Privacy is not a feature here, it is the only way this works
An app about your attention has to know what you open. Here is why that never leaves your phone, and what we gave up to keep it that way.
Think about what a screen-time app has to see in order to be useful.
It has to know which app is in front of you, right now. It has to know how long you have been there. To offer you something better, it has to know what you said you cared about, in your own words, on a bad day.
That is a more intimate picture than almost anything else on your phone. Your bank knows what you buy. This knows what you reach for at midnight.
Which is why the answer cannot be a promise. It has to be an architecture.
There is no server
Linger has no backend for your usage. Not a secure one, not an encrypted one, not one in a good jurisdiction. There is nowhere for that data to go, because we did not build anywhere for it to go.
Your apps, your times, your thresholds and the things you said you would rather be doing live in storage on your device and are never transmitted. There is no account, so there is nothing to log into, nothing to breach, and no table anywhere with your name in a row.
This is the part people find hard to believe, because every other app says something that sounds like this while quietly meaning something else. So here is the test: if we wanted to hand your data to someone tomorrow, whether a buyer, a court or an attacker, we could not. We do not have it.
What about the research thing
There is one switch, off by default, labelled something like help improve Linger. Turn it on and the app sends anonymous signals about how it is used: which nudges you accepted, how long sessions ran, what you tuned.
What it never sends, in any state, with the switch on or off:
- The words you write in your redirects. Those are yours and they stay on the phone.
- Your messages, your notifications, your screen contents.
- What you actually looked at inside any app.
- Your name, your email, or any identifier that points back at you, unless you separately choose to give us an email so we can send you what we learn.
The switch is off when you install, and turning it off later stops the sending immediately. If it were on by default, this paragraph would be marketing. It is off by default, which is what makes it a fact.
Why an app about wellbeing has to get this right
There is a specific trap in this category, and most products fall into it.
The business model of the feeds is surveillance: they watch what holds you, and sell the watching. A product that opposes that, and then builds a smaller version of the same machine to do it, has not fixed anything. It has just told you that surveillance is fine when the intentions are good.
It also does not work, practically. The whole mechanism in Linger depends on you writing down something true about your life, on a day when you were honest with yourself. Nobody writes that down truthfully into a text field they believe is being uploaded. The product would degrade into generic advice, which is the thing that already does not work.
So the privacy is not a trust badge bolted to the side. Remove it and the product stops functioning, because people would stop telling it the truth.
What we gave up. This is not free, and pretending otherwise would be the same dishonesty in a different direction.
No cloud sync between devices, because there is no cloud. No "see your history from the web". Reinstall the app and your history is gone, because it lived on the phone you wiped. And we fly much blinder than a normal company: we cannot see what most people do with the product, so we improve it slowly, from the small number of people who choose to help.
Those are real costs. We think they are the right ones, and you should know we paid them on purpose rather than by accident.
How to check, instead of believing us
Do not take the claim on faith. A few things anyone can do:
- Turn off the network. Put the phone in airplane mode and use Linger normally. Everything works, because nothing was ever going anywhere.
- Read the Play listing's data section. Google requires every app to declare what it collects, and the declaration is enforceable in a way marketing copy is not.
- Watch the traffic. If you are the sort of person who knows what a proxy is, point one at it.
- Read the policy. It is short, and it names every vendor on every surface. If a name ever appears there that surprises you, that is a real signal.
The one-payment part is a privacy decision too
You pay once, ten dollars, and it is yours.
That is not only a pricing choice. A company with no recurring revenue and no ad business has one way to survive: people paying for the product. A company that gives the app away has to find the money elsewhere, and there is only one place attention apps ever find it.
The business model is the privacy promise that survives a bad quarter. Everything else is an intention, and intentions get revisited when the runway gets short.
No account. Nothing about your use leaves the device. Pay once.