Privacy policy
Last updated 26 July 2026.
The short version
OwnHour decides what to block on your phone. What you open, type, search or browse is evaluated on the device, in the moment, and is never stored by us and never sent anywhere. An account is optional; without one, the only things that can leave your phone are a crash report and a message you choose to send us from Send feedback — both only if you start them yourself.
What stays on your phone
- Your rules, schedules, limits, allowlist, protection mode, blocked feed choices, blocked-page redirect, Guardian state, and short-lived Device Admin removal grants.
- Screen-time insights. These are read live from Android's usage statistics and summarised on the device.
- The local record of blocks ("paused pulls"), which you can clear at any time under Settings → Privacy & local data.
- Anything you type into a "report a mistake" note. (Send feedback is the separate, deliberate exception, described below.)
- Your notification preferences.
To apply enabled content rules, OwnHour uses Android Accessibility to inspect visible words and displayed links across foreground apps. Password fields, OwnHour, launchers, safety apps and apps you mark Essential are excluded. Structural identifiers distinguish YouTube Shorts, Instagram Reels and Facebook Reels; while Guardian mode is active, exact OwnHour app-details, uninstall and Device Admin deactivation surfaces are also recognized. These readings exist only in memory for the immediate on-device decision. They are not logged, retained or transmitted. Unknown social-app layouts fail open instead of blocking the whole app.
The optional DNS filter, if you turn it on, resolves domain lookups through a privacy-respecting resolver so that site rules can apply. OwnHour does not keep a record of the domains you look up.
What we hold, and only if you choose it
An account is needed only to buy or restore Pro, or to use partner features that work over the internet.
- Your email address — used to send you a one-tap sign-in link and account notices. There is no password.
- Device registration — an installation identifier, the platform, a public key, and a push token, so protected-change requests can reach the right phone.
- Partner and Guardian links — their email address, public key, relationship role, Guardian attestation time, approval requests, recovery events and protection capability health. They never receive screen text, URLs, keywords, detected feed content, app usage or messages.
- Purchases — Google Play tells us that a purchase is valid; we keep a one-way hash of the purchase token and which product it was, so your Pro access can be restored.
We do not collect usage analytics, advertising identifiers, contacts, location, or the contents of your screen, and there is no third-party tracking or advertising in the app. The one thing you can choose to send us is a crash report, described next.
Separately, OwnHour asks Google Play whether a newer version exists when you open the app and when you return to it, so it can offer you the update. That check tells Google your device details and which version of OwnHour you are running — the same things the Play Store already knows because it installed the app. It sends nothing about your rules, your usage or your partner, it is not used for advertising, and it reaches Google rather than us.
Crash reports, if you turn them on
Crash reports are off by default. While they are off, the reporting software is not started at all — nothing is collected, buffered or queued. Setting up OwnHour offers you the choice, and you can change it at any time under Settings → Privacy & local data. Skipping the question during setup leaves reporting off. Turning it on begins reporting the next time you open OwnHour; turning it off again stops reporting immediately.
A report contains the technical detail of the failure and nothing about you:
- Where in the code OwnHour failed, and the error type.
- Your device model, Android version, and the OwnHour version.
It never contains a web address you visited, a keyword you chose to block, an app name, your email address, or anything you typed. Reports are stripped of addresses and anything resembling a sign-in token before they are sent, and on the parts of OwnHour that handle domain lookups the error text is removed entirely, leaving only the location in the code.
Separately, and whether or not you turn on app crash reports, errors that happen on our own servers — a sign-in email that fails to send, for example — are recorded so we can fix them. Those records are stripped of email addresses and sign-in tokens in the same way. This is server diagnostics, not tracking: nothing about what you open or browse ever reaches our servers to begin with.
Feedback you choose to send
Settings → Help & feedback → Send feedback is the one place in OwnHour where something you wrote leaves the phone, and it only ever happens because you tapped Send. There are no prompts, no "enjoying OwnHour?" popups, and nothing is sent in the background.
Before it goes, the app shows you the whole message. It contains:
- Your note, and whether you marked it an idea, a problem or praise.
- A reply address, only if you typed one. It is never filled in from your account.
- Unless you switch them off — one tap, on the same screen — six diagnostic lines: app version and build, your Android version and device model, whether protection is healthy and how many capabilities are granted, which change guard is active, and your language.
-
A reference id such as
FB-2K4M9. It is generated fresh for each message, not for your phone, so two messages cannot be linked to each other. No device or advertising identifier is attached.
Never included: browsing history, your rules, app usage, partner identity, your email.
Feedback is not linked to your account, even when you are signed in. That is deliberate, and it has a consequence worth stating plainly: because there is nothing tying a message to you, deleting your account does not delete it. Quote the reference id and we will — that is what it is for, and why the app lets you copy it.
If your phone is offline the message waits in OwnHour's encrypted database and sends the next time you open the app with a connection. Nothing is retried in the background.
Who else is involved
- Google Play handles payment; we never see your card details.
