Privacy Policy — TemptShield
Effective date: July 14, 2026 App: TemptShield (com.mnhmilu.temptshield) Developer contact: mnhmilu.app@gmail.com
TemptShield is a self-control app that adds a short pause before you open apps you've flagged as tempting. It is built on a simple principle: friction, not surveillance. The app works fully offline — it has no account system, no backend server, no analytics, and no ads.
The short version
We do not collect any personal data.
We do not transmit any data off your device.
We do not use analytics, tracking, or advertising SDKs.
Everything the app knows lives in local storage on your device and is deleted when you uninstall the app.
Data the app stores (on your device only)
TemptShield keeps a small amount of data in local, device-only storage so the app can function:
Your list of flagged ("tempting") apps — the apps you chose to add friction to.
Pause statistics — counts of how often the pause screen appeared and whether you closed the app or opened it anyway (today and all-time), and your "Safe Day" streak.
Partner-lock PIN (if you set one) — stored only as a cryptographic hash in Android Keystore-backed secure storage. The PIN itself is never stored and cannot be recovered by us or anyone else.
App settings and permission state.
None of this leaves your device. There is no server to send it to. Android auto-backup is intentionally disabled, so this data does not survive an uninstall and is never uploaded to cloud backups.
Permissions and why the app needs them
Usage Access (prominent disclosure). TemptShield uses Android's Usage Access permission (PACKAGE_USAGE_STATS) for exactly one purpose: to detect which app comes to the foreground, so the pause screen can appear when you open an app you flagged. This check happens on-device in real time. TemptShield never records what you do inside any app — no browsing history, no URLs, no messages, no screen contents — and no usage information is ever stored beyond the aggregate pause counts described above or transmitted anywhere. You grant this permission explicitly in system settings, and you can revoke it there at any time.
Display over other apps. Used solely to draw the pause screen on top of a flagged app when you open it.
Notifications and foreground service. The app runs a persistent foreground service so the pause feature keeps working; Android requires a visible notification for this.
Run at startup. Restores the protection service after your device reboots.
Installed-app list (package visibility). Used only to show you the picker where you choose which apps to flag. The list is read on-device and never stored or transmitted.
Device admin / Device Owner (optional, advanced). If you choose to provision TemptShield as a Device Owner (a manual, deliberate setup step), the app uses that role only to make your own protection tamper-resistant — for example, restoring the Private DNS setting if it is changed. It is never used to collect data, and the app works without it.
Optional content filtering (Private DNS)
TemptShield can guide you to enable Android's system Private DNS setting with Cloudflare Family (family.cloudflare-dns.com) to filter adult content network-wide. If you enable this:
Your device's DNS queries are resolved by Cloudflare, not by TemptShield. TemptShield never sees, handles, or logs your network traffic — it only reads whether the Private DNS setting is currently active, to show you a status indicator.
Cloudflare's handling of DNS queries is governed by Cloudflare's privacy policy and their 1.1.1.1 for Families commitments.
This feature is optional and controlled entirely by you through Android's own settings.
Data sharing and third parties
We do not share, sell, rent, or disclose any data to third parties — because no data ever reaches us in the first place. The app contains no third-party analytics, advertising, or tracking SDKs.
Children
TemptShield is a self-control tool intended for general audiences. It does not knowingly collect personal information from anyone, including children — it does not collect personal information at all.
Data retention and deletion
All data is stored locally on your device. To delete it, simply uninstall the app: all stored data (flagged apps, statistics, streak, partner-lock hash) is removed and does not survive reinstallation.
Security
The small amount of local data the app keeps is stored using Android's application sandbox, and sensitive values (such as the partner-lock hash) are protected with Android Keystore-backed encrypted storage.
Changes to this policy
If the app's data practices ever change, this policy will be updated and the effective date revised. Because the app is fully offline by design, we expect changes to be rare.
Contact
Questions about this policy or the app's privacy practices: Email: mnhmilu.app@gmail.com