IronLock ("we", "us", "our", or "the app") is a digital-discipline Android application that hard-locks selected apps and websites for a duration you choose. This Privacy Policy explains what data IronLock collects, how it is used, and the rights you have over it.
By installing or using IronLock you agree to this Privacy Policy. If you do not agree, please do not use the app.
IronLock is operated by:
Touchstone Labs Contact:touchstonelabs1@gmail.com
For privacy questions, write to the email above.
We do not require an email, phone number, or social login to use IronLock.
We assign your installation a random anonymous Device ID (a UUID). That is the only identifier we store about you.
We store your lock state, whitelist, blocklist, and focus statistics on our server, keyed to that Device ID. This is what makes the "Nuclear" timer tamper-proof against clock changes.
We do not track your browsing, your messages, the contents of any app, or your location.
The Accessibility Service is used only to detect which app is open (its package name) so we can show the lock overlay. It does not read your screen contents, key presses, or messages.
The local VPN is local-only — it never sends your traffic to our servers. It only resolves DNS queries and blocks ones that match the blocklist.
All payments go through Google Play Billing. We never see your card number.
You can delete your data at any time — see Section 11.
Data
When
Purpose
Required?
Email address
Only if you choose Link Email in Settings to enable cross-device premium restore
Recover premium on a new device
Optional
Whitelist / Blocklist preferences
When you customize them in-app
To enforce locks correctly
Yes (functional)
Lock duration and categories you choose
When you start a Nuclear lock
To enforce the lock for the duration you committed to
Yes (functional)
Data
Purpose
Stored?
Anonymous Device ID (UUID v4 generated on device, stored in Android SecureStore)
Identifies your installation across sessions; required for server-synced timer
Yes — until you delete the app or request deletion
App lifecycle events required by the Accessibility Service (foreground package name only)
To trigger the lock overlay when a blocked app opens
Processed in-memory on your device only; not transmitted to our servers
DNS queries inside the local VPN
To match against the blocklist and sinkhole adult/gambling domains
Processed in-memory on your device only; never transmitted to our servers or to any third party
Lock start / end / extend timestamps
Server-synced anti-cheat timer
Yes
Focus statistics (total time saved, sessions completed, longest session)
Display on your dashboard
Yes
Server time
Authoritative reference for the timer (we ignore your device clock for anti-cheat)
N/A — generated server-side
Google Play purchase token + product ID
Verify a subscription / lifetime purchase via Play Developer API
Yes
Crash and basic diagnostic data (if enabled by Android OS / Google Play)
Improve stability
Aggregated, anonymous
❌ Names, phone numbers, real-world location, contacts, photos, microphone, camera input
❌ The text of any messages, search queries, web pages, or app contents
❌ Keystrokes or anything you type in any app
❌ A list of apps installed on your device beyond those you explicitly add to your whitelist or blocklist
❌ Credit card / banking information (handled entirely by Google Play)
❌ Browsing history (the VPN only inspects DNS queries in-memory)
❌ Advertising identifiers — IronLock contains no third-party advertising SDKs
IronLock requests several powerful Android permissions. Each is justified below in compliance with Google Play's Permissions and APIs that Access Sensitive Information policy.
Purpose: Detect which app the user has brought to the foreground so we can show the lock overlay over blocked apps and selected Android Settings sub-screens (App info, Uninstall, Storage, Accessibility Services).
Data accessed: Foreground app's package name, and — only inside the Settings app — visible UI text/contentDescription on screen, used solely to detect navigation toward sensitive sub-screens. No screen content is logged, stored, or transmitted.
Off-device transmission: None. All Accessibility data is processed locally and discarded immediately.
Purpose: Block adult and gambling domains across every browser (Chrome, Brave, Incognito, etc.) by intercepting DNS queries locally.
How it works: IronLock starts an on-device VPN that loops back to itself. It is not a remote VPN. Your internet traffic is not routed through any external server — not ours, not anyone's. Only DNS queries (UDP port 53) are inspected, and only the queried domain name is examined. Non-blocked traffic flows through unmodified.
Off-device transmission: None.
Purpose: Prevent IronLock from being uninstalled while a Nuclear lock is active. When the lock expires, you can disable Admin and uninstall freely.
What we do NOT do with Device Admin: We do not wipe data, lock the device, change passwords, monitor camera, or use any other Device Admin capability beyond uninstall protection.
Purpose: Draw the calming lock-screen overlay on top of a blocked app.
No other use.
Purpose: Keep IronLock running so the lock cannot be silently killed by aggressive battery savers.
