Privacy Policy
AlarmMCP (the "Service") lets you and the AI agents you authorize schedule real alarms on your iPhone. This policy describes what personal data the Service collects, why, and what choices you have. It covers the AlarmMCP iOS app, the console at alarm-mcp.com, and the API/MCP server behind them.
By using AlarmMCP you agree to this Privacy Policy. Questions or requests can be sent to nathanbdaeila@gmail.com.
Who We Are
AlarmMCP is operated by After Hours IT LLC ("we", "us"), which acts as the data controller for personal data processed through the Service.
Information We Collect
Account information
Sign-in is handled by Clerk. We store your Clerk user ID and email address so we can associate alarms, devices, and API keys with your account.
Device information
To deliver alarms, each device you link stores: a device name and model, OS version, a one-way hash of its device token (never the plaintext token), an Apple Push Notification (APNs) token used to nudge the device when an alarm needs to sync, and a last-seen timestamp.
Alarm data
Alarm labels, scheduled times, timezone, repeat schedule, which device(s) an alarm targets, and its delivery status (e.g. whether it was successfully scheduled on-device).
API keys ("agent keys")
If you create a key so an AI agent or MCP client can manage alarms on your behalf, we store the key's name, expiry, and last-used time, plus a one-way hash of the secret. The plaintext secret is shown once at creation and never stored or displayed again.
Technical and log data
Standard request metadata (IP address, timestamps, endpoint called, error details) is logged by our hosting provider, Cloudflare, for security monitoring, abuse prevention, and debugging.
Mobile app session data
The iOS app uses PostHog for session replay only — there is no custom event tracking, and replays are not linked to your account identity. Recordings are screenshot-based: PostHog's default masking of text inputs stays on, and we additionally mask the views that display personal or user-entered data (your email and profile, alarm labels, and agent names) so they do not appear in recordings. Default app lifecycle events (e.g. app opened) are captured so recordings are findable in our PostHog project.
How We Use Your Information
- Schedule and deliver alarms to your device(s) via Apple's AlarmKit and APNs
- Authenticate you and your linked devices
- Let your authorized AI agents and MCP clients manage alarms through your API keys
- Operate, secure, and troubleshoot the Service, including detecting abuse
- Understand app reliability and usage through session replay, to fix bugs and improve delivery
Cookies
The console at alarm-mcp.com uses a session cookie set by Clerk, strictly necessary for keeping you signed in. We do not use advertising or analytics cookies on the website, so no cookie-consent banner is currently required. The PostHog SDK in the iOS app does not use browser cookies.
How We Share Your Information
We do not sell your personal data. We share it only with the processors necessary to run the Service:
| Processor | Purpose |
|---|---|
| Clerk | Authentication and account management |
| Apple | Push notifications (APNs) and on-device alarm scheduling (AlarmKit) |
| Cloudflare | Hosting, database (D1), and edge network |
| PostHog | Mobile session replay |
We may also disclose data if required by law, or to protect the rights, property, or safety of AlarmMCP, our users, or the public.
Data Retention
| Data | Retention |
|---|---|
| Account, device, and alarm data | For the life of your account, plus a short period after deletion for backups and dispute resolution |
| API key metadata | Until revoked, plus a short grace period |
| Server access/error logs | Typically 30 days |
| Session replay recordings | Per PostHog's default retention; deletable on request |
Data Security
Device tokens and API key secrets are stored only as one-way hashes. All traffic is encrypted in transit (HTTPS/TLS). Access to the underlying database is limited to what the Service needs to operate.
Your Privacy Rights
You can permanently delete your entire account — and all data associated with it (alarms, linked devices, and API keys) — directly in the AlarmMCP iOS app under Settings → Delete Account. You can also delete individual devices and revoke API keys from the console, or request access to, correction of, or deletion of your personal data at any time by emailing nathanbdaeila@gmail.com.
EU/EEA (GDPR): you have the rights of access, rectification, erasure, restriction, portability, and objection under Articles 15–22 of the GDPR, and may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the right to know, delete, and correct your personal information. We do not sell or share personal information for cross-context behavioral advertising, so no opt-out mechanism is required, but you may still contact us with any request.
Children's Privacy
AlarmMCP is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact nathanbdaeila@gmail.com and we will delete it.
International Data Transfers
Our processors (Cloudflare, Apple, Clerk, PostHog) operate global infrastructure, so your data may be processed outside your country of residence, subject to appropriate contractual safeguards.
Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date above. Continued use of the Service after a change constitutes acceptance of the revised policy.
Contact Us
Email nathanbdaeila@gmail.com for any privacy question or request. Data controller: After Hours IT LLC.