Overview
24 Block is a visual time-block planning app. It works without an account and stores the main planning data on the user's device. While Lock Screen Live Activity is enabled on iOS, selected planning details are sent to an update service as described below.
The public v1.0 release works as described by the local-planning and Live Activity sections below. The unreleased v1.1 adds an explicit Live Activity upload confirmation as described below. Optional device-calendar display and iCloud sync are implemented for a future release and are not yet available in the public app. The earlier account implementation is dormant: account creation, sign-in and session monitoring are disabled in the app. The preview sections describe these implementations; they do not announce a backend deployment or new app release.
24 Block is operated by Jamgo Labs Ltd, a private limited company registered in England and Wales.
- Company number: 17181144
- Registered office: 4th Floor, Silverstream House, 45 Fitzroy Street, London, England, W1T 6EB
- Privacy contact:
support@24block.app
For the limited personal data described in this policy, Jamgo Labs Ltd is the controller.
Data We Store On Device
24 Block stores planning data locally on the device so the app can work as intended.
This can include:
- schedules and time blocks
- recurring routine definitions and generated routine blocks
- block comments and notes entered in the planner
- activity categories, colours, and theme selections
- app settings and planning preferences
On supported iOS devices, the app can also show current-block and upcoming-block information in a live activity or home screen widget.
Optional Device Calendars — Unreleased Preview
Calendar sync is off by default. If the user connects device calendars in Settings and grants system permission, 24 Block can read calendars already available through the phone's calendar system, including calendars from providers the user has added there. Users choose which calendars to display. 24 Block does not ask for calendar-provider passwords or sign in directly to those providers.
The app reads calendar names, colours and source labels for selection, and event identifiers, titles, times, all-day status and cancellation status for display. Calendar information is held in memory while the app runs. Only the enabled setting, selected calendar identifiers and a flag recording that a selection has been made are saved in local app preferences. Imported events are kept separate from planning blocks and are not added to planner storage, iCloud planner sync, exports, schedule sharing, statistics, widgets or Live Activity update payloads. 24 Block does not upload this calendar information to its services or write, edit or delete events in the source calendars.
The app refreshes the displayed date range while in use, on return to the foreground and when the user requests a refresh. The phone's calendar system and the calendar provider control when provider changes reach the device; 24 Block does not provide its own background calendar sync service.
On iOS, reading events requires the system's full calendar-access permission, which also permits writes at the operating-system level. 24 Block uses that access only to read. On Android, the app requests calendar-read permission and excludes calendar-write permission. It does not request access to reminders or device location for this feature.
Turning Calendar sync off clears the imported calendar information from the app's memory and stops further calendar reads while off. Users can also revoke access in device Settings. Neither action deletes events from the source calendar. The calendar provider and operating system continue to handle the original calendars under their own settings and privacy practices.
Optional Accounts and iCloud Sync — Unreleased Preview
These are separate optional features. Signing in to 24 Block identifies the user to 24 Block; it does not turn on sync or change the Apple Account signed into iCloud on the device. Local planning remains available without either feature, and an account-service outage does not disable the planner or otherwise available iCloud sync. Android planning remains local.
Sign in with Apple
When a user chooses Apple's sign-in button, the app sends a single-use authentication challenge, Apple's identity token and authorization code to the configured 24 Block account service. The service verifies them with Apple before creating a 24 Block session. The app does not request the user's name or email address. Accounts are identified by Apple's verified subject identifier within the configured developer/app context, not by email.
The account service keeps the account identifier, verified Apple subject, session and expiry records, protected Apple credentials needed for revocation, and limited records for replay protection, rate limiting and deletion completion. It does not receive or store the planner. Hosting and database providers may process service request metadata. Production providers and their operational retention must be confirmed before this feature is released.
The device stores its 24 Block session, any pending session-revocation credential and deletion receipt in Keychain-backed SecureStore. These credentials are not put in planner exports, planner storage or AsyncStorage. An expired or revoked session requires signing in again.
Private iCloud planner sync
Sync starts off. Enabling it requires confirmation before the existing plan is uploaded. On supported Apple systems, planner records are stored in the private CloudKit database of the Apple Account signed into iCloud on the device. This iCloud identity is separate from the identity used for Sign in with Apple; the app does not match them by email or silently move data between them.
Synced data includes scheduled blocks and comments, routine rules and exceptions, custom activities and ordering, day themes and assignments, and these shared preferences: time format, app language, appearance mode and accent colour. Navigation, scroll position, selections, onboarding progress, push tokens, Live Activity identifiers and undo/redo history stay local. Statistics and widget content are calculated from the plan. CloudKit is provided by Apple and is subject to Apple's service settings, availability and storage limits.
