◑ Lockaway

Privacy Policy

Last updated: 25 September 2026

This policy explains what the Lockaway app does with data. It is written to be read, not to be skimmed past.

The short version: the app has no accounts, no servers of its own, and asks you for nothing. Your routines, your session history and every setting stay on your phone. Two things involve outside services — the advertising that keeps the app free, and a small amount of crash and usage reporting that keeps it working — and both are described in full below.

1. Who is responsible

The app is published by RANK9 LABS, which is the data controller for the purposes of the GDPR and equivalent laws.

Questions, requests or complaints: support@rank9labs.com

2. What stays on your device

The following is stored locally on your phone or tablet and is never transmitted anywhere. There is no account, no server of ours holding a copy, and no backup or sync feature:

Deleting the app deletes all of it. There is no copy elsewhere for us to return or erase.

Nothing you type leaves the device. The display name is never sent anywhere — it is read back to you on the Today screen and nowhere else. You can clear it at any time in Settings, and the app works perfectly well without one.

3. Advertising

The app is free and is funded by advertising, served by Google AdMob. It shows a banner at the foot of most screens, a card inside the Routines and You lists, and a short video before a session begins. There are no interstitials and no ads when you open the app, and none at all while a Locked session is running.

To serve and measure those ads, the Google Mobile Ads SDK collects data directly — it does not pass through us, and we never see it tied to you. Google describes this collection as including:

How Google uses this is governed by its own policies, not ours:

Watching the optional video ad in Settings earns you an hour with no ads at all. That hour is recorded on your device as a timestamp and nowhere else.

3a. Crash reports and usage statistics

The app uses two Google Firebase services to keep itself working: Crashlytics, which reports crashes, and Google Analytics for Firebase, which counts a short list of events. Neither runs in development builds.

When the app crashes, Crashlytics sends a technical report — the state of the code at the moment of failure, your device model, operating system version, and how long the app had been running. It also carries one fact of our own: whether a session was running at the time, and how firm it was. A crash inside a Locked session is the one we most need to understand and the hardest to reproduce, because the phone is locked while it happens.

The analytics events are deliberately few. This is the complete list:

EventWhat it carries
session_startedThe intent (sleep, deep work, dinner, custom) and the commitment (soft, firm, locked).
session_endedThe same two, whether it ran to the end or was left early, and how long it lasted as a band — "3h–6h", never a clock time.
routine_savedThe commitment, how many days a week it runs, and whether it has a wind-down. Not the times.
reward_earnedThat an optional video ad paid out, and which reward it bought.
setup_finishedHow many of the setup permissions were granted, out of how many were offered.

What these events cannot contain. No display name — nothing you type ever leaves the device, and the analytics code has no way to reach it. No clock times: a session's length is reported in bands, because "8h, locked" is a useful fact about the app while "away 22:31–06:29 every night" is a diary. Every value is one of a fixed set, so no free text can be passed in by accident. These are not intentions; the build fails if any of them stops being true.

Alongside those five, Google Analytics records a few housekeeping events of its own that come with the service — that the app was opened for the first time, opened again, or updated, and how long a visit lasted. Its automatic screen reporting is turned off, so it does not record which screens you use or how long you spend on them.

Analytics is configured so that none of it feeds ad personalisation — the advertising consents are set to denied in the app's own code, not left to a console setting. The advertising SDK logs its own measurement events; those belong to section 3. Both services are operated by Google under the Firebase Privacy and Security terms.

4. Device Admin, and what it is not

To lock the screen, Lockaway asks to be a device administrator. Android shows a strongly worded warning for this, so here is precisely what the app registers for and what it can therefore do:

Policy requestedWhat it allows
force-lockTurning the screen off and bringing up your lock screen — the same thing your power button does.

That is the entire list. The app does not request the policies that make device administration frightening: it cannot wipe your phone, cannot set or read your PIN, cannot change your password rules, cannot disable your camera, and cannot see anything on your screen. Your own lock screen is what keeps the phone shut — Lockaway only turns it on.

You can withdraw it whenever you like, from Settings → How to uninstall inside the app, or from Android's own Settings. Android will not let you uninstall an app that still holds device administration, which is why the app gives you a button that hands it back and starts the uninstall in one step.

5. The other permissions, and why

PermissionWhy the app needs it
NotificationsTo show the countdown while a session runs, and the ten-minute wind-down reminder before a routine.
Do Not Disturb accessTo silence the phone for the length of a session and hand the quiet back afterwards. Optional — without it, sessions run and the phone stays as noisy as it was.
Exact alarmsSo a routine starts at 22:30 rather than whenever the system gets round to it.
Run at startupSo a session that was running when you restarted the phone is still running afterwards.
Foreground serviceTo keep the countdown alive and the session honest while your phone is away. Android requires apps to declare why; ours is declared as specialUse, because the session is the feature.
Ignore battery optimisationOffered, never forced. Some manufacturers kill background apps aggressively enough to end a session early.
InternetUsed by the advertising SDK. The app itself has nothing to send.

6. What the app does not do

7. Purchases

This version of the app has nothing to buy. There is no subscription and no in-app purchase; the hour without ads is earned by watching a video, not paid for. The app bundles Google Play Billing so that a future version can offer an ad-free upgrade, and opening that screen would connect to Google Play in the ordinary way — but with no products to sell, no purchase can be made and no payment information is ever involved. We never see a card number under any circumstances; Google Play would handle that end to end.

8. Children

The app is not directed at children under 13 (or the equivalent minimum age where you live), and we do not knowingly collect personal information from them. It is rated for general audiences but carries advertising, so it is not enrolled in Google Play's Designed for Families programme. If you believe a child has provided personal information through the app, contact us and we will act on it.

9. Your rights

Because the app holds no account and no personal profile, most data-subject requests resolve directly on your device:

If you are in the EEA, the UK or Switzerland, our legal basis for serving personalised ads is your consent, and for non-personalised ads it is the legitimate interest in funding the app. You may withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection authority.

If you are a California resident, you have the right to know what is collected, to delete it, and to opt out of its sale or sharing. We do not sell personal information. The advertising described in section 3 may qualify as "sharing" under the CPRA; opting out of ad personalisation in your device's settings, or declining consent where offered, exercises that right.

To make any request, email support@rank9labs.com. We will respond within 30 days. Since we hold nothing that identifies you, there is usually nothing for us to look up — which is the point.

10. Data outside your country

Google's advertising and Firebase infrastructure operates globally, so the data described in sections 3 and 3a may be processed on servers outside your country, including the United States. Google's transfer safeguards are described in the policies linked above. Nothing else the app holds ever leaves your device, so nothing else crosses a border.

11. Security

The app's data sits in its own private storage, which Android keeps from other apps, and it is encrypted with the rest of your device. No transport is perfectly secure — but what the app sends is the ad requests and the events in section 3a, which hold nothing about you that a stranger could use.

12. Changes to this policy

If this policy changes materially, the date at the top will be updated and the new version published at this address before the change takes effect. Continuing to use the app after that means you accept the revised policy.

13. Contact

RANK9 LABS
support@rank9labs.com