DEADSCROLL
Home Why We Nudge How It Works Permissions Support

Privacy Policy

Privacy Policy

DEADSCROLL is built to interrupt compulsive scrolling, not to turn your attention into an advertising product. This page explains what the app needs access to, what stays on your device, what you may choose to share, and where limited third-party processing may occur.

Current Policy Snapshot Effective Date: 6 September 2026

01Operator and scope

DeadScroll ("DEADSCROLL," "we," or "us") is an independently operated product based in India. This policy covers the Android app, the DEADSCROLL website, Google Play purchases, and the Firebase and Google Cloud services used to configure, secure, operate, and improve the product.

Privacy and grievance contact: product@deadscroll.app.

02Accessibility, Usage Access, and overlay permissions

DEADSCROLL uses Android Accessibility to detect when you open user-selected target apps and certain interface events, such as scrolling, so it can present the intervention you requested. Usage Access supports selected-app activity and on-device progress insights. Overlay access lets the intervention appear above a selected target app.

DEADSCROLL does not use these permissions to read or transmit messages, passwords, typed challenge text, or screenshots; make purchases; or change device settings without your action. Revoking a required permission can stop or reduce protection.

03Data kept on your device

Selected target-app package names, detailed app and session history, individual nudge attempts, challenge content, pause state, intervention settings, progress summaries, diagnostic transition stories, monetization milestones, and a token-free entitlement cache are stored locally. They support interventions and progress views; DEADSCROLL does not operate a cloud-sync account for this detailed behavioral history.

You can clear local behavioral history and diagnostics separately in the app. Those actions do not remove verified purchases or protection access. Android backup or device transfer may copy only the limited configuration allowed by DEADSCROLL's include-only backup rules. Analytics consent, analytics identity, pending analytics events, databases, debug state, notification state, and the local entitlement cache are excluded from those rules.

04Optional product analytics

Product analytics is optional, off by default, and controlled by an explicit choice during setup and in Settings > Data & Privacy. Protection continues to work if you decline it.

If you opt in, DEADSCROLL may send a resettable random analytics identifier and approved, bounded categories about setup steps and actions, permission state, selected-target count buckets, protection opportunities, nudge type and presentation, response and outcome, re-entry time buckets, pause and re-arm state, feature use, technical reliability, paywall and offer actions, value buckets, checkout failure categories, verified entitlement state, app/build channel, device category, operating system, and coarse country where retained by the approved Firebase configuration.

Firebase may create standard consented technical lifecycle events such as app open, app update, session, and engagement events. Automatic screen reporting is disabled. Those lifecycle events are not treated as DEADSCROLL's approved analytics facts for KPI or persona reporting.

DEADSCROLL does not send exact target-app package names or labels, installed-app lists, typed or challenge content, email addresses, payment methods, purchase tokens, order IDs, advertising IDs, or exact session, flow, or nudge-attempt identifiers as product analytics. App-family information is also absent unless the separate research choice and server safety gate described below are both enabled. We do not use analytics for advertising or ad personalization, and we do not sell analytics data.

Before you make the setup choice, disclosed onboarding events may be held temporarily on your device in a bounded queue for up to 24 hours. They are uploaded only if you opt in during setup; otherwise they are deleted. Opting in later from Settings does not upload that earlier setup queue.

05Optional crash diagnostics

Crash diagnostics is a separate, optional, default-off choice. If enabled, Firebase Crashlytics may receive crash traces, app/build information, operating-system and device information, and bounded technical failure state. Exact target-app names, analytics identifiers, commerce identifiers, and free text are blocked from crash keys.

06Optional app-family research

App-family research is a separate choice and is unavailable unless both product analytics and a server-side safety gate are enabled. When enabled, only the app involved in a configured target or nudge event is mapped on the device to a short allowlist of mainstream app families. All other apps are reported as other; exact package names and installed-app lists remain on the device. Small cohorts are suppressed, and this information is not used for advertising.

07Configuration and installation services

Firebase Remote Config provides safety switches and product configuration. Firebase Installations may create an app-installation identifier and process technical information needed to deliver those services. These operational services are separate from DEADSCROLL's optional schema-v2 product analytics.

08Purchases and entitlement verification

Google Play processes checkout, payment methods, receipts, subscriptions, refunds, and account-level purchase ownership. DEADSCROLL does not receive your full card or bank-account details.

When a purchase is made or restored, DEADSCROLL sends the Google Play purchase token, package/product type, and App Check attestation to protected Firebase Cloud Functions. The token is used to query Google Play, acknowledge eligible purchases, prevent duplicate entitlement records, and maintain subscription or One-Time Unlock access. The Android app stores only an opaque server entitlement identifier and token-free verified state.

