Privacy Policy

Last updated 3 August 2026

This policy describes what LockIn actually does with your data — not what a template says. It is written to be read, so it is in plain English and it is specific.

Who we are

LockIn is operated by Musa Majid, an individual trading as LockIn in England and Wales.

Musa Majid is the data controller for the personal data described here. That means the decisions about what is collected and why, and the responsibility for it, rest with one identified person rather than an anonymous company. For anything to do with your data, including any of the rights set out below, email support@musa.codes.

What we collect

Everything in this list is stored on our servers. Most of it sits in our database (Google Firestore), attached to your account; where something is held differently — or, like the waitlist, without an account at all — the entry says so.

  • Your account details. Your email address, your display name, and your profile photo link if you signed in with Apple or Google. Also the date you signed up. If you signed up with an email address and password, Firebase Authentication separately holds that email address and a scrambled (hashed) version of your password — we never see or store the password itself.
  • Notification tokens. A push token for each device you use, so we can send you session invites and override alerts. It identifies the device rather than you personally — but we store it against your account.
  • Your plan and your stats. Whether you have LockIn Plus, your total focus minutes, sessions completed, current and longest streak, how many times you have used an override, and your focus minutes per day.
  • Your sessions. Each session you create or join: how long it was set for, when it started and ended, who took part, your status in it, and each emergency override — how many, and when.
  • Your friendships. Who you are friends with, who added whom, and when. Also the six-character friend codes you generate.
  • Your feed posts. If you share a finished session, we store your message (up to 280 characters), the focus minutes taken from that session, and the time. We also store which of the three emoji you react with on a friend's post.
  • Your notifications. The invites and alerts sent to you in the app, and whether you have read them.
  • Your block list — as a sealed envelope. We store how many apps, categories and websites you picked, and the selection itself as an opaque block of data created by Apple. See the next section for what that does and does not tell us.
  • Your email, if you join the waitlist on this website. This one has nothing to do with an account — you do not need one to join. We use the address once, to tell you when LockIn is out, and you can ask us to delete it at any time. Vercel, who host this site, also log your IP address briefly when you submit the form — see “Who we share it with” below.

What we do not collect

We do not collect which apps you open, when you open them, or how long you spend in them. Not for your blocked apps, and not for any other app on your phone.

LockIn blocks apps using Apple's Screen Time (Family Controls). The weekly chart in the app is drawn from measurements taken by a small Apple extension that runs on your iPhone. That extension writes a rough daily figure into a private storage area on the device that only LockIn can open. The app reads it back to draw the chart, and that is the end of it. Those figures are never sent to us, never written to our database, and never shared with anyone. Your phone clears out old ones each time it records new usage, so it never keeps more than 14 days' worth.

The selection of apps you block is a different thing, and we are precise about it because we do store it. When you pick your apps, Apple's own picker hands us a sealed block of data. Apple encrypts it, and only your device and Apple can open it. It contains no app names. We store it, we hand it back to your phone so blocking works, and we cannot read which apps you chose. What we can see is the number of items you picked, because the app records that count separately.

We do not collect your location, your contacts, your browsing history, your keystrokes, or an advertising identifier. The app contains no advertising or analytics trackers, and this website sets no advertising or analytics cookies.

To be equally clear the other way: we are not claiming to store nothing. Your account, sessions, friendships and posts are all held on our servers and are readable by us as the operator. LockIn is not anonymous and it is not end-to-end encrypted.

Why we collect it

Under UK GDPR we need a lawful basis for each use. Ours are:

  • To provide what you signed up for (contract). Your account, your block list, your sessions, your friends and your feed. Without this data the app cannot do its job.
  • To keep the service working and safe (legitimate interests). Preventing abuse and spam, expiring friend codes, checking session and override rules on our servers rather than trusting the app, and diagnosing faults. We have weighed this against your privacy and kept it to what the service needs.
  • Because you said yes (consent). Push notifications, and waitlist emails. You can withdraw consent for notifications at any time in Settings → Notifications → LockIn on your iPhone. Withdrawing it does not affect anything else in the app.

What other people can see

Your friends can see your display name and profile photo. That is the only part of your account anyone else can read — your email address and your notification tokens are not visible to other users.

In a session you share with a partner, they can see three things: that you are locked in, how long the session is, and whether you used an emergency override. That is all. They cannot see which apps you block, how you use your phone, your other sessions, or anything at all outside a session you are both in. Session records can only be read by the people taking part in them.

Feed posts are visible to you and to your accepted friends. There is no public feed, and no way for a stranger to find you.

How long we keep it

  • Your account and everything attached to it: until you delete your account. Then it goes.
  • Session history: 180 days after a session ends, then it is deleted.
  • Friend codes: they stop working 24 hours after you generate them, and are deleted the moment someone uses one.
  • Screen Time figures on your phone: never more than 14 days' worth, cleared out by the phone itself. We never had them in the first place.
  • Waitlist emails: until launch, or until you ask us to remove yours.

Who we share it with

We do not sell your data. We do not use it for advertising, and we do not give it to advertisers or data brokers. These are the companies involved in running LockIn:

  • Google is our processor. LockIn runs on Firebase — Authentication, Firestore, Cloud Functions and Cloud Messaging — so your data is stored and processed on Google's infrastructure on our instructions. That includes transfers to the United States, which rely on the UK Extension to the EU–US Data Privacy Framework and Google's standard contractual clauses.
  • Apple handles subscriptions. LockIn Plus is billed through the App Store, so Apple takes the payment. We never see or store your card details — only whether your account is on the paid plan. If you sign in with Apple, Apple also handles that sign-in.
  • Vercel hosts this website. If you submit the waitlist form, your email address passes through Vercel's servers on its way to us, and their request logs record your IP address for a short period. Vercel does not receive anything from the app itself.

We would also disclose data if the law required us to — a court order, for example.

Your rights

Under UK GDPR you have the right to:

  • Access — ask for a copy of the data we hold about you.
  • Rectification — have anything wrong corrected.
  • Erasure — have your data deleted.
  • Restriction — ask us to pause using it while something is in dispute.
  • Portability — get your data in a machine-readable form, or have it sent elsewhere.
  • Objection — object to us relying on legitimate interests, and withdraw any consent you have given.

To use any of them, email support@musa.codes. We will reply within one month.

Deleting your account does not need us at all. You can do it yourself in the app under Settings, or from our account deletion page. It removes your account record, your block list, your notifications, your friendships, your friend codes, the sessions you created, your posts and your reactions, your public name and photo, and your sign-in itself. Where you joined a session someone else created, that session stays for them — with you taken out of it. Deletion is permanent and cannot be undone.

If you think we have handled your data badly, please tell us first — but you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint (opens in a new tab) whether or not you have.

Age

LockIn is for people aged 16 and over. We do not knowingly collect data from anyone younger. If we find out that an account belongs to someone under 16, we delete it and its data. If you are a parent or carer and think we hold your child's data, email support@musa.codes and we will remove it.

Changes to this policy

If this policy changes, we will update this page and change the “Last updated” date at the top. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.