Privacy Policy

NotNow — Android application

Last updated: 21 September 2026

Local firstBlocking rules, schedules, and usage history are primarily stored on your device.
Optional accountAn account is optional, and cloud backup stays off until you enable it.
Your controlYou can review deletion details through the public account-deletion route.

1. Introduction

NotNow is an Android app for screen time and digital wellbeing. It lets you block or limit distracting apps and websites, set schedules, run focus sessions, and see where your time goes.

This policy explains what information the NotNow app handles, what stays on your phone, what is sent to us if you choose to create an account, and who else is involved. It covers the NotNow Android app and this website.

2. The short version

NotNow works on your device. You do not need an account to use any of the blocking, scheduling or statistics features, and if you never create one, the app does not send your settings or your activity to us.

If you do create an account and turn on cloud backup, a copy of your settings and your in-app history is uploaded so you can restore it on another device. Cloud backup is off until you switch it on.

NotNow contains no analytics SDK, no crash-reporting SDK, no advertising SDK and no tracking SDK. It does not use an advertising identifier. We do not sell your personal information, and we do not share it with advertisers.

3. Information on your device

The following is created and stored on your phone, in the app's private storage. It is not transmitted to us unless you enable cloud backup (see section 8).

Your settings

  • Which apps, websites and keywords you have chosen to block, and any app groups you create
  • Schedules, usage limits, launch limits and scroll controls
  • Focus session configuration and task lists
  • Guard Mode configuration, including whether adult-content filtering is enabled
  • Language, appearance and notification preferences

Your in-app history

  • Daily time totals per app, session counts and hourly breakdowns
  • Counts of blocks triggered, grouped by day, app and which feature triggered them
  • Counts of short-form video feeds ("reels") stopped, per day
  • Focus sessions started and completed
  • Weekly reports generated from the above
  • A record of how much time each NotNow feature protected for you

This history is stored as aggregate counters and totals — a date, an app's package name, and a number. NotNow does not keep a log of individual actions, messages, or content.

Uninstalling the app removes this data from your device. Note that Android's own backup system may hold a copy — see section 11.

4. Android Accessibility Service

NotNow uses Android's Accessibility Service API. This is the most sensitive permission the app asks for, so this section explains it in full.

Why NotNow needs it

Android does not give an ordinary app any way to find out which app you just opened, or to show something over it. The Accessibility Service API is the only mechanism available to a normal Play Store app that can do this. Without it NotNow cannot block anything. The features that depend on it are:

  • App blocking — noticing that a blocked app has come to the foreground, and showing the NotNow block screen over it
  • Website and keyword blocking — recognising a blocked site or search term in a supported browser
  • Adult-content filtering — recognising a site on the filter list, when you have enabled that feature
  • Short-form video ("reel") blocking — recognising that you have opened a video feed inside an app you have asked NotNow to intervene in
  • Usage limits, launch counters and scroll controls — measuring how long and how often a blocked app is actually in front of you
  • Obstacles and mindful pauses — showing a delay screen before an app opens

NotNow is not an assistive technology and does not present itself as one. It uses this API solely for the digital wellbeing features listed above, which you configure yourself.

What it observes

While it is enabled, the service receives accessibility events and can read the content of the window in front of you. Specifically, it looks at:

  • the package name of the app currently in the foreground;
  • the name of the screen (activity or window class) within that app;
  • the identifiers and structure of on-screen elements, which is how it tells a video feed apart from the rest of an app;
  • on-screen text, including the address bar and search field of supported browsers, so it can tell whether the page or search matches something you have blocked.

What happens to it

Each event is compared, in memory, against the rules you have configured, and then discarded. NotNow does not record, store, log or transmit the screen content, text, URLs or search terms it inspects.

The only things written to storage as a result are the aggregate counters described in section 3 — for example "today, 14 reels stopped" or "today, Instagram blocked 6 times". Those counters name the app and the date. They do not contain what was on screen.

