Deutsch · 日本語 · 한국어 · Español · Français
Privacy Policy — Unwind
Effective date: October 5, 2026
Unwind is an Android app that asks you to trace a path with your finger before a distracting app opens. This policy explains, in plain words, what the app does and does not do with information. The short version: Unwind has no server and no account, and no code we wrote opens a network connection, so the app never sends anything it records about you anywhere. What it records is kept on your phone, and in your own Google account only if Android's backup copies it there. Google's billing library, which the app needs to sell itself, sends Google diagnostics of its own, and none of what Unwind records is in them.
The accessibility service
The app lock works through an Android accessibility service. When you switch apps, Android tells the service that a window has come to the front. That notice carries the technical name of the app now on screen (for example, com.instagram.android), along with details such as the window's title. The service reads the app's name and ignores the rest.
- The service compares that name, on your phone, against the list of apps you chose to lock. If it matches, the trace screen opens.
- It reads no screen content, no text, no messages, no passwords and no screenshots — only the app's package name. The service is configured with
canRetrieveWindowContent="false", which means it cannot look inside any window, and it listens for one kind of event only: a window coming to the front. - It does not open the trace screen while your phone is locked, or while Android reports a call ringing or under way. To know that, it asks Android whether the phone is locked and whether its sound is set for a call. Nothing about either answer is stored or sent.
- If you unlock the phone into an app you crossed out, the trace screen opens once the lock screen has gone. That includes a call or an alarm from a crossed-out app that is showing over the lock screen: answer it there, with the buttons on the lock screen, and the trace screen stays out of the way, because a call that is answered is a call under way.
- The name is never sent anywhere. There is no "anywhere": the app has no server, and no code we wrote opens a network connection.
So that one trace covers one visit, the service also holds two things in its memory while it is running: the name of the app you are in right now — a single name, replaced when you move to another app — and a note that you have already traced for an app, which lasts as long as you stay in that app. Opening a keyboard, a photo picker or a system dialog inside it does not ask you to trace a second time; leaving for another app, for the home screen, or letting the screen go dark ends the note, and coming back costs another trace. A visit to Unwind itself, such as opening a card someone sent you, does not end it. Opening this policy from Unwind's Settings in a browser you crossed out sets the same note without a trace, and it ends the same way.
So that unlocking the phone into a crossed-out app still asks for a trace, it holds one thing more while the phone is locked: the name of a crossed-out app that came to the front behind the lock screen, and when it did. It is forgotten when you unlock the phone or when the screen goes dark.
To tell "you switched to another app" apart from "a keyboard opened on top of the app you were already in", the service asks Android which of your installed apps are launchers, which are keyboards, and which have a home-screen icon. Those lists describe the apps on your phone, not you, and they are worked out afresh each time the service starts.
None of that is written to storage and none of it leaves the phone. It lives in the running app's memory and is gone when the service stops.
You turn this service on yourself in Android's accessibility settings, after the app explains it, and you can turn it off there at any time.
What the app stores on your phone
Everything below lives in the app's private storage on your device, in a database called unwind.db — all but whether you bought the app, which is a single flag in a small settings file of the app's own. We have no copy and no way to read it.
- The apps you chose to lock — each one's package name, the label Android shows for it, the mode you picked, and when you added it.
- Your settings — whether you have finished onboarding, the master blocking switch, the path width, the wall's sound and its voice, and which look the app wears.
- Your deck of cards — for each card you drew or received, its name, its colour, the stroke itself as a list of points, whether you drew it or were sent it, and when it arrived.
- Your walked diary — one row for each path you traced: which drawing or card it was, when you traced it, and which locked app was waiting behind the gate. This is a history of when you opened the apps you chose to lock. It is kept so the drawings can be redrawn faintly on the Home screen inside Unwind, and the app never sends it anywhere.
- Whether you bought the app or are still inside the free trial, and when that trial started and ends.
Copies kept before an update: when an update is about to change how that database is laid out, the app first copies it, as it was, into the same private storage, so that if the update ever gets something wrong a later one can put your data back. A copy holds what the database held at that moment, stays on your phone, and is not part of Android's backup. The copies from the last three such updates are kept and older ones are deleted. Something you delete in the app, such as a card, can remain in a copy taken before you deleted it, until that copy is deleted in turn.
Deleting it: uninstalling the app, or clearing its storage in Android settings, permanently deletes all of it from the phone, copies included. It does not delete a copy that Android's backup has made in your Google account (below). That copy can remain, and be restored if you install the app again, until it expires or you delete it in your Google account's backup settings.
