Product-specific document. This schedule applies only to Anchor (app.rork.anchor-app-blocker). It supplements the separate Anchor Terms of Service and Privacy Policy, each of which has its own immutable version and SHA-256 hash.
Important: Anchor depends on Apple Family Controls, Managed Settings, Device Activity, extensions, permissions, and operating-system behavior. It cannot guarantee that every app or website is blocked, that every bypass is prevented, or that schedules and reports always run.
1. Incorporated agreement
This schedule is part of the Service Terms. The Privacy Policy and Apple Standard EULA also apply.
2. Eligibility
You must be at least 13. A user age 13–17 may use Anchor only after a parent or legal guardian reviews and accepts for the minor. Users under 13 receive limited mode and may not start protection.
3. User-configured controls
You choose protected apps, websites, schedules, friction levels, emergency limits, and recovery settings. Review the plan preview and protection-health status before relying on a rule. Do not configure Anchor where delayed access could create danger, prevent emergency communication, interfere with caregiving, block required workplace or school systems, or violate another person’s rights.
4. Lockout and recovery
Stronger friction is intentionally difficult to exit and can delay access. Daily Passes and emergency recovery may be limited. You are responsible for maintaining another safe way to call emergency services, reach trusted people, and access essential information. Ending an active run, clearing shields, or disabling future schedules may require device authorization and may not succeed if Apple services are unavailable.
5. Reliability and attribution
Force quit, reboot, Screen Time settings, Family Sharing, operating-system updates, revoked authorization, extension limits, notification delivery, time changes, and Apple bugs can alter enforcement and reports. Blocked-attempt history and activity summaries are best-effort and may be delayed, incomplete, or attributed differently by Apple frameworks. Notifications, widgets, Shortcuts, and Live Activities are status aids, not guaranteed alarms.
6. Pro features and purchases
The app identifies which plans, schedules, friction, analytics, widgets, or shortcuts require Anchor Pro. Access is based on Apple/RevenueCat entitlement status, not a local promise. Manage Subscription and Restore Purchases remain available in limited mode.
7. Limited mode after declining
Limited mode provides legal documents, support, Restore Purchases, Manage Subscription, protection status, authenticated emergency recovery, ending active runs, clearing shields where the system permits, and disabling future schedules. Declining stops future enforcement without deleting saved plans. You must confirm protection is actually inactive.
8. Privacy
Family Controls selections and enforcement data stay within the device, Apple frameworks, and Anchor’s App Group extensions. Uncommon Weather does not receive the apps or websites you select. The separate acceptance receipt does not contain Screen Time selections or activity.
9. No substitute for supervision or safety systems
Anchor is a self-management tool, not parental-control assurance, security software, emergency service, medical treatment, or a substitute for supervision. You remain responsible for device use and consequences of blocked or unblocked access.
Current product data boundary
The following categories and operational boundaries are specific to Anchor. They form part of this product schedule and are described more fully in the product-specific Privacy Policy.
- Focus plans, selected applications, websites and domains, schedules, and Focus Run state
- Session history, blocked-attempt and activity summaries, progress measurements, and local analytics
- Accountability-partner names, labels, share codes, and report content
- Commitment safeguards, PIN-verifier state, and emergency-unlock attempt and audit records
- Notification, widget, display, and other product preferences
- Anonymous App Store purchase and entitlement metadata
- Privacy-minimal legal-choice evidence
Focus data and local safeguards
Anchor stores Focus Plans, selected applications, websites and domains, schedules, Focus Run and session history, blocked-attempt and activity summaries, progress measurements, local analytics, accountability-partner labels and share codes, notification preferences, and other settings in local app or App Group storage. Commitment safeguards, partner PIN verifiers, and emergency-unlock attempt and audit records may also be kept in the device Keychain so Anchor and its bundled extensions can enforce the choices made in the app.
Anchor does not send Focus Plans, selected applications, websites or domains, activity summaries, accountability-partner details, PIN verifiers, or emergency-unlock records to the developer, RevenueCat, or the legal-choice ledger.
Screen Time and Family Controls
Selections made through Apple's Screen Time and Family Controls frameworks are processed on the device by Apple-provided system interfaces. The developer cannot read the underlying application or website tokens as ordinary identifiers, and Anchor does not transmit those selections to its own servers.
Device services
Anchor schedules local notifications and uses local widgets and bundled Screen Time extensions. If App Lock is enabled, Apple's Local Authentication framework evaluates Face ID, Touch ID, or the device passcode; Anchor does not access or store biometric templates.
The optional Walk It Off flow uses Core Motion to count steps on the device. Step data is used for that flow and is not stored as a long-term health record or transmitted by Anchor.
Accountability sharing
Accountability-partner names, labels, and share codes remain local. Anchor generates accountability reports on the device and shares them only when the user invokes the iOS share sheet. Anchor does not operate a server that delivers those reports or exchanges partner data; the recipient and any selected sharing service may retain a copy after it is shared.
Purchases and legal choices
Apple processes App Store purchases and payment credentials. RevenueCat receives an anonymous app-user identifier and limited app, device, purchase, and entitlement metadata needed to determine access; it does not receive Anchor's Focus Plans, selections, activity summaries, partner details, or safeguard records.
The legal-choice service receives only signed, privacy-minimal evidence of an acceptance, decline, or withdrawal, including product and document identifiers, versions and hashes, the choice, broad age band and acceptor role when applicable, pseudonymous installation and request identifiers, timestamps, locale, and security proof. It does not receive Anchor product content.
Retention and deletion
Anchor keeps local records until the user removes them with an available control, resets the app, clears applicable device storage, or removes the app, subject to Apple's storage behavior. Reset All Data is available after active Focus Runs end and removes Anchor data from app storage, the shared App Group, and the Keychain. Because iOS may preserve Keychain items after an uninstall, a user who wants those safeguards removed should use Anchor's in-app reset before uninstalling. Reports already shared remain wherever the user or recipient saved them.
Legal choices and limited mode
A decline or withdrawal takes effect locally at once. Anchor stores that limited-mode choice and does not turn it into a recurring prompt merely because a later document family is published. The user can review the current documents and affirmatively accept from Legal & Privacy settings. A previously accepted user is asked once when a materially changed document family requires a new choice; a verified acceptance for the current family is not asked again.
Related documents
Anchor Terms of Service · Anchor Privacy Policy · Legal Center