Privacy Policy
BrainClean · Effective date: 5 May 2026 · Last updated: 18 July 2026
Short version. BrainClean is an Android app that helps you block distracting apps until you complete a focus task, and offers optional scheduling, eye-care and screen-time features. We collect the minimum data needed to operate the service: your email and password (or a Google Sign-In, if you choose that) to sign you in, your tasks, and any feedback you choose to send us. The apps you choose to block, your schedules, and everything the app observes about your app usage stay on your device. We do not use analytics, advertising, or tracking SDKs. You can delete your account at any time from inside the app.
1. Who we are
This privacy policy describes how BrainClean (“we”, “us”, “our”) handles your information when you
use the BrainClean mobile application (Android package com.brainclean.app, the
“App”).
We are based in Pakistan. If you have any questions about this policy or your data, contact us at support@brainclean.app
2. Information we collect
We collect only what is needed to provide the App.
2.1 Account information
When you create an account with an email address and password, you provide:
- Email address — used to sign you in, identify your account, and (if you forget your password) reset it.
- Username — a display name you choose, between 3 and 50 characters.
- Password — transmitted over HTTPS and stored on our server only as a one-way cryptographic hash. We never store your plain-text password and we cannot recover it.
2.2 Signing in with Google
You may instead choose to sign in with your Google account. If you do, Android’s Credential Manager shows you a Google account chooser and, once you pick an account, returns a signed Google ID token to the App. The App sends that token to our server, which verifies it with Google and uses it to create or sign you in to your BrainClean account.
From that token we receive and store your email address, your name as set on your Google account, and your Google account identifier. We use these only to identify your account and sign you in.
We do not receive your Google password, and we are not granted access to your Gmail, Drive, Contacts, Calendar, or any other Google service. If you sign in with Google, no BrainClean password exists for your account. Choosing this option means Google knows you use BrainClean — Google’s handling of that is covered by the Google Privacy Policy. If you prefer not to share this with Google, use email and password sign-in instead.
2.3 Task information
When you create or use a focus task, we store:
- The task name you choose
- The minimum duration you set, and the maximum duration if you set one
- The task status (pending, active, or completed), and whether it was completed by you or automatically when its timer elapsed
- Timestamps for when the task was created, started, and completed
Task data is associated with your account and stored on our servers so the App can show your tasks across devices and confirm completion.
2.4 Selected apps to block
You choose which apps the service should block during a focus task. The list of selected app package names is stored only on your device — it is never sent to or stored on our servers. The App also generates a session identifier when you start a blocking session; this identifier is stored on your device.
2.5 Authentication token
After you sign in, our server issues a JSON Web Token (JWT). The App stores this token on your device using
expo-secure-store, which uses platform-provided encrypted storage (Android Keystore-backed). The token is sent in the
Authorization header of requests to our backend so the server knows which account is making the request.
2.6 Schedules
You can set up schedules that start a blocking session automatically at a time you choose. The schedule itself — its time, duration, repeat days, and the optional label you give it — is stored only on your device.
When a schedule fires, the App creates and starts a focus task on our servers on your behalf, exactly as if you had created it yourself, and the task information in section 2.3 is stored. The label you give a schedule becomes that task’s name and is therefore sent to our servers when the schedule runs. If you leave the label empty, the App uses the time and date instead. This happens even if the App is closed at the time.
2.7 Feedback you send us
If you use the “Send Feedback” form in the App, we receive and store:
- The category you select (for example “Bugs & Crashes” or “Privacy Concerns”).
- The message you write, up to 2,000 characters.
- An email address, only if you choose to enter one. This field is optional and is left blank unless you fill it in. We use it to reply to you about your feedback.
If you are signed in when you send feedback, the submission is also associated with your account so we can follow up. You can send feedback without being signed in.
Please note: the message box is free text, and we store whatever you type in it. Please do not include passwords, financial details, or other sensitive personal information in your feedback.
We use feedback only to understand problems and improve the App. We do not publish it or use it for marketing.
2.8 What we do not collect
- We do not collect your phone number, address, or any government identifiers. We do not ask you for your real name — if you sign in with Google, we receive the name set on your Google account, as described in section 2.2.