No accessibility-derived information is sent to NotNow's servers, to Supabase, or to any other third party. It stays on your device, and it is not sold or shared.

You can turn the Accessibility Service off at any time in Android Settings. Blocking stops working when you do.

5. Notification access

NotNow includes an optional feature that holds back notifications from apps you are currently blocking, so a blocked app cannot pull you back in, and releases them when the block ends. This requires Android's notification access permission, which you grant separately in system settings. The feature does nothing until you both grant that permission and turn the setting on.

When it is active, NotNow sees the notifications posted on your device and checks which app sent each one. Normally it then asks Android to snooze that notification, and no content is copied anywhere.

If Android refuses the snooze, NotNow falls back to saving the notification so it can be shown to you again later. In that case it stores, on your device only, the sending app, the notification's title and text, and when it arrived — up to 100 held notifications at a time. These are deleted once they are replayed, and they are not included in NotNow's cloud backup, so they are never uploaded to us.

NotNow does not read, analyse, profile or transmit your notifications for any other purpose. Revoking notification access in Android Settings stops this entirely.

6. App usage and installed apps

Installed apps

To let you pick which apps to block, NotNow asks Android for the list of apps on your phone that can be launched, together with their names and icons. This list is used to draw the app picker and to match your rules. It is processed on your device and is not uploaded.

The package names of the apps you actually choose to block are part of your settings, and those settings are included in cloud backup if you enable it.

Usage statistics

With the Usage Access permission, NotNow reads Android's usage statistics to show you how long you spend in each app and to enforce the usage limits you set. It stores daily totals, session counts and hourly breakdowns per app on your device.

Android only keeps these statistics for a short window, so NotNow copies them into its own storage periodically in order to build a longer history for you. This history stays on your device unless you enable cloud backup.

7. Your NotNow account

An account is optional and is only needed for cloud backup and for premium features. You create one with an email address and a password. NotNow does not offer sign-in with Google or any other social login, and does not create anonymous accounts.

If you create an account, the following is stored on our backend:

  • Your email address and an internal account identifier, held by our authentication provider. Your password is never stored — the provider keeps only a salted hash of it.
  • A display name, if you choose to enter one. This is optional and you can change or clear it.
  • Your language preference, so the interface and any emails match it.
  • Your subscription status — whether you have an active subscription, which product, whether it is a trial, and when it renews or expires. This comes from Google Play through RevenueCat, not from you.
  • If you use cloud backup, a small record describing your stored archive: its size, when it was saved, how many days of history it covers, your device's model name (for example "Pixel 8"), and the app version that saved it.

NotNow does not generate or collect a device identifier, an advertising ID, or any hardware identifier such as IMEI, MAC address or Android ID.

NotNow does not request or collect your contacts, location, photos, microphone, camera, call logs or SMS. The app does not declare those permissions.

8. Cloud backup

Cloud backup is off by default. You need an account, and you have to switch it on. If you never do, no archive is uploaded.

When it is on, NotNow uploads a single archive file to private storage in your account, replacing the previous one each time. Please read what that archive contains, because taken together it says a lot about you:

  • Which apps you have chosen to block — and therefore which apps you have installed
  • Which websites and keywords you block, including whether you have enabled adult-content filtering
  • Your schedules and routines, which describe your daily and weekly rhythm
  • Your usage history: how long you spent in each app, on which days, and how often you were blocked
  • Your focus sessions, the feeds you stopped, your saved weekly reports, and the record of time each feature protected

We treat this as sensitive. The storage bucket is private, access is restricted at the database level so that only your own account can read your archive, it is transmitted over an encrypted connection, and it is encrypted at rest by our hosting provider. We do not analyse it, mine it, or use it for anything other than restoring it to your device when you ask.

What we will not claim. The archive is not end-to-end encrypted. It is encrypted in transit and at rest, but it is not encrypted with a key only you hold, so in principle our infrastructure could access it. We do not, and access is restricted — but we would rather say this plainly than imply a protection we have not built.

