SYE - Save Your Eyes
Download
Privacy Policy

Your Privacy, Respected.

Effective date: April 2025 · Version 2.0 · Governed by Australian law

1Who We Are

SYE is developed and operated by an independent developer based in Australia. The app is available on the Apple App Store and is maintained as a privacy-first digital wellbeing tool.

Contact: support@getsye.com. Website: getsye.com.

Because the developer is based in Australia, this policy is governed by the Australian Privacy Act 1988 (Cth). Where users are located in the European Economic Area or United Kingdom, GDPR and UK GDPR also apply and additional rights are described in Section 10.

2The Short Version

SYE does not sell your data. Ever.

SYE does not run ads. There are no advertising SDKs.

Screen Time and app blocking data never leaves your device — it is processed entirely by Apple's frameworks.

We store your account info (email, sign-in method, onboarding answers) on Supabase servers to let your settings persist across reinstalls.

We send local notifications (blink reminders) — these never leave your device.

We do not use Google Analytics, Firebase Analytics, Mixpanel, Amplitude, or any equivalent.

3What Data We Collect

Data Type Where It Lives Why We Collect It How Long We Keep It
Apple ID / Google account email Supabase (encrypted at rest) Account identity Until account deleted
Sign-in provider (Apple / Google) Supabase Know how you authenticated Until account deleted
Onboarding answers (how you found SYE, what brings you) Supabase users table Personalise future content Until account deleted
Screen Time usage data On-device only (Apple frameworks) Never stored by us
Power usage reports inside the app On-device only Never stored by us
App selections for blocking On-device only (ManagedSettings) Configure which apps are blocked Never stored by us
Block schedules On-device App Group (group.com.company.sye) Persist schedules across app kills On-device, cleared on uninstall
Blink reminder notification schedule On-device only Send local reminders Never sent to servers
Device locale / timezone On-device only Schedule content correctly Never stored by us
Crash logs Apple (if you have Share Analytics enabled in iOS Settings) Debug crashes Controlled by Apple's privacy policy

SYE never accesses your camera, microphone, contacts, location, photos, or health data.

4Screen Time Data

SYE uses Apple's FamilyControls, ManagedSettings, and DeviceActivity frameworks to provide its core screen time and app blocking features. These frameworks are sandboxed by Apple, which means the developer cannot read which specific apps you use or how long you spend in them through a server.

The screen time report shown inside the app is rendered by Apple's own DeviceActivityReport view extension. That report runs in a separate process controlled by Apple, and its data is not available to SYE.

App blocking features, including Quick Blocks, Soft Interruptions, and Block Scheduling, work by passing app tokens to ManagedSettingsStore. These tokens are opaque identifiers that only Apple can resolve, and they do not reveal app names or usage details to the developer.

None of this data is transmitted to Supabase or any server. Screen time data remains on-device and is governed by Apple's operating system privacy protections.

Screen Time data is the most sensitive data on your device. SYE is architecturally prevented from reading or transmitting it — not just by policy, but by Apple's OS-level sandbox.

5How We Use Your Data

  • Authenticate your account and maintain your session.
  • Store your onboarding preferences so the app can personalise content in future updates.
  • Deliver remote content (daily quotes, eye health tips, blog posts) from Supabase — this content is the same for all users, it is not personalised based on your usage.
  • Send local blink reminder notifications at intervals you set — processed entirely on-device.
  • Improve the app based on aggregate, non-identifiable patterns (e.g. if the Supabase fetch fails, we see an error count — not who failed).

6Third-Party Services

Supabase (supabase.com)

What it does: Provides authentication (Apple/Google OAuth relay), stores the users table, serves the quotes, eye_health_tips, and blog_posts tables.

Data sent to Supabase: Email, sign-in provider, onboarding answers.

Data NOT sent: Screen Time data, app selections, block schedules, notification settings.

Supabase's infrastructure is hosted on AWS. Supabase is SOC 2 Type II certified.

Supabase Privacy Policy: supabase.com/privacy

Apple Sign-In

When you sign in with Apple, Apple authenticates you and passes a user identifier and optionally an email to SYE. Apple may provide a private relay email address — SYE stores whatever Apple provides. Apple’s privacy policy governs what Apple does before passing data to us.

Apple Privacy Policy: apple.com/privacy

Google Sign-In (googleapis.com)

When you sign in with Google, Google authenticates you and passes your email and a user identifier to SYE via Supabase's OAuth relay. Google's privacy policy governs what Google does during sign-in.

Google Privacy Policy: policies.google.com/privacy

Apple DeviceActivity / ManagedSettings / FamilyControls

These are Apple system frameworks. All data stays on-device and is governed by Apple's privacy policy.

We do not use Facebook SDK, Google Analytics, Firebase, Crashlytics, Mixpanel, Amplitude, Sentry, Datadog, or any other analytics or advertising SDK.

7Data Storage and Security

  • Supabase data is encrypted at rest using AES-256 and in transit using TLS 1.3.
  • Row Level Security (RLS) is enforced — your row in the users table can only be read and written by a session authenticated as you.
  • On-device data is stored in the iOS App Group container, protected by iOS Data Protection (encrypted when device is locked).
  • We do not store passwords — authentication is entirely delegated to Apple and Google.
  • The developer does not have direct access to individual user rows — Supabase admin access is restricted to the developer account and is protected by MFA.

8Data Retention and Deletion

Your account data is retained until you delete your account.

To delete your account: go to Settings inside SYE → Delete Account, or email support@getsye.com with the subject "Delete My Account" and we will delete it within 30 days.

On-device data (App Group, UserDefaults) is automatically deleted when you uninstall the app.

Cached remote content (quotes, tips, blog posts) is stored in UserDefaults and cleared on uninstall.

We do not keep backups of deleted user data beyond 90 days (Supabase's standard backup window).

9Children's Privacy

SYE is intended for users aged 13 and over. The app is designed to be used by adults to manage their own screen time, or by parents to manage their family's screen time.

We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact support@getsye.com and we will delete it within 7 days.

For users aged 13–17, we recommend a parent or guardian review this policy.

10Your Rights

Australian Privacy Act rights

  • Right to access the personal information we hold about you.
  • Right to correct inaccurate information.
  • Right to complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

GDPR / UK GDPR rights (EEA and UK users)

  • Right of access (Article 15).
  • Right to rectification (Article 16).
  • Right to erasure / "right to be forgotten" (Article 17).
  • Right to restrict processing (Article 18).
  • Right to data portability (Article 20).
  • Right to object (Article 21).
  • Right to lodge a complaint with your local supervisory authority.

Legal basis for processing: contract performance (account management) and legitimate interests (content delivery, app improvement).

To exercise any right: email support@getsye.com — we will respond within 30 days.

11Changes to This Policy

We may update this policy from time to time. When we make material changes we will update the effective date at the top of this document. For significant changes affecting your rights, we will show a notice inside the app. Continued use after changes take effect constitutes acceptance.

12Contact

Contact

Email: support@getsye.com

Website: getsye.com

We aim to respond to all privacy enquiries within 5 business days.