- We do not collect your location.
- We do not collect your contacts, photos, or files.
- We do not collect which apps you use, how long you use them, or which apps are installed on your device. The App observes these on your device to make blocking work, but never sends them to us. See section 3.
- We do not collect the content of your notifications, and do not store or transmit it, even when notification blocking is switched on. See section 3.3.
- We do not directly collect or store any payment or credit-card information. All payments are processed by Google Play. See section 7 for details.
3. Information we read from your device
To make blocking work, the App reads certain information from your device. This information is processed locally and is not transmitted to our servers unless explicitly stated below.
3.1 List of installed apps
The App uses Android’s PackageManager to read the list of launchable apps installed on your device. We do this only
so the in-app picker can show you which apps you can choose to block, along with each app’s name and icon. The App declares a
narrow <queries> intent filter rather than the broad QUERY_ALL_PACKAGES permission. That filter is
limited to: launcher apps (so we can list them for you), a small fixed list of device-manufacturer settings apps (used only to open
the correct auto-start settings screen on certain devices), and apps that can open https links (used only to open pages
such as this one in your browser).
The list of installed apps is read on-device only and is never transmitted off your device.
3.2 Foreground app detection
The App uses Android’s UsageStatsManager to detect which app is currently in the foreground, and checks it
locally against the apps you selected. This runs while a focus task is active, and also while either of the optional wellness
features described in section 3.4 is switched on. It does not run otherwise.
Foreground app information is never logged or transmitted off your device.
3.3 Notification listener (optional)
In Settings you can choose how notifications are handled while a focus task is running. There are three options, and the default is Off:
- Off — the App does not touch your notifications at all.
- Selected Apps — notifications from the apps you chose to block are dismissed during a session.
- All Apps — notifications from every app on your device are dismissed during a session, except BrainClean’s own.
The last two options require you to grant Notification Access in Android Settings. Granting it means Android delivers every posted notification to the App so it can decide whether to dismiss it — this is how Android’s notification listener works, and it applies to the “Selected Apps” option too, not only “All Apps”.
Notification content is examined on your device, in the moment, and only to decide whether to dismiss it. We do not read it for any other purpose, do not store it, do not log it, and never transmit it to our servers. The App only ever looks at which app posted a notification — not at the message inside it.
Before choosing “All Apps”: this dismisses notifications from every app during a session, including calls, messages, and other alerts you may be waiting for. Please read section 6.1 of the Terms & Conditions before turning it on, and do not use it if you may need to be reachable.
You can change this setting or revoke Notification Access at any time.
3.4 Wellness features (optional)
The App includes two optional wellness features. Both are switched off by default, both run only while you have them switched on, and both work entirely on your device. When either is on, the App runs a second foreground service (with its own ongoing notification — see section 6) so Android does not stop it.
- Eye Blinker — on an interval you choose (20 minutes by default), the App briefly shows a full-screen reminder to rest your eyes. This is a timer. It does not read anything about you or your device.
- Doom Scroll Breaker — if you use one of the apps you selected continuously for longer than a limit you choose (15 minutes by default), the App covers it with a countdown for a few seconds to interrupt the habit. To do this, the App times how long the app you are currently using stays in the foreground.
The usage timings behind these features exist only in memory on your device while the feature is running. They are not written to a history, not built into a profile, and never transmitted to our servers. What is saved is only your settings for the features: whether each is on, your chosen interval, limit, and duration, and which apps Doom Scroll Breaker watches. Turning a feature off in Settings stops the monitoring immediately.