What is never uploaded

  • Your Guard Mode PIN. The PIN and everything derived from it are removed before the archive is written, so the PIN is not in your local backup, not in an archive you export, and not in the cloud copy. Restoring a backup does not bring your PIN back — you set a new one.
  • Whether Guard Mode is currently armed, and when a lock expires
  • Any focus session that is currently running
  • Held notifications (see section 5)

9. Local versus cloud, at a glance

Processed only on your device — never sent to us

  • Everything the Accessibility Service observes: foreground app, screen names, on-screen text, browser addresses, search terms
  • The list of apps installed on your phone
  • Notification content held by the optional notification feature
  • Raw Android usage statistics

Stored in your NotNow account — only if you create one

  • Email address, internal account identifier, optional display name, language preference
  • Subscription status

Stored in your NotNow account — only if you also enable cloud backup

  • Your settings: blocking rules, schedules, groups, preferences
  • Your in-app history: per-app daily totals, block counts, focus sessions, weekly reports
  • The archive's description: size, date, days covered, device model, app version

Detecting which app is in the foreground happens entirely on your phone. It is not a transmission to us, and nothing in this policy should be read as saying otherwise.

10. Why we process this information

  • Email address and account identifier — to create your account, verify it, let you sign in, and let you reset your password.
  • Display name and language preference — to show your chosen name in the app and present the interface and emails in your language.
  • Foreground app, screen structure and on-screen text — to decide, in the moment, whether a rule you configured applies, and to show the block screen. Not retained.
  • Usage statistics — to show you your screen time, to enforce the limits you set, and to build your weekly reports.
  • Installed app list — to let you choose which apps to block.
  • Notification sender — to hold notifications from apps you are currently blocking, when you have turned that feature on.
  • Backup archive and its description — to restore your settings and history on request, and to tell you which device last saved a backup.
  • Subscription status — to unlock premium features on the devices where you sign in.
  • Support messages — to answer you. If you email us, we hold your message and your email address for as long as needed to deal with your request.
  • Security and abuse prevention — to protect accounts and keep the service working.

11. Third parties

NotNow contains no analytics, crash-reporting, advertising or tracking SDK. The following third parties are nonetheless involved in running the service, and we list all of them.

Supabase — authentication, database and storage

Supabase provides the backend for accounts. If you create one, it processes your email address, password hash, account identifier, display name, language preference and subscription record, and — if you enable cloud backup — it stores your archive file. Supabase does not receive accessibility data, notification content, your installed-app list, or raw Android usage statistics.

RevenueCat and Google Play — subscriptions

Subscriptions are sold and charged by Google Play, which is the seller of record and handles all payment processing. NotNow never sees or receives your card or bank details.

RevenueCat validates and synchronises purchases on our behalf. It receives your NotNow account identifier and the purchase information Google Play provides, and it tells our backend whether your subscription is active. Google Play also processes purchase information independently, under its own privacy policy.

GitHub — the adult-content filter list

The domain list used by the adult-content filter is a public file that NotNow downloads about once a week from raw.githubusercontent.com, so the filter stays current. This is a one-way download of a public file: no account information, settings, usage data or identifiers are sent with the request. As with any download, GitHub can see the IP address the request came from. This download currently happens on devices running NotNow whether or not the adult-content filter is switched on.

Email delivery

Account verification and password-reset emails are sent through our authentication provider's email infrastructure, which necessarily receives your email address in order to deliver them.

Mail you send to the contact address in section 20 arrives in a mailbox hosted by Google. Google therefore handles that correspondence in the course of delivering and storing it, under its own privacy policy, in the same way it would for mail you sent to any other Gmail address.

Android's own backup — a Google service, under your control

Separately from NotNow's cloud backup, Android itself may copy app data to your own Google account, and may transfer it when you set up a new phone. For NotNow this can include the on-device statistics database, the NotNow backup archive file, and other files the app keeps — including any notifications it is currently holding. Your NotNow sign-in credentials are deliberately excluded and never ride along, and neither does your Guard Mode PIN.

