Privacy at a glance
AppAddiction is provided by Sohitech. It helps people create intentional pauses around selected Android apps and, when explicitly configured, lets a Guardian see limited health information from paired Child devices.
Information kept on your phone
AppAddiction uses Android usage events to identify the foreground app and measure active time for apps selected on that device. The following information is stored locally:
- selected app/package identifiers and per-app timing rules;
- daily usage totals, goals, streaks, and completed-session results;
- monitoring state, appearance preferences, and permission readiness;
- Child-device settings and the encrypted local settings PIN, when Child mode is active.
This information remains until it is cleared in AppAddiction, removed through account deletion where applicable, or the app is uninstalled. Android device backups may retain limited app data until the device or backup provider replaces it.
Information processed by our services
Optional account and membership
When a Guardian or subscriber signs in with Google, Firebase Authentication processes the Google account identifier, email address, display name, and profile information needed to sign in. Our backend stores a pseudonymous account identifier, verified membership state, encrypted Google Play purchase tokens, and short-lived checkout records. We never receive payment-card details.
Guardian and Child pairing
A paired Child device sends a generic device label chosen during pairing, random installation/device identifiers, AppAddiction version, permission readiness, monitoring on/off status, and last-seen time. A Guardian can view this limited status and unpair the phone.
App names, app-usage history, screen content, messages, URLs, typed text, and keystrokes from a Child phone are not sent to the Guardian or our backend.
Deletion requests
If you use the form below, this website stores the account email, optional details, request status, timestamps, and a reference code so Sohitech can verify and complete the request. The email and optional details are encrypted in the website database.
Android permissions
- Usage Access measures foreground time for selected apps.
- Display over other apps presents the user-configured pause intervention.
- Notifications shows visible monitoring status and fallback alerts.
- Foreground service keeps user-started monitoring reliable while showing a persistent notification.
Initial setup can be skipped. Permissions can be reviewed or revoked later through AppAddiction Settings and Android system settings.
Ads and consent
Rewarded ads may appear only when a Free Self Monitoring user chooses to continue at an eligible intervention. Premium, Guardian, and Child modes do not show rewarded ads.
Google Mobile Ads and Google's User Messaging Platform may process network information, consent choices, approximate location inferred from IP, app/ad interactions, diagnostics, and device or other identifiers such as App Set ID. AppAddiction removes Advertising ID and Android Privacy Sandbox ad-ID, attribution, and topics permissions from its manifest.
Where required, AppAddiction requests consent before requesting ads and provides access to privacy choices. Learn more about how Google uses information from partners' apps.
Service providers and sharing
We do not sell personal information. We use service providers only to operate AppAddiction:
- Firebase Authentication and App Check for account and application integrity;
- Google Cloud Run, Firestore, Cloud KMS, and Pub/Sub for backend, storage, encryption, pairing, and subscription events;
- the Cashcaw website host, database, and configured mail provider for deletion-request intake and private administrative notification;
- Google Play Billing and Android Publisher services for purchases and membership verification;
- Google Mobile Ads and User Messaging Platform for the optional rewarded-ad path.
Information may also be disclosed when required by law, to protect users and the service, or during a business transfer subject to appropriate safeguards.
Retention and security
Backend account, entitlement, and pairing records are retained while the account or pairing is active. Pairing codes and abuse-prevention records expire automatically. Purchase records retained by Google are governed by Google's policies.
Deletion requests remain pending until ownership is verified and the request is completed. The request record is scheduled for deletion no later than 30 days after completion. Limited information may be retained longer where reasonably necessary for security, fraud prevention, dispute resolution, or legal compliance. Encrypted backups can retain deleted records until the documented backup-retention period ends.
Network requests use HTTPS. Sensitive purchase tokens are encrypted with Google Cloud KMS. Account routes require Firebase Authentication and Firebase App Check. Child status uses a revocable device credential. The website deletion form uses Laravel CSRF protection, rate limiting, encrypted database fields, and does not load advertising or analytics scripts. Laravel may set a strictly necessary session/CSRF cookie for form security; it is not used for advertising.
Your choices
- stop monitoring or revoke Android special access;
- clear local results and update timing rules;
- change ad privacy choices where available;
- unpair Child devices;
- manage or cancel a subscription through Google Play;
- delete an account in AppAddiction under Settings → Privacy, or submit the form below.
For privacy questions connected to an account-deletion request, include them in the optional details field. This policy will be updated when AppAddiction's data practices materially change.
Account deletion
Request deletion without the app
Enter the Google account email used with AppAddiction. Sohitech may contact that address to verify ownership before deleting the account. Do not enter a Child's name or any unrelated sensitive information.
A verified account-deletion request covers the Firebase Authentication identity and AppAddiction backend records linked to it, including entitlement data, encrypted purchase-token links, checkout intents, pairing codes, Guardian pairing state, and paired Child-device records. Local app data is cleared by the in-app deletion flow or by uninstalling AppAddiction.