Privacy Policy
Effective date: September 25, 2026
This Privacy Policy applies to the OpLoop mobile application, hereby referred to as the “Application,” and the OpLoop website at oploop.app. The Application and website are provided by StudioJson, hereby referred to as the “Service Provider.”
This Privacy Policy explains what information the Application may process, how it is used, and what choices you have. By using the Application, you agree to the processing of information as described in this Privacy Policy.
1. Privacy Summary
The Application is an application blocker that operates primarily on your device. Blocking decisions, routines, blocked application selections, usage statistics, and records of blocking events are stored locally on your device and are not transmitted to the Service Provider.
Information that is transmitted is limited to the following:
- your email address and a display nickname, if you choose to sign in;
- achievement badge unlock state, if you are signed in;
- purchase and subscription status, when you purchase paid features;
- advertising identifiers and related information, when advertising is displayed on the free tier;
- analytics identifiers, application usage events, tier, device information, and approximate region, as described in Section 8;
- an anonymous report of a blocking message, if you choose to report one;
- your email address, if you ask on the website to be notified about a future release.
Signing in is optional. The Application’s blocking features and paid features operate without an account.
The Application does not include a crash reporting library. It does not request permissions for location, contacts, camera, photos, files, calendar, SMS, or call logs.
2. Accessibility Service
The Application uses the Android Accessibility Service to determine which application is currently in the foreground. This is required for the Application’s blocking function.
The service receives window change events. When an application comes to the foreground, the Application reads the package name of that application and compares it against the blocking rules stored on your device.
Some blocking features additionally require the service to examine what is on the screen, on your device. If you enable the blocking of a short-form video screen within an application (such as Shorts or Reels), the service examines the screen layout of that application in order to recognise when such a screen is displayed. Where a blocking feature is defined by content rather than layout — for example, a filter for particular categories of website — the service may also examine on-screen identifiers such as the address of the page being visited.
All such examination happens on your device, in memory, and its only use is deciding whether the current screen should be blocked. Nothing that is examined is stored or transmitted: the Application keeps no record of what you viewed, browsed, or typed, and passwords, account credentials, and payment details are never collected. Screen examination is active only for the applications and features you have enabled; when nothing you have enabled requires it, the service unsubscribes from screen content events entirely.
If an application that is being blocked continues to play in a floating picture-in-picture window, the Application dismisses that window the same way you would — by dragging it away. This is an action performed on your device and involves no reading or transmission of the window’s content.
The foreground package name and the result of screen examination are used in memory to determine whether blocking applies, and are not transmitted. If a blocking screen is shown, a record of that event is stored locally so that the Application can display your own statistics.
You may disable the Accessibility Service at any time in Android Settings under Accessibility. The Application’s blocking features will not operate while it is disabled.
3. Information Stored on Your Device
The following information is stored in a local database and local preference files on your device. Except for the items expressly noted below, it is not transmitted to the Service Provider and no server-side copy exists.
- routines, including schedules, blocking modes, overlay tones, and escape policies;
- application groups and the applications you have selected to block or allow;
- blocking events, including when a blocking screen was shown and for which application;
- daily application usage minutes;
- temporary unlock and pass usage;
- focus session records, including mode and duration;
- records of which blocking messages have been shown, and which you have reported (the report itself is sent — see Section 4);
- achievement badge unlock state (synchronised to your account if you sign in — see Section 5);
- your nickname (synchronised if you sign in — see Section 4), daily reset time, pass policy, language, and other settings.
Usage Access
The Application requests the Usage Access special permission in order to read screen time information from the Android system. This information is used to establish a usage baseline and to calculate the statistics displayed in the Application. These calculations are performed on your device. Because the Android system retains its own daily usage records for a limited period, the Application accumulates completed days in its local database in order to display longer-term comparisons. This information is not transmitted.
Installed applications
The Application requires a list of installed applications in order to display the application selection screen and to apply blocking rules. The Application does not use the QUERY_ALL_PACKAGES permission; it declares a limited set of intent queries instead. The resulting list is used on your device only and is not transmitted.
Exclusion from cloud backup
The local database and the authentication token store are excluded from Android automatic backup and from device-to-device transfer through the Application’s backup rules. Settings such as your nickname and pass policy remain included in backup.
Uninstalling the Application deletes all locally stored information. This information cannot be recovered after uninstallation, including by the Service Provider.
