DuoLock
Contact
Back to home

Privacy Policy

DuoLock helps couples, friends, and families start consent-based offline sessions. Privacy is part of the product design: the apps and distractions you select stay on your own iPhone or Android device and are not shown to other participants.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Jonas Becker
Hauptstraße 95c
30916 Isernhagen
Germany
Email: hello@duolock.app

2. Scope and Overview of Processing

DuoLock consists of this website and iOS and Android apps for shared offline sessions. The website and apps process different data for different purposes.

3. Website Hosting with Vercel

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you access the website, Vercel processes technical connection data to deliver, protect, and operate the site reliably.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the secure and performant operation of this website. For transfers to the United States, Vercel uses appropriate safeguards, including Standard Contractual Clauses, and is certified under the EU-U.S. Data Privacy Framework.

More information is available in Vercel's privacy policy: vercel.com/legal/privacy-policy.

4. Vercel Web Analytics

We use Vercel Web Analytics on this website only to understand which pages are viewed and whether the landing page works technically. This may involve processing technical information such as URL, referrer, approximate location, browser, operating system, device type, and event time.

Vercel Web Analytics is not used to track individual visitors across multiple websites. We do not use advertising or retargeting cookies on this website. Vercel Web Analytics is not integrated into the DuoLock mobile apps and does not receive app events.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is privacy-conscious measurement of reach and technical page views.

5. Email Contact and App Access Requests

If you contact us by email or request DuoLock access, we process your email address, the content of your message, and technical email metadata in order to respond to your request.

The legal basis is Art. 6(1)(b) GDPR if the request relates to using or preparing to use the app, and otherwise Art. 6(1)(f) GDPR.

6. App Accounts, Profiles, Pairing, and Shared Data

DuoLock uses Sign in with Apple, Sign in with Google, or email and password together with Supabase Auth for account access. To provide accounts, partner pairing, and shared offline session coordination, the app may process and store the following data in Supabase:

Supabase may automatically link Apple and Google identities to the same Supabase user when both providers return the same verified email address. Apple relay addresses or different email addresses remain separate accounts. DuoLock does not offer manual provider linking.

Email and password is a sign-in-only option for existing, confirmed accounts in this release. The password is sent over an encrypted connection directly to Supabase Auth for verification. DuoLock does not persist or log it and does not offer public email registration, password reset, or account recovery in the app.

Plain invite tokens and backup codes are returned once so you can share them with your partner. The backend stores hashes, not the plaintext token or code.

7. How We Use App Data

We use app data only to provide App Functionality:

The legal basis for processing needed to provide the app is Art. 6(1)(b) GDPR. We do not sell personal data and do not use account, pairing, session, ritual, or notification data for advertising or tracking.

8. Local App Choices and Blocking Permissions

iOS

DuoLock uses Apple's Family Controls, Managed Settings, and Device Activity frameworks to pause the apps, categories, or websites you select. The app may store the following data locally on your device or in its local App Group container:

Screen Time selections, blocking profile contents, recap history, and recap reflections are not sent to us, Supabase, or your partner. You can revoke Screen Time permission at any time in iOS Settings.

Android

Android app blocking is optional. After your consent and permission in Android Settings, DuoLock uses the AccessibilityService API during an explicit setup test or an active session to detect when you open one of the apps you selected and to display a dismissible focus screen.

9. Data We Do Not Collect Through Local App Blocking

The current iOS and Android builds do not collect or transmit:

10. Third-Party Services and Diagnostics

Supabase provides Apple, Google, and email/password authentication, private profile-photo storage, pairing data storage, shared session coordination, scheduled ritual storage, device token storage, and invite push delivery through a Supabase Edge Function. Supabase processes this data only as needed to provide the app's backend functionality.

Apple provides Sign in with Apple, the Screen Time frameworks, APNs, and platform diagnostics. The current iOS app uses Apple's App Store Connect crash reporting and local OSLog entries for development and debugging. The app does not send these local logs to DuoLock, Supabase, or a third-party crash provider.

