Privacy Policy
Effective: 2026-09-08 · Last updated: 2026-09-08
1. Overview
Shadow Sheep Labs LLC ("Shadow Sheep Labs," "we," "us," or "our") develops software applications. This Privacy Policy explains what data our applications may collect, how we use it, where it is stored, and the rights you have over your information.
Our core commitment: Your personal data stays on your device by default. Where cloud sync is used, data is encrypted before it leaves your device. We do not sell your data, use third-party analytics, or serve ads.
By using any Shadow Sheep Labs application, you agree to this Privacy Policy. If you do not agree, please discontinue use of our applications.
2. Scope
This policy applies to all software applications published by Shadow Sheep Labs LLC, and to this website (shadowsheeplabs.com). Where a specific application offers features that handle particular categories of data, the practices described below apply to those applications. Data practices specific to this website are described in Section 3.5.
3. Data We Collect
We only collect data necessary for the features you choose to use. Different applications handle different categories of data. All data is stored locally on your device by default.
Some applications also process data that Washington law defines as "consumer health data." Where that applies, we publish a separate Consumer Health Data Policy covering exactly what that means for that application.
3.1 Device Permissions
Where applicable, our applications may request access to system data such as health information, calendar events, contacts, location, microphone, photos, or similar device resources. Access is requested only with your explicit permission via standard operating-system prompts, and is used solely to provide the feature you have chosen to use.
Data accessed through these permissions is processed on your device. It is not transmitted to Shadow Sheep Labs servers.
3.2 User-Generated Content
Content you create within our applications is stored locally on your device. A subset of this content (such as preferences and settings) may be synced across your devices via your platform's native cloud-sync service. Any data synced in this way is encrypted before transmission (see Section 6).
3.3 Account Credentials
Where an application requires you to sign in to a third-party service, the credentials you provide are stored in your device's secure system keychain. They are not transmitted to Shadow Sheep Labs.
3.4 Per-Application Data Categories
The table below is generated from the canonical GDPR registry committed in this repository. It is the authoritative, application-by-application breakdown of what each app collects, the lawful basis for processing, where data is stored, retention, and sensitivity.
Shadow Sheep Calendar
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Calendar events and reminders read through Apple EventKit. The events themselves live in your Apple Calendar / Reminders accounts; this app reads them with your permission and does not keep its own copy. | Consent | Apple framework | Unknown | Standard |
| Focus group assignments for calendars and individual events (which focus shields activate during which events). | Contract | iCloud (encrypted) | Unknown | Standard |
| Places discovered from your calendar event locations (categories, commute estimates) used for time-to-leave alerts and shared with the Focus app. | Consent | iCloud (encrypted) | Unknown | Sensitive — Location |
| Daily planner intentions and end-of-day notes you write in the morning planning and evening shutdown cards. | Contract | On-device only | Unknown | Standard |
| Sleep schedule window read from Apple Health to shade sleep hours on the timeline. Sleep data stays in HealthKit; the app only displays it. | Consent | Apple HealthKit | Unknown | Sensitive — Health |
| Recently used calendar subscription feed addresses (holiday and iCal feeds), kept so you can re-subscribe quickly. | Contract | On-device only | Unknown | Standard |
| Generated weekly brief digests summarizing your upcoming week (schedule shape, highlights, optional weather hints). | Contract | iCloud (encrypted) | Unknown | Standard |
Finance
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Accounts you've added (name, type, starting balance) — manually entered. | Contract | iCloud (encrypted) | Unknown | Standard |
| Recurring bills you're tracking (name, amount, due date, frequency) — used to calculate what's available before your next paycheck. Tracking only; does not post a transaction itself. | Contract | iCloud (encrypted) | Unknown | Standard |
