Privacy
Privacy Policy
For the OffDuty iPhone app · Last updated 24 August 2026
You don't create an account with us. We never see your camera provider's password. We never collect your location, even though the app asks for the permission. We do collect anonymous usage and crash data to fix bugs. Every field is listed below, and you can switch it off in the app at any time.
This policy covers the OffDuty iPhone app, published by OffDuty Labs LLC ("we", "us"). It explains what the app collects, why, and what control you have. Our other apps have their own policies.
1. What we never collect
None of the following is transmitted to us, ever:
- Your camera provider password. Sign-in happens on your provider's own page. We never receive it.
- Your access token. The token your provider issues is stored in your iPhone's Keychain, protected by the device, and used only to talk to your provider directly.
- Your name or email. The app displays the name on your camera account, read straight from your provider. It stays on your device.
- Your location. No coordinates, no addresses, no places. See section 4.
- Video, images, or clips. Recordings stream from your provider to your phone. They never touch our servers.
- Contacts, photos, health data, or messages. The app never requests them.
We do not use advertising SDKs or third-party analytics services, we do not track you across other apps or websites, and we do not sell or share your data. There is no advertising identifier in OffDuty.
2. What we do collect
OffDuty sends anonymous usage and diagnostic events to our own server at
appevents.offdutylabs.com. This is how we find crashes and see which features
are actually used.
Every event carries this envelope
| event | The name of what happened, for example snooze_started |
|---|---|
| occurred_at | When it happened |
| app_version, build | Which version of OffDuty you're running |
| ios_version | Your iOS version, for example 18.4 |
| device_class | Your iPhone model identifier, for example iPhone16,2. Not a serial number and not unique to you |
| environment | Whether the event came from a production or test build |
| installation_id | A random identifier for this installation. See section 3 |
| properties | A few details specific to the event, listed below |
| correlation_id | Ties related events together, such as one snooze from start to expiry |
| camera_system | Which provider was involved, for example blink |
The complete list of events
This is all of them, with everything each one records. Nothing else is sent.
| Event | What it records |
|---|---|
app_opened | How the app was launched (cold start, from the background, by a shortcut, or woken by a button) |
app_backgrounded | Nothing beyond the envelope |
permission_status | Whether location and Bluetooth permissions are granted or denied |
button_press_detected | How the press was detected, the gesture, and whether the phone was locked |
button_press_suppressed | Why a press was ignored, such as a cooldown, and the cooldown length |
background_task_expired | Nothing beyond the envelope |
button_configured | Whether the button was set up with beacon wake-up |
button_removed | Nothing beyond the envelope |
settings_opened | Nothing beyond the envelope |
duplicate_press_protection_changed | Whether you turned it on or off |
configuration_lock_changed | Whether you locked or unlocked configuration |
ibeacon_monitoring_failed | The technical error reported by iOS |
notification_received, _viewed, _dismissed, _cta_tapped | Which in-app announcement, and whether you opened or dismissed it |
snooze_started | How many cameras were targeted, how many succeeded, and whether it extended an existing snooze |
snooze_extended | Minutes added and minutes remaining |
snooze_cancelled, snooze_expired | Nothing beyond the envelope |
api_request_failed | Which endpoint failed, the HTTP status, and the error type |
api_auth_expired | Nothing beyond the envelope |
crash_detected | Crash diagnostics from iOS: termination reason, exception type and code, signal |
hang_detected | How long the app was unresponsive |
cpu_exception_detected, disk_exception_detected | Processor time and disk writes reported by iOS |
Camera names, system names, clip contents, and account details never appear in any event.
3. About the installation ID
The installation_id is a random identifier generated the first time you open
the app and kept in the app's own storage. It exists so we can tell "one person hit this
crash fifty times" apart from "fifty people did."
- It is generated on your device and is not derived from anything about you or your iPhone.
- It is not Apple's advertising identifier and cannot be linked to one.
- It is not shared with anyone and is meaningless outside our own database.
- Deleting the app erases it. Reinstalling produces a brand-new one, with no connection to the old.
Because this identifier is attached to your events, Apple's privacy labels classify that data as "linked to you," and we've declared it that way. We think the description above is more useful than the label.
4. Location, and why the app asks for it
Only if you add a physical button. If you use OffDuty as most people do, tapping in the app, asking Siri, or using the home-screen shortcut, the app never requests location permission at all. Nothing in this section applies to you.
Adding a Bluetooth button changes that, and it deserves a straight explanation, because on its face it looks like more access than a camera-snoozing app should need.
iOS does not let an app be woken by a nearby Bluetooth beacon through Bluetooth APIs alone when the phone is locked. The only mechanism Apple provides is beacon region monitoring, which lives behind the location permission. OffDuty registers the identifier of your button and asks iOS to wake it when that identifier appears.
No coordinates are read, stored, or transmitted. The app never asks iOS where you are, and no location data of any kind appears in any event listed in section 2. What we learn is "that button was pressed," not where you were.
5. Turning analytics off
Analytics are on by default. To switch them off, open OffDuty's settings and turn off Share Anonymous Analytics under Privacy.
It takes effect immediately. Nothing further is sent, and queued events are discarded. Every feature of the app keeps working. The setting stays off until you change it.
6. Where the data goes
Events are received by a Cloudflare Worker and stored in a Postgres database hosted by Supabase. Both act as processors for us, under their own security and privacy commitments; neither has any right to use your data for their own purposes.
| Cloudflare, Inc. | Receives and routes events; serves this website |
|---|---|
| Supabase, Inc. | Stores events |
Your camera provider, Blink, operated by Amazon, is not our processor. When you connect your account, your phone talks to them directly under their privacy policy, not ours.
As with any internet request, our servers necessarily see the IP address your phone connects from in order to respond. IP addresses are not stored with events and are not part of our database.
7. How long we keep it
Analytics events are retained for up to 24 months and then deleted. Because events carry no name, email, or account identifier, we generally cannot connect them to a person even if we wanted to.
8. Your choices and rights
- Stop collection at any time using the setting in section 5.
- Erase your identifier by deleting the app.
- Request deletion of past events by emailing us. Events carry no name, email, or account details, so we locate them by installation ID alone. Write to us and we'll tell you how to supply it.
- Ask what we hold for your installation, and we'll tell you.
Depending on where you live, you may have additional rights over personal data under laws such as the GDPR or the CCPA. We honor these requests regardless of where you live. Write to the address in section 11. We do not sell personal information and never have.
9. Children
OffDuty is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has, contact us and we'll delete it.
10. Changes to this policy
If we change what the app collects, we'll update this page and move the date at the top. Material changes will also be announced in the app. Previous versions are available on request.
11. Contact
OffDuty Labs LLC
support@offdutylabs.com
Questions about this policy are welcome, including skeptical ones.