Scope
This policy covers the Gestalt iOS app (formerly Guppy) and this legal-information website. Gestalt is a digital wellbeing app for Screen Time trends, Focus history, routines, and app-pause choices.
The Gestalt app has no shipping account system, advertising SDK, or automatic native crash-report upload. Product Analytics and Coded Diagnostics are independent, optional, and default off. This public website uses the limited first-party measurement described below.
Optional Product Analytics and Coded Diagnostics
Your Screen Time totals, app and website identities, selected or blocked apps, and report results stay on your device.
Product Analytics
If you turn on Product Analytics, Gestalt sends coarse, allowlisted setup, feature, paywall, and purchase-flow outcomes linked to a resettable pseudonymous consent epoch for up to 90 days. Privacy-qualified aggregate product metrics may be retained for up to 13 months.
Coded Diagnostics
If you separately turn on Coded Diagnostics, Gestalt sends only stable flow and failure codes for up to 30 days—never logs, text, screenshots, URLs, Screen Time facts, crash stacks, or performance payloads. Privacy-qualified diagnostic aggregates may be retained for up to 90 days.
Gestalt processes this optional data on its EU-hosted Gold infrastructure only to operate and improve the app. It is not sold, used for advertising or tracking, joined to another company’s user or device data, or used to create an advertising profile.
The resettable epoch, App Attest authenticity state, optional commerce link, and bounded request identifiers are conservatively treated as linked data while their source records remain. Turning a choice off closes its epoch. Server tombstone digests may remain for up to 13 months to prevent an offline device or restored backup from recreating deleted data.
See Privacy Choices for the exact controls and deletion behavior.
Screen Time
Standard report-only access
Standard Screen Time results are processed and displayed inside Apple’s visible Device Activity report extension. Gestalt does not export those report values, app identities, rankings, or returned coverage into the host app, logs, widgets, or a network service.
Enhanced access, when Apple makes it available
On eligible devices and only after explicit authorization, Apple may allow Gestalt to receive enhanced Screen Time data directly. Successful readings received through that capability are stored locally on the device. Coverage depends on the device, operating system, authorization state, and the intervals Apple returns. Gestalt does not promise a complete lifetime history.
App-pause selections
Apple provides opaque application, category, and web-domain tokens for the choices you make in Family Controls. Gestalt uses those tokens locally to apply the app-pause behavior you requested. It does not receive ordinary bundle identifiers from those opaque tokens.
Local app data
Gestalt stores app-owned records needed to provide the product, including settings, onboarding progress, Focus sessions and schedules, reminder preferences, app-pause selections, subscription state, and display preferences. Core operation is offline-first and does not require a Gestalt account or server.
Focus history and Screen Time authority remain separate. Buying a subscription does not grant Screen Time permission, change measured coverage, or bypass Apple’s authorization controls.
Local diagnostics
Gestalt uses Apple OSLog and MetricKit plus protected on-device storage for reliability diagnostics. There is no configured Sentry, Crashlytics, or other automatic crash uploader. Crash artifacts remain local until verified local-data deletion removes them.
If you deliberately export ordinary diagnostic logs or contact Support, information leaves the app only through that action and the destination you choose. Review the disclosure shown before sharing and avoid including sensitive information unless it is necessary.
Purchases
Apple handles App Store purchases, renewals, billing, cancellation, refunds, restoration, and Ask to Buy approval. Gestalt receives the product and entitlement status needed to show your access. Gestalt does not receive or store your payment-card details.
This website
This website has no account, payment form, advertising, contact form, or optional cookies. It uses a self-hosted Umami instance on Gestalt's own infrastructure to measure aggregate page visits, approved campaign tags, clicks on “See Gestalt in action,” and, where the browser supports them, three Core Web Vitals: CLS, INP, and LCP. Each performance event contains only the metric name, a rounded numeric value, and its rating; metric identifiers, performance entries, element targets, attribution, and navigation URLs are not sent as event data. The tracker honors browser Do Not Track, does not use cookies, does not identify you, and is not linked to the app, Screen Time data, app identities, purchases, or an advertising profile.
The analytics policy removes arbitrary query parameters, advertising click identifiers, URL fragments, and unapproved event data before a request is sent. Approved campaign values and raw website analytics are retained for no more than 90 days. Web-server request logs may contain an IP address, user agent, timestamp, and requested path for delivery and security and rotate after 14 days. Do not send personal or Screen Time information to this website; it has no intake surface.
Your controls
- Review or revoke Screen Time and notification permissions in iOS Settings.
- Use Gestalt Settings to inspect current authorization and local-data boundaries.
- Independently enable, disable, or delete Product Analytics and Coded Diagnostics data in Data and privacy. Both choices default off.
- Create a protected export of the app-owned data listed in the export disclosure. Standard Screen Time report results and crash artifacts are excluded.
- Use Delete All Gestalt Data to run the verified local erasure transaction.
- Manage subscriptions, cancellation, and refunds through Apple.
Changes and questions
Material changes will be published here with a new effective date and policy version. The app may also present a notice when a change materially affects its data handling.
For privacy questions or requests, use Support inside the Gestalt app. Include the app and iOS versions when helpful, and do not include sensitive information unless it is necessary for the request.