Privacy Policy
Thank you for choosing to be part of the Social Limits community ("Company", "we", "us" or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, how we store and protect it, and what rights you have in relation to it. It is designed to meet the disclosure requirements of the Google Play Developer Program Policy, including the Health Apps and User Data sections.
1. Definitions
For the purposes of this Privacy Policy:
| Term | Meaning |
|---|---|
| Application / Service | The Social Limits mobile application, website and any associated services. |
| Health & Fitness Data | Personal and sensitive data related to your physical activity (e.g. step count, distance walked, active minutes, activity recognition) that our app accesses through Google Fit, Health Connect, Apple Health, device motion & fitness sensors, or on-device APIs. |
| Personal Data | Any information that relates to an identified or identifiable individual, including Health & Fitness Data. |
| Processing | Any operation performed on Personal Data such as collection, storage, use, sharing, or deletion. |
2. What Data We Collect
2.1 Account & Contact Data
- Email address
- First and last name
- Phone number (where provided during onboarding)
- Password or authentication token
Where you provide your phone number, we use it for account verification, service-related messages, and reminders you have opted into. We do not use your phone number for third-party marketing, and we do not sell it.
2.2 Usage Data
Automatically collected technical data about how you interact with the Service (e.g. IP address, device model, OS version, time stamps, in-app events).
2.3 Health & Fitness Data
| Data type | Source | Purpose |
|---|---|---|
| Step count & distance | Google Fit / Health Connect / Apple Health or phone motion sensors | Core feature — unlocks social apps once your daily goal is reached |
| Activity state (walking, running, idle) | On-device Activity Recognition API | Gamification (leaderboard, streaks) & accurate goal tracking |
We do not collect heart-rate, location routes, medical conditions, or any other sensitive health data.
2.4 App Blocking & Screen Time Data
To provide the core blocking feature, Social Limits uses your device's screen-time management framework (Apple's Screen Time / Family Controls on iOS, or the equivalent on Android). When you select which apps to block:
- Your app selections are handled by the operating system using privacy-preserving references. On iOS, Apple's framework provides these as opaque tokens, meaning we cannot see which specific apps you have chosen by name.
- We do not monitor, collect, or receive your activity inside other apps, your browsing history, your messages, or the content of anything you view.
- Blocking state (whether your apps are currently locked or unlocked) is processed to operate the feature and display your status.
You can revoke Screen Time / app management permission at any time in your device settings, which will disable the blocking feature.
2.5 Advertising Attribution & Device Identifiers
We promote Social Limits through advertising channels (such as Meta and TikTok). To measure whether our advertising works, we use a mobile measurement partner (AppsFlyer) and platform-provided attribution frameworks (such as Apple's SKAdNetwork).
- What is processed: device identifiers (such as IDFV, and IDFA/advertising ID only where you have given consent via your device's tracking prompt), install and campaign attribution data, and limited in-app events (such as completing onboarding or starting a subscription).
- What is never processed for advertising: your Health & Fitness Data. Step counts and activity data are never shared with advertising or attribution partners, never used to build advertising audiences, and never used in attribution events.
- Your choices: On iOS, you can decline tracking via the App Tracking Transparency prompt or in Settings → Privacy & Security → Tracking. On Android, you can reset or delete your advertising ID in system settings. Declining does not affect app functionality.
3. How We Use Your Data
| Purpose | Lawful basis |
|---|---|
| Provide and maintain the Service (e.g. determine when social media blocking is lifted) | Performance of contract — providing the features you requested |
| Analytics & product improvement (aggregate, de-identified metrics only) | Legitimate interests — improving app reliability & user experience |
| Send service-related communications (e.g. goal reminders, policy updates) | Legitimate interests / Consent |
| Legal compliance & security (fraud prevention, dispute resolution) | Legal obligation / Legitimate interests |
| Measure advertising effectiveness and attribute app installs (excluding all Health & Fitness Data) | Consent (where required, e.g. App Tracking Transparency) / Legitimate interests |
Health & Fitness Data is never used for advertising, marketing, credit scoring, or sold to third parties. We do not combine it with other data to infer sensitive attributes.
4. Sharing & Disclosure
We share Personal Data only in the following situations:
- Service providers — cloud hosting, analytics, crash reporting. They act under written agreements that require confidentiality and security.
- Platform integrations — when you connect Google Fit, Health Connect, or Apple Health, activity data flows between your device and those platforms on your instruction. We do not receive other data stored in those services.
- Legal obligations — to comply with court orders or lawful requests.
- Business transfers — in the event of a merger or acquisition (with notice to you).
- Attribution & advertising measurement — we share device identifiers and limited non-health in-app events with our mobile measurement partner (AppsFlyer) and advertising platforms solely to measure campaign performance. Health & Fitness Data is never included.
We do not share Health & Fitness Data with advertising networks, data brokers, or other unrelated third parties.
Employer and partner programs. Where you access Social Limits through an employer, government, or partner wellbeing program, that organisation receives only aggregated, de-identified program statistics. We never provide your individual step counts, health data, blocked-app selections, or usage activity to your employer or any program partner.
