Locknest

Privacy Policy

Last updated 2026-09-01

Who we are

Locknest is a digital-wellbeing and app-blocking app with optional family controls, made and operated by Md Mahabubur Rahman, an independent developer based in Dhaka, Bangladesh, who is the data controller for the data described here. Privacy contact: tulx.app@gmail.com.

You do not need an account

Locknest works without one. In that mode your blocking rules, your run-time points and your settings are stored on your device only.

What we collect

DataWhenWhy
A random install ID, app version, platform, language Every install, on launch Operate the service, deliver remote configuration, and see which versions are in use
Name and email (or, for a child, a username), hashed password, role Only if you create an account Sign-in, the sign-up bonus, and syncing your wallet and rules across devices
A child's name, username, which apps they use and for how long, and the rules set for them Only on a device a parent manages To provide the monitoring and parental controls that parent asked for
Points balance and rewarded-ad counters Signed-in users Keep earned run-time across devices, and stop the daily ad cap being bypassed
Device and advertising identifiers, via Google AdMob When you choose to watch a rewarded ad Serve the ad that funds the free tier

Screen-time data read through Android Usage Access stays on your device unless a parent manages that device. We do not sell personal data.

Children

Children are never shown ads. On a device signed in as a child the advertising SDK is not started at all, and we never serve behavioural advertising to a child.

Child accounts are created and managed by a parent, and we collect the minimum needed for parental controls. Parents can review and delete their child's account and data at any time.

Advertising and your choices

Locknest is free and funded by optional rewarded ads that you choose to watch. In the EEA and UK we ask for your consent through Google's certified consent platform before any ad is requested, and if you decline, none is requested. You can change that choice at any time in Settings → Ad privacy settings.

Legal bases (GDPR)

Providing and securing the service (contract and legitimate interests); remote configuration and abuse prevention (legitimate interests); advertising (consent); child data (the consent of the holder of parental responsibility).

Retention

Account data is kept while the account exists. Anonymous install telemetry is retained for 18 months and then deleted or aggregated. Backups are retained for 30 days.

Your rights

You can access, correct, delete, export, and object to or withdraw consent for the processing of your data. Parents may exercise these for their children. Delete everything from inside the app at Profile → Account → Delete account, which removes your account, usage history, rules and tokens. You can also write to tulx.app@gmail.com.

Sharing

We share data only with Google AdMob (advertising, never for child accounts) and our hosting provider, or where the law requires it.

Security

Traffic is encrypted with HTTPS, passwords are hashed, and access to production data is least-privilege.

Changes

We post changes on this page and update the date above. Questions: tulx.app@gmail.com.