Skip to main content

Privacy Policy

Effective: 2026-09-08 · Last updated: 2026-09-08

1. Overview

Shadow Sheep Labs LLC ("Shadow Sheep Labs," "we," "us," or "our") develops software applications. This Privacy Policy explains what data our applications may collect, how we use it, where it is stored, and the rights you have over your information.

Our core commitment: Your personal data stays on your device by default. Where cloud sync is used, data is encrypted before it leaves your device. We do not sell your data, use third-party analytics, or serve ads.

By using any Shadow Sheep Labs application, you agree to this Privacy Policy. If you do not agree, please discontinue use of our applications.

2. Scope

This policy applies to all software applications published by Shadow Sheep Labs LLC, and to this website (shadowsheeplabs.com). Where a specific application offers features that handle particular categories of data, the practices described below apply to those applications. Data practices specific to this website are described in Section 3.5.

3. Data We Collect

We only collect data necessary for the features you choose to use. Different applications handle different categories of data. All data is stored locally on your device by default.

Some applications also process data that Washington law defines as "consumer health data." Where that applies, we publish a separate Consumer Health Data Policy covering exactly what that means for that application.

3.1 Device Permissions

Where applicable, our applications may request access to system data such as health information, calendar events, contacts, location, microphone, photos, or similar device resources. Access is requested only with your explicit permission via standard operating-system prompts, and is used solely to provide the feature you have chosen to use.

Data accessed through these permissions is processed on your device. It is not transmitted to Shadow Sheep Labs servers.

3.2 User-Generated Content

Content you create within our applications is stored locally on your device. A subset of this content (such as preferences and settings) may be synced across your devices via your platform's native cloud-sync service. Any data synced in this way is encrypted before transmission (see Section 6).

3.3 Account Credentials

Where an application requires you to sign in to a third-party service, the credentials you provide are stored in your device's secure system keychain. They are not transmitted to Shadow Sheep Labs.

3.4 Per-Application Data Categories

The table below is generated from the canonical GDPR registry committed in this repository. It is the authoritative, application-by-application breakdown of what each app collects, the lawful basis for processing, where data is stored, retention, and sensitivity.

Shadow Sheep Calendar

CategoryLawful basisStorageRetentionSensitivity
Calendar events and reminders read through Apple EventKit. The events themselves live in your Apple Calendar / Reminders accounts; this app reads them with your permission and does not keep its own copy.ConsentApple frameworkUnknownStandard
Focus group assignments for calendars and individual events (which focus shields activate during which events).ContractiCloud (encrypted)UnknownStandard
Places discovered from your calendar event locations (categories, commute estimates) used for time-to-leave alerts and shared with the Focus app.ConsentiCloud (encrypted)UnknownSensitive — Location
Daily planner intentions and end-of-day notes you write in the morning planning and evening shutdown cards.ContractOn-device onlyUnknownStandard
Sleep schedule window read from Apple Health to shade sleep hours on the timeline. Sleep data stays in HealthKit; the app only displays it.ConsentApple HealthKitUnknownSensitive — Health
Recently used calendar subscription feed addresses (holiday and iCal feeds), kept so you can re-subscribe quickly.ContractOn-device onlyUnknownStandard
Generated weekly brief digests summarizing your upcoming week (schedule shape, highlights, optional weather hints).ContractiCloud (encrypted)UnknownStandard

