LockIn · Legal
LockIn privacy policy.
LockIn is the alarm that makes you prove you’re up. Proving it should not cost you your privacy — this policy explains exactly what the app collects, what stays on your iPhone, and what never leaves it.
Effective 4 August 2026 · Last updated 4 August 2026
The short version
- Most camera missions (like push-ups) are verified entirely on your iPhone. Photo-proof missions send one downscaled photo for a single verification check, then discard it — it is never saved on your phone or kept on our servers.
- Sleep data stays on your iPhone. What LockIn reads from Apple Health, and the sleep stages it estimates itself from a monitored night, are both worked out on the device and never reach our servers. We never sell any of it or use it for advertising.
- Microphone audio — sleep sensing, night-audio clips, spoken missions — is analysed on your iPhone and never uploaded to us.
- Payments run through Apple. We never see or store your card number.
- We do not sell your data. There are no ads in LockIn.
- We do use product analytics, and the events are linked to your account rather than anonymous — see “Analytics and diagnostics” for exactly what is and is not collected.
- You can delete your account from inside the app at any time — Profile → Delete account — or by emailing support@toolsai.app.
Who we are
LockIn is made by ToolsAi Pty Ltd (ABN 73 698 152 902), an independent iOS software company based in Sydney, Australia (“ToolsAi”, “we”, “us”). This policy covers the LockIn iOS app. Our website has its own privacy policy, and use of LockIn is governed by our terms of use.
Account data
An account is optional. LockIn works without one — the sign-in step during setup has a “Skip for now”, and your alarms, missions and settings behave the same either way. An account exists so that they, along with your streaks, follow you to a new phone.
If you do create one, you can use Sign in with Apple, Google, or an email address and password. What we hold is your email address, the sign-in identifier from whichever provider you used, and a display name. If you sign in with a password it is handled by Supabase, our authentication provider, and stored only as a hash — we never see it, and there is no way for us to read it back.
Alongside your account we store your app settings and activity: alarm times, the missions you configure, mission outcomes (completed or missed), and streaks.
Camera and photos — mission verification
Some missions use your iPhone’s camera. There are two kinds, and they handle your camera differently:
- On-device missions — push-ups, squats, the camera games and the AR games, and scanning a code you printed. The camera feed is analysed entirely on your iPhone. No image is ever uploaded, and we never receive one.
- Photo-proof missions — a made bed, a tidy space, an item you’re asked to find, the sky, a meal you prepped, touching grass. These send a single downscaled photo to our verification service for one automated pass-or-fail check, which runs on our servers and uses a third-party AI provider (Anthropic) to read the photo. The photo is used only for that one check and is then discarded — it is never saved to your device, added to your photo library, or stored on our servers.
What we keep from a photo-proof mission is the outcome (completed or missed), how confident the check was, and a short perceptual hash — a non-reversible fingerprint that stops the same photo being reused. Never the photo itself.
You can decline camera access and choose missions that do not use the camera, such as math drills.
Screen-time bank
If you turn on the screen-time bank, LockIn uses Apple’s Screen Time framework to keep the apps you pick shut until you have earned minutes — from your wake-up mission, gym time, focus sessions, a made bed or a tidy space. Apple’s framework hands LockIn opaque tokens for the apps you choose: LockIn never learns their names, never sees what you do inside them, and nothing about your app use leaves your iPhone. You can turn the bank off, or revoke Screen Time access in Settings, at any time.
Microphone, sleep sensing and night audio
The microphone is used for two things and nothing else: sensing how you sleep, and hearing you speak a verse or an affirmation aloud to dismiss an alarm. Both are analysed on your iPhone.
- Sleep sensing. You choose how a night is tracked. Movement only uses the accelerometer and never opens the microphone. Acoustic sensing listens for restlessness. Active sonar plays a tone above the range of human hearing through the speaker and reads its echo to sense breathing. Whichever you pick, the sound becomes a restlessness measure on the device — the audio itself is not kept.
- Night audio is off unless you switch it on for an alarm. When it is on, LockIn saves a short clip — a few seconds, at most twelve — around each detected sound such as snoring, coughing or sleep talking, so you can listen in the morning. It never records the whole night. Clips are written only to your iPhone and are never uploaded to us. They delete themselves after 7, 20 or 100 nights depending on the setting you choose, and you can delete any of them by hand at any time.
- Your sleep stages are estimated from that same restlessness measure, on your iPhone, and shown as a sleep score in the morning. Nothing extra is recorded or kept to do it: it reads the minute-by-minute restlessness figure the night already produced. It is an estimate from movement and sound, not a medical measurement, and LockIn labels it as one — if Apple Health holds stages measured by an Apple Watch for the same night, those are used instead.
- Battery level. While a night is being monitored LockIn reads your battery level so it can tell you to charge, switch off clip recording, and finally stop the session while there is still enough charge for your alarm to ring. The level is used on your iPhone and stored only in that night's own record; it is never sent to us.
- Spoken missions. Speech recognition runs on your device. The Bible-verse mission is checked against the verse text bundled in the app, so nothing leaves your phone. The affirmation mission is the one exception: the words you spoke — as text, never as audio — are sent for a single automated check and are not stored.
