Privacy Policy
Effective date: August 11, 2026
This Privacy Policy applies to the OpLoop mobile application, hereby referred to as the “Application,” and the OpLoop website at oploop.app. The Application and website are provided by StudioJson, hereby referred to as the “Service Provider.”
This Privacy Policy explains what information the Application may process, how it is used, and what choices you have. By using the Application, you agree to the processing of information as described in this Privacy Policy.
1. Privacy Summary
The Application is an application blocker that operates primarily on your device. Blocking decisions, routines, blocked application selections, usage statistics, and records of blocking events are stored locally on your device and are not transmitted to the Service Provider.
Information that is transmitted is limited to the following:
- your email address and a display nickname, if you choose to sign in;
- achievement badge unlock state, if you are signed in;
- purchase and subscription status, when you purchase paid features;
- advertising identifiers and related information, when advertising is displayed on the free tier.
Signing in is optional. The Application’s blocking features and paid features operate without an account.
The Application does not include a product analytics library or a crash reporting library. It does not request permissions for location, contacts, camera, photos, files, calendar, SMS, or call logs.
2. Accessibility Service
The Application uses the Android Accessibility Service to determine which application is currently in the foreground. This is required for the Application’s blocking function.
The service is registered to receive window state change events. When an application comes to the foreground, the Application reads the package name of that application and compares it against the blocking rules stored on your device.
The service is declared with canRetrieveWindowContent set to false. As a result, the Application cannot read the content of any screen. It cannot read text displayed in any application, text you type, passwords, search queries, form fields, account credentials, images, media, notification content, or which screen you are viewing within an application.
The foreground package name is used in memory to determine whether blocking applies, and is not transmitted. If a blocking screen is shown, a record of that event is stored locally so that the Application can display your own statistics.
You may disable the Accessibility Service at any time in Android Settings under Accessibility. The Application’s blocking features will not operate while it is disabled.
3. Information Stored on Your Device
The following information is stored in a local database and local preference files on your device. It is not transmitted to the Service Provider, and no server-side copy exists.
- routines, including schedules, blocking modes, overlay tones, and escape policies;
- application groups and the applications you have selected to block or allow;
- blocking events, including when a blocking screen was shown and for which application;
- daily application usage minutes;
- temporary unlock and pass usage;
- focus session records, including mode and duration;
- records of which blocking messages have been shown and which you have reported;
- achievement badge unlock state;
- your nickname, daily reset time, pass policy, language, and other settings.
Usage Access
The Application requests the Usage Access special permission in order to read screen time information from the Android system. This information is used to establish a usage baseline and to calculate the statistics displayed in the Application. These calculations are performed on your device. Because the Android system retains its own daily usage records for a limited period, the Application accumulates completed days in its local database in order to display longer-term comparisons. This information is not transmitted.
Installed applications
The Application requires a list of installed applications in order to display the application selection screen and to apply blocking rules. The Application does not use the QUERY_ALL_PACKAGES permission; it declares a limited set of intent queries instead. The resulting list is used on your device only and is not transmitted.
Exclusion from cloud backup
The local database and the authentication token store are excluded from Android automatic backup and from device-to-device transfer through the Application’s backup rules. Settings such as your nickname and pass policy remain included in backup.
Uninstalling the Application deletes all locally stored information. This information cannot be recovered after uninstallation, including by the Service Provider.
4. Information You Provide
Signing in is optional. The Application’s blocking features operate without an account, and paid features may be purchased and used without an account. If you choose to sign in, you may do so with a Google account or with an email address that receives a six-digit verification code. The Application does not use passwords.
If you sign in, the following information is processed:
- your email address, held by the authentication provider so that verification codes can be sent and the account identified;
- a provider identifier, if you sign in with Google;
- a display nickname;
- account timestamps, such as the date the account was created.
The Service Provider’s account record contains an account identifier, a nickname, timestamps, and badge state. Your email address is held in the authentication provider’s access-controlled schema, which is required in order to send sign-in codes. The Service Provider does not store an additional copy of it in its own tables.