Finance

CategoryLawful basisStorageRetentionSensitivity
Accounts you've added (name, type, starting balance) — manually entered.ContractiCloud (encrypted)UnknownStandard
Recurring bills you're tracking (name, amount, due date, frequency) — used to calculate what's available before your next paycheck. Tracking only; does not post a transaction itself.ContractiCloud (encrypted)UnknownStandard
Budget categories you've configured (name, icon, color, allocated amount) used to organize spending.ContractiCloud (encrypted)UnknownStandard
Debt balances you're tracking (name, balance, interest rate, minimum payment) and your preferred paydown method.ContractiCloud (encrypted)UnknownStandard
Savings goals you've created (name, target amount, current amount, optional target date).ContractiCloud (encrypted)UnknownStandard
Income sources you've added (name, amount, pay schedule).ContractiCloud (encrypted)UnknownStandard
Bank accounts you've linked via Plaid (account name, type, last 4 digits) and the access credentials used to reconnect to your bank. Off by default — nothing is linked until you explicitly connect an account in Settings.ConsentiCloud (encrypted)UnknownSensitive — Financial
Location-assisted payee suggestions: while you're editing an unclear transaction, Finance can ask a narrow on-device SheepKit service to suggest a payee name by correlating the transaction's timestamp with your existing Travel App location history. The service returns only a place name and a confidence score — never raw coordinates or your visit history — and nothing is auto-filled; you must explicitly confirm a suggestion before it becomes the transaction's payee. Nothing from this lookup is stored on the Finance side beyond the merchant name you confirm (already covered by Transaction history). Distinct purpose from, and does not reuse consent for, Travel's own Visited Places history. Off by default, toggled in Finance Settings > Advanced.ConsentOn-device onlyUnknownSensitive — Location
Manual corrections you've made to how a raw bank transaction description displays as a merchant name in "Where I Spent/Received" (raw description text mapped to your corrected name).ContractiCloud (encrypted)UnknownStandard
Your Finance app preferences (Overview layout, debt paydown method, whether cents are shown).ContractiCloud (encrypted)UnknownStandard
Recurring bill and income templates that automatically post a transaction when due (payee, amount, account, frequency, next due date).ContractiCloud (encrypted)UnknownStandard
Transaction history (date, amount, merchant/payee, category, cleared status) that you enter manually or import from a CSV file.ContractiCloud (encrypted)UnknownStandard
Learned transfer associations: once a transaction description has been identified as a transfer to/from one of your other tracked accounts, that association is remembered so future transactions with the exact same description resolve the same way (raw description text mapped to the other account).ContractiCloud (encrypted)UnknownStandard

Fitness

CategoryLawful basisStorageRetentionSensitivity
Apple Health activity data read to build the Today dashboard and the overnight workout-pattern summary: activity rings, steps, distance, active calories, exercise/stand time, body weight, heart rate variability, and workout history. Stays in HealthKit — this app never keeps its own copy of the raw samples.ConsentApple HealthKitUnknownSensitive — Health
Movement goal definitions you create in Fitness: name, HealthKit metric type (steps, distance, active calories, Move/Exercise ring) and target value, and linked Focus app groups. Progress toward a goal is derived from HealthKit data on-device and is never stored here. Also read by Focus App, which enforces app-blocking shields until a goal is met.ContractiCloud (encrypted)UnknownStandard