4. Permissions we request and why
The App declares the following Android permissions. Each is used solely for the purpose described below.
| Permission | Why it is needed |
|---|---|
INTERNET |
To communicate with our backend (sign in, save tasks, check task completion). |
Launcher app visibility (<queries> filter) |
To show you the list of installed apps so you can choose which ones to block. The list is read on-device only and never sent to our servers. Only apps with a launcher icon are visible to the App. |
PACKAGE_USAGE_STATS (Usage Access) |
To detect which app is in the foreground, so blocking can be triggered when a blocked app opens, and so the optional wellness features can time continuous use of an app. Granted by you in Android Settings. |
SYSTEM_ALERT_WINDOW (Display over other apps) |
To show the blocking overlay on top of a blocked app, and to show the eye-care reminder and Doom Scroll Breaker countdown if you enable those. Granted by you in Android Settings. |
FOREGROUND_SERVICE + FOREGROUND_SERVICE_SPECIAL_USE |
To keep the App’s engines running so Android does not kill them mid-session. Two services declare this: the blocking engine, subtype “App blocking enforcement for digital wellness”, which runs while a focus task is active; and the wellness engine, subtype “Eye care reminders and app usage monitoring for digital wellness”, which runs only while you have an optional wellness feature switched on. |
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS |
To request exemption from battery optimization so the blocking service keeps running while the screen is off or your device is in Doze mode. Granted by you via a system dialog. |
WAKE_LOCK |
To keep the CPU awake while a focus task is active so the blocking service can reliably detect the foreground app. Released as soon as the task ends. |
RECEIVE_BOOT_COMPLETED |
To restore your setup after you reboot your device: restarting blocking if a focus task was active when the device shut down, restarting an enabled wellness feature, and re-registering your schedules so they still fire. No data is sent at boot. |
| Alarms (no permission required) | To start your schedules at the time you set, the App registers them with Android’s alarm clock. This uses the same mechanism as a normal alarm and needs no special permission, but your device may show an alarm indicator while a schedule is pending. |
Notification Listener (BIND_NOTIFICATION_LISTENER_SERVICE) |
Optional, and only used if you set notification blocking to “Selected Apps” or “All Apps”. Lets the App dismiss notifications during a focus task, as described in section 3.3. Granted by you in Android Settings and revocable there at any time. |
com.android.vending.BILLING |
To offer the subscription through Google Play Billing. Payment is handled by Google Play; this permission does not give the App access to your payment details. See section 7.2. |
VIBRATE |
To provide brief haptic feedback in the user interface. |
5. How we store and protect your data
5.1 On your device
-
Encrypted storage — your authentication token and email are stored using
expo-secure-store, which uses Android’s platform-provided encrypted storage. Your app preferences are kept here too: which apps you selected, your chosen language, your wellness-feature settings, your “Block Notifications” choice, and a cached copy of your subscription status so the App knows what to show before it can reach our server. -
App-private storage — blocking session state (such as the package names you chose to block, session
identifier, start time, and your maximum block-time setting), your wellness-feature settings, and your schedules are stored in
Android
SharedPreferencesin the App’s private storage area, accessible only to the App. The blocking engine keeps its own copy here so that blocking keeps working even if you force-close the App or restart your device. - A copy of your authentication token is also kept in that app-private area, because the blocking engine has to reach our server without the rest of the App running — to check whether your task is complete, and to create and start the task when a schedule fires. It is kept while a focus task is active, and for as long as you have any schedule saved. It is cleared when you sign out or delete the App.
5.2 In transit
All communication between the App and our backend uses HTTPS (TLS). Our backend is reachable at
https://api.brainclean.app/api.
5.3 On our servers
- Passwords are stored only as one-way cryptographic hashes.
- Each user’s data is isolated by account and is accessible only with a valid authentication token.
- We follow industry-standard practices to protect data, but no system can be guaranteed 100% secure.
6. Notifications
Android requires the App to display an ongoing notification whenever one of its engines is running as a foreground service. You may see either of these:
-
BrainClean — BrainClean is protecting your focus.— shown while a focus task is active. It disappears when the task ends or you stop blocking. -
BrainClean — Eye care active/Usage monitoring active/Eye care & usage monitoring active— shown while an optional wellness feature is switched on, naming whichever is running. It disappears when you switch the feature off. -
Scheduled task started— shown once when one of your schedules fires, naming the task and how long it will block for.
These notifications are generated by your device only. We do not send push notifications, and we do not use notifications for marketing or promotional messages.
7. Third parties
BrainClean does not use any third-party analytics, advertising, attribution, or crash-reporting SDKs. We do not sell, rent, or share your personal data with third parties for advertising or marketing.
