Privacy Policy
This policy describes what AppLock does with information. We have tried to write it so that you can actually tell what happens, rather than so that everything is technically permitted.
1. The short version
- There is no account, no sign-in and no server of ours. We do not operate a backend, and we never receive your files.
- Your vault media, intruder photos, locked-app list and PIN stay on your device.
- The app is free and ad-supported. Google's AdMob and Firebase SDKs inside it collect advertising and diagnostic data.
- In the EEA, the UK and Switzerland you are asked for consent before personalised advertising data is used.
- Purchases go through Google Play Billing. We never see your card or payment details.
- AppLock is not directed to children. It is intended for users aged 18 and over.
2. What stays on your device
The following never leaves your phone. It is not uploaded, not backed up to us, and not shared with any third party:
- Vault contents — photos, videos, audio files and documents you move into the app, stored as files in AppLock's private internal storage.
- Intruder photos — front-camera images captured after repeated failed unlock attempts, if you turn that feature on.
- Your PIN, pattern or password — stored only as a salted one-way hash, so the app can check an entry without keeping the original.
- Biometric data — your fingerprint or face is handled entirely by Android. AppLock only receives a yes/no result and never has access to the biometric itself.
- Your list of locked apps, settings, key balance and purchases you have unlocked — kept in a local database on the device.
Please read this part
Files in the vault are kept in AppLock's private internal storage, which other apps on the device cannot read. They are not encrypted at rest. Your PIN is used to gate access, not as an encryption key. AppLock protects against another person picking up your unlocked phone; it does not protect against forensic extraction, a rooted device, or someone with physical access and technical skill.
3. What is collected, and by whom
We do not run analytics or advertising infrastructure ourselves. The collection below is performed by Google SDKs embedded in the app, acting as independent data controllers or as our processors depending on the service.
| Service | What it collects | Why |
|---|---|---|
| Google AdMob (advertising) |
Advertising ID (a resettable device identifier), approximate location derived from your IP address, device and app information, and how you interact with ads. | To select, deliver, cap and measure ads, and to detect invalid traffic and fraud. |
| Google User Messaging Platform (consent) |
Your consent choices and the fact that a consent form was shown. | To ask for, record and honour your advertising consent where the law requires it. |
| Firebase Analytics (product analytics) |
A per-installation app instance identifier, device and app information, approximate IP-derived location, and in-app events. In AppLock the events are limited to advertising and reward activity — for example that an ad was requested, shown, clicked, failed to load, or granted keys — plus a session counter. | To understand whether the ad and reward system works, and to fix it when it does not. |
| Firebase Remote Config (configuration) |
An app instance identifier and basic app/device attributes, sent when the app fetches its configuration. | To tune limits such as ad frequency caps and key rewards, and to switch a placement off remotely if it misbehaves. |
| Google Play Billing (purchases) |
Handled entirely by Google. The app receives a purchase token and which product was bought. | To grant the Premium subscription or key pack you paid for, and to restore it later. |
Some of the above — your advertising ID and your approximate location — is shared with Google and its advertising partners for advertising and measurement. AppLock does not sell personal information, and it contains no other third-party SDKs.
What is never collected
No name, no email address, no phone number, no contacts, no precise GPS location, no message or call content, and no content of any file you place in the vault.
4. Permissions and why the app asks
Android requires each of these to be granted by you, and every one of them can be declined — declining simply disables the matching feature.
| Permission | Used for |
|---|---|
| Usage access | To detect which app has just come to the foreground, so the unlock screen can be shown for a locked app. AppLock reads only which app is in front and when — never anything inside it. |
| Display over other apps | To draw the unlock screen on top of a locked app. |
| Query all packages | To list the apps installed on your device so you can choose which to lock. The list stays on the device. |
| Camera | Only if you enable intruder photos. Used to take a single front-camera photo after repeated failed unlock attempts. It is written to private storage and never uploaded. |
| Photos, video and audio access | Only when you import media into the vault, so the app can read the file you picked and, if you ask, remove the original from your gallery. |
| Notifications | For the ongoing notification Android requires while the lock service runs, and for occasional in-app messages. |
| Run at startup, ignore battery optimisation, foreground service | To keep the lock service alive so protection resumes after a reboot and is not killed in the background. |
| Internet and network state | To load ads, fetch remote configuration and complete purchases. The app makes no other network calls. |
| Biometrics | To let Android verify your fingerprint or face as an unlock method. |
5. Legal bases (EEA, UK and Switzerland)
- Consent — personalised advertising, advertising measurement and analytics. Collected through Google's consent form the first time you open the app, and you may refuse.
- Legitimate interest — keeping the app functioning, preventing fraud and invalid ad traffic.
- Contract — processing a purchase you make so that we can deliver what you paid for.
6. Your choices
- Refuse or limit advertising data. When the consent form appears, choose Do not consent, or use Manage options to allow only some purposes.
- Reset or delete your advertising ID. Android Settings → Privacy → Ads. You can reset the identifier or delete it entirely, which stops personalised advertising across all apps.
- Remove ads. The Premium subscription and the Lifetime purchase both switch advertising off.
- Delete everything. See Deleting your data.
If you are in the EEA, the UK or Switzerland you also have the rights to access, correct, delete, restrict and object to processing, and to data portability, plus the right to complain to your local supervisory authority. Because we hold no personal data about you on any server, most of these are satisfied by acting on the device itself — but write to us and we will help.
If you are a California resident, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising outside what Google's advertising services do under your ad-settings choices.
7. Retention
Everything AppLock stores lives on your device for as long as the app is installed, and is removed when you uninstall it or use the in-app reset. Data collected by Google's advertising and analytics services is retained by Google under its own policies; see the links in section 10.
8. Children
AppLock is not directed to children and is intended for users aged 18 and over. We do not knowingly collect information from children. If you believe a child has used the app and you want the associated advertising identifier disassociated, contact us and reset the advertising ID in Android Settings.
9. Changes to this policy
If this policy changes materially we will update the date at the top of the page and, where the change affects how data is collected, ask for consent again inside the app. Continuing to use AppLock after a change means you accept the updated policy.
10. Contact and further reading
Questions, requests or complaints: finishuppp@gmail.com. We aim to reply within 30 days.