Shadow Focus

CategoryLawful basisStorageRetentionSensitivity
Communication and notification preferences, plus an optional medication window used only to pick safer default timing. Nothing about a diagnosis is stored — this is not the accommodation walkthrough's selection (see the separate shared 'Accommodation Choices' data category, which covers that). Stored only on this device and never sent to iCloud.ContractOn-device onlyUnknownSensitive — Health
Off unless you turn it on: counts of whether subscription screens and notifications work — shown, started, purchased, cancelled, opened, dismissed. Daily totals only, no identifiers, no prices or transaction details. Never leaves the device, kept for 90 days, erased when you turn the setting off.ConsentOn-device only[object Object] days rollingStandard
FamilyControls application tokens — the app selections per group. Device-specific by Apple API design; cannot be synced or transferred.ContractOn-device onlyUnknownStandard
Consent record for reading Apple Health sleep-analysis data, used to time the Sleep and Morning system schedules. The read itself does not happen until this is granted; withdrawing or deleting it stops future reads.ConsentOn-device onlyUnknownSensitive — Health
Body-doubling partner roster (name, contact reference, check-in preferences) and session defaults.ContractiCloud (encrypted)UnknownStandard
App group configurations (name, icon, color, block mode). The app selections themselves are device-specific FamilyControls tokens stored separately.ContractiCloud (encrypted)UnknownStandard
Learned patterns: location-to-group associations (synced to iCloud in encrypted form) and session duration predictions (on-device only). Neither derives from HealthKit. Wake-time inference from Apple Health sleep data is a separate category — see focus.wakeHistory, which needs (and requires) sleep-data consent; this category does not.Legitimate interestiCloud (encrypted)UnknownStandard
Location-based focus rules (place name, coordinates, radius, arrive/leave trigger settings).ContractiCloud (encrypted)UnknownSensitive — Location
Movement goal definitions (name, HealthKit metric type and target value, linked app groups). Progress toward a goal is derived from HealthKit data on-device and never leaves the device.ContractiCloud (encrypted)UnknownStandard
Time-based focus schedule definitions (name, start/end time, active days, group assignments).ContractiCloud (encrypted)UnknownStandard
Completed focus session history (session type, duration, group names, start and end timestamps).ContractiCloud (encrypted)UnknownStandard
Notification preferences, accountability lock setting, wind-down warning configuration, and sleep/wake schedule parameters.ContractiCloud (encrypted)UnknownStandard
Anonymous app statistics used to find and fix problems with the app itself: how often features are used, which onboarding step was reached, which permissions were granted or declined, how you move between screens, and where the app trips you up. Daily totals only — no identifiers, no timestamps finer than the day, no names or content of any kind. Never leaves the device. On by default; you can turn it off at any time, which also erases what was collected.Legitimate interestOn-device only[object Object] days rollingStandard
Wake-pattern history: a rolling window of about 90 confirmed wake events derived from Apple Health sleep data, used to time morning prompts. Stored only on this device and never sent to iCloud.ConsentOn-device only[object Object] days rollingSensitive — Health

Habits

CategoryLawful basisStorageRetentionSensitivity
Habit completion records (date, actual duration per session)ContractiCloud (encrypted)UnknownStandard
Habit definitions (name, icon, color, frequency, estimated duration, notes)ContractiCloud (encrypted)UnknownStandard
Habit consistency tracking entries (per-day completion status powering the heat map and analytics)ContractiCloud (encrypted)UnknownStandard
Habit group configurations (name, schedule, notification preferences, reward)ContractiCloud (encrypted)UnknownStandard

Habits Watch

CategoryLawful basisStorageRetentionSensitivity

Mail

CategoryLawful basisStorageRetentionSensitivity
Email cache (messages, drafts, snippets, saved searches)ContractOn-device onlyUnknownSensitive — Communications
Email cache iCloud mirror (CloudKit private database, iCloud.com.shadowsheeplabs.email default zone)ContractiCloud (encrypted)UnknownSensitive — Communications
Learned categorization rules and signaturesLegitimate interestOn-device onlyUnknownSensitive — Health
Inbox cleanup statistics and session history (KVS bucket Mail::, shared App Group)Legitimate interestiCloud (encrypted)UnknownStandard
Encrypted IMAP / SMTP / OAuth account credentials (Keychain, service EmailAppIMAP) and Sign in with Apple federated session (revoked via Apple's REST endpoint at deletion time)ContractiCloud (encrypted)UnknownSensitive — Communications
Package delivery and finance tracking recordsContractOn-device onlyUnknownSensitive — Financial
Travel itinerary records parsed from emailContractOn-device onlyUnknownStandard
Email workflow state (category rules and heuristics, signature centroids, cleanup and inbox-zero session bookkeeping, mail-merge follow-up sequences, saved excerpts, scheduled sends, AI action cards, AI tone and intent notes, and morning briefings)Legitimate interestOn-device onlyUnknownStandard