The only third party involved in running the App is Google, and only through the Google services listed below. Each is described under the Google Privacy Policy.
7.1 Google Play
The App is distributed through Google Play, which may collect its own diagnostic data. The App also uses Google Play’s in-app update mechanism to offer you a newer version when one is available; this exchanges version information with Google Play and does not involve your account or task data.
7.2 Google Play Billing
The App offers a paid subscription processed entirely through Google Play Billing. We do not collect, process, or store your credit card number, billing address, or any other payment instrument details. Google handles all payment processing. We receive from Google only: your subscription status (active, expired, cancelled, or in a grace period), the purchase token, and the transaction date. This information is used solely to determine whether your account has an active subscription. Your payment relationship is with Google; see Google Payments Privacy Notice for how Google handles your payment data.
7.3 Google Sign-In
If you choose to sign in with Google, the App uses Android’s Credential Manager together with Google Identity Services to show the account chooser and obtain a Google ID token. This happens only when you tap “Continue with Google”. What we receive from that token, and what we do not, is described in section 2.2.
If we add a service in a future version (for example, an opt-in crash-reporting tool), we will update this policy and the effective date before the new version is published.
8. Data retention
We keep your account information and tasks for as long as your account is active. If you delete your account, we permanently delete your account record and associated tasks instantly. Some information may persist in encrypted backups for a short period, after which it is also deleted.
Locally stored data (your authentication token, email, selected apps, schedules, wellness settings, and other preferences described in section 5.1) is removed from your device when you sign out, delete your account, or uninstall the App.
Feedback is kept separately from your account, because it can be sent without being signed in and we need it to fix the problems it reports. Deleting your account removes the link between your feedback and your account, but does not automatically delete the feedback text itself. If you want feedback you sent deleted as well, email us at support@brainclean.app and we will remove it.
9. Your rights and account deletion
You can:
- Access your account information — your email address is shown in the App under Settings. If you signed up with an email and password, you can change your password using the “Forgot password” flow on the sign-in screen.
- Correct your account information — if any of it is wrong and you cannot change it in the App, email us at support@brainclean.app from the address on your account and we will correct it for you.
- Delete your account at any time. Open the App, go to Settings, and tap “Delete Account”. After confirmation, we permanently delete your account, all your tasks, and all associated data. This action cannot be undone.
- Sign out of the App at any time, which removes your authentication token from your device.
- Revoke permissions at any time in Android Settings. Revoking certain permissions (Usage Access, Display over other apps) will disable or weaken the blocking feature.
- Turn off the wellness features at any time in Settings, which stops the on-device usage monitoring described in section 3.4 immediately.
- Disable or delete your schedules at any time from the Schedules tab, which cancels the pending alarm so no further sessions start automatically.
- Change notification blocking at any time in Settings, including setting it back to “Off”, and revoke Notification Access in Android Settings.
If you cannot access the App for any reason and want your data deleted, contact us at support@brainclean.app from the email address associated with your account and we will process your request.
10. Children’s privacy
BrainClean is not directed at children under the age of 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact us at support@brainclean.app and we will delete the account.
11. International users
The App is operated from Pakistan, and data is processed on servers in the region where our backend is hosted. By using the App, you consent to your information being transferred to and processed in that region. If you are located in a jurisdiction with specific data-protection rules (such as the EU/UK GDPR, California CCPA, or India DPDP), you may have additional rights under your local law — you can exercise them by contacting us at support@brainclean.app.
12. Security
We use HTTPS for all network traffic, encrypted on-device storage for sensitive values, and one-way password hashing on the server. No method of transmission or storage is perfectly secure, however. If you become aware of a security issue affecting the App, please report it to support@brainclean.app.
13. Changes to this policy
We may update this policy from time to time. When we do, we will update the “Effective date” and “Last updated” values at the top of this page. For material changes, we will also surface a notice in the App. Your continued use of the App after a change means you accept the updated policy.
14. Contact us
If you have any questions, requests, or concerns about this policy or your data, contact us at:
Email: support@brainclean.app
Operator: BrainClean, Pakistan