MONK

Privacy Policy

App: Monk

Provider: Stoic AS, organisation number 926 193 880

Contact: [email protected]

Effective date: 7 September 2026

In short

Monk works offline without an account. Your practice stays on your iPhone unless you explicitly
choose cloud sync. Cloud sync is unticked by default and is not required to use the app. We do not
sell personal data, show advertising, track you, or collect product-interaction analytics or
developer diagnostics.

On-device use

Without cloud sync, Monk stores the following only on your device:

elapsed history, and settings

The private practice record, including rescued unreadable copies, is encrypted using a key that
stays on this device. These files and the widget snapshot are marked excluded from device backups.
A device-only key does not migrate to another iPhone, so recover there using optional Monk cloud
sync or an explicit Monk export. This update cannot remove copies in earlier device backups.

Exports contain your readable practice data. Their temporary working files are protected and
removed after the share sheet closes; the destination you choose controls any further storage or
sharing. A support recovery export may also contain damaged or encrypted files that require help
to interpret. Monk preserves recovery copies when replacing an unreadable record rather than
silently discarding them.

Deleting Monk removes its local files. Reset progress clears the active local practice from
within the app; previously rescued recovery copies remain available for support until the app's
local files are removed.

New Health imports retain sample identifiers so an explicit deletion returned by Health can correct
Monk's copied totals. Earlier imports have no source identifiers and remain independently saved in
Monk until you delete them here. The new format begins at the next calendar midnight after the
accepted history is reconciled. Empty queries or denied read access never erase saved minutes.
Health can stop retaining old deletion records, so Monk may miss a deletion after a long absence.
These identifiers and intervals are protected like the rest of your practice record.

Optional cloud sync and explicit consent

Before any practice data is uploaded, Monk shows an unticked consent choice explaining what cloud
sync stores and where. If you choose it, Monk records the consent time and policy version. Existing
accounts must reconfirm when the consent policy changes before further uploads.

Cloud sync stores the following with Supabase in Stockholm, Sweden:

reflections, mood, and notes

does not upload your raw Health database or unrelated Health data

reporter and reported account identifiers, shared-item identifier, relevant shared text, selected
reason, submission time, moderation decision and review time

These records are linked to your account and may reveal sensitive matters, including information
about health, beliefs, addiction, sexuality, or other private commitments. Cloud sync is provided
only after your explicit choice and is used solely to provide account authentication, backup,
cross-device sync, private challenges, export, support, and deletion.

Sign in with Apple provides an Apple user identifier and an email address, which can be Apple's
private relay address. We use them only for account functionality and support, never marketing.
Monk also stores Apple's authorization tokens encrypted on the server to check whether your Apple
authorization remains valid and revoke it when you delete your account. These tokens are not
available through the app's database access and are removed with your cloud account.

Shared content and moderation

Monk checks shared display names, challenge titles and shared habit names against a text filter.
Your private practice history, Health entries and private notes are not copied into reports or
used for shared-text moderation. When you deliberately report a shared item, the server selects
only its relevant shared text and sends it with your selected reason to a private moderation queue.
Stoic AS uses these records to investigate abuse and decide whether to hide content or restrict
social features. Ordinary users cannot read the queue or see who reported or blocked them.

Blocking stores the two account identifiers and the blocked person's display name so you can
manage your list. Reports and moderation restrictions remain linked to the relevant accounts while
those accounts exist. Deleting either account involved in a report or block removes that linked
report or block from the live database. Contact support if you want to discuss or correct a report
or moderation decision.

App Privacy inventory

For App Store privacy disclosure, Monk's complete developer-collected data inventory is:

Each category is linked to the account, used only for App Functionality, and never used for
tracking. Monk does not developer-collect Purchase History, Location, Product Interaction,
advertising data, or Diagnostics. Apple processes the App Store purchase; Stoic AS does not receive
your payment details or purchase history. MetricKit diagnostics remain on the device unless you
deliberately export and send information to support.

Device permissions

before the system permission request. Access can be changed in iOS Settings.

strict phone fasts. App and website selections stay in Apple's Screen Time system and are not
uploaded. Monk uploads no attempted-app or website history.

are rounded to whole degrees before the coarse region is cached on your device for future sunset
calculations. Monk does not retain precise coordinates or upload location.

Processors and international handling

Stoic AS is the data controller for optional cloud data. Resend delivers moderation alerts to our operator, containing only a report identifier, category and submission time, with a link to the private queue. Shared text, names, private practice records and Health records are not included in these alerts. Supabase provides authentication, database,
Edge Functions, and hosting as our processor in Stockholm, Sweden. Apple separately processes Sign
in with Apple, App Store purchases, HealthKit, Screen Time, and notifications under Apple's terms.

We do not use advertising networks, third-party analytics, or tracking SDKs, and we do not sell data
or build marketing profiles.

Retention and account deletion

Active cloud data is kept while your account exists. In **Settings → Account & data → Delete account
and cloud data**, Monk requires a fresh Sign in with Apple confirmation, requests revocation of
Monk's Apple authorization, hard-deletes the Supabase Auth user, and removes all linked live database
rows. The app reports account deletion only after both Auth deletion and database cascades are
verified. If Apple authorization cannot be revoked automatically, Monk still deletes the account and
provides Apple's instructions for manually removing the authorization.
An unconfirmed deletion preserves your local record and shows a retry or support route; a partial
server deletion may already have ended the cloud session.

Deleted data can remain temporarily in encrypted disaster-recovery backups until the processor's
configured backup rotation expires. Those backups are isolated from ordinary processing and are used
only for service recovery; deleted records are removed again if restoration is required. We may keep
only records required by law.

Your rights and choices

You may keep all data on-device, export your local Monk record, sign out, withdraw consent by deleting
the cloud account, or reset local progress. Depending on applicable law, you may request access,
correction, deletion, restriction, objection, or portability. Contact us to exercise these rights.
You may complain to Datatilsynet or your local supervisory authority.

Children

Monk is not directed at children under 13 and does not knowingly collect their information.

Changes

The current policy is posted at https://monkhabits.app/privacy. Material changes to cloud processing
or consent will be shown in the app before further uploads.

Contact

Stoic AS

Vulkan 10, 0178 Oslo, Norway

Organisation number 926 193 880

[email protected]