Privacy Policy
LOXN
Who we are
LOXN is developed and operated by Matěj Malý, an individual developer based in the Czech Republic, European Union.
As a developer based in the EU, this policy is written to comply with the General Data Protection Regulation (GDPR). If you are located in another jurisdiction, additional local laws may apply.
What data we collect, and where it stays
LOXN is designed to collect as little data as possible. Everything described below is stored exclusively on your device and is never transmitted to any external server or third party by us.
NFC card identifier
When you register an NFC card or tag, the app reads the card's hardware identifier (UID). This identifier is immediately converted into a one-way SHA-256 hash, a mathematical fingerprint that cannot be reversed to recover the original UID. Only this hash is stored, in your iPhone's Keychain. The raw UID is never written to any storage, never logged, and never transmitted anywhere.
App blocking preferences
Your selected apps (which apps to block), timer settings, and lock profiles are stored locally on your device using iOS App Groups shared storage. This data is only accessible to LOXN and its on-device extensions. It is never transmitted anywhere.
Note: LOXN never learns the names of the apps you choose to block. Apple's Screen Time API returns only anonymous tokens, so the actual app identities remain private, even from us.
Biometric authentication (Face ID / Touch ID)
If you choose Face ID or Touch ID as your unlock method, authentication is performed entirely by iOS through Apple's LocalAuthentication framework. LOXN never receives, sees, or stores your biometric data. iOS only returns a simple success-or-failure result. The press-and-hold unlock method involves no data at all.
Subscription status
Your subscription is managed entirely by Apple via the App Store and StoreKit. LOXN verifies your subscription status directly through Apple's framework, client-side. We never receive, store, or process your payment information, Apple ID, or billing details. For information on how Apple handles your data, see Apple's Privacy Policy.
System notifications
LOXN may send local notifications to your device, for example to inform you that your apps have been automatically re-locked. These notifications are generated entirely on-device and do not involve any data being sent to external servers.
Motion & activity data
If you enable Morning Lock, LOXN may check your device's recent motion and activity data through Apple's CoreMotion framework at your first unlock of the morning. This is used for one purpose only: to detect whether you have clearly been up and moving for a while, so the app can decide whether to skip the Morning Lock hold. The check happens entirely on your device, in the moment: the motion data is read, evaluated, and discarded. It is never stored, never logged, and never transmitted anywhere, and we never receive it. Granting motion access is optional; if you decline, Morning Lock simply always applies its hold.
Photo library (saving only)
When you tap Save on a streak share image, LOXN writes that single image to your photo library using iOS's add-only photo access. The app cannot read, browse, or access any existing photos. It can only add the image you explicitly asked it to save. No photo data is ever transmitted to us or anyone else.
Sharing a streak image
If you choose to share your streak image (to Instagram, Messages, or any other app via the system share sheet), the image and a link to LOXN's App Store page are handed to the app you picked. That app then handles them under its own privacy policy, not ours. This only ever happens when you tap a share destination yourself. We receive nothing.
Streak rewards
If you reach a long-streak reward, LOXN shows you a screen and invites you to send us a screenshot of it as a direct message on Instagram. This is entirely optional and entirely outside the app: nothing is transmitted automatically, and the app never collects your name, address, or contact details for this. If you choose to message us, that conversation is held in Instagram under Meta's privacy policy, and any details you give us to fulfil a reward are used solely for that purpose and deleted afterwards.
What we do NOT collect
- No name, email address, or any personal identifiers: unless voluntarily provided via feedback submission (see §07)
- No user accounts of any kind
- No usage analytics or behavioral tracking
- No crash reports sent to third-party services
- No advertising identifiers (IDFA)
- No location data
- No payment card numbers or billing information
- No raw NFC card UIDs: only the one-way hash described above
- No biometric data: Face ID and Touch ID are handled entirely by iOS; we never receive your biometric information
- No information about which specific apps you block
- No motion or activity data is ever stored or transmitted: the optional Morning Lock check is evaluated on-device and immediately discarded
- No access to your existing photos: the app can only add a streak image you explicitly choose to save
- No contacts, calendar, microphone, camera, or health data
- No device or advertising identifiers of any kind, and no fingerprinting
Legal basis for processing (GDPR)
Under the GDPR, we process the minimal data described above on the following legal basis:
- Contractual necessity: The hashed NFC identifier and blocking preferences are required to deliver the core functionality of the app you have chosen to use.
- Legitimate interests: Local system notifications are sent to inform you of events directly related to your use of the app (e.g. auto-relock), and the optional Morning Lock motion check is evaluated on-device to deliver a feature you enabled. These are essential to the relevant feature's purpose and impose no privacy risk, as they are entirely on-device.
