Privacy Policy
Squishy is available as a Chrome extension and apps for iPhone, iPad, and Android. We keep blocking details on your device where possible and collect only the information needed for optional sync, shared Squishy, Heal activities, purchases, analytics, and notifications.
The short version
- Your block lists, schedules, Apple Screen Time selections, Android selected-app list, and active unblock states stay on the device where you created them.
- If you sign in, supported Squishy state and recent activity sync through your account. A shared partner sees general contributions and happiness changes—not the specific app, site, or photo behind them.
- Walk uses the step counter on your phone. Show sends a compressed camera photo for one-time AI verification; the photo is not saved to your gallery or our database.
- Notifications are optional and can be disabled in Squishy or your device settings.
- We do not sell your data, run ads, use ad tracking, or fingerprint you.
What stays on your device
Chrome
The extension uses Chrome's storage.local to keep local settings and progress: your mascot state, block groups and schedules, blocked domains, focus settings, local top-site stats, health activity, and purchase or sync status. Uninstalling the extension deletes local extension data.
iPhone and iPad
The Apple app stores your mascot state, skin, happiness, difficulty, streak, focus and recovery settings, stats, and Screen Time configuration in its private App Group container. Deleting the app deletes this local app data.
Screen Time: Squishy uses Apple's Family Controls, Device Activity, and Managed Settings frameworks. The apps and categories you select are handled by iOS as opaque tokens. Squishy does not send selected app names, tokens, or raw Screen Time usage to our servers. It may sync the resulting general event, such as a block or recovery, to update happiness and recent activity.
Android
The Android app stores your mascot state, block groups and schedules, selected apps, recovery settings, local activity, walk progress, and device-local notification preferences on your device. Cloud backup is disabled for this data, including account session tokens. Partner-notification preferences are account settings stored through Supabase as described below.
How blocking works
Chrome
Squishy uses Chrome's declarativeNetRequest API to redirect blocked domains to its takeover page. Chrome performs the matching. Squishy does not collect your full browsing history. Local stats may include aggregate hit counts for domains you chose to block. If Sync is enabled, a block activity row may include that domain for your own synced recent activity.
iPhone and iPad
Apple's Screen Time frameworks enforce shields for the apps and categories you select. Those selections remain opaque to Squishy and are not sent to our servers.
Android
With your explicit permission, Squishy's Accessibility service observes which app moves to the foreground while a blocking schedule or recovery session is active. It uses the app name only to decide whether to show Squishy's blocking screen. The service does not read screen text, taps, passwords, messages, or other screen contents, and it does not perform gestures. Your selected-app list and schedules remain local. If Sync is enabled, your own synced activity may include the blocked app's name.
Heal Squishy activities
Focus with Squishy
Focus stores the session timing and resulting happiness change. If Sync is enabled, the completed session and its reward may appear in recent activity and shared contributions.
Walk with Squishy
On iPhone, Squishy asks for Motion & Fitness permission and uses Apple's Core Motion pedometer. On Android, Squishy asks for Physical Activity permission and reads the device step-counter sensor during an active walk. Android also runs a foreground service with an ongoing step-progress notification while a walk is active. Squishy stores the active walk's start time and step total locally so the session can continue while the screen is off.
When you end a walk, Squishy records the completed step count and resulting happiness reward. If Sync is enabled, the walk event and reward may sync to your account; a partner sees the general activity and contribution, not unrelated movement or a continuous location trail. Squishy does not collect GPS location for Walk. Step counting is unavailable on devices without a supported sensor and is currently disabled on iPad and Android tablets.
Show Squishy something
Show uses your camera only after you grant permission. When you take a picture, Squishy compresses it to a JPEG of no more than 400 KB and sends it over an encrypted connection to a Supabase Edge Function. The function sends the image and the selected scavenger-hunt prompt to OpenRouter, which routes it to the configured vision model for one-time verification. As part of the same request, the model first checks for unsafe content or clearly visible private information and rejects the image if it detects either. The request is configured to deny provider data collection and require zero-data-retention processing.
The photo is held only long enough to complete or retry that verification. It is not added to your Photos or Gallery, stored in Squishy's database, included in analytics, or shown to your partner. We store limited verification records such as an attempt ID, prompt ID, pass, fail, or unsafe-content outcome, reward, daily totals, and timestamps to prevent duplicate rewards and enforce daily limits. AI safety and prompt verification can make mistakes.
Account sync and shared Squishy
If you sign in, Squishy uses Supabase for email one-time-code authentication, account sessions, entitlement checks, shared Squishy membership, and sync storage. Resend may deliver sign-in-code emails. We store your email address, user ID, display name, linked-device records, subscription entitlement status, and sync timestamps.
Synced Squishy data can include current happiness, skin, difficulty, streaks, daily happiness history, recent health activity, and aggregate activity statistics such as blocks, recoveries, focus sessions, completed walks, Show finds, and estimated time saved. Chrome activity may include a blocked-domain label and Android activity may include a blocked-app label in your own account activity. Apple Screen Time activity does not include selected app names.
We do not sync your Chrome block lists or schedules, Apple Screen Time selections or tokens, Android selected-app lists or schedules, active temporary-unblock state, or raw browsing/app-usage history.
