Privacy Policy
Last updated: 2026-08-07
This policy covers two things operated by GreenVend UG (haftungsbeschränkt): this website (shamelock.app) and the ShameLock mobile app (Android). It explains what data each collects, why, and where it goes.
Controller
GreenVend UG (haftungsbeschränkt)
Bredtschneiderstr. 14
14057 Berlin, Germany
Email: [email protected]
1. This website
The website uses PostHog (hosted in the EU, eu.i.posthog.com) for product analytics — page views, clicks, and general usage patterns to understand how visitors use the site.
PostHog is configured to store data in browser localStorage, not cookies. It does not set tracking cookies. Data collected may include your browser/device type, approximate location derived from IP address, pages visited, and interactions on the page. Legal basis: your consent (Art. 6(1)(a) GDPR), collected via the consent banner shown on your first visit. Under § 25 TDDDG (formerly TTDSG), consent is required for storing or accessing information on your device even when that storage is localStorage rather than a cookie — so we ask first. You can accept or decline in the banner, and clear this data at any time via your browser settings.
The site does not use advertising trackers, does not sell data, and has no user accounts or login on the website itself.
2. The ShameLock app
ShameLock is an Android app that blocks distracting apps until you take a selfie to unlock them. Here is exactly what it does with your data:
Selfies and app-blocking data — stored only on your device
When you unlock a blocked app, ShameLock takes a photo using your front camera and runs on-device face detection to confirm a face is present before allowing the unlock. This photo, along with your list of blocked apps, unlock timestamps, and app-blocking schedules, is stored locally on your phone only, in a local database and local file storage. None of this — photos, app usage, blocking rules — is ever uploaded to us or to any third party. We do not operate a server that this data is sent to. Deleting an entry in the app permanently deletes the photo and record from your device.
Installed app list
To let you choose which apps to block, ShameLock reads the list of apps installed on your device (name and package identifier). This stays on your device and is never transmitted anywhere.
Camera permission
Used exclusively to take the unlock selfie described above, processed on-device. No image is transmitted off your device by ShameLock.
Accessibility Service & Notification Access
ShameLock uses Android's Accessibility Service to detect when you open an app you've chosen to block, and Notification Listener access to block/hold notifications from those apps until you unlock them. Both are used solely to power the app-blocking feature you configure yourself, run entirely on-device, and are not used to read, log, or transmit the content of your notifications or other apps to us or anyone else. You can revoke either permission at any time in Android Settings, which will disable app-blocking accordingly.
Purchases (RevenueCat)
If you buy a subscription or one-time unlock in the app, purchase and entitlement data (such as a device-linked purchase identifier and transaction status) is shared with our payments provider, RevenueCat, and with Google Play's billing system, solely to verify and manage your purchase. RevenueCat acts as a processor on our behalf. No selfies, app lists, or blocking data are ever shared with RevenueCat. See RevenueCat's privacy policy at revenuecat.com/privacy.
Sharing
If you choose to share a photo (e.g. to Messages or another app) using the in-app Share button, that photo is handed to the app you pick via Android's standard share sheet. This only happens if you actively tap Share — it is never automatic.
What ShameLock does not do
No analytics SDK, no crash reporting SDK, no advertising SDK, and no account/login system are included in the app. We do not collect your name, email, or contacts through the app, and we have no server that app data is synced to.
3. Beta access via LinkedIn
Since ShameLock is in private testing, requesting beta access currently works by sending a direct message on LinkedIn. If you do this, we see your LinkedIn name/profile and the content of your message, which we use solely to grant you access to the beta and communicate with you about it. This happens on LinkedIn's platform, under LinkedIn's own privacy policy; we do not import or store this data outside of LinkedIn beyond what's needed to add you to the test group. This channel will be replaced once the app is publicly available on Google Play.
4. Your rights
If you are in the EU/EEA/UK, you have the right to access, correct, delete, or export your data, and to object to processing based on legitimate interest, under the GDPR. For the app, this is largely moot since the data never leaves your device — deleting the app or its data from your phone removes it entirely. For website analytics, contact us at [email protected] to request access or deletion of any data PostHog may hold about you. You also have the right to lodge a complaint with a supervisory authority, e.g. the Berlin data protection authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
5. Children
ShameLock and this website are not directed at children under 16, and we do not knowingly collect data from them.
6. Changes to this policy
We may update this policy as the website or app changes. Material changes will be reflected by updating the "Last updated" date above.