Privacy Policy
Last updated: October 2026
This policy describes what Blockerflow reads, what stays on your device, and what leaves it. Blocking content requires seeing what is on screen, so Blockerflow uses Android's Accessibility Service to read on-screen information in browsers and supported apps — including the web address in your browser's address bar — and decides locally whether to block it.
On-device processing
The following is processed entirely on your device and never uploaded:
- Web addresses read from your browser, checked locally against blocklists bundled in the app
- On-screen accessibility content, such as detecting a Reels or Shorts feed, inspected locally in memory
- Your blocklist, allowlist, and settings, stored locally on your device
Your browsing history is not uploaded. Blockerflow has no analytics SDK, no crash reporter, and no telemetry upload path.
What leaves your device
Only three features send anything off-device. Each is optional and only activates when you deliberately turn it on.
AI Coach
If you choose the AI Coach as your accountability partner (requires sign-in), each time you try to disable a blocker the app sends the reason you type and the name of the feature to Blockerflow's server, which forwards it to Google's Gemini API for an approve/reject decision. Your browsing history is never sent. The server does not store your text; it only keeps a per-account daily count of checks to enforce a free daily limit. If Gemini returns an error or an answer the server can't read, that answer — which may quote your reason — is written to the server's error log. Google's handling of this text is governed by the Gemini API terms.
Accountability Partner
If you set an accountability partner's email address (requires sign-in), the app sends that address to Blockerflow's server, which generates a one-time PIN and emails it via Amazon SES. The server keeps only a salted hash of the PIN until it is used or expires after 10 minutes, plus a daily count of emails sent per account to prevent abuse. The sites you visit are never included.
Cloud settings sync
Signing in with Google is entirely optional — Blockerflow is fully functional offline with no account. If you choose to sign in, Blockerflow stores the following in a Firestore document scoped to your account:
- Profile: the email, display name, and photo URL Google Sign-In returns
- Settings: your blocking toggles, blocklist/whitelist entries, and similar preferences — including your accountability-partner mode and email, if you've set one
Device-local state (such as whether onboarding is complete) and your browsing history or blocklist match decisions are never synced. This data is stored under your Google account's identity in Firebase and is governed by Firebase's own terms. Signing out stops further sync; it does not delete what was already written to Firestore.
Permissions
| Permission | Why |
|---|---|
| Accessibility Service | Read on-screen content to detect and block |
| Internet | The three optional features above — never used to upload browsing data |
| Device Admin | Optional uninstall protection |
| Foreground Service | Keeps the blocker running |
| Notifications | Status notifications |
| Query All Packages | Lists installed apps so you can choose which to block |
No sale of data
Blockerflow does not sell your data, does not use third-party advertising SDKs, and does not track you across apps or websites.
Your choices
Every feature that sends data off-device is opt-in — simply not setting an accountability partner, not choosing the AI Coach, and not signing in with Google means nothing leaves your device at all.
Deleting your account
If you've signed in with Google, you can permanently delete your account and everything synced to the cloud (your profile and settings document) directly in the app: open Blockerflow, go to Settings, scroll to Danger Zone, and tap Delete Account. Confirming deletes your Firestore data and your Firebase Auth account outright; this cannot be undone. Blocking settings stored only on your device are not affected by this and can be cleared separately with Factory Reset, also in Settings. If you'd rather not use the in-app option, email us at the address below and we'll delete it for you.
Contact
Questions about this policy can be sent to [email protected].