Skip to content
Disturb Me Nots
Privacy Terms

Privacy Policy

Effective August 11, 2026 · Last updated August 11, 2026

Contents

  1. The short version
  2. Information we collect
  3. Automated picture moderation
  4. What we do not collect
  5. How we use information
  6. How information is shared
  7. Cookies, storage and analytics
  8. Push notifications
  9. How long we keep data
  10. Security
  11. Deleting your account
  12. US privacy rights
  13. EEA and UK privacy rights
  14. International transfers
  15. Children and privacy
  16. Changes to this policy
  17. Contact

Disturb Me Nots is a status-sharing app: you tell a group whether you are available, and they see it. That only works if some information about you is stored and shown to the people you choose. This policy explains exactly what is collected, who can see it, and how to get rid of it.

This policy applies to the Disturb Me Nots mobile application and to this website (together, the Service). The Service is operated by Andriamasinoro Mandresy Fenohasina, an individual developer (“we”, “us”). For data-protection purposes we are the data controller for the information described below.

The short version

  • We collect the minimum needed to run the app: your account details, the groups and friends you choose, and the statuses you set.
  • We do not sell your information, and we do not use it for advertising. There is no advertising network in the app and nothing about you is profiled, rented or shared for marketing.
  • We never collect your location, your contacts, your microphone, or your browsing history.
  • Your status is visible to the members of the groups you join — that is the point of the app — and to nobody else.
  • You can delete your account and everything in it from inside the app at any time, without contacting us.

Information we collect

Account information

When you create an account we store:

  • Email address. Used to sign you in, verify your account, and send essential service messages such as password resets. Verification is mandatory before you can use the app.
  • Display name. Whatever you choose. It is shown to your friends and to members of your groups. It does not need to be your real name.
  • Profile picture, if you upload one. Images are resized on your device and stored in our hosted file storage. Uploading is entirely optional; the app works without one. Every picture you upload — your own and any group picture you set — is checked by an automated moderation service before it is stored, and rejected if it is flagged. See Automated picture moderation.
  • A user code — a random six-character identifier generated for you. This is how other people add you. It replaces searching by email or phone number, so your email is never exposed to other users.
  • Time zone. Needed so scheduled statuses fire at the right local time.
  • Subscription tier (Free or Pro), so the app knows which features to enable.

If you sign in with Google or with Apple, we receive your email address and, where provided, your name and profile picture from that provider. We never receive your password. If you use Sign in with Apple and choose Apple’s Hide My Email, we only ever see the relay address Apple generates — that is fine, and the app works normally.

Your groups and connections

  • The groups you create or join, and whether you are an administrator of them.
  • Group names and group profile pictures.
  • Your friend list, and pending friend requests and group invitations.
  • Users you have blocked.

Status information

  • Your current status in each group — Available, Busy, Meeting, Sleeping, Working or Neutral. You can hold a different status in each group.
  • Status notes, if you add one. A short free-text note (up to 140 characters) shown alongside your status. Do not put anything sensitive in it: every member of that group can read it.
  • Status history — a record of which status you held and for how long, which powers the statistics screen.

Scheduled statuses

The recurring rules you set up (for example “Busy, 9am–12pm, Monday to Friday”), together with a log of when the system applied them, which we keep so that a schedule that misfires can be diagnosed.

Device and notification data

If you allow notifications, we store a push notification token issued by your device operating system. It lets us deliver a notification to that device. It is not an advertising identifier and cannot be used to track you across other apps. The token is deleted the moment you sign out, so a shared device never delivers one person’s notifications to the next person who signs in.

We also keep the time we last sent you a notification in each group — one row per group, nothing more. It exists so the app cannot spam a group with repeated alerts within seconds, and it is deleted with your account.

Purchase and subscription information

If you subscribe to Pro, the purchase is made through the Apple App Store or Google Play and processed by them. We receive a record that an entitlement started, renewed, lapsed or was refunded. We store that record as it reaches us, which means it also contains the product identifier, the price and currency, which store it came from, the country of the store account, and the store’s transaction identifiers, along with timestamps.

