The Gnomestead Collective

Privacy Policy

Effective August 18, 2026

The Gnomestead Collective (“the Collective,” “we,” “us,” or “our”) builds apps, and we care about keeping your information as safe. This Privacy Policy explains what we collect, how we use it, and the choices you have. It applies to this website and to our mobile applications (together, the “Services”).

1. How to read this policy

Our apps are not all alike. Rather than write a policy vague enough to cover both, we’ve split this one in two:

  • The core policy — sections 1 through 13 below — applies to every app we make and to this website.
  • An annex for each app, at the end, sets out what that particular app reads, stores, and sends. There is one for Little Wings and one for Amber Lock.

Where an app’s annex conflicts with the core policy, the annex controls for that app. The core describes what we do in general; the annex describes what a specific app actually does, and the specific wins.

2. What we collect

Not every app collects every kind of information. This table is the short answer for each one; the annexes explain the details.

Data typeLittle WingsAmber Lock
Account informationUsername or display name, email address, sign-in identifiersCollectedNot used
Step & activity dataStep counts from Apple Health / HealthKit and Health ConnectCollectedOn device only
Screen Time & app usageThe apps and categories you choose to lock, and app & website usageNot usedOn device only
App content & progressWhat you have made, collected, unlocked, or configuredCollectedOn device only
Purchase & subscription statusWhether a subscription is active, and a pseudonymous purchase IDCollectedCollected
Diagnostics & crash reportsCrash traces, device model, operating system and app versionCollectedCollected
Product analyticsWhich screens and features are used, and a pseudonymous device IDCollectedCollected
CommunicationsMessages you send us by email or on social channelsCollectedCollected

Collected means the information reaches us or one of the providers listed in section 7. On device only has the specific meaning set out in section 4 — it never reaches us at all. Not used means the app does not ask for it or read it.

3. On-device processing

Some of what our apps read is far too personal to send anywhere, so we don’t. Where this policy marks something on device only, we mean all of the following, and we mean it as a commitment rather than a description of our current setup:

  • It is read on your device, used on your device, and stored on your device.
  • It is never transmitted to us. We do not receive it, we cannot see it, and we hold no copy of it — which also means we cannot retrieve it for you if you lose it.
  • It is never sent to any third party, including the analytics and crash-reporting providers named in section 7. It is not included in crash reports, analytics events, diagnostic logs, or support attachments.
  • It is never sold, never shared for advertising, and never used to build a profile of you.
  • It stays under your control. Revoking the relevant permission in your device settings stops the app reading it, and deleting the app removes what it stored.

4. Health & fitness data

Several of our apps are built around walking. With your permission, we read step counts from your device’s health services — Apple Health / HealthKit on iOS, and Health Connect on Android. You can grant or revoke this permission at any time in your device settings, and an app will keep working without it, just with less to go on.

Step and activity data is used only to provide an app’s features. We do not sell it, we do not use it for advertising or any form of marketing, and we do not include it in analytics or crash reports. We do not share it with third parties except where strictly needed to operate an app that syncs your progress, or where the law requires it. Whether a given app sends any step-derived information to us at all is set out in its annex.

5. Screen Time & app usage data

One of our apps helps you step away from apps that keep pulling you back. To do that, it needs to know which apps you want to set aside and when they are being used. On iOS this uses Apple’s Screen Time APIs (Family Controls, Managed Settings, and Device Activity); on Android it uses the usage access permission.

This is among the most revealing information a phone holds — the apps you struggle to put down, and how long you spend in them — so it is handled as on device only, with everything section 3 describes. Specifically:

  • The apps and categories you select are chosen through a picker provided by your operating system. Where the platform supports it, your selections are opaque tokens that identify apps only to your own device.
  • Your selections and your app & website usage are never transmitted to us or to anyone else. We do not know which apps you locked, and we could not find out.
  • No app name, bundle identifier, category, or usage figure drawn from these APIs is ever included in an analytics event or a crash report.
  • This information is never sold, never shared, and never used for advertising.

Granting this access is entirely your choice, and you can withdraw it at any time in your device settings.

6. How we use your information

We use the information we collect to:

  • Provide, operate, and maintain the Services;
  • Deliver the features an app is built around;
  • Save your settings and, where an app offers an account, sync them across your sessions and devices;
  • Confirm whether a subscription is active and give you the features you have paid for;
  • Fix bugs, diagnose crashes, improve features, and understand how the Services are used in aggregate;
  • Respond to your questions and provide support;
  • Protect the Services and keep our little community safe.

7. How we share information — and who helps us

We share information only in the limited situations below. We name our providers rather than hiding them behind “service providers”, because you are entitled to know who processes your information:

  • RevenueCat manages subscriptions and purchases across our apps. It receives your purchase and subscription status and a pseudonymous identifier it generates itself. We do not give it your name or email address.
  • Sentry receives crash reports and error diagnostics — what went wrong, and the device model, operating system, and app version it went wrong on.
  • PostHog receives product analytics: which screens and features are used, and a pseudonymous device identifier. We use this to see which parts of an app are working and which are not.
  • Apple and Google process your payment when you buy something. We never receive or store your payment card details.
  • Legal reasons, if required to comply with the law or to protect the rights, safety, and property of the Collective and our users;
  • Business transfers, if the Collective is ever involved in a merger, acquisition, or sale of assets. Any successor would be bound by the commitments in this policy.

