Digital Control

Privacy policy

Digital Control is a screen-time blocker, so it necessarily sees which apps you open. This page says exactly what it reads, what stays on your phone, the one thing that can leave it, and how to erase everything.

Applies to the Digital Control Android app (com.digitaldetox.appblock.app) · Last updated 21 August 2026

1. The short version

  • No advertising SDK and no analytics SDK are built into the app. There is no tracking to opt out of, and no advertising identifier is read.
  • Nothing you do in the app is sent to us. We operate no server that receives your screen-time data, and there is no account to create in order to use it.
  • Your rules, statistics, and settings live in the app's own storage on the device and are erased when you uninstall it.
  • One optional feature sends data off the device: if you switch on network-level site blocking, website names you have not blocked are passed to the DNS server your own network already provides — see section 4. Not to us.
  • Everything sensitive is opt-in, explained in plain language inside the app before Android asks, and the app keeps working with any of it declined.

2. Who we are

Digital Control is published by M Mubashir Abbas, established in Pakistan. For anything in this policy, write to sourcecode777@gmail.com. We are the data controller for the limited processing described in section 4; everything in section 3 happens on your device, where you are the only party with access.

3. What stays on your phone

All of the following is read, used and stored only on your device. None of it is transmitted, and none of it reaches us.

WhatWhyHow long
The name of the app in the foreground To notice the moment a blocked app opens, so the block screen can appear Compared against your rules in memory, then discarded — never written down
The web address shown in your browser Only while a website or in-app content rule is switched on, to tell a blocked page from an allowed one Compared in memory, then discarded
Names of on-screen elements in an app you are using Only while a content rule is on, to tell a short-video feed or a comment thread from the rest of the app Compared in memory, then discarded
Screen-time figures Statistics, the wellbeing score, daily usage limits Read from Android's own usage statistics each time a screen opens; the app keeps daily totals in its own storage
Your rules and settings Profiles, schedules, places, networks, limits, blocked apps and sites, badges, streaks In the app's storage until you change or uninstall
Your last known position Only if you create a place rule — so the rule still works after a restart One coordinate pair in the app's own storage, overwritten by the next reading
The connected Wi-Fi network's name Only if you create a Wi-Fi rule Compared against your rules; the current name is held while the rule is active
Your App lock PIN To stand in front of your own settings, so rules cannot be switched off on impulse The PIN itself is never stored. The app keeps a random salt and a PBKDF2 hash derived from it, which cannot be turned back into your PIN
Which notifications arrived, by sending app Only if you switch on Silence — to hold back notifications from apps that are blocked right now Only the sending app's name is examined, and only in the moment. Notification titles and text are not read, stored or sent

Android's own backup service copies your rules and Deep-focus settings if you have device backup switched on, so a new phone starts where the old one left off. That copy is limited by the app to those two files: your App lock PIN hash, your consent choices, and the network-blocking switch are deliberately excluded, so nothing sensitive travels between devices and no consent is ever restored on your behalf.

4. What can leave your phone

4.1 Network-level site blocking (off unless you switch it on)

This optional feature blocks a site everywhere on the phone rather than only in browsers the app can read. Android provides one way to do that, and it requires the VPN permission — which is why the system shows you a VPN consent dialog.

What it actually does. The app creates a connection that exists entirely on your device. It has no remote server: there is no endpoint of ours anywhere, and none of your traffic is routed to us or to any third party we chose.

What it sees. Only the names of sites your phone looks up — example.com — and nothing else. Not the pages you read, not what you do on them, not anything you type, and no other traffic of any kind. Only name lookups are routed into it; everything else on your phone bypasses it completely.

What happens to each name. It is checked against your own block list on the device. A name you have blocked is refused on the spot, locally, and never leaves. A name you have not blocked is passed on to the same DNS server your network already gave your phone — your mobile operator's, or your Wi-Fi router's — exactly as it would have been if this app were not installed. We do not choose that server, we do not change it, and we never substitute one of our own.

What is kept. Nothing. No lookup is written to storage or sent to us in any form. The app keeps only running counts for the duration of the session — how many lookups were seen and how many were blocked — and those are forgotten when it stops.

Switching this feature off, or uninstalling the app, ends it immediately. Android only permits one VPN at a time, so turning it on disconnects any other VPN you use, and connecting another later switches this off.

4.2 Support partner — not active in this version

A future version will let you invite someone you trust to grant a small daily allowance of blocked-app time. That feature is switched off in the current release and sends nothing. When it ships it will, and only after you sign in and send an invitation, store the following with Google Firebase (Firestore and Firebase Authentication) so the two devices can agree: your email address and your partner's, the account identifiers Google issues, the allowance settings you choose, and the time an invitation was made. It will never carry your screen-time figures, your rules, your location, or anything the accessibility service reads. This policy will be updated before that feature is enabled.

4.3 Google Play and your device maker

Installing from Google Play, and Android itself, involve Google under their own privacy policies rather than this one. We receive no personal data from Google Play — only aggregate, non-identifying installation and crash counts that Play shows every developer, which we cannot connect to any individual.

5. What we never do

Show adsNo advertising SDK is in the app
Analytics or usage trackingNo analytics SDK is in the app; this is deliberate and recorded in the source
Sell or share your dataNever, to anyone, for any purpose
Read your messages, photos, contacts, camera or microphoneThe app requests none of those permissions
Read notification contentsOnly the sending app's name, only while Silence is on
Track your location in the backgroundNo background-location permission is requested at all
Send your browsing history anywhereNo history is compiled; see section 4.1 for what the DNS feature does and does not do
Require an accountEvery feature in this version works without signing in

6. Permissions, one by one

Android grants each of these separately, and the app is built so that declining any optional one costs you that feature and nothing else. The complete list is on the features page, with what each is for and what happens if you say no.

Three of them are sensitive enough that the app shows you its own plain-language explanation before Android's dialog appears, with equally weighted Agree and No thanks buttons, and records nothing if you decline: the accessibility service, notification access, and network-level site blocking. Declining any of them leaves the rest of the app working.

7. Keeping and deleting

8. Security

Because almost nothing leaves the device, the main protection is that there is no central store to breach. On the device: app data sits in Android's private per-app storage; the App lock PIN is kept only as a salted PBKDF2 hash; the backup copy is restricted to your rules and excludes the PIN hash, consent flags and the network-blocking switch. No method of storage or transmission is perfectly secure, and we do not claim otherwise.

9. Children

Digital Control is a self-control tool for general audiences and is not directed at children under 13. We do not knowingly collect personal data from children. If a parent or guardian believes a child has provided personal data, write to sourcecode777@gmail.com and it will be deleted.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, delete or restrict the use of your personal data, and to object to its processing. For nearly everything this app handles those rights are already in your hands: the data is on your device, and uninstalling erases it. For the limited processing in section 4 — currently nothing, until the support-partner feature is enabled — contact sourcecode777@gmail.com and we will respond within one month. You may also complain to your local data-protection authority. This policy is governed by the law of Pakistan.

11. Changes

If the app's data handling changes, this page changes with it, and the date at the top changes too. A change that widens what is collected will be announced inside the app before it takes effect, not quietly published here.

12. Contact

M Mubashir Abbas · sourcecode777@gmail.com · Pakistan
Questions about this policy, requests about your data, and security reports are all welcome at that address.