Privacy Policy for AppLock
Last Updated: December 14, 2025
1. Introduction
AppLock ("we," "our," or "the app") is committed to protecting your privacy and ensuring transparency about how we handle your data. This Privacy Policy explains in detail how we collect, use, store, and safeguard information when you use our Android application.
By installing and using AppLock, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with any part of this policy, please do not use our application.
2. Information We Collect
2.1 Usage Statistics Permission (PACKAGE_USAGE_STATS)
Status: Required for core functionality
What We Collect:
- App package names (e.g., "com.example.app") of applications installed on your device
- Timestamps when apps are opened (MOVE_TO_FOREGROUND events)
- Timestamps when apps are closed or moved to background (MOVE_TO_BACKGROUND events)
- Duration of app usage (time spent in foreground)
- Launch count (how many times each app was opened)
- Foreground/background status of applications
- Last time used for each application
Why We Need This:
- To detect when protected apps are opened in real-time
- To enforce app lock restrictions and show the lock screen
- To provide usage statistics and insights (daily, weekly, monthly reports)
- To implement time-based restrictions (daily usage limits)
- To track app launch attempts for security purposes
- To calculate screen time and usage patterns
How We Use This:
- This data is stored locally on your device only in Android's DataStore
- Used exclusively to determine when to show the lock screen
- Used to calculate app usage time for restriction enforcement
- Used to generate usage reports and statistics within the app
- Never transmitted to external servers unless you explicitly enable cloud backup features
- Data is cached temporarily (10 minutes) for performance optimization
2.2 Accessibility Service
Status: Recommended for enhanced security (especially on MIUI/Xiaomi devices)
What We Collect:
- Window state changes (which app is currently in the foreground)
- App package names and window titles
- Text input events (only when parental control features are enabled)
- Window content changes (for detecting app launches)
Why We Need This:
- To provide faster and more reliable app detection (especially on custom Android skins)
- To enable real-time parental control text monitoring (optional feature)
- To improve lock screen timing and accuracy
- To work around manufacturer-specific restrictions (especially on Xiaomi/MIUI, Huawei, Oppo devices)
- To intercept app launches before any content is visible (enhanced security)
How We Use This:
- Accessibility service data is processed in real-time only
- Text monitoring is disabled by default and only active when parental control features are explicitly enabled
- No accessibility data is stored permanently unless explicitly configured for parental controls
- No data is transmitted outside your device
- Window state information is used only to detect app launches
2.3 System Alert Window (Overlay Permission)
Status: Required for core functionality
What We Collect:
- No data is collected through this permission
Why We Need This:
- To display the lock screen overlay on top of protected apps
- To show authentication prompts (PIN, pattern, biometric) when restricted apps are opened
- To ensure the lock screen appears immediately and prevents any content from being visible
- Required for core app locking functionality
How We Use This:
- Only used to display UI elements (lock screen) on screen
- No data collection or storage
- No access to underlying app content
2.4 Notification Permission
Status: Required (Android 13/Tiramisu and above)
What We Collect:
- No data is collected through this permission
Why We Need This:
- To run the app lock service in the background
- To display service status notifications
- To ensure the app lock service continues working even when the app is not actively used
- To notify users about app lock events (optional, can be disabled)
How We Use This:
- Only used to display notifications
- No data collection or storage
2.5 Full Screen Intent Permission
Status: Required (Android 14/Upside Down Cake and above)
What We Collect:
- No data is collected through this permission
Why We Need This:
- To display the lock screen when your device is locked
- To ensure the lock screen appears immediately when you try to open a protected app, even if your device screen is off
- Required for proper lock screen functionality on Android 14+
How We Use This:
- Only used to display the lock screen on locked devices
- No data collection or storage
2.6 Battery Optimization Exclusion
