Banked.

Screen time, earned first and spent second.

Document
No. 002
Issued
2026-08-05
Revised
2026-08-05
Applies to Banked. for iPhone and iPad — formerly Earned.

Privacy Policy

Version 1.0

MemoPrivacy Policy, effective August 5, 2026

Issued byRayyan Anwar

|: banked :| privacy :| v1.0 :| 2026-08-05 :| ios :|

Banked. is a parental control app, so it is exactly the kind of app that could collect a great deal about a child. It collects less than most, but it is not nothing — it reads step counts, it can share a location, and it passes both between two phones. This policy says what that data is, where it goes, and how to get rid of it.

No accounts. No ads. No trackers. We run no server and sell nothing

§ 01The short version

At a glance
Do you need an account?No. There is no sign-up, no email, no password.
Where does data live?On the two phones, and in a CloudKit record keyed by a random pairing token.
Do you have a server?No server of our own. Your data syncs through our CloudKit container, which Apple hosts.
Is health data collected?Yes — step count and mindful minutes. Nothing else from Health.
Is location collected?Only if switched on. Off by default, and the child controls the switch.
Ads or analytics SDKs?None of either.
Sold or shared for money?Never, under any circumstances.
Can you read what apps my child uses?No. iOS gives us sealed tokens, not names.

This policy applies to Banked. for iPhone and iPad — previously published as Earned. — and is published by Rayyan Anwar.

§ 02Who this covers

Banked. is used by a parent and a child on two paired devices. The parent sets every rule; the child device shows a balance and a history. Neither person creates an account with us.

Two names do exist in the app. The parent types their own first name during setup, and types a name for each child. The child's device also reports its device name — which on many phones is something like "Ali's iPhone". Both travel between the paired devices so each screen can greet the right person. We never ask for an email address, a phone number, a birthday, or a postal address, and we have no way to learn them.

§ 03What stays on the device

Most of what Banked. knows sits in a shared container on the device itself, so the app and its Screen Time extensions can read the same numbers:

  • The minute balance — earned, spent, granted, carried over, and remaining.
  • Today's step count and mindful minutes, read from Health.
  • Reading, practice and chores the child logged, and whether a parent approved them.
  • Sessions — when one started, how long it was, how it ended, and today's history of them.
  • Earning rates, daily caps, bedtime windows and the rest of the rules the parent set.
  • Sealed app and category tokens for the apps chosen on the parent device.
  • The activity streak, and which days counted.
  • The parent's PIN, stored only as a salted SHA-256 digest — never the digits.
  • The most recent location point, if location sharing is switched on.
  • Subscription status, so the app knows whether to enforce restrictions.

This is covered by your device passcode and Apple's file protection. Deleting the app deletes all of it, and also removes every restriction that app was applying.

§ 04What syncs between the two phones

Two phones can't talk to each other without something in the middle. Rather than run a server, Banked. uses Apple's CloudKit to pass a small record between the paired devices, filed under a random pairing token generated on the device.

Synced record
FieldWhy it's there
Pairing tokenThe random key the two devices agree on. Not derived from any identity.
Parent's first name, child's name and device nameSo each screen can greet the right person and label the right child.
Minute balance and the day's ledgerSo the parent dashboard shows the same numbers the child sees.
Step count, mindful minutesThe activity those minutes were earned from.
SessionsWhether one is running, how long, and today's finished ones.
StreakSo both sides show the same run of days.
Rules, rates and tiersWritten by the parent device, read by the child device.
Requests and approvalsIncluding any short note the child types when asking for more minutes.
Parent PIN digestA salted hash, so the child's phone can check a PIN it was never told.
Most recent location pointOnly present if location sharing is switched on. See § 06.
Whether Screen Time was switched offSo the parent is told when nothing is being enforced.
Read this part carefully

This record lives in the public database of our CloudKit container, not in your private iCloud storage. That choice is what lets two different Apple Accounts — a parent's and a child's — see the same record at all.

It is keyed by the random pairing token and holds no email address or contact detail, but anyone who obtained your pairing token could read it, including the names, balances and any location point in it. That is why the code closes after one device uses it, and why it should only ever go to the phone you are setting up.

Apple stores this data under Apple's privacy policy. We do not receive analytics, reports, or copies from it, and we do not query it for anything other than serving your own two devices.

§ 05Health and activity data

Earning minutes is the point of the app, so Banked. reads activity from Apple's Health app. It reads exactly two things and nothing else:

  • Step count for the current day.
  • Mindful minutes for the current day.

It requests read access only. Banked. never writes anything to Health — the write permission Apple requires it to declare is never used. It reads no heart rate, no sleep, no weight, no cycle data, no clinical records, and no history beyond the day in progress.

Those two daily totals are stored on the device and synced to the paired parent device so the dashboard can show what the minutes were earned from. Health data is never used for advertising, never sold, never shared with anyone else, and never sent anywhere except the CloudKit record your two phones share — Apple's rules forbid all of that, and so does this policy.

You can revoke access at any time in the Health app, under Profile › Apps & Services. Revoking it stops steps being counted; nothing else in the app changes.

§ 06Location sharing

Banked. can share the child's location with their parent. This is off by default, needs the child to grant iOS location permission on their own device, and can be switched off by them at any time.

  • What is shared is a single most-recent point — latitude, longitude, an accuracy figure, and the time it was recorded.
  • There is no route and no history. Each new point replaces the last one; nothing keeps a trail.
  • Points are collected roughly every 200 metres of movement rather than continuously, and only while sharing is on.
  • It is visible to whoever has paired as a parent for that child, and to nobody else. It goes into the same synced record described in § 04.

