Privacy policy
Last updated: 6 October 2026
The short version
- Images never leave your device. The app checks your screen on the phone, and the browser extension checks pictures in your browser, in memory. Nothing you see is stored or sent anywhere.
- No browsing history is uploaded. We never see which websites you visit, from the app or from the browser extension.
- The browser extension works without an account, and then sends us nothing at all.
- Your account holds very little: your name, email, sign-in details, your GlanceOff settings, your change requests, your purchase status, and basic device details.
- No advertising, no analytics trackers, no selling of data. Ever.
- You can export your data from the app and delete your account at any time. Deletion takes effect after 30 days (explained below).
1. Who we are
GlanceOff is operated by DCBYTES S.R.L, Blaj, Coriolan Suciu 1, Romania, registration number RO48659422 ("we", "us"). We are the controller of the personal data described here.
Contact for anything about privacy: contact@dcbytes.ro.
This policy covers the GlanceOff Android app, the GlanceOff browser
extension (for Chrome, Edge and Firefox), the GlanceOff account service
at glanceoff.dcbytes.ro, and the pages accountability
partners open from our emails.
2. What stays on your device
On your phone
GlanceOff protects you by checking what is on your screen and, if you turn it on, by filtering web addresses. Both happen on your phone.
- Screen checks. With your permission, the app uses Android's accessibility service to take a screenshot every few seconds and checks it with a detection model that runs on the phone. The image is analysed in memory and discarded straight away. No screenshot, crop, thumbnail, fingerprint (hash), or any other representation of your screen is saved or sent anywhere, not to us and not to anyone else.
- Detection history. The app keeps a local log with the time, the app that was open, the category, and the confidence numbers. Nothing in it could recreate what was on the screen. This log stays on your phone and is never uploaded.
- Safe browsing tunnel. If you turn it on, the app sends your phone's DNS lookups (the step that turns a website name into an address) directly to the filtering provider you picked, for example CleanBrowsing, Cloudflare for Families, OpenDNS FamilyShield or AdGuard Family. They don't pass through us. That provider's own privacy policy applies to those lookups. The app does not log them unless you turn on a debug log, which stays on the phone.
In your browser (the browser extension)
The extension covers revealing pictures on the pages you visit and, if you leave it on, blocks adult websites. Both happen in your browser.
- Picture checks. The extension finds the pictures on each page and keeps them blurred until they are checked. To check one, it downloads the picture from the website that serves it, the same way your browser does to show it, and judges it with a detection model that runs inside your browser. The picture and the result are kept only in memory, and only while the browser is running. No picture, page, address or result is saved to disk or sent to us or anyone else.
- Site blocking. Page addresses and searches are checked against lists that come with the extension, and against your own block and allow lists. Nothing is looked up online.
- What the extension keeps in your browser. Your settings, your block and allow lists, a random install ID it creates for itself, and, if you sign in, your sign-in session and a copy of your account settings for that browser, so protection keeps working offline.
- Without an account, the extension sends us nothing at all. With one, it sends only what section 3 lists.
3. What we store on our servers, and why
You can use the app's core protection, and all of the browser extension, without an account. An account exists so that your settings, your accountability timer and your partner survive a reinstall or a new device. Otherwise, uninstalling would be a free way around your own safeguards.
| What | Details | Why |
|---|---|---|
| Account | Display name, email address, whether the email is verified, password (stored only as an Argon2id hash, never readable), your Google account ID if you sign in with Google, account creation date. | To run your account and let you sign in. |
| Device | A device ID for GlanceOff on that phone (a one-way fingerprint of the ID Android gives GlanceOff; other apps see a different one, and it stays the same if you reinstall GlanceOff), phone model, Android version, app version, a push notification token, and when the phone last checked in. For the browser extension: the random install ID it created, the browser and its major version (for example "Chrome 141"), the type of operating system (for example Windows), the extension version, and when it last checked in (once a day while signed in). Browsers have no push notification token. | To keep your devices in sync, to send approval notices to the right phone, to tell your partner which kind of device a request comes from, and to notice when a protected phone stops checking in (section 5). |
| Protection settings and lists | Your GlanceOff settings, plus the websites and apps you put on your own allow and block lists, and which block lists are switched on. Each phone and browser keeps its own settings and lists; your accountability partner is the same on all of them. Lists you import from a file stay on the phone. | So your protection is restored on reinstall and cannot be loosened without your accountability step. |
| Change requests | Which setting you asked to change, on which kind of device, when, the timer, and the outcome (approved, denied, applied), with your partner's optional note. | The accountability feature itself. |
| Accountability partner | Your partner's name and email address, whether they accepted, and when. | To email them your requests (section 4). |
| Purchases | Your subscription or lifetime status, product, trial start and expiry dates. We never see your card or payment details. | To unlock paid features. |
| Tamper history (optional) | Only if you turn on history backup: time, kind (for example "accessibility turned off") and severity of tamper events. No content. | So the history survives a reinstall. |
| Security and server logs | Our server logs record the time, the address called, the result and your user ID. Google Cloud's own request logs also record your IP address and the app's technical identifier (user agent). We log sign-in abuse signals, such as a reused sign-in token. | To keep the service secure and working. |
We never collect: screenshots or anything derived from your screen, the pictures, pages or addresses you see in your browser, browsing history, the detection log, your contacts, your location, photos or files, advertising IDs, or analytics about how you use the app or the extension.
