# Can I trust Opal Screen Time Limit & Timer?

Opal Screen Time Limit & Timer for iOS, version 4.1 (build 0612165642) (scanned 17 June 2026) is labelled NOT ASSESSED, with a score of 88 out of 100. This app has an open trust check or a verdict held for review. The scan names 18 third-party services: Adjust, Facebook SDK (FBSDKCoreKit, FBAEMKit), Firebase Analytics, Firebase Crashlytics, Firebase Firestore, Firebase Remote Config, Firebase App Check, Google App Measurement, Google Ads On-Device Conversion, OneSignal, RevenueCat, Superwall, Amplitude Analytics, Amplitude Session Replay, ContextSDK, RecaptchaEnterprise, Lottie and Rive Runtime. It recorded 6 findings rated low or higher across 4 categories, 2 of them rated medium or higher. A static scan shows what the app's code and manifest contain; the app's network traffic needs a capture of the running app.

- Package: `com.withopal.opal`
- Platform: iOS
- Version: 4.1 (build 0612165642)
- App Store version: 4.17, released 26 September 2026, newer than the scanned version (checked 5 October 2026)
- Developer: Opal OS
- Scanned: 17 June 2026
- Label and score: NOT ASSESSED, 88 of 100 (criteria: https://canitrustthat.com/methodology)

## Trust checks

- Secure by Design: Strong
  - Strong security foundation
  - This check looks for security issues at high severity or above in the code of this build, and none were recorded. Its scope covers stored credentials, how the app protects data on the device, and how it protects data in transit.
  - No critical or high-severity security vulnerabilities were found. All network connections use HTTPS. Minor issues include staging server addresses compiled into the release app and a developer test address inside a third-party payment SDK that is unreachable on real devices. Storage protection is appropriate for a consumer app. None of these represent realistic security risks under normal use.
- Data Minimization: Items recorded, result pending review
  - Tracking lacks clear disclosure
  - This build contains analytics or attribution code written to send data to companies other than the developer. No consent step was found before that code runs, and the app's disclosures do not describe the collection in full. Tracking by itself is ordinary; what this check reports is the combination of collection, recipient and absent disclosure.
- Manifest Mismatch: One criterion not met
  - Disclosure incomplete or contradicted
  - The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.
- User Control: Strong
  - No lock-in
  - The check looks for a way to export the data an account has accumulated and a way to delete the account itself. In this build, either both were found, or the app has no account of its own and keeps its data on the device. For an app without an account, the developer has no server-side copy to export or delete, and deleting the app removes the data in its own storage.
  - Subscriptions are handled through Apple's standard in-app purchase system, which users can cancel at any time directly in iPhone Settings without going through the app. No proprietary data formats or artificial barriers to leaving the service were found.
- Truly Local: Items recorded, result pending review
  - Contains code to send personal data off the device
  - This app presents itself as working offline or on the device alone, and this build contains code written to send personal data to servers. The check covers analytics, crash reporting, advertising code and any first-party endpoint the code addresses personal data to. Code of this kind is common; what this check reports is the distance between that code and how the app describes itself.

## Summary

- Best for: Focus app users comfortable with standard analytics
- What it means for you: The app includes code to pass app usage data, including session behavior and feature interactions, to Firebase Analytics, Amplitude Analytics, and Google App Measurement. When the user consents via Apple's App Tracking Transparency prompt, the build includes code to pass attribution data to Adjust and Facebook SDK to measure ad campaigns. OneSignal handles push notifications, and the app includes code to pass subscription and paywall activity to RevenueCat and Superwall.
- Main concern: Privacy label omits health & location data; Facebook auto-events bypass consent
- The developer's description: Opal is a screen-time management app that helps users track app usage, understand their digital habits, and manage focus with personalized insights.

## Strengths

- Firebase App Check enforced for app integrity attestation
- RecaptchaEnterprise used for bot and fraud protection at authentication
- All external API endpoints use HTTPS
- Multiple stricter Keychain protection classes used correctly for most items (WhenUnlocked, AfterFirstUnlock)
- ATT prompt present for OS-gated IDFA collection
- 49 SKAdNetwork entries registered for privacy-preserving attribution

## What the app contains

- Adjust
- Facebook SDK (FBSDKCoreKit, FBAEMKit)
- Firebase Analytics
- Firebase Crashlytics
- Firebase Firestore
- Firebase Remote Config
- Firebase App Check
- Google App Measurement
- Google Ads On-Device Conversion
- OneSignal
- RevenueCat
- Superwall
- Amplitude Analytics
- Amplitude Session Replay
- ContextSDK
- RecaptchaEnterprise
- Lottie
- Rive Runtime

## Corrections

No correction is published for this app.

## Method and limits

Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.

HTML page: https://canitrustthat.com/apps/com.withopal.opal?platform=ios