- Consent: When you voluntarily submit feedback, you provide your email address and message. This is entirely optional and based on your explicit choice to contact us. You may request deletion of this data at any time by contacting privacy@lockin.cz.
Data storage and security
All data created by LOXN is stored on your iPhone using the following mechanisms:
- iOS Keychain: The hashed NFC card identifier is stored here with the access flag
kSecAttrAccessibleWhenUnlockedThisDeviceOnly. This means it is encrypted by iOS, cannot be read when the device is locked, and is not included in iCloud backups. - App Groups storage: Preferences and lock state are stored in a shared container accessible only to LOXN and its on-device extensions.
No data is stored in the cloud, on any server operated by us, or in any iCloud-synced location.
Third-party services
LOXN does not integrate with any third-party analytics or advertising services.
The following third-party services are involved:
- Apple App Store / StoreKit: handles subscription purchases. Governed by Apple's Privacy Policy.
- Apple App Store lookup service: at most twice a day, the app asks Apple's public lookup endpoint (
itunes.apple.com/lookup) which version of LOXN is currently on the App Store, so it can tell you when an update is available. The request contains only the app's own public bundle identifier. No information about you, your device, or your usage is included. Governed by Apple's Privacy Policy. - Cloudflare: provides the infrastructure that hosts our website and the secure endpoint that delivers optional feedback submissions (email address and message only) to our inbox. Cloudflare acts as a data processor for this traffic. Governed by Cloudflare's Privacy Policy and their Data Processing Addendum. The feedback portion only applies if you choose to submit feedback.
Feedback data
When you choose to submit feedback through the app, we collect:
- Your email address
- The feedback message you write
This information is transmitted over an encrypted (HTTPS) connection to an endpoint we operate ourselves on Cloudflare, which relays it directly to our private email inbox. We do not use any third-party form-hosting or email-marketing service, and your feedback is not stored in any third-party database. We use it solely to read your feedback and respond if needed. We do not sell, share, or use your feedback data for advertising or analytics.
Feedback submissions are optional. The app is fully functional without them.
Feedback emails are retained in our inbox indefinitely. To request deletion of a specific feedback submission, contact us at privacy@lockin.cz and we will delete it promptly.
Your rights under GDPR
As a person based in or accessing the app from the European Economic Area, you have the following rights:
- Right of access: You can request a description of what data the app holds about you.
- Right to rectification: You have the right to correct inaccurate data. Since all data is stored locally on your device, you can update your preferences and registered card directly within the app at any time.
- Right to erasure: You can delete the data stored by LOXN from within the app: go to Settings → Delete My Data. This removes your registered NFC card from the Keychain and wipes your stored preferences, and returns the app to a first-launch state. Two things are deliberately kept, and neither identifies you: the count of emergency unlocks used in the current calendar month (so a reset cannot be used as an unlimited-unlocks button), and the local record of whether you have an active subscription (so a reset does not cost you something you paid for). Because your apps must not be left blocked by a deletion, this option is available while your apps are unlocked; unlock first, then delete. Deleting the app from your device removes everything unconditionally, at any time, and is always available to you.
- Right to portability: The data stored is minimal and device-local. There is no server-side data to export.
- Right to object: You may contact us at any time with concerns about how your data is processed.
To exercise any of these rights, contact us at privacy@lockin.cz. Because we hold no personal data on any server and cannot identify you, most requests are best fulfilled by using the in-app deletion option.
You also have the right to lodge a complaint with the Czech supervisory authority: Úřad pro ochranu osobních údajů (UOOU), www.uoou.cz.
Children's privacy
LOXN is intended for users aged 13 and older, in line with the minimum age in our Terms of Use and with the App Store age rating on its listing. It is not directed at children under 13, and we do not knowingly collect any data from them.
Almost nothing in LOXN involves personal data at all: your settings, your blocked apps and your streak never leave your phone. The one exception is the optional feedback form, which asks for your email address and relies on your consent. In some countries, including the Czech Republic, a person under 15 needs a parent or guardian's consent to give personal data on that basis, so if you are under 15 please ask them before sending feedback.
If you believe a child has used the app and you have concerns, contact us at privacy@lockin.cz and we will delete anything we hold.
Changes to this policy
We may update this privacy policy from time to time, for example when new features are added that involve different data handling. When we do, the "Last updated" date at the top of this page will change. If any material change affects how your data is handled, we will provide notice through the app or the App Store listing.
We encourage you to review this policy periodically.
Contact
For any privacy-related questions, requests, or concerns: