Privacy · en-US
Privacy, in plain language.
Session keeps scan content on your iPhone, separates analytics choice from purchases and marketing, and limits third-party services to the jobs described here.
Last updated: July 24, 2026
What Session stores on your device
Session stores the product state needed to run your workflows, including alarms, reminder history, consent choices, normalized scan results, and the status of any Session-owned shield. It also creates a random, non-guessable identifier and stores it in the iOS Keychain. The identifier is not your email, provider username, Apple advertising identifier, or provider account name.
Camera and on-device scans
Camera access is requested only when you choose a Usage Screen Scan. Session uses the image and on-device OCR to interpret a supported coding-agent usage screen. The raw image, OCR text, prompts, code, and provider account data are not sent to PostHog, RevenueCat, or a Session server. Normalized values may remain on your device so Session can confirm the reminder you created.
A scan can be rejected when it is ambiguous, stale, unsupported, or missing required information. You can deny camera access and use a manual Reminder Only path where available.
Purchases and entitlement checks
Session uses RevenueCat’s iOS SDK to load subscription options, make or restore purchases through Apple, and verify the current Session Pro entitlement. RevenueCat receives the random Session identifier plus purchase and subscription information needed for those functions. Session does not receive your full payment-card details.
RevenueCat is always-on functional commerce when valid configuration exists. Purchases and entitlement checks continue independently of your product measurement choice or Marketing Email Consent.
Your product analytics choice
Session uses the PostHog iOS SDK for privacy-minimal product analytics and feature evaluation when valid production configuration exists. Product analytics starts enabled without an upfront opt-in. You can use the persistent opt-out independently of your subscription and Marketing Email Consent; an explicit opt-out is honored before later SDK startup.
Session may record bounded events such as app opens, purchase or restore outcomes, reminder creation or cancellation, and completion outcomes. Reviewed screen, lifecycle, feature-flag, safe-interaction, and sanitized error surfaces may also be enabled. Allowed properties use fixed categories, counts, versions, locale, or a one-way alarm identifier hash. Session Replay and session recording remain disabled and out of scope. Scan images, OCR text, email, provider account data, prompts, code, raw URLs, and arbitrary errors are prohibited from analytics payloads.
Attribution, ATT, and marketing consent
IDFA-free AppsFlyer attribution and deep linking start when their production configuration is valid. An explicit Product Measurement opt-out stops future AppsFlyer collection and identity use; on the website it also bypasses OneLink and uses the direct verified App Store destination. The current stack uses no ATT or IDFA.
Marketing Email Consent is separate, starts unchecked, and controls only marketing email. It does not enable product measurement, attribution, purchases, or core product access.
Notifications and conditional Focus Lock
Notification permission lets Session call you back at a confirmed time. If a later release separately qualifies Focus Lock and you authorize Family Controls, Session may store Apple-issued selections and apply a Screen Time shield to the apps, websites, or categories you select. Session cannot control the iPhone lock screen or clear restrictions owned by Apple, another app, or system policy. Reminder Only does not shield apps.
This website
This base static route package does not yet load PostHog or construct AppsFlyer OneLink URLs. When valid production measurement configuration is deployed, website product analytics starts from the first page view with the same persistent opt-out, bounded data rules, and Session Replay disabled. Opted-out download clicks use the direct verified App Store destination. Cloudflare may process ordinary request information needed to deliver and protect these pages.
The support form shown on this site is a disabled interface preview. It does not send or store a name, email, message, or other form value. No website form asks for Usage Screen Scan content, OCR text, prompts, code, provider credentials, receipts, or payment information.
Retention, deletion, and choices
Local product state remains on your device until it is cleared through the app or removed by the operating system. The Keychain identity can follow iOS Keychain retention behavior. RevenueCat and PostHog retain data under their service policies and Session’s configured account controls. You can keep the Product Measurement opt-out enabled without losing the ability to manage a purchase.
For a privacy question or deletion request, use the Session support route. Do not attach scan images, OCR output, code, prompts, credentials, or payment information to a public request.
Scope and changes
This policy covers the United States en-US launch release. Verified OneLink routing and website measurement activate only under the rules above. Web2App checkout, web claims, referrals, Promotional Access, Loops signup, popups, banners, and non-en-US surfaces are not enabled in this launch package. If Session materially changes its data practices, this page will be revised before the new behavior is represented as available.