Privacy
Privacy policy
Effective September 28, 2026.
Mialera works without an account, on iPhone and on Android. What you do in the app stays on your phone, with the exceptions explained below: the subscription, an anonymous usage measurement that tells us where the app gets in the way, the measurement of our ads and, only if you want it, an optional account to take your progress to another phone.
What stays on your phone only
- Your screen time and how much of each goal you used.
- Which apps you chose to limit.
- Your goals, focus sessions, saved templates and history.
- Bento’s wellbeing and your streak of days.
None of that content leaves your phone. On iPhone, Mialera reads your screen time through Apple’s Screen Time API, which hands the data to the app inside the device. On Android, it reads it from the system’s usage statistics, also inside the device. Neither we, nor Apple, nor Google get a copy because of Mialera. The measurements described below send quantities (how many goals exist, how many minutes a session lasted), never the text you wrote or which apps you block.
Android permissions
Android does not let one app block another on its own. To cover the apps you chose to limit, Mialera asks for three permissions and explains each one before you turn it on:
- Usage access: to measure how much time you spend in each app. The numbers stay on the device.
- Display over other apps: to show the pause screen on top of the app that reached its limit.
- Accessibility service: to know which app just opened. Mialera uses this API only to read the name of the app in the foreground. It is set up without access to screen content: it does not read what is on the screen, does not read what you type and does not tap anything for you. That name is used on the spot, to decide whether the pause screen shows up, and is not sent off the device.
So you can pick which apps to limit, Mialera lists the installed apps that have an icon on the home screen. That list is read on the device, only while the picker is open, and is not sent to anyone. You can turn any of these permissions off in Android Settings whenever you want; blocking stops, and the rest of the app keeps working.
What leaves the device: the subscription
If you subscribe to Mialera+, your phone’s store processes the purchase: Apple on iPhone, or Google Play on Android. We do not receive or keep your card, your name or your email.
To know whether your subscription is active, we use RevenueCat (RevenueCat, Inc., USA). What travels is:
- an anonymous identifier generated for the app, which is not your name or your email;
- the purchase receipt issued by the store and the subscription state (active, in trial, canceled);
- technical data the store reports, such as the account’s country and the app version.
We use this for one purpose only: unlocking Mialera+ for those who paid. We do not use this data for advertising and we do not sell it to anyone. RevenueCat’s policy is at revenuecat.com/privacy.
What leaves the device: usage measurement
To understand where the app confuses or gets in the way, we use PostHog (PostHog, Inc.), with the data hosted in the European Union. What travels is:
- a random identifier created at install, which is not your name, your email or an advertising identifier (deleting the app discards it for good);
- which screens you opened and which actions you took, such as creating a goal or starting a session, with the quantities involved (number of goals, session minutes) and never their content;
- technical device data: model, system version, language and app version;
- recordings of the app’s screen, with all text and all images masked: what shows is the shape of the screen and where you tapped, not what is written on it.
We use this for one purpose only: improving the app. We do not use it for advertising, we do not combine it with data from other apps or sites, and we do not sell it to anyone. PostHog’s policy is at posthog.com/privacy.
What leaves the device: measuring our ads
We promote Mialera with ads on Facebook and Instagram. To know which of them bring people who install and use the app, Mialera includes the Meta SDK (Meta Platforms, Inc.), which sends Meta:
- app events: the install, each app open, finishing the initial setup and purchases made through the store (amount and currency, with no payment data);
- technical device data: model, system version, language and app version;
- on Android, Google’s advertising ID. You can delete or reset it in Settings → Google → Ads, and Meta can no longer link the events to you;
- on iPhone, the app asks first, through iOS’s tracking permission. Mialera never reads Apple’s advertising identifier. If you decline, Meta only receives the events in a way that does not let it link them to you, and the measurement happens in aggregate.
None of this includes your screen time, your goals or which apps you block. Meta may combine these events with what it already knows about people who have a Facebook or Instagram account, under its own policy, at facebook.com/privacy/policy. On our side, we use the result for one purpose only: deciding which ads to invest in.
If you create an account
The account is optional and does one thing: it takes your progress and Mialera+ to another phone. Without it, nothing of yours is kept on a server of ours. You sign in with Apple, with Google or with a code sent by email; there is no password.
What the account keeps, on a server of ours:
- your email (or the relay address Apple creates if you hide yours) and an account identifier;
- your day streak, treats, the number of focus sessions and focus minutes;
- Bento's state;
- the history of goal days (kept, broken or unmeasured) and focus sessions, without the name of any app;
- an identifier of the phone using the account, because it works on one phone at a time.
These still never leave the device, with or without an account: which apps you use, your screen time, your goals and the selection of apps you limit.
Where it lives: the database is Supabase (Supabase, Inc.), hosted in São Paulo, Brazil, and requests go through Cloudflare (Cloudflare, Inc.). To send the sign-in code by email we use MillionSend (Codari Global, LLC, USA), which receives your address and keeps the email body for 30 days and the sending record (address, subject, status) for 365 days. With an account, RevenueCat uses the account identifier instead of the anonymous one, so Mialera+ works across iPhone and Android. None of this is used for advertising or sold.
Account data is kept until you delete the account, which you do in the app itself (Profile → Account → Delete account) or as the deletion page explains. Deletion erases the account and the backup right away; what is on your phone stays there. The legal basis is performing the service you asked for. The account is for people aged 13 and over.
What Mialera does not do
- It does not require an account. It is optional, and without one it asks for no email, phone number or password.
- It does not show ads inside the app.
- It does not read your screen content or what you type.
- It does not send off the device which apps you use or block. On iPhone, the selection is kept by iOS itself and Mialera only gets an opaque identifier from it; on Android, app names stay on the device.
- It does not sell or share data with data brokers.
Notifications
If you allow them, the app sends local reminders: goal alerts and the mascot’s daily note. Your phone creates and schedules these alerts, which do not go through a server or a push service.
This website
Cloudflare hosts the site, which uses no cookies or trackers. Cloudflare keeps technical access logs, like any host, for as long as security and the operation of the service require. Fonts come from Google Fonts, which receives the IP address of whoever loads the page.
Children
Mialera is not directed to children under 13, and we do not collect data from children.
Your rights
Without an account, the app keeps no personal data on a server of ours, and you handle access, correction and deletion requests on the device itself: deleting the app deletes everything, including the measurement’s random identifier. With an account, what it keeps is described above and is erased when you delete the account, in the app or through the deletion page. On Android, you can also delete the advertising ID in Settings; on iPhone, decline or revoke the tracking permission. Your subscription data stays with the store and RevenueCat, usage measurement with PostHog and ad events with Meta. For any request, write to contato@mialera.app.
Changes
If this policy changes, the date at the top changes with it. If we ever expand data collection, we will let you know before the change takes effect.
Mialera