1. Who we are
Mast is operated by Thomas Bryden, trading as Mast, a sole trader based in the United Kingdom (“Mast”, “we”, “us”). Mast is a screen-time app for iPhone that blocks the apps you choose until you complete a real-world commitment.
We are the data controller for the personal data described in this policy. This policy covers the Mast iOS app and this website (usemast.app). You can reach us about anything in this policy at contact@tombryden.dev.
2. Our Screen Time commitment
Mast is built on Apple’s Family Controls and Device Activity frameworks. We want to be unambiguous about what that means for your data:
- We never sell, and never disclose to third parties, any data relating to your screen time or the apps you block, for any purpose.
- We cannot see which apps you choose to block. When you pick apps in Apple’s selection screen, Apple gives Mast an opaque, encrypted token for your selection. We store that token so your blocking works across sessions, but it can only be decoded by your own device. The only thing visible to us is how many apps, categories, and websites you selected.
- We do not collect your Screen Time usage data. Mast does not read how long you spend in other apps. Any usage figures shown during onboarding are based on what you tell us on a slider, and that answer stays on your device.
3. The data we collect
Account information
When you create an account we collect your email address and, if you provide it, your name. If you use Sign in with Apple, we receive the identity Apple shares with us (which may be a private relay email address). Accounts are managed by our authentication provider, Clerk; passwords are held by Clerk in hashed form and are never visible to us. Inside Mast’s own database you are identified only by a random account ID.
Your commitments
We store the commitments you create: the name you give each one, its schedule and timezone, the unlock method you choose (including any photo-check prompt you write), and your completion history, such as when a commitment was completed, skipped, or unlocked.
Photo checks
If a commitment uses photo verification, the photo you submit is sent securely to OpenAI, our AI provider, to check it against your prompt. The photo itself is never stored - it is reviewed and immediately discarded. We keep only the outcome (approved or rejected) and, if rejected, a short reason.
Commitment images
If you add a cover photo to a commitment, it is resized on your device, stripped of hidden metadata such as location (EXIF/GPS), and stored privately in our cloud storage.
Device information
We record your device’s model name (for example “iPhone 15 Pro”), its platform, a random installation ID we generate, and when the app last checked in. This lets your commitments follow the right device.
Subscription information
Purchases are made through Apple. We receive transaction identifiers, the product you bought, its price and currency, and the subscription’s status (for example trialling, active, or expired). We never receive or store your payment card details - Apple handles all billing.
Analytics and diagnostics
We use PostHog (hosted in the EU) to understand how Mast is used and to fix problems. This includes:
- usage events, such as signing up, creating a commitment (including its name), completing onboarding, or unlocking - tied to your account ID and email address;
- session replays of how the app’s interface is used, with all text you type and all images automatically masked;
- crash reports and error diagnostics; and
- server logs, which can include your photo-check prompt and the AI’s short text description of a submitted photo (never the photo itself).
4. How we use your data
Under UK and EU data protection law, we rely on:
- Performance of a contract - operating your account, syncing your commitments and devices, running photo verification, and managing your subscription.
- Legitimate interests - understanding how Mast is used, improving the product, diagnosing crashes and errors, and preventing abuse. We balance these interests against your rights and minimise what we collect.
- Legal obligation - keeping transaction records we are required to retain for tax and accounting.
- Consent - where we ask for it, such as iOS permission prompts for Screen Time access, camera, photos, and notifications. You can withdraw these at any time in iOS Settings.
We do not use your data for advertising, we do not build advertising profiles, and we do not sell personal data to anyone.
5. Who processes your data
We share personal data only with the service providers below, who process it on our instructions:
- Clerk (USA) - account creation, sign-in, and transactional email such as verification codes.
- Amazon Web Services (London, UK - eu-west-2) - our database and image storage.
- PostHog (EU cloud) - analytics, session replay, error tracking, and logs.
- OpenAI (USA) - transient AI review of photo-check submissions; photos are not retained.
- Apple - App Store billing, Sign in with Apple, and the Screen Time frameworks. Apple acts under its own privacy policy for purchases you make.
Where a provider processes data outside the UK or EEA (Clerk and OpenAI in the USA), transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses.
6. How long we keep your data
- Account, commitment, device, and image data is kept while your account exists and is deleted when your account is deleted.
- Photo-check photos are never retained at all.
- Subscription and transaction records may be kept after account deletion where we need them for tax, accounting, or resolving billing disputes.
- Analytics, diagnostics, and logs are kept in line with our providers’ retention settings and are not kept longer than needed for the purposes above.
7. Deleting your account
You can delete your account and data at any time, either directly in the app (Profile → Delete Account) or by emailing contact@tombryden.dev from the address on your account. We honour deletion requests within 30 days, subject only to records we must keep by law (see section 6).
8. Your rights
Under the UK GDPR and EU GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent where processing is based on consent. To exercise any of these rights, email contact@tombryden.dev. We will respond within one month.
You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). If you are in the EEA, you may complain to your local data protection authority.
9. Security
Your data is encrypted in transit (TLS) and at rest: our database and image storage are encrypted, and the database is not reachable from the public internet. On your device, sign-in credentials are stored in the iOS Keychain. No system is perfectly secure, but we design for minimal collection - most notably, we architected Mast so that we are technically unable to read which apps you block.
10. Communications
The only emails we send are transactional - sign-in verification codes and messages about your account. We do not send marketing email, and we will not do so in future without your consent and an easy way to opt out.
11. US residents
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. For the purposes of the California Consumer Privacy Act (CCPA), the categories of personal information we collect are: identifiers (email, account ID, device ID), commercial information (subscription and transaction records), internet or electronic activity (app usage events and diagnostics), and user content (commitment names, prompts, and images). California residents have the rights to know, delete, and correct their personal information, and to non-discrimination for exercising those rights - contact us at contact@tombryden.dev.
12. Children
Mast is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it promptly. If you believe a child under 13 has provided us personal information, please contact us.
13. Changes to this policy
If we change this policy, we will update it here and revise the “Last updated” date. For significant changes we will give you more prominent notice, such as in the app. Continued use of Mast after a change takes effect means the updated policy applies.
Questions? Email contact@tombryden.dev.