IronLock ("we", "us", "our", or "the app") is a digital-discipline Android application that hard-locks selected apps and websites for a duration you choose. This Privacy Policy explains what data IronLock collects, how it is used, and the rights you have over it.
By installing or using IronLock you agree to this Privacy Policy. If you do not agree, please do not use the app.
IronLock is operated by:
Touchstone Labs Contact:touchstonelabs1@gmail.com
For privacy questions, write to the email above.
We do not require an email, phone number, or social login to use IronLock.
We assign your installation a random anonymous Device ID (a UUID). That is the only identifier we store about you.
We store your lock state, whitelist, blocklist, and focus statistics on our server, keyed to that Device ID. This is what makes the "Nuclear" timer tamper-proof against clock changes.
We do not track your browsing, your messages, the contents of any app, or your location.
The Accessibility Service is used only to detect which app is open (its package name) so we can show the lock overlay. It does not read your screen contents, key presses, or messages.
The local VPN is local-only — it never sends your traffic to our servers. It only resolves DNS queries and blocks ones that match the blocklist.
All payments go through Google Play Billing. We never see your card number.
You can delete your data at any time — see Section 11.
Data
When
Purpose
Required?
Email address
Only if you choose Link Email in Settings to enable cross-device premium restore
Recover premium on a new device
Optional
Whitelist / Blocklist preferences
When you customize them in-app
To enforce locks correctly
Yes (functional)
Lock duration and categories you choose
When you start a Nuclear lock
To enforce the lock for the duration you committed to
Yes (functional)
Data
Purpose
Stored?
Anonymous Device ID (UUID v4 generated on device, stored in Android SecureStore)
Identifies your installation across sessions; required for server-synced timer
Yes — until you delete the app or request deletion
App lifecycle events required by the Accessibility Service (foreground package name only)
To trigger the lock overlay when a blocked app opens
Processed in-memory on your device only; not transmitted to our servers
DNS queries inside the local VPN
To match against the blocklist and sinkhole adult/gambling domains
Processed in-memory on your device only; never transmitted to our servers or to any third party
Lock start / end / extend timestamps
Server-synced anti-cheat timer
Yes
Focus statistics (total time saved, sessions completed, longest session)
Display on your dashboard
Yes
Server time
Authoritative reference for the timer (we ignore your device clock for anti-cheat)
N/A — generated server-side
Google Play purchase token + product ID
Verify a subscription / lifetime purchase via Play Developer API
Yes
Crash and basic diagnostic data (if enabled by Android OS / Google Play)
Improve stability
Aggregated, anonymous
❌ Names, phone numbers, real-world location, contacts, photos, microphone, camera input
❌ The text of any messages, search queries, web pages, or app contents
❌ Keystrokes or anything you type in any app
❌ A list of apps installed on your device beyond those you explicitly add to your whitelist or blocklist
❌ Credit card / banking information (handled entirely by Google Play)
❌ Browsing history (the VPN only inspects DNS queries in-memory)
❌ Advertising identifiers — IronLock contains no third-party advertising SDKs
Product Analytics (Mixpanel) To operate and improve IronLock, we collect anonymous, aggregated usage data about how the app is used — for example: which screens you view, when you start or complete a lock session, and where you interact with the paywall. This data is identified only by a random device ID we generate on your device — never by your name, email, or content. This is essential for our operations (understanding whether the app works, detecting bugs, planning features). We use Mixpanel as our analytics processor. See: https://mixpanel.com/legal/privacy-policy/
What we never collect:
The names of apps or websites you block (stored on your device only)
Your search queries or content of Safe Browser sessions
Your device contacts, calendars, media, or files
Your precise location
Your rights: You can request deletion of your analytics data at any time by emailing contactus@touchstonelabs.ai — we honour deletion requests within 30 days.
IronLock requests several powerful Android permissions. Each is justified below in compliance with Google Play's Permissions and APIs that Access Sensitive Information policy.
Purpose: Detect which app the user has brought to the foreground so we can show the lock overlay over blocked apps and selected Android Settings sub-screens (App info, Uninstall, Storage, Accessibility Services).
Data accessed: Foreground app's package name, and — only inside the Settings app — visible UI text/contentDescription on screen, used solely to detect navigation toward sensitive sub-screens. No screen content is logged, stored, or transmitted.