A persistent notification will be shown while a lock is active, as required by Android.
Purpose: Let you pick apps to whitelist or block from a list of installed apps.
The list of installed packages stays on your device. We do not transmit it.
Purpose: Re-arm an active Nuclear lock if you restart your phone mid-lock (anti-cheat).
We use the data described above to:
Enforce the locks you configure (foreground blocking + DNS sinkhole)
Compute the server-synced timer so changing your device clock does not bypass a lock
Track your focus statistics so you can see what you've earned
Process subscription and lifetime purchases through Google Play Billing
Verify Google Play receipts to grant premium features
Generate calming quotes for the lock screen (see Section 7)
Respond to support requests you send us
We do NOT:
Sell your data to anyone
Share your data with advertisers
Use your data to build behavioral profiles
Use your data for any purpose unrelated to running IronLock
We process personal data on the following legal bases:
Performance of a contract — to provide the IronLock service you installed.
Legitimate interests — fraud prevention on premium purchases, anti-cheat on the Nuclear timer, basic stability diagnostics.
Consent — for the optional email account linking (you can withdraw at any time by deleting the link in Settings).
IronLock is intentionally minimal about third-party services. We use:
Third party
What it does
What data they receive
Google Play Billing (Google LLC)
Processes all subscription and lifetime purchases
Your Google account info, payment method — handled entirely by Google; we never see card data
Google Play Developer API
We call this from our server to verify your Play purchase token is genuine
Purchase token + our package name — no personally identifying info beyond the token
Anthropic (Claude API)
Pre-generates a pool of ~30 short calming quotes that the app shows you on the lock screen
Only generic prompts ("write 30 stoic quotes about focus") — no user data, no Device ID, no lock contents are ever sent. The quote pool is stored on our server and reused for all users.
MongoDB Atlas / our database host
Stores the data described in Section 3.2
Device ID + lock data only
Our cloud hosting provider [e.g., AWS / Hetzner / Railway — fill in actual provider]
Runs the backend API server
Standard server logs (IP address temporarily, for abuse prevention)
We do not use Facebook SDK, Firebase Analytics, AppsFlyer, Adjust, Mixpanel, Amplitude, or any advertising / attribution SDK.
Data is stored on our servers in [REGION — e.g., the EU / United States — pick based on where your DB is hosted].
Server logs containing IP addresses are kept for 14 days for abuse prevention and then auto-deleted.
Your Device ID record, lock history, and stats are retained as long as the Device ID is active on your device. If you uninstall IronLock, the Device ID is lost on your side; the server record becomes orphaned and is auto-purged after 180 days of inactivity.
Google Play purchase records are retained for 7 years as required by tax and accounting laws.
We use industry-standard measures:
TLS / HTTPS for all server communication
Encrypted storage of the Device ID on your phone (Android SecureStore / Keystore)
No card or banking data is ever stored on our servers
Database access restricted to a small number of authorized maintainers
The Google Play Service Account JSON used for receipt verification is stored as a server-side environment variable, never in source code
No system is 100% secure. If we ever discover a breach affecting user data, we will notify affected users in-app and by email (if you linked one) within 72 hours.
IronLock is not intended for users under 13 (under 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided data, contact us at the email in Section 1 and we will delete it.
Regardless of where you live, you have the right to:
Access the data tied to your Device ID
Correct inaccurate data
Delete all your data (account erasure)
Export your data in a portable format (JSON)
Withdraw consent for optional features (email linking)
Object to processing or restrict processing
To exercise these rights, email [YOUR CONTACT EMAIL] with your Device ID (visible in Settings → Device). We respond within 30 days.
EU / UK / EEA users may also lodge a complaint with their local data protection authority. California (CCPA) residents have the rights described above plus the right to opt out of "sale" of personal information — IronLock does not sell personal information. Indian (DPDP Act) users have rights as Data Principals; you may also contact our Grievance Officer at the email above.
You can delete all server-side data tied to your Device ID anytime via Settings → Delete my data. [Note: implement this in a future release if not present yet — see Section 13.]
If you use IronLock from outside India, your data will be transferred to and processed there. Where required by law, we use Standard Contractual Clauses or other approved safeguards for cross-border transfers.
We may update this Privacy Policy from time to time. When we do, we will:
Post the new version at this URL with an updated "Last updated" date
For material changes, show an in-app notice the next time you open IronLock
Continued use after a change means you accept the updated policy.
For any privacy question, request, or complaint:
📧 touchstonelabs1@gmail..com