Effective date: August 2, 2026
Latch is a Screen Time app that helps you shield chosen apps behind a short, deliberate friction gate, and shows you where your time actually went. This policy explains what the app does — and, mostly, does not do — with your information. In this policy, "we," "us," and "our" mean Keaton White, the developer of Latch; "Latch" or "the app" means the Latch application; and "you" means the person using the app.
Latch has no user accounts, collects no analytics, and runs no servers. Your Latch activity — your sessions, stats, streaks, app-group selections, Screen Time app choices, and settings — is stored only on your device, inside a private container shared between the app and its widgets, and none of it is transmitted to us or to any third party.
The Focus tab shows you real per-app usage numbers from Apple's Screen Time. Those numbers are read and drawn inside a sandboxed component that has no network access. The only thing that ever crosses out of that sandbox is a small derived layout value — never your raw usage numbers — and none of it reaches us. See "Family Controls / Screen Time" below, which explains exactly where that line sits.
The one thing that uses the network is your purchase, which Apple handles entirely; those payment details never pass through us.
There is no sign-up, no sign-in, and no personal profile. You never give Latch a name, an email address, or any other identifying information beyond an optional display name you can type into Settings, which is used only to personalize the app's own greeting text and is never sent off your device.
Latch does not use any analytics, crash-reporting, or advertising SDKs. There are none in the app — not disabled ones, not optional ones. We do not know how often you open the app, which features you use, or anything else about your behavior. We do not collect this information or transmit it anywhere.
One clarification, so that claim isn't read as broader than it should be: Apple gives every developer aggregate App Store reports — download, sales, and subscription totals — and, separately, crash reports from users who have left "Share with App Developers" switched on in iOS Settings. That data comes from Apple, not from anything inside Latch; it is aggregated or anonymized by Apple before we ever see it, and it does not identify you. You can turn crash sharing off at any time in Settings → Privacy & Security → Analytics & Improvements.
Latch has no backend. All data — latch session history, streaks, weekly-goal progress, app-group definitions, and your settings — is written to an on-device App Group container (a private storage area shared only between the Latch app and its own widget and system extensions) using Apple's standard UserDefaults storage. No session, stats, streak, app-group, or settings data ever leaves your device over the network. The one exception is purchases, which are processed entirely by Apple — see "Subscriptions and purchases" below.
Latch uses Apple's Family Controls, Screen Time, and DeviceActivity frameworks for two things: to shield the apps you choose, and to show you the usage breakdown on the Focus tab. Those two work differently from each other, and the difference is worth spelling out.
Choosing apps to shield. When you pick apps using Apple's system picker, Latch receives only an opaque token representing your selection. It stores that token on your device so your selection persists between sessions, but the Latch app cannot decode the token into a list of which apps you picked or their names — that remains reserved to iOS.
The Focus tab. Your per-app usage is read and drawn by a separate, sandboxed component of Latch called a Screen Time report extension. Inside that sandbox, it can see app names, app identifiers, how long each app was used, how many times each was picked up, and the category each falls into, for the day you are looking at. That component has no network access, and the main Latch app cannot read your per-app usage back out of it — not by policy, but because Apple's framework is built so the extension can only draw those numbers to your screen and returns nothing to the app. This boundary is enforced by Apple's operating system, not by a promise we're making on top of it.
To lay out what it draws — for instance, how many rows to make room for on a given day — that component stores a small derived value, such as a count of apps used, in Latch's own private on-device storage, where the main app can read it back to size the screen correctly. That value carries none of the specifics behind it: no app names, no durations, no order, nothing you couldn't already see on the screen it's sizing. It stays on your device on exactly the same terms as the rest of Latch's data, described throughout this policy — it is not transmitted anywhere, by us or by anyone else.
How apps get sorted. The Focus tab groups your apps into "Distracting" and everything else. "Distracting" means any app or category you have chosen to block in Latch, plus a fixed, built-in list of commonly-distracting apps and the Social, Entertainment, and Games categories. That list ships inside the app and is the same for everyone — it is not a judgment derived from your behavior, nothing about how your apps were sorted is sent anywhere, and no profile of you is built from it.
Accuracy. The figures on the Focus tab are Apple's, not ours. Latch surfaces what Screen Time reports and has no way to verify or correct it.
App names, icons, and logos that appear within Latch — for example when you choose which apps to shield, or when the Focus tab shows your usage by app — are rendered directly by Apple's Screen Time frameworks from your own device. Latch's own code never receives, stores, or reproduces that image or name data — see "Choosing apps to shield" above. Those names, icons, and logos remain the trademarks or copyrighted works of their respective owners, and their appearance in Latch is solely to identify the apps you use; it does not imply any affiliation with, sponsorship by, or endorsement from those companies, or from Apple. "Screen Time," "Family Controls," and other Apple product names referenced in this policy are trademarks of Apple Inc.
Latch's on-device data is protected by iOS's app sandbox — other apps cannot read it — and by your device's own encryption, which is tied to your passcode or biometric unlock. We hold no copy of it anywhere, so there is no server of ours to breach.
One thing worth knowing, because it is the one place Latch's data can leave your phone: because that data lives in the app's own container, it is included in your device backups if you back up to iCloud or to a computer. Those backups are governed by Apple's privacy policy and your Apple ID, not by us, and we have no access to them. You can exclude Latch from iCloud backup in Settings → [your name] → iCloud → Manage Storage → Backups.