We never see or store your payment details. Card numbers, billing addresses and bank information go to Apple or Google and never reach our servers.

Safety and abuse prevention

  • Reports you submit about another user — the account reported, the reason you selected, where it happened, and any description you write. These are kept so a report can actually be reviewed and acted on.
  • Short-lived rate-limiting records. When someone looks up a user code, we briefly record the attempt so that nobody can guess their way through the code space to enumerate accounts. These records are automatically deleted after about a day.
  • Audit records for sensitive actions such as changing a profile or group picture, used to investigate abuse of those features.

Correspondence

If you email us for support or to exercise a privacy right, we keep that correspondence so we can answer you and show that we handled the request.

Automated picture moderation

App store rules require us to keep objectionable imagery off the Service, and we are one person — we cannot look at every upload. So every profile picture and group picture is checked automatically before it is stored.

The check is performed by OpenAI, using its moderation API. When you upload a picture, the image is sent to OpenAI, scored, and either accepted or rejected. We do not send your name, your email, your user code or any other detail about you with it — only the image. If the check cannot be completed, the upload is rejected rather than allowed through unchecked.

Your pictures are not used to train anything. Images sent for this check are not used to train OpenAI’s models, and we do not store a copy of the image with OpenAI — it is sent, scored, and the result comes back. The picture itself is stored only in our own file storage, and only if it passes. What OpenAI does with what it receives is governed by its own policy, published at openai.com/policies/api-data-usage-policies.

Nothing else is screened this way. Your display name, your group names and your status notes are not sent to OpenAI or to any other moderation service — they are reviewed only when somebody reports them.

What we do not collect

Rather than state this vaguely, here is the explicit position. Disturb Me Nots does not collect:

  • Your location. The app requests no location permission of any kind.
  • Your contacts or address book. People are added by user code only.
  • Your microphone or audio. Microphone access is explicitly disabled in the app build configuration.
  • Your photos, beyond the single image you deliberately pick as a profile or group picture. The camera and photo-library permissions exist for that one purpose.
  • Advertising identifiers (IDFA, Android Advertising ID).
  • Browsing history or activity in other apps.
  • Anything that follows you off the Service. Nothing here tracks you across other apps or other companies’ websites, and there is no advertising SDK in the app. What we do measure about our own website is set out in Cookies, storage and analytics.

How we use information

We use To Legal basis (EEA/UK)
Account information Create and secure your account, sign you in, verify your email Performance of a contract
Groups, friends, statuses Deliver the core feature: showing your availability to people you chose Performance of a contract
Status history Produce your personal statistics screen Performance of a contract
Time zone and schedules Apply your recurring status rules at the correct local time Performance of a contract
Push token Deliver status notifications to your device Consent, which you may withdraw in your device settings at any time
Subscription records Unlock Pro features and honour restores across your devices Performance of a contract
Reports, blocks, rate-limit and audit records Keep the Service safe, investigate abuse, prevent account enumeration Legitimate interests, and compliance with legal obligations
Pictures you upload Automated screening for objectionable imagery before the picture is stored Legitimate interests, and compliance with app store requirements
Email address Send essential service messages (verification, password reset, security) Performance of a contract

We do not use your information to build advertising profiles, and we do not make any decision about you by automated means that produces a legal or similarly significant effect.

How information is shared

With other users — the part that matters

The app is built to show information to specific people. Concretely:

  • Members of a group you belong to can see your display name, your profile picture, your current status in that group, and your status note in that group.
  • Your friends can see your display name and profile picture.
  • Setting your status to Sleeping or Meeting sends a push notification to the other members of that group. Other statuses update silently.
  • Your status is per-group. A status you set in one group is not visible to a different group.
  • Your email address is never shown to other users. People find you by your user code.
  • Blocking is enforced on our servers, not merely hidden in the interface: a blocked user cannot send you requests or reach your profile. We do not tell anyone that they have been blocked.

