Barriers
Privacy
Privacy Policy
Last updated: 12 September 2026
Barriers is built local-first: by default your information lives on your device and, if you enable it, in your own private iCloud account — we cannot see it. An optional online account is available only if you choose to sign in to share tasks with family. The app contains no advertising or third-party analytics SDKs, and the optional usage & diagnostics reporting described below stays off until you switch it on.
Who we are
Barriers is a product of IV Technologies Ltd, a company registered in England & Wales (company no. 17316561). IV Technologies Ltd is the data controller for the optional online account. In this policy, "we", "us", and "our" mean IV Technologies Ltd. You can reach us at support@ivtechnologies.uk.
Two ways to use Barriers
- On this device (default) — no account, no sign-in. Your tasks, finances and receipts stay on your device and, if enabled, your personal iCloud. We never receive them.
- Online account (optional) — to share tasks with family members you sign in, and your family data is stored on our cloud backend. You can use the app fully without ever choosing this.
What you put in the app
- Tasks — titles, notes, deadlines, completion status, optional attached photos.
- Finance — income, outgoings, expenses, savings figures and your chosen currency.
- Receipts — photos you scan, plus vendor, amount, date and category.
- App lock — a 4–6 digit PIN (stored as a salted, irreversible hash — an install old enough to predate that change still holds the PIN it was given until the first time you unlock, which converts it) and your biometric preference.
Where it is stored
- On your device — standard local storage (UserDefaults on iOS/macOS, SharedPreferences on Android) plus the app's sandboxed files for images.
- In your iCloud (optional) — if iCloud is enabled, text data syncs through Apple's iCloud Key‑Value store and backups/images through the app's private iCloud Documents container. This stays inside your Apple account; we never see it. Sync keeps your iPhone, iPad and the companion Mac app in step; the Apple Watch app is not part of that sync — it receives the list from the paired iPhone over Apple’s direct device-to-device link.
- On Android — the system’s Auto Backup may copy the app’s data to your own Google Drive as part of your device backup; sign-in session keys are excluded from that backup. This stays inside your Google account; we never see it.
- In a shared area of your own device that the Home Screen widgets, the Lock Screen Live Activity and the Apple Watch app can read — an App Group on iPhone, a private preferences file on Android. It holds only what those small surfaces show: how many tasks are open, and a short list of the nearest ones — task id, title and deadline. It also holds anything you do there while the app is closed — a task ticked off, a deadline moved to tomorrow, an assignment accepted or declined, a task dictated on the wrist — until the app next opens and applies it. The Apple Watch keeps its own copy of that same short list, in its own App Group on the watch, so the face complication and a cold launch have something to draw before the phone answers; deleting the Watch app removes it. None of it is sent anywhere.
- In your device's own calendar, but only if you turn on calendar publishing — see Device permissions and What leaves your device below.
Online account (optional)
If you create or join a family, you sign in with Apple, Google, or your email address — either with a password you choose, or with a one‑tap sign‑in link we email you. A device used by a child can instead sign in with no email and no password at all: that account exists only on that device, so it cannot be recovered if the device is lost. Authentication and storage for this feature are provided by Supabase, our third‑party cloud processor. When you use an online account we store, on that backend:
- Your account identifier and, where provided, email and a display name you choose. Sign in with Apple uses a private relay address; we store your display name, not a real email.
- Your family membership and role, and the name the family was given when it was created.
- Family tasks you create, are assigned, accept, complete or decline — heading, description, deadline, status, which member assigned or completed them, and any short note you attach when declining.
- Receipts you file to your family — the vendor, the amount, the currency, the date, the category and any note you write, stored so the other members of that family can see them, alongside the photo. A receipt you keep to yourself is not sent.
- Photos, stored as image files: a photo you attach to a family task or a family receipt, so the other members of that family can see it; your profile picture, if you set one; and, if you have paid access, your own receipt photos, backed up so a reinstall does not take them with it.
- Up to two push notification identifiers for each device you sign in on, so family events (a new task, an acceptance, a nudge) can reach you: one for ordinary notifications, and on iPhone a second one that lets an incoming assignment raise the Lock Screen card while the app is closed. On Apple devices both are anonymous identifiers issued by Apple; on Android the one identifier is a registration token issued by Google's Firebase Cloud Messaging, which the app obtains from Google when it first launches on that device. Each is deleted when it stops working or when you sign out, and used for nothing else. The notification itself carries the task's heading, because that is what the banner and the Lock Screen card show — Apple's push service — or Google's on Android — delivers it to your phone as it would any notification.
- If you buy something while signed in, the store's own record of the purchase, so your unlock follows your account instead of one device. From Apple that is: the product and subscription group, the transaction identifiers, whether the purchase is yours or shared with you through Family Sharing, the purchase, renewal, expiry and any revocation dates, the auto‑renew setting, the storefront country, the price and currency the store charged, any introductory offer applied, and Apple's app‑level transaction identifier, which is stable for your Apple Account and this app. From Google Play it is the purchase token and what Google says about it. We keep a fixed list of those fields and nothing else: no name, no email address, no payment instrument, and never the signed receipt itself. We never see your payment details.