If you share Squishy, the other member can see your display name, the type of contribution or slip, the resulting happiness change, and shared totals. Partner-facing activity is deliberately stripped of blocked app names, blocked domains, Show prompts, photos, and other event details. Either member can unlink; owners can remove the other member.
Notifications
With permission, Squishy may send recovery-complete reminders, low-happiness reminders, trial or subscription messages, partner-activity messages, and service notifications required for active features such as Android walk tracking. Partner messages may tell you when your partner adds at least 10 happiness or when shared happiness falls to 20 or below. Notification availability and presentation depend on your operating system.
The mobile apps use OneSignal for push delivery and RevenueCat-related subscription messaging. OneSignal may receive an app-assigned or account-linked identifier, push token, permission/subscription status, device information needed for delivery, messaging tags, and the notification title and body. A partner-activity title may include your partner's display name, and its body may include the happiness contribution. It does not include the specific blocked app, blocked site, Show prompt, or Show photo behind the event.
Local reminder choices are stored on your device. If you sign in and share Squishy, your partner-notification choices are stored in Supabase so they apply to account-linked delivery. To queue, limit, retry, and audit those pushes, Supabase stores a private delivery record that can include the source activity, shared Squishy, actor and recipient identifiers, notification type and contents, day, delivery status and attempts, timestamps, provider notification identifier, and limited error information. These delivery records are not exposed as partner activity. Notification opens and preference changes may be recorded in product analytics so we can measure whether messaging works.
You can turn Squishy notifications off in the app's Settings where available, or revoke notification permission in iOS, iPadOS, or Android settings. Some required Android foreground-service notices cannot be hidden while the related service is running.
Purchases
Apple and Google Play
Mobile subscriptions are processed by Apple or Google Play. We never receive your payment-card details. We use RevenueCat to receive purchase events, product and entitlement status, store transaction references, and app-assigned identifiers so Squishy can confirm access across eligible devices. To confirm eligibility for Show, the app may also send a signed Apple transaction or Google Play purchase token to a Supabase Edge Function. Apple proofs are cryptographically verified; Google Play tokens are checked with Google. Squishy's database stores derived one-way identifiers and may temporarily cache a one-way identifier for a rejected proof, but does not store the raw signed transaction or purchase token. Manage or cancel your subscription through the store where you purchased it. RevenueCat's privacy practices are at revenuecat.com/privacy.
Chrome and Lemon Squeezy
If Chrome Premium is purchased directly through Lemon Squeezy, Lemon Squeezy collects the information required to process payment, handle tax, issue receipts, provide a license key, and support refunds. Its privacy practices are at lemonsqueezy.com/privacy. The extension stores the activation details needed to confirm Chrome Premium.
Analytics
The mobile apps use PostHog for product analytics such as onboarding views and completion, feature use, paywall events, purchase outcomes, notification-permission choices, and app-assigned identifiers. Show analytics may record that verification passed or failed and a general status, but never the image itself. We use analytics to understand drop-off, reliability, and feature use—not for advertising. We do not use advertising IDs or session replay.
Website data
This website loads Google Fonts for typography. Google may receive your IP address when font files load under its standard CDN practices. We do not use advertising cookies, ad trackers, fingerprinting, or session replay on this site.
Service providers
Companies that may process limited data on our behalf include Apple and Google Play (mobile purchases and purchase verification), RevenueCat (subscription management), Supabase (authentication, sync, shared Squishy, notification preferences and delivery, purchase-proof checks, and Show verification routing), Resend (sign-in email), OpenRouter and the configured vision-model provider (temporary Show safety and prompt verification), Lemon Squeezy (direct Chrome purchases, if offered), PostHog (mobile product analytics), OneSignal (mobile push notifications), and Google Fonts (website font delivery). We do not sell personal data or share it with advertisers.
Your choices
- Decline or revoke Screen Time, Accessibility, Motion & Fitness, Physical Activity, Camera, or notification permissions. Features that need a declined permission will not work until it is restored.
- Disconnect Sync at any time to stop future sync on that device.
- Delete your account in the mobile app from Settings → Sync with Chrome → Delete sync account, or follow the instructions on our account-deletion page. This deletes your account-owned server data. If another active member shares the pet, the shared Squishy and its history remain with that person.
- Uninstall the app or extension to delete its local data. On Android, clearing app storage also removes local data.
- Manage or cancel your subscription through Apple, Google Play, or the applicable Chrome checkout provider.
- Contact hello@blankslateapps.com for a privacy request not covered by in-app controls.
Retention and security
Account, sync, partner-notification preference, and notification-delivery data remain while your account is active. In-app account deletion runs immediately against active cloud data. Encrypted database backups may retain residual copies for no more than 30 days before automatic rotation. Show photos and raw store proofs are not written to those databases or backups. Limited Show verification, derived purchase-proof, and anti-abuse records may remain without a direct user-ID link so we can prevent duplicate rewards, enforce limits, investigate abuse, and maintain service integrity. We use encrypted transport and access controls, but no service can guarantee absolute security.
Children
Squishy is not directed at children under 13. If you are under 13, do not use Squishy.
Changes to this policy
If we update this policy, we will revise the date above. We will provide reasonable notice of material changes where required.
Contact
Questions about privacy can go to hello@blankslateapps.com.