Tirly Privacy Policy
Effective date: September 12, 2026
Tirly ("the app," "we," "us") is developed by Raye Technology. This
policy explains what information Tirly collects, what stays on your
phone, what reaches our servers, who else processes it, and how to
delete it.
Summary
Tirly blocks apps you choose according to rules you write: while a
friend is nearby, at certain times, after a number of opens, or at a
place you name. Whether a friend is nearby is decided between the two
phones over Bluetooth and an inaudible sound, never by our servers. Your
account holds your phone number, the name you give yourself, who your
friends are, a copy of your rules so they survive a reinstall, and your
daily screen-time totals for the friends leaderboard. We
show no ads, use no analytics SDKs, and never sell your information.
Information We Collect
Account
- Phone number. You sign in with a one-time code sent
by SMS through Twilio. We store your number as entered, in international
format, together with a hashed form of it used for contact matching. The
number is your account: it is how you sign back in and how friends find
you.
- Name. Tirly asks for a name at sign-in and requires
one. It is sent to our servers and shown to people you have sent a
friend request to, people you are friends with, and everyone in a
Tirly session with you, including someone waiting to be let in, whether
or not you are friends. Nobody else can read it. You can change it from the Account tab; signing out clears it from
our servers.
- Sign-in token. A random credential that keeps the
app signed in. Signing out or signing in on another phone revokes
it.
Contacts
- With your permission, the app reads your address book to show you
which contacts already use Tirly and to put names on your friends. It
sends a salted hash of each phone number to our server
for matching. We match those hashes against our accounts and do not
keep them. Contact names never leave your phone.
- Hashing hides a number from casual reading, but phone numbers are
few enough that a determined party holding our salt could test
candidates against a hash. Treat the hash as a stand-in for the number
rather than as an irreversible secret.
- Inviting a contact who is not on Tirly prepares a text message for
you to send from your own messaging app. Nothing about that person is
sent to us. The message carries an invite link; when somebody signs up
through it, our server adds one to your invite count and records that
the new account claimed an invite. When you sign up through a friend's
invite, Tirly remembers who invited you so they can be rewarded when
you subscribe, and when you do, they are told the name you gave Tirly
and nothing else about you; it is deleted with your account.
Friends
- A friendship is a row on our server holding the two accounts, its
status (pending, active or removed), timestamps, and one random key
from each phone. The two phones use those keys to recognise each
other's Bluetooth signal. The keys are held so a reinstalled phone can
recognise its friends again.
- Either person can remove a friendship at any time. The row is kept
marked as removed, with its keys cleared, so that the two of you can
become friends again later. Once removed, neither of you can read the
other's name or keys.
- A friend request by phone reveals your name to the person asked. It
reveals nothing about them to you until they accept.
Rules
- The rules you write are evaluated on your phone. A copy of them is
also saved to your account so they come back after a reinstall or a new
phone. That copy contains everything a rule is: which apps it blocks
(their package names), what triggers it, the friend it names, the
schedule, the allowance, and, for a location rule, the address you
typed and the coordinates and radius of that place.
- Our server stores that document as an opaque whole and does not
read or act on it. It is replaced each time your phone saves.
- Asking a friend's permission to open a blocked app sends our server
the app's package name and label, who you asked, and their answer, so
the request can reach them and their answer can reach you. A request
lasts five minutes.
- Whether a block is in force, and every app you open, stays on your
phone. Tirly reads which app is in the foreground through Android's
Usage Access and never sends it anywhere.
- Tirly Pro can also block a rule's websites in your browser and count
time on them toward a time or open limit. That uses an Android
accessibility service which reads only the address bar of the browser in
front, only for a site one of your rules covers, and compares it with the
rule on your phone. No address or browsing history is stored or sent
anywhere; the only record kept is the minutes and visits counted against
your own limits, on the phone and excluded from backup.