4. Information You Provide
Signing in is optional. The Application’s blocking features operate without an account, and paid features may be purchased and used without an account. If you choose to sign in, you may do so with a Google account or with an email address that receives a six-digit verification code. The Application does not use passwords.
If you sign in, the following information is processed:
- your email address, held by the authentication provider so that verification codes can be sent and the account identified;
- a provider identifier, if you sign in with Google;
- a display nickname;
- account timestamps, such as the date the account was created.
The Service Provider’s account record contains an account identifier, a nickname, timestamps, and badge state. Your email address is held in the authentication provider’s access-controlled schema, which is required in order to send sign-in codes. The Service Provider does not store an additional copy of it in its own tables.
Nickname
A nickname is generated on your device when the Application is first launched. It is a display name, is not required to be unique, is not an identifier, and is not shown to other users. If you sign in, it may be synchronised so that it is available on a new device.
Message reports
If you report a blocking message, the Application sends the identifier of that message, its language, the type of blocking screen it appeared on, the reason you selected, the message pack version, and the time of the report. This is used to find and rewrite messages that land badly. The report is sent without an account token and carries no identifier of you or of your device, so it cannot be attributed to you or linked to your other reports. It does not include which application was being blocked, and nothing is sent unless you choose to report.
Release notifications
If you ask on the website to be notified about a future release, the Service Provider stores the email address you enter, the referral or campaign code and any campaign parameters contained in the link you arrived through, the address of the page that referred you, the country reported by the content delivery network, your browser language, and the platform your browser reports. Your IP address is not stored.
This information is used to email you when a release ships — the iOS release, and significant updates — and to understand which channels people arrive through. It is not used to build a profile of you, is not combined with any information from the Application, and is not sold or shared for anyone else’s marketing.
Asking to be notified does not create an account, and is unrelated to the Application and its blocking features. Every such email contains an unsubscribe link, and unsubscribing takes effect without signing in.
Support requests
If you contact support from within the Application, an email is prepared containing your device model, Android version, application version, and language. You may review and edit this information before sending. When sent, the Service Provider receives that information together with your email address and the content of your message.
5. Achievement Badges
The Application awards badges when cumulative activity reaches defined milestones. If you are signed in, badge unlock state may be synchronised to the Service Provider so that badges are available after a change of device.
A synchronised badge record consists of the badge’s identifier and the time at which the badge itself was unlocked. It does not include which application was involved, the date or time of any individual blocking or usage event, or any other detail of your activity. The underlying events remain on your device and are not transmitted.
If you are not signed in, badges are stored only on your device. If you sign out, synchronisation stops. If you delete your account, synchronised badge state is deleted with it; badges stored on your device are unaffected.
6. Sign-In and Session Security
When you sign in, the authentication provider records the IP address associated with the session for the duration of that session as a standard security measure. This information is not used to estimate location, to identify you across services, or for advertising purposes.
Signing out removes the server-side session. If you do not sign in, no session is created and no IP address is recorded for this purpose.
The Application does not refresh authentication sessions when it starts. Sessions are refreshed only when you open a screen that requires an account.
7. Advertising
The free tier of the Application displays advertising. Advertising appears only in designated slots on three of the Application’s own screens. It is never displayed on the blocking screen, during a focus session, or anywhere in the path that decides whether an application is blocked. Subscribing to the paid tier removes advertising: on the paid tier the advertising code does not run and no advertising request is made.
Advertising is served by Google AdMob. In order to serve and measure advertising, AdMob may process:
- the Android Advertising ID, a resettable identifier assigned by your device;
- device and network information, such as device model, operating system version, language, and approximate region derived from IP address;
- advertising interaction data, such as impressions and clicks.
Advertising partners do not receive blocking records, application usage statistics, the list of applications you have selected to block, the list of applications installed on your device, your routines, your email address, or your account identifier.
The Application itself sends nothing about you with an advertising request. For revenue reporting, it records through the entitlement provider which of its three advertising slots an advertisement was shown in, together with impression, click, and revenue events, under the anonymous application user identifier described in Section 9. That record identifies the slot, not your activity: it does not include which applications you block, your usage, your routines, or anything examined on screen.
The free tier may also offer a temporary trial of a paid feature in exchange for watching rewarded advertisements. Where such a trial is offered, completion of the advertisement is verified by Google AdMob and the entitlement provider so that the trial can be granted. The verification identifies the advertisement and the anonymous application user identifier, and contains no information about your use of the Application.
