Privacy
What sesh collects, where it goes, and how to get rid of it. This page describes the sesh iPhone and Android apps.
The short version
sesh has no analytics SDK, no advertising, and no third-party trackers. Nothing is sold, and nothing is shared with advertisers or data brokers. The app collects what it needs to keep your record, put you on a leaderboard with people you have added as friends, and send the notifications you have switched on.
Two things are worth stating plainly rather than leaving you to find them further down.
Your profile photo is public
If you upload a profile photo it is stored in a public bucket. Anyone who has the file's web address can open it without signing in to sesh and without being your friend. The address is not published or listed anywhere, and the bucket cannot be browsed, but the file itself is not access-controlled. If that is not acceptable to you, do not add a photo. sesh works without one, and you can remove one you have already added.
On Android, app usage never leaves your phone
While a session is running, the Android app checks which app is in the foreground so it can hold the block up. That check happens on your phone, several times a second, and the result is never transmitted, stored on a server, or written to your session record. sesh cannot tell you which apps you opened during a session, because it never kept that. The only thing the record keeps is a count of how many times you hit the block screen. The iPhone app does not read foreground app data at all. Blocking there is done by Apple's Screen Time, which never reports your activity to sesh.
What sesh collects
Sign-in identity
You can sign in with Apple, with Google, or by having a code emailed to you. sesh never sees or stores a password, because it never asks for one.
- Which provider you used, and the account identifier that provider gives us.
- Your email address. If you use Sign in with Apple and choose Hide My Email, sesh only ever receives Apple's relay address, not your real one.
Your profile
- The display name you choose, up to 40 characters.
- The handle you choose, 3 to 20 characters.
- Your profile photo, if you add one. See the note above about it being public.
- The date your account was created.
Session history
One record per session, kept so your hours, streak and leaderboard position are real. Each record holds:
- When it started and when it ended.
- How long it ran, and how much of that time the block was verifiably applied. The second number is what counts toward the board.
- Your device's time zone and the local date it belongs to.
- How it ended: you ended it, it hit the maximum length, or it was interrupted.
- How many times you opened a blocked app during it. A count, never which app.
- The time of the last presence check. The time only. The check records that it happened, never what you were doing.
- Which of your devices it ran on.
A session record does not include the note you attach to a session, or which apps you chose to allow. Both stay on your phone. See the next section.
Daily totals
Your session records are rolled up into a per-day total: blocked time, blocks held, and number of sessions. This is the only session data anyone else can read, and only people you have confirmed as friends can read it.
Friends, invites and leagues
- Who you are friends with, and when each friendship was confirmed.
- Your invite code, when it was created, and who has redeemed it.
- Leagues you create or join: the league's name, which you type, plus its code and its member list.
- Anyone you block, and when. Blocking is not visible to the person blocked.
- Any report you file, including the reason you give, so it can be reviewed.
Devices and notifications
- An identifier for each install of sesh you sign in to, its platform, its time zone, and when it was last active. The time zone is what makes quiet hours land at the right time for you.
- A push notification token, so notifications can reach that device. The token is cleared whenever your operating system will not deliver notifications, and is removed when you sign out.
- Whether you have friend nudges and the weekly recap switched on.
Product interaction
sesh records three events, and only these three:
- app_opened: you opened the app.
- session_start_refused: a session could not start.
- session_discarded: a session was too short to keep.
Each carries the time it happened, your current streak length, your platform, and whether you were signed in. A refused start also carries the reason it was refused, and on iPhone the number of apps on your allowlist: the count, never which apps. These events exist to answer whether people who have friends keep using sesh, and how often sessions fail to start. They are never read back into your hours, and they are deleted with your account.
What never leaves your device
These are stored on your phone and are never uploaded, on either platform:
- The apps you pick to stay open during a session.
- Notes you attach to a session.
- Sessions you schedule in advance.
- On Android, every foreground app reading, as described above.
- On iPhone, your Screen Time app selections. Apple's system hands the app opaque tokens rather than app names, and sesh never sends them anywhere.
If you use sesh without signing in, your entire session history is local too. Nothing is uploaded until you create an account, and deleting the app deletes that history permanently.
What other people can see
Only people you have confirmed as friends can see anything, and they see:
- Your display name, handle and profile photo.
- Your daily and weekly totals (blocked hours, blocks held, session count) and where that puts you on the board.
- That you are currently in a session, and how long it has been running.
They cannot see which apps you block or allow, your notes, individual sessions, your email address, or your devices. Removing a friend is silent, and so is blocking someone.
Who else handles your data
sesh uses three providers, and no others.
- Supabase hosts the database, the sign-in system, the profile photo storage and the server code. Data is held in Supabase's Mumbai, India region, so if you are elsewhere your data is transferred there.
- Apple provides Sign in with Apple, and the Apple Push Notification service delivers notifications to iPhones.
- Google provides Google sign-in, and Firebase Cloud Messaging delivers notifications to Android phones. Firebase Cloud Messaging is the only Google service in the app. There is no Firebase Analytics and no crash reporting SDK.
A notification sent to you passes through Apple's or Google's servers on the way, and it contains the display name or handle of the friend it is about, plus a fixed line of text. Notifications carry an expiry of about an hour, so an undelivered one is discarded rather than stored.
How long it is kept
There is no automatic expiry. Everything above is kept for as long as your account exists, because your record is the product. A streak and a leaderboard mean nothing if the history behind them is quietly aged out.
Deleting your account deletes it. That is described in full on the account deletion page.
Age
sesh is intended for people aged 18 and over. It is not directed at children, and sesh does not knowingly collect data from anyone under 18. If you believe a child has created an account, write to the address below and it will be deleted.
Your choices
- Delete everything. In the app: You, then Settings, then Delete account, then hold for three seconds. Without the app: see the account deletion page.
- Remove your photo. You, then the settings icon, then your profile row, then Change photo, then Remove photo.
- Turn off notifications. Settings, then Friend nudges. You can also revoke notification permission in your phone's settings, which stops delivery to that device entirely.
- Kill an invite link that got out. Settings, then Privacy and safety, then Replace invite link.
- Get a copy of your data, or correct it. Write to the address below.
Changes to this page
If what sesh collects changes, this page changes with it and the date at the top moves. The date is the honest signal. If it has not moved, nothing here has.