- Firebase Cloud Messaging delivers a contentless wake-up to your phone so it can fetch a partner's answer. The message carries an event code and an identifier — never any content.
- Resend delivers sign-in links and partner invitations by email.
- Google Sheets holds a copy of each feedback message in a private spreadsheet we use to read and sort them. It carries the note, the kind, whatever diagnostics you allowed and the reference id — never your reply address.
- Sentry receives error reports. From the app, only if you turn crash reports on; from our own servers, always. See the section above for exactly what a report contains.
Each of them acts on our instructions and may only use what we send for the job we send it for. None of them is allowed to use it for their own purposes, and none of them receives anything about what you open, browse, search or type — that never leaves your phone in the first place.
Where your data is handled
Those four services come from three United States companies, so the little we hold — your email address, device registration, partner links, purchase records — is processed outside the UK and the European Economic Area.
All three are certified under the EU–US Data Privacy Framework and its UK Extension, which is what makes those transfers lawful: Google LLC (Play and Firebase Cloud Messaging), Functional Software, Inc. (Sentry), and Resend, Inc., whose agreement with us also carries the European Commission's Standard Contractual Clauses. You can look any of them up on the public Data Privacy Framework list.
How we protect it
On your phone, which is where nearly everything lives:
- Your rules, insights and block history are kept in an encrypted database. The key is generated on the device and held in Android's own protected key storage, not in a file the app can hand over.
- The enforcement snapshot the blocker reads is encrypted with a separate key of its own.
On our side, for the parts of an account that have to exist:
- There is no password to steal, because there are no passwords. Sign-in links and partner invitations are 256-bit random tokens, and we store only a one-way hash of each one — a copy of our database could not be used to sign in as you.
- Purchase tokens are stored the same way, as a hash and never in the clear.
- A partner's decision is signed with an ECDSA P-256 key and verified on your phone, so an answer cannot be altered on its way to you.
- Traffic between the app and our servers is encrypted in transit.
- Card details never reach us at all — Google Play handles payment.
No system is beyond compromise, and we would rather say so than imply otherwise. If a breach ever affects your data and is likely to put you at risk, we will tell you and the relevant regulator, without waiting to be asked.
How long we keep it
On your phone, insights are pruned on the schedule you choose under Privacy & local data, and "Delete local data & reset protection" in Settings removes everything OwnHour keeps there.
On our side, nothing is kept indefinitely for want of anyone deleting it. A job runs continuously and clears each of these on its own clock:
| What | How long |
|---|---|
| Sign-in links | Valid 15 minutes, then deleted |
| Emails and notifications waiting to be sent | 7 days from being queued, whether or not delivery succeeded |
| Protected-change requests, including any note you typed with one | 30 days after the request expires |
| Feedback you sent us, and any reply address with it | 180 days. The spreadsheet copy carries no reply address. |
| A disconnected partner's email and key | Erased 30 days after disconnection |
| Security events recorded against a device | 90 days |
| Your email address, devices, partner links and purchase records | Kept while the account exists — they are what the account is |
So the only thing that lasts is the account itself, and that lasts exactly as long as you want it to. Delete it and all of the above goes with it. Where your protection mode guards destructive changes, that guard applies to deleting an account too — but it never blocks the request: you can always ask us by email instead, and that route is never guarded.
Your rights
Data protection law gives you rights over the information we hold about you. They apply whatever country you are in — we are not going to check where you live before honouring them.
- See it. Ask for a copy of everything we hold about you.
- Correct it. Have anything wrong put right.
- Delete it. In the app, or by email — see the deletion page.
- Take it with you. Get it in a portable, machine-readable form.
- Limit it. Ask us to pause what we do with it while a question is open.
- Object. Tell us to stop relying on our legitimate interests — the only thing we use them for is keeping our own servers working and secure.
- Change your mind. Withdraw a consent at any time — crash reports go off with the same switch that turned them on, and turning them off stops reporting immediately.
Email admin@ownhour.app and we will answer within one month. There is no charge, and you never have to explain why.
If you think we have got it wrong, you can complain to a data protection regulator. In the UK that is the Information Commissioner's Office; in the EEA it is the supervisory authority where you live or work. We would rather you told us first so we can fix it, but that is your choice, not a requirement.
Children and young people
There is no age limit on the app itself. OwnHour works fully without an account, and without one nothing personal leaves the phone — so a young person can install it, pause whatever is pulling at them, and we hold nothing about them at all. Wanting your hours back is not something we think you should have to be eighteen to act on.
An account is different, and it is for adults. It forms an agreement with us, it is how Pro is bought, and it is the only point at which we hold your email address. You need to be 18 to have one. Everything the app does on the phone works without it.
We don't knowingly keep account data for anyone under 18. If you believe a young person has created one, tell us at admin@ownhour.app and we will delete it — no account holder has to be involved and no guard applies.
Supervised setup — an adult managing protection on a young person's phone — is not available yet. When it ships it will require the young person's informed consent on their own device. It will never be something that can be put on someone's phone quietly.