You can decline microphone access. Sleep tracking then runs in movement-only mode and spoken missions are unavailable; every other mission still works.
HealthKit and sleep data
If you choose to connect Apple Health, LockIn asks for exactly two things, both read-only: sleep analysis and workouts. Sleep analysis is what puts your sleep trends next to your wake-up streaks, and — where an Apple Watch or another app recorded the stages of a night — what LockIn shows you as your sleep stages and sleep score, in preference to its own estimate. Workouts are what let a habit be verified by something you actually did rather than by ticking a box, and what fills in your training hours. Those are the only two, and LockIn asks for no permission to write to Apple Health at all.
LockIn only ever reads Apple Health after you have granted access from a button you tapped. It never asks in the background, and on a device that has not granted access it reads nothing at all rather than raising a permission prompt you did not go looking for.
- None of it leaves your iPhone. Health data is read and analysed on the device. We hold no sleep or workout records on our servers — so unlike your alarms, your sleep history does not sync to a new phone, because it was never ours to sync.
- Health data stays under Apple Health’s own controls.
- We never use health data for advertising or marketing.
- We never sell health data or share it with third parties.
- You can revoke LockIn’s access at any time in the Health app.
Calendar
LockIn estimates when in the day you are likely to be sharpest. If you tap to add those windows to your calendar, it writes them there as ordinary events — “Peak focus” and “Secondary focus”, each with a note saying LockIn suggested it.
- The access is write-only, and iOS enforces that. LockIn can add an event and cannot read anything already in your calendar. It does not know what you have on, who you are meeting, or what any existing event is called.
- Only when you ask. Nothing is written in the background. Events go into whichever calendar your iPhone already uses for new events.
- Nothing about your calendar reaches us. The events are created on your device by iOS itself; no calendar data is sent to our servers.
- Because the access is write-only, LockIn cannot find those events again afterwards, or remove them. Delete them in the Calendar app like any other event, and revoke the permission in Settings whenever you like.
Payments
Subscriptions are purchased through the App Store using Apple’s StoreKit. Apple processes the payment; we never see your card details. You manage or cancel your subscription in your App Store account settings.
Two companies help us run that subscription, and both are listed under “When we share information” below. RevenueCat checks with Apple whether your subscription is active, so the app knows what to unlock. Superwall draws the subscription screen itself and is told your age range, so the offer you see suits you. Neither of them receives a payment method — there is none to receive, because the purchase happens inside Apple’s own sheet.
Earlier builds also offered an optional real-money stake on an alarm, charged through Stripe if a mission wasn’t finished in time. It was removed from the app on 1 August 2026 — no card is collected for it any more, the Stripe SDK is no longer part of the app, and LockIn has no real-money feature today beyond the subscription above. A small number of accounts created before then may still hold Stripe’s reference for a saved card, and a record of any stake charge that was made; see “Deleting your data” below for how those are kept and removed.
A note on a removed feature: the Social tab
Earlier versions of this policy described a Social tab — a stripped-back browser for TikTok, Instagram, Facebook, X, LinkedIn, WhatsApp and Telegram, each opening its own website inside the app. It was removed on 1 August 2026, alongside the stakes feature above. While it existed it never saw your platform passwords, never read your feeds, messages, followers or contacts, and the only thing it read from a page was the unread-count in its title. Nothing it collected is still held, and the app has no browser or social-platform integration of any kind today.
Analytics and diagnostics
We use product analytics to see which features people actually use and where the app loses them. “Analytics” covers a lot of different things, so here is exactly what it means in LockIn:
- What we collect. In-app events — the app being opened, an alarm created, a wake-up mission completed, a paywall shown, a subscription started, and which onboarding step you reached — along with your app version, device model, operating system version and language.
- You can turn it off, and in Europe it starts off. There is a “Share usage analytics” switch in Profile. If your device region is in the EEA, the UK or Switzerland it is off until you turn it on; everywhere else it starts on and you can turn it off at any time. Switching it off stops collection immediately and discards anything not yet sent. The app works exactly the same either way — nothing is withheld from you for saying no.
- We do not infer your location from your IP address. Analytics providers commonly derive a city from the connecting IP by default; we have turned that off. Combined with the app linking no location framework at all, this means we hold no location data of any kind.
- It is linked to you, not anonymous. Once you sign in, these events are tied to your LockIn account identifier so we can follow one person’s path through the app. This is event-level data about you, not aggregate statistics, and we would rather say so plainly than imply otherwise.
- What it never contains. Photos or camera imagery, health or sleep data, night-audio recordings, your card number, or anything you type.
- Your onboarding answers stay on your phone — with two deliberate exceptions. We send the “where did you hear about us?” answer, which exists only to tell us which channels are working, and your age range, which selects which subscription offer you are shown. Every other answer you give during setup is stored only on your device.
- No advertising, no cross-app tracking. LockIn contains no advertising SDK, does not use Apple’s advertising identifier (IDFA), never asks for App Tracking Transparency permission, and shares nothing with ad networks or data brokers.