5. Payments & Subscription Data
Subscriptions are billed through the Apple App Store or Google Play. We do not receive or store your full payment card details for these purchases; payment is processed by Apple, Google, or our payment processor under their own privacy policies. We store only the information needed to operate your subscription (such as subscription tier, status, renewal date, and transaction identifiers) and, where required, for tax and accounting compliance.
6. Retention
- Account & Contact Data: kept while your account is active plus 12 months, then deleted or irreversibly anonymised.
- Health & Fitness Data: stored locally on your device and retained on our servers (hosted on Google Firebase) for as long as your account is active, so that your step history, streaks, and progress statistics can be displayed. When you delete your account, associated Health & Fitness Data is deleted from our systems within 30 days, unless a longer retention period is required by law.
- Usage Data: retained for 24 months for security and analytics, then aggregated.
You can delete your account at any time from the in-app settings or by emailing sociallimitsb@gmail.com. Deletion triggers irreversible erasure of associated Personal Data within 30 days unless retention is required by law.
7. Security
Where your data is stored. Personal Data collected through the Service is stored on secure Google Cloud (Firebase) infrastructure located in Singapore (asia-southeast1 region). Access to Personal Data is restricted to personnel who have completed privacy and data-handling training and who require access for a legitimate operational purpose (such as responding to a support request you have made or maintaining the security of the Service). Access is granted on a least-privilege, need-to-know basis — it is not available to all staff by default.
We apply industry-standard safeguards to protect Personal Data:
- Encryption in transit (TLS 1.2+) and encryption at rest (AES-256).
- Strict access controls, least-privilege policies, and multi-factor authentication for employees.
- Regular security audits and vulnerability scanning.
Despite our efforts, no internet transmission or storage system can be 100% secure. We therefore cannot guarantee absolute security.
8. Your Rights & Choices
Depending on your jurisdiction, you may have rights to:
- Access the personal information we hold about you.
- Rectify inaccurate or incomplete data.
- Delete your data ("right to be forgotten").
- Object / restrict certain processing.
- Data portability.
- Withdraw consent at any time (this does not affect processing carried out before withdrawal).
Requests can be made via the in-app settings or by emailing sociallimitsb@gmail.com. We respond within 30 days.
9. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect Personal Data from children under 13. Users aged 13 to 17 may only use the Service with the consent of a parent or legal guardian. If we become aware that we have inadvertently collected Personal Data from a child under 13, or from a minor without appropriate consent, we will delete it promptly.
10. International Transfers
Social Limits is operated from Australia, and Personal Data is stored on Google Cloud (Firebase) servers located in Singapore. By using the Service, you acknowledge that your data will be transferred to and processed in Singapore and, for limited purposes, by our service providers (such as analytics, attribution, and payment providers) in other jurisdictions. Where data protection laws in your jurisdiction (such as the GDPR or UK GDPR) require safeguards for international transfers, we rely on standard contractual clauses or equivalent legal mechanisms — including those incorporated into Google Cloud's data processing terms — to ensure your data receives adequate protection.
11. Australian Privacy Law
Social Limits Pty Ltd complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme. If you are dissatisfied with our handling of a privacy complaint, you may lodge a complaint with the OAIC at www.oaic.gov.au.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last updated" date and will be effective as soon as it is accessible. We will notify you of material changes via email or an in-app notice.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Email: sociallimitsb@gmail.com
Health Connect & Platform Disclosure (Android-specific)
When you connect Social Limits to Google Fit or Health Connect, Android will present a permissions dialog describing the exact data types (e.g. Steps, Distance) that the app requests. Granting permission allows Social Limits to read those data types solely to enable the core feature of unlocking social media once your daily step goal is achieved. Social Limits does not write data back to Google Fit/Health Connect and does not share the retrieved data with third parties. You can revoke access at any time in Android → Settings → Security & privacy → Health Connect.
Apple Health & Screen Time Disclosure (iOS-specific)
When you connect Social Limits to Apple Health (HealthKit), iOS will present a permissions screen listing the exact data types requested (Steps). Granting permission allows Social Limits to read step data solely to determine when your daily goal is reached and to display your progress. In line with Apple's requirements, data obtained through HealthKit is never used for advertising or marketing, never shared with data brokers, and never sold.
Separately, the app-blocking feature uses Apple's Screen Time (Family Controls) framework. Your blocked-app selections are represented by Apple as privacy-preserving tokens; we cannot see the names of the apps you select, and we receive no information about your activity within other apps. You can revoke either permission at any time in iOS Settings.
Data Safety Summary (Google Play Console)
| Data Type | Collected? | Shared? | Purpose | Required? |
|---|---|---|---|---|
| Step count & distance (Health & Fitness) | Yes | No | Core functionality (unlock) | Yes |
| Activity recognition | Yes | No | Goal tracking & analytics | Yes |
| Email, name | Yes | Yes (auth & messaging provider) | Account creation, communication | Yes |
| Usage diagnostics & device identifiers | Yes | Yes (measurement partner — AppsFlyer) | Analytics, crash detection, install attribution | No (opt-out) |
| Phone number | Yes | No | Account verification & service messages | No (optional) |
This table is provided for transparency; the authoritative source is the Data Safety form in the Play Console.