| Budget categories you've configured (name, icon, color, allocated amount) used to organize spending. | Contract | iCloud (encrypted) | Unknown | Standard |
| Debt balances you're tracking (name, balance, interest rate, minimum payment) and your preferred paydown method. | Contract | iCloud (encrypted) | Unknown | Standard |
| Savings goals you've created (name, target amount, current amount, optional target date). | Contract | iCloud (encrypted) | Unknown | Standard |
| Income sources you've added (name, amount, pay schedule). | Contract | iCloud (encrypted) | Unknown | Standard |
| Bank accounts you've linked via Plaid (account name, type, last 4 digits) and the access credentials used to reconnect to your bank. Off by default — nothing is linked until you explicitly connect an account in Settings. | Consent | iCloud (encrypted) | Unknown | Sensitive — Financial |
| Location-assisted payee suggestions: while you're editing an unclear transaction, Finance can ask a narrow on-device SheepKit service to suggest a payee name by correlating the transaction's timestamp with your existing Travel App location history. The service returns only a place name and a confidence score — never raw coordinates or your visit history — and nothing is auto-filled; you must explicitly confirm a suggestion before it becomes the transaction's payee. Nothing from this lookup is stored on the Finance side beyond the merchant name you confirm (already covered by Transaction history). Distinct purpose from, and does not reuse consent for, Travel's own Visited Places history. Off by default, toggled in Finance Settings > Advanced. | Consent | On-device only | Unknown | Sensitive — Location |
| Manual corrections you've made to how a raw bank transaction description displays as a merchant name in "Where I Spent/Received" (raw description text mapped to your corrected name). | Contract | iCloud (encrypted) | Unknown | Standard |
| Your Finance app preferences (Overview layout, debt paydown method, whether cents are shown). | Contract | iCloud (encrypted) | Unknown | Standard |
| Recurring bill and income templates that automatically post a transaction when due (payee, amount, account, frequency, next due date). | Contract | iCloud (encrypted) | Unknown | Standard |
| Transaction history (date, amount, merchant/payee, category, cleared status) that you enter manually or import from a CSV file. | Contract | iCloud (encrypted) | Unknown | Standard |
| Learned transfer associations: once a transaction description has been identified as a transfer to/from one of your other tracked accounts, that association is remembered so future transactions with the exact same description resolve the same way (raw description text mapped to the other account). | Contract | iCloud (encrypted) | Unknown | Standard |
Fitness
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Apple Health activity data read to build the Today dashboard and the overnight workout-pattern summary: activity rings, steps, distance, active calories, exercise/stand time, body weight, heart rate variability, and workout history. Stays in HealthKit — this app never keeps its own copy of the raw samples. | Consent | Apple HealthKit | Unknown | Sensitive — Health |
| Movement goal definitions you create in Fitness: name, HealthKit metric type (steps, distance, active calories, Move/Exercise ring) and target value, and linked Focus app groups. Progress toward a goal is derived from HealthKit data on-device and is never stored here. Also read by Focus App, which enforces app-blocking shields until a goal is met. | Contract | iCloud (encrypted) | Unknown | Standard |
Shadow Focus
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Communication and notification preferences, plus an optional medication window used only to pick safer default timing. Nothing about a diagnosis is stored — this is not the accommodation walkthrough's selection (see the separate shared 'Accommodation Choices' data category, which covers that). Stored only on this device and never sent to iCloud. | Contract | On-device only | Unknown | Sensitive — Health |
| Off unless you turn it on: counts of whether subscription screens and notifications work — shown, started, purchased, cancelled, opened, dismissed. Daily totals only, no identifiers, no prices or transaction details. Never leaves the device, kept for 90 days, erased when you turn the setting off. | Consent | On-device only | [object Object] days rolling | Standard |
| FamilyControls application tokens — the app selections per group. Device-specific by Apple API design; cannot be synced or transferred. | Contract | On-device only | Unknown | Standard |
