Privacy Policy for Forslow
Last Updated: August 31, 2026
This Privacy Policy explains how Forslow (“we,” “our,” or “us”) handles data when you use the Forslow mobile application (the “App”), available on the Google Play Store under the package name com.forslow.app. Forslow is published by Ammar / Forslow Digital Wellbeing (“Developer”).
Forslow is a personal digital well-being and mindfulness utility. Our core operational philosophy is local-first data processing. The App does not require user accounts, registration, or cloud-based data storage. All configurations, app-blocking rules, and screen-reflection preferences remain strictly local to your Android device and are never transmitted to our own servers.
Please read this Privacy Policy to understand how we access, process, and handle information to support your digital well-being.
Note: This document is provided as a practical, Play-Store-ready template based on Google Play policies and standard mobile-app privacy practice. It is not a substitute for advice from a qualified attorney. We recommend a final legal review before publishing.
1. Google Play Developer Policy Compliance (Digital Well-being Utility)
Forslow is classified under the Digital Well-being / Productivity category. To help you manage intentional screen time and prevent compulsive app usage, the App requires specific system-level permissions.
In strict compliance with the Google Play Developer Program Policies:
- We request only the permissions absolutely necessary to deliver the digital well-being blocking and reflection features.
- All data accessed via sensitive permissions is processed in real-time and locally on the device.
- We do not collect, store, log, or transmit your personal or sensitive usage history to any remote servers we operate.
2. Sensitive Permissions & How We Process Data Locally
To perform its core digital well-being functions, Forslow requires the following permissions. Each is explicitly granted by you during setup:
A. App Usage & Active Screen Monitoring (Usage Access)
- API/Permission Name:
PACKAGE_USAGE_STATS(Usage Access) - Purpose: To detect when you attempt to open distracting apps that you have chosen to block, so the App can intercept them and display a mindfulness reflection gate.
- Local Processing: The package name of the active foreground app is checked in a real-time local loop. We do not record or maintain logs of your app usage history, nor do we ever transmit this information off your device.
B. List of Installed Applications
- API/Permission Name:
QUERY_ALL_PACKAGES - Purpose: To display a list of your installed apps inside the settings dashboard, enabling you to search and select which specific apps you wish to add to your personal blocklist.
- Local Processing: The package query runs entirely on your device. The list is only used to build the picker interface and is never uploaded, shared, or compiled outside the App.
C. Display Over Other Apps (Overlay Permission)
- API/Permission Name:
SYSTEM_ALERT_WINDOW - Purpose: To display a fullscreen mindfulness gate and a floating, draggable countdown timer pill directly over the apps you have blocked.
- Local Processing: The overlay displays only the App’s reflection interface and countdown graphics. It has no capability to read, track, or capture any input, text, keystrokes, or user data from the background application you are blocking.
D. Run Persistently in Background & Auto-Start
- Permissions:
FOREGROUND_SERVICE,FOREGROUND_SERVICE_SPECIAL_USE, andRECEIVE_BOOT_COMPLETED - Purpose: Runs a persistent background monitoring service (with a visible notification) and registers a receiver to restart the monitoring service on device boot. This ensures your self-imposed digital well-being configurations remain reliable even after system restarts.
- Local Processing: No user data or usage metrics are collected by these background services.
E. Battery Optimization Exemption
- Permission:
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS - Purpose: Prompts you to exempt Forslow from system sleep limits to prevent Android from closing the monitoring service.
F. Wake Lock
- Permission:
WAKE_LOCK - Purpose: Prevents the device CPU from entering deep sleep during the foreground monitoring service’s polling cycle so monitoring runs reliably.
G. Vibrate (Haptic Feedback)
- Permission:
VIBRATE - Purpose: Provides a brief vibration when the reflection gate or countdown timer overlay appears.
H. Post Notifications
- Permission:
POST_NOTIFICATIONS - Purpose: Posts the persistent foreground service notification (“Forslow Focus Assist is active”).
I. Internet Connectivity
- Permission:
INTERNET - Purpose: Required solely for Firebase Crashlytics and Firebase Analytics to transmit anonymized diagnostic and crash data (see Section 3). No personal data, app usage history, or blocklist information is transmitted to us.
3. Telemetry and Diagnostic Tools (Third-Party SDKs)
To monitor app stability and improve the product, the App integrates Google Firebase services. These services may collect technical, non-personally-identifying diagnostic data over an internet connection:
- Firebase Crashlytics collects anonymized crash reports, stack traces, device model, operating system version, and system state details to help us fix bugs. Crashlytics also receives an anonymous, app-scoped installation identifier.
- Firebase Analytics collects anonymous app-interaction events to help us understand feature usage. These events may include:
- Screen views and navigation (e.g., Home, Permissions, App Picker, Diagnostics).
- Your configuration actions, including the package names of the apps you add, remove, or toggle in your blocklist, and your chosen pause/countdown durations.
