KOVE Privacy Policy · 3 Bears Studio LLC

KOVE Privacy Policy

Publisher / data controller: 3 Bears Studio LLC ("3 Bears Studio," "we," "us," or "our")
Application: KOVE for iOS (the "App")
Effective date: July 23, 2026
Last updated: July 23, 2026
Privacy contact: hello@3bears.studio


1. About this policy

This Privacy Policy explains how 3 Bears Studio LLC collects, uses, discloses, and protects information in connection with the KOVE mobile application and describes the choices and rights available to you. It applies to the App and to the limited online services that support it (together, the "Services"). It does not apply to any third‑party product, website, or service that we do not own or control, including Apple, Google, and the third‑party services described in Section 8.

KOVE is a personal focus, app‑blocking, and habit‑tracking application. It is built on a deliberate principle: the information you would most want kept private is designed never to reach us in the first place. Where that is true, we say so plainly and explain the technical reason, because the strongest privacy protection is architectural, not merely promised.

By downloading, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the App. Certain features (the optional social features described in Section 5) require your separate, affirmative opt‑in before any information described there is collected.

This policy is written to be read by a person, not only by a lawyer. Section 2 is an at‑a‑glance summary; the sections that follow give the complete detail that governs.


2. Summary at a glance

This summary is provided for convenience only and is qualified in its entirety by the full policy below.

Question Short answer
Do you store my blocks, habits, focus history, or screen‑time data? No. They live in your own private iCloud. We have no server‑side copy and no way to read them (Section 4).
Do you collect my location? No. Location‑based blocking is evaluated entirely on your device; coordinates never reach us (Section 4).
Do you read my Apple Health data? Only on your device, to power habits and challenges. Raw Health samples never leave your device. The one narrow exception — a single daily number for a health challenge you join — is described in Section 5.
Do you run analytics? Yes — anonymous analytics (counts and categories, never content). We never link them to your identity (Section 5).
Do the social features collect data? Only if you choose to sign in to them. Then we collect your account ID, sign‑in email, display name, the activity you deliberately share, and (if you join a health challenge) a daily fitness total (Section 5).
Do you sell my data or show me ads? Never. No sale, no "sharing" for cross‑context advertising, no ad SDK, no cross‑app tracking (Section 6).
Can I delete everything? Yes — you can delete your social account from inside the App, and your on‑device/iCloud data is removed when you delete the App (Sections 9 and 12).
Where are analytics processed? In the European Union (Section 11).
How do disputes work? Through individual arbitration with a class‑action waiver, and you may opt out within 30 days (Section 19).

3. Definitions

To keep the rest of this policy precise:


4. Information that stays on your device — we never receive it

The core of KOVE runs entirely on your device and syncs, when you choose, through your own private iCloud account (Apple CloudKit) under your Apple ID. We do not collect, receive, store, transmit to ourselves, or have any ability to read the following:

This is not merely a promise; it is how the App is built. This data is written only to your device and to your private iCloud, which is controlled by your Apple ID and governed by Apple's Privacy Policy. Under the definition used by Apple and by U.S. privacy statutes, information that is never transmitted off your device in a way that lets us or our partners access it is not "collected," which is why none of it appears in our collection disclosures below.

Screen Time specifically. Apple's Screen Time framework is designed so that usage data can only be displayed inside a sandboxed, on‑device report. The App itself cannot read the raw numbers, and none of that data is transmitted to us. Any categorization of apps you set for the Insights view is stored on your device and, where applicable, in your private iCloud.

Location specifically. If you use location‑based blocking, your device evaluates the geofence locally using Apple's Core Location framework. Your location and your saved places are not sent to us; they remain on your device and in your private iCloud. KOVE collects no location data of any kind. We do not maintain location‑history logs, and our analytics provider's IP‑based geolocation feature has been disabled (Section 5).