| Consent record for reading Apple Health sleep-analysis data, used to time the Sleep and Morning system schedules. The read itself does not happen until this is granted; withdrawing or deleting it stops future reads. | Consent | On-device only | Unknown | Sensitive — Health |
| Body-doubling partner roster (name, contact reference, check-in preferences) and session defaults. | Contract | iCloud (encrypted) | Unknown | Standard |
| App group configurations (name, icon, color, block mode). The app selections themselves are device-specific FamilyControls tokens stored separately. | Contract | iCloud (encrypted) | Unknown | Standard |
| Learned patterns: location-to-group associations (synced to iCloud in encrypted form) and session duration predictions (on-device only). Neither derives from HealthKit. Wake-time inference from Apple Health sleep data is a separate category — see focus.wakeHistory, which needs (and requires) sleep-data consent; this category does not. | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Location-based focus rules (place name, coordinates, radius, arrive/leave trigger settings). | Contract | iCloud (encrypted) | Unknown | Sensitive — Location |
| Movement goal definitions (name, HealthKit metric type and target value, linked app groups). Progress toward a goal is derived from HealthKit data on-device and never leaves the device. | Contract | iCloud (encrypted) | Unknown | Standard |
| Time-based focus schedule definitions (name, start/end time, active days, group assignments). | Contract | iCloud (encrypted) | Unknown | Standard |
| Completed focus session history (session type, duration, group names, start and end timestamps). | Contract | iCloud (encrypted) | Unknown | Standard |
| Notification preferences, accountability lock setting, wind-down warning configuration, and sleep/wake schedule parameters. | Contract | iCloud (encrypted) | Unknown | Standard |
| Anonymous app statistics used to find and fix problems with the app itself: how often features are used, which onboarding step was reached, which permissions were granted or declined, how you move between screens, and where the app trips you up. Daily totals only — no identifiers, no timestamps finer than the day, no names or content of any kind. Never leaves the device. On by default; you can turn it off at any time, which also erases what was collected. | Legitimate interest | On-device only | [object Object] days rolling | Standard |
| Wake-pattern history: a rolling window of about 90 confirmed wake events derived from Apple Health sleep data, used to time morning prompts. Stored only on this device and never sent to iCloud. | Consent | On-device only | [object Object] days rolling | Sensitive — Health |
Habits
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Habit completion records (date, actual duration per session) | Contract | iCloud (encrypted) | Unknown | Standard |
| Habit definitions (name, icon, color, frequency, estimated duration, notes) | Contract | iCloud (encrypted) | Unknown | Standard |
| Habit consistency tracking entries (per-day completion status powering the heat map and analytics) | Contract | iCloud (encrypted) | Unknown | Standard |
| Habit group configurations (name, schedule, notification preferences, reward) | Contract | iCloud (encrypted) | Unknown | Standard |
Habits Watch
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Email cache (messages, drafts, snippets, saved searches) | Contract | On-device only | Unknown | Sensitive — Communications |
| Email cache iCloud mirror (CloudKit private database, iCloud.com.shadowsheeplabs.email default zone) | Contract | iCloud (encrypted) | Unknown | Sensitive — Communications |
| Learned categorization rules and signatures | Legitimate interest | On-device only | Unknown | Sensitive — Health |
| Inbox cleanup statistics and session history (KVS bucket Mail::, shared App Group) | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Encrypted IMAP / SMTP / OAuth account credentials (Keychain, service EmailAppIMAP) and Sign in with Apple federated session (revoked via Apple's REST endpoint at deletion time) | Contract | iCloud (encrypted) | Unknown | Sensitive — Communications |
| Package delivery and finance tracking records | Contract | On-device only | Unknown | Sensitive — Financial |
| Travel itinerary records parsed from email | Contract | On-device only | Unknown | Standard |
| Email workflow state (category rules and heuristics, signature centroids, cleanup and inbox-zero session bookkeeping, mail-merge follow-up sequences, saved excerpts, scheduled sends, AI action cards, AI tone and intent notes, and morning briefings) | Legitimate interest | On-device only | Unknown | Standard |
Meal Plan
