Privacy

What we keep, and what we never see.

This is the plain-language version. Formal terms will be published before the app launches.

On the waiting list

  • Your email address, and whether you signed up to be blocked or to hold a key.
  • Your referral code, and the code of whoever invited you, if anyone did.
  • Your keyholder’s email, only if you choose to give it to us.
  • Where you came from: the referring page and any campaign tags (utm_*) in the link.
  • One cookie, sk_ref, remembers an invite link for 30 days. Your browser also keeps your place in line (so the page shows you’re in), and PostHog keeps an anonymous visitor ID when analytics are on. None of it is used for advertising.

In the app

  • Your display name and time zone, and who you are paired with.
  • Your schedules: days, hours, strictness, and the apps you chose. On iPhone the choice is an opaque token from Apple — we can’t see which apps it means. On Android it’s the list of app package names you picked.
  • Unlock requests: the length, the reason you typed, and your keyholder’s answer.
  • Block sessions and bypass alerts: when a block started and ended, and whether a protection was switched off.
  • A push-notification token for each of your phones, so requests and answers can reach you.

Never

  • Your messages, photos, browsing, or what you watch or read inside any app.
  • How long you spend in apps outside your schedules.
  • Selling or sharing your data for advertising.

Who sees what

  • Your keyholder sees your requests, their answers, bypass alerts and your weekly tally — nothing else.
  • Data is stored with Supabase. Product analytics use PostHog, without advertising identifiers.
  • Ask us to delete everything at any time; the app will also have a delete-account button.

Questions, or a deletion request: hello@secondkey.link. Last updated 2026-09-25.