Welcome to MindLock ("the App", "we", "our", "us"). MindLock is a digital wellness application developed and operated by Ganesh Rathor, an individual operating from Ward No. 23, Gram Panchayat Dal Dabra Kalan, Athva, Neemuch, Madhya Pradesh — 458226, India.
This Privacy Policy explains how MindLock collects, uses, stores, protects, and handles your personal information when you use our App. By downloading, installing, or using MindLock, you agree to the practices described in this Privacy Policy.
If you do not agree with any part of this Privacy Policy, please do not use the App.
Account Information
When you create a MindLock account, we collect:
We do not collect your name, phone number, or any other personal identifier unless you voluntarily provide it in support communications.
Support Communications
If you contact us at supportmindlock@gmail.com, we receive your email address and the content of your message. We use this solely to respond to your inquiry.
MindLock automatically collects the following data points to power its core features:
App Usage Data (Stored Locally on Your Device)
MindLock collects the following data to provide its core features. The majority of this data is stored only on your device in a local database and is never transmitted to our servers:
| Data Type | What It Is | Why We Collect It |
|---|---|---|
| Blocked app sessions | Which apps you opened and when you opened them | To enforce focus sessions and show you your usage patterns |
| Intent statements | The purpose you typed when opening a blocked app | To track intentional vs impulsive phone use |
| Focus session records | When you started focus sessions, how long they lasted, whether completed | To show your focus history and calculate XP rewards |
| Challenge records | Which challenges you started and completed | To award XP and track streaks |
| Doom scroll sessions | How long you scrolled in short-video sections, scroll count | To detect and interrupt doom scrolling |
| Block schedule data | The schedules you created for blocking apps | To enforce scheduled blocking |
| Content filter logs | Domain names of blocked adult websites (not page content) | To show you your content protection stats |
| Strict mode events | When strict mode was activated and for how long | To enforce strict mode settings |
| Brain health scores | Daily scores calculated from your usage patterns | To display brain health visualization |
App Usage Statistics (via Android UsageStatsManager)
With your permission, MindLock reads:
This data is read directly from Android's built-in UsageStats system. It is used only to calculate your Brain Health Score and Digital Fingerprint statistics. This data is processed on your device and is never transmitted to our servers in raw form.
Device Information (Synced to Cloud)
When you create an account, we may sync the following minimal information to our servers:
This is used to provide appropriate support and ensure compatibility.
When you are logged in to a MindLock account and have an internet connection, the following aggregated, anonymised summary data is synced to our servers (Supabase) to preserve your progress across reinstalls:
What is NOT synced to our servers:
Given the broad scope of the Accessibility Service required for our features, we want to explicitly state what we do NOT collect or read:
We use your information for the following purposes only:
| Purpose | Data Used | Basis |
|---|---|---|
| Provide app blocking features | Blocked app list, session records | Contract (providing the service you signed up for) |
| Calculate Brain Health Score | Usage stats, session data | Contract |
| Restore your progress after reinstall | Cloud-synced scores and streaks | Contract |
| Verify your subscription | Email address, Razorpay payment confirmation | Contract |
| Respond to support requests | Your email and message | Legitimate interest |
| Improve the app | Aggregated, anonymised crash reports | Legitimate interest |
| Legal compliance | Minimal required records | Legal obligation |
We do not:
MindLock uses Android's Accessibility Service. Because this is a sensitive permission, we are fully transparent about its use.
App Blocking Service (MindLock — App Blocker)
Content Filter Service (MindLock — Content Filter)
Android does not provide a public API to detect the foreground app in real time without using either Accessibility Service or UsageStats polling. We use Accessibility Service because it allows us to detect the precise moment an app opens, which is necessary for the breathing/intent flow in Utility 1 (Per-App Interception) and doom scroll detection in real time.
You can disable either or both accessibility services at any time via: Settings → Accessibility → Installed Services → MindLock. Disabling the App Blocker service will stop all app blocking functionality. The Content Filter VPN will continue working for domain-level blocking.
