Privacy, plainly

Effective date: September 14, 2026

The Amish App is built on a promise: your Kin see your requests — never your activity. A privacy policy is where that promise gets written down carefully. Here is ours, in plain language — the whole of it, including the parts most policies leave out.

Who we are

The Amish App ("we," "us") makes kin controls for your phone — boundaries you choose, held by a few people who love you. Questions about anything on this page can go straight to a person: hello@theamishapp.com.

What stays on your phone

Your screen-time usage, your browsing, and your app activity stay on your device. This isn't just a policy choice — it's how Apple's Screen Time framework works. The operating system keeps usage data inside a sandbox that our app cannot read out, export, or send anywhere, and our servers have no endpoint that would accept it. We couldn't build activity reports for your Kin even if we wanted to. We don't want to.

What the operating system will not let us see, we cannot store: the apps and websites your rule points at are held by iOS as opaque tokens that mean nothing outside your phone. Those tokens never travel, so even the part of your rule we do keep can't be turned back into a list of the apps you limit.

Your Rule of Life itself — the categories you chose, the time budgets, the night and Sabbath windows — is backed up to our servers so that losing your phone doesn't mean losing the rule you wrote. We changed this deliberately: an earlier version of this page said your rule never left your phone, and that was true until we found people rebuilding a carefully considered rule from memory after replacing a handset. You can read what we hold and delete it with your account at any time. When you ask your Kin to approve a change, what still travels to them is only a short description of the change in your words — never the configuration itself.

What we store

Some things have to travel — your Kin can't answer a request that never reaches them, or read a message you never sent. Here is everything our servers hold:

What your Kin see

Your Kin see what you send them and the state of the promise you share — never a log of your activity:

Who holds the data

Two companies process data on our behalf, and only these two:

The steward's access

Someone has to keep the lights on. The operator of the service has an admin panel that can list accounts — display names, sign-up dates, cooldowns, and counts of devices and Kin — and can correct a display name. And because the database is not end-to-end encrypted, the operator could technically read stored content, messages included. We don't browse it; that access exists for running and repairing the service. We mention it because internal access is exactly the kind of thing privacy pages tend to leave out.

What we never do

Keeping, leaving, and deleting

While your account exists, we keep the records above — the shared history of asks, answers, and messages stays intact for as long as the covenant does. Leaving the app is designed to be a door, not a wall: when you depart, your covenant record closes; it isn't weaponized, published, or held over you.

Deleting is stronger than leaving, and you can do it yourself, inside the app: Account → Delete my account. It takes effect immediately. Everything you wrote and everything that identifies you — your identity, devices, Kin ties, asks, messages, notes, and your stored Rule of Life — is actually deleted from our database, not flagged and kept; where your name appeared in someone else's history, the reference is blanked so their record keeps its shape without you in it. Deleting also asks Apple to disconnect the app from your Apple ID. Your Kin aren't notified — you're simply gone, which is the deletion working.

Two honest footnotes. Deletion can't reach into other people's phones: notifications already delivered to your Kin's devices stay on their devices. And a small amount of operational data survives for security — the steward login records above, and the short-lived service logs our hosting provider keeps.

If you want a copy of your data first, email us and a person will assemble an export by hand — there's no button for that yet, so it takes days, not seconds. And if you'd rather have a person handle anything on this page, the inbox is read by one: hello@theamishapp.com.

The early-access list

If you signed up on this website, we hold exactly three things: your email address, whether your interest is for yourself or for a community, and when you signed up — stored with Cloudflare (in Workers KV). We use it for exactly one thing: writing to you about early access. No newsletters you didn't ask for, no sharing with anyone else. If you'd like off the list, email us and we'll delete your entry.

Children

The Amish App is for adults — people eighteen and older choosing their own accountability. It is not a parental-control product and is not directed at children under thirteen. If you believe a child has given us personal information, email us and we'll delete it.

Changes to this policy

We'll update this page as the product grows. When we make meaningful changes, we'll update the effective date above, and if you're on our list for the app, we'll tell you directly. We won't quietly loosen a promise.

Requests, never activity. That's the whole policy, really — the rest is detail.