Android's own backup
The app allows Android's standard backup, which means everything listed above — the apps you chose to lock, your settings, your deck, your walked diary, your free trial's dates and whether you bought the app — may be copied into your own Google account's app backup, and restored when you set up a new phone or reinstall the app. Moving to a new phone with Android's phone-to-phone transfer copies the same things across. That backup is a feature of Android between you and Google under Google's privacy policy — it does not go to us, and we cannot read it. You can turn app backup off for the whole phone, or for this app, in Android's system settings.
What uses the internet
No code we wrote does. Nothing we wrote into Unwind opens a network connection: no analytics, no crash reporting, no server of ours to call. Every path, card and drawing is generated or read on the phone itself.
Three things around that are worth saying plainly, because you can check them yourself and you should hear them here first.
- The finished app does carry the
INTERNETpermission, along withACCESS_NETWORK_STATE, and Play's listing will say "full network access" because of it. We do not ask for either. They arrive inside Google Play's billing library, which brings a diagnostics component of Google's with it, and a permission any library declares becomes a permission the whole app declares. We would rather it did not. Taking it out means taking out part of the billing library, and we will not ship that until we have proved it does not break buying the app. - That library does use the internet, for diagnostics of its own. The app needs it to sell itself, and uses it each time you open the app to ask Google Play whether you have bought it. The library sends Google its own diagnostics about how those calls went, with details of the device: its model and Android build, the country, language and time zone it is set to, the mobile carrier's code, the kind of network it is on, and which versions of Unwind and of the library are running. That goes to Google, not to us, under Google's privacy policy. None of what Unwind records is in it — not the apps you lock, not your walked diary, not your deck.
- Google Play purchases are handled by Google Play, in Google's own app and on Google's servers. Payment details go to Google, never to us — Unwind only learns "purchased" or "not purchased" and stores that flag on the phone. Google's privacy policy governs the transaction.
What none of those changes is the part that matters. The apps you lock, your walked diary and your deck are written to this phone's private storage and read back from it, and no line of code in this app sends any of them anywhere. The only copy of them that can leave the phone is the one Android's own backup makes, described above.
Sending a card
You can send a card you drew to someone else. When you do, the app writes that single card to a temporary file and hands it to Android's share sheet, and you choose where it goes. The file holds the drawing and its name — nothing about you, your phone or the apps you lock. The app never shares anything on its own, and never more than the one card you picked.
What the app does not do
- No accounts and no sign-in.
- No analytics of ours, no trackers of ours, no advertising and no ad SDKs. Google's billing library carries diagnostics of its own; see "What uses the internet" above.
- No selling or sharing of personal data, and no code of ours transmits any — Unwind has no server to send it to.
- No reading of notifications, messages or screen content.
- No location, no contacts, no camera, no microphone.
Permissions, in full
Three that Unwind asks for:
- Accessibility service — described above; the app lock depends on it.
- Vibrate — the trace answers your fingertip with small taps.
- Billing — lets Google Play handle the one-time purchase.
And three that arrive inside the libraries the app is built on. Android merges those into the finished app as though it had asked for them itself, so they are the app's permissions too and are listed here:
- Internet and View network connections — from Google Play's billing library, as described above. No code we wrote uses either; the library uses them for its own diagnostics.
- A private receiver permission, named after the app itself, created by an Android support library so that one of Unwind's own internal broadcasts cannot be reached by other apps. It grants nothing to anyone.
And one that Google Play adds to the copy it delivers:
- Check licence (
com.android.vending.CHECK_LICENSE) — part of Google Play's automatic protection: a check, made through the Play Store app, that the copy on your phone was installed from Google Play. It is Google's code rather than Unwind's, it is not in the app as Unwind builds it, and it has nothing to do with anything Unwind records.
That is the whole list. The first six are checked against the finished app on every release build rather than written here from memory; the last is added by Google Play after the app is uploaded, where no build can see it, so it is checked against what the Play Console reports for each release.
Children
Unwind is made for adults and is not directed at children under 13. Regardless of age, nothing Unwind records is collected. The only data collected from the app is the billing library's diagnostics about the phone, described under "What uses the internet", and they go to Google.
Changes to this policy
If the app ever starts doing something this policy does not cover, the policy will be updated first and the effective date above will change. The app links to the current version from its Settings, under "Privacy policy".
Contact
Questions about privacy: support@hackneyhackers.com