With service providers

These companies process data on our behalf, under contract, only for the purposes below:

Provider What it does What it handles
Supabase Hosting, database, authentication, file storage Effectively all account, group and status data
Expo push service, then Apple (APNs) or Google (FCM) Delivers push notifications to your device Push token and the notification text
Google Sign in with Google, if you use it Your email address, name and picture from your Google account
Apple Sign in with Apple, if you use it Your email or Apple relay address, and name if you share it
OpenAI Automated moderation of pictures you upload The image itself, and nothing else about you
RevenueCat Manages subscription entitlements across both stores Your account user ID, and the purchase record the store sends — product, price, currency, store, country and transaction identifiers
Apple App Store, Google Play Sell and bill the subscription Payment details, which they hold and we never see
Vercel Hosts this website and counts its page views Standard web server logs for the pages you are reading now, and the anonymous page-view data described under Cookies, storage and analytics

For legal reasons

We may disclose information if we are legally required to, or where we believe in good faith that it is necessary to investigate a violation of our terms, to prevent fraud, or to protect the safety of any person.

In a business transfer

If the Service is ever acquired or transferred, your information may transfer with it. You will be told before that happens and before any different privacy policy applies to you.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — under the California Consumer Privacy Act or any comparable law. We never have.

Cookies, storage and analytics

This website

This website sets no cookies. It stores exactly one thing in your browser, using local storage rather than a cookie: whether you chose the light or the dark theme. It is written only when you press the theme button, it is never sent to us or to anyone else, and clearing site data in your browser removes it.

The site uses Vercel Web Analytics to count page views, so we can see which pages people read and roughly where they arrived from. It sets no cookies and stores nothing on your device.

Each page view records:

  • the page address and the site that referred you, if any
  • an approximate location from your IP address: country, region and city
  • your browser, operating system and device type
  • the time of the visit

Your IP address itself is not stored. Repeat views within a day are grouped using a value derived from your request, and that value is discarded after 24 hours, so there is no way to follow one person across days, across devices, or onto any other website. None of it is linked to your Disturb Me Nots account, and it is never used for advertising.

What Vercel Web Analytics does with the data it receives is governed by its own policy: https://vercel.com/docs/analytics/privacy-policy .

The app

The app does not use cookies. It keeps two things on your device: a sign-in token, so you are not asked to log in every time you open it, and your own settings, such as your notification preferences. Both are removed when you sign out or delete the app.

Your account also has a user ID. That identifier is how your groups, your statuses, your schedules and your settings are linked to you in our database, and it is the same identifier shown on your Profile screen so that friends can add you. It is not an advertising identifier, it is not sold, and it is not used to recognise you anywhere outside Disturb Me Nots.

Push notifications

Notifications are optional. If you decline the permission, the app works normally; you simply see status changes when you open it. You can revoke the permission at any time in your device settings, and you can sign out to have the stored token deleted immediately.

How long we keep data

Data Kept
Account, profile, groups, friends Until you delete your account
Current status and status notes Until replaced by your next status, or until you delete your account
Status history (Free plan) 90 days, then deleted automatically by a scheduled job
Status history (Pro plan) Until you delete your account
Push token Until you sign out, or until your device tells us the token is dead
Last-notification timestamps Overwritten by the next notification; deleted with your account
Subscription records Until you delete your account. Records we could never match to an account are deleted after 90 days
User-code lookup rate-limit records About 25 hours, then deleted automatically
Abuse reports Up to 12 months, then deleted automatically. A report is kept even if the reported account is deleted — otherwise closing an account would erase the record of the behaviour
Support correspondence Up to 2 years

Security

  • All traffic between the app and our servers is encrypted with TLS.
  • Data is encrypted at rest by our hosting provider.
  • Your login session is stored in your device secure keystore — the iOS Keychain or the Android Keystore — not in ordinary app storage.
  • Access to every database table is enforced by row-level security, so the rules about who can read what are applied on the server and cannot be bypassed by a modified client.
  • Pictures are the exception, and we would rather say so than imply otherwise. Profile and group pictures are served from long, randomly-named web addresses that are not individually access-controlled: anyone who is given the address of an image can open it, the way an unlisted link works. The address is only ever handed to the app, and it cannot be guessed, but it is not protected by the rules above. Everything else — your statuses, your notes, your groups, your friends — is.
  • We do not store passwords; authentication is handled by our provider.