The Apple implementation migrates the planner to a native local store shared with the app's extension group, with atomic writes for records and pending sync work. It retains recovery copies of legacy data and a bounded set of recent backups and conflict/account-change recovery records. A failed migration keeps the original data recoverable. Platform backup settings may also apply. This policy does not claim end-to-end encryption for planner records, exports or the account service.
Account, sync and planner deletion
Signing out removes the active device session and requests server-session revocation. If offline, a credential is kept in SecureStore only to retry revocation until it succeeds or expires; Settings reports the pending state. Signing out does not sign out of iCloud, turn off sync or delete a plan.
Disabling sync stops future sync work and retains the device and cloud copies. Deleting the 24 Block account removes its backend account/session data and starts Apple credential revocation. A pending Apple cleanup is shown as pending. A deletion receipt lets the app check completion after an interrupted request. Credentials required for incomplete revocation remain protected on the backend until cleanup completes; completed receipt records are retained for 30 days. Infrastructure logs and provider backups have separate retention, to be confirmed before release.
The account-deletion confirmation explicitly keeps the local and iCloud planner. Erasing the planner is a separate client action in iCloud settings; the account backend cannot erase the user's private CloudKit database. Cloud erasure needs access to the relevant iCloud account, and incomplete cleanup must remain visible. The reset protocol prevents old offline devices from restoring the erased dataset as the active plan. Keeping a local copy leaves sync off until the user deliberately enables it again. These actions affect 24 Block data, not the person's Apple Account.
Local planner erasure also removes the app's internal planner recovery copies and legacy planner storage. If cleanup of the old local storage fails, its pending status survives restart and the app retries; Settings also offers a retry. User-created exports or copies saved to another app are outside that deletion. Exported files contain personal planner content and recovery data; users choose where to save or share them and are responsible for those external copies.
Optional Live Activity Update Service
Lock Screen Live Activity is off by default. In the unreleased v1.1, enabling it in Settings first explains what will be sent and asks the user to allow updates. Earlier On settings without that recorded confirmation are turned off; users can enable the feature again after reading the explanation. Existing Off settings stay off. Users can withdraw permission at any time by turning it off in Settings. While enabled on a supported iOS device, 24 Block sends the activity's push token and identifier, today's scheduled block names, colours, times, comment and note excerpts, and update timestamps to its backend hosted on Vercel. The backend uses Upstash QStash to queue future updates and Apple Push Notification service (APNs) to deliver them to the Live Activity while the app is in the background or closed.
This service does not create an account or synchronise the planner between devices. Home screen widgets use on-device data. The Live Activity service is not used by the Android app.
Turning Lock Screen Live Activity off stops new schedule uploads and requests cancellation of queued updates for the activity. Cancellation requires a working connection and may not stop messages already being delivered. It does not delete infrastructure logs or provider records. Vercel, Upstash, and Apple may also process request and delivery metadata to operate and protect the service.
Data We Do Not Collect Through the App
At launch, 24 Block does not require an account and does not intentionally collect the following as part of core app operation:
- name
- phone number
- payment information
- profile data
- advertising identifiers
- analytics data
- crash-reporting data
- location data
- calendar account data
- photos, files, or audio recordings
The calendar-account statement above describes the public launch app. The calendar preview reads the device-calendar information described above after permission, without receiving calendar-provider credentials. The public launch app does not provide cloud sync or in-app account creation. The unreleased optional implementations are described separately above. Collaboration and advertising are not part of either implementation.
If a user chooses to contact support, Jamgo Labs Ltd may receive the email address, message content, and any details the user chooses to include in that email. Support email is used to respond to the request and improve support for the app, not for advertising or third-party marketing.
How Data Is Used
Planning data is used to provide the app's core functionality, including:
- displaying and editing schedules
- saving categories, themes, and preferences
- generating recurring routine blocks
- showing current-block and upcoming-block information in live activities and home screen widgets on supported iOS devices
At launch, 24 Block does not use in-app data for advertising, third-party marketing, behavioural profiling, or personalised ad targeting.
Where support email or website request metadata is processed, the purposes are to:
- respond to support, feedback, or privacy requests
- maintain basic business records
- operate, secure, and protect the public website
- understand and resolve service, abuse, or security issues
Lawful Bases
Where UK data protection law applies, Jamgo Labs Ltd relies on the following lawful bases for the limited personal data it handles:
- legitimate interests for responding to support requests, maintaining service security, and protecting the website from abuse
- legal obligation where records must be kept to comply with applicable law
- consent only where a user has clearly chosen an optional action, such as sending a support email or using a device share feature
- consent for the optional Live Activity update service; the upcoming release asks the user to allow the disclosed uploads before enabling it in Settings
- consent for the optional preview account and iCloud features when the user chooses to sign in or enable sync
- consent for optional device-calendar access when the user connects calendars and grants system permission
Users can turn Lock Screen Live Activity off in Settings, leave Calendar sync off or turn it off, revoke calendar access in device Settings, and choose not to send support email or share schedule content through external apps.
