Privacy Policy (iOS)
Last updated: August 6, 2026
This Privacy Policy describes how the iOS Regain App (“Regain,” “the app,” “we,” “us,” or “our”) handles information when you install and use it on an Apple device. The Android version of Regain is covered by a separate Privacy Policy (Android).
1. General information
The data controller for this app is EpowerX Labs Private Limited, a private limited company registered in India with its registered office at Plot No. 77, JBR Tech Park, 6th Rd, Whitefield, EPIP Zone, Bengaluru, Karnataka 560066, India. EpowerX Labs Private Limited is the GDPR controller for any personal data processed in connection with this app.
For privacy, GDPR, or CCPA queries, contact privacy@regainapp.ai. For general support, contact help@regainapp.ai.
2. What the app does on iOS
Regain is an iOS focus app. The blocking feature uses Apple’s Screen Time API. The app does NOT require an account for core functionality. Signing in with Apple or Google is offered as an optional convenience — it links your Regain Pro subscription across your devices; see Section 4 (“Account authentication”) for what is collected only when you sign in. Regain also records anonymous product-usage events only if you opt in on first launch — see Section 4 (“Optional usage analytics”) for the full inventory and Section 5 for how to withdraw consent. Regain uses privacy-preserving ad-measurement SDKs (Meta App Events, Firebase Analytics, and Google Ads on-device conversion) as described in Section 4 (“Ad-measurement partners”); no Advertising Identifier (IDFA) is ever collected and the app never shows the AppTrackingTransparency prompt.
3. Screen Time API disclosure
Regain uses Apple's Screen Time technology (FamilyControls, DeviceActivity, and ManagedSettings frameworks) to block distracting apps and websites. This technology does not provide Regain or EpowerX Labs with the ability to read, collect, or modify the list of apps installed on the user’s device. The apps selected for blocking are identified by opaque tokens generated by Apple and stored on-device inside the app’s App Group (group.ai.regainapp.shared); these opaque tokens cannot be used by Regain, EpowerX Labs, or any third party to discover the name or identity of the apps.
4. Information collected on iOS
The following enumerates exactly what data is associated with the iOS app, and who is responsible for collecting each category. Most categories are collected by Apple or by RevenueCat (a third-party processor) rather than by Regain as a controller. Optional usage-analytics events, if you opt in, are received on Regain’s own self-hosted infrastructure — see Section 7 for the data-processor list and Section 14 for the CCPA categories.
- Focus session records. Start time, end time, completion status, and references to the on-device app-blocking tokens. Stored locally in an on-device SQLite database (managed by the GRDB library) inside the app sandbox. Never transmitted to Regain’s servers.
- RevenueCat-collected data. The RevenueCat SDK collects the following device-level information for subscription-state management: an anonymous app-user identifier (a UUID generated at first launch, NOT linked to email, name, or phone), Apple’s Identifier for Vendor (IDFV, a per-vendor device identifier that resets on full uninstall of all of that vendor’s apps), app version, iOS version, and country code. Purchase events (subscribe, renew, cancel, restore) are recorded against the anonymous identifier. These purchase events are the only events RevenueCat receives. RevenueCat’s complete collection list and retention rules are documented at revenuecat.com/privacy — Regain forwards users to that document for the canonical list because RevenueCat is the data processor for this category.
- App Store purchase receipt. Handled by Apple and validated by RevenueCat for entitlement state. Receipt contents are governed by Apple’s policies; Regain receives only entitlement metadata (active/inactive, product ID, expiry) from RevenueCat’s response.
- Server logs at
regainapp.ai. When the app fetches theme images via the on-device image-loading library, the origin server records standard HTTP access logs (IP address, user agent, requested path, timestamp). No cookies are set. Retention: 30 days. - App Store Connect analytics. Anonymized installation, session, and (when users opt in to share with developers) per-crash stack-trace data provided by Apple. Regain does NOT ship Sentry, does NOT ship Firebase Crashlytics, and does NOT use any other third-party crash-reporting SDK; this is the ONLY source of crash data Regain receives.
- Optional usage analytics. If you tap “Allow” on the first-launch consent alert, Regain sends anonymous events (which screens you view, when a session starts) tagged with a per-install UUID — not your name, email, Apple ID, IDFV, or advertising identifier — to self-hosted infrastructure in the EU. Used only to fix bugs and prioritize features. Tap “Not now” and nothing leaves your device.
