10 MINUTEBLOCKS
Legal

Privacy Policy

What 10MB collects, who processes it, and what you can do about it — the formal version of the promises on Your data.

8 min read

01 Who this covers

This policy explains what 10MB collects, why, who else touches it, and what you can do about it. It applies to the 10MB apps on iOS, Android, macOS and the web, and to this website. It is a legal document; the plain-language version of the same promises lives on Your data, and where the two ever disagree, this page governs.

The service is provided by 10 Minute Blocks, Texas, United States. For anything in this policy, write to 10minuteblockapp@gmail.com.

Last updated: 14 August 2026.

02 What we collect

Nearly everything 10MB holds is something you typed in on purpose. We collect no location data, we do not watch your screen, and we do not read your calendar or your files.

Account
Your email address, and the sign-in method you chose — a password, Google, or Apple. If you use Google or Apple, we receive an identifier and an email from them; we never receive your password.
Your time data
The ten-minute blocks you fill in, the categories and tags you create, and the daily totals derived from them.
Habits & day logs
The habits you track, whether you met them, your day ratings, and any notes you write on a day.
AI conversations
Questions you ask in Reflect, the answers you get back, and any thumbs-up/down feedback with its optional note. See §04.
Support messages
Anything you send us through in-app support, so we can answer it.
Connected services
Only if you connect them. If you link Todoist, we store the task labels and counts needed to draw your task history. You can disconnect at any time.
Usage analytics
Which screens are opened and which features are used, via Firebase Analytics, along with a device and app-version identifier. This tells us that a screen is used, never what you wrote in it — your blocks, notes and conversations are not sent to analytics.
Technical logs
Standard server logs from our hosting provider — IP address, timestamps, error traces — kept briefly for security and debugging.

03 How we use it

We use what we collect to run the product you asked for, and for nothing else:

  • To provide the service — store your blocks, sync them between your devices, compute your streaks and summaries, and show you your own history.
  • To produce the features you invoke — Reflect answers, Wrapped recaps, insights and exports.
  • To keep it working — diagnose crashes, repair data inconsistencies, and prevent abuse.
  • To answer you — respond to support messages.
  • To understand which features matter — aggregate usage analytics, so we build the right things.

We do not sell your data, rent it, or share it for advertising. There are no ads in 10MB and no advertising trackers. We do not build profiles about you for anyone else, and we do not use your time data to train machine-learning models.

04 AI features, specifically

10MB has features that use a third-party language model: Reflect (asking questions about your own time), Wrapped (the written recap of a period), and the goal suggestions during sign-up. These are the only places your data leaves our own infrastructure for processing, so they deserve their own section.

What actually leaves

When you ask Reflect a question, your question plus the slice of your own time data needed to answer it — category names, block counts, dates, and where relevant your day notes — is sent to OpenAI's API, which returns the answer. Wrapped sends the same kind of summary for the period it covers. Your email address and account identifiers are not part of that request.

  • OpenAI does not train on it. Data submitted through the OpenAI API is not used to train their models, per their API terms. We do not train models on it either.
  • Wrapped runs on a schedule. Your weekly, monthly, quarterly and yearly recaps are generated when the period closes, without you pressing anything — so this processing happens as part of normal use, not only when you open the feature. You can turn this off: Settings → Wrapped has two switches, one to stop scheduled recaps being generated at all, and one to keep the recaps but build them from your numbers alone without sending anything to OpenAI.
  • Conversations are stored in your account so you can return to them, and are deleted with your account. You can delete individual Reflect sessions from the session history at any time.
  • Answers can be wrong. A language model summarising your week is a convenience, not a system of record. Your blocks are the truth; the recap is an interpretation of them.

05 Who else sees it

We use a small number of service providers to run 10MB. They process data on our instructions and are not allowed to use it for their own purposes. This is the complete list:

Google Firebase
Hosting, database (Firestore), authentication, push notifications and analytics. This is where your data lives. Google processes it as our provider.
OpenAI
The language model behind Reflect, Wrapped and sign-up goal suggestions — see §04.
Apple & Google sign-in
Only if you choose one of them to sign in. They tell us who you are; we tell them nothing about what you track.
Todoist
Only if you connect it, and only for the task data that draws your task insights.

