Privacy Policy for Sam App Lock

Last Updated and
Effective Date:
July 23, 2026

This Privacy Policy describes how Sam App Lock ("We", "Us", "Our", or the "Company") collects, processes, uses, and protects your personal data when you use our mobile application and related services.

We are committed to protecting your privacy in strict accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000, and Google Play Data Safety guidelines.

🛡️ Core Guarantee: 100% On-Device Security & Zero Tracking

Sam App Lock operates entirely on your local device. We do not collect, store remotely, transmit over the internet, sell, or share any of your personal data, PINs, biometric verification tokens, application usage statistics, or installed app lists with any third-party servers, cloud services, analytics providers, or advertisers.

1. Roles Under the DPDP Act, 2023

Data Fiduciary: Because Sam App Lock operates entirely locally on your Android device without transmitting, processing, or storing personal data on cloud servers or sharing data with third parties, we do not act as a server-side Data Fiduciary under the DPDP Act.
Data Principal: You (the user accessing and locking apps on your device) act as the Data Principal under Section 2(j) of the DPDP Act. You provide local authorization by granting system permissions, and retain full autonomy to modify or erase your security preferences instantly.

2. Notice of Itemized Data Collection (Section 5, DPDP Act)

We collect and process the following specific categories of personal data with your explicit consent:

A. Usage Access (PACKAGE_USAGE_STATS)

What is collected: Active foreground application package names detected locally via Android UsageStatsManager.
Purpose: Used to detect when you launch an application on your device so that Sam App Lock can immediately check if that app is locked and display the security lock screen overlay. No app usage history, launch timestamps, or tracking data is ever recorded remotely or transmitted off your device.

B. Display Over Other Apps (SYSTEM_ALERT_WINDOW)

What is collected: System overlay permission.
Purpose: Used exclusively to draw the secure PIN or Biometric lock screen overlay directly on top of protected applications when they are opened. Sam App Lock never captures, records, monitors, or transmits screen contents, keyboard inputs, or personal information from any application.

C. Query Installed Packages (QUERY_ALL_PACKAGES)

What is collected: Local list of installed applications on your Android device.
Purpose: Used to scan and list all installed applications on your device inside Sam App Lock so you can choose which applications you wish to lock and protect. The list is generated locally for configuration purposes and is never shared outside your device.

D. Device Administrator (BIND_DEVICE_ADMIN)

What is collected: Optional uninstallation protection authorization.
Purpose: Optional security feature requested strictly to prevent unauthorized users or intruders from uninstalling Sam App Lock to bypass your application locks. No administrative commands beyond uninstallation protection (lockTask / uninstall prevention) are executed. No device metrics, system configurations, or personal data are accessed or transmitted.

E. Biometric Authentication (USE_BIOMETRIC / USE_FINGERPRINT)

What is collected: Biometric verification status signals from Android BiometricPrompt.
Purpose: Allows you to unlock protected apps conveniently and securely using your device's built-in fingerprint or facial recognition sensor. Biometric verification is handled directly by the Android OS BiometricPrompt system. Sam App Lock never accesses, reads, collects, or stores raw biometric templates or fingerprint images.

F. Master PIN & Security Settings (PinManager / SharedPreferences)

What is collected: Your 4-digit or 6-digit master PIN and custom app lock toggles.
Purpose: Used to authenticate you when unlocking apps or modifying security settings. Your PIN is securely hashed and stored locally in encrypted on-device preferences (SharedPreferences). It is never transmitted to any external server.

Device Permissions & Justifications

To perform its advertised core functionality as an advanced time tracker, mission countdown tool, and exact alarm clock, our application requests specific operating system permissions:

PACKAGE_USAGE_STATS (Usage Access)
Monitors foreground app transitions locally to instantly trigger the lock overlay when a protected app is opened.
SYSTEM_ALERT_WINDOW (Display Over Other Apps)
Renders the secure PIN/Biometric authentication overlay directly over locked applications.
android.permission.QUERY_ALL_PACKAGES
Populates the in-app configuration list so users can select which installed apps to secure.
BIND_DEVICE_ADMIN (Device Administrator)
Optional anti-uninstall protection that prevents unauthorized intruders from removing the locker.
USE_BIOMETRIC / USE_FINGERPRINT
Enables seamless unlocking via system fingerprint/face sensors without handling raw biometric data.
INTERNET
Used solely to load developer profile pictures via GitHub and open official website links inside the About screen. No personal telemetry or usage data is transmitted across these connections.

