Privacy Policy

Effective date: August 16, 2026

AppLock is an Android utility that lets you protect selected apps with a PIN, pattern, or optional system biometric authentication. Your protected-app list, credentials, settings, and app-usage events remain on your device. Eligible Google Play release bundles use Firebase Analytics for limited product events and Firebase Crashlytics for app stability. AppLock does not contain advertising SDKs and does not display ads.

1. Who We Are

This Privacy Policy applies to the Android app AppLock, package name com.ai.simple.applock.vault.password.locker. AppLock is provided by Quovad Studio. In this policy, "we", "us", and "our" refer to Quovad Studio.

For privacy questions, contact us at support@quovadstudio.cc.

2. Scope and Accounts

This policy describes the current data practices of AppLock. The app does not require an AppLock account, and we do not operate an account database, cloud backup, or cloud synchronization service for AppLock.

3. Installed Apps and Usage Events

AppLock queries apps on your device that have a launcher entry so it can display an app picker. It may process app names, icons, and package names locally. The apps you select are stored locally as your protected-app list. AppLock does not request broad QUERY_ALL_PACKAGES access.

After you grant Usage Access in Android settings, AppLock reads recent Android app-usage events to determine which app is currently in the foreground and whether it is one you chose to protect. This access is used only to trigger the local lock screen. AppLock does not use Usage Access to read screen text, messages, photos, files, keystrokes, passwords, browsing content, or content inside other apps.

App names, icons, raw package names, your protected-app list, and app-usage events are not intentionally sent to Firebase Analytics or Crashlytics.

4. Credentials and Biometric Authentication

AppLock does not store your PIN or pattern in plain text. It stores a versioned verification record derived locally using a random salt, PBKDF2-HMAC-SHA256, and key material protected by Android Keystore. AppLock also applies retry limits and temporary cooldowns after repeated failed attempts.

If you enable biometric unlocking, Android's system biometric service performs fingerprint or face enrollment, storage, and matching. AppLock does not receive, store, or upload fingerprint templates, face templates, or biometric images. It receives only limited authentication results such as success, cancellation, lockout, unavailability, or error. Your AppLock PIN or pattern remains available as the primary credential.

5. Local Settings, Reminders, and Diagnostic Logs

AppLock stores your protected-app list, global protection state, relock timing, onboarding state, biometric preference, notification preference, and related settings locally. If you enable new-app reminders, AppLock may temporarily store package names for newly installed launcher apps that you have not reviewed. This list is used only to create an aggregate local notification; apps are never added to protection automatically.

AppLock keeps bounded rolling diagnostic logs in its private app storage to help identify lifecycle, permission, protection-state, authentication-result, performance, and reliability issues. These logs are designed not to include PINs, pattern points, search text, app names, raw package names, biometric data, the anonymous installation identifier, or other user-entered content. The logs use up to four segments of up to 1 MiB each, with older segments overwritten. Complete local log files are not automatically uploaded to Firebase.

6. Permissions and System Capabilities

AppLock does not implement an Accessibility Service and does not request camera, microphone, contacts, location, photo, video, broad storage, Device Administrator, or advertising-ID permission. The final manifest explicitly removes advertising-ID and supported AdServices identifier permissions inherited from dependencies.

7. Firebase Analytics

Eligible production versions distributed as a Google Play Android App Bundle use Firebase Analytics to understand broad feature use and improve reliability. Debug builds and locally assembled APK builds are configured not to upload analytics.

Analytics events may describe the type of screen or onboarding step, credential method type, bucketed selected-app counts, permission actions and results, protection-health status, setting changes, biometric-authentication status, and bucketed new-app reminder counts. Firebase and Android may also provide app version, device type, operating system, language, region, session, and installation information.

We do not intentionally send PINs, pattern points, raw package names, app names, protected-app lists, usage events, search text, biometric data, authentication session identifiers, raw exception messages, or user-entered content to Firebase Analytics. We do not use Analytics for advertising or personalized advertising.

8. Firebase Crashlytics and Installation Identifier

Eligible production versions use Firebase Crashlytics to diagnose crashes, application-not-responding events, and selected non-fatal errors. Crashlytics may process exception types, privacy-reviewed stack traces and diagnostic codes, app version and build information, package name, device manufacturer and model, operating-system information, language, network connection type, session information, and limited technical state needed to investigate a failure.

AppLock creates a random anonymous installation identifier and stores it locally. The identifier is sent to Crashlytics as a user ID so we can correlate failures from the same installation. It is not an account, name, email address, advertising ID, Android ID, hardware serial number, IMEI, IMSI, or MAC address. Clearing app data or uninstalling and reinstalling AppLock replaces it.

9. Third-Party Services and International Processing

AppLock uses Google Firebase Analytics, Crashlytics, Installations, and supporting Firebase components. This Privacy Policy is published using Firebase Hosting. Google may process service data on servers outside your country or region under its applicable safeguards.

10. Sharing and Sale of Data

We do not sell or rent personal information and do not share personal information with advertising companies. Limited information may be disclosed only:

11. Retention and Deletion

Local settings, your protected-app list, and credential verification records remain until you modify or clear them, clear AppLock's storage, or uninstall the app. Pending new-app reminder entries remain until you review them, disable reminders, clear app storage, or uninstall. Local logs roll over within the size limits described above. Android automatic app-data backup and device-to-device transfer are disabled for AppLock.

Firebase retains Analytics, Crashlytics, installation, and session data according to our Firebase settings and Google's applicable retention practices. Because AppLock has no user accounts, there is no AppLock cloud account to delete. To request deletion of support correspondence or ask about service data associated with your installation, contact support@quovadstudio.cc. We may need technical information from you to identify a relevant record, and some service data may not be reasonably linkable to you.

12. Security and Your Choices

We use reasonable safeguards including Android private storage, Android Keystore-backed key material, salted credential derivation, constant-time verification, retry cooldowns, bounded and sanitized logs, validated analytics fields, and encrypted network connections for Firebase. No app-locking, storage, or transmission method can guarantee absolute security. Android background restrictions, device-vendor power management, split-screen use, force stop, revoked permissions, and usage-event latency can delay or suspend protection.

You can disable AppLock protection, biometrics, or new-app reminders in the app. You can revoke Usage Access, overlay, notification, or battery-related access in Android settings. You can clear all local data through Android's App Info screen or uninstall AppLock.

13. Children's Privacy

AppLock is a general-audience utility and is not specifically directed to children under 13. We do not knowingly ask children to provide personal information through the app. If you believe a child has provided personal information, contact us and we will take appropriate action.

14. Changes to This Policy

We may update this Privacy Policy as AppLock changes. The latest version will be posted on this page with a revised effective date.

15. Contact Us

For questions or requests about this Privacy Policy, contact support@quovadstudio.cc.

This page is provided for Google Play and in-app privacy policy access for AppLock.