Beyond those, we disclose data only if the law requires it — a valid legal order — or to protect someone's safety. If 10MB were ever acquired or transferred, your data would move with it under this same policy, and you would be told before anything changed.

Where it is processed: our providers store and process data in the United States. If you are outside the US, using 10MB means your data is transferred there.

06 Staff access — said plainly

A very small number of 10MB administrators can read account data, including your AI conversations and support threads, through internal admin tools. This exists so support requests can be answered and broken data can be repaired.

We would rather state this than let a policy imply nobody can ever look. What we commit to: administrators access accounts to answer a request you sent or to fix a fault, never out of curiosity and never to build anything from what they see. Nothing in your account is used for any purpose in this policy that isn't listed in §03.

07 How long we keep it, and how to end it

Your data stays until you delete it. There is no automatic expiry — a five-year-old block is as much yours as today's, and deleting things for you would be a data-loss bug, not a privacy feature.

  1. Export first, if you want a copy

    Settings → Data exports your complete history as open CSV or JSON. No ticket, no waiting period.

  2. Delete the account

    Settings → Data → Delete account. Every block, category, tag, habit, day score, note, AI conversation and support thread is erased from our live database, along with your sign-in credentials.

  3. What that means

    Immediate, and reversible for 7 days if you ask us. The moment you confirm, everything above is gone from our live database and neither you nor we can see it in the app. We do take routine backups so that a fault on our side cannot lose everyone's history, and your data survives in one for up to 7 days — so if you change your mind, or deleted something by accident, write to us within 7 days and we will try to recover it. After that the backup expires and takes it with it, and nobody can bring it back.

  4. What recovery involves, so you can decide

    Recovering data means a person here restores a copy of the backup and reads enough of it to find your account — the same staff access described in §06. We only do it when you ask. Your account itself — your email address and sign-in method — is also held in a separate daily export for the same 7 days; it never contains your password, so a recovered sign-in with an email and password needs a password reset, while Google and Apple sign-in keeps working.

Anonymous usage analytics and server logs, which are not linked to your content, are retained on our providers' standard schedules and are not restored to anyone.

08 Your rights

Depending on where you live — the UK/EEA under the GDPR, California under the CCPA/CPRA, and a growing number of other places — you have rights over your data. 10MB extends the following to everyone, wherever you are, because splitting users into tiers of dignity is not a thing we want to build:

  • Access and portability — export everything, yourself, in open formats, at any time.
  • Correction — every piece of content in 10MB is editable by you in the app.
  • Deletion — delete your account and its contents yourself, immediately.
  • Objection and restriction — write to us and we will act on it.
  • No sale, no targeted advertising, no automated decisions about you — none of these happen, so there is nothing to opt out of.

You do not need our permission or a form for the first three: they are buttons in Settings. For anything else, email 10minuteblockapp@gmail.com and we will respond within 30 days. If you are in the UK/EEA, our lawful bases are performance of a contract (running the service you signed up for) and legitimate interests (keeping it secure and working); you may also complain to your local supervisory authority.

09 Security

Your data is encrypted in transit and at rest by our hosting provider. Access to the production database is restricted to administrators and enforced by server-side security rules rather than by the app — a modified client cannot read another account's data. Sign-in is handled by Firebase Authentication, so we never store your password.

No service can promise it will never be breached. What we can promise is the discipline that limits the damage: collect little, connect to few third parties, and tell you promptly and plainly if something goes wrong.

10 Children

10MB is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to 10minuteblockapp@gmail.com and we will delete it.

11 Changes to this policy

If this policy changes in a way that materially affects you, we will tell you in the app before it takes effect — not by quietly editing this page. The "last updated" date at the top always reflects the current version.

Questions, or something here that doesn't match what you see in the app? 10minuteblockapp@gmail.com. If the two ever disagree, the app's behaviour is the bug and we want to hear about it.

Was this guide helpful? Get in touch if something's missing.