PaperWeight

Privacy Policy

Last updated 2026-08-13

PaperWeight is a screen-time app that runs on your device. It has no account, no server of its own, and no analytics. This policy describes what it stores, where that data goes, and the one case where something leaves your phone.

What we collect

Nothing. PaperWeight does not collect data about you, does not track you across apps or websites, and contains no advertising, analytics or crash-reporting software. Its App Store privacy manifest declares no tracking, no tracking domains and no collected data types.

There is no account to create and no way to sign in, so there is nothing that identifies you to us.

What is stored on your device

PaperWeight keeps its own working data in your device's app storage:

  • Policies — the apps, categories and web domains a policy controls
  • Keys — a record of each key you have added, including where it came from (QR code, bar code, NFC chip, photo, or generated in the app)
  • Schedules — the recurring windows that start a session automatically
  • Session state — whether a session is running, which policy it uses, and when it ends
  • Preferences and onboarding flags — including which tips you have seen

Key payloads are hashed, not stored as scanned. PaperWeight keeps a hash of each key so it can recognise the right key when you present it again; the code itself is not kept in readable form.

App and category selections are made through Apple's own Screen Time picker. What comes back to PaperWeight is an opaque token, not a list of app names — the app enforces your selection without being able to read what you picked.

Diagnostic log

PaperWeight writes a local diagnostic log to help work out what went wrong when something misbehaves. It lives in the app's own storage, entries older than seven days are deleted automatically, and it is only ever shared if you choose to export it yourself from Settings. Nothing is uploaded.

iCloud sync

iCloud sync is on by default. When it is on, your policies, keys and schedules sync through your own iCloud account, in Apple's private database for this app. That data is tied to your Apple Account — we cannot see it, and neither can anyone else you have not shared your Apple Account with.

Some data never syncs at all. PaperWeight keeps two separate stores, and the local one is excluded from iCloud regardless of this setting.

You can turn sync off in Settings › Data › iCloud Sync. The change takes effect the next time the app launches.

Device permissions

PaperWeight asks for a permission only at the point a feature needs it, and every one of these is used on the device:

Permission Used for
Screen Time Enforcing your policies. Without it, nothing can be blocked.
Camera Scanning a QR code or bar code as a key.
NFC Reading a physical key tag.
Microphone Measuring how loud the room is during an emergency unlock. Audio is metered, never recorded or saved.
Location Confirming you have moved far enough during an emergency unlock. Used to compute a distance, not stored as a location history.
Motion Detecting the phone being flipped during an emergency unlock.
Notifications Alerts when sessions start and end.

The microphone, location and motion permissions are only ever requested if you choose the emergency-unlock method that needs one.

Other Vernacular apps on your device

PaperWeight shares a storage container with the other apps in the Vernacular family so they can work together — for example, so another app can ask PaperWeight to start a focus session. Summaries of your keys and policies are readable by those apps when they are installed on the same device. This never leaves the device, and it involves no other company.

The one thing that leaves your device

If a policy blocks web domains, PaperWeight fetches each domain's icon so the list is readable at a glance. It asks the site itself, over HTTPS, at the standard locations a site publishes its icon (/apple-touch-icon.png and /favicon.ico, on the domain and its www. variant).

This means your device connects directly to the sites you have chosen to block. Those sites can see that a device at your IP address asked for their icon, the same as any browser fetching a page would. The request carries no account, no identifier, and nothing about your keys, schedules or sessions — and your list of blocked domains is never sent anywhere as a list. Nobody but the site itself is contacted: no favicon service, no third party, no server of ours.

If that trade is not one you want to make, switch off Fetch site icons in that policy's Advanced settings: its domains show a plain globe and no request is ever made for them.

Third-party code

PaperWeight uses two open-source libraries to generate and read QR codes. Both run entirely on your device and neither collects data. There are no advertising, analytics, attribution or crash-reporting services in the app.

Your choices

  • Turn off iCloud sync — Settings › Data › iCloud Sync.
  • Delete everything — Settings › Data › Delete All Data removes every policy, key, schedule, log file and onboarding flag from the device, and resets the app to a clean install. If iCloud sync is on, the same data is removed from your other devices too. This cannot be undone.
  • Withdraw a permission — any of the permissions above can be revoked in the iOS Settings app. Revoking Screen Time access stops PaperWeight being able to block anything.
  • Delete the app — removes its local data with it. If iCloud sync was on, use Delete All Data first, otherwise the synced copy remains in your iCloud account.

Children

PaperWeight is a general-purpose productivity app. It is not directed at children and collects nothing from anyone.

Changes

If this policy changes, the date at the top of this page changes with it.

Contact

Questions about this policy: [email protected]

PrivacyTerms

© 2026 PaperWeight