You may reset or delete your Advertising ID in Android Settings. If you are located in the European Economic Area, the United Kingdom, or Switzerland, the Application presents a consent request before personalised advertising is used, and that choice may be changed later. Subscribing to the paid tier removes advertising from the Application.
Google’s processing of advertising data is governed by its own privacy policy, available at policies.google.com.
8. Analytics
The Application uses Google Analytics for Firebase on both the basic and pro tiers to understand how people move through the Application, improve the Application, and measure the performance of advertising campaigns.
Google Analytics for Firebase may process:
- a Firebase application instance identifier;
- the Android Advertising ID;
- application usage events, including onboarding progress, whether permissions and required settings have been configured, paywall views, and purchase steps;
- your tier, recorded as basic or pro;
- device and application information, such as device model, operating system version, language, and application version;
- an approximate region derived from your IP address.
RevenueCat may send subscription status changes, including trial conversion, renewal, cancellation, and expiration, to Google Analytics together with the Firebase application instance identifier. Where analytics consent is required, RevenueCat sends this information only while that consent is in effect.
Analytics does not receive accessibility inspection results, application usage statistics, lists of installed or blocked applications, blocking records, routines, your email address, or your account identifier. The Application does not set a Google Analytics user ID.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the Application is configured so that analytics identifiers are not used before you consent. Until then, only limited event information without these identifiers may be sent, which Google uses to estimate aggregate measurements. The consent request applies to both the basic and pro tiers, and you may change your choice later in the Application’s settings.
9. Payments, Trials, and Entitlements
Paid features are sold as a subscription through Google Play. Subscription status and entitlements are managed through RevenueCat.
- The Service Provider does not receive or store payment card information. Payment is processed by Google Play.
- An anonymous application user identifier is assigned when the Application is first run, so that paid features may be purchased and used without an account.
- If you subsequently sign in, that identifier is linked to your account identifier so that purchases can be restored on another device. The Service Provider stores a record of this link.
- Purchase-related information, including subscription status, renewal state, trial eligibility, and entitlement validity, is processed to determine whether paid features are available.
- If you install the Application through a partner link (for example, a link shared by a content creator), the Google Play install referrer is read once to attribute the installation to that partner and to present the partner’s introductory offer. It is not used to identify you.
The entitlement provider may also collect device and application information as part of its own service, governed by its own privacy policy.
10. Information Not Collected
The following categories of information are not collected by the Application.
| Category | Reason |
|---|---|
| Screen content, typed input, credentials | Examined on-device only, in memory, to decide whether to block; never stored or transmitted, and no viewing or browsing history is kept |
| Application usage transmitted off the device | Statistics are calculated locally |
| List of installed applications transmitted off the device | Used locally only |
| Location | No location permission is requested |
| Contacts, calendar, SMS, call logs | No such permission is requested |
| Camera, microphone, photos, files | No such permission is requested |
| Crash and diagnostic reports | No crash reporting library is included |
| Payment card information | Processed by Google Play |
The Service Provider does not sell personal information and does not share personal information with third parties for their own independent marketing purposes.
If the Application’s collection practices change, this Privacy Policy will be updated to describe the change before the version that introduces it is released.
11. How Information Is Used
Information described in this Privacy Policy is used to:
- determine on your device whether an application should be blocked;
- display the blocking screen and select a message;
- calculate usage statistics, baselines, and comparisons;
- award and display achievement badges;
- provide sign-in and make your nickname and badges available on another device;
- verify and restore paid entitlements and manage subscriptions and trials;
- serve and measure advertising on the free tier;
- measure onboarding and conversion, improve the Application, and measure the performance of advertising campaigns;
- respond to support requests and investigate reported problems;
- maintain security, prevent abuse of trials, referrals, or entitlements, and comply with legal obligations.
12. Third-Party Services
The Application and website use third-party services that process information under their own privacy policies:
- Google Play Services;
- Google Sign-In and Credential Manager;
- Google Play Billing;
- Google AdMob;
- Google Analytics for Firebase;
- RevenueCat;
- Supabase;
- Resend;
- Cloudflare.
These services may process information for purposes including authentication, purchase processing, entitlement verification, backend storage, email delivery, analytics, advertising, website delivery, and service reliability.
14. Your Choices
- You may use the Application without signing in. Blocking features and paid features operate without an account.
- You may delete your account within the Application, under Settings. Deletion requires confirmation and cannot be undone. Routines, application groups, and passes remain on your device. You may also request account deletion without the Application — see the account deletion page.
