SelfGuard

Privacy Policy

Last updated: 21 September 2026

SelfGuard (“SelfGuard”, “the app”, “we”, “us”) is an Android app that helps you block pornography, distracting apps, and content, and stay accountable during recovery. It is published on Google Play under the developer name RestartLab — an independent solo developer, not a registered company. This policy explains what information the app handles, why, and the specific cases where data leaves your device. It applies to the SelfGuard Android app (com.selfguardapp.android).

The short version. Your blocks, keywords, focus sessions, streaks, notes, and check-ins are stored only on your device and encrypted, and the app has no ads and no analytics or tracking SDKs. However, to create a content or app block — SelfGuard’s core feature — you must first verify an accountability email (this is required, not optional). Once you do, that email and the details of your active blocks (including the keywords and app names you block) are sent to our server to run verification, backup, and accountability alerts. Focus sessions don’t require an accountability email and stay on your device. If you turn on the optional Network Protection, your device’s DNS is handled by a third-party filtering provider (see Section 4).

1. Information stored only on your device

The following is created and kept locally on your phone, in a database that is encrypted at rest. We cannot see it, and it is not sent to us (aside from the active-block details described in Section 3):

2. Device access and permissions

Permission / accessWhyLeaves your device?
Accessibility Service To enforce your blocks, SelfGuard reads on-screen content (the current app, the web address in supported browsers, and visible text) in real time to detect blocked apps, sites, and words. No. This is processed on-device, only to enforce your blocks. It is never recorded, stored, or transmitted.
Installed-app list To show you a list of your installed apps so you can choose which to block or silence. SelfGuard asks Android only for apps that have a launcher icon — it does not request the broad QUERY_ALL_PACKAGES permission. Their names are also read once, on the phone, so that while a block is running the app can tell its own settings page (where it could be removed) from an ordinary list of apps. No, the list is read on-device. Only the identifiers of apps you actually choose to block are backed up (see Section 3).
Internet Accountability email/verification and trusted-time sync. See Sections 3–5.
Device administrator Uninstall protection. While it is active, Android’s own package manager refuses to uninstall SelfGuard, so a block cannot be escaped by deleting the app. SelfGuard requests no administrator powers: it cannot lock your screen, change or expire your PIN, password or fingerprint, erase your device, or locate it. You switch it on yourself on Android’s own screen, and can switch it off at any time in Settings → Security → Device admin apps. No. Nothing is collected, stored, or sent.
Notifications For one message, and only ever that one: blocking has stopped and only you can start it again. On Android 13 and later the app asks for it once a block exists, not before; older versions allow notifications without asking. Declining costs you the warning, nothing else. No. The notification is written and shown on your device.
Run at startup Android cancels an app’s alarms when the phone restarts. SelfGuard uses this only to put back the timer that checks its own enforcement is still running. No. Nothing is collected, stored, or sent.
Ignore battery optimisations Lets the app raise Android’s own one-tap dialog asking to keep running in the background — without it, phones put SelfGuard to sleep and blocks stop being enforced. The app only opens that dialog; the choice, and the switch, are yours, and it can be reversed in your battery settings at any time. No. Nothing is collected, stored, or sent.
Clipboard — only when you tap “Paste” On the screen where you enter the 6-digit code, a Paste button reads what you have copied and takes the six digits out of it, so the code need not be retyped. Nothing is read unless you tap it, and Android 12 and later show a notice each time. No. The clipboard text is used on your device, then discarded.

SelfGuard declares four Android permissions — INTERNET, notifications, run at startup, and the battery-optimisation exemption above. The Accessibility Service and the device administrator are not permissions the app can request: you grant each of them yourself, on Android’s own screens, and can withdraw either at any time. SelfGuard does not request location, contacts, storage, camera, or microphone.

3. Information sent when you create blocks (accountability)

Creating any block requires a verified accountability email. This is a required step for SelfGuard’s core blocking — you cannot create an app, keyword, adult-content, short-video, browser, profile, or network block without it. The email may be your own or a trusted partner’s. When you set this up and while you have active blocks, we process:

Focus sessions do not require an accountability email and are not sent to our server. If you only use Focus and never create a block, none of the above is collected.

4. Network Protection (Private DNS) — optional

SelfGuard’s optional Network Protection guides you to set your device’s system Private DNS to a family-filtering DNS provider — CleanBrowsing (family-filter-dns.cleanbrowsing.org) — so that adult sites are blocked and Safe Search is enforced for apps that use your device’s DNS. If you enable it:

5. Trusted time

So that a block can’t be ended early by changing the phone’s clock, SelfGuard takes the time from a trusted source rather than from the device:

6. Purchases and subscriptions

This version of SelfGuard sells nothing. There are no in-app purchases and no subscriptions: the app contains no billing code, takes no payment, and collects no purchase or financial information of any kind. A “Premium” tier is described inside the app as coming later, but it cannot be bought yet.

If paid features are added in future, this policy will be updated before they go on sale to name the payment processor and say exactly what it receives.

7. Who processes data on our behalf

We use a small number of service providers strictly to run the features above:

We do not sell or rent your personal information. The app contains no advertising and no third-party analytics or tracking SDKs of any kind. (This website is a separate thing — see Section 12.)

8. Data retention

9. Security

On-device data is stored in an encrypted database (SQLCipher). Data sent to our server is transmitted over HTTPS. Server-side email keys are held only on our provider’s infrastructure and are never included in the app.

10. Your choices and rights

11. Children’s privacy

SelfGuard is intended for adults aged 18 and over and is not directed to children. It is not designed for, marketed to, or intended for use by anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

12. This website

This page and the rest of selfguardapp.com are hosted on Cloudflare, which serves the site and processes standard request data such as your IP address. The site also uses Cloudflare Web Analytics to count page views. It uses no cookies, does not fingerprint your browser, and does not track you across other websites — it records aggregate information such as page, referrer, country and device type.

This applies to the website only. The Android app itself contains no analytics or tracking of any kind (Section 7).

13. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected here with a new “Last updated” date. Continued use after an update means you accept the revised policy.

14. Contact

Questions or requests about privacy: privacy@selfguardapp.com.