Privacy Policy
Effective 17 August 2026
· Applies to Tessera on iOS.
Tessera: Photo Puzzle Alarm (“the app”) is a private wake-up alarm developed by Tamas Bereczki (“we”, “us”, “our”). We operate no servers of our own, we require no account, and we use no analytics, advertising or tracking SDKs. The photos you wake to are yours and never leave your device. One third party is involved, and only when you buy: RevenueCat, which validates App Store purchases (§6). This page explains what the app stores, what it sends, and who is involved.
1. Data stored on your device
Everything you set up in Tessera is stored locally on your iPhone using Apple’s on-device frameworks. This includes:
- Your photos — the images you deliberately import are copied into the app’s own private container so it can build the puzzle. They are not uploaded anywhere.
- Your alarms — times, repeat days, and labels.
- App settings — which puzzle you solve, appearance (System / Light / Dark), and in-app language.
This data stays on your device. It is removed when you delete the app. We have no copy of it and no way to access it.
Tessera does not use iCloud. Nothing syncs between your devices — your photos and alarms exist only on the iPhone you set them up on.
2. Photos
Tessera uses Apple’s PHPickerViewController so you can choose photos without
granting the app access to your photo library. The picker runs outside the app,
and Tessera only ever receives the specific images you select. Those images are
then copied into the app’s own container. Tessera does not read, scan, or index
your wider camera roll, and no photo is ever transmitted off the device. You can
remove any photo from the pool at any time, with one or two taps.
3. Alarms (AlarmKit)
Tessera schedules real alarms using Apple’s AlarmKit framework so they can ring
through Silent mode and Focus. Alarm scheduling happens entirely on your device.
No data about your alarms or wake-up times is sent to us or to any third party.
You can revoke the app’s permission to schedule alarms in iOS Settings at any
time; the app detects this and surfaces it.
A ringing alarm is never blocked by anything — not by a lapsed subscription, not by being offline. Whatever else is going on, you can always silence it.
4. Send a Morning
Send a Morning lets you write a short message and share it as a link that opens in Tessera, where the person you send it to solves a small puzzle to reveal it.
There is no server involved, and no message is ever stored by us. The whole message travels inside the link itself: the app encrypts it on your device, and the recipient’s copy of Tessera decrypts it on theirs. Nothing about it is uploaded, logged, or seen by anyone in between.
Some things worth being plain about:
- You choose who gets the link. Tessera has no messaging system of its own. It hands the finished link to iOS’s standard share sheet, and you send it through whatever app you’d normally use. That app’s own privacy policy applies to anything you send through it.
- The link is the message. Anyone holding the link can open it, in the same way that anyone holding a photo you sent can look at it. The encryption keeps the text from being readable in the URL itself — in a chat preview, an address bar, or over someone’s shoulder — and makes a tampered link fail rather than show altered words. It is not a secret that only one person can open. Treat the link the way you’d treat the message.
- No contacts, no accounts, no notifications. The optional names you type are presentation only — nothing is looked up, matched, or stored. Sending a morning does not schedule an alarm on the recipient’s phone or send them a notification.
- Nothing is kept. Neither your copy nor theirs is saved anywhere in the app once it has been read.
5. What the app sends over the network
Only one thing, and it isn’t your content: purchases, to Apple and to RevenueCat, as described below. There are no other network requests — no telemetry, no crash reports, no remote configuration, no content downloads.
6. Purchases and RevenueCat
Tessera is free to download, and full use is unlocked by a subscription or a one-time lifetime purchase. Purchases are processed by Apple; we never see your payment method, billing address, or Apple Account details.
We use RevenueCat, Inc. as a processor to validate those purchases and to tell the app whether your access is active. When you open the paywall, buy, or restore a purchase, the following is exchanged with RevenueCat:
- Purchase and subscription data — the App Store transaction receipt, the product identifier bought, purchase and expiry dates, and renewal status.
- An anonymous customer identifier generated by RevenueCat. We do not provide RevenueCat with a user account, email address, name, or any identifier of our own, because the app has no accounts.
- Basic technical context — app version, device platform and OS version, and App Store country, used to return the correct pricing and to validate the receipt.
This data is used solely to run purchases and entitlements, and for the sales figures we see in RevenueCat’s dashboard. It is not used for advertising, and it is not used to track you across other apps or websites. Data is encrypted in transit.
RevenueCat’s privacy policy: revenuecat.com/privacy. Their GDPR information: revenuecat.com/gdpr.
The paywall itself is part of the app, not RevenueCat’s; what it fetches from them when it opens is the offer — which plans exist, their order, their prices, and any introductory offer you are still eligible for. The Customer Center, used to manage or cancel a subscription, is rendered by RevenueCat’s SDK.
7. App Store privacy label
In line with the above, Tessera declares the collection of Purchase History for app functionality and analytics. It is not linked to your identity — the app uses anonymous identifiers only — and is not used for tracking. No other data type is collected. Your photos, alarms and messages are not collected, because they never leave your device except in a link you send yourself.
8. What we do not do
- No analytics, attribution, advertising, or crash-reporting SDKs.
- No advertising and no use of the IDFA (Advertising Identifier).
- No developer-operated servers, and no third-party tracking requests.
- No accounts, sign-in, or user profiles.
- No access to your photo library, contacts, or location.
- No push notifications.
- No tracking across other apps or websites.
- No sale or sharing of personal data — we have none to sell.
9. Children
Tessera is intended for a general audience and does not knowingly collect personal data from anyone, including children.
10. Your rights
Your photos, alarms and messages live on your device, not on any system of ours, so there is nothing on our side to access, export, correct, or delete. You remain in full control:
- Remove any photo from the pool at any time.
- Delete any alarm at any time.
- Delete the app to remove all of its local data from the device.
- Manage or cancel a subscription through the Customer Center in the app’s Settings, or in Settings → Apple Account → Subscriptions.
If you are in the EEA or UK, laws such as the GDPR and UK GDPR may grant you rights including access, rectification, erasure, and portability. Because your content lives only on your device, these are exercised directly through your device. For the purchase data held by RevenueCat as our processor, contact us at the address below and we will action your request with them.
11. Changes
We may update this Privacy Policy as the app evolves. Material changes will be reflected by updating the effective date at the top of this page.
12. Governing law
This Privacy Policy is governed by the laws of Romania, without regard to conflict of law principles.
13. Contact
Questions, requests, or anything else: support@appsbytommy.com.