LOCKAFRIEND

PRIVACY POLICY

LAST UPDATED 11 AUGUST 2026

lockafriend puts apps you choose to sleep during hours you choose, and gives the early-unlock key to a friend. This page says exactly what that costs you in data.

The Android app is not released yet. Everything below about the app describes what it will store from the moment you install it and sign in. Today, only the website sections apply.

The short version. The part of lockafriend that could watch you doesn't. The accessibility service reads the name of the app in front of you, in the moment, to decide whether to put a wall up. It never reads what is on your screen, never writes that name down, and never sends it anywhere. What we do store is the pact: which apps, which hours, whether you held the night. Your friend sees the pact. Nobody sees your usage, including us.

1. WHO IS RESPONSIBLE

lockafriend is built and operated by Olivier Martinez, an individual developer based in France, acting as data controller under the GDPR.

Contact for anything on this page, including access requests: lockafriend@protonmail.com. To delete your account and everything attached to it, see delete your account — it works from inside the app or from the web.

2. THE ACCESSIBILITY SERVICE — WHAT IT DOES AND DOES NOT DO

To put a wall in front of an app, lockafriend has to know which app you just opened. On Android the only supported way to know that is an accessibility service, which is why the app asks for one, and why Android shows you an alarming permission dialog when it does. That dialog is written by Android and is the same for every accessibility service; it is not a description of what this one does.

Here is what this one does:

It never reads the content of your screen. No text, no messages, no passwords, no images, no field you type into. It never stores which app you opened — the package name is used to make one decision, in memory, and is gone. It never transmits anything. Nothing from the accessibility service reaches our servers, your friend, or anyone else.

The technical consequence, if you want to check it: your usage never leaves your phone because it is never written down in the first place, on the phone or off it.

3. WHAT THE APP STORES ABOUT YOU

Once you sign in, the following is stored on our servers.

WhatWhy
Your Google account identifier and email address Sign-in is Google Sign-In only. The identifier is how we recognise you on a new phone; the email is how end-of-trial and guard-down warnings reach you.
Your nickname It names you to your friend, on the ladder, and on your public card. Prefilled from your Google account, changeable.
Your pact: the apps you chose, the lock window, its status, your current streak, total hours locked, and — if you end it — the closing message you picked from a fixed list This is the product. Your friend has to be able to see what they are guarding.
Invitation links you send, and whether they were used An invitation link binds one Player 1 to one Player 2 and dies once accepted.
Early-unlock requests: when you asked, the optional message (80 characters), and your friend's answer and optional reply Your friend needs the request to answer it, and you need the answer.
Subscription status: whether it is active, whether you are in the trial, when it expires, and the Google Play purchase token A pact only arms if the subscription is live. The token is how Google Play tells us about renewals and cancellations.
A heartbeat: the last time your phone checked in, and whether the lock is still switched on If the lock silently falls over — Android revoked the permission, a battery manager killed the app — the pact would look fine while protecting nothing. The heartbeat is how you and your friend find out.

All of it is kept until you delete your account, and goes when you do. There is no separate retention clock per row and no archive kept afterwards. Site measurement is the one exception, because it is not attached to an account: those rows are kept for 24 months and then dropped.

We do not store your location, your contacts, your photos, your device identifiers, or any advertising identifier. There is no advertising in lockafriend and no third-party analytics or tracking SDK in the app.

4. WHAT YOUR PLAYER 2 SEES

Your friend holds the key, so they see the pact and nothing but the pact:

They never see a single usage event. Not which app you opened, not when, not for how long, not that you tried to open one during a locked hour. That boundary is the product, not a setting — the data does not exist to be shown.

The number of times you have asked to unlock early is kept private and is not published on your card or the ladder.

5. YOUR PUBLIC CARD AND THE LADDER

Your commitment card is public by default and has no password. It lives at lockafriend.com/u/<your nickname> and shows your nickname, your current streak and your total hours locked. Anyone who guesses or is told your nickname can open it, and search engines can index it. Choose a nickname you are happy to be found by.

The same nickname and streak appear on the ladder. Nothing else about you is published — not your email, not your real name, not which apps you locked, not your unlock requests.

6. THE WEBSITE

6.1 Audience measurement

This site counts visits with our own code, on our own domain. There is no Google Analytics, no third-party beacon, and no advertising network.

It sets no cookie and writes nothing to your browser storage — no cookie, no localStorage, not even sessionStorage. That is why you are not being asked to accept anything.

Each visit records: the page, which of our hostnames served it, the referring site's hostname (never the full referring URL), any campaign tags in the link, your country, region and city, your network operator, a coarse device type, and how long the page was open.

Your IP address is never stored. It is used, in memory, to build a one-way hash that also mixes in a secret and the current date. Because the date is part of it, the same browser on two different days produces two unrelated values: we can count how many people came, and we cannot follow anyone from one day to the next. We do not store latitude, longitude or postal code, and we do not fingerprint your browser.

6.2 The launch list

If you give us your email address on this site, it is stored to send you one message, on the day lockafriend launches. Not a newsletter, not product updates, not an invitation to test. We keep your address, which of our sites collected it, and the date — nothing else. Using it for anything else would break the promise the form was signed under.

To be removed, email lockafriend@protonmail.com. Removal means the row is deleted; we do not keep a record that you unsubscribed.

7. LEGAL BASES

8. WHO ELSE HANDLES YOUR DATA

We do not sell your data, and we do not share it with advertisers or data brokers. There is nobody else. Where a provider processes data outside the European Economic Area, it does so under the European Commission's standard contractual clauses.

9. HOW TO GET IT DELETED

You can delete your account from inside the app, under OPTIONS → ACCOUNT → DELETE ACCOUNT. It removes your account, your pact and everything attached to it. Because ending a pact is a real event for the person guarding you, deleting your account also ends the pact and tells your friend — the same as ending it deliberately.

You can also ask for deletion by email at lockafriend@protonmail.com, whether or not you still have the app installed.

Uninstalling the app is always possible and lockafriend will never try to stop you. Note that uninstalling alone does not delete your account: your friend is told, your streak goes to zero, and the account stays until you delete it.

10. YOUR RIGHTS

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, and receive it in a portable form. Write to lockafriend@protonmail.com and you will get an answer within one month.

If you are not satisfied, you can complain to your national supervisory authority. In France that is the CNIL, at cnil.fr.

11. AGE

lockafriend is not intended for children. You need a Google account and a paid subscription to be Player 1, and we do not knowingly collect data from anyone under 16. If you believe a child has an account, write to us and it will be deleted.

12. CHANGES

If this policy changes in a way that affects what we collect or who sees it, the date at the top changes and the app tells you before the change applies to you.