Privacy Policy
Effective: September 10, 2026
This policy explains how personal data is processed when you use the Reblock Android app, visit reblockapp.com, join the launch waitlist, create an account, contact us, or purchase a subscription.
1. Controller
Monika Hoeltzenbein-Pfaff, trading as ReblockIm Langenfeld 4a
61350 Bad Homburg
Germany
Email: hello@reblockapp.com
“Reblock”, “we” and “us” in this policy refer to this controller. Privacy requests can be sent to the email address above.
2. Data we process
Website and waitlist
- Technical request data: IP address, date and time, requested URL, browser/device information, referrer and security or error information generated when the site is delivered.
- Website analytics: aggregated or pseudonymous page-view, referral, device and performance information supplied by Vercel Analytics, Speed Insights and, if you accept optional analytics, Google Analytics.
- Waitlist data: the email address you enter, submission time and related consent or delivery information processed through Loops.
- Local storage: a timestamp stored in your browser for approximately one minute to prevent repeated waitlist submissions, your analytics-consent choice and, on blog pages, your selected light or dark theme.
- Contact data: your email address and anything you include when contacting us.
Account and authentication
- Email address, display name, account identifier and authentication status.
- Password-derived authentication data, verification codes and security events processed by Clerk. Reblock does not receive your readable password.
- If you choose Google sign-in: Google account identifiers and profile information that Google and Clerk make available for authentication.
Reblock app data
- Locally detected installed applications and Android app-usage information needed to provide blocking, screen-time statistics and focus features.
- Focus sessions, schedules, app limits, task and reminder settings, streaks, XP, daily statistics and onboarding or feature state.
- Profile information and an avatar if you upload one.
- Notification permission state, push token, time zone, reminder schedule, task title and optional custom reminder message when cloud reminders are enabled.
- Device, operating-system, app-version, diagnostic and event information used to operate and improve Reblock.
Some app data stays on your device. When you sign in or enable a cloud-backed function, relevant profile, progress, schedule, app-limit, statistics, avatar, reminder or event data may be synchronised to Reblock's cloud services.
Optional product analytics
If you select “Allow analytics” in the app, Reblock uses PostHog for product analytics and diagnostics. PostHog receives a pseudonymous device identifier, the stable Reblock/Clerk account identifier after sign-in, app lifecycle, screen and feature events, limited device/app details and exception diagnostics. IP anonymisation is enabled and Reblock uses PostHog's EU ingestion service. Reblock does not send your email address to PostHog and has disabled session replay, screen recordings and replay-based capture of text, images, logs or network-request metadata.
Subscriptions
Google Play processes purchases and payment credentials. Reblock and RevenueCat receive transaction identifiers, product and offer information, purchase status, entitlement status, renewal/expiry information and the Reblock account identifier used to provide paid access. Reblock does not receive your full payment-card number.
3. Purposes and legal bases
- Provide the app, account, cloud sync, reminders and paid features — Article 6(1)(b) GDPR: processing necessary to perform the user agreement or take requested pre-contract steps.
- Optional product analytics — Article 6(1)(a) GDPR: understanding feature use and diagnosing product problems after you choose “Allow analytics”. You may withdraw consent at any time without affecting earlier processing.
- Optional Google Analytics website measurement — Article 6(1)(a) GDPR: understanding page use, referral sources and successful waitlist submissions after you accept analytics. You may withdraw consent at any time.
- Limited operational analytics, fraud prevention and service security — Article 6(1)(f) GDPR: our legitimate interests in keeping Reblock reliable, preventing abuse and protecting accounts. We balance these interests against your rights.
- Waitlist launch email — Article 6(1)(a) GDPR and applicable electronic-marketing law: sending the launch update you requested. You can withdraw before it is sent.
- Support and communication — Article 6(1)(b) or 6(1)(f) GDPR: responding to requests and maintaining service records.
- Tax, accounting, consumer and legal obligations — Article 6(1)(c) GDPR.
- Legal claims — Article 6(1)(f) GDPR: establishing, exercising or defending legal claims.
Where data is required to create an account, provide a requested cloud feature or validate a subscription, not providing it may prevent that function from working. Optional permissions and consent-based processing are not required for unrelated core functions.
