Privacy, plainly
Effective date: September 14, 2026
The Amish App is built on a promise: your Kin see your requests — never your activity. A privacy policy is where that promise gets written down carefully. Here is ours, in plain language — the whole of it, including the parts most policies leave out.
Who we are
The Amish App ("we," "us") makes kin controls for your phone — boundaries you choose, held by a few people who love you. Questions about anything on this page can go straight to a person: hello@theamishapp.com.
What stays on your phone
Your screen-time usage, your browsing, and your app activity stay on your device. This isn't just a policy choice — it's how Apple's Screen Time framework works. The operating system keeps usage data inside a sandbox that our app cannot read out, export, or send anywhere, and our servers have no endpoint that would accept it. We couldn't build activity reports for your Kin even if we wanted to. We don't want to.
What the operating system will not let us see, we cannot store: the apps and websites your rule points at are held by iOS as opaque tokens that mean nothing outside your phone. Those tokens never travel, so even the part of your rule we do keep can't be turned back into a list of the apps you limit.
Your Rule of Life itself — the categories you chose, the time budgets, the night and Sabbath windows — is backed up to our servers so that losing your phone doesn't mean losing the rule you wrote. We changed this deliberately: an earlier version of this page said your rule never left your phone, and that was true until we found people rebuilding a carefully considered rule from memory after replacing a handset. You can read what we hold and delete it with your account at any time. When you ask your Kin to approve a change, what still travels to them is only a short description of the change in your words — never the configuration itself.
What we store
Some things have to travel — your Kin can't answer a request that never reaches them, or read a message you never sent. Here is everything our servers hold:
- Account basics — your display name and your email address (if you use Apple's private relay, the relay address is all we ever see).
- Your Kin relationships — who is in your Kin, whose Kin you belong to, and the invite codes that formed those ties.
- Pass requests and responses — what you asked about (a category, or a specific app if that's what you named your rule after), the duration, any note you attached, and how your Kin answered — including the words they wrote if they declined.
- Messages between you and your Kin — the full text of what you write. Messages are stored in plain text on our servers; they are not end-to-end encrypted.
- Rule-change requests — the description of each change you asked your Kin to approve, and when you committed to your rule.
- Your Rule of Life — the categories and the tier you placed each in, your daily time budgets in minutes, your night and Sabbath window times, and any web-filter domains you added. This is the rule as you wrote it, not a record of you keeping it. It is kept so a new phone can restore it, and it is visible only to you — your Kin are never shown it.
- Departure notes — if you leave, the farewell note you write and your Kin's blessings on it.
- An enforcement heartbeat — whether enforcement is switched on, and when your phone last checked in. It's a single on-or-off signal, kept so your Kin can be told if you go quiet; it carries nothing about what you did on your phone.
- Device push tokens — the identifier Apple issues so we can deliver notifications to your phone.
- Steward login records — the IP address and outcome of each sign-in attempt to our own admin panel, kept for security.
What your Kin see
Your Kin see what you send them and the state of the promise you share — never a log of your activity:
- Your display name.
- Your pass requests — the label (a category, or a named app), the duration, and any note you attached.
- How each ask was answered, including any decline words.
- The messages you exchange.
- Rule-change requests, in your words.
- Your farewell note, if you depart.
- A gone-quiet alert if your phone stops checking in.
- A weekly digest computed from request metadata — how many passes you asked for — never from usage logs, because usage logs never leave your phone in the first place.
Who holds the data
Two companies process data on our behalf, and only these two:
- Cloudflare hosts everything — this website, our servers (Workers), the app's database (D1), and the early-access list (Workers KV). Every category above lives there.
- Apple — Sign in with Apple handles your login, and Apple's push service (APNs) delivers notifications. Push payloads pass through Apple's servers in transit and can carry display names, notes, and message bodies.
The steward's access
Someone has to keep the lights on. The operator of the service has an admin panel that can list accounts — display names, sign-up dates, cooldowns, and counts of devices and Kin — and can correct a display name. And because the database is not end-to-end encrypted, the operator could technically read stored content, messages included. We don't browse it; that access exists for running and repairing the service. We mention it because internal access is exactly the kind of thing privacy pages tend to leave out.
What we never do
- We never sell your data. Not to advertisers, not to data brokers, not to anyone.
- We never show ads.
- We never run third-party trackers or analytics — not in the app, not on this site. This page doesn't even fetch its typeface from someone else's servers; the fonts are served from our own domain.
- We never send your Kin your activity. They see what you send them — requests, notes, messages — and the list above is the complete list.
Keeping, leaving, and deleting
While your account exists, we keep the records above — the shared history of asks, answers, and messages stays intact for as long as the covenant does. Leaving the app is designed to be a door, not a wall: when you depart, your covenant record closes; it isn't weaponized, published, or held over you.
Deleting is stronger than leaving, and you can do it yourself, inside the app: Account → Delete my account. It takes effect immediately. Everything you wrote and everything that identifies you — your identity, devices, Kin ties, asks, messages, notes, and your stored Rule of Life — is actually deleted from our database, not flagged and kept; where your name appeared in someone else's history, the reference is blanked so their record keeps its shape without you in it. Deleting also asks Apple to disconnect the app from your Apple ID. Your Kin aren't notified — you're simply gone, which is the deletion working.
Two honest footnotes. Deletion can't reach into other people's phones: notifications already delivered to your Kin's devices stay on their devices. And a small amount of operational data survives for security — the steward login records above, and the short-lived service logs our hosting provider keeps.
If you want a copy of your data first, email us and a person will assemble an export by hand — there's no button for that yet, so it takes days, not seconds. And if you'd rather have a person handle anything on this page, the inbox is read by one: hello@theamishapp.com.
The early-access list
If you signed up on this website, we hold exactly three things: your email address, whether your interest is for yourself or for a community, and when you signed up — stored with Cloudflare (in Workers KV). We use it for exactly one thing: writing to you about early access. No newsletters you didn't ask for, no sharing with anyone else. If you'd like off the list, email us and we'll delete your entry.
Children
The Amish App is for adults — people eighteen and older choosing their own accountability. It is not a parental-control product and is not directed at children under thirteen. If you believe a child has given us personal information, email us and we'll delete it.
Changes to this policy
We'll update this page as the product grows. When we make meaningful changes, we'll update the effective date above, and if you're on our list for the app, we'll tell you directly. We won't quietly loosen a promise.
Requests, never activity. That's the whole policy, really — the rest is detail.