Privacy Policy
The app has no account and no sign-in, and almost everything it knows stays on your iPhone. One feature in the app sends anything anywhere, and this page names it. The one thing we ask you for is on this website, not in the app: the waitlist form, which takes an email address and nothing else.
01 The short version
- There is no account. The app never asks for your name, your email or a password, and there is no sign-in screen anywhere in it.
- The waitlist form on this website is the one place we ask for an email address. It buys you one email at launch and nothing else, and asking gets it deleted.
- Your alarms, streak, morning log, morning cards and onboarding answers are stored on your iPhone. There is no cross-device sync and no backup on our side in this version.
- The push-up mission looks at camera frames live, on the device. No video is recorded, stored or sent.
- The object hunt takes one photo, checks it on the device with Apple's Vision framework, and deletes it immediately. It is never uploaded and never saved to your photo library.
- The AI photo missions are the only feature that transmits anything. One photo goes to Anthropic's Claude to judge whether the mission was done. We do not keep it. You have to agree to that once, before the first photo ever, and you can withdraw that agreement in Settings.
- We run no advertising, no third-party analytics, and no tracking across other apps or websites. We do not sell or share your data.
02 Who we are
MissionAlarm is an iOS alarm clock made by GlitchedLab. This policy covers the MissionAlarm app (bundle identifier com.glitchedlab.missionalarm) and this website. The app has not shipped yet: it is written for the iPhone version being built, which will require iOS 26.1, and it will be updated rather than replaced when that version reaches people.
Contact for anything in this policy: support@missionalarm.app
03 The waitlist on this website
This website is the one place we ask you for anything. The waitlist form on the front page takes an email address, a one-word choice of iPhone or Android, and a note of which part of the page you submitted from. Nothing else is asked for and nothing else is kept: no name, no IP address, no cookie, no analytics identifier and no tracking pixel.
The form posts to our own server on this same domain. The row is appended to a file on that machine, readable only by us, and it exists for exactly one purpose: to send you one email when there is a build you can install. There is no newsletter, no drip sequence and no second message. Your address is not sold, shared, rented or handed to an advertising or analytics service. The choice of phone is counted only so we know how much the Android version is wanted.
Ask us at the address in Contact and your row is deleted, with no reason needed. It is deleted anyway once the launch email has been sent and the list has done its job.
The app itself has no waitlist, no email field and no sign-in screen. Everything from here on is about the app.
04 No account, no sign-in
MissionAlarm does not have user accounts. The app does not collect your name, your email address, your phone number, your date of birth or a password, because it never asks for any of them and has no screen on which you could give them. The only email address we ever hold is one you typed into the waitlist form on this website, covered in section 3, and it is never joined up with anything the app does.
On first launch the app creates a guest identifier on the device: a random string that exists only so the app's own local database can label rows as yours. It is not derived from your device, your Apple Account or anything about you, and it cannot be traced back to a person. Deleting the app and reinstalling produces a new one.
The app also generates a second random identifier, stored in the iOS Keychain, used only as a per-install pass for the AI verification endpoint described in section 7. It exists so that the free allowance and the abuse limits can be counted without knowing who you are. Neither identifier is a device fingerprint. MissionAlarm does not collect a device identifier, an advertising identifier, or any hardware fingerprint, and it does not attempt to recognise you across installs.
05 What stays on your device
The following live in the app's own storage on your iPhone and are not transmitted to us:
- Your alarms: time, repeat days, label, chosen sound and chosen missions.
- Your morning log: when an alarm fired, whether the mission was finished, skipped or stopped, how long it took, and the time zone it happened in.
- Your streak and your history.
- Your morning cards, including the generated images.
- The three onboarding diagnostic answers. These never leave the device. They are not written to any server, ours or anyone else's.
- Your settings: alarm defaults, the object-hunt pool, the evening reminder time, and whether you have given AI consent.
Because there is no account and no server-side copy, this version of MissionAlarm has no cross-device sync, no cloud backup and no restore of your history. If you delete the app, that data is gone. Your data may still be present in your own iPhone backup, which is made and encrypted by Apple under Apple's terms, not ours. The Streak tab has an "Export my history" control so you can keep a copy yourself.
06 The camera, mission by mission
MissionAlarm asks for camera access once, during onboarding, behind our own explanation of why. One grant feeds two different things, and they behave differently, so here is each one.
Push-ups — live, on device, nothing recorded
The push-up mission runs a camera session inside the app and passes each frame to Apple's Vision framework on the device to estimate body pose and count reps. No video or still image is recorded, saved or transmitted. Frames are held in memory only for as long as it takes to measure an elbow angle, and nothing about them leaves your iPhone. There is no server involved in counting a push-up.
Object hunt — one photo, checked on the phone, then deleted
The object hunt asks you to photograph a household object drawn at random. The photo is written to the app's temporary storage, handed to Apple's Vision image classifier on the device, and deleted immediately afterwards. It is never uploaded, never sent to us or to anyone else, and never written to your photo library. The mission works with no network connection at all. MissionAlarm requests no photo-library permission and ships no photo-library usage string, so there is no path from your saved photos into this check.
AI photo missions — the exception
These are the only feature that transmits an image. They are covered in full in the next section.
07 AI photo missions and Anthropic
The AI photo missions (make your bed, touch grass, find a pet) ask you to photograph something so it can be judged. That judgement is not done on your phone. It is done by Claude, an AI model made by Anthropic, and it requires sending your photo.
You have to agree first
Before the first AI photo is ever taken, the app shows a one-time consent screen that says exactly this and offers "Use a physical mission instead". If you decline, no photo is sent and the physical missions carry on working as normal. You can withdraw your consent at any time in Settings.
