does leave is your purchase, which goes to our subscription provider under an anonymous id, purely so the app knows you are subscribed.
This policy explains how the Scrappy iPhone app ("Scrappy", "the app") and this website handle information. Both are provided by Scrappy ("we", "us"), based in India. We are the data fiduciary for the purposes of India's Digital Personal Data Protection Act, 2023, and the data controller for the purposes of UK and EU data protection law.
1. Information we collect
Nothing that identifies you. There is no account, so we never ask for and never receive your name, email address, phone number, date of birth, contacts, location, photographs or payment details. We run no server of our own and keep no database of users. We could not pick a single person who uses Scrappy out of a crowd.
One thing does leave your phone, and it is your purchase. Section 6 sets out exactly what that involves and what it does not. Everything else described in this policy stays on your device.
2. Information the app stores on your phone
Scrappy needs to remember things in order to work. All of it is written to storage that belongs to the app on your device, and none of it is readable by us or by other apps:
- The rules you create, and which apps or categories each rule guards.
- How many times you tried to open a guarded app, and when.
- Your treat balance, walks completed and streaks.
- Your settings and preferences, including whether the removal lock is on.
- Whether you have a Pro subscription, so the app knows what to unlock.
This is kept in your app's private container and in a shared container used by Scrappy's own Screen Time extensions. It is included in your device backup if you back your iPhone up to iCloud or a computer, in the same way every app's data is. That backup is controlled by Apple and by you, not by us.
3. Screen Time data
Scrappy uses Apple's Screen Time frameworks, Family Controls, Device Activity and Managed Settings, to see your usage and to shut apps. This deserves a plain explanation because it sounds alarming and is not.
When you choose apps to guard, iOS hands Scrappy an opaque token for each one rather than its name. The app cannot read your full app list, cannot tell what most of those tokens refer to, and cannot export them anywhere meaningful. Your usage figures are drawn on screen by a sandboxed Apple extension that the operating system deliberately prevents from making network requests. Apple designed it this way so that apps like Scrappy can be useful without ever seeing your data. The numbers you see in Scrappy are rendered on your phone and stay there.
You grant this access explicitly through an Apple system prompt, and you can revoke it at any time in Settings on your iPhone.
4. Health and motion data
Treats are earned by walking, so Scrappy needs to count steps. With your permission it reads your step count from Apple Health and from the motion coprocessor in your iPhone. It reads this figure only, it reads it only on your device, and it never writes anything back to Health.
Your step count is used to work out whether you have earned a treat and for nothing else. It is not stored beyond what the app needs to track today's progress, and it is never transmitted. If you decline this permission, Scrappy still works, and you can earn treats by completing walk sessions instead.
5. Notifications and Live Activities
Scrappy can send notifications and show a Live Activity on your lock screen while a walk is running. These are scheduled and drawn locally by your phone. There is no push server, so no notification content ever passes through us.
6. Purchases
Subscriptions and the lifetime unlock are sold and paid for through Apple's App Store. Apple handles the money. We never see your payment details, your Apple Account, your billing address or your name, and Apple's own privacy policy governs that part.
To know whether your subscription is still active, Scrappy uses RevenueCat, a subscription management service. When you buy, restore or renew, RevenueCat receives the App Store transaction and an anonymous identifier that RevenueCat itself generates. It exists to answer one question: is this person subscribed.
Nothing else travels with it. No screen time figures, no list of the apps you guard, no rules, no step counts, and nothing you have typed. The identifier is not your name, your email or your device's advertising id, it is not linked to your identity, and it is not used to track you across other apps or websites.
RevenueCat processes this in the United States, so if you are elsewhere your purchase record is transferred there. This is the only transfer of any kind that Scrappy makes.
7. Advertising measurement
If we advertise Scrappy, we need to know whether the advertising worked. Scrappy uses Apple's AdAttributionKit and SKAdNetwork for this. It is worth being precise about what that does, because it sounds worse than it is.
The app registers a single number between 0 and 3, meaning installed, finished onboarding, started a trial, or subscribed. Your iPhone's operating system, not the app, may later send that number to the advertising network that showed you the ad. Apple designed these frameworks so that the postback carries no identifier for you or your device, is delayed and aggregated, and cannot be tied back to an individual. We receive counts, never people.
This is not tracking as the App Store defines it. Scrappy does not use the Advertising Identifier, does not ask for App Tracking Transparency permission, and does not link anything to your identity.
8. What Scrappy does not do
- No analytics service of any kind. There is no Firebase, no Amplitude, no Mixpanel, no crash reporter and no session recording.
- No third party software development kits other than RevenueCat, which sees only what section 6 describes.
- No advertising inside the app.
- No selling or renting of personal information, and no sharing of it beyond the single purpose in section 6.
- No cookies on this website, and no visitor analytics.
9. Children
Scrappy is not directed at children under 13 and we do not knowingly collect information from anyone, of any age. Because the app requires no account and collects nothing that identifies a person, there is no children's data for us to hold, disclose or delete.
10. Your rights and your control
Data protection law gives you rights to access, correct, export, delete and restrict the use of your personal information. We hold nothing that identifies you, so in almost every case there is nothing for us to hand over or erase. If you want the purchase record described in section 6 dealt with, write to us and we will ask RevenueCat to delete it.
Everything Scrappy knows lives on your phone and is under your control:
- Deleting the app removes all of its data from your device permanently.
- Screen Time access can be withdrawn in the Settings app.
- Health access can be withdrawn in Settings or in the Health app.
- Notification permission can be withdrawn in Settings.
One note on deletion: if you have turned the removal lock on, uninstalling Scrappy takes a day by design, so that a bad evening cannot undo a good decision. You are never permanently stuck, and the delay applies to the app itself, never to your data rights.
11. Data retention and transfers
What is on your phone stays there until you delete the app, and then it is gone. The purchase record described in section 6 is held by RevenueCat for as long as it is needed to tell the app whether you are subscribed, and is processed in the United States. That is the only international transfer, because it is the only data that leaves.
12. Changes to this policy
If Scrappy ever starts collecting something, this page will say so clearly and in advance, the date at the top will change, and the app's App Store privacy label will be updated to match. We will not quietly add analytics to a future version and leave this page as it is.
13. Contact
Questions about privacy, or about anything else, go to [email protected] and a person will answer.
If you believe we have handled your information improperly, you can complain to a regulator. In India that is the Data Protection Board of India. In the UK or the EU it is your local supervisory authority.