We do not run a third-party crash-reporting SDK. Crash reports reach us only through Apple, and only if you turned on “Share With App Developers” in your iPhone’s privacy settings. Our own servers keep short-lived technical logs of requests the app makes, so we can debug failures and detect abuse.
The analytics providers are named under “When we share information” below. To stop collection, use the switch in Profile. To have data already collected about you deleted, email support@toolsai.app with the subject “Delete my LockIn analytics” and we will remove it. Deleting your account also removes it.
What we never do
- We never sell your personal information.
- We never show ads or share your data with ad networks.
- We never store your camera imagery or mission photos, or use them for anything but checking that one mission.
- We never upload your night-audio clips, and we never receive a recording of your voice.
- We never use your health data for anything except the features you asked for.
- We never read your calendar — LockIn can only add to it.
When we share information
We do not sell your personal information. We share it with the service providers below, who process it on our behalf to run the app:
- Apple — for App Store purchases, Sign in with Apple, alarms and push notifications.
- Supabase — our cloud infrastructure provider. Hosts the database, sign-in and secure server functions that store your account, alarms and activity.
- Stripe — the historical processor for the real-money stakes feature removed on 1 August 2026. No new card data is sent to Stripe today; a small number of accounts created before then may still have a saved card or a past charge record on file there. We never see your card number.
- Anthropic — receives a photo-proof mission image transiently to return a pass-or-fail verdict. It is used only for that check and is not retained.
- Mixpanel — our product analytics provider. Receives the in-app events described under “Analytics and diagnostics”, tied to your LockIn account identifier. It never receives your photos, health data, audio or card details, and we do not use it for advertising.
- RevenueCat — manages and verifies your subscription, and receives your account identifier and purchase history.
- Superwall — presents and optimises the subscription screen. It receives your account identifier, which subscription screens you saw and what you did with them, and your age range, which selects which offer you are shown.
Some of these providers store data outside Australia, including in the United States. Where that happens, we take reasonable steps to make sure your information is handled consistently with the Australian Privacy Principles. We will disclose information if the law requires us to.
Retention
We keep account and activity data while your account is active. Historical stake transaction records, from before the feature was removed on 1 August 2026, are kept as long as financial record-keeping laws require. Data stored only on your device — including photo proofs — is removed when you delete the app.
Security
No system is perfectly secure, so rather than offer you an adjective, here is what we actually do:
- Everything in transit is encrypted. The app talks to our servers over encrypted connections only.
- The database decides who can read what — not the app. Every row we store is tied to an account, and rules inside the database itself allow you to read and write only your own records. A bug in the app cannot hand you someone else’s data, because the check does not live in the app.
- Keys never ship inside the app. The credentials for payments and for the photo-verification service exist only on our servers. Taking the app apart yields nothing anyone can use.
- We hold as little as we can. Mission photos, night-audio clips and camera imagery are never stored on our side at all — which is the strongest protection available for them, and the reason the sections above are written the way they are.
If a breach ever affects your personal information, we will move to contain it and notify you and the Office of the Australian Information Commissioner where the Privacy Act requires it.
Your choices and rights
You do not have to take our word for what we hold. Under the Australian Privacy Principles you can ask us for a copy of the personal information we hold about you, and ask us to correct it if any of it is wrong. Email support@toolsai.app and we will respond within 30 days. If we cannot give you something, we will tell you why.
You can also turn analytics off in Profile, revoke any permission — camera, microphone, Apple Health, calendar, notifications — in the iOS Settings app whenever you like, and delete your account outright. Nothing in the app is withheld from you for exercising any of these.
Deleting your data
You can delete your account from inside the app, at Profile → Delete account. That is not a request that goes into a queue — it runs immediately. Your profile, alarms, stakes, wake events and verification records are removed from our database on the spot, your saved card is detached at Stripe so no payment method stays on file, and if you signed in with Apple, that grant is revoked with Apple.
If you would rather ask us to do it, email support@toolsai.app with the subject “Delete my LockIn data” and we will delete your account and associated data within 30 days.
One thing survives either route, and we would rather name it than leave it inside “records we are required to keep”: if you were ever charged for a missed alarm, the record of that charge — the amount and the payment reference — is retained for as long as financial and chargeback rules require. Your account is detached from it, so what remains is an anonymous transaction record, and it is not visible to anyone using the app.
Deleting the app from your iPhone immediately removes everything held only on the device, including your night-audio clips, sleep history and settings.
Children
LockIn is intended for people aged 13 and over, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us information, contact us and we will delete it.
Australian privacy law
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you are located outside Australia, we apply the same standards described in this policy.
Nothing in this policy or in our terms of use limits any rights you have under the Australian Consumer Law, and nothing in it can be read as excluding a guarantee that law does not allow us to exclude.
Complaints
If you think we have mishandled your personal information, email support@toolsai.app with the subject “Privacy complaint”. We will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
Changes to this policy
If we change this policy, we will post the new version at this address and update the date at the top. If a change affects how camera, photo or health data is handled, we will tell you in the app before it takes effect.
Contact
ToolsAi Pty Ltd · ABN 73 698 152 902
Sydney, Australia
support@toolsai.app
Related: Website privacy policy · InvoiceMe privacy policy · Terms of use