Privacy Policy
App Lock for Android (package com.jamshid.applock)
Effective date: October 7, 2026
In short: your PIN, hidden files, intruder photos, locked-app list and settings stay on your
phone. We never receive them and cannot recover them. The app does send a small amount of technical
data (device model, Android version, an approximate city and country, usage statistics and crash
reports) to help us run and improve the app. Purchases are handled by Google Play and RevenueCat.
This policy explains what information the App Lock app ("App Lock", "the app", "we", "us") handles, why,
and the choices you have. App Lock is published by Jamshid M.
If you have questions, contact us at 97Jamshid@gmail.com.
1. Information that stays on your device
The following is created and stored only on your phone. It is never uploaded to us or to any third party,
and we have no way to see, recover or reset it.
- Your PIN and optional fake PIN, and your settings (locked apps, unlock timers, theme, language, disguise, guest-mode choices).
- Hidden files (the vault), including a separate decoy vault used with the fake PIN. Vault files are encrypted with a key held in your device's Android Keystore. Because the key never leaves your device, hidden files cannot be restored on another device or after you uninstall the app or clear its data.
- Intruder history, if you turn on intruder mode: a front-camera photo taken after a failed unlock attempt, the time, the app that was being opened and the PIN that was entered. These records are encrypted on your device.
- Notes you write in the Notes disguise. These are part of the disguise and are stored in the app's private storage without extra encryption.
- The list of apps installed on your phone, which the app reads so you can choose which apps to lock or lend in guest mode.
App Lock's vault and intruder data are excluded from Android cloud backup and device-to-device transfer.
2. Permissions and why we ask for them
- Accessibility service: To detect which app has just been opened, so the lock screen can appear immediately, and to keep other apps locked in guest mode. App Lock does not read, collect or share the content of your screen, your typing or your messages.
- Usage access: A fallback way to detect the app in front when the accessibility service is not available.
- Display over other apps: To show the lock screen on top of a locked app.
- Camera (optional): Only if you turn on intruder mode: to take a silent front-camera photo after a failed unlock attempt. Photos stay on your device.
- Files and media / all-files access: To move the photos, videos and files you choose into the encrypted vault and to restore them when you unhide them.
- Notifications, foreground service, ignore battery optimization, run at startup: To keep app protection running reliably, including after a restart.
- Query installed apps: To show the apps you can lock or lend. This list never leaves your device.
- Internet: For the services described in section 3 and for the private browser.
3. Information sent from your device
3.1 Device record
About once every three days, while the app is open, App Lock sends a short device record to our database
(Google Firebase Cloud Firestore):
- your device's Android ID (an identifier Android assigns per app and device),
- device manufacturer and model, and Android version,
- an approximate city and country, looked up from your IP address using the third-party service ip-api.com,
- the date of the update.
We use this to understand which devices, Android versions and regions use App Lock, so we can test and
support them. The record is overwritten on each update rather than accumulated. It does not include your
name, contacts, precise location, PIN, files or anything you lock or hide.
3.2 Usage analytics and crash reports
App Lock uses Google Firebase Analytics to understand how features are used (for example,
that a screen was opened, a feature was turned on, or the paywall was shown) and Firebase Crashlytics
to receive reports when the app crashes. These services collect an app-instance identifier, device and OS
information, approximate region and the events themselves. They never receive your PIN, hidden files,
intruder photos or the contents of other apps.
3.3 Feedback you send
If you send feedback from the Settings screen, we receive the text you write together with your device's
Android ID, so we can tell feedback from different devices apart. Please do not include personal
information in your feedback.
3.4 Purchases (App Lock Premium)
Payments are processed by Google Play; we never receive your card or payment details.
We use RevenueCat to manage subscriptions and purchases. RevenueCat receives a random,
anonymous app user ID, the products you buy, purchase and renewal dates, prices, your store country and
basic device information, so the app can tell whether Premium is active and restore it after a reinstall.
App Lock does not use accounts, and we do not link purchases to your name or email.
3.5 Private browser
Websites you open in App Lock's private browser are loaded directly from those websites, which may
collect information under their own policies. App Lock does not send your browsing to us.
4. Service providers
- Google Firebase (Cloud Firestore, Analytics, Crashlytics) – firebase.google.com/support/privacy
- Google Play (payments, in-app review) – policies.google.com/privacy
- RevenueCat (purchases) – revenuecat.com/privacy
- ip-api.com (approximate location from IP address) – ip-api.com/docs/legal
We do not sell your information and we do not share it with advertisers.
5. How long we keep information
- Data on your device stays until you delete it in the app, clear the app's data or uninstall the app.
- The device record is kept while the app is in use and replaced on each update. You can ask us to delete it at any time (see section 7).
- Analytics data is kept according to our Firebase settings, for no longer than 14 months.
- Crash reports are kept by Crashlytics for up to 90 days.
- Feedback is kept for as long as it is useful for improving the app.
- Purchase records are kept by Google Play and RevenueCat as long as needed to provide your purchase and to meet legal and accounting obligations.
6. Security
Hidden files and intruder records are encrypted on your device with a key protected by the Android Keystore.
Information sent to Firebase and RevenueCat is transmitted over encrypted connections. The approximate-location
lookup with ip-api.com is made over an unencrypted connection and reveals only your IP address to that service.
No method of storage or transmission is completely secure, and App Lock cannot protect against someone who
already knows your PIN or has full control of your device.
7. Your choices and rights
- Delete local data: clear App Lock's data in Android settings or uninstall the app. Unhide any files you want to keep first, because hidden files cannot be recovered afterwards.
- Camera: turn off intruder mode, or revoke the camera permission in Android settings, at any time.
- Server data: email us to access or delete the device record and feedback associated with your device. Include your Android ID if you can, so we can find the record.
- Subscriptions: manage or cancel at any time in Google Play → Payments & subscriptions.
Depending on where you live (for example in the EU, the UK or California), you may have rights to access,
correct, delete or restrict the use of your personal information, to object to processing and to complain to a
data protection authority. We process the information described in section 3 based on our legitimate interest in
operating, securing and improving the app, and to provide purchases you request. Contact us to exercise any of
these rights.
8. Children
App Lock is not directed at children under 13 (or under 16 where local law requires), and we do not knowingly
collect personal information from them. If you believe a child has sent us information, contact us and we will
delete it.
9. International transfers
Our service providers may process information in countries other than your own, including the United States.
They protect it with the safeguards described in their own policies.
10. Changes to this policy
We may update this policy when the app changes. We will post the new version on this page and update the
effective date above. Significant changes will also be noted in the app's release notes.
11. Contact
Jamshid M
97Jamshid@gmail.com