Status: Required for reliable background operation
What We Collect:
- No data is collected through this permission
Why We Need This:
- To ensure AppLock continues monitoring app usage in the background
- To prevent the system from killing the AppLock service to save battery
- To ensure the app lock service continues working when the device goes to sleep
How We Use This:
- Only used to prevent system from stopping our service
- No data collection or storage
2.7 Device Information
What We Collect:
- Device manufacturer and model (e.g., "Samsung Galaxy S21")
- Android version (e.g., "Android 13")
- App installation data (package names of installed apps)
- Device language and locale settings
Why We Need This:
- To provide manufacturer-specific optimization guides
- To ensure compatibility across different Android versions
- To improve app reliability and performance
- To customize user experience based on device capabilities
How We Use This:
- Used locally to customize user experience
- No personally identifiable information is collected
- Not shared with third parties (except anonymized crash reports)
2.8 User Account Information (Optional)
What We Collect (if you create an account):
- Phone number (for authentication)
- Email address (optional)
- User name (optional)
- Access tokens and refresh tokens (for authentication)
Why We Need This:
- To authenticate your identity
- To enable cloud backup features (if enabled)
- To enable remote management features (if enabled)
- To sync settings across devices (if enabled)
How We Use This:
- Stored locally on your device in encrypted format
- Only transmitted to servers if you explicitly enable cloud features
- Used only for authentication and account management
- Never shared with third parties
2.9 App Lock Settings
What We Collect:
- List of locked/protected apps (package names)
- Lock method preferences (PIN, pattern, biometric)
- Security settings (stealth mode, intruder selfie, auto-lock, etc.)
- Unlock duration settings
- App usage restrictions (daily limits, time restrictions)
- Parental control settings (if enabled)
Why We Need This:
- To enforce app locking functionality
- To remember your security preferences
- To apply usage restrictions
- To enable parental control features
How We Use This:
- Stored locally on your device in Android DataStore
- Encrypted using Android Keystore
- Never transmitted unless you enable cloud backup
2.10 Biometric Data
Important: We do NOT collect, store, or have access to your biometric data (fingerprints, face recognition). Biometric authentication is handled entirely by the Android system and never leaves your device.
3. Data Storage and Security
3.1 Local Storage Only
- All app lock settings are stored locally on your device using Android DataStore
- App usage logs are kept in a local database
- Lock screen patterns/PINs are encrypted using Android Keystore
- Authentication credentials are hashed and encrypted
- No cloud synchronization unless you explicitly enable it
3.2 Encryption
- Authentication credentials (PIN, pattern) are encrypted using AES-256
- Sensitive data uses Android Security Crypto library
- Encryption keys are managed by Android Keystore (hardware-backed when available)
- Biometric data is handled entirely by Android system (we never access it)
3.3 Data Retention
| Data Type |
Retention Period |
Notes |
| App usage logs |
Configurable (default: 30 days) |
Can be cleared anytime from app settings |
| Lock watch logs |
7 days (auto-deleted) |
Diagnostic purposes only |
| Authentication data |
Until manually removed |
Stored until you remove or change it |
| App lock settings |
Until app uninstallation |
Stored locally on device |
| User account data |
Until account deletion |
Can be deleted anytime |
| Crash reports |
90 days (anonymized) |
Only if crash reporting is enabled |
4. Data Sharing and Third Parties
We DO NOT:
- Sell your data to third parties
- Share usage statistics with advertisers
- Transmit app usage data to external servers (by default)
- Access or store your biometric data
- Share your personal information without your explicit consent
4.1 Third-Party Services
We may use the following third-party services for app functionality:
| Service |
Purpose |
Data Shared |
| Firebase Crashlytics |
Crash reporting and error tracking |
Anonymized crash logs, device model, Android version |
| Firebase Performance |
Performance monitoring |
Anonymized performance metrics |
| Google Play Services |
App updates and security |
App installation data (handled by Google) |
Note: You can disable crash reporting and analytics in app settings.