Each of these providers is bound to protect what it receives and to use it only on our instructions. None of them receives health data, Screen Time data, or anything else this policy marks on device only.

8. We do not sell your information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have never done so, for any app. We do not show ads in our apps, and we do not let anyone else use what we collect to target you.

9. Data retention

Information we hold is kept only as long as we need it for the purpose we collected it. Where an app offers an account, we keep your information while that account is active, and you may ask us to delete the account and the data associated with it at any time. Diagnostic and analytics records are kept for a limited period and then discarded.

Where an app stores information only on your device, there is nothing for us to retain or delete — deleting the app removes it. See the app’s annex for which of these applies.

10. Your choices & rights

You can revoke health, motion, and app-usage permissions in your device settings at any time. Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to certain processing. To make a request, email us at support@gnomesteadcollective.com. We will not treat you differently for exercising any of these rights.

One honest limitation: we can only act on information we actually hold. For anything marked on device only, we have no copy to send you and none to delete — that data is yours alone, and your device settings are the place to manage it.

11. Children’s privacy

The Services are not directed to children under 13 (or the minimum age required in your region), and we do not knowingly collect personal information from them. We do not ask for your date of birth, and we do not try to work out how old you are from how you use an app.

If we learn that we hold personal information from a child under that age, we delete it and close any account associated with it. If you are a parent or guardian and believe your child has given us information, write to us at support@gnomesteadcollective.com and we will act on it promptly.

12. Security

We use reasonable technical and organizational measures to protect your information. Keeping sensitive data on your device, rather than gathering it up on a server, is itself one of those measures. No method of transmission or storage is perfectly secure, but we work to keep the lantern lit and the door locked.

13. Changes to this policy

We may update this Privacy Policy from time to time — including by adding a new annex when we release a new app. When we make meaningful changes, we’ll revise the date above and, where appropriate, let you know within the Services.

14. Contact us

Questions about this policy? Knock on our door at support@gnomesteadcollective.com and we’ll be glad to help.


The annexes below cover each app in turn. Open the one you’re interested in.

Annex A — Little Wings

Little Wings is a walking game. Every step you take in the real world stirs something from the undergrowth, and the app shows you the critters you crossed paths with.

What it reads

  • Step counts, with your permission, from Apple Health / HealthKit on iOS and Health Connect on Android. This is what drives the game. Little Wings does not read your location.
  • Account information. Little Wings has an account so your collection follows you between sessions and devices. Depending on how you sign in, this is a username or display name and an email address or an identifier from a third-party sign-in provider.
  • Your progress — the critters you have found, what you have unlocked, and your activity in the game world — which is stored with your account so it is not lost if you change phones.
  • Purchase status, diagnostics, and analytics, as described in section 7.

Where it goes

Your account and your progress are stored on our servers so they can be synced. Step data is used to advance the game; we do not sell it, use it for advertising, or include it in analytics or crash reports.

Deleting your data

Because Little Wings has an account, you can ask us to delete it and everything associated with it. Email support@gnomesteadcollective.com and we will take care of it.

Annex B — Amber Lock

Amber Lock seals the apps that keep pulling you back, and your steps are what melts the resin. It is a utility, not a game.

No account, and nothing to sign in to

Amber Lock has no accounts. It does not ask for your name, your email address, or any sign-in, and there is no profile of you anywhere. Your settings live on your device, not on our servers.

What stays on your device

The following is on device only, with everything section 3 promises. None of it reaches us:

  • The apps and categories you seal. You choose these through your operating system’s own picker. We never learn what you selected.
  • Your app & website usage, read through Apple’s Screen Time APIs on iOS and the usage access permission on Android, and used solely to know when a sealed app is being reached for.
  • Your step counts, read with your permission from Apple Health / HealthKit or Health Connect, and used to work out how much of the resin has melted.
  • Your settings and balances — how much you have banked, what is currently sealed, and how you have set things up.

This information is stored in your device’s app storage and, on iOS, in a shared container that lets the app and its Screen Time extension see the same settings. It is not backed up to us. Deleting Amber Lock removes it.

What does leave your device

So that the picture is complete: Amber Lock does send the three things every one of our apps sends, described in section 7 — your subscription status and a pseudonymous identifier to RevenueCat, crash reports to Sentry, and product analytics with a pseudonymous device identifier to PostHog. These tell us that a screen was opened or that something crashed. They never contain which apps you sealed, how long you spend in them, or your step counts.

Deleting your data

There is no account to delete and we hold no copy of your settings. Deleting the app removes everything it stored on your device. If you would like us to delete the diagnostic and analytics records associated with your device identifier, email support@gnomesteadcollective.com.