Off-device transmission: None. All Accessibility data is processed locally and discarded immediately.
Purpose: Block adult and gambling domains across every browser (Chrome, Brave, Incognito, etc.) by intercepting DNS queries locally.
How it works: IronLock starts an on-device VPN that loops back to itself. It is not a remote VPN. Your internet traffic is not routed through any external server — not ours, not anyone's. Only DNS queries (UDP port 53) are inspected, and only the queried domain name is examined. Non-blocked traffic flows through unmodified.
Off-device transmission: None.
Purpose: Prevent IronLock from being uninstalled while a Nuclear lock is active. When the lock expires, you can disable Admin and uninstall freely.
What we do NOT do with Device Admin: We do not wipe data, lock the device, change passwords, monitor camera, or use any other Device Admin capability beyond uninstall protection.
Purpose: Draw the calming lock-screen overlay on top of a blocked app.
No other use.
Purpose: Keep IronLock running so the lock cannot be silently killed by aggressive battery savers.
A persistent notification will be shown while a lock is active, as required by Android.
Purpose: Let you pick apps to whitelist or block from a list of installed apps.
The list of installed packages stays on your device. We do not transmit it.
Purpose: Re-arm an active Nuclear lock if you restart your phone mid-lock (anti-cheat).
We use the data described above to:
Enforce the locks you configure (foreground blocking + DNS sinkhole)
Compute the server-synced timer so changing your device clock does not bypass a lock
Track your focus statistics so you can see what you've earned
Process subscription and lifetime purchases through Google Play Billing
Verify Google Play receipts to grant premium features
Generate calming quotes for the lock screen (see Section 7)
Respond to support requests you send us
We do NOT:
Sell your data to anyone
Share your data with advertisers
Use your data to build behavioral profiles
Use your data for any purpose unrelated to running IronLock
We process personal data on the following legal bases:
Performance of a contract — to provide the IronLock service you installed.
Legitimate interests — fraud prevention on premium purchases, anti-cheat on the Nuclear timer, basic stability diagnostics.
Consent — for the optional email account linking (you can withdraw at any time by deleting the link in Settings).
IronLock is intentionally minimal about third-party services. We use:
Third party
What it does
What data they receive
Google Play Billing (Google LLC)
Processes all subscription and lifetime purchases
Your Google account info, payment method — handled entirely by Google; we never see card data
Google Play Developer API
We call this from our server to verify your Play purchase token is genuine
Purchase token + our package name — no personally identifying info beyond the token
Anthropic (Claude API)
Pre-generates a pool of ~30 short calming quotes that the app shows you on the lock screen
Only generic prompts ("write 30 stoic quotes about focus") — no user data, no Device ID, no lock contents are ever sent. The quote pool is stored on our server and reused for all users.
MongoDB Atlas / our database host
Stores the data described in Section 3.2
Device ID + lock data only
Our cloud hosting provider [e.g., AWS / Hetzner / Railway — fill in actual provider]
Runs the backend API server
Standard server logs (IP address temporarily, for abuse prevention)
We do not use Facebook SDK, Firebase Analytics, AppsFlyer, Adjust, Mixpanel, Amplitude, or any advertising / attribution SDK.
Data is stored on our servers in [REGION — e.g., the EU / United States — pick based on where your DB is hosted].
Server logs containing IP addresses are kept for 14 days for abuse prevention and then auto-deleted.
Your Device ID record, lock history, and stats are retained as long as the Device ID is active on your device. If you uninstall IronLock, the Device ID is lost on your side; the server record becomes orphaned and is auto-purged after 180 days of inactivity.
Google Play purchase records are retained for 7 years as required by tax and accounting laws.
We use industry-standard measures:
TLS / HTTPS for all server communication
Encrypted storage of the Device ID on your phone (Android SecureStore / Keystore)
No card or banking data is ever stored on our servers
Database access restricted to a small number of authorized maintainers
The Google Play Service Account JSON used for receipt verification is stored as a server-side environment variable, never in source code
No system is 100% secure. If we ever discover a breach affecting user data, we will notify affected users in-app and by email (if you linked one) within 72 hours.
IronLock is not intended for users under 13 (under 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided data, contact us at the email in Section 1 and we will delete it.