One item lives outside that container: a small counter tracking free Golden Latch trials is stored in your device's Keychain rather than the app's shared container (see "Data retention and deletion" below for why). Like other Keychain items it is included in encrypted local and computer backups, but it is not enabled for iCloud Keychain syncing, so it never roams to your other devices.
No method of storage is perfectly secure. A device that has been jailbroken or otherwise compromised may not protect app data the way iOS intends.
Latch schedules local, on-device notifications only — for example, to tell you when a latch session has completed. These are not push notifications and do not involve any notification server operated by us or anyone else.
Latch offers actions you can trigger from Siri, the Shortcuts app, and the Action Button — for example, "Start a Latch." Latch itself receives only the resolved action and its settings, such as a duration. If you trigger one by voice, the voice request is handled by Siri, which is Apple's, and may be processed on your device or on Apple's servers depending on your Siri settings; that processing is governed by Apple's privacy policy, not ours. We receive no recording, no transcript, and no record that you used Siri at all.
Latch Pro is offered as an auto-renewing monthly or yearly subscription, or a one-time lifetime purchase, through Apple's App Store. All payment processing, billing information, and receipts are handled entirely by Apple under Apple's own privacy policy — Latch's own code never receives, stores, or transmits your payment details. Latch only ever learns whether you currently hold an active entitlement (Pro or not, and which plan), not any billing information behind it. The yearly plan may include a free trial period; the monthly plan does not.
Everything above describes the app. Email is different, so it deserves saying plainly: if you write to us for support, to exercise a privacy right, or to raise a dispute, we necessarily receive your email address and whatever you choose to put in the message. That mail is handled by our email provider under its own privacy policy. We use it only to answer you, we don't add it to any mailing list — there isn't one — and we keep it only as long as we need it to deal with what you wrote about. Please don't send us anything sensitive that we don't need in order to help.
Because almost all of Latch's own data is stored only on your device, deleting the Latch app deletes that data along with it — there is no copy held by us anywhere else to separately request or wait on. (Your purchase and subscription record is kept by Apple, not by Latch, and is managed through your Apple ID; a device backup made before you deleted the app may still contain Latch's data until that backup is replaced or removed.) Within the app, Settings also offers ways to reset specific pieces of data — like your golden-ticket count or weekly-goal progress — without deleting the whole app. Your Focus tab usage figures themselves are never retained — the extension that reads them keeps nothing after the screen changes. The one exception is the small derived layout value described above (for example, a count of apps shown that day), which is deleted the same way as the rest of Latch's on-device data.
One deliberate exception to "deleting the app deletes the data": a small counter tracking how many free Golden Latch trials this device has used is stored in the device's Keychain rather than the app's own storage, specifically so that deleting and reinstalling Latch cannot be used to refill that free allowance. It records only a usage count — never anything that identifies you — and it is the one piece of Latch's data that intentionally survives an app deletion. It is not tied to your identity and cannot be looked up or reset by us; it is cleared only if you erase the device itself.
Latch collects no personal data from anyone, of any age, so there is nothing age-specific for us to disclose beyond what's already described above. Latch is not directed at children and we do not knowingly collect personal information from them — since we do not collect personal information from anyone. Consistent with COPPA, if you believe a child has somehow provided us with personal information — realistically, by emailing us — contact us at the address below and we will delete it.
The Terms of Service set out who may use Latch. If Latch is installed on a child's device managed through Family Sharing, Screen Time permission may be controlled by the family organizer rather than by the person using the phone; that arrangement is Apple's, and it doesn't change anything described in this policy.
Latch collects no personal data, runs no servers, and does not sell or share personal information — and has not sold or shared personal information in the preceding twelve months, under any definition of "sell" or "share" in the CCPA as amended. Because Latch holds no personal data about you anywhere outside your own device, there is nothing for us to access, export, correct, or delete in response to a rights request — deleting the app removes all of Latch's on-device data, as described above. (Purchase records held by Apple are governed by Apple's own privacy policy and your Apple ID.) Because there is no sale or sharing of personal information to opt out of, Latch does not provide a "Do Not Sell or Share My Personal Information" link; if that ever changes, this policy and the app will be updated to add one.
For the limited on-device processing Latch performs, and for any email you send us, Latch's developer (Keaton White) is the data controller. Where the UK or EU GDPR applies, our lawful basis is our legitimate interest in providing and supporting the app you asked for (Article 6(1)(f)) and, for handling a purchase or a support request you started, performance of a contract with you (Article 6(1)(b)). We do not process special-category data, we do not use your data for automated decision-making or profiling, and we ourselves do not transfer personal data internationally, because we hold none to transfer. The only data that leaves your device at all — Apple's aggregate App Store reports and the anonymized crash reports described under "No analytics, no telemetry, no third-party SDKs" above — is collected and processed by Apple directly, under Apple's own privacy policy, not by us, and does not identify you.
You have the right not to be discriminated against for exercising any of these rights. We offer no financial incentives in exchange for data, and we could not treat you differently for making a request even if we wanted to, because we cannot identify you.
If you are in the EU or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU it is the authority for your member state. We'd appreciate the chance to address your concern first — contact us at the address below.
Latch is made by one person. If it is ever sold, transferred, or merged into another business, what would transfer is the app and its future development — not a database of users, because there isn't one. Any personal data actually held at that time, which realistically means past support email, would transfer only subject to this policy, and we'd note the change here.
If this policy changes, we'll update the effective date above and, for any change that meaningfully affects how the app handles your data, call it out in the app's release notes.
Questions about this policy can be sent to keatnkeat3752@gmail.com.