Core principle
Blocking and screen-time data stays on your device by default. It leaves your device only if you sign in — then it auto-syncs and you can also tap Sync. Analytics/crash reports and purchase verification always leave the device as described below.
1. What we collect
a) Account (only if you sign in with Google)
Email, display name, avatar URL, Supabase user ID, auth session. Via Supabase Auth + Google Sign-In (scopes email, profile). No passwords — sign-in is Google-only.
b) On-device blocking data (stays local unless you sign in)
- Installed app list for the picker.
- Block schedules + settings (schedule name, times, days, blocked apps/websites, difficulty, daily goal minutes, Strict Mode flags, permission-blocking flags).
- Screen-time stats (daily totals: total ms, most-used app package/name/time, hourly buckets, per-app usage JSON, daily goal progress).
- Gamification (streaks, achievements).
Stored in private on-device storage (SQLite via sqflite + SharedPreferences + native private prefs). This is private to the app but not end-to-end encrypted.
c) Cloud sync (when signed in)
When you are signed in, the data in (b) auto-syncs to Supabase (tables include daily_totals, user_blocking_prefs, user_gamification, user_achievements; profile and user_subscriptions rows are maintained server-side and read by the client). You can also trigger a manual sync from Settings > Cloud Sync > Sync now.
On a new device, signing in restores your blocking schedules/settings and gamification if the device is empty; usage history is read from the cloud for charts.
d) Analytics + crash (PostHog, always on)
Interaction events (e.g. app_opened, onboarding_started/completed, schedule_created/updated/deleted, first_schedule_created, paywall_viewed/dismissed, checkout_started, purchase/payment_completed/payment_cancelled_halfway, review_prompt_*), plus auto-screen views.
- User identity in analytics: when signed in we call
identify(userId, {email, provider}). - Device/session: device model, OS version, session metrics via PostHog SDK defaults.
- Crash: stack traces + error context via PostHog error tracking.
- No advertising ID is collected.
- Host:
https://us.i.posthog.com(United States).
There is no in-app analytics opt-out toggle. Uninstalling stops future collection; contact [email protected] for past-data requests.
e) Payments (RevenueCat + Google Play Billing)
Your Supabase user ID as the app user ID when signed in (otherwise a RevenueCat anonymous ID), product IDs (zen_plus, zen_plus:zen-plus-yearly, zen_plus_lifetime), price/currency, entitlement status, expiration, receipts. We never see card numbers. Subscription status is maintained server-side.
We collect no location, contacts, camera, mic, files, or message content.
2. Device permissions — why we need each
- Accessibility Service: core blocking. Detects when a blocked app comes to the foreground to show the block screen (listens to window-state / window-change / window-content events;
canRetrieveWindowContent=true,canPerformGestures=false,canRequestFilterKeyEvents=false). Reads visible window text/URLs only to enforce website blocks and detect Settings/uninstall screens. Does not log keystrokes. - Usage Access (PACKAGE_USAGE_STATS): builds screen-time charts.
- Display over other apps (SYSTEM_ALERT_WINDOW): draws the block overlay.
- Notification Listener (BIND_NOTIFICATION_LISTENER_SERVICE):hides notifications from currently blocked apps only (never restored by us).
- Device Admin (force-lock policy): optional Strict Mode > Prevent Uninstallation. Uses lock plus, during an active schedule, hinders uninstall/disable (uninstall restriction, hide installer packages, back/home intercept). You can disable it anytime in Settings when no schedule is active; uninstall is never permanently blocked — system Settings always wins after the warning.
- Battery exemption / Autostart / Foreground Service (dataSync + specialUse: app_usage_tracking) / Boot receiver: keeps blocking/tracking alive in the background.
- Exact alarms (SCHEDULE_EXACT_ALARM) + Notifications (POST_NOTIFICATIONS):daily 10:00 Cloud Sync Ready reminder (premium only) + one-time D+5 trial-ending reminder at 10:00. Inexact fallback if exact alarms are denied.
Granting blocking permissions is optional — the app still tracks time and you can choose Continue anyway in onboarding.
3. Third parties
- Supabase (auth + sync) — https://supabase.com/privacy
- RevenueCat (entitlements) — https://www.revenuecat.com/privacy
- PostHog (analytics/crash, US) — https://posthog.com/privacy
- Google Play Billing / Google Sign-In — https://policies.google.com/privacy
No sale of personal data.
4. Retention + deletion
Local: until you clear app data. Cloud: until you delete your account.
In-app: Settings > Account > Delete Account (type DELETE) requests server deletion via delete_user_data plus wipes local usage/schedules/prefs and signs you out. An active Play subscription must still be cancelled in the Play Store — deletion does not cancel billing.
Web request: email [email protected] from your account email; fulfilled within 30 days.
5. Your rights
Access, correct, export, delete, object to analytics (uninstall stops future collection; contact us about already-collected data). Email [email protected] for requests.
6. Children
Not for under 13. No knowing collection.
7. Changes
Material changes posted here + in-app notice. Continued use = acceptance.
Contact Us
Questions about this policy or your data? Email [email protected].