PRIVACY POLICY – MIDSCROLL
Last updated: July 21, 2026
GENERAL INFORMATION
midscroll (“the app”) displays mindfulness-oriented reminders (“quests”) while users are using apps they previously selected.
This Privacy Policy explains which personal data may be processed when using midscroll, why the data is processed, and which rights users have.
midscroll does not provide user accounts and does not operate its own servers for storing app content. The data required for the app’s core functionality is generally processed locally on the user’s Apple device.
DATA CONTROLLER
The controller responsible for processing personal data is:
[FULL NAME OR COMPANY NAME]
[STREET AND HOUSE NUMBER]
[POSTCODE AND CITY]
[COUNTRY]
Email: support@midscroll.app
LOCAL DATA PROCESSING
Quests, categories, settings, app selections, and history data created or selected by the user are generally stored exclusively on the user’s device.
This data is not transmitted to servers operated by the developer. midscroll does not use its own cloud database and currently does not provide account-based synchronization of app content.
Certain technical activities may nevertheless involve processing by Apple, the provider hosting this Privacy Policy, or the email provider. This includes:
– downloading and updating the app through the App Store,
– in-app purchases and purchase restoration,
– App Store statistics and diagnostic information that Apple may make available,
– device or iCloud backups,
– accessing this Privacy Policy,
– contacting the developer by email.
These activities are described below.
SCREEN TIME AND APP SELECTION DATA
midscroll uses Apple’s FamilyControls, DeviceActivity, and ManagedSettings frameworks to provide its core functionality.
Users select apps or app categories through Apple’s system-provided FamilyActivityPicker.
Apple provides midscroll with opaque selection values, including ApplicationTokens or CategoryTokens. These values represent the apps or categories selected by the user without allowing midscroll to directly read the app name or bundle identifier from the token.
midscroll stores these selection values locally in an Apple-provided app-group container so that the selection can also be used by the app’s related extensions.
midscroll does not transmit these selection values to the developer or to any other recipient engaged by midscroll.
The data is processed solely to:
– store the user’s app selection,
– detect situations relevant to the functionality of midscroll,
– display or trigger the quests requested by the user,
– manage the reminders or restrictions configured by the user.
The processing is necessary to provide the functionality requested by the user.
Where information is stored on or accessed from the user’s device, this occurs only where technically necessary to provide the service expressly requested by the user.
LOCALLY STORED CONTENT
midscroll may store the following information locally on the device:
– categories created or selected by the user,
– quests created or selected by the user,
– app settings,
– selected app and category tokens,
– a history of quests previously displayed,
– statistics generated within the app from that history,
– information indicating whether onboarding or information screens have already been displayed,
– the local status of unlocked Pro features.
This information is stored using Apple-provided storage technologies, including SwiftData, UserDefaults, and app-group containers, where required for the relevant functionality.
The information is not used for advertising, user profiling, or cross-app tracking.
NOTIFICATIONS
midscroll may display local notifications to remind users about quests or other content selected by the user.
Notifications are scheduled and delivered locally through Apple’s UNUserNotificationCenter. midscroll does not use its own push notification server or a push service provided by an advertising or analytics company.
Notification permission is granted through the iOS system settings and can be changed or withdrawn at any time under:
Settings → Notifications → midscroll
The app may still be used without notification permission. However, reminders outside the open app will not be displayed.
PERMISSIONS
Providing personal data is not required by law or contract.
Certain system permissions are, however, necessary for specific features.
Screen Time or FamilyControls permission:
This permission is required so that midscroll can take into account the apps or categories selected by the user. Without this permission, the app’s core functionality will not be available or will be significantly restricted.
Notification permission:
This permission is required if reminders are to be displayed as local notifications. Other parts of the app can generally be used without notification permission.
Permissions can be changed or withdrawn at any time in the settings of the Apple device.
