Privacy Policy

Hours Tracker, by Scanly Studio · Last updated 2026-10-01

The short version. Your jobs, entries, rates and notes are stored on your phone and are never sent to us. There is no account and no login. The app does not read from or write to Apple Health. It contains no advertising or crash-reporting SDK. Data leaves your device in three cases only: when you buy a subscription, which is handled by Apple and by our payments provider, RevenueCat; as anonymous usage statistics about the setup and purchase screens, sent to our analytics provider, PostHog; and when you yourself export a timesheet or a backup file and choose where to send it.

Who we are

Hours Tracker is published by Scanly Studio. If you have a question about anything on this page, write to scanlystudio.support@proton.me and a person will answer.

Your data, stored on your device only

The app keeps everything you enter on your device, in the app’s own storage:

None of this is sent to us. There is no account and no server of ours; none of it is collected and none of it passes through a server of ours, because we do not have one. The Lock Screen timer (Live Activity) and the Home Screen widget are drawn by iOS from the same data on your device; nothing is sent anywhere to show them.

Files you create yourself

You can export a timesheet (PDF or CSV) and you can back up your jobs and entries to a file. Both files are created on your device and handed to the iOS share sheet. They go only where you send them – the Files app, AirDrop, a mail to yourself – and we never receive them. A backup file is not encrypted, so keep it somewhere you trust. Restoring reads a backup file that you pick on your device and replaces the jobs and entries in the app; the file is not uploaded anywhere.

Permissions the app asks for

Notifications. If you set a reminder time for a job, or ask to be reminded before a free trial ends, the app schedules a local notification on your device. It is created and delivered by iOS on your phone; no push server is involved. The app asks for this permission only when you turn a reminder on, and every reminder is optional.

Face ID / Touch ID. If you turn on the app lock, the app asks iOS to confirm it is you, using Face ID, Touch ID or your device passcode. The check is done by iOS; the app only learns whether it succeeded and never sees or stores your face, fingerprint or passcode.

Data handled by third-party services

Two services are involved: one in connection with a purchase, one for anonymous usage statistics.

RevenueCat (subscriptions and one-time purchases)

When you start a free trial, buy a subscription, buy the lifetime option, or tap “Restore”, the purchase is processed by Apple through the App Store. We use RevenueCat to check whether a purchase is valid and still active. For that, RevenueCat receives an anonymous identifier generated for your installation, the App Store transaction details for what you bought, and basic device and country information supplied by the store. Attached to that anonymous identifier are the options you picked in the setup questions (the kind of work you do, how you track your hours today, your typical weekly hours, whether you set an hourly rate – never the rate itself), your app language, and how often the purchase sheet was closed without buying. It does not receive your name, your email address, your jobs, your entries or your notes. RevenueCat acts as our processor. Their own privacy policy is at revenuecat.com/privacy.

Apple additionally provides RevenueCat with an Apple Ads attribution token where one exists, which tells us only whether an install came from an Apple Search Ads campaign. It is not linked to your identity, it is never combined with anything you enter in the app, and no advertising SDK is present in the app.

PostHog (usage statistics)

To understand where the setup and the purchase screen lose people, the app sends anonymous events to PostHog, hosted in the European Union: that the app was opened, which setup step was shown and completed, which option was picked in a setup question, that the purchase screen was shown, which plan was tapped, and whether a purchase was completed, cancelled or failed. Each event carries a random identifier generated for your installation, the app version, the app language, and the device model and iOS version; your IP address is processed to derive an approximate location. The events never contain your name, your email address, your jobs, hourly rates, entries, notes or anything you typed. There is no session recording. PostHog acts as our processor. Their own privacy policy is at posthog.com/privacy.

What the app does not do

Children

Hours Tracker is not directed at children and we do not knowingly collect personal information from anyone under 16.

Data retention

Because your entries are never sent to us, there is nothing for us to retain or delete. Deleting the app removes them; timesheets and backup files you exported stay wherever you saved them until you delete them there. Usage statistics are kept in PostHog until we delete them or the retention period of our plan ends. Purchase records held by RevenueCat and by Apple are retained under their own policies and for as long as required for tax and accounting purposes.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export or delete personal information held about you, and to object to certain processing. In practice we hold almost nothing: your history is on your device only, and the purchase record is keyed to an anonymous identifier. If you want to exercise a right, or want the purchase record associated with your installation deleted, write to scanlystudio.support@proton.me and we will act on it. To manage or cancel a subscription itself, use Settings → your name → Subscriptions on your iPhone.

Changes to this policy

If this policy changes we will update the date at the top of this page. Material changes will also be flagged in the app.

Contact

Scanly Studio · scanlystudio.support@proton.me


© 2026 Scanly Studio. All rights reserved.