Privacy

Accounts are optional. Curfew works locally without Apple, Google, or a Hypertext Studio account, and requests only the permissions it uses.

What Curfew stores

DataWhereRetention
Schedule, budgets, preferences, license key ~/Library/Preferences/studio.hypertext.curfew.plist and ~/Library/Group Containers/group.studio.hypertext.curfew/Curfew/widget-settings.json Until you remove it or uninstall Curfew
Activity log (lockouts, extensions, overrides) ~/Library/Group Containers/group.studio.hypertext.curfew/Curfew/activity.sqlite3 52 weeks rolling
Reflections (your morning & evening journal answers) ~/Library/Application Support/Curfew/reflections.sqlite3 52 weeks rolling
Pending MCP write requests ~/Library/Application Support/Curfew/mcp-requests.json Until resolved
Browser decision audit metadata (hostname, decision, and scope type) ~/Library/Logs/Curfew Rotated segments for 90 days; the current segment until rotation

What Curfew does not do

  • No analytics, telemetry, or crash reporting.
  • No advertising or sale of personal information.
  • No access to your files or app content.
  • No reading of page content, page subresources, or general browser history.

Optional Curfew Account

If you sign in, your schedules, wake settings, callback definitions, and other synchronized content are end-to-end encrypted. Hypertext Studio coordinates ciphertext but cannot read that content. A plain Android build works without Google Play Services; the GMS build uses them only to reduce notification and sync latency, never for correctness.

The service still needs unavoidable metadata to operate: your Apple or Google sign-in identity, purchase entitlements, device public keys and revocation state, encrypted-record headers and timing, routing handles, OAuth and MCP grants, and remote unlock audit records. Card details go directly to Stripe and never reach Curfew servers.

Recovery and deletion

Two-factor backup codes restore account access; they do not decrypt synchronized content. That requires an enrolled device or your separate Curfew Recovery Key. You can export your account data and delete your Curfew account. See the retention policy for what is removed and what must be retained.

Permissions

PermissionWhy
Calendars (Pro) Read today's events for display. Never written to.
Notifications Warning countdowns and lockout alerts.
Accessibility (optional) Keyboard shortcut interception during lockout.
Chrome navigation (optional) Observe top-level HTTP and HTTPS navigation while task enforcement is active.

Task-scoped browser enforcement

When you enable task-scoped browser enforcement, the Chrome extension observes top-level HTTP and HTTPS navigation so Curfew can allow known destinations and block unknown ones before they load. Curfew does not inspect page content or subresources. Known destinations stay on your Mac. For an unknown destination only, Curfew sends the normalized origin and path to Docket and Athena with the current task and your answer for review. Curfew removes URL credentials, query strings, and fragments first.

Curfew retains an initial justification only while one live challenge remains pending, so the challenge can survive a page reload. Curfew never persists a completed justification or a challenge answer. The local audit log records only the hostname, decision, and scope type. It never records a full path, query, fragment, credential, justification, challenge answer, reviewer reason, or reviewer question.

iCloud sync (Pro)

When enabled, your schedule is stored in your private iCloud database (CloudKit). Hypertext Studio has no access — it lives in your personal iCloud account, encrypted by Apple.

MCP server

When curfew-mcp is running, a connected assistant can read your enforcement state and reflections, and request an extension or schedule change. Reflections are read-only. Curfew asks before write requests by default; you can change that policy in Settings. Curfew does not upload this data, but the assistant you connect may send it to its own service. Check that service's privacy policy before sharing your reflections.

Remote MCP clients receive only the scopes you approve. Remote unlock requests include a reason, are time-bounded, and are written to a remote unlock audit record. Direct unlock is off by default and can be authorized only for selected clients and devices.

Questions: hello@hypertext.studio