Google LLC provides the Google Sign-In service and the GoogleSignIn iOS SDK and Android Credential Manager/Google Identity. When you choose Google, Google processes the account selection and authentication and provides short-lived authentication tokens to the app. The app passes those tokens to Supabase Auth to establish the DuoLock session; it does not log them. Google and Supabase may process your Google account email and provider identity data for this purpose. These Google sign-in tools are used for authentication, not advertising or analytics. More information is available in Google's Privacy Policy.

The Android app uses Firebase Cloud Messaging for session notifications. Firebase may process a Firebase installation identifier, push token, and technical app or device information needed to address and deliver those notifications. After notifications are turned off, DuoLock attempts to unregister push and delete its token on the next synchronization. Firebase may retain technical information according to its own retention rules.

Together Pass purchases on Android use Google Play Billing and RevenueCat. Google Play processes the payment. RevenueCat processes the DuoLock user ID and purchase or subscription history to provide and analyze subscription access. DuoLock does not receive your credit-card number. RevenueCat is connected after account sign-in in a build where Together Pass is enabled, not only after a purchase.

The current mobile apps contain no advertising SDKs and no general product-analytics or third-party crash-reporting SDK. RevenueCat's subscription analytics is limited to providing and operating Together Pass. Vercel and Vercel Web Analytics are used for this website only, not in the mobile apps.

11. Participant Visibility and Data Sharing

Authorized connected participants can see your display name, avatar mascot or profile photo, the relevant Couple, Friends, or Family relationship, shared ritual metadata, and the shared session state needed to participate together.

Other participants cannot see your iOS Screen Time or Android app selections, the contents of your local blocking profiles, app usage, opened apps, local recap history, or private reflection text. We do not share personal data for advertising or tracking.

Push notifications are used only as a wake-up or visible invite for a new session. They are not a guarantee that shielding starts in the background.

12. Retention and Deletion

Website and email data is deleted once its processing purpose no longer applies and no statutory retention obligation requires us to retain it. Email requests are retained only as long as needed to handle the request and reasonable follow-up communication.

Local app data remains on your device until you change or clear it where available, revoke permissions, or delete the app. Account, pairing, scheduled ritual, session coordination, and device notification data remains in Supabase while your account or active couple exists. Leaving a couple or signing out disables the registered device token where possible.

Deleting your account removes your Supabase Auth user, linked provider identities, profile, profile photos, device tokens, pair invites, scheduled rituals, current couple and session coordination records, and that account's local recap history and, when linked, the corresponding RevenueCat customer record. Local Screen Time or Android app selections remain on your device until you change them, delete the app, or revoke the relevant system permission. It does not delete your Apple ID or Google Account.

You can also request account deletion without installing the app. Use the instructions under Delete your DuoLock account or email hello@duolock.app with the subject “DuoLock Account Deletion.” Include the email address linked to DuoLock or your sign-in method, but never send your password. We verify that the account belongs to you before processing deletion.

Deleting your DuoLock account does not automatically cancel a Together Pass subscription. Manage or cancel the subscription in the store where you purchased it. Cancellation is not a prerequisite for requesting deletion.

13. Children and Family Use

DuoLock is designed for adults and teenagers aged 13 and over who use the app with partners, friends, or family. It is not designed for children under 13. Where local law requires a parent or guardian's consent for a teenager to use an online service, the teenager must have that consent before creating or using a DuoLock account.

DuoLock contains no advertising. Parents and guardians can request access to or deletion of a teenager's account data by contacting hello@duolock.app. We verify the requester's authority before disclosing or deleting account data.

14. Tracking

The current mobile apps do not track you across apps or websites owned by other companies and do not use your data for targeted advertising.

15. Your Rights

Under the GDPR, you have rights including access, rectification, deletion, restriction of processing, data portability, objection, and withdrawal of consent.

To exercise your rights, contact hello@duolock.app. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for the controller's place of business is the State Commissioner for Data Protection of Lower Saxony.

16. Changes to this Privacy Policy

This privacy policy may be updated if legal requirements, this website, or the app functionality change. If we add analytics, payments, support features, crash reporting, or other third-party SDKs to the app, we will update this policy and the relevant App Store and Google Play privacy details. The current version is always available on this page.