This is a Google feature, governed by your Android backup setting and by Google's privacy policy, not something NotNow sends us. You can turn it off in your device's backup settings.

12. Selling personal information

We do not sell your personal information, and we do not share it for advertising or cross-context behavioural advertising. NotNow has no advertising SDK and no advertising identifier.

The providers listed in section 11 process data on our behalf so the service can function. That is not a sale, and they are not permitted to use your data for their own purposes.

13. Where data is stored

Account data and backup archives are stored on infrastructure operated by Supabase, our hosting, database and authentication provider.

The production backend runs in Supabase's West EU (Paris) region. Your account and, if you turn it on, your backup archive are therefore stored in the European Union.

That was a deliberate choice: we want your data held close to us, under a data protection regime we can hold our provider to. If we ever have to move it — to a different region, or to a different provider — it will only ever go to the European Union or the United States, and nowhere else. We will update this page, and the date at the top of it, before any such move takes effect. A move to the United States would be an international transfer under the GDPR, and we would put the safeguards that requires in place first.

The other companies in section 11 are separate from this. Google Play and RevenueCat operate internationally and handle purchase information under their own terms and their own privacy policies, not ours.

14. How long data is kept

  • Account data — kept until you delete your account. See section 15 for what deletion involves.
  • Backup archive — we keep only your most recent archive. Each upload replaces the previous one. It is removed when you delete your stored backup from the app, and when your account is deleted.
  • History inside the archive — limited by the retention window you choose in the app, between 1 and 12 months. The default is 6 months. Older entries are trimmed.
  • Data on your device — kept until you delete it in the app or uninstall the app.
  • Held notifications — kept on your device until they are released, up to 100 at a time.
  • Support messages — kept for as long as needed to handle your request and for a reasonable period afterwards.

The rule behind those lines is a simple one. Once you ask for your account to be deleted, everything held with it is erased at the end of the 90-day window described in section 15, and we keep no copy of it afterwards. Two things sit outside that rule: email you have sent us, which is kept only as long as your request needs, and the billing records below, which are held by Google rather than by us.

Billing records

NotNow does not process payments and holds no card, bank or billing details. Subscriptions are sold and charged by Google Play, which is the seller of record. The only purchase information on our side is the subscription record attached to your account — whether it is active, and when it runs out — together with the events that have changed it. That is account data like any other: it is erased with the rest of your account at the end of the same 90-day window, and we keep no billing archive of our own afterwards.

The legal bases for holding it are performance of a contract while your subscription is running, because we need the record to give you what you are paying for, and our legitimate interest during the 90 days, so that an account deleted by mistake can still be recovered intact. Should a specific law ever require us to keep something connected to a purchase for longer — a tax or accounting obligation, for example — we would keep only what that law asks for, for no longer than it asks, on the basis of that legal obligation.

Your receipts, invoices and purchase history sit with Google, not with us, because Google is the company that took your payment. Google keeps them under its own terms and its own retention periods. We cannot see them, change them or delete them, and deleting your NotNow account does not remove them. For anything to do with that record — a receipt, a refund, or cancelling a subscription — you need to go to Google Play. The same applies to the payment method you used there, such as Google Pay: it is governed by that provider's rules, not by this policy.

15. Account and data deletion

You can delete your NotNow account, and you can do it either from inside the app or from this website.

  • In the app: Profile → Account → Delete account.
  • On the web: request deletion here, without installing or opening the app.

How deletion works:

  1. Your account becomes inactive immediately and you are signed out on every device.
  2. There is then a 90-day window during which nothing is destroyed. If you change your mind, signing in again within those 90 days reactivates the account with everything intact.
  3. After 90 days, your account and the data held with it are permanently erased: your profile, your subscription record, your cloud backup archive and its description, and the deletion request itself. This cannot be undone.

