Rewired Privacy Policy

Effective date: September 25, 2026
Last updated: September 25, 2026

This Privacy Policy explains how Primal Patchwork ("we," "us," "our") collects, uses, and shares information when you use the Rewired mobile app (the "App"). It also explains your choices and rights. If you have questions, contact us at [email protected] or at the address in the Contact Us section below.

By using Rewired, you agree to this Policy. If you don't agree, please don't use the App.

1. Information We Collect

a) Information you provide directly

  • Account & sign-in. You can sign in using Google or Apple, or create an account with an email address and password. With Google/Apple sign-in we receive a unique account identifier and, depending on what you allow, your email address and name. If you use Sign in with Apple, you can choose Apple's private email relay, in which case we receive a relay address rather than your real email. If you sign up with email and password, the password is handled by our authentication provider (Supabase Auth) and stored only in securely hashed form — we never see or store your plain-text password.
  • Your content. The habits, tasks, rewards, categories, goals ("mega rewards"), and related settings you create, along with your progress history (completions, coin/gem balances, streaks).

b) Information collected automatically

  • Device & technical data. Device type, operating system and version, screen size, and the App version and build.
  • Usage & analytics data. We record events when you use key features — for example opening the App, signing in or out, completing a habit, spinning the reward wheel, creating or redeeming a reward, setting up or triggering a block, editing a reward's exchange rate, skipping the tutorial, or requesting account deletion — along with the time, platform and App version. Some of these events are stored in our own database (Supabase); others are sent to our analytics provider, PostHog (see Section 4). Analytics events are linked to your Rewired account ID and your account email address so we can understand how the App is used over time. Analytics does not record your screen, your keystrokes, or the text of your habits and tasks.
  • Location. We do not collect your location. We have configured our analytics provider not to store IP addresses or derive location from them.
  • Diagnostics/crash data. We do not use a third-party crash-reporting service. If the App crashes, diagnostic information may be reviewed directly by our developer through Apple's or Google's own developer tools (e.g. TestFlight, Play Console) to fix problems.
  • Sync data. Sync timestamps used to reconcile your data between your device and the cloud.
  • Notifications. Reminders and alerts are scheduled locally on your device. We do not collect device push tokens and do not send server-driven push notifications.

c) App-blocking / Screen Time information (feature-specific)

Rewired's optional reward mechanic can restrict and temporarily unblock other apps. How this works differs by platform:

  • iOS (Apple Screen Time / Family Controls). When you choose which apps to restrict, Apple's system returns opaque tokens — Rewired stores these to enforce blocks but cannot read them as human-readable app names, and this selection is not transmitted off your device to us. Blocking is enforced by Apple's on-device frameworks.
  • Android (Usage Access). To enforce blocks, the App uses the Usage Access permission to detect which app is currently in the foreground and a display-over-other-apps permission to show the block screen. This foreground-app information is used only locally on your device to enforce the block and is never transmitted to our servers or any third party.
  • Blocking events. We record that a block was set up, started or re-applied (with the time, platform and App version) so we can check that blocking works reliably. These events do not include which apps you block.

d) On-device features (no data collected by us)

  • Biometric app lock. You can optionally lock the App behind Face ID, Touch ID, or your device's fingerprint/biometric unlock. Authentication happens entirely on your device through Apple's or Google's system frameworks — we never receive, see, or store any biometric data.
  • Photo library. With your permission, the App can save images (e.g. collected reward images) to your photo library. This is add-only: we do not read, scan, or upload your existing photos.
  • Data import/export. You can export your habit data to a file and import it back. These files are created and read locally on your device.

e) Sensitive information

Rewired is a general habit tracker and does not intentionally collect sensitive categories of data (health, biometric, precise location, etc.), and we do not analyze, categorize, profile, or target based on the content of what you write. However, the habits you write are free text and could describe health, religious, or other sensitive topics if you choose to enter them. Because this content is optional and entirely within your control, we treat it as ordinary account content. If you'd prefer not to store sensitive personal details in a cloud-synced database, you can simply avoid entering them as habit/task names.

2. How We Collect Information

  • Directly from you — when you sign in and create content.
  • Automatically — through the App and its underlying services (Expo, secure token storage, and our analytics provider PostHog) as you use it.
  • From platform providers — Google and Apple provide sign-in identity when you use those sign-in options.