- Account authentication (optional). If you choose to sign in with Apple or Google (Settings → Login, or when upgrading to Regain Pro), the identity provider returns your name, email address, and a stable per-provider account identifier (Apple sub or Google sub). Regain stores these on its own server, linked to your Regain account, for one purpose only: restoring your Pro subscription across your devices via RevenueCat. This data is never sold, is not shared with advertising networks, and is not used for analytics. Signing in is entirely optional — the free tier and core features work without it. You can permanently delete your account at any time from Settings → Delete Account; for Apple accounts this also revokes the Sign in with Apple grant via
appleid.apple.com/auth/revoke. - Ad-measurement partners. When you consent to analytics (see “Optional usage analytics” above), a subset of high-importance events (install, onboarding completed, subscription purchased) is also sent to Meta App Events and to Firebase Analytics / Google Ads for the sole purpose of ad-campaign conversion optimization. These events are tagged with pseudonymous app-install identifiers (Firebase instance ID, Meta app-install identifier), never with your name, email, Apple ID, or IDFA. Attribution runs through Apple’s SKAdNetwork and Meta’s Aggregated Event Measurement — both privacy-preserving frameworks that report aggregate campaign data without identifying individual users. If you decline analytics (or later withdraw consent in Settings → Privacy Corner), no events reach Meta or Google.
5. Withdrawing or granting analytics consent
The consent alert shown at first launch is the initial opt-in gate. You can change your answer at any time from Settings → Privacy Corner in the app.
6. What the app does NOT collect on iOS
Explicit negative inventory — the iOS Regain app does NOT collect any of the following:
- name and email — only collected if you explicitly choose to sign in (see Section 4, “Account authentication”), and only for the purpose of linking your subscription across devices. Users who never sign in never provide a name or email.
- phone — no phone number.
- postal address — no street, city, or postal-code data.
- IDFA / AppTrackingTransparency. The app does NOT use the AppTrackingTransparency framework, does NOT request the ATT prompt, and does NOT collect IDFA (Identifier for Advertisers).
- HealthKit data. The app does NOT use HealthKit, does NOT include HealthKit, and does NOT request HealthKit permissions.
- contacts — no access to the device address book.
- photos — no access to the photo library.
- location — no GPS, no Core Location, no IP-based geolocation lookup beyond standard country code routing.
- camera — no camera access.
- microphone — no microphone access.
- push notification token. The app does NOT register for remote notifications and does NOT send any push notification token to a server.
- third-party crash SDK. Regain does NOT ship Sentry, does NOT ship Crashlytics, does NOT ship Firebase Crashlytics, and does NOT use any equivalent third-party crash-reporting tool.
7. Data processors (third-party services we transmit data to)
Regain transmits data to the following third-party processors. Optional usage-analytics events (Section 4) additionally go to Regain’s own self-hosted infrastructure in the EU (not a third-party):
- RevenueCat (revenuecat.com/privacy) — Regain’s subscription-state and receipt-validation processor. Transmits the data described in Section 4 (“RevenueCat-collected data”).
- Apple (Sign in with Apple) (apple.com/legal/privacy) — identity provider if you choose to sign in with Apple. Returns your name, email, and Apple sub (per-app opaque identifier) to Regain.
- Google (Sign-In) (policies.google.com/privacy) — identity provider if you choose to sign in with Google. Returns your name, email, and Google sub (stable per-account identifier) to Regain.
- Meta (Facebook) App Events (facebook.com/privacy/policy) — ad-conversion optimization processor. Receives high-importance events (install, onboarding completed, purchase) only after you grant analytics consent. No IDFA is transmitted; attribution runs via Meta’s Aggregated Event Measurement.
- Google Firebase Analytics & Google Ads (firebase.google.com/support/privacy) — ad-conversion optimization processor. Receives the same high-importance event set as Meta, only after analytics consent. No IDFA is transmitted; attribution runs via Apple’s SKAdNetwork.
8. Open-source libraries (no data transmission to third parties)
The following open-source libraries execute on-device only. They are listed for transparency, not because they introduce a data-sharing relationship:
- Kingfisher — image-loading library; fetches from URLs the app passes it, which currently resolve only to
regainapp.aiorigins under Regain’s control. - Factory — dependency-injection framework; performs no network access of any kind.
- GRDB.swift — SQLite wrapper; reads and writes only the local on-device database file.