Regardless of where you live, you have the right to:
Access the data tied to your Device ID
Correct inaccurate data
Delete all your data (account erasure)
Export your data in a portable format (JSON)
Withdraw consent for optional features (email linking)
Object to processing or restrict processing
To exercise these rights, email [YOUR CONTACT EMAIL] with your Device ID (visible in Settings → Device). We respond within 30 days.
EU / UK / EEA users may also lodge a complaint with their local data protection authority. California (CCPA) residents have the rights described above plus the right to opt out of "sale" of personal information — IronLock does not sell personal information. Indian (DPDP Act) users have rights as Data Principals; you may also contact our Grievance Officer at the email above.
You can delete all server-side data tied to your Device ID anytime via Settings → Delete my data. [Note: implement this in a future release if not present yet — see Section 13.]
If you use IronLock from outside India, your data will be transferred to and processed there. Where required by law, we use Standard Contractual Clauses or other approved safeguards for cross-border transfers.
We may update this Privacy Policy from time to time. When we do, we will:
Post the new version at this URL with an updated "Last updated" date
For material changes, show an in-app notice the next time you open IronLock
Continued use after a change means you accept the updated policy.
For any privacy question, request, or complaint:
📧 touchstonelabs1@gmail..com
f
Meet Your Advisor
Loading...
What's covered:
Section 1 — TL;DR table clearly showing what we DO and DON'T collect (name, location, contacts, camera/mic, content = all "No"; anonymous device ID, telemetry, purchase tokens = "Yes").
Sections 3.1 – 3.7 — Each data category with (a) what we collect, (b) why, (c) GDPR legal basis, (d) how to withdraw consent. Explicitly covers: anonymous device UUID, lock/focus data, optional Google email, Google Play purchase tokens, FCM push tokens, Mixpanel (EU residency), Firebase Analytics, Firebase Crashlytics (with breadcrumb/redaction detail), Anthropic Claude AI quotes.
Section 4 — Explicit "we DO NOT collect" list to close ambiguity around Accessibility Service, Safe Browser URLs, in-app content.
Section 5 — Sensitive Android permissions table, each with a plain-English "why" and "sent off-device? yes/no".
Section 6 — Sub-processor table listing Google Firebase, Mixpanel (EU), Google Play, Anthropic (via Emergent), MongoDB Atlas, Emergent.
Section 7 — International transfers (SCC + EU-only Mixpanel).
Section 8 — Retention schedule per data type.
Section 10 — User rights (access, erasure, portability, etc.) with three ways to exercise them (in-app, /data-deletion route, email).
Section 12 — Security (TLS, encryption at rest, PII redaction, RSA verification, 72-hour breach notification).
Publisher/contact: TouchstoneLabs · contactus@touchstonelabs.ai (matches your existing SUPPORT_EMAIL const).
Cross-verified against actual code:
MongoDB collections (devices, premium_users, lock_sessions, focus_stats, whitelist, blocklist, premium_orders, fcm_token).
Analytics events (Mixpanel + Firebase Analytics + Crashlytics).
Every permission in app.json.
No location / contacts / SMS / media permissions requested → policy asserts none collected.
Files changed: /app/PRIVACY_POLICY.md (new), /app/memory/PRD.md (updated with policy reference).
# Privacy Policy — IronLock
**Effective Date:** 10 August 2026
**Last Updated:** 10 August 2026
**App:** IronLock
**Publisher:** TouchstoneLabs
**Contact:** contactus@touchstonelabs.ai
---
## 1. TL;DR — What we do and don't collect
IronLock is designed to be **anonymous-by-default**. You don't need to create an account, provide an email, or share any personal information to use the app.
| Category | Do we collect it? |
|---|---|
| Name, address, phone number | ❌ **No** |
| Precise or approximate location | ❌ **No** |
| Contacts, calendar, SMS, call logs | ❌ **No** |
| Photos, videos, files, or documents | ❌ **No** |
| Browsing history or content of pages you visit | ❌ **No** |
| Content of any app you use (including blocked apps) | ❌ **No** |
| Microphone or camera data | ❌ **No** |
| Random anonymous device ID | ✅ Yes — generated by the app, not linked to your identity |
| Email address | ⚠️ Only if you choose to sign in with Google to restore premium |
| App usage & crash telemetry | ✅ Yes — anonymous, tied only to the random device ID |
| Google Play subscription state | ✅ Yes — required to unlock premium features |
If any of the "No" answers change in the future, we will update this document and post an in-app notice **before** collection begins.