4. Service providers and recipients
We disclose only the data reasonably necessary for each service:
- Vercel: website hosting, request delivery, performance and website analytics.
- Google: Google Fonts, optional Google Analytics, optional Google authentication, Google Play distribution, billing and subscription management.
- Clerk: authentication, account management and account-security events.
- Supabase: database, cloud synchronisation, file storage and server-side functions.
- PostHog: consent-based product analytics and exception diagnostics. Reblock uses PostHog's EU ingestion endpoint with IP anonymisation and session replay disabled.
- RevenueCat: product offerings, purchase validation, entitlement state, restoration and subscription customer centre.
- Expo: push-notification delivery infrastructure.
- Loops: waitlist email and limited account/waitlist messaging data.
- Professional advisers and authorities: where necessary for legal obligations or claims.
Some providers also process limited data as independent controllers for their own legal, security or platform purposes. Google Play's purchase confirmation and the provider's own privacy information explain those activities.
5. International transfers
Some providers are established in or use subprocessors in the United States or other countries outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we rely as applicable on the European Commission's Standard Contractual Clauses and supplementary safeguards. Where a US recipient is validly certified, the EU-US Data Privacy Framework may be used. Copies or further information about applicable safeguards can be requested from us.
6. Retention
- Account and synchronised app data: while the account exists, then deleted or anonymised after a verified deletion request, subject to backup cycles and legal exceptions.
- Subscription and transaction records: for the subscription lifecycle and any longer period required by tax, accounting, fraud-prevention or legal-claims rules.
- Waitlist data: until the requested launch message has been sent, consent is withdrawn, or the waitlist purpose ends. Limited eligibility information may be retained to prevent repeat reward claims.
- Support correspondence: until the request is resolved and for as long as reasonably needed for follow-up or legal claims.
- Analytics, security and server logs: according to the configured provider retention period and no longer than needed for product improvement, reliability, abuse prevention or security.
- Backups: until overwritten under the relevant backup cycle, with access restricted to recovery and security needs.
When exact deletion is not possible or a legal retention duty applies, data is restricted from unrelated use and removed when the relevant period or purpose ends.
7. Your choices and device permissions
Android permissions for usage access, displaying over other apps and notifications can be managed in device settings. Removing a permission may disable the related blocking, statistics or reminder function.
You can cancel marketing consent by emailing us or using any unsubscribe option provided. In the Reblock app, you can allow or withdraw product analytics at any time under Settings → Product Analytics. The app starts with analytics disabled until you make a choice. You may change the website analytics choice by clearing site data and choosing again. Refusing or withdrawing optional analytics does not affect the app, account or subscription functions.
The website does not use advertising cookies. Google advertising storage, advertising user data and advertising personalisation are disabled. Google Analytics storage starts disabled and is enabled only if you select “Accept analytics”. The site also uses the short-lived waitlist rate-limit value, the analytics-consent choice and the optional blog theme value described above. Third-party resources still receive ordinary network-request data when loaded.
8. Your rights
Subject to the GDPR's conditions and exceptions, you may request access, correction, deletion, restriction, data portability and objection. You may withdraw consent at any time. Where processing is based on legitimate interests, you may object for reasons arising from your particular situation. You also have an unconditional right to object to direct marketing.
Send requests to hello@reblockapp.com. We may request proportionate verification. Account deletion instructions are available at reblockapp.com/delete-account.
You may complain to a data protection authority, particularly in the EU country where you live or work or where an alleged infringement occurred. Reblock's lead local authority is the Hessian Commissioner for Data Protection and Freedom of Information, Wilhelmstraße 7, 65185 Wiesbaden, Germany.
9. Security
We use access controls, encrypted transport, authenticated server functions and service-provider security measures designed to protect personal data. No internet service can guarantee absolute security. Please use a strong, unique password and contact us if you suspect unauthorised account access.
10. Children
Reblock accounts and paid services are intended for people aged 18 or older. We do not knowingly request personal data from children. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.
11. Changes to this policy
We may update this policy when Reblock, its providers or legal requirements change. The effective date above identifies the current version. Material changes affecting existing account processing will be communicated in the app, by email or through another appropriate notice where required.