A privacy policy
with little to say.
The Eclipsis extension and app do their work on your device: what you browse, what gets hidden, and your usage stats stay there. An account is optional and holds the minimum a subscription needs: your email and your plan. Payments are handled by Stripe or Apple, so we never see card numbers. We run no analytics or trackers, we send no marketing email you did not ask for, and we sell nothing to anyone.
What runs on your device
The browser extension and the mobile app read the pages of the platforms you point them at (YouTube, TikTok, Instagram, X, Reddit, and the beta platforms Facebook, Threads, and LinkedIn) in order to hide feeds, pace posts, and remove attention-bait elements. That reading happens locally. Page contents, the posts you see, and your browsing history are never transmitted to us or to anyone else.
These stay in local storage on your device and never leave it:
- Your settings: mode, platforms, per-platform toggles, appearance choices.
- Usage stats: blocked counts, feed minutes, and streaks, kept to render your own dashboard.
- Session state: per-platform pacing progress, so a reload does not reset your allowance.
- Local passcodes: if you protect settings or Parent Mode with a passphrase, only a cryptographic hash of it is stored, on the device.
The optional AI Detector examines page text for machine-written content entirely on your device. It makes no network requests, and what it scans never leaves the browser. It runs only if you turn it on, and only gets access to sites you grant.
Uninstalling removes ordinary local settings and browsing statistics. On iOS, the Parent Mode lock and recovery record stays in the Keychain so reinstalling cannot bypass the lock. Turn off Parent Mode with the parent passphrase to remove that record.
Accounts, if you make one
You never need an account to use the free extension. If you create one (for Eclipsis Pro, or to sync your entitlement across devices), we store the minimum it takes to run a subscription:
- Your email address, and a hash of your password, or your Google or Apple sign-in identity if you use those instead. We never see or store the password itself.
- An assigned account identifier that links your sign-in, devices, and subscription.
- Your subscription state: which plan, where it was bought (Stripe or Apple), and when it renews or ends.
- A device identifier and the device model (for example "iPhone") for each phone that signs in, so the subscription follows you and we can notice a login being shared. Not the name you gave your phone.
- Referral data if you use invites: your invite code, redemptions, and banked months.
- Parent Mode recovery data if you request remote approval: a device label, the linked account or purchase identifier, a hashed request secret, request status, and request/approval times. The passphrase and backup recovery code stay on the device.
Account data lives in our database. Your browsing activity, your stats, and what Eclipsis hides for you are never linked to your account. We could not sell your attention profile because we do not have one.
Deleting your account (from the account page or inside the app) removes your sign-in, device, and linked purchase records from our account database. Web subscriptions end immediately without a refund. App Store and Google Play subscriptions must be cancelled separately in that store to stop future renewals. A store purchase can be restored to a replacement account using proof of purchase verified by the store. We keep refund verification records without your account details to prevent reuse of refunded purchases. We delete your Stripe customer and saved payment details. Stripe retains historical transaction records, which may include billing information required for financial recordkeeping. Other payment providers retain their own billing records.
Payments
Web subscriptions are processed by Stripe; purchases in the iOS app go through Apple. Card numbers and full billing details go to those processors directly and never touch our servers. We keep only the reference that ties your payment to your plan.
We send transactional email only: account confirmations, password resets, and receipts of things you explicitly submit (like a bug report). No marketing email goes out without your explicit opt-in, and nothing about your usage is ever emailed anywhere.
What you choose to send us
- Bug reports send what the form shows: your description, optional screenshots, an optional contact email, and, behind a visible toggle, a short whitelisted diagnostics block. If you include both diagnostics and an email address, they are linked in the same report. Reports are relayed to our inbox and not stored in a database.
- The uninstall survey on the goodbye page is optional; an answer is relayed to our inbox and not stored in a database. We cannot tell who uninstalled unless you write to us.
Anti-abuse, in the open
Public forms are protected by a bot check that runs in the browser. Our rate limiter counts requests against a salted hash of the requesting address; the salt rotates daily, and the raw address is never stored.
The iOS app and Screen Time
Features like app locking, Lockdown mode, and the device-wide screen report use Apple's Screen Time and Family Controls frameworks. Apple designed those so the data stays on the device: we never receive which apps you use, how long you use them, or which apps you lock. Widgets, wallpapers, and stats are rendered from data on the phone.
The optional Weather widget asks for your location once, at city-level accuracy, and keeps the coordinates on the phone. Each refresh sends only those coordinates to Open-Meteo for the forecast; no account information travels with them. Weather data by Open-Meteo.com, used under CC BY 4.0.
The Android app
The optional native-app blocker uses Android Accessibility events to identify when a selected social app opens and return you to the Home screen. It does not read screen contents, messages, or typed text, and does not store or send this app activity. You can revoke Accessibility access in Android Settings.
Calendar access is optional and used only to show today's agenda on your device. Android weather uses approximate coordinates rounded to about 10 km. Our weather service passes those coordinates to MET Norway without your account, device ID, or network address. Forecasts are cached; location is not written to our account database. You can remove the saved coordinates in the app. Weather data is provided by MET Norway under CC BY 4.0; temperatures and condition labels are formatted for display.
Google Play purchases are verified with Google. We store a hash of the purchase token, verified subscription status and, when you connect an account, purchase ownership. Account tokens on Android are encrypted with Android Keystore. Device backups are disabled for the app.
What we still don't do
- No analytics SDKs, telemetry, crash trackers, or A/B testing, in the extension, the app, or the site.
- No selling, renting, or sharing of personal data with anyone, for any reason.
- No ads and no ad networks.
- No reading of your feeds server-side. The whole point of Eclipsis is that your attention is yours.
Children
Eclipsis accounts are for people 13 and older, and Parent Mode is operated from the parent's account. A child's device running Eclipsis does not need its own account, and we do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If Eclipsis changes in a way that affects this policy, we will update this page and the "Last updated" date above, and call out material changes clearly. Data that is local-only today will not start being uploaded without a fresh, opt-in choice from you.
Contact
Eclipsis is operated by HALLTECH LLC, the data controller for the account data described above. Questions, concerns, or corrections: info@eclipsis.io.
← Back to eclipsis.io