STORAGE AND DELETION OF LOCAL DATA
Locally stored information generally remains on the device until:
– the user deletes or resets the relevant content in the app,
– the user removes an app selection,
– the app data is deleted through the device settings,
– or the app is uninstalled.
Deleting the app generally removes the app data stored locally on the device.
Depending on the user’s settings, app data may form part of an iCloud backup or a locally created device backup. These backups are controlled by Apple or by the user. The developer of midscroll does not have access to these backups and cannot delete information contained in them.
Users can manage their iCloud and device backups through their Apple device settings or the backup software they use.
IN-APP PURCHASES AND STOREKIT
Paid features of midscroll, including “midscroll Pro,” are offered through Apple’s App Store and StoreKit.
Payments are processed directly by Apple. midscroll does not receive access to:
– credit card or bank account details,
– the user’s Apple Account password,
– complete payment details,
– the complete purchase history of the user’s Apple Account.
StoreKit may provide the app with technical transaction information, including:
– the identifier of the purchased product,
– the purchase or subscription status,
– a StoreKit transaction identifier,
– the purchase date,
– the expiry date of a subscription, where applicable,
– information required to restore a purchase,
– information concerning a refund or revocation.
This information is used solely to verify the purchase, unlock Pro features, and restore previous purchases.
Apple is independently responsible for processing personal data in connection with the App Store and payment processing. For users in the European Economic Area, the responsible Apple entity is generally:
Apple Distribution International Limited
Hollyhill Industrial Estate
Hollyhill, Cork
Ireland
Apple’s privacy policy and terms also apply.
APP STORE STATISTICS AND DIAGNOSTIC INFORMATION
midscroll does not include its own third-party analytics, telemetry, or crash-reporting SDKs.
Apple may provide the developer with aggregated statistics regarding app usage, downloads, purchases, and technical stability through App Store Connect or Apple’s developer tools.
Where a user has enabled the sharing of analytics and diagnostic information with Apple and app developers, Apple may also provide the developer with technical diagnostic information. This may include information concerning crashes, device and operating-system versions, or technical error conditions.
Where such information is made available, it is used solely to:
– identify technical problems,
– investigate crashes,
– improve the stability and security of the app,
– maintain compatibility with current operating-system versions.
It is not used for advertising, personal user profiling, or cross-app tracking.
Users can manage the sharing of analytics and diagnostic information with Apple and app developers in the privacy and analytics settings of their Apple device.
NO ADVERTISING OR TRACKING
midscroll does not contain:
– advertising SDKs,
– personalized advertising,
– tracking pixels,
– social-media trackers,
– third-party analytics SDKs,
– cross-app tracking,
– data-broker integrations.
The app does not use the information it processes to track users across other apps or websites.
CONTACT BY EMAIL
When a user contacts the developer by email, the information contained in the message is processed. This may include:
– the user’s name,
– email address,
– message content,
– the date and time of the communication,
– technical metadata,
– voluntarily provided attachments or screenshots.
The information is processed to review and respond to the request.
Gmail is currently used for email communication. For users in the European Economic Area, the provider is generally:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
When Gmail is used, Google may process information on its own systems. This may include processing outside the European Economic Area. Google’s privacy policy also applies to this processing.
Email requests are deleted when the request has been fully resolved and no legal retention obligation or legitimate interest requires continued storage.
Regular support requests will be deleted no later than [RETENTION PERIOD, FOR EXAMPLE 12 MONTHS] after the request has been resolved, unless legal reasons require longer storage.
HOSTING OF THIS PRIVACY POLICY
This Privacy Policy is hosted by:
[NAME OF HOSTING PROVIDER]
[ADDRESS OF HOSTING PROVIDER]
When the webpage is accessed, the hosting provider may process technically necessary connection information. This may include:
– IP address,
– date and time of access,
– requested page or file,
– amount of data transferred,
– referrer URL,
– browser type and version,
– operating system,
– information concerning successful or failed page requests.
This processing is technically necessary to deliver the webpage and to ensure stability, security, and protection against misuse.