A parent can make location sharing a condition of the arrangement, in which case the child's bank stops growing while it is off. Even then the child keeps the switch: already-banked minutes still work, nothing is confiscated, and turning it back on resumes earning immediately. No app can turn on location for someone else, and this one does not try.

Switching sharing off deletes the stored point. Revoking location permission in iOS Settings does the same.

§ 07Screen Time data and app tokens

Banked. uses Apple's Family Controls and Screen Time frameworks. When a parent picks apps to restrict, iOS hands the app an opaque token for each app or category — a sealed reference the system understands and we cannot decode.

  • We cannot read which specific apps were chosen. Not on the parent device, not on ours.
  • We cannot see what happens inside a restricted app.
  • A token minted on one phone is meaningless on another, which is why a parent's dashboard shows counts of allowed, limited and restricted apps rather than a list of names.
  • The per-app usage chart is rendered by a sealed Apple extension. It draws directly on screen and hands its figures to nobody — not to the app, and not to us.
  • Apple's rules forbid using Screen Time data for anything but the feature you asked for. We don't, and structurally we couldn't.

§ 08Camera

The camera is used for exactly one thing: scanning the pairing QR code when a phone is being set up. Frames are read live to find the code and are discarded immediately.

No image, video, or frame is saved, added to your photo library, sent off the device, or sent to us. If you would rather not grant camera access, the pairing code can be typed in by hand instead — the app works identically either way.

§ 09What we never collect

Stated plainly, Banked. does not collect or contain:

  • Email addresses, phone numbers, birthdays, or postal addresses.
  • Contacts, photos, messages, or calendars.
  • Any Health data beyond the three daily activity totals in § 05 — no heart rate, sleep, weight, cycle tracking, or clinical records.
  • Any location history or route. Only the single latest point, and only when sharing is on.
  • Browsing history, search history, or anything typed inside another app.
  • Advertising identifiers, and no advertising SDKs at all.
  • Third-party analytics, attribution, or crash-reporting SDKs.
  • Microphone audio.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no arrangement under which we could — no ad network is integrated, and the only place your data goes is the CloudKit record your two phones share.

§ 10Subscriptions and payment

Subscriptions are sold through Apple's In-App Purchase system. Apple handles the entire transaction. We never see, receive, or store your card number, billing address, or Apple Account credentials.

What the app receives is a signed receipt confirming whether a subscription is active and when it expires. That status is stored on the device so restrictions know whether to apply. Apple also gives us aggregate, anonymised sales reports — units and revenue by country, with no identifiable buyer.

§ 11Children's privacy

Banked. is set up and controlled by a parent or guardian. A child using it creates no account, has no profile or username, uploads no photo, and has no way to send anything to us or to anyone outside their own family's paired devices.

Being straightforward about what does exist for a child: the name their parent gave them, their device name, their daily step and activity totals, their minute balance and session history, any short note they type when asking a parent for more minutes, and — if it has been switched on — their most recent location point. All of it is keyed to a random pairing token, visible only to their own parent's device, and deleted when the app is deleted or the pairing ended.

Consistent with COPPA, we do not collect personal information from children for our own purposes, do not condition participation on disclosing more than is needed, and have no means of contacting a child. The parent who set the app up can see everything listed above, delete it by unpairing, and revoke Health or location access on the child's device at any time. If you believe a child has somehow provided personal information to us, email rayyan.zahid.anwar@gmail.com and we will delete it.

§ 12Keeping and deleting data

  • On-device data is kept while the app is installed and is removed when you delete the app.
  • Synced records stay in CloudKit until the parent unpairs, which clears that pairing token's record, or until you delete the app's data from your iCloud settings.
  • Location points are replaced by each newer one and deleted outright when sharing is switched off.
  • Session history covers the current day only, and is cleared at midnight.
  • Emails you send us are kept only as long as needed to resolve what you wrote in about.

To wipe everything: unpair on the parent device, then delete the app from both devices. Cancelling a subscription is a separate step, done in the App Store.

§ 13Security

Data on the device is protected by iOS file protection and your passcode. Data in transit to and from CloudKit is encrypted by Apple. The parent's PIN is stored and synced only as a salted SHA-256 digest, so the digits themselves exist nowhere — not on either device, not in the synced record.

We run no server of our own, so there is no separate database of ours to breach. Your data does sit in our CloudKit container, which Apple hosts and secures. That removes a whole category of risk, but it also means the security of your data rests on your device passcode, your Apple Account, and keeping the pairing code private — anyone holding that token can read the record it keys.

Use a passcode on both devices and turn on two-factor authentication for your Apple Account.

§ 14Service providers

Banked. has exactly one third party: Apple, for CloudKit sync, App Store distribution, and payment processing. There are no other processors, no analytics vendors, and no advertising partners.

§ 15Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to know whether it's sold or shared (it isn't), and not to be discriminated against for exercising those rights. California residents have these rights under the CCPA and CPRA; residents of the EU and UK have them under the GDPR.

In practice, most of these you can exercise yourself in seconds: everything is on your devices and in a record keyed to your own pairing token, so unpairing and deleting the app removes it. If you'd like help, or want written confirmation of what we hold — which is nothing beyond any email you've sent us — write to rayyan.zahid.anwar@gmail.com. We'll respond within 30 days.

§ 16Changes to this policy

If this policy changes, the version and revision date at the top of the page change with it. If a change materially affects how your data is handled, we'll tell you in the app before it takes effect.

§ 17Contact

Privacy questions, deletion requests, and anything else: rayyan.zahid.anwar@gmail.com.

The rules for using the app are in the Terms of Service, and day-to-day help is on the Support page.