AppLocker – Privacy Policy
Last updated: July 2026
Overview
AppLocker ("the App") is developed by DevCodeApps. This Privacy Policy explains how we collect, use, and protect your information when you use AppLocker.
Data We Collect
- Installed app list: We query the list of installed applications on your device solely to display them in the app list so you can choose which apps to lock. This data never leaves your device.
- Camera (Intruder Selfie): If you enable the Intruder Selfie feature (Premium), the front camera captures a photo when someone enters the wrong PIN. Photos are stored locally on your device. They are only ever sent off your device if you separately turn on Email Break-in Alerts (see below).
- Usage Stats: We use Android's UsageStatsManager to detect when a locked app is launched. This data is processed locally in real time and is never stored or transmitted.
- Biometric data: Fingerprint/biometric authentication is handled entirely by the Android OS (BiometricPrompt). We do not access or store any biometric data.
- Notifications: We send local notifications for break-in alerts. Notification content is not sent to external servers.
- Email address (optional, Pro): Only if you turn on Email Break-in Alerts. We send a 6-digit code to the address to confirm it belongs to you, and then use it to deliver alerts. You can change it or switch the feature off at any time.
- Break-in evidence (optional, Pro): While Email Break-in Alerts is on, a failed-unlock event sends the intruder photo (if captured), the locked app's name, the time of the attempt, and your device model over an encrypted connection to our server, for the sole purpose of emailing them to your verified address.
- Usage analytics (with your consent): Via Google Analytics for Firebase we collect anonymous product events — for example which onboarding step you reached, which features you open, and whether a purchase screen was shown — together with app version, device model, OS version, coarse region, and a randomly generated app-instance identifier. Collection is off until you consent, and you can change your choice at any time from Privacy Settings in the app.
- Crash diagnostics: Via Firebase Crashlytics, if the app crashes we collect the crash report (stack trace), device model, OS version, and app version so we can fix the fault.
Data We Do NOT Collect
- We do not collect your name, phone number, or location.
- We collect an email address only if you explicitly enable Email Break-in Alerts. No email is required to use the app.
- Your PIN and pattern never leave your device.
- Intruder photos stay on your device unless you enable Email Break-in Alerts.
- We never collect the contents of your locked apps, your messages, or your files.
- Analytics and crash data never include your PIN, your photos, or the list of apps you have locked.
- We do not sell your data.
Third-Party Services
- Google AdMob: The free version displays ads served by Google AdMob. AdMob may collect an advertising ID (GAID) for ad personalization. See Google's Privacy Policy.
- Google Play Billing: In-app purchases are processed by Google Play. We do not handle or store payment information directly.
- Google Analytics for Firebase: Anonymous usage analytics, collected only with your consent. See Google's Privacy Policy.
- Firebase Crashlytics: Crash and stability reporting. See Google's Privacy Policy.
Permissions Explained
- QUERY_ALL_PACKAGES: Required to list all installed apps for the app-locking interface.
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USE: Keeps the app monitor running to intercept locked app launches.
- SYSTEM_ALERT_WINDOW: Required to display the lock screen over other apps.
- PACKAGE_USAGE_STATS: Detects which app is currently in the foreground.
- CAMERA: Used only for the Intruder Selfie premium feature.
- USE_BIOMETRIC: Allows fingerprint unlock (Premium feature).
- RECEIVE_BOOT_COMPLETED: Restarts the lock service automatically on device reboot.
Data Security
Your PIN is stored locally on your device in a hashed format (SHA-256) and never leaves it. Unless you turn on Email Break-in Alerts, no personal data is sent off your device.
If you do turn on Email Break-in Alerts, evidence is sent to a server we operate at devcode.cloud over an encrypted (HTTPS/TLS) connection. That server relays and discards: the intruder photo is attached to the email sent to you and is never written to disk on the server. Your email address is held only transiently — to check the verification code and to enforce anti-abuse rate limits — and is not kept as a permanent record. Alerts can only be sent to an address you have verified with a code.
Children's Privacy
AppLocker is not directed at children under 13. We do not knowingly collect data from children.
Changes to This Policy
We may update this Privacy Policy. Updates will be reflected with a new "Last updated" date. Continued use of the App after changes constitutes acceptance of the revised policy.
Contact Us
If you have questions about this Privacy Policy, contact us at:
under.cntrl.dev@gmail.com