The browser extension's use of information follows the Chrome Web Store User Data Policy, including the Limited Use requirements: the data above is used only to provide the extension's features, never transferred for any other purpose, never sold, and never used for advertising or to decide creditworthiness.
Legal bases (GDPR)
- Contract (Art. 6(1)(b)): your account, syncing, change requests, partner emails you ask for, and purchases.
- Legitimate interests (Art. 6(1)(f)): security logs and abuse prevention, and telling you (and your partner, if you have one) when a protected phone stops checking in, which is part of the protection you signed up for.
- Legal obligation (Art. 6(1)(c)): records we must keep by law, for example for tax.
Using an app like this can reveal something about you, namely that you want to avoid explicit content. We keep that to the minimum above, never share it for any other purpose, and never use it for advertising or profiling.
4. If you are someone's accountability partner
If a GlanceOff user named you as their accountability partner, we hold your name and email address because they gave them to us, together with whether you accepted and when. We use them only to send you:
- one invitation, which you can accept or decline;
- if you accept, one email each time they ask to loosen a setting, naming the setting and the kind of device (for example "in their browser (Chrome)") only, never any screen content, website, app, or browsing, with Approve and Deny buttons;
- a notice if their protected phone stops checking in for more than 48 hours.
Every email has a link to stop being their partner. It works immediately, without an account or a reason, and we then stop emailing you. The legal basis is our legitimate interest in providing the feature the user asked for, which you can end at any time. If you decline or step down, we keep your name, email address and that fact until that user's account is deleted, and we send you nothing more about their requests. You can ask us to erase it sooner at contact@dcbytes.ro.
5. The "phone stopped checking in" notice
Deleting the app is the simplest way around it, so GlanceOff notices when a signed-in phone has been silent for 48 hours and our push notification service reports that the app is no longer installed. When that happens, we email you, and your accountability partner if you have one, once. No other information is included.
This notice is for phones only. Browsers cannot be reached by push notifications, so a browser that stops checking in sends no email; it is simply removed from your account after 90 days (section 7).
6. Who processes data for us
We use these providers, under data processing agreements, only to run the service:
| Provider | What for | Where |
|---|---|---|
| Google Cloud (Google Ireland Ltd.) | Hosting the service, key management, storage, logs | Belgium (EU) |
| Neon | Database | Frankfurt, Germany (EU) |
| Firebase Cloud Messaging (Google) | Push notifications to wake the app (they carry no personal content) | Global |
| Resend | Sending emails (verification codes, password resets, partner emails) | USA |
| RevenueCat | Checking purchases with Google Play | USA |
Google Play processes your payments as an independent controller under Google's own privacy policy. If you sign in with Google, in the app or in the browser extension, Google tells us your name, email address and Google account ID. The Chrome Web Store, Microsoft Edge Add-ons and Firefox Add-ons distribute the extension under their own privacy policies; installing it shares nothing with us.
Where data is handled outside the EU (Resend, RevenueCat, and possibly Google), it is protected by the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
We do not sell or rent personal data, and we share it with nobody else, except where the law requires it.
7. How long we keep it
- Account data: for as long as you have the account.
- Device records: removed when you sign out on that phone or browser, or after 90 days in which it never checked in.
- After you ask to delete your account: deletion is scheduled for 30 days later, and signing in during those 30 days cancels it. This delay is deliberate: deleting the account would otherwise be a quick way around a waiting period you set for yourself, so it gets the longest delay in the app. On day 30 everything tied to the account is erased. Database backups roll over within 7 days after that.
- Tamper history: 12 months.
- Security records: 12 months. Server request logs: about 30 days.
- Email links (password reset, partner links) expire after 1 hour to 30 days. We only ever store a one-way fingerprint of them.
- Purchase records that we must keep for tax or accounting: as long as the law requires.
8. Your rights
You have the right to access, correct, delete, restrict or object to the processing of your data, and to get a copy of it in a portable format. You can:
- Export everything your account holds as a file, from the app or by asking us.
- Change your display name in the app. To change your email address, contact us.
- Delete your account from the app, or by asking us (subject to the 30 day delay above).
For anything else, email contact@dcbytes.ro. We answer within one month. You can also complain to the authority in the EU country where you live.
9. Security
Everything travels over encrypted connections (HTTPS). Passwords are stored as Argon2id hashes. Sign-in and email link tokens are stored only as one-way fingerprints. The key that signs our time service is held in Google Cloud's key management service, and nobody, including us, can extract it. Access to production systems is limited to the people who run the service.
10. Children
GlanceOff accounts are for people aged 16 or over. If someone younger uses GlanceOff, a parent or guardian should set it up and hold the account. If you believe a child under 16 created an account without that, contact us and we will delete it.
11. Changes
If we change this policy in a way that matters, we will tell you in the app or by email before the change takes effect. The date at the top shows the latest version.