Nickname
A nickname is generated on your device when the Application is first launched. It is a display name, is not required to be unique, is not an identifier, and is not shown to other users. If you sign in, it may be synchronised so that it is available on a new device.
Support requests
If you contact support from within the Application, an email is prepared containing your device model, Android version, application version, and language. You may review and edit this information before sending. When sent, the Service Provider receives that information together with your email address and the content of your message.
5. Achievement Badges
The Application awards badges when cumulative activity reaches defined milestones. If you are signed in, badge unlock state may be synchronised to the Service Provider so that badges are available after a change of device.
Badge records indicate that a cumulative threshold has been reached. They do not include which application was involved, the date or time of any individual event, or any other detail of your activity. The underlying events remain on your device and are not transmitted.
If you are not signed in, badges are stored only on your device. If you sign out, synchronisation stops. If you delete your account, synchronised badge state is deleted with it; badges stored on your device are unaffected.
6. Sign-In and Session Security
When you sign in, the authentication provider records the IP address associated with the session for the duration of that session as a standard security measure. This information is not used to estimate location, to identify you across services, or for advertising purposes.
Signing out removes the server-side session. If you do not sign in, no session is created and no IP address is recorded for this purpose.
The Application does not refresh authentication sessions when it starts. Sessions are refreshed only when you open a screen that requires an account.
7. Advertising
The free tier of the Application displays advertising. Advertising is not displayed on the blocking screen. Subscribing to the paid tier removes advertising.
Advertising is served by Google AdMob. In order to serve and measure advertising, AdMob may process:
- the Android Advertising ID, a resettable identifier assigned by your device;
- device and network information, such as device model, operating system version, language, and approximate region derived from IP address;
- advertising interaction data, such as impressions and clicks.
Advertising partners do not receive blocking records, application usage statistics, the list of applications you have selected to block, the list of applications installed on your device, your routines, your email address, or your account identifier.
You may reset or delete your Advertising ID in Android Settings. If you are located in the European Economic Area, the United Kingdom, or Switzerland, the Application presents a consent request before personalised advertising is used, and that choice may be changed later. Subscribing to the paid tier removes advertising from the Application.
Google’s processing of advertising data is governed by its own privacy policy, available at policies.google.com.
8. Payments, Trials, and Entitlements
Paid features are sold as a subscription through Google Play. Subscription status and entitlements are managed through RevenueCat.
- The Service Provider does not receive or store payment card information. Payment is processed by Google Play.
- An anonymous application user identifier is assigned when the Application is first run, so that paid features may be purchased and used without an account.
- If you subsequently sign in, that identifier is linked to your account identifier so that purchases can be restored on another device. The Service Provider stores a record of this link.
- Purchase-related information, including subscription status, renewal state, trial eligibility, and entitlement validity, is processed to determine whether paid features are available.
The entitlement provider may also collect device and application information as part of its own service, governed by its own privacy policy.
9. Information Not Collected
The following categories of information are not collected by the Application.
| Category | Reason |
|---|---|
| Screen content, text entered, credentials | Window content retrieval is disabled |
| Application usage transmitted off the device | Statistics are calculated locally |
| List of installed applications transmitted off the device | Used locally only |
| Location | No location permission is requested |
| Contacts, calendar, SMS, call logs | No such permission is requested |
| Camera, microphone, photos, files | No such permission is requested |
| Product analytics events | No analytics library is included |
| Crash and diagnostic reports | No crash reporting library is included |
| Payment card information | Processed by Google Play |
The Service Provider does not sell personal information and does not share personal information with third parties for their own independent marketing purposes.
If a future version of the Application collects a category of information described above as not collected, this Privacy Policy will be updated before that version is released.
10. How Information Is Used
Information described in this Privacy Policy is used to:
- determine on your device whether an application should be blocked;
- display the blocking screen and select a message;
- calculate usage statistics, baselines, and comparisons;
- award and display achievement badges;
- provide sign-in and make your nickname and badges available on another device;
- verify and restore paid entitlements and manage subscriptions and trials;
- serve and measure advertising on the free tier;
- respond to support requests and investigate reported problems;
- maintain security, prevent abuse of trials, referrals, or entitlements, and comply with legal obligations.