- Anonymous diagnostic properties such as blocklist size and whether optional permissions are granted.
- An anonymous, app-scoped user identifier (not your name, email, or any account) so related events refer to the same installation.
What we do NOT send to Firebase or any third party: your continuous app-usage history, the content of any app you open, your quotes, or any personally identifying information. The package names referenced above identify which apps you chose to block — they are configuration data, not personal or usage-history data, and are not linked to your identity.
These SDKs do not collect names, emails, phone numbers, or account details. Firebase is a Google service; data is processed under Google’s policies. For details see the Google Privacy & Terms and Firebase Privacy Policy.
4. Data Stored On Your Device
All of the following are stored locally in Android’s SharedPreferences and never leave your device:
- Your blocklist (the apps you choose to block).
- Your custom and built-in reflection quotes.
- Your settings (countdown duration, pause state, permission flags, battery-optimization status).
- Local usage/timer statistics (e.g., gate counts and durations) used to show your progress.
- An anonymous, app-scoped identifier used for diagnostics.
We operate no backend servers and synchronize nothing to the cloud.
5. Data Sharing & Disclosure
- We do not sell, trade, rent, or share your personal information with advertisers or third parties.
- CCPA/CPRA: We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA), and we do not use cross-context behavioral advertising. We do not process sensitive personal information for the purpose of inferring characteristics about you.
- The only external processor is Google (Firebase), used solely for crash reporting and anonymous analytics as described in Section 3. Google acts as a data processor, not an independent seller of your data.
- We may disclose information if required by law, lawful government request, or to protect the rights, property, or safety of the Developer, the App, or its users.
6. Data Safety Form Alignment (Google Play)
Consistent with our Play Console “Data safety” declaration, the App:
- Collects: App interactions (anonymous analytics events, including the package names of apps you configure in your blocklist), Crash logs, Diagnostics, and Device or other IDs (anonymous Firebase installation/App ID).
- Shares: No data with any party other than Google (Firebase) as processor.
- Encryption: Data transmitted to Firebase is encrypted in transit (HTTPS/TLS).
- Data deleted on uninstall: All locally stored data is removed when you uninstall the App.
7. Legal Bases for Processing
Where applicable (e.g., under the EU/UK GDPR), we rely on:
- Consent — for optional analytics and crash diagnostics (you may opt out via your device settings).
- Legitimate interests — to secure, maintain, and improve the App (e.g., fixing crashes).
- Contract — to provide the features you request when you use the App.
- You may withdraw consent for analytics and crash diagnostics at any time via your device settings; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. International Data Transfers
Firebase operates globally as part of Google’s infrastructure. If you are located outside the United States, your anonymized diagnostic and analytics data may be processed in the United States or other countries. Google relies on Standard Contractual Clauses and other lawful transfer mechanisms for such transfers.
9. Security
- All locally stored data remains on your device and is not transmitted to us.
- Data sent to Firebase is encrypted in transit using TLS.
- The App’s release builds are obfuscated and signed; we guard our signing keys. No app can be published under our identity without our upload key.
- No method of transmission or storage is 100% secure; we strive to use commercially reasonable safeguards.
10. Data Retention
- Local data: Retained on your device until you clear the App’s storage/cache or uninstall the App.
- Firebase Crashlytics: Crash data is automatically deleted after 90 days.
- Firebase Analytics: Retained per Google’s analytics retention settings (default 2 months event data, with some aggregates longer).
11. Your Rights & Data Deletion
Because all personal configuration data is stored locally, you have complete control:
- Delete all local data: Clear the App’s storage/cache in Android Settings, or uninstall the App.
- Opt out of analytics/crash reporting: Disable them in your device’s Google/Android ad and usage settings, or via your device privacy controls.
- Request deletion of Firebase data: Email [email protected]. We will action verifiable requests to delete associated anonymous analytics/crash data where feasible under Google’s retention policies.
For users in the EEA/UK (GDPR) and California (CCPA/CPRA), you have rights to access, rectification, erasure, restriction, portability, and objection to processing of your data. To exercise any right, contact [email protected]. We respond within applicable statutory timeframes and will not discriminate against you for exercising your rights. You also have the right to lodge a complaint with a data protection supervisory authority in your country of residence. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
12. Children’s Privacy
Forslow is intended for individuals aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has accessed the App, contact us and we will take appropriate action.
13. Cookies and Tracking
The App itself does not use cookies or browser-based tracking. Any website we operate (e.g., forslow.app) is governed by its own notice where applicable.
14. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in Google Play Policies, laws, or App features. We will update the “Last Updated” date above and, for material changes, provide additional notice. Continued use after changes constitutes acceptance.
15. Contact Us
Questions about this Privacy Policy or your data? Contact:
- Email: [email protected]
- Data Controller: Ammar, trading as Forslow Digital Wellbeing — the controller of the personal data described in this Policy.