PRIVACY POLICY.
Blocking runs on this iPhone. Untilt makes the covered apps and sites unavailable without seeing what you do. This page explains the limited aggregate counters, purchase data, and a migrated plan’s conditional schedule request that can leave the app.
What we collect
Manual-wall schedule, coverage state, settings, and history stay on your iPhone. The migrated-plan exception is described below.
What the app can send:
- Unlinked purchase history and subscription entitlement status, via Apple and our subscription provider (RevenueCat). RevenueCat uses this for subscription analytics and app functionality, including Customer History, Charts, Experiments, receipt validation, purchase restoration, and Pro entitlements. It is not linked to identity and is not used for tracking.
- For an installed user who still has an automatic plan migrated from an earlier build: the saved sport selection, a date range, and the iPhone’s IANA time-zone identifier, so the existing schedule can be refreshed. No Untilt account or installation identifier is attached.
- Six one-time product milestones: first run viewed, first hold begun, first wall started, first wall completed, first paywall viewed, and first purchase completed. Each request contains only the milestone name and app build number. It contains no account, installation, device, or session identifier and no wall details. The service immediately adds it to a build-level total instead of storing an individual event record.
- Install attribution, through AppsFlyer’s Strict SDK. When Untilt opens, the SDK reports the install and app session to AppsFlyer with an identifier that AppsFlyer generates for this installation, basic device information such as model, iOS version, app version, and language, and, if you installed from a creator or campaign link, the opaque campaign code carried by that link. Untilt reports one product event to AppsFlyer, the first wall started, with no wall details. AppsFlyer does not receive the advertising identifier (IDFA), the vendor identifier (IDFV), or your device name, and Untilt never requests App Tracking Transparency. RevenueCat forwards subscription events (start, renewal, cancellation) to AppsFlyer under the same installation identifier so we can see which campaigns lead to subscriptions.
Untilt has no account system, so there is no profile to build and nothing to sign in to. Release builds send no third-party crash diagnostics. The only installation identifier that leaves the phone is the one AppsFlyer generates for attribution, described above; it is never attached to Untilt’s own milestone counters. Untilt does not read page content, keystrokes, messages, bets, balances, browsing history, or Screen Time activity — it can only close the doors you asked it to close.
Anonymous analytics is on by default and can be turned off at any time in Settings. Turning it off stops future requests and clears milestones waiting on the phone. The switch controls Untilt’s own milestone counters; AppsFlyer attribution is part of the app and is not controlled by the switch. Cloudflare processes each network request to operate the counter, but Untilt stores no IP address or request log for it. Build-level totals are kept for up to 24 months.
New users cannot create an automatic sports plan. For a migrated plan, Untilt first requests schedule boundaries from its calendar service and may fall back to ESPN’s public scoreboard service. Those requests are used to answer in real time; Untilt stores no per-user request record, scores, odds, bets, or precise location.
Separately, this website (not the app) uses anonymous, cookieless Vercel analytics to count page views, referrers, campaign tags, and which on-site install button was clicked. It sets no cookies, and we do not attach an account, search term, invite code, or device identifier to those events. The visitor hash it uses resets every 24 hours. For a session that arrives through our paid Google Search campaign, the site also loads Google Ads conversion measurement and reports whether an App Store button was clicked. Google Consent Mode is initialized with advertising, analytics, user-data, and personalization storage denied, so Untilt does not grant Google permission to place those identifiers. Google can still receive a limited cookieless conversion request, including the page and ad-click context supplied by the browser, for measurement and modeling. Your phone’s wall activity never leaves the device — but visiting a web page is still a request your browser makes, so we say so plainly here.
How we use it
- Complete, load, and restore your Untilt Pro subscription.
- Refresh the dates of an existing automatic plan migrated from an earlier build.
- Measure the first-run and purchase funnel using build-level totals that cannot be connected to a person or installation.
- Measure which creator links and campaigns lead to installs, first walls, and subscriptions, through AppsFlyer.
Screen Time
Blocking is enforced by Apple’s Screen Time technology, on this iPhone. The permission works one way: it lets Untilt restrict the covered apps and websites, and it does not let Untilt read your Screen Time activity, app usage, or web history. Apple does not expose that data to us, and we collect none of it.
One documented side effect, disclosed rather than discovered: applying the web filter turns off Safari private browsing for the life of a wall. It returns when the wall ends.
Your rights
You can turn anonymous analytics off at any time in the app’s Settings. Turning it off stops future requests and clears milestones waiting on the phone. The service stores only aggregate totals, so it has no individual analytics record to access or selectively delete. You can also ask us to access, correct, export, or delete other data we hold. Because there is no account, that is typically limited to subscription records. Email support@tryuntilt.com.
Children
Untilt is for people 18 and older. We do not knowingly collect data from anyone under 18.
See also: Terms of Service