What deletion does not cover:

  • Data on your device. Your blocks, schedules, statistics and Guard Mode keep running on the phone itself. Uninstall the app to remove that.
  • Your subscription. Deleting your account does not cancel it, and you will keep being charged until you cancel it in Google Play.
  • Copies held by Google, including Play purchase records and anything in Android's own backup of your device.
  • Records we are legally required to keep, such as those connected to a purchase.

16. Your privacy rights

Depending on where you live, you may have rights over your personal data. If you are in the EU/EEA or the UK, the GDPR gives you the right to access your data, to have it corrected, to have it erased, to restrict or object to how it is processed, and to receive it in a portable form. You also have the right to complain to your national data protection authority — in Spain, where we are established, that is the Agencia Española de Protección de Datos (aepd.es).

In practice you can exercise most of these yourself:

  • Access and portability — the app's backup export produces your settings and history as a machine-readable archive. You can also ask us for a copy.
  • Correction — your display name, language and every setting are editable in the app.
  • Erasure — see section 15.
  • Withdrawing consent — you can turn cloud backup off, and delete the stored archive, at any time. Doing so does not disable any on-device feature.

For anything else, contact us at the address in section 20. We will respond within one month.

NotNow has not appointed a Data Protection Officer, and is not required to. Where a legal basis is needed under the GDPR, we rely on: performance of a contract, for creating and running your account and your subscription; your consent, for cloud backup, which you can withdraw at any time; and our legitimate interests, for security and abuse prevention.

17. Age and younger users

There is nothing in NotNow that is unsuitable for a younger user: no advertising, no age-restricted content, no chat, no social feed. It is a tool for spending less time on a phone, and it is useful at any age. It is also a tool that changes how a phone behaves, which is not something a young child should be left to configure alone.

  • Using NotNow. We recommend a minimum age of 12 to set NotNow up and use it on your own.
  • Younger users. For anyone aged 13 or under, we recommend that a parent, guardian or other adult goes through the setup with them — choosing what to block, setting the schedules, and keeping the Guard Mode PIN — even if they use the app by themselves afterwards. The whole app works on the device with no account, so a child need not give us anything at all.
  • Creating an account. You must be at least 13 to create a NotNow account. An account is optional, and no feature of the app depends on having one.

If you are in the EEA or the United Kingdom and are below the age at which your country lets you agree to an online service by yourself — it is between 13 and 16, depending on the country — then a parent or guardian has to agree to the account, and to cloud backup, on your behalf.

NotNow is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created a NotNow account, write to us at the address in section 20 and we will delete it.

18. Security

We use measures appropriate to the data involved:

  • Network traffic uses encrypted HTTPS connections; the app does not permit unencrypted connections.
  • We never store your password. Authentication is handled by Supabase Auth, which keeps only a salted hash.
  • Your sign-in session is stored on your device encrypted with a key held in the Android Keystore, so it cannot be read off the device.
  • Access to account data is enforced at the database level by row-level security, so one account cannot read another's data. The backup storage bucket is private.
  • Your Guard Mode PIN is never included in any backup, local or cloud.

No system is completely secure, and we cannot guarantee absolute security. If you find a vulnerability, please report it to the contact address in section 20 so we can fix it.

19. Changes to this policy

We will update this policy as the app changes. The "last updated" date at the top always reflects the current version. If a change materially affects how your information is handled, we will make that clear in the app before it takes effect.

20. Contact

For any privacy question, to exercise your rights, or to report a security issue, contact:

One address covers all of it: privacy questions, requests under section 16, account deletion, security reports, and ordinary support. Write to us in English or Spanish. We reply as quickly as we can, and within one month at the latest for a request made under section 16.

Never send us your password. We will never ask for it and we never need it — not to delete an account, not for support, not for anything. Please leave one-time codes, recovery codes and payment-card details out of your message as well.

Who is responsible for your data

NotNow is made and run by one person, not a company. The data controller responsible for everything described in this policy is:

Tales Galilea Rodrigues
Calle Aurelio Diez 15
39470 Renedo de Piélagos
Cantabria, Spain

You can write to that address if you prefer post, but email is faster and is the route we recommend for a request under section 16.