- If you link Alexa, a pairing code, the identifier Amazon uses for your Alexa account (so the skill knows whose list to add to), and any voice‑added tasks awaiting import.
Family data you create or are assigned is visible to members of that family. You are responsible for who you invite. When you ask to join a family, your request and your display name are shown to that family's owner and admins so they can decide — including if they decide to decline you. This data is transmitted over HTTPS and held by Supabase on your behalf; it is not sold, rented, or used for advertising.
Usage & diagnostics (optional — off by default)
If you switch on "Share usage & diagnostics" in Settings → Privacy, the app sends us anonymous counts of what it was asked to do — which section you opened, that a task was added by voice or by camera, that a purchase succeeded or failed, that a sync failed, that something took a long time. Each record carries the app version, the platform, your language code and a random identifier. This is our own small database table, not a third-party analytics SDK; the app contains no such SDK.
How you are asked. Once, and not on the way in: after you have opened the app a few times, a card appears in your list offering the choice. It is not a dialog, it does not block anything, and ignoring it is a real answer — whichever way you answer, or if you never answer, it does not come back. The setting stays in Settings → Privacy for whenever you change your mind.
What a record never contains. No task, note, deadline, amount, receipt or photo — nothing you typed or scanned, in any form. No name, no email address, no account, family or user identifier. No device identifier, no advertising identifier, no location, and no IP address stored with the record. The list of things a record can say is fixed in the app’s code and enforced again by our database, which refuses anything that is not on it.
The identifier. A random 32-character value created on your device when you switch the setting on and deleted when you switch it off — switching it on again creates a new one. It is not your device ID, not your Apple or Google account, and it is not linked to a Barriers account if you have one. It exists only so that ten uses of a feature by one person do not look like ten people.
Where it goes, and for how long. To Supabase, our cloud processor, over HTTPS, into a table only we can read. We delete the records after 90 days. They are never used for advertising, and never sold or shared. It is off unless you switch it on, you can switch it off at any moment, and anything still waiting on your device is deleted the moment you do.
Third-party services
Depending on the platform you are on and the features you use, data may be processed by Apple (App Store payments, iCloud, Sign in with Apple, Speech, Vision, Apple Intelligence's on‑device language model, Siri and Shortcuts, push notifications on Apple devices, the App Store version lookup, and — if your calendar account is iCloud — the calendar events the app publishes); Google (Google Play payments on Android and the check that confirms a Play purchase with Google; push notifications on Android through Firebase Cloud Messaging, including the registration identifier that service issues when the app first launches; Android's Auto Backup, which copies app data into your own Google Drive; Google sign‑in, if you choose it; and, if your calendar account is a Google one, the calendar events the app publishes); Supabase (online‑account authentication and storage, and optional usage & diagnostics storage); open.er-api.com (the public currency reference rates the app reads when it starts); and Amazon Alexa (only if you link it). Each is governed by its own privacy policy; we are not responsible for their independent practices.
What leaves your device
- Currency rates — to convert foreign amounts, the app makes an anonymous HTTPS request for public reference rates from
open.er-api.com. It happens once each time the app starts, on every platform, whether or not you have ever opened Finance. No personal or financial data is sent — the provider sees only your device's network address, as any website would.
- Receipt and document text recognition — runs on the device on iPhone, iPad and Mac, through Apple's Vision framework: the photograph is never uploaded.
- Dictation — runs on iPhone, iPad and Mac through Apple's Speech framework, governed by Apple's privacy policy. Where your language has an on‑device model, it stays on the device. Where it does not — which depends on the language and on how new your device is — Apple's recogniser uses its server path instead of the feature simply being unavailable, and the audio you dictate is sent to Apple to be transcribed. We never receive it either way.
- Apple Intelligence — on recent Apple devices with Apple Intelligence switched on, Apple's on‑device language model reads a dictated sentence, or the text Vision lifted off a photographed page, to work out how many separate tasks are in it. It runs on the device and sends nothing.
- Siri and Shortcuts — can add a task without opening Barriers. When they do, Siri asks what the task should say and transcribes it through Apple's own pipeline under Apple's privacy policy — not through the app — and the finished task is written to your device like any other.
- Android has neither dictation nor text recognition — those features do not exist there, so nothing is sent for either.
- A version check when the app starts — on iPhone, iPad and Mac, an anonymous read of the app's public App Store record from
itunes.apple.com; on Android, a read of the current Android version number from our backend. Neither carries anything about your tasks, finances or receipts, and both happen whether or not you have an account. On Android, if you are signed in, that read travels on your account's own connection to our backend, like every other request the app makes there — so it is not anonymous to us the way the App Store lookup is.
