Check On You

Legal

Privacy Policy

Effective 3 August 2026 ยท Last updated 3 August 2026

The short version

Who this policy covers

This policy explains how the Check On You iPhone app (“the app”) and the website at checkonyou.app (“the site”) handle personal information. It applies to everyone who uses either.

Check On You is an independent app. Where data-protection law requires a “controller”, that is the app’s developer, reachable at privacy@checkonyou.app.

Where your data is stored

Check On You has no backend of its own. There is no company database, no application server, no third-party cloud provider holding your information.

Everything the app stores is written to your own iCloud account using Apple’s CloudKit, in two places:

A copy is also kept on your iPhone so the app works offline. One narrow exception exists for delivering invitations, described under The invitation inbox.

What the app stores

Account

You sign in with Sign in with Apple. The app receives an anonymous Apple user identifier and, if you allow it, your name and email address โ€” which may be one of Apple’s private relay addresses. Your display name, chosen avatar or photo, and sharing preferences are stored in your own iCloud. Your Apple ID password is never seen by the app.

Location

When you have granted someone access, the app records your location in the background using significant-location-change monitoring (roughly every 500 metres, chosen because it is far gentler on your battery than continuous tracking). Each entry contains:

If you choose approximate sharing, coordinates are rounded to two decimal places (about a kilometre) before they are written. The imprecise version is the only version that exists; the exact one is never stored or transmitted.

When someone checks on you, they are shown only your most recent location โ€” not a trail or a history of your movements.

Checks

Each check records who checked, when, and the optional message they wrote. A copy goes to both people, so the log of who looked at you is yours to keep and cannot be quietly edited by the other person.

Connections and circles

The app stores who you are connected to, what each of you has permission to do, and any circles you belong to along with their names and emoji.

Notifications

If you allow notifications, Apple issues the app a push token so alerts can reach your device. Notification content is delivered through Apple Push Notification service.

Diagnostics

The app keeps a debug log on your device to help you report problems. It stays on your phone unless you deliberately share it, and it is erased when you delete your account or the app.

The invitation inbox

Inviting someone requires reaching a person who has not yet accepted anything. For that one purpose, and only that purpose, the app uses CloudKit’s public database as an inbox. An invitation record contains:

No location, no plaintext email address, no name, and no other personal content is ever written to the public database. Invitation records are removed once accepted or expired.

Being straight about the trade-off: because the inbox can be searched by token, somebody with a copy of the app who guesses an exact email address could learn whether an invitation is waiting for it. They learn nothing else โ€” not who sent it, not where anyone is. We considered that a fair price for invitations that work without a server.

Permissions the app asks for

Who can see your location

Only people you have explicitly granted access to, and only for as long as you allow it. Specifically:

What the developer can see

Nothing. Because your data is written to your own iCloud account rather than to a server we run, the developer has no technical means to read your location, your messages, your connections, or your history โ€” not on request, not for support, not for debugging.

The app contains no analytics, no crash-reporting SDK, no advertising identifiers, and no third-party libraries that transmit data. Your information is never sold, rented, shared for advertising, or used to train anything.

If you email support, we see only what you choose to put in that email.

Apple’s role

Check On You is built on Apple services: iCloud and CloudKit for storage and sharing, Sign in with Apple for identity, Apple Push Notification service for alerts, Apple Maps for displaying locations, and the App Store or TestFlight for distribution. Your use of those services is governed by Apple’s Privacy Policy. Apple may make aggregate App Store statistics available to developers; these do not identify you.

Retention and deletion

Your rights

Depending on where you live โ€” including under the GDPR in the UK and EEA, and the CCPA/CPRA in California โ€” you have rights to access, correct, export, delete, and restrict the processing of your personal data, and to object to it. You also have the right not to be discriminated against for exercising them.

In practice most of these are already in your hands: the data is in your own iCloud account, the app shows you everything it has stored about your location, and account deletion is a button in the app. We do not sell or share personal information, so there is nothing to opt out of. If you would like help exercising a right, or want a written response, email privacy@checkonyou.app and we will reply within 30 days. You may also complain to your local data protection authority.

Where a legal basis is required, we rely on your consent (for location sharing and notifications, which you may withdraw at any time) and on the performance of our agreement with you (to operate the app you asked for).

Children and teenagers

Check On You is not directed at children under 13, and accounts require Sign in with Apple. The app is often used within families โ€” a parent and a teenager, for instance โ€” and the design assumes that: the person being checked on is always told, always sees the history, and always keeps the ability to revoke. If you believe a child under 13 has created an account, contact us and it will be deleted.

Security

Data in transit and at rest is protected by Apple’s CloudKit encryption and by your device’s own protections. Access between people is enforced by Apple’s sharing participant lists, not by trust in an app server. Invitation links placed in the public inbox are encrypted and pinned to the recipient’s Apple ID. No system is perfect, but the architecture is chosen so that a breach of any server we run cannot expose your location โ€” because there is no such server.

This website

checkonyou.app sets no cookies, runs no analytics, embeds no fonts or scripts from other domains, and does not track you. It is served as static files by Cloudflare, which processes standard request logs (including IP addresses) for security and delivery on our behalf.

Changes to this policy

If this policy changes, the effective date above changes with it, and material changes will be announced in the app before they take effect. Continuing to use Check On You after that means you accept the updated policy.

Contact

Privacy questions and data requests: privacy@checkonyou.app

Everything else: support@checkonyou.app

โ† Back to Check On You