Privacy Policy
KeyBond ("we", "us") is a screen-time lock operated by WaveApp LLC. This policy describes what we collect, why, and who processes it. KeyBond is a productivity tool. We do not provide medical advice, and we do not collect health data.
What we collect
- Account contact: your email (sign-in via magic link). If you invite a keyholder by SMS, their phone number for that invite.
- Display names: your name and an optional keyholder display name.
- Keyholder asks: duration you request and an optional one-way reason note. Reasons are kept only for the life of the request and deleted within 30 days after it is answered.
- Bond metadata: whether a keyholder bond is pending, active, or ended; invite and ask lifecycle timestamps.
- Schedule metadata: time windows and a policy revision number. We do not store which apps you selected.
- Protection status: whether protection is active, revoked, or unconfirmed when the app reports that, plus a closed-set cause when known.
- Entitlement status: subscription / trial state from the store via RevenueCat.
- Product analytics: only after a separate opt-in, a closed list of anonymous interaction events (no app names, IDs, free text reasons, schedules, or contacts).
- Crash diagnostics: only after a separate opt-in, a closed failure category and runtime tag; no user identity, app selection, request payload, raw exception message, replay, screenshots, or breadcrumbs.
- Subscription identifier used by RevenueCat for entitlement mapping; it is never used as analytics or diagnostic identity.
What never leaves the device
App identity does not leave the device. On iOS, system selections are opaque tokens. On Android, package names for blocked apps stay on the device only and are never uploaded. The holder pages, email, and SMS show duration and reason only — never which apps, screen time, or history.
Why we collect it
- Provide the product: magic-link sign-in, keyholder invites, unlock asks, timed grants, emergency and protection-status notices.
- Process subscriptions and restore purchases.
- Measure product health with minimal analytics (no shame metrics, no health scoring).
Processors (service providers)
We use these processors under contract; they process data on our behalf and are not "sold" or "shared" for advertising under Google Play's definition:
- Resend — transactional email (sign-in links, keyholder invites, unlock asks, account notices).
- PostHog — product analytics after opt-in (autocapture, lifecycle, screen tracking, session replay, logs, surveys, feature flags, and person profiles are off).
- Crash diagnostics provider — optional diagnostics after a separate opt-in; replay, screenshots, breadcrumbs, tracing, profiling, attachments, user/IP collection, and request collection are off.
- RevenueCat — subscription entitlement verification with Apple App Store and Google Play.
SMS delivery, if enabled for invites/asks, uses a KeyBond-configured messaging provider with the minimum fields needed to deliver the message.
What keyholders see
Keyholders open a one-time link. They see: how long you asked for, your optional reason, how often you ask (aggregate), and your display name. They never see app names, screen time, or history. Their reply is grant/deny (and duration for grants) — not free-text chat.
Retention and deletion
- Ask reason text: deleted within 30 days after the ask is answered.
- Magic-link raw tokens: never stored; only a hash is kept until use or expiry.
- Account deletion: available in the app and via /delete-account (public entry that hands off to the product deletion flow). After confirmation we delete account data, bonds, tokens, and provider mappings. Some payment records may be retained as required by tax or store rules.
Security
Traffic uses TLS. High-risk actions use request IDs, idempotency keys, and CSRF protection on web POSTs. Holder contacts are encrypted at rest with keys separated from the database.
Children
KeyBond is not directed at children under 13. Do not create an account for a child under 13.
Contact
Privacy questions: [email protected] Support: [email protected] Operator: WaveApp LLC
Changes
We will update this page and the "Last updated" date when the policy changes.
Last updated: 2026-08-03