4.2 Optional Cloud Features
If you enable cloud backup or remote management features:
- Data may be transmitted to our secure servers
- You will be notified and must explicitly consent
- Data transmission uses encrypted HTTPS connections
- You can disable cloud features at any time
- All cloud data can be deleted upon request
5. Permissions Summary
| Permission |
Purpose |
Required |
Data Collected |
| Usage Statistics (PACKAGE_USAGE_STATS) |
Detect when protected apps are opened |
Yes |
App names, timestamps, duration, launch count |
| System Alert Window (Overlay) |
Display lock screen overlay |
Yes |
None |
| Accessibility Service |
Enhanced app detection and parental controls |
Recommended |
Window states, text events (only if parental control enabled) |
| Notification Permission |
Background service notifications |
Yes (Android 13+) |
None |
| Full Screen Intent |
Display lock screen on locked devices |
Yes (Android 14+) |
None |
| Battery Optimization Exclusion |
Prevent service from being killed |
Yes |
None |
| Biometric Authentication |
Unlock with fingerprint/face |
Optional |
None (handled by Android system) |
| Device Admin |
Enhanced security features |
Optional |
None |
6. Your Rights and Controls
6.1 You Can:
- View all app usage logs in the app's usage statistics section
- Clear all logs and data at any time from app settings
- Disable parental control text monitoring
- Revoke any permission through Android settings
- Uninstall the app to delete all local data
- Request data export (through app settings)
- Disable crash reporting and analytics
- Delete your account and all associated data
- Opt-out of cloud backup features
6.2 Access Your Data:
- App Open Log: View in the app's diagnostic section
- Lock Watch Logs: View in diagnostic/logs section
- Usage Statistics: View in usage stats section (daily, weekly, monthly)
- Settings data: Accessible through app settings
- Locked apps list: View and manage in app lock section
7. Children's Privacy
AppLock includes parental control features but is designed for use by parents/guardians, not children. We do not knowingly collect information from children under 13.
The parental control text monitoring feature:
- Is disabled by default
- Requires explicit activation by the device owner
- Stores filtered text locally on the device only
- Can be disabled at any time
- Never transmits data to external servers
8. Changes to This Policy
We may update this Privacy Policy to reflect:
- Changes in legal requirements
- New features or functionality
- User feedback and requests
- Security improvements
You will be notified of significant changes through:
- In-app notification
- Update notes in the Play Store
- Prominent display on first app launch after update
Last Updated: December 14, 2025
9. Compliance
9.1 GDPR (European Union)
If you are located in the European Union, you have the following rights:
- Right to access: Request a copy of your personal data
- Right to rectification: Correct inaccurate data
- Right to erasure: Request deletion of your data
- Right to data portability: Receive your data in a structured format
- Right to object: Object to processing of your data
- Right to restriction: Restrict processing of your data
9.2 CCPA (California)
If you are a California resident, you have the following rights:
- Right to know: Know what personal information is collected
- Right to delete: Request deletion of personal information
- Right to opt-out: Opt-out of sale of personal information (we don't sell data)
- Right to non-discrimination: Not be discriminated against for exercising your rights
9.3 Google Play Policy
- This app complies with Google Play's User Data policies
- Sensitive permissions are used only for core functionality
- No deceptive or hidden data collection
- All permissions are clearly explained to users
10. Security Measures
- Local data encryption using AES-256
- Android Keystore for key management (hardware-backed when available)
- No plain-text storage of sensitive data
- Secure deletion when data is removed
- No network transmission without consent
- Regular security audits and updates
- HTTPS encryption for all network communications (when cloud features are enabled)
11. Contact Us
12. Technical Details
12.1 Data Storage Locations
- Local Storage: Android DataStore (encrypted)
- Usage Logs: Local SQLite database
- Authentication: Android Keystore (hardware-backed when available)
- Cloud Storage: Only if you enable cloud backup (encrypted servers)
12.2 Data Processing
- All data processing occurs on your device
- No data is sent to external servers unless explicitly enabled
- Real-time processing for app detection
- Background processing for usage statistics