Privacy Policy

Sadhana Lock · Effective 14 August 2026

There is no account, no advertising, and no server belonging to us. Your practice — your name, your streak, your japa counts, your reading, and the list of apps you guard — stays on your phone. We cannot see it.

The app does send anonymous diagnostics to Google Firebase: crash reports, and counts of things like "a lock appeared" or "a practice was completed". These carry no name and never say which app you opened. You can switch them off in Settings → Share anonymous diagnostics, and the app works identically with them off.

This policy explains what the app stores, what the permissions it asks for are used for, and every place data can leave your device.

1. Who we are

Sadhana Lock is published by Interludeapps. You can reach us at interludeapp.official@gmail.com.

2. What the app stores, and where

All of the following is written to private storage on your device. If you never sign in, none of it is sent to us or to anyone else — signing in is optional and the app works fully without it. If you do sign in, most of it is also saved with your Google account so that a new phone can bring it back; section 3 sets out exactly what travels and what does not.

WhatWhy
Your name, and the answers you give during setup (age range, iṣṭa devatā, and similar)To address you by name and choose which mantra and verses to show
Which apps you chose to guard, and your practice timesThis is the app's core function
Your practice history — sittings, duration, japa bead counts, streaksYour streak, your diya's growth, and the Insights screen
Your reading position in each scripture, and reading-plan progressSo a book reopens where you left it
Preferences — reminders on or off, your scripture languageTo honour your settings
Whether you have purchased Sadhana PlusTo unlock what you paid for, including when offline

Google backup

Android's own backup service is enabled for this app. If you have device backup switched on in your Google account settings, Android may copy the data above to your Google Drive, where it is governed by Google's privacy policy. We have no access to it. You can turn this off in your phone's system settings. Two things are deliberately excluded from backup: your device-specific setup state, and the cached record of your purchase.

3. Signing in with Google

Signing in is optional. The app is complete without it, and nothing in this section applies to you unless you choose it.

It exists for one reason: so that your practice survives a new phone. When you sign in, we receive through Google and Firebase Authentication:

and a copy of your practice is then saved against that account in Google Cloud Firestore, readable only by that account:

What is never sent, even when you are signed in

Which apps you have chosen to guard. That list stays on your phone and is never saved with your account. It is the most revealing thing this app holds, and we would rather not hold it — so when you set up a new phone you will be asked to choose those apps again. That is deliberate.

Also never sent: your device setup state, and the cached record of your purchase.

Turning it off, and removing it

You can sign out at any time in Settings → Account; your practice stays on the phone. Deleting your account removes the saved copy along with your name and email — see section 12, or the account deletion page.

4. Anonymous diagnostics

This is the one place where information about your use of the app leaves your device. It goes to Google Firebase — Analytics, Crashlytics and Remote Config — acting as our data processor, not to a server of ours.

Why it exists. This app's core mechanic depends on an Android accessibility service that several phone manufacturers shut down silently in the background. When that happens, the app looks fine and quietly stops guarding anything. Counting how often the service starts and stops across all installs is the only way we can see that failure at all — otherwise it reaches us only as a one-star review months later.

What is sent

WhatDetail
Crash and error reportsStack traces, the app version, the device model and Android version, and whether the accessibility service was running at the time
That a lock appearedA count only
That a practice was completedWhich practice mode, how many minutes, how many beads
That the emergency exit was usedHow many seconds passed first, and how many times that week
Setup progressWhich setup step was reached, and whether each permission was granted or declined
Purchase funnelThat the purchase screen was shown, from where, and whether a purchase started, completed or failed
Accessibility service started / stoppedThe reason this section exists
Coarse groupingWhether you have purchased, your scripture language, and roughly how many apps you guard (as a band: 0, 1–3, 4–6, 7+)
Collected automatically by FirebaseApp version, device model, Android version, country or region derived from your IP address, and a random per-install identifier Google generates. Your IP address is not stored by us

What is never sent

Switching it off

Diagnostics are on by default, and Settings → Share anonymous diagnostics turns them off at any time. Turning it off stops collection immediately, for the rest of that session and every session after. No feature of the app depends on it. Diagnostics are also never collected from development builds of the app.

Data sent before you switched it off stays with Google for a limited retention period and is then deleted automatically. Firebase's handling is described in Firebase's privacy documentation and Google's privacy policy.

5. Notifications from us

The app can receive occasional announcements through Firebase Cloud Messaging — a new scripture translation, or word that a bug affecting the lock has been fixed. These are broadcasts: they are not addressed to you individually, and receiving one tells us nothing about you. We do not store any device token, and we do not send re-engagement or marketing notifications. Announcements arrive on their own notification channel, which you can silence in Android's settings without affecting your practice reminders.

