Privacy Policy for AppLock
Last updated: [FILL IN DATE]
AppLock ("the app") is developed by [YOUR NAME / DEVELOPER NAME] ("we", "us").
This policy explains what the app does with your information. In short:
everything stays on your device — we do not collect, transmit, sell,
or share any of your data with anyone, including us. The app makes
no network requests of any kind.
What the app stores, and where
All data below is stored locally on your device only, using Android's
EncryptedSharedPreferences/EncryptedFile (AES-256) or standard app-private
storage. None of it is ever transmitted off your device, to us or to any
third party.
- Your PIN, pattern, or knock code — stored only as a
salted cryptographic hash. The actual credential is never stored or
recoverable, including by us.
- Your recovery code — stored as a salted hash, the same
way your PIN/pattern is.
- Your list of locked apps and per-app notification
privacy choices — package names only, stored locally.
- Photos and videos you choose to hide in the Hidden Vault
— encrypted on-device (AES-256-GCM) using Android's Jetpack Security
library. Only photos/videos you explicitly pick are affected; the app does
not scan or access your photo library beyond what you select. If you turn
on the optional "auto-hide new photos from a folder" feature, you choose
that folder yourself via Android's system file picker, and only that one
folder is watched.
- Intruder Log photos — optional feature; front-camera
photos taken after a failed unlock attempt are stored encrypted, locally
only.
- Files you create with the Tools (a generated QR code
image, a PDF you built from photos, a compressed photo) — saved either to
your own device gallery/files or wherever you choose via the system save
picker. Nothing is uploaded anywhere.
- App settings and usage-based stats shown to you —
auto-lock delay, feature toggles, your security-streak count, and the
screen-time figures shown in the Tools tab (computed from Android's own
Usage Access API, described below) — all stored locally, only ever
displayed back to you inside the app.
Permissions the app uses, and why
- Usage Access — lets the app detect which app is
currently in the foreground, so it knows when to show the lock screen for
an app you've protected. It's also used to power the optional Screen Time
and Weekly Recap tools, which show you your own on-device usage stats. The
app does not transmit your usage history anywhere.
- Display over other apps — needed to show the lock
screen on top of a protected app.
- Camera — used in two optional, user-initiated places:
(1) the Intruder Log feature, which takes a front-camera photo after a
failed unlock attempt, stored encrypted on-device; and (2) the QR Scanner
tool, which reads a QR/barcode live using on-device recognition — no camera
frames or images are ever saved, uploaded, or leave the device for this
feature.
- Microphone — used only by the optional Voice
Calculator tool, to let you speak calculations instead of typing them.
Audio is processed by Android's on-device speech recognition while that
screen is open and is never recorded to a file, stored, or transmitted
anywhere. The microphone is only active while the Voice Calculator screen
is open on-screen, and stops the instant you leave it. (Separately, the
Voice Lock feature does not use this permission at all — it delegates
entirely to a system voice-input app and never touches the microphone
itself.)
- Notification Access — optional, per-app feature. If
you enable it for a specific app, AppLock replaces that app's notification
text with a generic placeholder so previews don't leak content on your lock
screen or status bar. AppLock does not read, store, or transmit the
content of your notifications anywhere — it only checks which app a
notification came from, and (if you enabled the feature for that app)
replaces the visible text on-device.
- Biometric authentication — used only to unlock the
app or a protected app, via Android's own BiometricPrompt system API. Your
fingerprint/face data never leaves Android's secure hardware and is never
seen by AppLock or us.
- Notifications (POST_NOTIFICATIONS) — used to show the
"protection active" status notification (with a "Lock now" quick action),
and to post sanitized notification replacements for the feature described
above.
- Vibration — used only for the optional break-in alarm,
which vibrates (alongside an audible alarm) after repeated failed unlock
attempts.
- Battery optimization exemption — optional, user-
initiated. Lets the app keep running reliably in the background to detect
app switches. You can decline or revoke this at any time in system
Settings.
Files, photos, and documents you pick for the Tools
The QR Generator, PDF Toolkit, Photo Compressor, and Duplicate Finder tools
only ever work with files you explicitly choose through Android's own system
file/photo picker (or a folder you pick, for Duplicate Finder). AppLock never
has standing access to your photo library or file system — each tool only
sees the specific files you select in that moment, processes them entirely
on-device, and saves the result back to your device or wherever you choose.
Sharing a generated file (e.g. tapping "Share" on a QR code) uses Android's
standard share sheet and only goes to whichever app you pick — AppLock itself
never sends it anywhere.
Data we do NOT do
- No analytics, crash reporting, or advertising SDKs.
- No account creation, no sign-in, no network requests of any kind.
- No data is sold, shared, or transmitted to any third party.
- No standing access to your photo library, contacts, or files beyond
what you explicitly pick each time.
Children's privacy
AppLock does not knowingly collect any information from anyone, including children, because it does not collect information at all.
Changes to this policy
If this policy changes, the updated version will be posted at this same URL with a new "Last updated" date.
Contact
Questions about this policy: sahaniavtar1@gmail.com