- You may sign out to stop badge synchronisation without deleting your account.
- You may disable the Accessibility Service in Android Settings. Blocking will not operate while it is disabled.
- You may revoke Usage Access in Android Settings. Statistics and baselines will not be updated.
- You may reset or delete your Advertising ID in Android Settings. This affects the identifier used for both advertising and analytics. You may also subscribe to the paid tier to remove advertising.
- You may change your advertising and analytics consent choices in the Application’s settings if you are located in a region where consent is requested.
- You may unsubscribe from release notifications at any time using the link in any such email. No sign-in is required.
- You may uninstall the Application to delete all locally stored information.
- You may contact the Service Provider to request access, correction, deletion, or other assistance.
Certain features will not operate if required permissions are denied or revoked.
15. Data Retention
Information stored on your device is retained until you delete it within the Application or uninstall the Application. Certain records are removed automatically in the course of normal operation.
Account information is retained while your account exists. When you delete your account, the account record and synchronised badge state are deleted.
Purchase and entitlement records may be retained by Google Play and by the entitlement provider under their own retention rules, including where retention is required for accounting, tax, refund handling, or dispute resolution. The Service Provider may retain limited records where reasonably necessary to prevent repeated trial abuse, payment abuse, or entitlement misuse. Such records are intended to be limited and not directly identifying on their own.
Google Analytics event data is retained for 14 months.
A request to be notified about a release is retained until that notification has been sent, and in any event no longer than twelve months from the request, after which it is deleted. Unsubscribing removes you from any further notification.
Support correspondence is retained for as long as reasonably necessary to handle the request and any related follow-up.
16. Security
The Service Provider uses reasonable technical, administrative, and organisational measures to protect information. Network requests are encrypted in transit. Access to backend data is restricted by row-level security rules, and account deletion is performed by a server function that acts only on the account of the authenticated caller.
No method of transmission, storage, or processing is completely secure, and absolute security cannot be guaranteed. You are responsible for maintaining the security of your device, operating system, and sign-in account.
17. Children’s Privacy
The Application is not directed to children under the age of 13, or a higher age where required by applicable law. The Service Provider does not knowingly collect personal information from children under 13 without appropriate consent where required.
The Application contains occasional mild profanity in its blocking messages and is rated accordingly on the application store. If you are a minor, you should use the Application only with the consent and supervision of a parent or legal guardian.
If you are a parent or guardian and believe that a child under 13 has provided personal information through the Application, contact the Service Provider at [email protected]. Reasonable steps will be taken to delete such information.
18. International Users
The Application may be used in different countries and regions. Account, entitlement, and analytics information may be processed and stored in countries other than the country in which you reside, including through the third-party services listed in Section 12. Data protection laws in those countries may differ from those in your location. Where required, reasonable steps are taken to protect information in accordance with applicable privacy laws.
For users in the Republic of Korea, analytics information is transferred electronically to Google LLC in the United States when an analytics event occurs. The transferred information consists of the Firebase application instance identifier, Android Advertising ID, application usage events, tier, device and application information, approximate region derived from IP address, and subscription status changes sent by RevenueCat. It is transferred to improve the Application and measure advertising campaign performance, and Google Analytics event data is retained for 14 months. You may refuse this overseas transfer by not installing or using the Application, or by uninstalling it. If you refuse in this way, analytics information will not be transferred, but you will not be able to use the Application after uninstalling it. Where an analytics consent choice is available, you may also refuse or withdraw consent in the Application’s settings; the Application’s core features remain available when you do so.
19. Regional Privacy Rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about how your personal information is processed.
To make a privacy request, contact the Service Provider at [email protected]. Identity verification may be required before a request can be answered. Certain requests may be limited by legal, security, fraud prevention, payment, or entitlement verification requirements.
Requests relating to blocking records, usage statistics, or blocked application lists cannot be fulfilled by the Service Provider, as that information is stored only on your device. It may be reviewed within the Application and deleted by uninstalling the Application.
20. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time. When changes are made, the updated version is posted on this page with a revised effective date, or otherwise made available through the Application or the website.
You are advised to review this Privacy Policy periodically. Continued use of the Application after changes become effective indicates that you acknowledge the updated Privacy Policy.
21. Contact
If you have questions or suggestions regarding this Privacy Policy, contact the Service Provider at:
StudioJson[email protected]
This address is also the contact channel for access, correction, deletion, consent withdrawal, and other privacy-related requests.