RLX

Privacy

Privacy, without asterisks.

Your attention is not our product. RLX has no account, ads, analytics, or tracking, and no RLX server receives your data.

Effective: 9 September 2026
Developer: Jan Litjens (Dutch Yankees) · litjens@me.com

Information RLX handles on your device

You choose what to keep in RLX. This can include settings and protection rules, journal entries and reflections, parked worries, tasks, a support plan, energy, mood and sleep check-ins, saved articles, and local Child Mode boundaries. The app stores this content in its own storage on your iPhone. Passcodes, active Locked commitments, and related security records are kept in the device-bound iOS Keychain.

RLX uses Apple Screen Time to limit apps. The system picker gives the main app opaque tokens rather than app identities it can read as text. Wherever iOS locally renders a real name, icon, category, or website, or provides a local display name or domain to the Shield extension on the blocked screen, RLX deliberately shows as much of that information to you as possible. RLX never reads, guesses, or displays the underlying token value.

Usage duration, pickups, sessions, and app, category, or website labels are calculated and drawn only inside Apple’s privacy-protected DeviceActivityReport extension. These details do not enter the main app, RLX storage, an export, your iCloud copy, or the developer’s possession.

Apple services and permissions

Apple processes these system services under its own terms and privacy policy. They do not give the developer access to your data.

Your own iCloud copy and deliberate sharing

With iCloud copy enabled, RLX saves a separate file for each device in your Apple Account’s private iCloud Drive container. From 1.5, saved notes, day reflections, topics and photos can be included alongside supported settings, tasks and progress. Existing users first choose whether to include their journal. There is no syncing: you restore a copy yourself. This is separate from your device’s iCloud Backup. Worries, support plans, wellbeing data, HealthKit, Apple app selections, Screen Time tokens, passcodes and device secrets are excluded. The developer cannot view the copy.

A complete manual export, journal file, PDF, or diagnostics report reaches Apple’s share sheet only when you choose it. Diagnostics contain fixed statuses and counts, not notes, names, or app selections. A recipient or service you select in the share sheet has its own privacy policy.

No RLX data sent to us

The app sends no RLX or device data to the developer. RLX includes no backend or third-party account, advertising, analytics, attribution, crash-reporting, subscription, or remote-configuration SDK. RLX does not sell data or share anything for advertising or profiling. Its App Store privacy answer is therefore Data Not Collected.

A support website or phone number opens only after your tap. RLX adds no journal, Screen Time, device, or click data. A website or phone service you choose to open has its own privacy policy.

If you voluntarily email support

If you voluntarily email Jan Litjens (Dutch Yankees) at litjens@me.com, that email is separate from RLX. The developer receives your email address, message, and anything you choose to attach only because you send it. It is used only to respond to you, investigate a security concern, or meet a legal obligation. The legal basis is the legitimate interest in handling your voluntary support or security request and, where applicable, a legal obligation.

Support email is kept only as long as needed for that response, security investigation, or law. At the same address, you can request access, correction, deletion, or restriction, and object to its use. You can also complain to the privacy regulator in your country. Unless retention is required by law, the email is deleted when it is no longer needed. Do not include journal text, app selections, passcodes, or other private content unless strictly necessary, and then include as little as possible.

This static website

This GitHub Pages website has no RLX JavaScript, tracking, forms, cookies, or analytics controlled by RLX. It does not receive RLX data. A normal request for this static page is handled by GitHub under GitHub’s privacy policy.

Your choices, retention, and deletion

You can erase sensitive sections separately, revoke system permissions in iOS, turn off your iCloud copy, and create an export of your RLX data. Local content remains until you change or erase it. Copies you previously exported or shared remain wherever you chose to save them.

Erase all your data attempts to remove RLX storage, files, local notifications, and device-bound RLX secrets such as the parent passcode and lock log. RLX checks each storage layer separately: if the app cannot confirm that everything is gone, it reports that only part was erased and lets you retry the same action. Data already erased is not restored. RLX also asks iCloud to delete its copy. If iCloud is temporarily unavailable, RLX keeps a content-free pending flag and retries when the app opens again. During Strict Mode or an active Locked commitment, erasing is deliberately unavailable because it would otherwise bypass the protection you chose. After the commitment ends, or through its preselected exit, you can erase everything. Deleting the app alone is not a substitute for this action: iOS controls the Keychain and does not guarantee that device-bound RLX items are automatically removed with the app. If you want everything erased, use Erase all your data first once a hard commitment has ended. The developer has no server copy that requires a separate deletion request.

Children

Child Mode runs locally on the child’s iPhone and is configured there by a parent. RLX has no remote monitoring portal or parent account. The RLX app sends no personal data about a child, or anyone else, to the developer.

Changes

If RLX data handling changes, this policy and the App Store privacy answer will be updated before that change ships.