- Calendar publishing, if you turn it on (iPhone, iPad and Mac) — the heading, description and deadline of each active task that has a real deadline and has not been handed to someone else are written into a calendar of the app's own, named "Barriers", on your device. Tasks parked for "at some point", and tasks you assigned to another family member, are not published. That calendar is created in whichever account your device already uses for new events. If that account is iCloud — as it usually is — or a Google or Exchange account you have added, then those events sync through it to your other devices exactly as an event you created yourself would. We are not part of that: the app writes locally, and your calendar account does the rest. Reading your calendar is different — the day's events are used to draw the strip beside your tasks and are never stored, synced, exported or sent anywhere.
- In‑app purchase — the one‑time unlock and the family subscription are processed by Apple on iPhone, iPad and Mac, and by Google Play on Android. We never receive your payment details. If you are signed in, the store's receipt identifier is used to attach the purchase to your account — on Android that means sending the Play purchase token to our backend so Google can confirm it.
Nothing in that list identifies you. Beyond it, the app sends data only if you use the optional online account, or switch on the optional usage & diagnostics reporting described above. The one exception is the Android version check while you are signed in, described above: it travels on your account's own connection to our backend.
Device permissions (requested only when used)
- Camera & Photos — scan receipts/documents and attach images.
- Microphone & Speech Recognition — dictate tasks.
- Face ID / Touch ID — unlock the app.
- Notifications — reminders and family‑assignment alerts.
- Alarms & reminders (Android) — so a deadline reminder arrives at the minute you set. Decline it and reminders still arrive, just approximately.
- Calendar (iPhone, iPad and Mac) — asked when you turn on one of the two calendar switches in Settings; both are off until you do. iOS and macOS grant calendar access as one thing, so the app is able to read your calendars as well as write to them. With today's events on, it reads the titles and times of today's events, for that day only, to draw them beside your tasks; nothing it reads is stored, synced or sent. With publishing on, it writes your task deadlines into a calendar of its own — see What leaves your device above. Turning publishing off takes the events it created back down.
You may decline or revoke any permission in your device's system settings; the related feature simply turns off.
Purchases & subscriptions
Barriers is free to download. Finance and Receipts, and dictating several tasks in one breath, are unlocked by a single one‑time purchase. Family is a separate auto‑renewing subscription, billed monthly or annually, with fourteen days free for new subscribers where the store finds them eligible — you can cancel it any time in your App Store or Play Store account settings. Writing tasks down, sharing a household and assigning tasks within it cost nothing; what the free tier includes is shown on the Compare plans screen in the app, which is the current authority and can change between releases. Purchase, renewal, restore and refunds are handled entirely by the App Store or Play Store, and we never see your payment details. If you are signed in, the store tells us which product was bought, whether it is still active and when it renews, together with its transaction identifiers and the rest of the fixed field list described under Online account above.
Your control & deletion
- Export a full backup any time (Settings → Data).
- Deleting the app removes on‑device data. To remove synced data, delete it from iCloud (Settings → [your name] → iCloud → Manage Storage).
- One thing is not in the app — deadlines already published to your calendar belong to your calendar. Turn calendar publishing off, or use Settings → Data → Erase everything, before you delete the app or revoke calendar access. Afterwards the app can no longer take them back down, and the "Barriers" calendar has to be deleted by hand in the Calendar app.
- Online account — leave a family in Settings to stop sharing. To close the account itself, use "Delete account" in Settings — it removes your online account, profile and family membership from our backend, and, if you own a family, that family together with the tasks and receipts shared in it. Your data on this device and in your iCloud is untouched. The steps are set out on Delete your account & data, or you can email support@ivtechnologies.uk.
- Calendar — turning off calendar publishing in Settings deletes the events the app created. Turning off the day's‑events strip stops it reading your calendar. Neither switch touches your own events. Revoking calendar access in your device's system settings stops both, but it also takes away the app's ability to remove what it has already published, so turn publishing off first.
- Usage & diagnostics — switching it off in Settings → Privacy stops collection and deletes anything still held on your device. Records already sent carry no link to you or your account and are deleted after 90 days; email support@ivtechnologies.uk with any question about them.
Children
Barriers is not directed at children under 13 and is not intended for their use.
Changes
We may update this policy; material changes will appear here and in the app, and continued use after an update means you accept it.
This website
barriers.info is a static website hosted by Netlify. Like any web host, Netlify keeps standard server logs — the IP address a page was requested from, the page, the time, and the browser’s identification string — for a short period, for security and to keep the site running. We do not use them to identify you.
The site’s typefaces are loaded from Google Fonts, so Google may receive your IP address when a page loads.
The site sets no cookies. It uses your browser’s local storage for one thing: the language you choose in the picker. If you sign in on the web to join a household, your sign-in is handled by Supabase, our cloud processor, and your session is kept in the browser until you sign out.
There is no advertising, no analytics and no tracking on this website.
Contact
support@ivtechnologies.uk