App-specific policy

Slowroll: Stop Doomscrolling

Slowroll puts friction in front of the apps you open without meaning to: a breathing pause, an intention question, a short physical challenge. To do that it has to notice which app you just opened, which is the most sensitive thing it does — so it is worth being exact about it. Slowroll has no server of its own. Your rules, your schedules, your intercept history and your streak are written to a database on your phone and are never uploaded; there is no analytics, no crash reporting, no advertising and no tracking of any kind. Two optional things do reach the network — signing in, and buying the paid tier — and neither of them moves your rules or your history off the phone. The blocking itself runs with the network switched off.

Policy URL/apps/slowroll/
Packagecom.slowroll.app
Last updated2026-09-20

Privacy Policy

Scope

This privacy policy applies to Slowroll: Stop Doomscrolling, including the Android package com.slowroll.app. It explains how Herazur accesses, collects, uses, shares, retains, and deletes user data for this app.

If you also use another app from the same developer, please review the app-specific page for that product because data practices can differ.

Privacy Policy

Information we collect

Which app is in the foreground (accessibility service)

Blocking works by way of Android’s accessibility service, which tells Slowroll when a new app window comes to the front. The service is declared for one event type — a window changing — and with screen-content retrieval switched off, so the system does not hand it the text on your screen at all. Slowroll cannot read your messages, your passwords, what you type or what you browse inside another app; it learns a package name such as "com.instagram.android" and the moment it appeared, decides in memory whether a rule applies, and discards the rest. Nothing from this stream is transmitted anywhere, and the only trace kept is the intercept record described below.

Your rules and history, stored on your phone

Slowroll writes to a private database on your device: the apps you chose to watch and how each is configured (pause length, intention question on or off, challenge type and target, any custom task name you typed), your schedules, a record of each intercept — the app, the time, why it fired, what you chose, how long you spent on the screen and how much of the challenge you completed — a per-app daily open count, your streak, and your settings such as theme, reminder time and grace period. This lives in the app’s sandbox on your phone. We have no copy of it and no way to obtain one.

The intention question

When the intercept screen asks why you are opening an app, your one-tap answer and anything you type in the note field stay in memory for as long as that screen is open and are then discarded. Neither is written to the database, and neither leaves the device. The question exists to make you pause, not to build a record.

Usage access, for the Statistics tab

If you grant usage access in Android settings, Slowroll asks the system for the screen-time figures it already keeps — foreground time and launch counts per app — and shows them to you. They are read when you open a screen that needs them, never copied to a server, and never combined with anything else. Revoking usage access empties the Statistics tab and changes nothing about blocking.

Motion sensors, only during a challenge

Push-up, squat and burpee challenges read the accelerometer and proximity sensor while the challenge screen is open, and the step challenge reads Android’s step counter, which is why the app asks for physical-activity permission. Readings are counted in memory and thrown away as the screen closes; only the number of reps or steps you completed is kept, alongside that intercept. Nothing is shared, and the app works without the permission — every other challenge type is unaffected.

Account information, only if you create an account

Signing in is optional and entirely separate from everything above. If you choose to sign up, Firebase Authentication — acting as our processor — stores the email address you register with, or the address and display name your Google account supplies, along with an account identifier. That is the whole of it. An account uploads none of your rules, history or statistics, and it unlocks no feature: blocking, schedules, challenges and statistics are identical signed in and signed out. Legal basis (GDPR / KVKK): performance of the service you asked for, Art. 6(1)(b).

Purchase records, only if you buy the paid tier

The paid tier is sold through Google Play, and its entitlements are managed by RevenueCat acting as our processor. Opening the subscription screen asks RevenueCat which plans exist; buying one hands you to Google Play, which takes the payment. No card number, billing address or other payment detail ever reaches the app or us. What RevenueCat then holds is a purchase record: which product you bought, when it started and when it renews or expires, the store’s transaction identifier, the country the store reports, and an identifier the SDK generates for the app on your device. Signed out, that record sits under an anonymous identifier; signed in, the app links it to your account identifier so the subscription follows you to a new phone. We can see in the RevenueCat dashboard that a subscription exists and what state it is in — nothing about how you use the app. Legal basis (GDPR / KVKK): performance of the contract you entered into, Art. 6(1)(b). RevenueCat’s privacy information: https://www.revenuecat.com/privacy/

Android’s own backup, if you have it on

Slowroll takes part in Android Auto Backup, so if backup is enabled on your phone your rules, history and settings can be copied into your personal Google Drive backup and restored when you set up a new device. That copy belongs to your Google account, not to us; we cannot read it. You control it in your device’s Google backup settings.

Privacy Policy

How we use information

Store records locally on your device

Some apps are designed to keep your records on-device so core functionality works without maintaining a remote user database.

Notice a watched app and show the intercept

The foreground-app signal exists for one reason: to decide, within a fraction of a second, whether the app you just opened has a rule and what should stand in front of it. A foreground service keeps that monitor and its session timers alive so an intercept fires the instant it is needed rather than a minute later.