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|
Shadow Reminders
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Photo attachments added to reminders. Stored encrypted on this device only, capped at six per reminder. | Contract | On-device only | Unknown | Standard |
| On-device learning signals: completion patterns, layout-profile usage metrics, and AI priority training data. Aggregate counts only, never transmitted off device. | Legitimate interest | On-device only | Unknown | Standard |
| List organization (sort preference, custom list color and icon). | Contract | iCloud (encrypted) | Unknown | Standard |
| Reminder metadata (energy levels, categories, task steps, tags, gentle titles). The reminders themselves live in Apple Reminders via EventKit; this is the neurodivergent overlay only. | Contract | iCloud (encrypted) | Unknown | Standard |
| Reusable reminder templates with pre-decomposed steps that you create or customize. | Contract | iCloud (encrypted) | Unknown | Standard |
Shared (all apps)
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| The accommodations you picked, any defaults you've changed, your medication window, communication and notification preferences, and related on-device settings like font, motion, and sound preferences. Stored on this device only. Appears in every app's Data Management screen via SheepKitSharedDataCategories / SheepKitSharedExportCategories. | Consent | On-device only | Unknown | Sensitive — Health |
| Crash reports stored in the shared App Group container and synced to iCloud, used to diagnose and fix problems with the app. Appears in every app's Data Management screen via SheepKitSharedDataCategories. | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Learned locations, place categories, and visit history shared across apps (Focus, Calendar, AI Chat) to personalize suggestions. Appears in every app's Data Management screen via SheepKitSharedDataCategories. | Legitimate interest | iCloud (encrypted) | Unknown | Sensitive — Location |
Style
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|
Travel
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Calendar sync configuration (selected calendar, last sync time). Calendar events themselves live in your iOS Calendar and are removed when sync is disabled. | Consent | iCloud (encrypted) | Unknown | Standard |
| Packing list templates (named packing lists you can reuse across trips) | Contract | iCloud (encrypted) | Unknown | Standard |
| Places derived from your photos (locations read from the EXIF data of photos in your own library, used to reconstruct where you have been) | Consent | iCloud (encrypted) | Unknown | Sensitive — Location |
| Visited places history (precise locations you have been, visit counts, ratings) | Consent | iCloud (encrypted) | Unknown | Sensitive — Location |
| Place ideas near your trips, derived from your ratings and favorites | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Prep checklist templates (named to-do lists you can reuse across trips) | Contract | iCloud (encrypted) | Unknown | Standard |
| Saved travelers (reusable traveler profiles — name, Known Traveler Number, loyalty program/number — you can apply across trips) | Contract | iCloud (encrypted) | Unknown | Standard |
| AI-detected trip suggestions derived from your place history | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Travel taste profile (a summary of place types and named places you enjoy, derived from your ratings, favorites, trips, and wishlist) | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Considering (undated trip ideas you're thinking about, with optional notes) | Contract | iCloud (encrypted) | Unknown | Standard |
| Trip itinerary (trips, flights, hotels, saved places, confirmation codes, notes) | Contract | iCloud (encrypted) | Unknown | Standard |
| Want to Go places (places you saved as somewhere you'd like to visit, with optional notes) | Contract | iCloud (encrypted) | Unknown | Standard |
Travel (Mac)
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Calendar sync configuration (selected calendar, last sync time). Calendar events themselves live in your iOS Calendar and are removed when sync is disabled. | Consent | iCloud (encrypted) | Unknown | Standard |
| Packing list templates (named packing lists you can reuse across trips) | Contract | iCloud (encrypted) | Unknown | Standard |
| Places derived from your photos (locations read from the EXIF data of photos in your own library, used to reconstruct where you have been) | Consent | iCloud (encrypted) | Unknown | Sensitive — Location |
| Visited places history (precise locations you have been, visit counts, ratings) | Consent | iCloud (encrypted) | Unknown | Sensitive — Location |