Meal Plan

CategoryLawful basisStorageRetentionSensitivity

Shadow Reminders

CategoryLawful basisStorageRetentionSensitivity
Photo attachments added to reminders. Stored encrypted on this device only, capped at six per reminder.ContractOn-device onlyUnknownStandard
On-device learning signals: completion patterns, layout-profile usage metrics, and AI priority training data. Aggregate counts only, never transmitted off device.Legitimate interestOn-device onlyUnknownStandard
List organization (sort preference, custom list color and icon).ContractiCloud (encrypted)UnknownStandard
Reminder metadata (energy levels, categories, task steps, tags, gentle titles). The reminders themselves live in Apple Reminders via EventKit; this is the neurodivergent overlay only.ContractiCloud (encrypted)UnknownStandard
Reusable reminder templates with pre-decomposed steps that you create or customize.ContractiCloud (encrypted)UnknownStandard

Shared (all apps)

CategoryLawful basisStorageRetentionSensitivity
The accommodations you picked, any defaults you've changed, your medication window, communication and notification preferences, and related on-device settings like font, motion, and sound preferences. Stored on this device only. Appears in every app's Data Management screen via SheepKitSharedDataCategories / SheepKitSharedExportCategories.ConsentOn-device onlyUnknownSensitive — Health
Crash reports stored in the shared App Group container and synced to iCloud, used to diagnose and fix problems with the app. Appears in every app's Data Management screen via SheepKitSharedDataCategories.Legitimate interestiCloud (encrypted)UnknownStandard
Learned locations, place categories, and visit history shared across apps (Focus, Calendar, AI Chat) to personalize suggestions. Appears in every app's Data Management screen via SheepKitSharedDataCategories.Legitimate interestiCloud (encrypted)UnknownSensitive — Location

Style

CategoryLawful basisStorageRetentionSensitivity

Travel

CategoryLawful basisStorageRetentionSensitivity
Calendar sync configuration (selected calendar, last sync time). Calendar events themselves live in your iOS Calendar and are removed when sync is disabled.ConsentiCloud (encrypted)UnknownStandard
Packing list templates (named packing lists you can reuse across trips)ContractiCloud (encrypted)UnknownStandard
Places derived from your photos (locations read from the EXIF data of photos in your own library, used to reconstruct where you have been)ConsentiCloud (encrypted)UnknownSensitive — Location
Visited places history (precise locations you have been, visit counts, ratings)ConsentiCloud (encrypted)UnknownSensitive — Location
Place ideas near your trips, derived from your ratings and favoritesLegitimate interestiCloud (encrypted)UnknownStandard
Prep checklist templates (named to-do lists you can reuse across trips)ContractiCloud (encrypted)UnknownStandard
Saved travelers (reusable traveler profiles — name, Known Traveler Number, loyalty program/number — you can apply across trips)ContractiCloud (encrypted)UnknownStandard
AI-detected trip suggestions derived from your place historyLegitimate interestiCloud (encrypted)UnknownStandard
Travel taste profile (a summary of place types and named places you enjoy, derived from your ratings, favorites, trips, and wishlist)Legitimate interestiCloud (encrypted)UnknownStandard
Considering (undated trip ideas you're thinking about, with optional notes)ContractiCloud (encrypted)UnknownStandard
Trip itinerary (trips, flights, hotels, saved places, confirmation codes, notes)ContractiCloud (encrypted)UnknownStandard
Want to Go places (places you saved as somewhere you'd like to visit, with optional notes)ContractiCloud (encrypted)UnknownStandard

Travel (Mac)

