Home / Privacy
Privacy
This policy explains what information the GazeGuard application and website collect, how that information is used and disclosed, and the choices available to you. Last updated August 29, 2026.
Who we are
GazeGuard ("GazeGuard", "we", "us") provides the GazeGuard mobile application and this website (together, the "Service"). For the purposes of the UK GDPR, the EU General Data Protection Regulation, and comparable data protection legislation, GazeGuard is the data controller for personal data processed through the Service. Contact details are provided in the Contact section below.
Information we collect
Information you provide
Account information. If you choose to create an account, we receive from your chosen sign-in provider a limited profile: your display name, your profile photograph, a provider-assigned account identifier, and, where you sign in with Google, your email address. We do not receive or store your password. Account creation is optional; the Service's protection features are fully available without one.
Support and feedback communications. If you submit a report through the in-app feedback form or contact us directly, we process the content of your message, any screenshots or images you attach, your device description, your IP address, and your account identifier where applicable. Feedback submissions are relayed to our support channel, which is operated using Telegram, so that they can be reviewed and actioned.
Custom filtering preferences. Any additional websites or applications you elect to block are stored on your device and, where you have an account, synchronised to your account so that your configuration is preserved across devices.
Information collected automatically
Installation identifier. On first launch, the application generates a random identifier that is unique to that installation. This identifier is not derived from, and cannot be linked to, your advertising ID, IMEI, Android ID, or any other device- or user-level identifier assigned by your device or operating system. It is transmitted with usage statistics as described below, is reset if the application is reinstalled, and is deleted when the application is removed.
Device and technical information. We collect your device model and manufacturer, operating system version, application version, language setting, and time zone. This information is used to diagnose faults, prioritise device support, and understand the composition of our user base.
Usage statistics. We collect aggregate measures of your use of the Service, including the total time protection has been active, session counts, streak lengths, the number of blocked attempts, and the calendar days on which protection was active. These are numerical counters. They do not include, and cannot be used to derive, the websites you visited, the searches you made, or which specific sites or applications were blocked.
These statistics are collected whether or not you have created an account. Where you have not created an account, they are associated with the installation identifier described above rather than with an identified person.
Diagnostic and crash information. Where the application terminates unexpectedly, we collect a technical error report containing the software stack trace, application version, device model, operating system version, and your IP address. Crash reports do not contain the contents of your screen or your browsing activity.
IP address. As with any internet-connected service, our servers receive the IP address from which your device connects. We process IP addresses for security, abuse prevention, rate limiting, and the operation of the Service. We do not use IP addresses to determine your precise location and we do not use them for advertising or profiling.
Information we do not collect
We consider the following commitments to be central to the Service, and we state them explicitly:
- We do not collect your browsing history. Filtering is performed locally on your device. The websites you visit, the searches you perform, and the content displayed to you are not transmitted to us.
- We do not collect the identity of blocked content. We record how many attempts were blocked. We do not record which sites or applications they related to.
- The VPN function does not route, proxy, or inspect your traffic. GazeGuard uses the Android VpnService interface solely to evaluate DNS lookups locally on your device. No user traffic is transmitted to, or handled by, any VPN server operated by us. We operate no such server.
- We do not collect precise location data, contacts, messages, call logs, photographs (other than images you deliberately attach to a support request), microphone input, camera input, or the contents of your screen.
- We do not sell personal information, share it with data brokers, or use it for advertising, profiling, or automated decision-making producing legal or similarly significant effects.
- We integrate no third-party advertising or analytics software in the application.
How we use information
We process the information described above for the following purposes: to provide, maintain, and secure the Service; to synchronise your progress and settings across devices where you have an account; to operate optional community features such as leaderboards, which display only a first name and an aggregate time figure; to diagnose faults and improve reliability; to respond to your support requests; to understand aggregate usage patterns and measure the reach of the Service; and to comply with applicable law and enforce our Terms of Use.
Legal bases for processing
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases. Performance of a contract: processing account information, settings, and progress data in order to provide the Service you have requested. Legitimate interests: processing technical, diagnostic, usage, and IP information in order to secure the Service, prevent abuse, diagnose faults, and understand aggregate usage; we have assessed that these interests are not overridden by your rights, taking into account that the data is limited in scope and does not include browsing activity. Consent: where you voluntarily submit feedback or images. Legal obligation: where processing is necessary to comply with applicable law.