| Place ideas near your trips, derived from your ratings and favorites | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Prep checklist templates (named to-do lists you can reuse across trips) | Contract | iCloud (encrypted) | Unknown | Standard |
| Saved travelers (reusable traveler profiles — name, Known Traveler Number, loyalty program/number — you can apply across trips) | Contract | iCloud (encrypted) | Unknown | Standard |
| AI-detected trip suggestions derived from your place history | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Travel taste profile (a summary of place types and named places you enjoy, derived from your ratings, favorites, trips, and wishlist) | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Considering (undated trip ideas you're thinking about, with optional notes) | Contract | iCloud (encrypted) | Unknown | Standard |
| Trip itinerary (trips, flights, hotels, saved places, confirmation codes, notes) | Contract | iCloud (encrypted) | Unknown | Standard |
| Want to Go places (places you saved as somewhere you'd like to visit, with optional notes) | Contract | iCloud (encrypted) | Unknown | Standard |
Weather
| Category | Lawful basis | Storage | Retention | Sensitivity |
|---|---|---|---|---|
| Muted weather condition tokens and dismissed alert IDs (trauma-aware filter state, iCloud KVS keys: weather.mutedAlertConditions, weather.dismissedAlertIDs) | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| Weather display and notification preferences (sensory settings, unit choices, notification toggles — stored in iCloud KVS bucket Weather::) | Legitimate interest | iCloud (encrypted) | Unknown | Standard |
| User-saved named locations with place names and coordinates (iCloud KVS key: weather.savedLocations) | Contract | iCloud (encrypted) | Unknown | Sensitive — Location |
3.5 Website Analytics
This website uses self-hosted, cookieless analytics (Umami) that we run and control ourselves — not a third-party analytics platform. It records aggregate, non-identifying information about visits: which pages were viewed, the referring site, browser and operating system, device type, and country. It does not use cookies, does not assign you a persistent identifier, and does not track you across other websites. Visitor IP addresses are used momentarily to derive an approximate country and to compute a same-day-only visit count, and are not stored.
Requests to our self-hosted analytics collector are routed through Cloudflare's network, in the same way this website's hosting provider already routes every visitor's request to reach this site. Cloudflare's role here is network transport — like our hosting provider, its infrastructure necessarily handles the request in transit, but Cloudflare does not run its own analytics, advertising, or tracking on this data.
4. Data We Do Not Collect
We want to be explicit about what we do not do:
- No behavioral analytics. We do not use Firebase, Mixpanel, Amplitude, Segment, or any behavioral analytics platform.
- No third-party crash reporting. We do not send crash data to Crashlytics, Sentry, or any third-party crash service.
- No advertising IDs. We do not access advertising-related identifiers.
- No device fingerprinting. We do not collect device identifiers or any combination of data designed to uniquely identify your device.
- No cross-app tracking. We do not track your activity across other companies' apps or websites.
- No data brokering. We never sell, rent, or share your data with data brokers or advertisers.
- No social-login data. We do not require or support social login.
5. How We Use Your Data
Data handled by our applications is used exclusively to provide the features you have chosen to use. We do not use your data to build advertising profiles, train models on external servers, or for any purpose unrelated to providing the functionality you have requested.
6. Storage & Security
6.1 On-Device Storage
The majority of your data is stored locally on your device using your platform's native persistence frameworks. This data is protected by the operating system's built-in data-protection features (encrypted at rest when your device is locked).
Sensitive credentials are stored in your device's secure system keychain.
6.2 Cloud Sync & Encryption
Where data is synced across your devices, it is encrypted using industry-standard authenticated encryption before it leaves your device. The encryption key material is held in your platform's end-to-end encrypted keychain, which Shadow Sheep Labs cannot access. This means we cannot decrypt your synced data even if compelled to do so.
