Lockus Privacy Policy
This policy explains how Lockus handles data for focus, protection, creation, account, cloud synchronization, and optional Writing features.
1. Scope and service
Lockus helps people run focus sessions, restrict distracting apps and websites, review discipline patterns, and create local notes, To-dos, maps, and writing projects.
The core focus and protection experience is local-first. A Lockus account may provide account access, cloud backup, restoration, and continuity for the limited content identified below. Optional remote AI, publishing, collaboration, and advanced agents are not active in the initial release unless Lockus explicitly presents and enables them later.
2. Data that stays on device
Screen Time selections and tokens, DeviceActivity events, protection domains, focus history, discipline data, behavior metrics, local Notes and Maps, writing drafts, and unsynchronized local To-dos stay on the user's device in the initial release.
Lockus does not send Screen Time tokens, blocked-app selections, protection domains, focus history, discipline data, Notes, Maps, or writing drafts to Supabase or Brevo.
3. Account and Free cloud data
When a user creates or uses a Lockus account, Lockus and its providers may process the submitted email address, a server-generated user identifier, session and account timestamps, security and authentication events, an optional display name if made available, synchronized Free To-do titles and completion state, client dates, server revisions, content-free deletion tombstones, and operation metadata needed for reliable synchronization.
Passwords are handled by Supabase Auth. Lockus does not store or expose plaintext passwords. Transactional authentication email is delivered through Brevo, which may process the recipient email and delivery or bounce metadata. Anonymous tracking is enabled for transactional opens and clicks: aggregate counts remain, but they are not associated with specific contacts under the current Brevo configuration.
Supabase automatically records authentication events and operational logs. Logs can include timestamps, route or response metadata, IP or network metadata, and the account identifier needed for security, abuse prevention, and troubleshooting.
4. Optional Writing, Premium, and AI data
Writing remains local-first. If a remote Writing or AI feature is enabled later, Lockus must present the remote action and applicable consent before selected text is transmitted.
A remote request may include selected or minimized writing text, operation, language, tone, formatting constraints, target-platform metadata when needed, and request or schema metadata. It must not silently include Screen Time data, blocked apps, focus history, discipline events, social tokens, media files, or unrelated local content.
No generative AI provider is active for the initial account release. Provider activation, retention, and subprocessor disclosures require a separate review.
5. Marketing communications
Account creation and transactional authentication emails do not grant marketing consent. Marketing messages remain separate, optional, off by default, and revocable.
Refusing or withdrawing marketing consent does not remove Free product capabilities. Lockus does not send a promotional campaign unless a dedicated consent and suppression path has been enabled and certified.
6. Sale, advertising, and tracking
Lockus does not sell user content or account data. Lockus does not use third-party advertising tracking in the initial release and does not combine Lockus data with third-party data for targeted advertising or advertising measurement.
The app privacy manifest declares no tracking. Any future advertising, tracking, or analytics SDK requires updated App Privacy Details, manifest, consent flows, and policy before release.
7. Purposes and security
Lockus processes remote account and To-do data to provide authentication, synchronization, restoration, export, deletion, fraud and abuse prevention, operational reliability, and support. Where applicable, separate consent is used for marketing or optional remote AI.
Remote traffic uses encrypted connections. Account-owned rows use owner-scoped access controls, and server endpoints derive identity from the verified session rather than trusting a user identifier from the request body.
8. Retention
Local data remains on device until the user deletes it, removes the app, or uses an available reset control. Account and synchronized To-do records remain until the user deletes the account or applicable product records.
Account deletion revokes sessions and deletes the account-owned profile, preference, consent, active To-do, tombstone, and operation records covered by the Lockus deletion path.
Supabase and Brevo may retain operational, security, audit, delivery, or abuse-prevention records for provider-managed periods, legal obligations, or legitimate security needs. Lockus does not promise an EU-only path where a provider or its subprocessors document broader processing.
9. Export, deletion, and user choices
The Lockus account screen provides account-data export, sign-out, and confirmed in-app account deletion when the account feature is enabled.
Deleting the account removes the active account and synchronized account-owned product rows. It does not automatically erase unrelated local Notes or Maps, which users manage directly in the app.
Users may contact Lockus about access, correction, deletion, objection, restriction, portability, or withdrawal of consent where applicable. Identity verification may be required.
10. Children and sensitive data
Lockus is not designed to collect health, financial, precise-location, contacts, photo-library, or advertising-identifier data for the account and Free To-do cloud scope.
Users should not place sensitive personal information in a To-do title. Lockus does not knowingly use account or To-do data for targeted advertising.
11. Service providers and subprocessors
Active providers for the initial account scope are Apple for App Store distribution and iOS services; Supabase for authentication, Postgres account and Free To-do storage, Edge Functions, security controls, and logs; Brevo for transactional authentication email and delivery metadata; and Cloudflare for the public Lockus website and privacy page.
Cloudflare Worker services, AI providers, social platforms, collaboration providers, billing webhooks, and analytics providers are not active for the initial account scope merely because future code or documentation exists. They require separate activation and privacy review.
12. Responsible service and contact
Lockus is the service name. The service is operated by Malo Morantin, the individual developer identified by the Apple Developer membership and applicable App Store listing.
For privacy questions, access or deletion requests, and support, contact:
support@lockusapp.com
The final App Store metadata must identify Malo Morantin consistently as the responsible individual seller before account visibility is activated.
13. Changes to this privacy policy
Lockus may update this policy when product features, providers, retention rules, or data practices change. The effective date and version above identify the current published text.
The published policy and App Privacy Details must be reviewed before every release that changes remote data processing.