11. Third-Party Services
The Application and website use third-party services that process information under their own privacy policies:
- Google Play Services;
- Google Sign-In and Credential Manager;
- Google Play Billing;
- Google AdMob;
- RevenueCat;
- Supabase;
- Resend;
- Cloudflare.
These services may process information for purposes including authentication, purchase processing, entitlement verification, backend storage, email delivery, advertising, website delivery, and service reliability.
13. Your Choices
- You may use the Application without signing in. Blocking features and paid features operate without an account.
- You may delete your account within the Application, under Settings. Deletion requires confirmation and cannot be undone. Routines, application groups, and passes remain on your device.
- You may sign out to stop badge synchronisation without deleting your account.
- You may disable the Accessibility Service in Android Settings. Blocking will not operate while it is disabled.
- You may revoke Usage Access in Android Settings. Statistics and baselines will not be updated.
- You may reset or delete your Advertising ID in Android Settings, or subscribe to the paid tier to remove advertising.
- You may change your advertising consent choice if you are located in a region where consent is requested.
- You may uninstall the Application to delete all locally stored information.
- You may contact the Service Provider to request access, correction, deletion, or other assistance.
Certain features will not operate if required permissions are denied or revoked.
14. Data Retention
Information stored on your device is retained until you delete it within the Application or uninstall the Application. Certain records are removed automatically in the course of normal operation.
Account information is retained while your account exists. When you delete your account, the account record and synchronised badge state are deleted.
Purchase and entitlement records may be retained by Google Play and by the entitlement provider under their own retention rules, including where retention is required for accounting, tax, refund handling, or dispute resolution. The Service Provider may retain limited records where reasonably necessary to prevent repeated trial abuse, payment abuse, or entitlement misuse. Such records are intended to be limited and not directly identifying on their own.
Support correspondence is retained for as long as reasonably necessary to handle the request and any related follow-up.
15. Security
The Service Provider uses reasonable technical, administrative, and organisational measures to protect information. Network requests are encrypted in transit. Access to backend data is restricted by row-level security rules, and account deletion is performed by a server function that acts only on the account of the authenticated caller.
No method of transmission, storage, or processing is completely secure, and absolute security cannot be guaranteed. You are responsible for maintaining the security of your device, operating system, and sign-in account.
16. Children’s Privacy
The Application is not directed to children under the age of 13, or a higher age where required by applicable law. The Service Provider does not knowingly collect personal information from children under 13 without appropriate consent where required.
The Application contains occasional mild profanity in its blocking messages and is rated accordingly on the application store. If you are a minor, you should use the Application only with the consent and supervision of a parent or legal guardian.
If you are a parent or guardian and believe that a child under 13 has provided personal information through the Application, contact the Service Provider at [email protected]. Reasonable steps will be taken to delete such information.
17. International Users
The Application may be used in different countries and regions. Account and entitlement information may be processed and stored in countries other than the country in which you reside, including through the third-party services listed in Section 11. Data protection laws in those countries may differ from those in your location. Where required, reasonable steps are taken to protect information in accordance with applicable privacy laws.
18. Regional Privacy Rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about how your personal information is processed.
To make a privacy request, contact the Service Provider at [email protected]. Identity verification may be required before a request can be answered. Certain requests may be limited by legal, security, fraud prevention, payment, or entitlement verification requirements.
Requests relating to blocking records, usage statistics, or blocked application lists cannot be fulfilled by the Service Provider, as that information is stored only on your device. It may be reviewed within the Application and deleted by uninstalling the Application.
19. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time. When changes are made, the updated version is posted on this page with a revised effective date, or otherwise made available through the Application or the website.
You are advised to review this Privacy Policy periodically. Continued use of the Application after changes become effective indicates that you acknowledge the updated Privacy Policy.
20. Contact
If you have questions or suggestions regarding this Privacy Policy, contact the Service Provider at:
StudioJson[email protected]
This address is also the contact channel for access, correction, deletion, consent withdrawal, and other privacy-related requests.