Technical log information is deleted by the hosting provider after [HOSTING PROVIDER RETENTION PERIOD], unless longer storage is necessary to investigate a specific security incident.
The hosting provider may process information outside the European Economic Area. Where this occurs, the transfer is subject to the safeguards described by the hosting provider.
The developer does not use its own cookies, analytics tools, advertising networks, or tracking technologies on this webpage.
RECIPIENTS
App content stored locally in midscroll is not transmitted to the developer or to advertising, analytics, or cloud providers engaged by the developer.
Depending on how the app and this Privacy Policy are used, information may nevertheless be processed by the following independently operating providers:
– Apple in connection with the App Store, StoreKit, operating-system permissions, backups, App Store statistics, and diagnostic information,
– Google when the developer is contacted through Gmail,
– [HOSTING PROVIDER] when this Privacy Policy is accessed.
Information will otherwise be disclosed only where:
– disclosure is required by law,
– disclosure is necessary to establish, exercise, or defend legal claims,
– or the user has expressly consented.
INTERNATIONAL DATA TRANSFERS
Apple, Google, or the hosting provider may process information in countries outside the European Economic Area.
Where personal data is transferred to a country that is not covered by an adequacy decision of the European Commission, the transfer is subject to the lawful transfer mechanisms and safeguards used by the relevant provider.
The developer does not transfer quests, app selections, or history information stored locally by midscroll to a third country.
CHILDREN
midscroll is not specifically directed at children.
The app does not provide user accounts and does not transmit locally stored quests, app selections, or history information to the developer’s own servers, regardless of whether the user is a child or an adult.
Parents and guardians should decide whether and how a child may use the app and the device’s Screen Time functionality.
AUTOMATED DECISION-MAKING AND PROFILING
midscroll does not carry out automated decision-making that produces legal or similarly significant effects.
No profiling is carried out for advertising, credit assessment, insurance, employment, or comparable evaluation purposes.
The app operates exclusively according to the settings and rules selected by the user.
DATA SECURITY
midscroll uses Apple-provided system and storage mechanisms to protect locally processed information against unauthorized access.
The protection of the information also depends on the security settings of the device. Users should:
– use a device passcode,
– install current operating-system updates,
– restrict access to their Apple device,
– appropriately secure their device and iCloud backups.
USER RIGHTS
Subject to the applicable legal requirements, users may have the following rights regarding personal data processed by the controller:
– the right of access,
– the right to rectification,
– the right to erasure,
– the right to restriction of processing,
– the right to data portability,
– the right to object,
– the right to withdraw consent with effect for the future,
– the right to lodge a complaint with a data protection authority.
The developer has no technical access to information stored exclusively on the user’s device. The developer is therefore unable to remotely access, correct, export, or delete this information.
Locally stored information can be managed and deleted through the functions provided in the app, by resetting the app data, or by deleting the app.
Requests concerning information available to the developer, for example information contained in email communications, can be sent to:
nwahid94@gmail.com
RIGHT TO OBJECT
Where personal data is processed on the basis of a legitimate interest, users may object to the processing on grounds relating to their particular situation.
Following an objection, the controller will no longer process the relevant information unless there are compelling legitimate grounds for the processing or the processing is required to establish, exercise, or defend legal claims.
RIGHT TO LODGE A COMPLAINT
Users have the right to lodge a complaint with a data protection authority.
Where the controller is established in Bavaria, the competent authority for non-public entities is generally:
Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany
Users may also contact another data protection authority competent under Article 77 GDPR.
CHANGES TO THIS PRIVACY POLICY
This Privacy Policy may be updated if the functionality of the app, the services used, or the legal requirements change.
The current version will be published at the URL provided for this Privacy Policy.
The date shown at the beginning of this document will be updated when material changes are made.
CONTACT
Questions concerning privacy may be sent to:
[FULL NAME OR COMPANY NAME]
Email: support@midscroll.app