sesh

Privacy

What sesh collects, where it goes, and how to get rid of it. This page describes the sesh iPhone and Android apps.

Last updated 17 August 2026
Joseph Leung, sole developer of sesh

The short version

sesh has no analytics SDK, no advertising, and no third-party trackers. Nothing is sold, and nothing is shared with advertisers or data brokers. The app collects what it needs to keep your record, put you on a leaderboard with people you have added as friends, and send the notifications you have switched on.

Two things are worth stating plainly rather than leaving you to find them further down.

Your profile photo is public

If you upload a profile photo it is stored in a public bucket. Anyone who has the file's web address can open it without signing in to sesh and without being your friend. The address is not published or listed anywhere, and the bucket cannot be browsed, but the file itself is not access-controlled. If that is not acceptable to you, do not add a photo. sesh works without one, and you can remove one you have already added.

On Android, app usage never leaves your phone

While a session is running, the Android app checks which app is in the foreground so it can hold the block up. That check happens on your phone, several times a second, and the result is never transmitted, stored on a server, or written to your session record. sesh cannot tell you which apps you opened during a session, because it never kept that. The only thing the record keeps is a count of how many times you hit the block screen. The iPhone app does not read foreground app data at all. Blocking there is done by Apple's Screen Time, which never reports your activity to sesh.

What sesh collects

Sign-in identity

You can sign in with Apple, with Google, or by having a code emailed to you. sesh never sees or stores a password, because it never asks for one.

  • Which provider you used, and the account identifier that provider gives us.
  • Your email address. If you use Sign in with Apple and choose Hide My Email, sesh only ever receives Apple's relay address, not your real one.

Your profile

  • The display name you choose, up to 40 characters.
  • The handle you choose, 3 to 20 characters.
  • Your profile photo, if you add one. See the note above about it being public.
  • The date your account was created.

Session history

One record per session, kept so your hours, streak and leaderboard position are real. Each record holds:

  • When it started and when it ended.
  • How long it ran, and how much of that time the block was verifiably applied. The second number is what counts toward the board.
  • Your device's time zone and the local date it belongs to.
  • How it ended: you ended it, it hit the maximum length, or it was interrupted.
  • How many times you opened a blocked app during it. A count, never which app.
  • The time of the last presence check. The time only. The check records that it happened, never what you were doing.
  • Which of your devices it ran on.

A session record does not include the note you attach to a session, or which apps you chose to allow. Both stay on your phone. See the next section.

Daily totals

Your session records are rolled up into a per-day total: blocked time, blocks held, and number of sessions. This is the only session data anyone else can read, and only people you have confirmed as friends can read it.

Friends, invites and leagues

  • Who you are friends with, and when each friendship was confirmed.
  • Your invite code, when it was created, and who has redeemed it.
  • Leagues you create or join: the league's name, which you type, plus its code and its member list.
  • Anyone you block, and when. Blocking is not visible to the person blocked.
  • Any report you file, including the reason you give, so it can be reviewed.

Devices and notifications

  • An identifier for each install of sesh you sign in to, its platform, its time zone, and when it was last active. The time zone is what makes quiet hours land at the right time for you.
  • A push notification token, so notifications can reach that device. The token is cleared whenever your operating system will not deliver notifications, and is removed when you sign out.
  • Whether you have friend nudges and the weekly recap switched on.

Product interaction

sesh records three events, and only these three:

  • app_opened: you opened the app.
  • session_start_refused: a session could not start.
  • session_discarded: a session was too short to keep.

Each carries the time it happened, your current streak length, your platform, and whether you were signed in. A refused start also carries the reason it was refused, and on iPhone the number of apps on your allowlist: the count, never which apps. These events exist to answer whether people who have friends keep using sesh, and how often sessions fail to start. They are never read back into your hours, and they are deleted with your account.

What never leaves your device

These are stored on your phone and are never uploaded, on either platform:

If you use sesh without signing in, your entire session history is local too. Nothing is uploaded until you create an account, and deleting the app deletes that history permanently.

What other people can see

Only people you have confirmed as friends can see anything, and they see:

They cannot see which apps you block or allow, your notes, individual sessions, your email address, or your devices. Removing a friend is silent, and so is blocking someone.

Who else handles your data

sesh uses three providers, and no others.

A notification sent to you passes through Apple's or Google's servers on the way, and it contains the display name or handle of the friend it is about, plus a fixed line of text. Notifications carry an expiry of about an hour, so an undelivered one is discarded rather than stored.

How long it is kept

There is no automatic expiry. Everything above is kept for as long as your account exists, because your record is the product. A streak and a leaderboard mean nothing if the history behind them is quietly aged out.

Deleting your account deletes it. That is described in full on the account deletion page.

Age

sesh is intended for people aged 18 and over. It is not directed at children, and sesh does not knowingly collect data from anyone under 18. If you believe a child has created an account, write to the address below and it will be deleted.

Your choices

Changes to this page

If what sesh collects changes, this page changes with it and the date at the top moves. The date is the honest signal. If it has not moved, nothing here has.