Privacy policy
Last updated 9 October 2026. Hagiazomai is made by John Larson, as part of Ordinary Means.
The short version
Hagiazomai has no accounts, no ads and no analytics. Your rules stay on your phone. What your partners are told is encrypted on your phone before it leaves, and we cannot read it. We run no server.
What stays on your phone
- Your rules, limits and downtime. The apps and categories you choose are held as tokens that iOS gives the app; Hagiazomai never learns their names.
- The results of the app's own checks, and its log of changes, such as a filter turning off or the phone's clock being moved.
- A count of the times you tapped Close on a blocked app. The app does not know which app it was.
- Your encryption keys, in the iPhone's Keychain. They never leave the device.
What leaves your phone, and who can read it
Alerts and check-ins to your partners. If you pair with a partner, the app sends alerts, a regular check-in, and your display name and optional photo to that partner. Each of these is encrypted on your phone with a key that only your phone and your partner's phone hold. They are stored in Apple's iCloud (CloudKit), in a database belonging to this app.
We cannot read their contents, and neither can Apple. What is stored unencrypted with each record is a random identifier for the pair, the kind of record, which side of the pair wrote it, whether it should cause a notification, and the time. CloudKit also associates each record with an identifier for your iCloud account that is specific to this app; it is not your Apple Account, name or email address, and we do not use it to identify you.
An alert says that something happened, for example that the DNS filter turned off or that a rule was loosened. It never contains the name of an app, a category, a website, a search, or how long anything was used. The app does not have that information to send.
Website lookups, sent by iOS to the DNS filter. When you turn on the DNS filter in Settings, your iPhone sends the names of the sites it looks up to CleanBrowsing, the filtering service, over an encrypted connection. This is done by iOS, not by the app, and Hagiazomai never sees those lookups. CleanBrowsing's handling of them is described in its own privacy policy. If we ever change the filtering service, this policy will change in the same release.
A test of the filter. About every half hour, and whenever the app runs, Hagiazomai looks up the address of www.google.com and of Google's SafeSearch host and compares the two, to tell whether the filter is working. These are ordinary lookups, handled like any other on your phone. Only the result, filtered or not, and the time are kept, and only a change is sent to your partners, encrypted like every other alert.
What we do not collect
- No email address, phone number or account.
- No browsing history, app usage or location.
- No analytics, advertising identifiers or third-party tracking code.
- No crash reports of our own. If you have chosen to share diagnostics with app developers in iOS, Apple may pass us anonymous crash reports.
Permissions the app asks for
- Screen Time access, to apply the web filter, your rules, limits and downtime on your own device.
- DNS settings, to save the filter's configuration. You switch it on yourself.
- Notifications, for a reminder to check in and for alerts about people you are a partner to.
- Camera, only to scan a partner's pairing code. Nothing is recorded or stored.
- Photos, only for a picture you choose as your profile photo.
Keeping and deleting
Deleting the app removes everything it stored on your phone and every restriction it applied. Unlinking a partner in the app deletes the records your phone wrote for that pair from iCloud and tells the other phone, which then removes its own. If you want records removed and no longer have the app, write to us and we will delete what we can identify from the details you give.
Children
Hagiazomai is for adults restricting their own devices. It is not directed at children and has no features for managing a child's device.
Changes and contact
If this policy changes, the date at the top changes with it. Questions: john@jjlarson.com.