Apple Health specifically. If you connect Apple Health, KOVE reads metrics such as step count, active minutes, distance, or sleep on your device to power habit tracking and, if you choose, health challenges. These raw readings are processed locally and are not transmitted to us. The single, narrow exception — one aggregated daily number submitted only when you join a health challenge in the optional social features — is described in Section 5.3.

To remove this device/iCloud data, delete the App, or remove KOVE's data in iOS Settings → [your name] → iCloud → Manage Account Storage. Because it is your data in your iCloud, its deletion is within your control and independent of us.


5. Information we collect

We collect only the categories of information described in this section. We have organized them by the technical system that receives them.

5.1 Anonymous product analytics (PostHog)

To understand how KOVE is used in aggregate and to improve it, we collect anonymous product analytics using PostHog, processed in the European Union.

On the Apple App Store privacy label these correspond to Product Interaction, Other Usage Data, and the anonymous installation identifier (Device ID) — all declared not linked to you and not used to track you.

5.2 Diagnostic data

To find and fix problems, we collect limited diagnostic data through the same anonymous analytics system. When an error occurs, we may record a technical error domain and numeric code — never the error's human‑readable message, which can contain incidental content. Diagnostic data is anonymous and corresponds to Other Diagnostic Data on the App Store privacy label, not linked to you and not used to track you.

5.3 Optional social features (Firebase)

KOVE includes optional social and accountability features — friends, circles, challenges, activity feed, and accountability partners. These features are entirely opt‑in. If you never sign in to the social features, none of the information in this Section 5.3 is collected, and you can use the entire core of KOVE — focus, blocking, and habits — without an account.

If you choose to sign in (using Sign in with Apple or Google Sign‑In), we use Google Firebase (Firebase Authentication, Cloud Firestore, Cloud Functions, and Firebase Cloud Messaging) to operate these features, and we collect:

This information is used only to operate the social features you chose to use. On the App Store privacy label these appear as linked to you (they are tied to your account) but not used to track you. The corresponding Apple data categories are Email Address, Name, User ID, and Fitness.

5.4 Information collected automatically by supporting services

When your device communicates with the supporting services above, standard technical information — such as your IP address and the timing of requests — is transmitted as an inherent part of any internet connection and is processed by our service providers (Apple, Google/Firebase, and PostHog) to route traffic, secure the Services, and prevent abuse. As described in Section 5.1, we have configured our analytics provider not to use IP for geolocation. We do not use this technical information to build advertising profiles or to track you across other companies' apps or websites.

5.5 Information we do not collect

For clarity, KOVE does not collect: your precise or approximate location; your contacts; your photos or camera roll; your microphone or audio; your health records beyond the single challenge total described in 5.3; the content of your habits, blocks, notes, or focus sessions; your browsing history; or any information used for advertising or cross‑app tracking.


6. What we do not do


7. How we use information

We use the limited information we collect for the following purposes only:

We do not use your information for any purpose that is incompatible with the purpose for which you provided it, and we do not use anonymous analytics or diagnostic data to identify you.


8. How we share and disclose information

We share information only in the limited circumstances below. We do not sell it and do not disclose it for others' advertising.

8.1 Service providers (sub‑processors)

We rely on a small number of vetted service providers to operate the Services. They may process information only on our behalf and under contract, and may not use it for their own purposes:

Provider Role in KOVE What it processes Their policy
Apple Inc. Sign in with Apple; iCloud/CloudKit (your private data, which we cannot read); Screen Time; push delivery; App Store distribution Authentication credential; your private on‑device/iCloud data (controller: you, under your Apple ID); push tokens apple.com/legal/privacy
Google LLC (Firebase / Google Cloud) Authentication, database (Firestore), server functions, and messaging for the optional social layer Account ID, sign‑in email, display name, shared activity, health‑challenge totals, push token firebase.google.com/support/privacy; policies.google.com/privacy
PostHog, Inc. (EU Cloud) Anonymous product analytics and diagnostics, processed in the EU Anonymous events (counts, categories); technical context; IP (not used for geolocation, then discarded) posthog.com/privacy

We do not authorize these providers to use your information for their own advertising.

