Catto
Privacy Policy
Last updated: September 15, 2026
Catto is a cozy virtual pet for iOS that helps you build a calmer relationship with your phone. This policy explains what data Catto handles and why. The short version: Catto has no login, shows no ads, and never sells your data. We use service providers for app functionality, subscriptions, analytics, and diagnostics.
No account, no personal identity
Catto does not ask you to sign up, and does not require your real name, email address, phone number, or Apple ID. You may choose an optional display name. When you first open the app, Catto generates a random pseudonymous identifier (owner ID) that is not linked to your real-world identity. This identifier lets your pet and progress belong to this installation of Catto. Catto recovery and cross-device identity syncing are not currently enabled.
What Catto stores
- Anonymous identifiers — the random owner ID and install ID described above.
- Names you choose — a display name for yourself (optional) and a name for your pet. You can make these anything you like; they don't have to be real.
- Screen Time goals and outcomes — the daily time limits you set and whether each day's goal was met, close, or exceeded (see the next section for how this works).
- App-blocking (nap-guard) settings — whether you turned app blocking on, the strictness level you chose, and, as part of each day's summary, how many times you asked for "5 more minutes".
- Pet and progress data — your pet's stats (happiness, health, fullness, energy, weight, mood), your calm streak, earned backpack items, and your in-app yarn-ball balance and treat purchases.
How Screen Time data is handled
Catto uses Apple's Family Controls and Device Activity frameworks to help you track time in the apps you choose, and — if you turn on nap-guard — Apple's Managed Settings framework to show a block screen over those apps once your daily limit is used up. This matters for your privacy:
- The specific apps you select are represented by opaque tokens provided by iOS . Catto cannot see, read, or transmit which apps they are, and this information never leaves your device.
- Detailed usage stays on your device. What Catto records for your progress is limited to aggregate estimated minutes and the resulting goal status for the day. If morning recaps are enabled, the completed aggregate estimate and blocker-skip count are sent after the day ends so Catto can update your pet and prepare the recap without requiring you to open the app.
- App blocking happens entirely on your device. When nap-guard is enabled, iOS itself decides when to show Catto's block screen over your chosen apps. Catto never learns which apps were blocked — only the aggregate counts described above.
- In line with Apple's requirements, information obtained through the Family Controls framework is used only to power your pet and your personal experience. It is never used for advertising, never sold, and never shared with third parties for their own purposes.
Subscriptions, analytics, and diagnostics
RevenueCat processes subscription purchase history and pseudonymous app-user identifiers to validate purchases and manage access to paid features. Payments are handled by the App Store; Catto does not receive your payment-card details.
PostHog processes app interaction events, such as paywall views and purchase actions, with pseudonymous identifiers and device information to help us understand app use. Its IP-based geolocation can derive an approximate location. Sentry processes crash reports, diagnostics, and performance information to help us find and fix problems. These providers receive network information when the app connects to them. Selected-app names and detailed usage histories are not sent to these analytics and diagnostic services.
Optional iOS advertising measurement
In iOS versions with ad measurement enabled, Catto asks for your permission through Apple's App Tracking Transparency prompt before sharing identifier-based advertising signals with Meta. If you allow this, Meta may receive app activation, subscription events, and permitted device identifiers through the Meta SDK and RevenueCat to measure which advertisements lead to installs and subscriptions. Catto does not send selected-app identities, detailed Screen Time activity, pet or display names, or onboarding answers to Meta.
If you decline permission or have not been asked, Catto does not enable identifier-based Meta sharing. Apple may provide aggregate, privacy-preserving campaign attribution without identifying you. You can change tracking permission in iOS Settings. This optional Meta integration applies only to iOS. See Meta's Privacy Policy for how Meta handles data it receives.
Where your data lives
- On your device — your identity and local state are stored on your device.
- Convex — your profile, goals, pet state, daily summaries, items, and purchases are stored on our backend, provided by Convex, which processes this data on our behalf. This also includes completed aggregate usage estimates and an installation-scoped notification token, locale, and timezone when morning recaps are enabled. Records are associated only with your pseudonymous identifier.
Notifications
With your permission, Catto sends gentle daily summaries about your goals. Personalized morning recaps are sent through Expo's push service and Apple's Push Notification service. If the completed-day upload cannot reach our backend, Catto schedules a generic local recap on your device instead. You can turn morning recaps off inside Catto without disabling nap-guard warnings, or disable all Catto notifications in your device settings.
What Catto does not do
- No ads displayed inside Catto. Advertising identifiers are used for optional iOS ad measurement only with your permission.
- No sale of analytics or diagnostic data.
- No collection of contacts, photos, precise GPS location, or browsing history.
- No selling or renting of your data to anyone.
Children's privacy
Catto is not directed at children under 13 and does not knowingly collect personal data from them. If you believe a child under 13 has provided data, contact us so we can investigate and arrange deletion.
Data retention and deletion
Uninstalling Catto does not automatically delete records held by our service providers. You can delete your data at any time — see the account and data deletion page for step-by-step instructions.
Your rights
Under Brazil's General Data Protection Law (LGPD) and similar laws, you may request access to, correction of, or deletion of the data associated with your pseudonymous identifier, and you may object to or restrict certain processing. To exercise these rights, contact us using the details below. Note that because Catto does not require an account, we may need information from you (such as your owner ID) to locate the correct records.
Changes to this policy
We may update this policy as Catto evolves. When we do, we'll revise the "last updated" date at the top of this page. Material changes will be highlighted in the app or on this site.
Contact
Questions about privacy? Email praconfirmaconta@gmail.com.