3. Consent & Right to Withdraw Consent (Section 6, DPDP Act)

We obtain your explicit, affirmative consent via prominent in-app disclosures before requesting any system permission (Usage Access, Overlay, or Device Admin). All accessed permissions are used strictly for the stated security purpose.

Right to Withdraw Consent (Section 6(4))

You have the absolute right to withdraw your consent at any time. You can withdraw consent by:

Toggling off the protection service or removing specific apps from your locked list directly within the app.
Revoking system permissions directly in Android Settings (Settings > Apps > Special App Access > Sam App Lock).
Deactivating Device Administrator access (if enabled) via Settings > Security > Device Admin Apps.
Uninstalling the application, which immediately and permanently erases all locally stored preferences, hashed PINs, and configuration data from your device.

Since all data is processed strictly locally and wiped upon app uninstallation, we maintain zero external records or databases of your personal data.

4. Right to Erasure / Account Deletion (Section 12(3), DPDP Act & Google Play)

Because all your data exists exclusively inside your personal device's local storage (`SharedPreferences`), you have immediate and total control over its lifecycle.

In-App Deletion: You can modify your master PIN, change your protected app list, or adjust security preferences instantly within the app interface at any time.
Manual Deletion: Clearing the app's local storage (Settings > Apps > Sam App Lock > Storage > Clear Data) or uninstalling Sam App Lock completely erases all associated data and hashed PIN records from your device instantly without needing to submit server requests.

5. Third-Party Data Processors & Disclosure (Section 8 & Section 16)

We adhere strictly to data minimization and zero server-side harvesting. Sam App Lock does not integrate any third-party advertising SDKs, tracking pixels, or data analytics frameworks (such as Firebase Analytics, Crashlytics, or Google Ads). We do not sell, share, transmit, or disclose any of your data to any third-party processors or cloud servers. All data remains strictly on your local device.

6. Third-Party Services & Network Access

Sam App Lock does not integrate any third-party advertising SDKs, tracking pixels, or data analytics frameworks (such as Firebase Analytics, Crashlytics, or Google Ads). The application declares the INTERNET permission solely to enable optional links inside the "About" screen (such as loading developer profile pictures via GitHub and opening official website links). No personal data or telemetry is transmitted across these connections.

7. Data Security & Storage (Section 8(5))

Your 4-digit or 6-digit master PIN is securely hashed using cryptographic algorithms and saved in encrypted local preferences (`SharedPreferences`). Biometric authentication is delegated entirely to Android's secure hardware-backed `BiometricPrompt` framework. No security credentials ever leave your physical device.

8. Children's Privacy

Sam App Lock does not knowingly collect, store, or process personal data from children under the age of 13 (under COPPA) or under 16 (under GDPR-K). As the application does not collect personal data from any user, children's privacy is naturally and fully protected.

9. Developer Contact & DPDP Act Compliance (Section 8(9) & Section 13)

In compliance with Section 8(9) and Section 13 of the Digital Personal Data Protection Act, 2023, the contact details of the Developer are published below:

Name: Tanay (@Tanay2920003)
Role: Lead Developer
Co-Developer: Utkarsh (@utkarsh8700)
Response Timeline: If you have any questions, regulatory inquiries, or feedback regarding this Privacy Policy or our on-device security practices, please reach out via our GitHub repository or developer email.

Right to Approach the Data Protection Board (Section 13(3))

If your inquiry or grievance is not resolved to your satisfaction by the Developer, you have the statutory right to file a formal complaint with the Data Protection Board of India (DPBI).

10. Changes to this Privacy Policy

We may update our Privacy Policy periodically to reflect changes in legal or technical requirements. Any updates will be displayed directly within the application or published alongside new release versions on GitHub and Google Play.

11. European Union (GDPR) & California (CCPA) Privacy Rights

GDPR Legal Basis: European Union (GDPR) & UK GDPR: Under GDPR Article 6(1)(a) & Article 6(1)(b), local app selection and usage detection are processed strictly based on your explicit consent and performance of contract to deliver the requested application security locking functionality. You maintain full rights to access, rectification, and immediate erasure by clearing local app storage. No international data transfers occur.
CCPA "Do Not Sell or Share My Personal Information": California Consumer Privacy Act (CCPA / CPRA): We do not collect, sell, share, rent, or monetize any personal information of California consumers to third parties, data brokers, or ad networks. Uninstalling the application immediately fulfills all right-to-delete requests.