We may disclose information if we believe in good faith that doing so is necessary to (a) comply with applicable law, regulation, legal process, or a lawful government request; (b) enforce our terms or investigate potential violations; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of 3 Bears Studio, our users, or the public.

8.3 Business transfers

If 3 Bears Studio is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy, and we will provide notice (for example, in the App or by other reasonable means) before your personal information becomes subject to a materially different policy.

8.4 With your direction

When you use the social features, information you deliberately share (for example, joining a challenge or connecting with a friend) is disclosed to the specific people you choose to share it with, as an inherent part of the feature you activated.


9. Data retention

We keep information only as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law.


10. Data security

We take reasonable and appropriate administrative, technical, and organizational measures designed to protect information, including: encryption of data in transit (HTTPS/TLS); reliance on Apple's and Google's platform security for data at rest; server‑side security rules that restrict each user to their own data and route all social writes through validated server functions; least‑privilege access controls; and minimizing what we collect in the first place, which is the most effective protection of all.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your device and your Apple/Google account credentials secure. If we become aware of a security incident affecting your personal information, we will notify you and the appropriate authorities as required by applicable law.


11. International data transfers

3 Bears Studio LLC is based in the United States. Our anonymous analytics are processed in the European Union (PostHog EU Cloud); our optional social features are operated on Google Firebase / Google Cloud infrastructure, which is primarily located in the United States. If you access the Services from outside these regions, your information may be transferred to, stored in, and processed in countries whose data‑protection laws may differ from those of your country.

Where such transfers are subject to data‑protection law (for example, transfers from the EEA or the UK), they are made under appropriate safeguards, such as the European Commission's Standard Contractual Clauses or another lawful transfer mechanism offered by the relevant provider. At launch, KOVE is offered in the United States (Section 13); we will implement the additional measures required by other regions before making the App available there.


12. Deleting your account and data

You have direct control over deletion:

If you are unable to use the in‑App deletion for any reason, contact us at hello@3bears.studio and we will honor a verified request.


13. Region of availability

At launch, KOVE is offered in the United States. If we make the App available in the European Union, the United Kingdom, or other regions with additional requirements (such as opt‑in consent for analytics), we will update this policy and the in‑App experience — including any required consent controls — before doing so.


14. Your privacy choices and rights

Everyone can exercise the following choices, regardless of where they live:

Depending on where you live, you may also have the specific legal rights described below. Because our analytics are anonymous and your core data lives in your own iCloud, most requests are fully satisfied by the in‑App controls above; for anything else, contact us at hello@3bears.studio. We will not discriminate or retaliate against you for exercising any privacy right.

14.1 California residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides you the rights described here.

Categories of personal information. In the past 12 months, we have collected the following statutory categories, as detailed in Section 5:

We collect these from you and from your device/authentication providers, for the business purposes in Section 7. We disclose them only to the service providers in Section 8.1 and as described in Sections 8.2–8.4.

We do not "sell" and do not "share." We have not sold personal information and have not shared it for cross‑context behavioral advertising in the preceding 12 months. We do not sell or share the personal information of any individual, including minors under 16.

Your California rights. You have the right to: (a) know/access the personal information we have collected about you and details about our processing; (b) delete personal information we hold about you; (c) correct inaccurate personal information; (d) opt out of any sale or sharing (not applicable, as we do none); and (e) limit the use of sensitive personal information (we do not use sensitive personal information for any purpose requiring a limit right). You also have the right to be free from discrimination for exercising these rights.

How to exercise. Use the in‑App controls (Sections 12 and 14) or email us at hello@3bears.studio. We will verify your request by reference to information associated with your account or device. You may use an authorized agent to submit a request on your behalf with proof of authorization. If we deny a request, you may appeal by replying to our decision.