No system is perfectly secure, and we cannot guarantee absolute security. If we ever become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.

Deleting your account

In the app: Settings → Delete My Account. It takes effect immediately and needs no email to us. Deleting your account removes your profile, your statuses and status history, your scheduled statuses, your group memberships, your friendships and friend requests, your block list, your subscription records, your push token and your profile picture.

Some information survives, and it is worth being exact about which:

  • Reports other people filed about you, for up to 12 months from when they were filed. If deleting an account erased them, anyone could clear their record by signing up again.
  • Groups you created that still have members. The group carries on without you, administration passes to another member, and the group’s picture stays with the group — it belongs to everyone in it, not to you. A group with nobody left in it is deleted outright, picture included.
  • Anything we are legally required to retain.
  • Routine backups, from which deleted data disappears as they rotate, normally within 30 days.

If you cannot access the app, you can request deletion from our account deletion page.

Deleting your account does not cancel a subscription. Subscriptions are billed by Apple or Google and must be cancelled in your App Store or Google Play account settings.

US privacy rights

If you live in California, Colorado, Connecticut, Virginia, Utah, Texas or another US state with a comprehensive privacy law, you have the right to:

  • Know what personal information we hold about you and how it is used.
  • Access a copy of it.
  • Correct inaccurate information.
  • Delete it.
  • Opt out of sale, sharing for cross-context behavioural advertising, or profiling. There is nothing to opt out of: we do none of these things.
  • Not be discriminated against for exercising any of these rights. The app behaves identically either way.

Most of these are self-service: your profile is editable in the app, and account deletion is a single screen. For anything else, email support@disturbmenots.com. We will verify the request against the email on your account and respond within 45 days. You may use an authorised agent, in which case we will ask for proof of their authority.

EEA and UK privacy rights

Under the GDPR and UK GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on our legitimate interests. Where processing rests on consent — push notifications — you may withdraw it at any time without affecting processing carried out beforehand.

Email support@disturbmenots.com to exercise any of them; we respond within one month. You also have the right to lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the United Kingdom.

International transfers

We operate from the United States, and our providers may process data in the United States and elsewhere. This includes the picture moderation described above: an image you upload is sent to OpenAI in the United States before it is stored. Where data is transferred out of the EEA or the United Kingdom, it is protected by the European Commission Standard Contractual Clauses (with the UK Addendum where applicable) entered into with our providers, or by another lawful transfer mechanism.

Children and privacy

The Service is not directed to children. You must be at least 13 to use it, or at least 16 if you are in a country where 16 is the minimum age for consenting to data processing. We do not knowingly collect information from anyone below that age. If you believe a child has created an account, email us and we will delete it.

Changes to this policy

If we change this policy we will update the “last updated” date at the top. For changes that materially affect your rights or what we collect, we will give notice in the app before the change takes effect.

Contact

Questions, requests or complaints about privacy: support@disturbmenots.com.

Data controller: Andriamasinoro Mandresy Fenohasina.

Questions about this document? Email support@disturbmenots.com.

Disturb Me Nots

Let people know when not to knock. Set your status in a group and everyone in it sees the change instantly, so nobody has to guess whether now is a bad time.

The app

  • How it works
  • Statuses
  • Pricing
  • FAQ

Legal

  • Privacy Policy
  • Terms of Use
  • Delete your account

Contact

  • support@disturbmenots.com

© 2026 Disturb Me Nots. Built and run by one developer.