CategoryLawful basisStorageRetentionSensitivity
Calendar sync configuration (selected calendar, last sync time). Calendar events themselves live in your iOS Calendar and are removed when sync is disabled.ConsentiCloud (encrypted)UnknownStandard
Packing list templates (named packing lists you can reuse across trips)ContractiCloud (encrypted)UnknownStandard
Places derived from your photos (locations read from the EXIF data of photos in your own library, used to reconstruct where you have been)ConsentiCloud (encrypted)UnknownSensitive — Location
Visited places history (precise locations you have been, visit counts, ratings)ConsentiCloud (encrypted)UnknownSensitive — Location
Place ideas near your trips, derived from your ratings and favoritesLegitimate interestiCloud (encrypted)UnknownStandard
Prep checklist templates (named to-do lists you can reuse across trips)ContractiCloud (encrypted)UnknownStandard
Saved travelers (reusable traveler profiles — name, Known Traveler Number, loyalty program/number — you can apply across trips)ContractiCloud (encrypted)UnknownStandard
AI-detected trip suggestions derived from your place historyLegitimate interestiCloud (encrypted)UnknownStandard
Travel taste profile (a summary of place types and named places you enjoy, derived from your ratings, favorites, trips, and wishlist)Legitimate interestiCloud (encrypted)UnknownStandard
Considering (undated trip ideas you're thinking about, with optional notes)ContractiCloud (encrypted)UnknownStandard
Trip itinerary (trips, flights, hotels, saved places, confirmation codes, notes)ContractiCloud (encrypted)UnknownStandard
Want to Go places (places you saved as somewhere you'd like to visit, with optional notes)ContractiCloud (encrypted)UnknownStandard

Weather

CategoryLawful basisStorageRetentionSensitivity
Muted weather condition tokens and dismissed alert IDs (trauma-aware filter state, iCloud KVS keys: weather.mutedAlertConditions, weather.dismissedAlertIDs)Legitimate interestiCloud (encrypted)UnknownStandard
Weather display and notification preferences (sensory settings, unit choices, notification toggles — stored in iCloud KVS bucket Weather::)Legitimate interestiCloud (encrypted)UnknownStandard
User-saved named locations with place names and coordinates (iCloud KVS key: weather.savedLocations)ContractiCloud (encrypted)UnknownSensitive — Location

3.5 Website Analytics

This website uses self-hosted, cookieless analytics (Umami) that we run and control ourselves — not a third-party analytics platform. It records aggregate, non-identifying information about visits: which pages were viewed, the referring site, browser and operating system, device type, and country. It does not use cookies, does not assign you a persistent identifier, and does not track you across other websites. Visitor IP addresses are used momentarily to derive an approximate country and to compute a same-day-only visit count, and are not stored.

Requests to our self-hosted analytics collector are routed through Cloudflare's network, in the same way this website's hosting provider already routes every visitor's request to reach this site. Cloudflare's role here is network transport — like our hosting provider, its infrastructure necessarily handles the request in transit, but Cloudflare does not run its own analytics, advertising, or tracking on this data.

4. Data We Do Not Collect

We want to be explicit about what we do not do:

  • No behavioral analytics. We do not use Firebase, Mixpanel, Amplitude, Segment, or any behavioral analytics platform.
  • No third-party crash reporting. We do not send crash data to Crashlytics, Sentry, or any third-party crash service.
  • No advertising IDs. We do not access advertising-related identifiers.
  • No device fingerprinting. We do not collect device identifiers or any combination of data designed to uniquely identify your device.
  • No cross-app tracking. We do not track your activity across other companies' apps or websites.
  • No data brokering. We never sell, rent, or share your data with data brokers or advertisers.
  • No social-login data. We do not require or support social login.

5. How We Use Your Data

Data handled by our applications is used exclusively to provide the features you have chosen to use. We do not use your data to build advertising profiles, train models on external servers, or for any purpose unrelated to providing the functionality you have requested.

6. Storage & Security

6.1 On-Device Storage

The majority of your data is stored locally on your device using your platform's native persistence frameworks. This data is protected by the operating system's built-in data-protection features (encrypted at rest when your device is locked).

Sensitive credentials are stored in your device's secure system keychain.

6.2 Cloud Sync & Encryption

Where data is synced across your devices, it is encrypted using industry-standard authenticated encryption before it leaves your device. The encryption key material is held in your platform's end-to-end encrypted keychain, which Shadow Sheep Labs cannot access. This means we cannot decrypt your synced data even if compelled to do so.

7. Third-Party Services

7.1 Platform Services

Our applications use standard services provided by your device's operating system. Your use of these services is also governed by your platform vendor's privacy policy (for example, Apple's Privacy Policy).

7.2 Other Third Parties

Where a specific application integrates a third-party service in order to provide an opt-in feature you have chosen to use, that integration and any data handling associated with it will be disclosed within the application itself before you enable the feature. Shadow Sheep Labs does not retain copies of data exchanged with such third parties on its own servers.

Place-name lookups. When location features are on, naming a place you visited uses map lookups: Apple Maps, and for city and region boundaries OpenStreetMap's Nominatim service. These lookups send the coordinates being named — nothing else: no identifiers, no account information, and never your visit history. Your location history itself is stored on your device and in your own encrypted iCloud.

We do not use any third-party advertising networks, analytics platforms, or data brokers.

8. Children's Privacy

Our applications are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided personal information through our applications, please contact us at privacy@shadowsheeplabs.com and we will promptly delete any such information.

For users between 13 and 17, we recommend parental review of this policy before use.

9. Your Rights & Choices

9.1 Access & Deletion

Data stored by our applications is viewable and deletable from within the applications themselves. Deletion removes data from local storage and from any associated encrypted cloud sync. Data deleted in this way cannot be recovered.

The list below is generated from the canonical GDPR registry and reflects which rights each application supports per data category.

  • Shadow Sheep Calendar: 5 exportable, 5 erasable, 3 requiring explicit consent.
  • Finance: 12 exportable, 12 erasable, 2 requiring explicit consent.
  • Fitness: 1 exportable, 1 erasable, 1 requiring explicit consent.
  • Shadow Focus: 12 exportable, 14 erasable, 3 requiring explicit consent.
  • Habits: 4 exportable, 4 erasable.
  • Habits Watch: 0 exportable, 0 erasable.
  • Mail: 7 exportable, 8 erasable, 3 requiring explicit consent.
  • Meal Plan: 0 exportable, 0 erasable.
  • Shadow Reminders: 4 exportable, 5 erasable.
  • Shared (all apps): 1 exportable, 3 erasable, 1 requiring explicit consent.
  • Style: 0 exportable, 0 erasable.
  • Travel: 12 exportable, 12 erasable, 3 requiring explicit consent.
  • Travel (Mac): 12 exportable, 12 erasable, 3 requiring explicit consent.
  • Weather: 0 exportable, 3 erasable.

9.2 Revoke Permissions

You can revoke any device permission at any time in your device's system Settings. Revoking a permission disables the related feature but does not affect other application functionality.

9.3 Disable Cloud Sync

You can disable cloud sync for our applications in your device's system Settings. Disabling sync keeps your data entirely on-device.

9.4 California Residents (CCPA)

Under the California Consumer Privacy Act, California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@shadowsheeplabs.com.

9.5 European Users (GDPR)

If you are located in the European Economic Area, you have the right to access, rectify, erase, restrict processing, and port your personal data, as well as the right to object to processing. Because most data is stored locally on your device, you can exercise most of these rights directly within the applications.

To exercise GDPR rights for any data we may hold, contact us at privacy@shadowsheeplabs.com. We will respond within 30 days.

The legal basis for processing is: (a) performance of a contract (providing the features you requested), (b) your consent (for permissions such as health data or location), and (c) our legitimate interests (such as diagnosing and improving application stability).

10. Data Retention

Data is retained for as long as you use the applications and have not deleted it. When you delete an application from your device, locally stored data is removed. Encrypted data held in your platform's cloud-sync service persists until you delete it from within the application or delete your platform account.

We do not retain copies of your data on Shadow Sheep Labs servers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the applications.

Your continued use of our applications after changes are posted constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Shadow Sheep Labs LLC

Email: privacy@shadowsheeplabs.com

We aim to respond to all privacy inquiries within 5 business days.