Sensitive personal information. We do not collect Social Security numbers, government IDs, financial account details, precise geolocation, contents of communications, or similar sensitive categories. The only arguably sensitive data — a health/fitness total — is collected only when you affirmatively join a health challenge and is used solely to run that challenge.

14.2 Residents of other U.S. states

If you reside in a U.S. state with a comprehensive consumer‑privacy law (including, for example, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect), you may have rights to: confirm whether we process your personal data and access it; correct inaccuracies; delete it; obtain a portable copy; and opt out of targeted advertising, sale, or certain profiling. Because we do not conduct targeted advertising, sales, or such profiling, those opt‑out rights are satisfied by default. To exercise a right, contact us at hello@3bears.studio. If we decline a request, you may appeal by replying to our response; if an appeal is denied, you may contact your state Attorney General.

14.3 Nevada residents

Nevada law allows residents to opt out of the sale of certain "covered information." We do not sell covered information as defined by Nevada law. You may still submit a request to hello@3bears.studio.

14.4 EEA, UK, and Swiss residents (GDPR / UK GDPR)

KOVE is offered in the United States at launch (Section 13). To the extent the EU General Data Protection Regulation or the UK GDPR applies to you, 3 Bears Studio LLC is the controller of the limited personal data described in Section 5, and:


15. Children's privacy

KOVE is intended for a general audience and is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The social features are intended for users 13 and older. If you believe a child under 13 has provided personal information through the App, contact us at hello@3bears.studio and we will promptly delete it. We do not knowingly sell or share the personal information of any minor.


16. "Do Not Track" and Global Privacy Control

Because KOVE does not track you across other companies' apps or websites and does not conduct targeted advertising, it does not behave differently in response to a browser "Do Not Track" signal. We treat a recognized opt‑out‑preference signal (such as Global Privacy Control), where it applies, consistently with our practice of not selling or sharing personal information.


17. Third‑party platforms

The App relies on Apple and Google platform services, and the optional social features authenticate through Sign in with Apple or Google. Your use of those services is also governed by their own terms and privacy policies (linked in Section 8.1). We are not responsible for the privacy practices of third parties, and this policy does not modify your relationship with Apple or Google.


18. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice in the App or by other reasonable means before the change takes effect. Your continued use of the App after an update becomes effective constitutes acceptance of the revised policy. We encourage you to review this policy periodically.


19. Governing law and dispute resolution

PLEASE READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS, INCLUDING YOUR RIGHT TO FILE A LAWSUIT IN COURT AND TO HAVE A JURY TRIAL, AND REQUIRES INDIVIDUAL ARBITRATION OF MOST DISPUTES, SUBJECT TO YOUR RIGHT TO OPT OUT WITHIN 30 DAYS AS DESCRIBED BELOW.

19.1 Governing law

This Privacy Policy and any dispute arising out of or relating to it or to the App are governed by the laws of the State of Florida and applicable U.S. federal law, without regard to conflict‑of‑laws principles. The Federal Arbitration Act governs the interpretation and enforcement of the arbitration provisions in this Section 19.

19.2 Informal resolution first

Before starting an arbitration or other proceeding, you agree to first try to resolve the dispute informally by sending a written description of it, and your contact information, to hello@3bears.studio. We will do the same for any dispute we have with you. Both parties agree to negotiate in good faith for at least 60 days after such notice. This informal‑resolution requirement is a precondition to beginning arbitration, and any applicable statute of limitations is tolled during this period.

19.3 Binding individual arbitration

If the dispute is not resolved within 60 days, you and 3 Bears Studio LLC agree that any dispute, claim, or controversy arising out of or relating to this Privacy Policy, the App, or the Services — whether based in contract, tort, statute, fraud, misrepresentation, or any other legal theory — will be resolved exclusively through final and binding arbitration on an individual basis, rather than in court, except as provided in Section 19.6.