Disclosure to third parties
We do not sell personal information. We disclose information only as follows.
Service providers. We use MongoDB Atlas for database hosting and a commercial hosting provider for our servers. These providers process data on our behalf, under contract, and are not permitted to use it for their own purposes.
Authentication providers. Where you sign in with Google or Telegram, that provider processes your authentication request under its own privacy policy.
Support channel. Feedback submitted through the application is relayed to our support channel, which is operated using Telegram, in order that it can be read and actioned.
DNS resolution. Lookups that are not blocked by the on-device filter are forwarded to CleanBrowsing, a third-party public DNS resolver that provides an additional layer of family-safe filtering. This is analogous to the DNS resolution performed by your network operator when GazeGuard is not in use. CleanBrowsing processes those lookups under its own privacy policy.
Legal and safety. We may disclose information where we believe in good faith that disclosure is required by law, or is reasonably necessary to protect the rights, property, or safety of GazeGuard, our users, or the public.
Business transfer. If the Service is acquired or transferred, information may be transferred as part of that transaction, subject to the terms of this policy.
Retention
We retain personal data only for as long as necessary for the purposes set out above. Specifically: account data is retained for the life of your account and is deleted when you delete your account; installation records are retained for 24 months from the last activity and are then automatically deleted; per-day activity records are retained for 400 days; crash reports and feedback submissions, including attached images, are retained for 180 days; authentication sessions expire automatically and are deleted on expiry, on sign-out, or on account deletion. Aggregate statistics that do not identify any individual may be retained indefinitely.
Your rights and choices
Subject to applicable law, you have the right to access the personal data we hold about you; to request its correction or erasure; to object to or request restriction of processing; to request a copy of your data in a portable form; and, where processing is based on consent, to withdraw that consent at any time. Where the UK GDPR or EU GDPR applies, you also have the right to lodge a complaint with your supervisory authority.
Deleting your account. You may delete your account and all associated data at any time from the profile screen within the application, or by following the instructions on our account deletion page. Deletion is immediate and permanent; we do not retain an archived copy.
If you do not have an account. You may request deletion of the records associated with your installation by contacting us with your installation identifier, which is shown on the About screen within the application. Uninstalling the application also stops all further transmission, and the installation record expires automatically as set out above.
We respond to verified requests within 30 days.
This website
This website is served as static content. It sets no cookies, runs no analytics or tag management software, and embeds no third-party trackers, advertising, or social media widgets. Fonts, images, and stylesheets are served from this domain. Our hosting provider maintains standard server logs, including IP addresses, for security and operational purposes.
Children
The Service is not directed to children under 13, and we do not knowingly solicit or collect personal information from children under 13. Account creation requires a Google or Telegram account, each of which imposes its own minimum age requirement.
Where a parent or guardian installs the Service on a child's device without creating an account, the application collects the anonymous installation identifier, device and technical information, and usage statistics described above; it does not collect the child's name, email address, browsing history, or contacts. If you believe a child under 13 has provided us with personal information, contact us and we will delete it promptly.
Security
We maintain technical and organisational measures appropriate to the nature of the data we hold. Authentication credentials are never stored by us; sign-in is handled entirely by Google or Telegram. Session tokens are stored only as a one-way cryptographic hash, so a database compromise alone would not permit an attacker to authenticate as you. On your device, the session token is encrypted using a hardware-backed key that cannot be extracted. All traffic between the application and our servers is encrypted in transit using TLS. Access to production systems is restricted and protected by rate limiting and intrusion prevention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
International transfers
We are based in Bangladesh, and our service providers may process and store data in other countries, including within the European Union and the United States. Where personal data is transferred out of the UK or the European Economic Area, we rely on appropriate safeguards, including the standard contractual clauses adopted by the European Commission, or on a transfer being necessary for the performance of our contract with you.
Changes to this policy
We may update this policy from time to time. If we make a material change, we will revise the date at the top of this page and, where appropriate, provide notice within the application. Your continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
Contact
For questions about this policy, to exercise any of the rights described above, or to make a data protection complaint, contact us at ifactstudios@gmail.com. You may also reach us through our community channel at t.me/GazeGuardCommunity. We respond to verified requests within 30 days.