Show you your own numbers

Your intercept history, open counts and streak are kept so the app can show you how often you reached for something and how often you turned back. They are for you to read, and nobody else receives them.

Deliver reminders and notifications

We use reminder settings to schedule the notifications you ask the app to send.

Give you an account, if you want one

An account exists so that a future shared-streak feature has something to attach to. Today it does nothing else, and there is no sync: creating one does not move your data off the device.

Sell and restore the paid tier

Purchase records exist so the app can tell whether the paid capabilities are unlocked, restore them when you reinstall or change phones, and keep working while the store retries a declined card. The blocking engine never asks this question. Watching an app, the pause screen, the intention question, effort-to-unlock, strict mode, session lengths and daily caps are free on as many apps as you like; what the subscription adds is longer history, the remaining challenge types and more than two schedules. A lapsed subscription never removes configuration you already made.

Respond to support and deletion requests

We use contact and account details to verify requests, answer support questions, and process privacy-related actions.

Meet legal, tax, security, and fraud-prevention obligations

We may process limited data when necessary to comply with law, enforce agreements, prevent abuse, or protect users and the service.

Privacy Policy

Sharing and service providers

We may share data only with service providers or infrastructure needed to deliver the features you request, process payments, maintain security, or comply with law. We do not sell personal and sensitive user data.

Firebase Authentication

account sign-in and account security

Google Sign-In

optional account login provider

RevenueCat

subscription and entitlement management

Google Play Billing / app store billing infrastructure

purchase processing, restore flows, and subscription validation

On-device storage

storing settings, records, and other content locally on your device

Local notification services

scheduling reminders you configure inside the app

No analytics, crash-reporting, advertising or attribution service

Slowroll ships with none. There is no Firebase Analytics, no Crashlytics, no Firestore or other database of ours, no ad network and no attribution SDK, and no advertising identifier is read. The only servers the app can reach are Firebase Authentication when you sign in, and RevenueCat and Google Play when you open or buy the paid tier. Use none of those and the app makes no network requests at all. Google’s privacy information: https://firebase.google.com/support/privacy

Privacy Policy

Permissions and sensitive access

Accessibility service

This is how the app knows a watched app was opened, and without it nothing is blocked. It is declared for window-change events with screen-content retrieval off, so it cannot read what is on your screen. You grant it yourself in Android settings and can revoke it there at any time.

Display over other apps

The pause and challenge screen has to appear on top of the app you just opened. Without it, the intercept would arrive behind the very app it is meant to stand in front of.

Usage access

Only for the Statistics tab, so the app can read the screen-time figures Android already keeps. Blocking works without it.

Physical activity

Only for the step-count challenge, which reads Android’s step counter while that challenge is running. Decline it and every other challenge type still works.

Notifications

For the ongoing notification Android requires while the monitor is running, and for the optional daily reminder. These are scheduled by your own device; no push server is involved and no notification content leaves the phone.

Battery optimisation exemption and run at startup

Offered, never required. Some manufacturers stop background monitors, which would silently switch blocking off; the exemption and the boot receiver are what make blocking survive a restart or an aggressive battery manager.

Privacy Policy

Data retention and deletion

What Slowroll stores lives on your phone until you remove it: delete a rule and its configuration goes with it, clear your history in the app to remove the intercept records, open counts and streak, or uninstall the app to remove all of it at once, including your settings. There is no server-side retention period because there is no server copy. Settings → Save a backup writes all of it to a file you choose and keep, which is also how you exercise the right to data portability: the file is plain, readable JSON, it goes wherever you send it, and no copy of it reaches us. If you created an account, the email address held by Firebase Authentication remains until the account is deleted. If you bought the paid tier, RevenueCat keeps the purchase record for as long as the entitlement has to be honoured and restored and for the tax and accounting periods the transaction falls under; Google Play keeps its own record of the same transaction under Google’s terms, and neither we nor RevenueCat can remove that one. No analytics or diagnostic records exist to retain.

If you want to delete your account or associated data, use the dedicated account deletion page linked below. Open the Slowroll account deletion page.

Privacy Policy

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is perfectly secure.

Privacy Policy

Children's privacy

Slowroll is not directed at children under 13, and accounts are not intended for them. The app has no profiles, no messaging, no user-to-user content and no advertising, so there is no route by which a child’s information could reach us or another user. If you believe a child has provided personal data to us, contact nakrufrats@gmail.com so we can review and delete it where appropriate.

Privacy Policy

Changes to this policy

We may update this privacy policy from time to time. When we do, we will update the "Last updated" date on this site and, where appropriate, provide additional notice inside the app.

Privacy Policy

Contact

Developer: Herazur

Privacy contact: nakrufrats@gmail.com

Support contact: nakrufrats@gmail.com

Address: Contact by email for mailing address, Turkiye

We aim to respond to verified privacy requests within 30 days.