Privacy Policy
The short version
AVOW is built so that we never see your camera data. The camera is used on your device to answer two questions: are you present, and is a handheld device (like a phone) visible in your hands? Each answer is a simple yes or no. The microphone is used only if you choose to record a personal alarm, and recordings never leave your phone. No video, images, audio, or face data are ever uploaded. There are no analytics trackers and no ads. Accounts are optional: without one, no personal data is sent to us at all; with one, only your profile details and aggregate session numbers sync, as described below. Community leaderboards are opt in and verification based: joining a regional board reads your device location once, with your permission, and stores only a coarse region, never your coordinates; school and company boards use a verified email or an admin approval. Purchases are processed by Apple and RevenueCat, as described in the Purchases section below.
Camera processing
While a session is running, AVOW analyzes the front camera feed in real time, entirely on your device, to detect whether a person is present. Frames are processed in memory and immediately discarded. AVOW does not record, store, screenshot, or upload any video or images. It does not identify who is in front of the camera, does not perform facial recognition, and does not create biometric templates; it only determines whether someone is present.
If distraction detection is enabled (it is on by default and can be turned off in Settings), the same analysis on your device also checks whether a handheld device such as a phone is visible and actively in use in the frame. This produces only a yes/no "distracted" signal and a running total of distracted time. It cannot read your phone's screen and does not know what you are doing on it.
All presence and distraction math (focus totals, timelines, streaks) is computed locally on your device from those yes/no signals.
Depending on your app version, detection model files (face and object models) are either bundled with the app or downloaded from a content delivery network the first time detection runs, like any app resource. Your camera data is never sent anywhere in either case; processing happens strictly on your device. There is no cloud camera processing and no secret monitoring: detection runs only during a session you started, with the session screen visible.
Microphone and personal alarm recordings
AVOW uses the microphone only when you choose to record a personal alarm. Your recordings remain on your device unless you explicitly share them.
Microphone permission is requested only at the moment you tap record, never at install, onboarding, or session start. If you never record a personal alarm, AVOW never accesses the microphone at all.
Recordings (up to 30 seconds) are saved into AVOW's private storage on your phone. They are never uploaded, transmitted, analyzed, or used for anything other than playing your alarm. You can rename or delete them at any time in the Alarm Library, and deleting the app removes them permanently.
Imported audio files
If you import an audio file as an alarm, AVOW copies that file into its private local storage. Imported audio is never uploaded and is used only to play your alarm. You are responsible for having the rights to audio you import. You can delete imported audio at any time in the Alarm Library.
Voice alarms (spoken by your device)
Voice alarm phrases are spoken by your device's own speech engine, on the device, at the moment the alarm plays. No audio is generated on or sent to any server.
Data stored on your device
Your session history (durations, focus percentages, departure counts, distraction time and counts, session timelines, optional session names), settings, streaks, onboarding state, free session counter, personal alarm recordings, and imported alarm audio are stored locally on your phone. This data never leaves your device and is deleted when you delete the app. You can also delete individual sessions, your entire history, or individual alarm recordings inside the app at any time.
Optional accounts and cloud sync
You can use every core feature of AVOW without an account. If you choose to create one (to use friends, teams, groups, or leaderboards), signing in is handled by Clerk, our authentication provider, which processes your email address to create and secure the account. We store the profile you enter: a handle and a display name, plus your choices for stats visibility and leaderboard participation. Region, school, and company are not profile fields you type: they exist only through the verification flows described below, and you can remove them at any time.
With an account, AVOW also syncs aggregate numbers from your completed sessions: the mode, start and end times, totals for focused, away, distracted, and monitored time, focus percentage, and outcome. These are the only session facts that leave your phone. Camera frames, video, images, audio, alarm recordings, detailed session timelines, and session names are never uploaded, with or without an account.
Community features and leaderboards
Friends, teams, groups, and leaderboards are optional. Your aggregate stats are visible to accepted friends and to fellow members of teams and groups you join. Public leaderboards are strictly optional: you appear only if you turn on leaderboard participation, and you can turn it off at any time. You can block other users; blocked users cannot see you in search, friends, or boards, and you cannot see them.
Viewing a board never joins you to it or changes your profile. Regional, school, and company boards show coarse region names and verified affiliations at most, never addresses or coordinates, and identifiable ranking rows appear only once a board has at least 5 opted in participants.