7. Third-Party Services
7.1 Platform Services
Our applications use standard services provided by your device's operating system. Your use of these services is also governed by your platform vendor's privacy policy (for example, Apple's Privacy Policy).
7.2 Other Third Parties
Where a specific application integrates a third-party service in order to provide an opt-in feature you have chosen to use, that integration and any data handling associated with it will be disclosed within the application itself before you enable the feature. Shadow Sheep Labs does not retain copies of data exchanged with such third parties on its own servers.
Place-name lookups. When location features are on, naming a place you visited uses map lookups: Apple Maps, and for city and region boundaries OpenStreetMap's Nominatim service. These lookups send the coordinates being named — nothing else: no identifiers, no account information, and never your visit history. Your location history itself is stored on your device and in your own encrypted iCloud.
We do not use any third-party advertising networks, analytics platforms, or data brokers.
8. Children's Privacy
Our applications are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided personal information through our applications, please contact us at privacy@shadowsheeplabs.com and we will promptly delete any such information.
For users between 13 and 17, we recommend parental review of this policy before use.
9. Your Rights & Choices
9.1 Access & Deletion
Data stored by our applications is viewable and deletable from within the applications themselves. Deletion removes data from local storage and from any associated encrypted cloud sync. Data deleted in this way cannot be recovered.
The list below is generated from the canonical GDPR registry and reflects which rights each application supports per data category.
- Shadow Sheep Calendar: 5 exportable, 5 erasable, 3 requiring explicit consent.
- Finance: 12 exportable, 12 erasable, 2 requiring explicit consent.
- Fitness: 1 exportable, 1 erasable, 1 requiring explicit consent.
- Shadow Focus: 12 exportable, 14 erasable, 3 requiring explicit consent.
- Habits: 4 exportable, 4 erasable.
- Habits Watch: 0 exportable, 0 erasable.
- Mail: 7 exportable, 8 erasable, 3 requiring explicit consent.
- Meal Plan: 0 exportable, 0 erasable.
- Shadow Reminders: 4 exportable, 5 erasable.
- Shared (all apps): 1 exportable, 3 erasable, 1 requiring explicit consent.
- Style: 0 exportable, 0 erasable.
- Travel: 12 exportable, 12 erasable, 3 requiring explicit consent.
- Travel (Mac): 12 exportable, 12 erasable, 3 requiring explicit consent.
- Weather: 0 exportable, 3 erasable.
9.2 Revoke Permissions
You can revoke any device permission at any time in your device's system Settings. Revoking a permission disables the related feature but does not affect other application functionality.
9.3 Disable Cloud Sync
You can disable cloud sync for our applications in your device's system Settings. Disabling sync keeps your data entirely on-device.
9.4 California Residents (CCPA)
Under the California Consumer Privacy Act, California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@shadowsheeplabs.com.
9.5 European Users (GDPR)
If you are located in the European Economic Area, you have the right to access, rectify, erase, restrict processing, and port your personal data, as well as the right to object to processing. Because most data is stored locally on your device, you can exercise most of these rights directly within the applications.
To exercise GDPR rights for any data we may hold, contact us at privacy@shadowsheeplabs.com. We will respond within 30 days.
The legal basis for processing is: (a) performance of a contract (providing the features you requested), (b) your consent (for permissions such as health data or location), and (c) our legitimate interests (such as diagnosing and improving application stability).
10. Data Retention
Data is retained for as long as you use the applications and have not deleted it. When you delete an application from your device, locally stored data is removed. Encrypted data held in your platform's cloud-sync service persists until you delete it from within the application or delete your platform account.
We do not retain copies of your data on Shadow Sheep Labs servers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the applications.
Your continued use of our applications after changes are posted constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Shadow Sheep Labs LLC
Email: privacy@shadowsheeplabs.com
We aim to respond to all privacy inquiries within 5 business days.