What is sent, and where it goes
- The photo is resized and re-encoded on your device before it goes anywhere. That re-encode strips the EXIF metadata, so the location, camera and timestamp data an image usually carries is removed before transmission.
- The photo is sent over an encrypted connection to our verification endpoint, along with which mission you are attempting and the per-install pass from section 4. Nothing else. No name, no email, no location, no device identifier.
- Our endpoint passes the photo to Anthropic's Claude with a short instruction describing what a passing photo looks like.
- Claude returns a pass or fail, a confidence number and a one-sentence reason. That is all that comes back to your phone.
What is kept
MissionAlarm does not keep your photo. It is not stored on our server and it is not written to a database or a log. Our server never logs image data.
Anthropic does retain it for a limited period. Anthropic retains API inputs and outputs for up to 30 days, longer only where content is flagged for safety review, and does not use them to train its models. We state this plainly rather than claim a deletion we do not control. Anthropic's own policy is here: anthropic.com/legal/privacy.
Point the camera at the bed, the grass or the pet, and at as little else as you can. If you would rather nothing left the phone at all, the push-up, shake, math and object-hunt missions never transmit anything, and they are free forever.
08 Purchases
MissionAlarm Pro is sold through the App Store. Apple processes the payment. We never see and never receive your card details, your billing address or your Apple Account credentials.
Subscription state is managed for us by RevenueCat, which tells the app whether Pro is active. RevenueCat receives the pseudonymous guest identifier from section 4, the purchase receipt information Apple provides, and basic platform metadata such as the app version and the operating system. It does not receive your name, your email address or any content from the app. RevenueCat's policy: revenuecat.com/privacy. Apple's: apple.com/legal/privacy.
Because purchases are held against your Apple Account rather than an account with us, Restore Purchases is how Pro follows you to a new phone. Your alarm history does not follow it in this version.
09 Notifications
Every notification MissionAlarm sends is scheduled locally on your device. There is no push server. We do not register for or store a push token, and no notification is ever sent to your phone from the internet.
The alarm itself is not a notification: it rings through Apple's alarm system, the same one the built-in Clock app uses, which is why it comes through silent mode and Do Not Disturb at your system alarm volume. The optional evening reminder is off unless you turn it on, and iOS only asks for notification permission at the moment you do.
10 Tracking, analytics and advertising
- No advertising, no ad networks, no ad identifier (IDFA).
- No third-party analytics or attribution SDKs.
- No tracking as App Tracking Transparency defines it. The app never asks for permission to track, because it does not.
- No data sold, and none shared for advertising or cross-context behavioural advertising.
- No social login, no embedded social SDK, no pixel.
The counts the app shows you, such as how many mornings you have finished, are computed on your phone from your own local data.
11 Our verification server
The AI photo check in section 7 is the only part of MissionAlarm that talks to a server of ours. When it runs:
- Your device's IP address is visible to our hosting provider for the duration of the request, as it is for any request to any website. We do not use it to build a profile of you.
- We keep a counter, keyed to the per-install pass, of how many successful verifications that install has used. It exists to run the free allowance and the daily Pro limit, and to stop the endpoint being abused.
- We never log the image, and no photo is written to storage on our side.
If you never use an AI photo mission, MissionAlarm never contacts a server of ours at all.
12 Children
MissionAlarm is not directed to children under 13, and we do not knowingly collect personal information from children under 13. There is no account to create and no profile to fill in, so there is very little to collect in the first place. If you believe a child has sent us something through the AI photo mission, write to support@missionalarm.app and we will act on it.
13 Your controls, including Delete my data
Delete my data
Settings contains a Delete my data control. It removes, from your device:
- Every alarm, including the ones scheduled with the system, so they stop ringing.
- Your entire morning log, your streak and your saved morning cards.
- Your onboarding diagnostic answers and your app settings.
- The guest identifier and the per-install AI pass.
Two honest limits. First, it does not cancel or refund a purchase: an active subscription lives with Apple, and cancelling is done in your App Store subscription settings. Second, if you previously used an AI photo mission, the copy Anthropic holds under its own retention window is outside our control once it has been sent, though we hold no copy ourselves. Deleting the app from your iPhone removes the same local data as the control does.
Everything else you can change
- Withdraw AI consent in Settings. No further photo is sent.
- Export my history in the Streak tab, so the data is yours to keep before you delete anything.
- Camera, alarm and notification permissions can be revoked at any time in the iOS Settings app. Revoking camera access swaps the affected mission for one that does not need it. Revoking alarm permission stops the alarms ringing, and the app will say so on the Home screen in red.
- Manage the object pool in Settings, if you would rather the app never asked you to photograph a particular room.
14 If you are in the EEA, the UK or California
You have rights over personal data about you: access, correction, deletion, portability, and objection to certain processing. Because MissionAlarm holds your data on your own device and identifies you only by a random string, the fastest way to exercise all of them is the app itself: Export my history gives you a portable copy, and Delete my data erases it.
For the small amount that touches our server, our lawful basis is your consent for the AI photo check, which you give explicitly and can withdraw, and our legitimate interest in keeping the endpoint from being abused for the rate-limit counter. For a waitlist address, the lawful basis is your consent, given by submitting the form; ask and we delete the row, and there is no other consequence because there is nothing else it is used for. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California law. Write to support@missionalarm.app with any request and we will answer it.
15 Changes to this policy
If this policy changes, the date at the top of this page changes with it, and the previous wording is replaced rather than quietly edited around. If a change materially affects what leaves your device, the app will tell you before it takes effect, and anything that requires consent will ask again rather than assume it.
16 Contact
Questions, requests, or something on this page that does not match what the app actually does: support@missionalarm.app. A person reads that inbox.