Sharing and External Actions
24 Block includes optional actions that hand user-selected content to other apps or services only when the user initiates them.
These include:
- sharing schedule text through the system share sheet
- opening the user's mail app to send feedback to
support@24block.app - opening external links such as the product website
When a user uses one of these actions, the selected content is handled by the chosen app, service, or provider under that provider's own terms and privacy practices. If the user sends feedback to support@24block.app, Jamgo Labs Ltd receives the email and its contents so the support request can be handled.
After the user allows the disclosed uploads, the Live Activity update service sends the details described above while its setting is enabled; it does not require a separate sharing action for each update.
Public Website
The public website is a static site hosted with Cloudflare Pages. The current site does not intentionally include analytics, advertising pixels, or tracking scripts.
Cloudflare and other infrastructure providers may process standard request metadata, such as IP address, user agent, request URL, referrer, and timestamp, to deliver and protect the website under their own terms and privacy practices.
Service Providers
Jamgo Labs Ltd may use service providers to operate 24 Block and its public website. At launch, these may include:
- app-store platforms such as Apple App Store and Google Play
- website hosting and security providers such as Cloudflare
- Vercel for Live Activity API hosting, Upstash QStash for scheduled update delivery, and Apple APNs for delivering updates to the device
- email and business infrastructure providers used to receive and respond to support messages
These providers may process limited personal data only where needed to provide their services, comply with law, or protect their platforms.
Some providers may process data outside the United Kingdom. Where this happens, the provider is responsible for applying the transfer safeguards required for its service, such as adequacy arrangements or contractual safeguards.
Permissions and Platform Capabilities
The public launch build did not request sensitive runtime permissions. The unreleased calendar feature introduces optional calendar access, with the platform differences described in the device-calendar section above.
The public launch platform configuration includes:
- Android main manifest permissions for internet access and vibration
- iOS live activity support for the current block
- iOS home screen widget support for current and upcoming blocks
- an iOS app group used by the widget and live-activity extension
- iOS app transport security configured to disallow arbitrary network loads while allowing local networking for development
The calendar preview adds Android calendar-read permission and iOS calendar usage descriptions for legacy and full calendar access. These permissions are requested only after the user chooses to connect calendars.
If the app later adds capabilities or permissions that affect user data, this policy will be updated before those changes are released.
Storage, Backups, and Deletion
The public launch app stores the main planning data locally and does not provide account-based cloud storage or planner sync. The preview's optional CloudKit storage and separate account deletion are described above. When Lock Screen Live Activity is enabled, copies of the update details are held by the update service and its delivery queue. Queue, retry, failed-delivery, and infrastructure records are subject to provider retention settings and policies; turning the feature off or uninstalling the app does not itself erase these records. Contact support@24block.app about data held by the update service.
Depending on the user's operating system settings, local app data may also be included in device backups managed by Apple or the user's device platform. The Android release build opts out of Android app-data backup. Backups are not operated by 24 Block.
Users can remove planning data from within the app where controls exist, or remove app data by uninstalling the app, subject to how the operating system handles local storage and backups.
Support emails and privacy requests are kept only for as long as reasonably needed to handle the request, maintain business records, resolve disputes, and comply with legal obligations.
Website request metadata is retained by hosting and security providers under their own retention settings and policies.
Security
24 Block uses local storage for the planner and encrypted network connections for its configured Live Activity update service. No software system can guarantee absolute security, but the product should follow platform security defaults and continue improving as features expand.
The account preview uses server-verified Apple authentication, expiring sessions, secure device credential storage and encrypted production network connections. Private CloudKit sync uses Apple's platform access controls. These measures do not establish that the unreleased features have completed production setup or real-device verification.
Children
24 Block is a general productivity app and is not intended to knowingly collect personal information from children.
Privacy Rights
Depending on where the user lives and the basis for processing, privacy rights may include the right to:
- access personal data held about them
- ask for inaccurate personal data to be corrected
- ask for personal data to be deleted
- restrict or object to certain processing
- receive a copy of personal data in a portable format
- withdraw consent where consent is the lawful basis
Most planning data is stored locally on the user's device and is not held by Jamgo Labs Ltd. For support emails or other personal data Jamgo Labs Ltd does hold, users can contact support@24block.app.
Users also have the right to complain to the UK Information Commissioner's Office at https://ico.org.uk/ if they are unhappy with how their personal data is handled.
Changes to This Policy
If the app, legal requirements, or data practices change, this policy will be updated before those changes take effect in release builds.
Contact
For privacy questions, contact support@24block.app.