Google Play Real-Time Developer Notifications may trigger entitlement updates for renewal, cancellation, payment grace, account hold, expiry, refund, revocation, or recovery. Notification IDs are retained temporarily for deduplication.

09Referral passes and shared badges

If you use the referral programme, DEADSCROLL generates a random installation identifier on your device and sends it, with a referral token and App Check attestation, to protected Firebase Cloud Functions. The server stores that identifier only in hashed form, for the sender and the receiver of a pass, alongside the pass token, its state, its timestamps, and a record of any reward granted. These records are not linked to your name, email address, Google account, or purchase identity.

If you install DEADSCROLL after following a shared referral link, the app reads the Google Play Install Referrer to recover the referral token that Google Play recorded with the installation, together with the installation and referral timestamps Google Play provides. This is used to attach the installation to the pass that sent it and to run the checks that prevent self-referral, duplicate rewards, and manufactured installations. It is not used for advertising or attribution beyond the referral programme.

Referral and reward records are retained while needed to administer, verify, audit, or lawfully account for the programme. You are not required to use referrals, and declining to do so does not affect protection.

Share badges are images DEADSCROLL renders on your device and hands to whichever app you choose to share them with. A badge can contain your estimated reclaimed time and nudge counts, and, only if you turn on the option that shows it, the name of one app. DEADSCROLL does not upload badge images to its own servers. Once you share a badge, the receiving app and its recipients control it, and that app's own terms and privacy policy apply.

10Purposes and legal grounds

We process data to provide the protection and purchase access you request, secure and verify transactions, prevent fraud and duplicate processing, maintain reliability, respond to support and rights requests, and comply with legal obligations. We use optional analytics and diagnostics only after the corresponding consent. You may withdraw that consent without affecting processing already lawfully completed.

11Service providers and international processing

Relevant data may be processed by Google Play, Google Firebase/Google Cloud, Android backup services, and website hosting provider Vercel, subject to their service terms and privacy safeguards. These providers may process data outside your country. We do not sell or rent personal data and do not use it for third-party advertising.

12Retention and security

Local data remains until removed through app controls, Android settings, or uninstall, subject to any permitted Android backup copy. Verified entitlement records are retained while needed to provide, restore, audit, or lawfully administer a purchase. Purchase-notification deduplication records are scheduled for deletion after 30 days.

The configured Google Analytics property retains event and user data for up to 14 months. Raw BigQuery analytics events are intended to be retained for no more than 425 days; while the project uses the no-cost BigQuery sandbox, its stricter automatic expiry applies instead. Exported aggregate or event data may remain until the applicable retention period expires or a verified deletion request is completed, subject to security, dispute, accounting, and legal requirements.

We use encrypted transport, access controls, server-side Play verification, App Check, least-privilege service identities, restricted analytics schemas, and token-free Android entitlement storage. No system can guarantee absolute security.

13Your choices and rights

In Settings > Data & Privacy, you can independently withdraw product-analytics and crash-diagnostic consent, reset the shared analytics identity, clear pending events, and clear on-device behavioral or diagnostic history. Turning analytics off stops future DEADSCROLL analytics collection and resets the local Firebase analytics identity. It does not automatically erase data already exported to cloud systems.

You may revoke Accessibility, Overlay, notification, or related Android permissions, although protection may then stop working. You can manage or cancel a subscription in Google Play Subscriptions.

Subject to applicable law, you may request access, correction, erasure, withdrawal of consent, grievance handling, or other applicable rights by contacting product@deadscroll.app. We may request only the information reasonably needed to verify and respond. Do not send passwords, card or bank details, government identification, order IDs, or purchase tokens unless specifically and securely requested.

14Children

DEADSCROLL is intended only for users aged 18 or older and is not directed to children. If you believe personal data was processed contrary to applicable child-consent requirements, contact us so we can review it.

15Contact and grievance redressal

Operator: DeadScroll.

For privacy requests, support, or formal grievances, contact product@deadscroll.app.

When contacting us, describe the request or grievance and provide a reliable reply address. Do not send passwords, card numbers, bank details, government identification, purchase tokens, or other unnecessary sensitive data.

16Changes

We may update this policy for product, security, legal, billing, or platform changes. The effective date above will change when a revised policy is published. Material changes will be communicated where required.

DEADSCROLL
Home Why We Nudge How It Works Permissions Privacy Policy Purchase Terms Support