1. Who we are
Groggy is an iOS app that keeps distracting apps locked until you complete morning tasks verified with a live photo. This Privacy Policy explains what data the app uses and why.
Operator: Till Theurer, sole trader (Einzelunternehmen), Carl-Friedrich-Straße 7, 76437 Rastatt, Germany. No commercial register number. No VAT ID on file.
Contact for privacy questions: support@getgroggy.com. Website: getgroggy.com.
2. Short summary
- No account and no login. Your routine, streak, and settings stay on your device (App Group storage).
- Live task photos are sent only for a one-time AI check in the United States. Groggy does not store the image. We require zero-data-retention routing so the photo is not used to train models.
- Which apps you block is handled by Apple’s Screen Time APIs. Groggy does not learn the names of your selected apps.
- Subscriptions are billed by Apple. We do not receive your payment card details.
- You can delete local app data from Settings in the app, or by uninstalling Groggy.
3. What we collect
3.1 Data stored on your device
To run the app, Groggy stores locally (including in an App Group shared with system extensions):
- Your morning plan (tasks, schedule, weekdays)
- Streak and completion status
- App preferences (for example reminder settings)
- Subscription access status needed to enable or disable blocking
- Tokens and configuration needed to talk to our verify endpoint
This data is not synced to a Groggy cloud database. There is no Groggy user account.
3.2 Permissions
- Screen Time / FamilyControls: required to shield the apps you choose during your lock window.
- Camera: required to take live photos that prove a task. Groggy does not use your photo library for task verification.
- Notifications: optional local reminders (for example when tasks are ready).
3.3 Data we do not collect as a product feature
- No email/password account in the app
- No contacts, HealthKit, or location tracking for the core product
- No gallery upload for task proofs
3.4 Optional in-app product feedback
After you have used Groggy for a few successful mornings, the app may ask whether you like it. Saying yes can open Apple’s standard rating dialog. Saying no can open a short, voluntary feedback form (reason chips and an optional free-text note).
If you submit feedback, we send it over HTTPS to our Cloudflare Worker
(POST /feedback), along with an anonymous install id so we can honor deletion
requests. We may keep a copy in a spreadsheet or support inbox that
we operate, so we can improve the app. This feedback is optional. We do not use it for
advertising, and it is separate from task photos.
4. Task photos and AI checks
When you complete a task, Groggy opens the live camera. You take a photo. That image, plus the
task name and optional hint, is sent over HTTPS to a Cloudflare Worker
endpoint (POST /verify) that we operate.
The Worker forwards the check to a vision model via OpenRouter. The model in use is
Google Gemini (currently gemini-3-flash-preview). The response is a pass/fail
result and a short reason. Groggy and the Worker do not store the image
after the response is returned.
We require OpenRouter to use zero-data-retention endpoints that do not collect data for
training (zdr: true and data_collection: deny). If no such
endpoint is available, the check fails instead of falling back to a provider that stores
or trains on the photo.
Google’s paid Gemini API terms say Google does not use these prompts or images to train models. Google may still keep prompts for a limited time solely to detect abuse or prohibited use. We do not control that safety log, and we do not use extra Google features that add their own retention (for example Search grounding or the File API).
If verification fails, you get another attempt. After two failed attempts, Groggy applies a courtesy pass for that task so a bad lighting angle does not trap you. If our servers fail while your phone has internet, the live photo still counts (fail-open). If you have no internet, the photo is not counted until you are back online; you can still use the in-app pause / end path.
Photos can show private morning contexts (bathroom, bedroom). They exist only for the check. Do not include other people’s faces or sensitive documents in task photos if you can avoid it.
5. Screen Time and app blocking
Blocking uses Apple’s FamilyControls, ManagedSettings, and DeviceActivity frameworks. You pick apps or categories with Apple’s system picker. By Apple’s design, Groggy does not receive a readable list of which apps you selected. Shield screens and schedules run through Apple’s system extensions.
Without an active subscription, Groggy does not keep your apps locked. Blocking is a commitment tool, not a jail.
6. Subscriptions and payments
Paid access is sold as auto-renewable App Store subscriptions (product IDs such as
groggy_yearly, groggy_weekly, and groggy_founding_yearly).
Apple processes payment. We do not receive or store your card number.
We use RevenueCat to manage subscription status and restore purchases. RevenueCat may process App Store purchase receipts and device identifiers needed for entitlement checks. See RevenueCat’s Privacy Policy.
For Apple’s handling of payments, see Apple’s Privacy Policy.
7. Third parties / subprocessors
These companies process data for us so Groggy can run. They are not allowed to use task photos to sell ads or to train their own public models under the routing we require.
- Cloudflare, Inc. (USA): hosts this website and the Worker (verify and optional feedback). Receives the photo in transit for verify, does not keep it as a Groggy archive.
- OpenRouter, Inc. (USA): routes the photo to the vision model. We require zero data retention and no training/collection on these requests.
- Google LLC (USA): Gemini vision model. One-time yes/no check. Paid API: not used for training. Limited abuse-monitoring logs may still exist on Google’s side, as described in section 4.
- RevenueCat, Inc. (USA): subscription status and restore. Purchase receipts / device identifiers, not task photos.
- Apple Inc. (USA): App Store, In-App Purchase, Screen Time / Family Controls, device OS. Apple is a separate controller for App Store payments.
We do not sell your personal data.
8. Retention and deletion
- On device: until you use “Delete all data” in Settings or uninstall the app.
- Verify photos: not retained by Groggy or our Worker after the check completes. OpenRouter is instructed not to retain them. Google may keep a copy for a limited time solely for abuse detection, as described in section 4.
- Product feedback: kept as long as useful to improve the app, then deleted or anonymized. Delete all data in Settings also removes associated optional product feedback from our servers when identified by the anonymous install id.
- Support email: if you write to us, we keep the conversation as long as needed to help you, then delete or anonymize it when no longer needed.
- Subscription records: held by Apple / RevenueCat under their policies for billing, fraud prevention, and restores.
9. Your rights
Depending on where you live (for example GDPR in the EEA/UK, or similar laws elsewhere), you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. Because most Groggy data lives on your device, the practical path is:
- Change or clear settings and tasks in the app
- Use Delete all data in Settings
- Uninstall the app
- Manage or cancel your subscription in your Apple ID subscription settings
- Email support@getgroggy.com for help with anything we may hold (for example support mail)
If EU/UK GDPR applies, our lawful bases are typically: performance of the contract (running the app you subscribed to), consent where required (for example camera for verification), and legitimate interests for security and abuse prevention on the verify endpoint. The controller is Till Theurer (address above). No data protection officer is appointed.
10. Children
Groggy is built for adults who want a morning commitment tool. You must be at least 17 to use Groggy. Do not use the app if you are under 17.
11. International transfers
The photo check and subscription tooling run on servers outside the EEA, including in the United States (Cloudflare, OpenRouter, Google, RevenueCat, Apple). Where required, we rely on the safeguards those providers offer, typically Standard Contractual Clauses and, where a provider is certified, the EU-US Data Privacy Framework.
12. Changes
We may update this Privacy Policy. We will change the “Last updated” date above and, for material changes, provide a reasonable notice in the app or on this site when practical.
13. Contact
Questions about privacy: support@getgroggy.com
Operator: Till Theurer, Carl-Friedrich-Straße 7, 76437 Rastatt, Germany.