3. How We Use Information

  • Provide the App — authenticate you, store and sync your habits/rewards across your devices, and run the reward/blocking mechanic.
  • Deliver reminders — send the notifications you enable.
  • Maintain and improve — diagnose crashes, fix bugs, and understand which features are used so we can improve them.
  • Measure reliability and engagement — for example, whether blocks re-apply on time, where new users get stuck during setup, and whether people keep using the App over weeks. We look at this data in aggregate and, when investigating a bug or reliability problem, for individual accounts.
  • Security & integrity — protect against fraud, abuse, and unauthorized access, and keep accounts separate (we wipe local data on sign-out to prevent cross-account data leakage).
  • Legal compliance — meet our legal obligations.

We do not use your information for advertising, and we do not sell it. We will not use your information for materially new purposes without updating this Policy and, where required, obtaining your consent.

4. Data Sharing and Third Parties

We do not sell your personal information. We share it only with service providers who process it on our behalf, and only as needed:

  • Supabase — cloud database, authentication, sync, and first-party event logging. Hosted on AWS in Oregon, USA.
  • PostHog — product analytics (usage events, device data, account ID and email). Data is processed in PostHog's US cloud.
  • Google — Sign-in.
  • Apple — Sign-in; on-device Screen Time frameworks.
  • Expo — app delivery and updates.
  • Legal authorities — if required by valid legal process, or to protect rights, safety, and security.

5. Where Your Information Is Processed

Your information is processed in the United States, where our database provider (Supabase, hosted on AWS in Oregon, USA) and our analytics provider (PostHog, US cloud) store your data.

6. Data Retention and Deletion

  • Account & content data — retained while your account is active.
  • Analytics data — kept for up to 1 year, or until you delete your account, whichever comes first.
  • Deleting your account — you can delete your account from inside the App, or by emailing [email protected]. Deleting your account permanently removes your account record, all associated content (habits, tasks, rewards, balances), and the analytics data linked to your account, from our database and our analytics provider, within 30 days.
  • Diagnostic/crash logs — we do not operate an automated crash-reporting pipeline. Crash reports, if any, are accessed through Apple's and Google's own developer tools and are governed by those platforms' retention policies, not by us directly.
  • Backups — we do not currently maintain scheduled database backups.

7. Your Rights

Depending on where you live, you may have the right to:

  • Access a copy of your data;
  • Correct inaccurate data;
  • Delete your data ("right to be forgotten");
  • Export/port your data in a portable format;
  • Restrict or object to certain processing, including analytics;
  • Opt out of marketing and, where applicable, of "sharing" for cross-context advertising;
  • Withdraw consent at any time (without affecting prior processing);
  • Lodge a complaint with your local data protection authority.

To exercise any of these, email [email protected]. We will respond within the timeframe required by applicable law (generally 30–45 days). We will not discriminate against you for exercising your rights.

8. Cookies, Analytics and Tracking

Rewired is a mobile app and does not use traditional website cookies. It uses on-device storage (local storage and secure token storage) that is strictly necessary to keep you signed in and hold your data. It also includes the PostHog analytics SDK, which stores a random identifier on your device so usage events can be linked to your account, as described in Section 1(b). We do not use advertising identifiers (IDFA/GAID) and we do not track you across other companies' apps or websites. If we add any advertising or cross-app tracking technologies in the future, we will request consent where required and update this section.

9. Security

We protect your information with measures including: encrypted transport (HTTPS/TLS) to our cloud and analytics providers, secure on-device storage of authentication tokens (device keystore/secure enclave), access controls on our backend, and clearing local data on sign-out to isolate accounts. No system is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

Rewired is intended for users 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data, contact us and we will delete it.

11. Contact Us

  • Company: Primal Patchwork
  • Privacy contact: [email protected]
  • Postal address: 2100 S Bascom Ave, Ste 1 #506, Campbell, CA 95008

12. Changes to This Policy

We may update this Policy. If changes are material, we will notify you (e.g. in-app or by email) before they take effect and, where required, give you a choice. The "Last updated" date at the top always reflects the current version.

13. Additional Provisions

  • No sale or sharing of data. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as defined under the CCPA/CPRA.
  • Third-party services. Sign-in providers, our analytics provider, app stores, and OS-level features (Apple Screen Time, Android usage access) are governed by their own privacy policies, which we don't control.
  • Governing law. This Policy is governed by the laws of the State of California, USA, without regard to conflict-of-laws principles.