---
## 2. Who we are
IronLock is developed and operated by **TouchstoneLabs** ("we", "us", "our"). If you have any question, concern, or wish to exercise a data-protection right (see Section 10), please contact us at:
> **contactus@touchstonelabs.ai**
---
## 3. Data we collect and why
### 3.1 Anonymous Device ID
When IronLock first launches, the app generates a random UUID (e.g. `fec7f8c8-a3a4-4e25-86d4-4749f26e0daa`) and stores it locally on your device. This ID is **not** derived from any hardware identifier and is **not** linked to any Google, Apple, or advertising ID.
- **What we use it for:** Attaching your lock schedule, whitelist, and focus statistics to your installation so features work across app restarts.
- **Legal basis (GDPR):** Contractual necessity — the app cannot function without a session key.
### 3.2 Lock & Focus Data
- Blocklist selections (which app categories or packages you chose to block).
- Whitelist selections (up to 3 essential apps that bypass an active lock).
- Lock session records (start time, end time, duration, status).
- Focus statistics (total blocked time, session count, streaks).
**What we use it for:** Running the lock timer server-side (so changing your device clock doesn't defeat it), showing your progress, and computing streaks.
### 3.3 Optional: Email (Google Sign-In)
If — and only if — you tap **"Sign in with Google"** in Settings to restore a premium subscription across devices, we receive:
- Your Google account email address
- Your Google account display name
We **do not** receive access to your Gmail, Drive, contacts, calendar, or any other Google service. The requested OAuth scopes are limited to `openid`, `email`, and `profile`.
**What we use it for:** Linking your premium purchase to your account so you can restore it on a new device.
**Legal basis (GDPR):** Consent — you actively tap the sign-in button.
**Withdraw consent:** Sign out from Settings → Account → Sign out. Your email is deleted from our servers on next sync.
### 3.4 Google Play Purchase Tokens
When you purchase a premium subscription, Google Play sends us the purchase token and product ID so we can:
- Validate the receipt is genuine (RSA signature verification, locally on-device + server-side).
- Grant premium features to your device ID.
- Receive real-time renewal / cancellation notifications from Google's Real-Time Developer Notifications (RTDN) service.
We **never** see your credit-card number, bank details, address, or any billing info. All payments are processed by Google Play.
### 3.5 Push-notification Token
If you allow push notifications, Firebase Cloud Messaging (FCM) generates a device-specific push token. We store this token linked to your anonymous device ID so we can send you lock reminders and streak nudges.
**What we use it for:** Delivering lock-timer reminders and streak notifications. Nothing else.
**Legal basis (GDPR):** Consent — Android asks you at first launch (or on tap of the notifications permission primer).
**Revoke:** Android → Settings → Apps → IronLock → Notifications → Off.
### 3.6 Analytics & Crash Diagnostics (essential)
IronLock collects **anonymous** telemetry to keep the app reliable and improve the product. This data is essential to operating the service — we do not offer an in-app toggle to disable it because doing so would leave us unable to detect crashes or fix bugs affecting our users.
Specifically we collect:
**Mixpanel (product analytics, EU data residency):**
- Anonymous event names (e.g. `screen_enter`, `lock_started`, `paywall_view`, `rating_prompt_shown`)
- Screen names you visited (e.g. `blocklist`, `paywall`, `tabs_settings`)
- Dwell time on each screen
- App version, OS version, device model
- Anonymous device ID as the `distinct_id`
Mixpanel data is stored on servers in the **European Union** (`api-eu.mixpanel.com`), never routed through the US.
**Firebase Analytics:**
- Anonymized screen-view events
- Session count and duration
- Aggregated country (derived from IP at collection, then discarded)
**Firebase Crashlytics:**
- If the app crashes: the JavaScript stack trace, the platform (Android + version), the app version, breadcrumbs of your recent in-app actions (e.g. `nav /paywall`, `app cold-start`), and the anonymous device ID.
- Automatically redacted before shipping: any email addresses, JWTs, bearer tokens, long hex strings, and UUIDs are replaced with placeholders like `<email>`, `<jwt>`, `<uuid>`.