The arbitration will be administered by the American Arbitration Association (AAA) under its Consumer Arbitration Rules then in effect, as modified by this policy. The arbitration will be conducted in the English language. Unless you and we agree otherwise, any in‑person hearing will take place in the county of your residence or another mutually agreed location; many consumer arbitrations are conducted by telephone, video, or on written submissions. The arbitrator's award may be entered as a judgment in any court of competent jurisdiction. The arbitrator, and not any court, has exclusive authority to resolve disputes about the interpretation, applicability, enforceability, or formation of this arbitration agreement, except that a court decides whether a claim falls within the small‑claims exception (Section 19.6) and whether the class‑action waiver (Section 19.5) is enforceable.

19.4 Arbitration costs

Payment of filing, administration, and arbitrator fees is governed by the AAA Consumer Arbitration Rules. If those rules require you to pay a filing fee and the arbitration is not frivolous, we will reimburse or pay your portion to the extent required by the AAA rules or applicable law, and in any event we will not seek to recover our attorneys' fees from you unless the arbitrator finds your claim frivolous.

19.5 Class‑action and jury‑trial waiver

You and 3 Bears Studio LLC agree that each may bring claims against the other only in an individual capacity, and not as a plaintiff or class member in any purported class, collective, consolidated, or representative proceeding. The arbitrator may not consolidate more than one person's claims and may not preside over any form of class or representative proceeding. You and we waive any right to a jury trial. If a court decides that this class‑action waiver is unenforceable as to a particular claim, then that claim (and only that claim) will be severed and may proceed in court, while all other claims remain in arbitration.

19.6 Exceptions

Nothing in this Section 19 prevents either party from: (a) bringing an individual claim in small‑claims court if it qualifies and remains in that forum; or (b) seeking injunctive or other equitable relief in a court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation, or violation of intellectual‑property or other proprietary rights. In addition, nothing here waives any right you may have under applicable law that cannot be waived by agreement.

19.7 Your right to opt out of arbitration

You may opt out of this arbitration agreement (Sections 19.3–19.5) within 30 days of first accepting this Privacy Policy by emailing hello@3bears.studio with the subject line "Arbitration Opt‑Out" and stating your name and that you wish to opt out. Opting out will not affect any other part of this policy or your use of the App. If you opt out, disputes will be resolved in the courts identified in Section 19.8.

19.8 Forum for non‑arbitrated disputes

For any dispute not subject to arbitration (including if you opt out or if the arbitration agreement is found not to apply), you and 3 Bears Studio LLC agree to the exclusive jurisdiction of the state and federal courts located in Florida, and each party consents to personal jurisdiction and venue there.

19.9 Severability and survival

If any provision of this Section 19 is found unenforceable, the remaining provisions will remain in full force and effect, except that if the class‑action waiver in Section 19.5 is found unenforceable as to a claim seeking public injunctive relief, that claim will proceed in court as provided in Section 19.5. This Section 19 survives termination of your relationship with us and deletion of the App.


20. Contact us

If you have any questions, requests, or complaints about this Privacy Policy or your information, contact:

3 Bears Studio LLC Privacy contact: hello@3bears.studio

We will respond to verifiable requests within the timeframes required by applicable law.


Appendix A — Data collection summary (App Store privacy label)

This appendix maps our collection to Apple's App Store privacy‑label categories. It is provided for transparency and is consistent with the App's privacy manifest.

Data type Collected? Linked to you? Used to track you? Purpose Condition
Product Interaction Yes No No Analytics Always (anonymous)
Other Usage Data Yes No No Analytics Always (anonymous)
Other Diagnostic Data Yes No No Analytics / app functionality Always (anonymous)
Device ID (anonymous analytics identifier) Yes No No Analytics Always (anonymous)
Email Address Yes Yes No App functionality Only if you use social features
Name (display name) Yes Yes No App functionality Only if you use social features
User ID Yes Yes No App functionality Only if you use social features
Fitness Yes Yes No App functionality Only if you join a health challenge
Precise/Coarse Location No Never collected
Contacts, Photos, Browsing History, Financial Info No Never collected

End of Privacy Policy.