Skip to content

User activityExecution

Screen Time Databases: macOS App Usage Totals

ScreenTimeAgent RMAdminStore databases on macOS hold per-app and per-domain usage totals, pickups and notification counts per device and user.

Location
/private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/
Proves
How much time each app or web domain was used per period, on which device and by which Apple Account
Timestamps
Mac absolute time (seconds since 2001-01-01 UTC); durations in seconds
Access
Owning user or root; extra protection on current macOS, image collection is most reliable
Retention
Not documented by Apple; measure from the oldest usage block
Collection
mac_apt, Disk image, cp

What it is

Screen Time came to the Mac with macOS Catalina (10.15). The ScreenTimeAgent process keeps Core Data SQLite stores named RMAdminStore-Local.sqlite and RMAdminStore-Cloud.sqlite. They hold aggregated usage: total time per app bundle ID or web domain within a usage block, the number of pickups and notifications, and the device and Apple Account the usage belongs to. When "Share across devices" is on, usage from the user's other devices can appear too.

Screen Time is an aggregate view. The raw, event-level data behind similar questions lives in knowledgeC.db streams (/app/usage, /app/webUsage, /app/mediaUsage) and, on newer releases, in Biome streams such as ScreenTime.AppUsage.

Where it lives

ItemPathNotes
Screen Time stores/private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/RMAdminStore-Local.sqlite and RMAdminStore-Cloud.sqlitePer-user DARWIN_USER_DIR; find it with getconf DARWIN_USER_DIR as that user
Related event data~/Library/Application Support/Knowledge/knowledgeC.dbTCC-protected
Related Biome stream~/Library/Biome/streams/restricted/ScreenTime.AppUsage/local/TCC-protected

On current macOS the com.apple.ScreenTimeAgent folder is protected beyond normal file permissions: a Terminal with Full Disk Access, running as the owning user, was denied access on macOS 26, so plan for collection from a disk image. Each user has a different /private/var/folders/<xx>/<id>/ directory. On a disk image, map folders to users by the owner UID of the directory. Include the -wal and -shm files.

What it proves

  • Total time an app (ZBUNDLEIDENTIFIER) or website (ZDOMAIN) was used within a usage block.
  • Number of device pickups and notifications per app, and pickups without any app use.
  • Which device name and which Apple Account (ZAPPLEID, given and family name, family member type) the usage is attributed to.

It does not give individual sessions or exact start and stop times per app. Totals do not show which files were opened, and time attributed to another device is not activity on this Mac.

Key fields

Tables and columns used by the mac_apt SCREENTIME plugin (written for Catalina-era schemas; check .schema on newer releases):

TableColumnMeaning
ZUSAGETIMEDITEMZBUNDLEIDENTIFIER, ZDOMAINApp bundle ID or web domain
ZUSAGETIMEDITEMZTOTALTIMEINSECONDSUsage total in seconds
ZUSAGETIMEDITEMZCATEGORYLink to ZUSAGECATEGORY
ZUSAGECATEGORYZBLOCKLink to ZUSAGEBLOCK
ZUSAGEBLOCKZSTARTDATE, ZLASTEVENTDATEBlock start and last event time
ZUSAGEBLOCKZNUMBEROFPICKUPSWITHOUTAPPLICATIONUSAGEPickups with no app use
ZUSAGEBLOCKZUSAGELink to ZUSAGE (device and user)
ZUSAGECOUNTEDITEMZNUMBEROFNOTIFICATIONS, ZNUMBEROFPICKUPSPer-app counts in the block
ZCOREDEVICEZNAMEDevice name
ZCOREUSERZAPPLEID, ZGIVENNAME, ZFAMILYNAME, ZFAMILYMEMBERTYPEAccount identity and family role

Timestamps

ZSTARTDATE and ZLASTEVENTDATE are Mac absolute time, seconds since 2001-01-01 UTC. ZTOTALTIMEINSECONDS is a duration, not a timestamp.

SELECT datetime(ZSTARTDATE + 978307200, 'unixepoch') AS block_start_utc,
       datetime(ZLASTEVENTDATE + 978307200, 'unixepoch') AS last_event_utc
FROM ZUSAGEBLOCK ORDER BY ZSTARTDATE;

Retention

Apple does not document how long Screen Time aggregates are kept on macOS. Report the earliest and latest ZUSAGEBLOCK.ZSTARTDATE you actually observe.

Collection

# Run as the user of interest (Terminal with Full Disk Access); may be denied on current macOS
STORE="$(getconf DARWIN_USER_DIR)com.apple.ScreenTimeAgent/Store"
mkdir -p case/screentime && cp -p "$STORE"/RMAdminStore-* case/screentime/
shasum -a 256 case/screentime/*
  • On a disk image, search /private/var/folders/*/*/0/com.apple.ScreenTimeAgent/Store/ for every user.
  • mac_apt locates the stores through each user's DARWIN_USER_DIR and exports them with its SCREENTIME plugin.
  • Collect knowledgeC.db and Biome at the same time; they provide the event-level detail.

Parsing

  • mac_apt SCREENTIME plugin (image or artifact-only mode):
python3 mac_apt_artifact_only.py -i case/screentime/RMAdminStore-Local.sqlite -o out -c SCREENTIME
  • The same joins in plain SQL:
SELECT IFNULL(t.ZBUNDLEIDENTIFIER, t.ZDOMAIN) AS app_or_domain,
       t.ZTOTALTIMEINSECONDS AS seconds,
       datetime(b.ZSTARTDATE + 978307200, 'unixepoch') AS block_start_utc,
       d.ZNAME AS device, u.ZAPPLEID AS apple_id
FROM ZUSAGETIMEDITEM t
LEFT JOIN ZUSAGECATEGORY c ON c.Z_PK = t.ZCATEGORY
LEFT JOIN ZUSAGEBLOCK b    ON b.Z_PK = c.ZBLOCK
LEFT JOIN ZUSAGE z         ON z.Z_PK = b.ZUSAGE
LEFT JOIN ZCOREDEVICE d    ON d.Z_PK = z.ZDEVICE
LEFT JOIN ZCOREUSER u      ON u.Z_PK = z.ZUSER
ORDER BY b.ZSTARTDATE;
  • APOLLO has Screen Time modules (screentime_timed_items, screentime_counted_items, screentime_by_hour, screentime_by_category) for these stores, and its modules knowledge_app_usage, knowledge_app_webusage and knowledge_app_media_usage cover the underlying knowledgeC streams.

For the event-level data behind these totals, KnowledgeC Parser reads knowledgeC.db and the Biome ScreenTime.AppUsage stream in the browser; it does not read the RMAdminStore files.

Investigator tips

  • Always split results by ZCOREDEVICE.ZNAME: with sharing across devices enabled, an iPhone's usage can sit in the Mac's store.
  • ZAPPLEID and the family fields tie usage to an Apple Account and a family role (for example a child account under parental controls), which helps with attribution questions.
  • Use Screen Time totals to find the right days, then knowledgeC and Biome to reconstruct exact intervals.
  • A domain in ZDOMAIN with no matching browser history is worth explaining (another browser, another device, or history that was cleared); corroborate before concluding.
  • Map the /private/var/folders directory to its owning UID before attributing data to an account, especially on shared Macs (see user accounts).
  • Notification counts can be checked against the notification database.

See also