Privacy
Accounts are optional. Curfew works locally without Apple, Google, or a Hypertext Studio account, and requests only the permissions it uses.
What Curfew stores
| Data | Where | Retention |
|---|---|---|
| Schedule, budgets, preferences, license key | ~/Library/Preferences/studio.hypertext.curfew.plist and ~/Library/Group Containers/group.studio.hypertext.curfew/Curfew/widget-settings.json |
Until you remove it or uninstall Curfew |
| Activity log (lockouts, extensions, overrides) | ~/Library/Group Containers/group.studio.hypertext.curfew/Curfew/activity.sqlite3 |
52 weeks rolling |
| Reflections (your morning & evening journal answers) | ~/Library/Application Support/Curfew/reflections.sqlite3 |
52 weeks rolling |
| Pending MCP write requests | ~/Library/Application Support/Curfew/mcp-requests.json |
Until resolved |
| Browser decision audit metadata (hostname, decision, and scope type) | ~/Library/Logs/Curfew |
Rotated segments for 90 days; the current segment until rotation |
What Curfew does not do
- No analytics, telemetry, or crash reporting.
- No advertising or sale of personal information.
- No access to your files or app content.
- No reading of page content, page subresources, or general browser history.
Optional Curfew Account
If you sign in, your schedules, wake settings, callback definitions, and other synchronized content are end-to-end encrypted. Hypertext Studio coordinates ciphertext but cannot read that content. A plain Android build works without Google Play Services; the GMS build uses them only to reduce notification and sync latency, never for correctness.
The service still needs unavoidable metadata to operate: your Apple or Google sign-in identity, purchase entitlements, device public keys and revocation state, encrypted-record headers and timing, routing handles, OAuth and MCP grants, and remote unlock audit records. Card details go directly to Stripe and never reach Curfew servers.
Recovery and deletion
Two-factor backup codes restore account access; they do not decrypt synchronized content. That requires an enrolled device or your separate Curfew Recovery Key. You can export your account data and delete your Curfew account. See the retention policy for what is removed and what must be retained.
Permissions
| Permission | Why |
|---|---|
| Calendars (Pro) | Read today's events for display. Never written to. |
| Notifications | Warning countdowns and lockout alerts. |
| Accessibility (optional) | Keyboard shortcut interception during lockout. |
| Chrome navigation (optional) | Observe top-level HTTP and HTTPS navigation while task enforcement is active. |
Task-scoped browser enforcement
When you enable task-scoped browser enforcement, the Chrome extension observes top-level HTTP and HTTPS navigation so Curfew can allow known destinations and block unknown ones before they load. Curfew does not inspect page content or subresources. Known destinations stay on your Mac. For an unknown destination only, Curfew sends the normalized origin and path to Docket and Athena with the current task and your answer for review. Curfew removes URL credentials, query strings, and fragments first.
Curfew retains an initial justification only while one live challenge remains pending, so the challenge can survive a page reload. Curfew never persists a completed justification or a challenge answer. The local audit log records only the hostname, decision, and scope type. It never records a full path, query, fragment, credential, justification, challenge answer, reviewer reason, or reviewer question.
iCloud sync (Pro)
When enabled, your schedule is stored in your private iCloud database (CloudKit). Hypertext Studio has no access — it lives in your personal iCloud account, encrypted by Apple.
MCP server
When curfew-mcp is running, a connected assistant can
read your enforcement state and reflections, and request an
extension or schedule change. Reflections are read-only. Curfew asks
before write requests by default; you can change that policy in
Settings. Curfew does not upload this data, but the assistant you
connect may send it to its own service. Check that service's privacy
policy before sharing your reflections.
Remote MCP clients receive only the scopes you approve. Remote unlock requests include a reason, are time-bounded, and are written to a remote unlock audit record. Direct unlock is off by default and can be authorized only for selected clients and devices.
Questions: hello@hypertext.studio