6. The accessibility service — what it can and cannot see

Sadhana Lock uses Android's Accessibility API for one purpose: to notice when an app you have chosen to guard comes to the foreground, so it can show your practice screen over it. Google requires apps using this API to explain exactly what they do with it, so here is the whole of it.

The service is technically incapable of reading your screen. It is declared with canRetrieveWindowContent="false", which means Android does not give it access to window content at all. It subscribes to a single event type, typeWindowStateChanged, and from that event it reads exactly one value: the package name of the app now in front, for example com.instagram.android.

It does not, and cannot:

The package name is compared against your guarded list and then discarded. It is never written to disk, never kept in a history, and never transmitted anywhere — including in the diagnostics described in section 4.

7. The apps on your phone, and how long you use them

To let you choose which apps to guard, the app asks Android for the list of apps that have a launcher icon. This list is shown to you and used to store your choices. It never leaves your device, and we never see it.

Sadhana Lock can also read Android's usage statistics — how long you have spent in each app today — but only if you grant Usage Access. This is optional. Without it the app works exactly as before; the only difference is that your guarded-app list is ordered alphabetically rather than by the apps that actually take your time, and the "Today's pull" card on the home screen stays hidden.

We ask for it in two places only — on the guarded-app list, and as an invitation on the home screen. We never ask for it during setup.

These numbers never leave your device. They are read on demand to draw a list and a few bars, and they are not stored on a server, not included in the diagnostics in section 4, and not shared with anyone. There is no copy of them anywhere but your phone.

You can withdraw Usage Access whenever you like, in Android Settings → Apps → Special app access → Usage access → Sadhana Lock. The app keeps working; it simply stops ordering by usage.

8. Other permissions

PermissionWhy it is needed
Display over other appsTo draw the practice screen above a guarded app
Alarms & remindersTo begin your practice window at the exact time you set
NotificationsThe gentle reminder when a practice time begins, and the announcements in section 4. Optional — you can switch it off in Settings
Run at startupTo restore your practice times after the phone reboots
Ignore battery optimisationOptional. Some manufacturers stop the app while the phone sleeps, and the lock then silently fails
Usage accessOptional. To order your guarded-app list by the apps that actually take your time, and to show today's minutes. Read on the device, never uploaded — see section 6
VibrationThe bead tick while counting japa
Network accessUsed by Google's billing library to reach the Play Store, and to send the diagnostics in section 4. The app fetches no content of its own — every verse and translation is bundled inside the app

9. Payments

Sadhana Plus is a subscription — monthly or yearly — handled entirely by Google Play. It renews automatically until you cancel, and you can cancel at any time in the Play Store; cancelling leaves you subscribed until the end of the period you have already paid for. We never see or receive your card, UPI ID, bank details, billing address, or any other payment information. Google tells the app only whether this Google account owns the purchase, and gives it a purchase token used to confirm it. When you start a purchase, the app passes Google a random token generated on your device — it identifies the installation for Google's fraud checks and contains nothing about you. Payments are subject to Google's privacy policy and the Google Play terms.

10. Sharing a verse

When you share a verse, the app draws an image into its own temporary storage and hands it to whichever app you pick from the Android share sheet. What happens next is governed by that app's privacy policy, not ours. Nothing is uploaded by Sadhana Lock.

11. Children

Sadhana Lock is not directed at children. Unless you sign in with Google — see section 3 — we collect no personal data from anyone of any age, and the diagnostics in section 4 are anonymous either way, carrying no identifier we created. Under India's Digital Personal Data Protection Act, 2023, a person under eighteen should use the app with the consent of a parent or guardian.

12. Your data, and deleting it

On your phone. Everything about your practice sits on your phone and is yours. You can erase all of it at any time by clearing the app's storage in Android Settings, or by uninstalling the app. If you have Google backup enabled, remove the backup from your Google account settings as well.

The copy saved with your account, if you signed in. Open Settings → Account → Delete account. This erases your name, your email, the account identifier and the saved practice, and cannot be undone; the copy on your phone is untouched. If you have already uninstalled the app, or would rather we did it, the account deletion page explains how to ask — we reply within 7 days and complete deletion within 30.

Because the diagnostics in section 4 carry no identifier we created, we cannot look up, isolate, or delete "your" diagnostic data — there is nothing in it that points back to you. If you would rather send none of it, switch it off in Settings. If you have a question about any of this, write to us and we will answer.

13. Changes to this policy

If what the app collects ever changes, this page will be updated before that version is released, and the effective date above will change.

14. Contact

Questions about this policy: interludeapp.official@gmail.com.