We do not sell, rent, or trade your personal information.
We share information only in the following limited circumstances:
Supabase (backend database and authentication)
We use Supabase to host our database and user authentication system. (Hosting region: Singapore/Mumbai; data transferred outside India is protected under applicable cross-border transfer rules such as the DPDP Act).
Razorpay (payment processing)
We use Razorpay to process subscription payments.
Cloudflare (1.1.1.3 Family DNS)
Used for content filtering features.
We may disclose your information if required to do so by law, court order, or government authority in India, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of MindLock, our users, or the public.
If MindLock is ever acquired or merged with another entity, your information may be transferred as part of that transaction. You will be notified via email and in-app notification before your data is transferred and becomes subject to a different privacy policy.
MindLock's Content Filter feature uses a local VPN on your device to filter DNS requests.
All DNS filtering happens locally on your device using Cloudflare's Family DNS service. Your browsing domains are never transmitted to MindLock's own servers. Separately, aggregate usage statistics (not browsing content) are synced to power your Brain Health score — see 'Data We Collect' above.
Important facts about this VPN:
What the VPN does not do:
The local VPN is completely optional. You can disable it at any time from MindLock Settings → Content Filter → toggle OFF.
| Data Type | Where Stored | Retention Period |
|---|---|---|
| Blocked-attempt logs (domains/accounts) | Your device | Retained for 30 days, then automatically deleted |
| Session purpose notes (intent statements) | Your device | Retained for 90 days, then automatically deleted |
| Behavioral & Brain Health data | Supabase cloud | Retained for 90 days (Free tier) or up to 365 days (Premium tier) |
| Account information (email) | Supabase cloud | Until you delete your account |
| Streak and XP data | Supabase cloud | Until you delete your account |
| Payment records | Razorpay | As required by law (minimum 5 years per Indian financial regulations) |
| Support emails | Gmail | Deleted within 12 months of resolution |
You may request a summary of the personal data we hold about you by emailing supportmindlock@gmail.com.
You may request deletion of your account and all associated cloud data by emailing supportmindlock@gmail.com with the subject line "Account Deletion Request." We will process your request within 7 business days. Local data on your device can be deleted by uninstalling the app.
If your email address changes, update it in MindLock Settings → Account. For other corrections, contact supportmindlock@gmail.com.
You may use MindLock without creating an account. Guest mode stores all data locally on your device only. No data is synced to our servers.
You may disable MindLock's accessibility services at any time via your phone's Accessibility Settings. This will disable app blocking features but will not affect your account or data.
Pro and Premium users may export their usage data as a CSV file from MindLock Settings → Stats → Export Data.
MindLock is intended for users aged 13 years and older. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has created a MindLock account, please contact us at supportmindlock@gmail.com and we will promptly delete the account and associated data.
If we discover that a user is under 13, we will immediately deactivate the account and delete all associated data.
We take reasonable technical and organisational measures to protect your data:
No system is 100% secure. If you discover a security vulnerability in MindLock, please report it responsibly to supportmindlock@gmail.com.
MindLock may display links to external websites or open third-party apps. We are not responsible for the privacy practices of those websites or apps. We encourage you to read the privacy policy of any third-party service you interact with.
We may update this Privacy Policy from time to time. When we make significant changes, we will:
Continued use of MindLock after changes take effect constitutes acceptance of the revised Privacy Policy.
This Privacy Policy is governed by and construed in accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 of India, and applicable laws of the State of Madhya Pradesh.
Any disputes arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Neemuch, Madhya Pradesh, India.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
Ganesh Rathor
Developer, MindLock
📧 Email: supportmindlock@gmail.com
📍 Address: Ward No. 23, Gram Panchayat Dal Dabra Kalan, Athva, Neemuch, Madhya Pradesh — 458226, India
We aim to respond to all privacy-related inquiries within 3 business days.