Coldscroll

Privacy

Privacy policy

Last updated 13 September 2026. Written for the Android closed beta (app.coldscroll 0.2.0) and this website.

This is a draft policy for a closed beta, but it is the real one we use for Google Play’s privacy policy URL and Data safety form. It describes what the current build actually does — not a future product.

Coldscroll is run from Australia. Questions or deletion requests: hello@coldscroll.com.

We do not sell your information. We do not run ads. This build does not include analytics or crash-reporting SDKs.

Where the service lives

Fly and Cloudflare process data for us so the app and site can run. We do not sell data to them or to anyone else. Cloudflare may serve this website from locations outside Australia. Account data for the app is hosted in Sydney.

What we collect

Usage access (Insights)

Android Usage access lets Coldscroll see time in apps on this phone so Insights can show you a receipt, and so daily limits know how many minutes are left.

That on-device history is not uploaded as a dump. If you set a daily limit on an app, the phone sends short heartbeats (package name + seconds) to our API while that app is in the foreground, so the remaining budget can be enforced.

Accessibility Service (blocking only)

Coldscroll is not an accessibility aid. The Accessibility Service is used only to see which app is in the foreground and to show our lock screen if that app is on your list (or has used up its daily budget).

It does not read page content, what you type, notifications, or the web page you are looking at. More detail: Accessibility Service disclosure.

Why we use it

To run your account, sync lock rules, enforce limits and sessions, and let a partner unlock you. We do not use this for advertising, marketing lists, or selling data. If you create an account, the types above are part of how the app works — not optional tracking.

What we do not collect

We do not collect contacts, photos, location, payment details, or an advertising ID. The installed-app picker stays on your phone; only apps you add to the block list are sent to the API. Local sign-in prefs are left out of Android backup.

Google Play Data safety (short map)

On the Play form we declare collection of: email address; user IDs (sign-in token); other info (password hash, timezone, partner PIN hash); other user-generated content (lock rules); and app interactions (limit heartbeats). Shared with third-party products: no. Encrypted in transit: yes (HTTPS to Fly). Sold: no.

Deletion and your rights

Uninstalling the app clears it from the phone. It does not delete the server account.

Email hello@coldscroll.com from the account address and ask us to delete it (subject “Delete my Coldscroll account”). We will remove the account and the lock data attached to it.

You can also email to ask what we hold or to correct it. There is no in-app “delete account” button in 0.2.0 — email is the path for this beta. There is no email reset for a lost partner PIN.

If you are in Australia and you are not satisfied, you can complain to us first, or to the Office of the Australian Information Commissioner.

Children

Coldscroll is not aimed at children under 13. If we have an account for a child, email us and we will delete it.

Changes

If this policy changes in a material way, we will update the date at the top. This is still a beta — we will keep the page honest as the app changes.