The following third-party SDKs do transmit data over the network — they are covered by the Section 7 processor list above and are only active after you grant the relevant consent:
- Facebook iOS SDK — Meta App Events transport (see Section 7); dormant with
FacebookAutoLogAppEventsEnabled=falseandFacebookAdvertiserIDCollectionEnabled=falsein Info.plist until analytics consent is granted. - Firebase iOS SDK & Google Ads on-device conversion SDK — Firebase Analytics → Google Ads transport (see Section 7); dormant with
FIREBASE_ANALYTICS_COLLECTION_ENABLED=falsein Info.plist until analytics consent is granted. - GoogleSignIn-iOS & Sign in with Apple (AuthenticationServices) — identity-provider transports (see Section 7); inactive unless you explicitly choose to sign in.
9. Subscriptions and purchases
iOS subscriptions and in-app purchases are managed by Apple’s App Store. You can cancel a subscription at any time via Apple ID Settings: https://apps.apple.com/account/subscriptions. To request a refund for an iOS purchase, visit Apple’s Report a Problem page: https://reportaproblem.apple.com. EpowerX Labs does not handle iOS payments and cannot issue refunds for iOS purchases directly.
10. Data retention
Local data (focus sessions, app-block tokens, settings) persists for the lifetime of the install on-device and is deleted automatically when the app is uninstalled. RevenueCat retains subscription data per its own policy linked in Section 7. Optional usage-analytics events are retained on Regain’s self-hosted infrastructure for up to 24 months, after which raw event rows are purged. Server access logs are retained for 30 days.
11. Security
All network traffic (RevenueCat API calls, image fetches, and analytics events when consented) is encrypted via TLS. On-device data is protected by the iOS app sandbox and App Group access control. Because there is no server-side user account, there is no password storage or authentication-credential risk for Regain to manage.
12. Children’s privacy (COPPA)
Regain is rated 4+ in the App Store age rating. The app does not knowingly collect data from children under 13. Signing in with Apple or Google is optional; users who do not sign in provide no identifiable data. Users who do sign in must be old enough to have an Apple ID or Google account, per those providers’ own age policies.
13. Rights of data subjects (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:
- Right of access — to confirm whether we process your personal data and obtain a copy.
- Right to rectification — to request correction of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) — to request deletion of your data.
- Right to restrict processing — to limit how we use your data.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object — to object to processing, and the right to lodge a complaint with your supervisory authority.
Because Regain itself does not collect any personally identifying data directly (RevenueCat-collected data is governed by RevenueCat’s own policy linked in Section 7; optional usage-analytics events are anonymous per Section 4), most of these rights are inapplicable to data Regain itself holds. The policy nonetheless enumerates all six rights explicitly. To exercise any of them, contact privacy@regainapp.ai.
14. California residents (CCPA)
Categories of personal information Regain may collect directly:
- Identifiers — email address, name, and per-provider account identifier — only if you explicitly choose to sign in with Apple or Google (Section 4, “Account authentication”). Users who never sign in provide none of these.
- Internet or other electronic network activity — usage-analytics events (Section 4), tagged only with a pseudonymous per-install UUID; never linked to your name, email, or Apple ID. Collected only after you grant consent on first launch or in Settings.
You have the right under the CCPA to know what personal information is collected, to request deletion (Settings → Delete Account provides in-app deletion of all server-side account data), and to opt out of the sale or sharing of personal information for advertising purposes.
Sale / sharing disclosure. Regain does not sell personal information for monetary consideration. However, under the CCPA’s broad definition of “sharing” for cross-context behavioral advertising, the pseudonymous ad-measurement events transmitted to Meta and Google (Section 4, “Ad-measurement partners”) may qualify as sharing even though no IDFA and no direct identifier is included. To opt out, withdraw analytics consent in Settings → Privacy Corner. Once analytics consent is withdrawn, no events reach Meta or Google.
For CCPA queries, contact privacy@regainapp.ai.
15. International data transfers
RevenueCat, Apple, Google, and Meta operate in the United States. Standard Contractual Clauses apply to data transferred from EU users to each of these processors (see each processor’s privacy policy linked in Section 7 for details). Regain’s origin server logs and self-hosted analytics infrastructure are both located at Hetzner data centers in Helsinki, EU.
16. Changes to this policy
Updated versions of this Privacy Policy are posted at the same URL; the “Last updated” date at the top of the page reflects the most recent change. Material changes are communicated via an in-app notice on the next launch.
17. Contact
For privacy and GDPR/CCPA queries: privacy@regainapp.ai.
For general support: help@regainapp.ai.
Postal address: EpowerX Labs Private Limited, Plot No. 77, JBR Tech Park, 6th Rd, Whitefield, EPIP Zone, Bengaluru, Karnataka 560066, India.