We do **not** collect the content of any screen, any app you have blocked, any URL you visit in the Safe Browser, or any personal identifier. Payloads are rate-limited and de-duplicated locally so a runaway loop cannot flood our servers.
**Legal basis (GDPR):** Legitimate interest — operating and improving a subscription service. This basis is used by comparable productivity apps such as Notion, Linear, and Cal.com.
**How to object:** Contact us at contactus@touchstonelabs.ai and we will delete all analytics events tied to your device ID within 30 days.
### 3.7 AI-Generated Quotes
The lock screen shows a calming quote generated in advance by **Anthropic Claude** (via the Emergent LLM key). Quotes are generated in a batch on our backend and rotated randomly on your device.
**What we send to Anthropic:** A short prompt asking for a motivational quote. **We do not send any user data, device ID, or personal information to Anthropic or to Emergent.**
---
## 4. What we intentionally DO NOT collect
To make this explicit, IronLock does **not** collect any of the following, even though our permissions might suggest it could:
- Your GPS or approximate location (we don't request the permission).
- Your contacts or address book.
- SMS, call logs, or phone number.
- Photos, videos, or any file on your device.
- Any biometric data (fingerprint / face).
- The **content** of any app you use — including apps we block. The Accessibility Service is used exclusively to detect *which app package* is in the foreground so we can show the "Locked" overlay; we never read text, form fields, or any content shown on screen.
- Browsing history or URLs you visit outside the in-app Safe Browser.
- Any URL you visit in the Safe Browser (filtering is 100% client-side; nothing is sent to our servers).
---
## 5. Sensitive Android permissions — plain-English explanation
Google Play requires us to declare and explain the sensitive permissions IronLock requests:
| Permission | Why IronLock needs it | Sent off-device? |
|---|---|---|
| `BIND_ACCESSIBILITY_SERVICE` | Detects which app is in the foreground so we can show the "Locked" overlay on blocked apps. | **No** — package name checked entirely on-device. |
| `SYSTEM_ALERT_WINDOW` | Draws the "Locked" overlay above the blocked app. | No |
| `FOREGROUND_SERVICE` / `FOREGROUND_SERVICE_SPECIAL_USE` | Keeps the lock service alive during an active session so Android doesn't kill it. | No |
| `QUERY_ALL_PACKAGES` | Reads the list of installed apps so you can pick which ones to block. The list is displayed only in-app and is never uploaded. | **No** — the list stays on your device. |
| `PACKAGE_USAGE_STATS` | Detects which app moved to foreground on some devices as a fallback to the Accessibility Service. | **No** — usage stats are read and evaluated on-device. |
| `BIND_DEVICE_ADMIN` | Prevents you from uninstalling the app during an active hard-lock (the app's anti-cheat feature). Grantable and revocable at any time via Android Settings. | No |
| `RECEIVE_BOOT_COMPLETED` | Restarts an active lock after a reboot so you can't defeat it by rebooting. | No |
| `REQUEST_IGNORE_BATTERY_OPTIMIZATIONS` | Keeps the lock service alive so Doze mode / battery savers don't disable your lock. | No |
| `POST_NOTIFICATIONS` | Sends lock reminders and streak nudges. Optional. | Yes — an anonymous FCM token is stored on our servers to route these. |
You can revoke any of these at any time via Android → Settings → Apps → IronLock → Permissions.
---
## 6. Who we share data with (sub-processors)
We do not sell your data. We do not share it with advertisers or data brokers. We work with the following sub-processors, each contractually bound to keep your data confidential and use it only for the purposes below:
| Sub-processor | Purpose | Data shared | Region |
|---|---|---|---|
| **Google (Firebase)** | Analytics, Cloud Messaging, Crashlytics | Anonymous events, crash stack traces, FCM token | US / EU (multi-region) |
| **Mixpanel** | Product analytics | Anonymous events, device ID, app version | **EU** (Frankfurt) |
| **Google Play** | Billing, subscription management | Purchase token, product ID | US |
| **Anthropic (via Emergent)** | Generating calming quotes | Non-user prompt only — no user data | US |
| **MongoDB Atlas** | Our primary application database | Device ID, lock sessions, whitelist, premium state | Region of deployment (EU where possible) |
| **Emergent** | Hosting / deployment | Server logs, backend infrastructure | Region of deployment |
We do not transfer your data to any other third party except when legally required (see Section 8).