Location verification (optional)
Regional leaderboards are joined only through explicit location verification. If you choose to verify, AVOW asks for location permission and reads your device location once, at that moment. The coordinates are sent over an encrypted connection to our server, which resolves them into a coarse region: your country, plus your state or province and county or city where available. Only those region names are stored, together with the verification date. Your precise coordinates are not stored anywhere; they are used to resolve the region and immediately discarded.
AVOW never tracks your location in the background, never requests always on location access, and never uses your location for advertising or profiling. You can remove your verified region at any time in Account, which deletes the stored region names. To keep regions honest, you can update your region at most once every 7 days.
School and company verification (optional)
School leaderboards use a curated school directory and email verification. To join a school community, you enter an email address at that school's domain; Clerk, our authentication provider, sends a code to that address and keeps the verified email with your account. We store the membership itself (the school, the dates, and the email domain that proved it) plus a cryptographic hash of the verified address, which prevents one school inbox from verifying more than one AVOW account. The address itself is never written into our community records. School verification expires after 365 days; verifying again extends it.
Company communities work in one of two ways: an admin of that company's AVOW community approves your request to join, or you claim membership with a work email at a domain registered for that company, using the same code flow as schools. Either way, AVOW verifies only that you control a matching email address or that an admin approved you; AVOW does not verify employment and never contacts employers. After leaving a company community there is a 7 day wait before you can rejoin it.
If your school or company is missing from the directory, you can submit a request with its name, website, and context. Requests are reviewed before anything becomes public; submitting one stores those details with your account and never creates a public leaderboard by itself.
Reports and moderation
If you report another user, we store the report: who filed it, the reported handle at the time, the reason, and an optional note. Reports are used only for safety review. Reports that reference an account may be kept for moderation purposes even after that account is deleted.
Account deletion
You can delete your account inside the app at any time (Account, then Delete account). This immediately and permanently removes your cloud data: profile, synced session aggregates, stats, friendships, blocks, invites, and team and group memberships. Reports you filed are removed as well; reports other users filed that reference you may be retained as described above. Your local data on the phone is not affected by account deletion, and you can keep using AVOW without an account afterwards.
AVOW Desktop (optional companion)
AVOW Desktop is a separate, optional app for Mac and Windows built on the same privacy design. During a session it uses your computer's webcam, locally, to answer the same yes/no questions (are you present, and is a phone visibly in use) and can treat keyboard and mouse inactivity (idle time) as not working.
If you enable app awareness, AVOW Desktop checks the name of the frontmost app against your own distraction list; with the optional browser extension installed, it also checks the address of the active browser tab. These checks happen entirely on your computer and produce only "distracting or not" signals. AVOW Desktop never records your screen, never logs keystrokes, has no remote access, and does no hidden monitoring; nothing runs unless you started a session, and all data stays on your computer.
Purchases
Subscriptions are processed by Apple through your Apple ID. To manage subscription state, AVOW uses RevenueCat, a subscription management service, which receives App Store purchase information (such as receipts and subscription status) tied to an anonymous identifier generated by the app. We do not receive your name, email address, or payment details.
Data we collect
Without an account: almost none. AVOW has no analytics SDKs and no advertising SDKs, and the only data processing is purchases, as described above. With an optional account: your email address and any verification emails you add (processed by Clerk), the handle and display name you enter, the verified affiliations described above (coarse region names, school membership, company membership), and the aggregate session numbers described in the cloud sync section. Nothing else, and never camera, video, image, audio, or precise location data.
Children
AVOW is a work and study tool suitable for general audiences and does not knowingly collect personal information from anyone, including children.
Your choices
You can revoke camera access at any time in iOS Settings (AVOW cannot run sessions without it). Microphone access is optional and only needed to record personal alarms; you can revoke it and keep using everything else. Location access is optional and used only at the moment you choose to verify your region; you can revoke it in iOS Settings and keep using everything else, and you can remove a verified region, school, or company inside the app at any time. You can delete your history and recordings in the app, or remove all local data by deleting the app. If you created an account, you can delete it inside the app at any time, which removes your cloud data as described above.
Changes to this policy
If we change this policy, the updated version will be posted at this address and inside the app with a new effective date. Material changes will be highlighted in the app.
Contact
Questions about privacy: ahmedkhalafalla@hotmail.com