Bluetooth and the microphone
- Friends' phones find each other over Bluetooth Low Energy using the
keys above. What is on the air is a short identifier derived from those
keys and a signal-strength reading; no name, number or location is
broadcast, and none of it passes through our servers.
- To tell a friend in the room from a friend behind a wall, one phone
plays a brief tone above the range of hearing and both phones listen for
it. This opens your microphone for about one second at a
time. It happens when you open a blocked app, and also on your
phone at a friend's request while Tirly is in the background, which is
why the app runs a foreground service with microphone access. The
recording is reduced on the phone to a few numbers describing whether
and how loudly the tone arrived; no audio is stored, sent to the other
phone, or sent to us. Playing the tone briefly raises the alarm volume
and restores it afterwards.
- The app also reads the barometer, where the phone has one, to help
tell floors apart. That reading stays on the phone.
Location
- Tirly declares the precise, approximate and background location
permissions. They are optional and are asked for only
when you create a rule that applies at a place. Without a location
rule, Tirly never asks for or reads your location.
- With a location rule, your phone compares its position with the
place in the rule, on the phone. Where you are now is never sent
to us and is never written to disk. The place itself, as
typed and as coordinates, is part of the rule copy saved to your
account (see Rules).
- Background location lets the rule keep working while Tirly is not
on screen. Declining it keeps the rule from working and changes nothing
else.
- Bluetooth scanning is declared as never used for location.
Tirly sessions
- Opening a Tirly session creates a record on our server of who
hosted it, who joined, when, and when it was locked or ended. Joining
one makes you and the host friends immediately. Locking one keeps every
phone in it, the host's included, out of every app but Tirly for thirty
minutes; the end of that lock is kept on each phone so it expires even
offline.
- Members are identified to each other by hashed phone number and by
the name they gave themselves.
Notifications
- To reach your phone while Tirly is closed, the app registers a push
address (a Firebase Cloud Messaging token) with our server. A push
carries only a kind and an id; the words come from our server when the
app wakes. Google learns that a message was sent to your device and
nothing about its subject.
Screen time
- Your screen time and pickups are measured on your phone with Usage
Access. So that you and your friends can compare, the app uploads one
figure per day to our server: your total screen time for each of the
last seven complete days. Nothing finer leaves the phone — no
app names, no times of day, no pickups. Only people you have accepted
as friends see your daily average, and you see theirs; there is no
separate switch for this, since being friends is what puts you on each
other's board. Removing a friend removes you from each other's board at
once, and the totals are deleted with your account.
Tirly Pro
- Tirly Pro is bought through Google Play. Google handles payment and
holds your payment details; we never see them. Purchases are managed for
us by RevenueCat, which receives your purchase from Google Play under a
random billing identifier we create for your account — not your
phone number, name or any identifier of the phone.
- Our server keeps your subscription standing: the plan, whether it
renews, when it expires, and the store it came from, and a record of
each purchase event RevenueCat reports (product, price and currency,
dates, and Google's order identifier). We use them to decide what the
app unlocks, to share a yearly or lifetime plan with the people you seat
on your pass, and to reward the friend who invited you. After a
purchase, and from time to time while you use the app, our server asks
RevenueCat for your current purchases under that identifier so the
account and the store agree.
- When a friend you invited pays for Pro, you earn a point; the first,
tenth and fiftieth points are Pro credit. For a renewing plan we apply
the reward by asking Google Play, through its developer API, to defer
your next charge; that request carries your Google purchase token and
nothing else about you.
