Back to home

Privacy Policy

DuoLock helps couples start consent-based offline sessions. Privacy is part of the product design: the distractions you select stay on your iPhone and are not shown to your partner.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Jonas Becker
Hauptstraße 95c
30916 Isernhagen
Germany
Email: hello@duolock.app

2. Scope and Overview of Processing

DuoLock consists of this website and an iOS app for shared offline sessions. The website and app process different data for different purposes.

3. Website Hosting with Vercel

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you access the website, Vercel processes technical connection data to deliver, protect, and operate the site reliably.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the secure and performant operation of this website. For transfers to the United States, Vercel uses appropriate safeguards, including Standard Contractual Clauses, and is certified under the EU-U.S. Data Privacy Framework.

More information is available in Vercel's privacy policy: vercel.com/legal/privacy-policy.

4. Vercel Web Analytics

We use Vercel Web Analytics on this website only to understand which pages are viewed and whether the landing page works technically. This may involve processing technical information such as URL, referrer, approximate location, browser, operating system, device type, and event time.

Vercel Web Analytics is not used to track individual visitors across multiple websites. We do not use advertising or retargeting cookies on this website. Vercel Web Analytics is not integrated into the DuoLock iOS app and does not receive app events.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is privacy-conscious measurement of reach and technical page views.

5. Email Contact and App Access Requests

If you contact us by email or request DuoLock access, we process your email address, the content of your message, and technical email metadata in order to respond to your request.

The legal basis is Art. 6(1)(b) GDPR if the request relates to using or preparing to use the app, and otherwise Art. 6(1)(f) GDPR.

6. App Accounts, Profiles, Pairing, and Shared Data

DuoLock uses Sign in with Apple and Supabase Auth for account access. To provide accounts, partner pairing, and shared offline session coordination, the app may process and store the following data in Supabase:

Plain invite tokens and backup codes are returned once so you can share them with your partner. The backend stores hashes, not the plaintext token or code.

7. How We Use App Data

We use app data only to provide App Functionality:

The legal basis for processing needed to provide the app is Art. 6(1)(b) GDPR. We do not sell personal data and do not use account, pairing, session, ritual, or notification data for advertising or tracking.

8. Data Stored Locally and Screen Time Permission

DuoLock uses Apple's Family Controls, Managed Settings, and Device Activity frameworks to pause the apps, categories, or websites you select. The app may store the following data locally on your device or in its local App Group container:

Screen Time selections, blocking profile contents, recap history, and recap reflections are not sent to us, Supabase, or your partner. You can revoke Screen Time permission at any time in iOS Settings.

9. Data We Do Not Collect in the App

The current iOS build does not collect or transmit:

10. Third-Party Services and Diagnostics

Supabase provides authentication, private profile-photo storage, pairing data storage, shared session coordination, scheduled ritual storage, device token storage, and invite push delivery through a Supabase Edge Function. Supabase processes this data only as needed to provide the app's backend functionality.

Apple provides Sign in with Apple, the Screen Time frameworks, APNs, and platform diagnostics. The current build uses Apple's TestFlight and App Store Connect crash reporting and local OSLog entries for development and debugging. The app does not send these local logs to DuoLock, Supabase, or a third-party crash provider.

The current iOS build contains no advertising SDKs, analytics SDKs, payment SDKs, or third-party crash reporting SDKs. Vercel and Vercel Web Analytics are used for this website only, not in the iOS app.

11. Partner Visibility and Data Sharing

Your connected partner can see your display name, avatar mascot or profile photo, that you are paired, shared ritual metadata, and the shared session status needed to start or end together.

Your partner cannot see your Screen Time selections, the contents of your local blocking profiles, Screen Time usage, opened apps, local recap history, or private reflection text. We do not share personal data for advertising or tracking.

Push notifications are used only as a wake-up or visible invite for a new session. They are not a guarantee that shielding starts in the background.

12. Retention and Deletion

Website and email data is deleted once its processing purpose no longer applies and no statutory retention obligation requires us to retain it. Email requests are retained only as long as needed to handle the request and reasonable follow-up communication.

Local app data remains on your device until you change or clear it where available, revoke permissions, or delete the app. Account, pairing, scheduled ritual, session coordination, and device notification data remains in Supabase while your account or active couple exists. Leaving a couple or signing out disables the registered device token where possible.

Deleting your account removes your Supabase Auth user, profile, profile photos, device tokens, pair invites, scheduled rituals, current couple and session coordination records, and that account's local recap history. Local Screen Time selections remain on your device until you change them, delete the app, or revoke permission in iOS Settings.

13. Tracking

The current iOS build does not track you across apps or websites owned by other companies and does not use your data for targeted advertising.

14. Your Rights

Under the GDPR, you have rights including access, rectification, deletion, restriction of processing, data portability, objection, and withdrawal of consent.

To exercise your rights, contact hello@duolock.app. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for the controller's place of business is the State Commissioner for Data Protection of Lower Saxony.

15. Changes to this Privacy Policy

This privacy policy may be updated if legal requirements, this website, or the app functionality change. If we add analytics, payments, support features, crash reporting, or other third-party SDKs to the app, we will update this policy and the App Store privacy details. The current version is always available on this page.