Privacy Policy: blockit
App: blockit (on Google Play: "blockit: break phone addiction")
Data Controller / Developer: Francesco Sgnaolin, VAT no. (P.IVA) 01777090331, via Manfredi 58, 29121 Piacenza, Italy
Contact: francesco.sgnaolin+BLOCKIT@gmail.com
Version: 2.2. Last updated: July 17, 2026
This Privacy Policy, provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), explains what information the blockit application ("blockit", "the App", "we") processes, how, and why. blockit is available on Android only, through Google Play.
To download the App, make purchases, or leave reviews you use services provided by Google (Google Ireland Limited for users in the European Economic Area and Switzerland; Google LLC otherwise): for those activities Google acts as an independent data controller and Google's Privacy Policy applies.
1. Summary
blockit is designed to work with the minimum amount of data possible. If you never sign in, no personal data leaves your device. The App shows no advertising, contains no advertising SDKs, and does not use analytics or profiling for marketing.
Note on previous versions: up to version 1.x the App displayed advertising, and the previous policy described the related cookies and tracking technologies. As of version 2.0 advertising has been completely removed: those sections no longer apply. The App uses no cookies or advertising tracking technologies.
2. Data we process
On your device only (never transmitted):
Your focus sessions (date and duration), settings, and parachute (token) count are stored locally on the device. The Developer has no access to them.
During a block, blockit checks which app is in the foreground to enforce the block. This check happens entirely on your device, in real time, and is never stored or transmitted.
Only if you sign in with your Google account (optional):
Your account identifier / email (provided by Google Sign-In) is used to associate the cloud backup with you.
Your session data (date and duration) and parachute count are saved to Google Firebase so they can be restored (e.g. if you change device).
We do not collect contacts, messages, photos, precise location, or the content of any screen.
Play Store reviews: if you leave a review, Google may share the review content and username with the Developer. We use this information only to reply and to improve the App. The Developer and Google act as independent controllers, under the Google Play Data Controller Terms.
3. Legal bases for processing
Cloud backup and account features (optional data under §2): performance of the service you requested (Art. 6.1.b GDPR).
Replying to reviews and improving the App: the Developer's legitimate interest (Art. 6.1.f GDPR).
Compliance with legal obligations or requests from public authorities: legal obligation (Art. 6.1.c GDPR).
Defending the Developer's rights, in and out of court: legitimate interest (Art. 6.1.f GDPR), always balanced against your rights.
4. Third-party services
blockit relies on the following Google services:
Google Sign-In: optional authentication.
Google Firebase (Realtime Database): optional backup of sessions and parachutes.
Google Play Billing: for in-app purchases.
Google Play Integrity (App Check): to protect the backend from abuse.
These services are governed by Google's privacy policy. blockit integrates no third-party advertising, marketing, or analytics SDKs.
5. In-app purchases
blockit offers:
Parachutes (consumables): tokens that let you end a block early.
Premium (one-time purchase): unlocks sessions longer than 3 hours and automatic routines.
Purchases are handled entirely by Google Play: your payment data is processed exclusively by Google as an independent controller. The Developer receives the payments through Google without any access to your payment details, and only receives information from Google in anonymous, aggregate form.
6. Permissions and why we use them
Notifications: to alert you that a block is active and how much time is left.
Accessibility Service ("blockit · Session block"): used only to keep you on the block screen when you open a non-allowed app during a block, so you can't use other apps until it ends. The service does not read, retrieve, or collect screen content (`canRetrieveWindowContent` is disabled).
Device admin (where applicable): used only to lock the device during a block. You can revoke it at any time in system settings.
Usage access: to detect which app is in the foreground during a block, on-device only (see §2).
Ignore battery optimization: so the system doesn't interrupt an ongoing block.
Exact alarms: to start scheduled blocks (routines) at the time you choose.
7. How your data is protected
Backup data is encrypted in transit (HTTPS/TLS) and encrypted at rest on Google Firebase infrastructure. Access is restricted by security rules so that each user can read and write their own data only. App Check (Play Integrity) is enabled to block unauthorized clients. The Developer adopts appropriate technical and organizational measures to reduce the risk of loss, unlawful use, or unauthorized access.
8. Where data is processed (transfers outside the EU)
Backup, download, purchase, and review services are provided through Google: data may therefore also be processed on servers located in the United States. In such cases the transfer takes place in compliance with the EU-U.S. Data Privacy Framework (European Commission adequacy decision of July 10, 2023) or on the basis of the appropriate safeguards provided by Art. 46 GDPR (including standard contractual clauses and binding corporate rules).
9. Data retention and deletion
Local data stays on your device until you clear the App's data or uninstall it.
Backup data stays on Firebase until you delete your account: you can delete your account and all associated stored data directly from the App (Settings → account → delete account). Deletion is permanent.
Only where necessary to defend the Developer's rights, relevant data may be kept for up to 10 years; at the end of the retention period, data is deleted or irreversibly anonymized.
10. Your rights (Arts. 15-22 GDPR)
You have the right to request, at any time:
access to your data and a copy of it;
rectification of inaccurate or incomplete data;
erasure ("right to be forgotten") of data held without legal grounds;
restriction of processing;
objection to processing based on legitimate interest;
portability of your data in a structured, commonly used, machine-readable format;
withdrawal of any consent given, without affecting the lawfulness of prior processing.
To exercise them, write to francesco.sgnaolin+BLOCKIT@gmail.com: a reply is guaranteed within 30 days. If you believe the processing violates the GDPR, you can lodge a complaint with the Italian Data Protection Authority (Garante) or bring proceedings before the competent courts (Arts. 78-79 GDPR).
11. Children
blockit is not directed at children under 13, and we do not knowingly collect data from them.
12. Changes to this policy
This policy may change over time (as the App evolves, or due to legal or technological developments). The current version and its date are always shown at the top of this page: please check back periodically.
13. Data Controller's contacts
by mail: Francesco Sgnaolin, via Manfredi 58, 29121 Piacenza, Italy
by e-mail: francesco.sgnaolin+BLOCKIT@gmail.com