CtrlAltMove is made by Lifesaver Labs Public Benefit Corporation ("Lifesaver Labs", "we"). CtrlAltMove locks your computer until you've moved your body. Doing that honestly requires knowing where you are and how you're moving — so this policy is written to be read.
The short version: your movement evidence — locations, heart rate, steps, pace — is processed on your phone and is not uploaded. Your account carries your schedule, settings, and pass/fail outcomes so your devices agree. Optional, opt-out diagnostics tell us when the app crashes and which features get used. We don't sell personal data and we don't show ads.
What stays on your phone
These are processed and stored only on your device. We do not receive them:
- Where you've been. Gym locations you save, and your visit log — which gym, when you arrived and when you left — kept on the phone, for you, until you delete it from Settings, so you can see your gym time by month, quarter, and year. Your precise location is used only in the moment, to check you are at a gym, and is never stored.
- Health readings. Heart rate, steps, distance, and pace are read from Apple Health / Health Connect (and, if you pair one, a Bluetooth heart-rate sensor) with your permission, and reduced on the device to a pass/fail verdict against the rule you configured. The readings themselves are not stored durably and are not sent to us.
- Your birth year, used only to compute heart-rate zones and confirm the app is age-appropriate. It stays on the device.
- Pairing secrets and unlock codes for your computers.
What your account stores (if you sign in)
Signing in exists so your phone and computers agree. Your account, hosted on Google Firebase, stores:
- Identity: the email address (or Apple/Google sign-in identity) you used, and internal account identifiers.
- Your protection plan: workout schedule, lockout settings, and their revision history.
- Outcomes: one record per deadline — met, missed, waited, or an emergency unlock — so every signed-in device shows the same history and your computers unlock. Outcomes never include health readings or locations.
- Live progress, only if you enable it: while a deadline is open and "live on desktop" is on (and on-screen privacy is off), the phone publishes how far along each route is — a percentage, not the underlying readings. It is held only while that deadline is current, then deleted.
- Emergency-unlock ledger: when you spend an emergency unlock, the event and the reason you selected are recorded against your account so all your devices honor one shared budget. Only you can read it; reasons are never shared with Spotters automatically.
- Spotters, if you invite them: your chosen contacts receive the events you agreed to share (for example, a missed deadline). After an emergency unlock you may choose, per event, to send your Spotters a short note in your own words, and only what you type or approve is sent.
Purchases
Subscriptions are processed by Apple's App Store or Google Play — we never see your payment details. We use RevenueCat to know whether your subscription is active; what we receive is your subscription status, product, and store, tied to your account identifier.
Stakes (optional)
If you choose to put a stake on a week, you link a bank account or a card on a page hosted by Stripe. Your bank and card details go to Stripe, never to us. We store a Stripe customer id, the card brand, the last four digits, and the expiry month and year — or, for a bank account, the bank name and last four digits — so the app can show you what is on file; and the stake ledger — the amount, the plan revision it was bound to, the outcomes at judgement, every change of state, and the text of any contest you send. When you delete your account, the Stripe customer and the bank account or card on file are deleted with it. The stake ledger is a financial record: it is kept for seven years after the last settlement, detached from your account and email and keyed only by an opaque id, so a refund, a dispute, or a tax question can still be answered. Your birth year still never leaves the phone: the stake records only that you attested to being 18 or older. If you choose to send part of a forfeit to your Spotters, the Spotters you have at the time of a charge, and the amount each received, are recorded on the stake ledger too. A Spotter who opts in to receiving shares gives Stripe their identity and bank details directly — never to us — and we store their Stripe account id, whether their account can receive transfers, and their share ledger: each share, the stake it came from, its amount, and its state. A Spotter's share notice tells them that a stake of yours forfeited, and the amount.
Diagnostics and analytics (opt-out)
To keep the app working we collect, unless you turn it off in Settings:
- Crash reports (via Sentry): what went wrong in the code, app version, and device model. We scrub identifying content — including your schedule's identifiers — before reports leave the device, and crash reports are not linked to your account.
- Problem reports you send ("Report a problem" in the app): your description plus your account id, sign-in email, device id, app version, and platform — shown to you in full before you send, so we can find exactly which account and device had the problem. Delivered to Sentry when crash reporting is on, otherwise as an email you send yourself. Nothing is sent unless you press Send.
- Usage analytics (via PostHog): which features are used — from a fixed list of events such as "onboarding completed" or "deadline set" — under a random per-install identifier that is deliberately not joined to your account. These events never include health values, locations, gym names, or your schedule's contents.
One switch in Settings turns both off. We may adjust what diagnostics we collect as the product evolves — within the boundaries above (no health readings, no location history, no sale of data) — and material changes will show up in this policy and its effective date.
Third-party services
We use a small set of processors to run the product: Google Firebase (account, sync, and messaging), RevenueCat (subscription status), Stripe (bank account or card on file and charges if you place a stake; identity and payouts if you opt in to receiving stake shares as a Spotter), Sentry (crash reports), PostHog (usage analytics), and Apple/Google (payments, push notifications). On Android, the optional map on the add-gym screen loads tiles from Google Maps, which involves your IP address like any web request. Each processor receives only what its section above describes, and none of them are permitted to use your data for their own advertising.
We do not sell personal data. We do not show ads. We share data beyond the processors above only if the law requires it, or to protect someone's safety.
Retention and deletion
- Gym visit log (arrival and departure times per gym): kept on-device until you delete it from Settings — it is your record of your gym time. Precise location: not stored.
- Live route progress: deleted when its deadline resolves.
- Account data: kept while your account exists. Deleting your account in Settings deletes your account records, subscription linkage, and sign-in identity from our systems. App Store/Play purchase records are governed by Apple/Google. The stake ledger and a Spotter's share ledger are financial records kept seven years, detached from the account (see Stakes above).
- Crash reports and analytics: retained on our processors' standard schedules, then deleted or aggregated.
Your choices
- Every permission (location, health, motion, Bluetooth, notifications) is optional; the app degrades honestly without it.
- Live-on-desktop progress and on-screen privacy are controls, not defaults — progress publishing requires your explicit setup.
- Diagnostics and analytics: one opt-out switch in Settings.
- Spotters are chosen by you and removable by you.
- Account deletion is in Settings, not an email queue.
Depending on where you live you may have additional legal rights (access, correction, deletion, portability). Contact us and we'll honor what applies: privacy@ctrlaltmove.com.
Children
CtrlAltMove is not directed at children under 13, and the onboarding age question exists partly to keep it that way. We don't knowingly collect personal data from children under 13; if you believe a child has used the app, contact us and we'll delete the data.
Security
Pairing uses end-to-end key exchange between your own devices; backups you export are encrypted with a passphrase only you hold; account access requires your sign-in. No system is perfect, but the design principle throughout is that the most sensitive data — where you go and how your body performs — never leaves the phone in the first place.
Changes
We'll post changes here and update the effective date. Material changes to what we collect will also be called out in the app.
Contact
Lifesaver Labs Public Benefit Corporation
Boca Raton, FL, USA
privacy@ctrlaltmove.com