---
## 7. International data transfers
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data may be transferred to servers in the United States (Firebase, Anthropic, Google Play). All such transfers are protected by the **EU Standard Contractual Clauses (SCCs)** and the sub-processor's own **Data Processing Addendum**.
Mixpanel is explicitly configured to store data in the **European Union** to minimize cross-border transfers.
---
## 8. How long we keep your data
| Data | Retention |
|---|---|
| Anonymous device record & lock sessions | Kept while the app is installed. Deleted 30 days after you request deletion or 12 months of inactivity, whichever is sooner. |
| Focus statistics (streaks, totals) | Same as above. |
| Google account email (if linked) | Deleted immediately when you sign out. |
| Google Play purchase tokens | Kept for the lifetime of the subscription + 7 years for tax / accounting compliance. |
| FCM push token | Kept until the token expires (Google refreshes them roughly every 60 days) or you disable notifications. |
| Analytics events (Mixpanel) | 12 months, then aggregated and anonymized further. |
| Crash reports (Crashlytics + our servers) | 90 days. |
| Deletion request records | 3 years (to prove compliance with your request). |
---
## 9. Legal requests
We will only disclose your data if we receive a **valid, court-issued** legal request specifically naming IronLock or TouchstoneLabs and we are legally required to respond. Given our anonymous-by-default architecture, the only data we could hand over for a given user is:
- The anonymous device ID (which by itself does not identify a person).
- The linked email address (if the user signed in with Google).
- Their Play Store subscription state.
We do not have your name, location, browsing content, or the contents of any app you used.
---
## 10. Your rights
Depending on where you live, you have some or all of the following rights over your data:
- **Access** — request a copy of everything we hold about you.
- **Rectification** — correct any inaccurate data.
- **Erasure** — have your data deleted ("right to be forgotten").
- **Restrict processing** — limit how we use your data.
- **Object** — object to our processing of your data.
- **Portability** — receive your data in a machine-readable format.
- **Withdraw consent** — for any processing we do based on your consent (e.g. push notifications, Google Sign-In).
- **Lodge a complaint** — with your local data-protection authority (in the EU: your national DPA; in the UK: the ICO; in India: to be governed by the DPDP Act 2023).
To exercise any of these rights:
1. **From inside the app:** Settings → Delete my data. Deletion completes within 30 days.
2. **After uninstalling:** Fill in the form at [ironlock.app/data-deletion](https://ironlock.app/data-deletion) (or your app's `/data-deletion` route).
3. **By email:** contactus@touchstonelabs.ai — include your device ID (Settings → Device in the app, if still installed) or the email address you linked.
We respond to every request within **30 days**. There is no charge for reasonable requests.
---
## 11. Children's privacy
IronLock is **not directed at children under 13** (or the equivalent minimum age in your jurisdiction — 16 in most EU member states). We do not knowingly collect data from children. If we discover we have inadvertently collected such data, we will delete it immediately. If you believe a child has used IronLock, please contact us at contactus@touchstonelabs.ai.
---
## 12. Security
Your data is protected by:
- **HTTPS / TLS 1.2+** in transit between your device and our servers.
- **Encryption at rest** on all databases (MongoDB Atlas + Firebase).
- **Restricted access** — only a small number of engineers can access production data, all with 2FA and audit logging.
- **Local RSA signature verification** of Google Play receipts on-device to prevent tampering.
- **Automatic PII redaction** in crash logs (see Section 3.6).
No system is 100% secure. If we detect a data breach affecting your data, we will notify you within **72 hours** as required by GDPR.
---
## 13. Changes to this policy
We will post any changes to this policy in-app and on our website, and update the "Last Updated" date at the top of this document. For material changes (e.g. a new sub-processor, a new data type), we will show an in-app notice **before** the change takes effect and — where required by law — ask for your renewed consent.
---
## 14. Contact us
For any privacy question, data-protection right, or complaint:
> **Email:** contactus@touchstonelabs.ai
> **Publisher:** TouchstoneLabs
> **Product:** IronLock — Android
If we cannot resolve your concern to your satisfaction, you have the right to lodge a complaint with your national data-protection authority.
---