Information We Do Not Collect
- Your current location, or any location history
- Audio recordings, or any audio at all
- Contact names, or contact numbers in the clear
- Which apps you open, or when a block engages or lifts
- Browsing history, message content, or the content of any app
- Advertising identifiers, analytics or crash-reporting data
What Your Phone Holds
The app keeps on the phone: your sign-in token; your friends and the
keys their phones are recognised by; which of your contacts are on Tirly
(as hashed numbers and the names from your address book, so the list does
not have to be rebuilt each time you open the app); your rules; your
screen-time history, including time by app; the time and visits counted
against a limit; your Tirly Pro standing; badges; and the current Tirly
session. Your sign-in token, your friends and their keys, the contact
list, the current Tirly session, every rule and limit record, your Pro
standing, the leaderboard, time by app and the push registration are
excluded from Android's cloud backup and device-to-device transfer.
Uninstalling Tirly removes all of it; it does not delete your account.
How We Use Information
| Data | Used for |
| Phone number and its hash | Signing you in; letting your contacts find you |
| Name | Naming you to friends and people you ask |
| Contact hashes | Telling you which contacts use Tirly; discarded after matching |
| Friendships and keys | Letting friends' phones recognise each other, and restoring that after a reinstall |
| Rules document | Restoring your rules on a new install |
| Permission asks | Carrying a question to a friend and their answer back |
| Tirly sessions | Keeping everyone in a session in agreement about who is in it |
| Push address | Waking the app when something is waiting for you |
| Invite count | Showing you how many people joined through your link |
| Who invited you | Rewarding the friend whose invite you signed up through |
| Daily screen-time totals | Ranking you and your friends by average screen time |
| Purchase standing and events | Unlocking Tirly Pro, sharing a pass, rewarding the friend who invited you |
We use nothing for advertising, profiling, or sale, and we do not
share information with anyone for those purposes.
Third Parties
- Twilio receives your phone number to send and
check the SMS sign-in code.
- Google Firebase Cloud Messaging delivers push
wake-ups. Google holds your device's push token and sees that a message
was sent, not what it concerns.
- Android's geocoder (Google's service on most
phones) receives the address text you type while making a location
rule, to turn it into a place and to suggest completions as you
type.
- OpenStreetMap serves the map tiles drawn around a
place you chose, so the OpenStreetMap Foundation sees requests for the
map squares around that place, with the app's version in the
request.
- Google Play processes payments for Tirly Pro and
holds your payment details; we receive only the purchase and its order
identifier. For a referral reward on a renewing plan we ask Google Play
to defer your next charge.
- RevenueCat manages Tirly Pro purchases. It holds
your purchases under a random billing identifier and reports them to our
server; our server also asks it for your purchases after a purchase and
periodically. It never receives your phone number or name.
- Render hosts our servers and database.
Each of these processes data to provide the service described and
under its own privacy policy. None of them receives your contacts, your
friends, your rules, or your current location.
Data Retention & Deletion
- Your account and everything attached to it is kept while the
account exists.
- Permission asks expire after five minutes and friend requests after
fourteen days, after which they no longer appear, and removed
friendships are kept as removed with their keys cleared.
- Signing out revokes your sign-in token, clears your name, and
forgets your phone's push address; it leaves the account for your next
sign-in.
- Deleting your account, from the Account tab or as described at
/delete-account/, immediately and
permanently deletes your phone number, name, friendships and keys,
rules document, asks, push addresses, invite records, session records
and any daily totals, your subscription standing, and your purchase
record at RevenueCat. Anonymous purchase event records, which no longer
name any account, are kept for our accounts. Your friends' phones stop
recognising yours, and any rule they wrote that named you is removed
from their phone.
Children's Privacy
Tirly is not directed at children under 13 (or the relevant minimum
age in your jurisdiction), and we do not knowingly collect information
from them.
Changes to This Policy
We may update this policy as Tirly evolves. Material changes will be
reflected here with an updated effective date.
Contact
Questions about this policy or your data:
info@rayetechnology.com. The
Account tab's Feedback/Bug Report row opens your own email app addressed
to support@rayetechnology.com
with the app version and your phone's model and Android version filled
in; you can edit or delete any of it before sending, and nothing is sent
unless you send it. We keep support emails to answer them and for as long
as the matter is open.