Last updated: 19 September 2026
The short version
SvarLock runs on your phone. It has no Internet permission and does not send your app data to our servers. When you buy Pro, Google Play handles the purchase separately under Google's privacy policy.
The sections below explain this in full.
This policy describes how SvarLock (package com.svarlock.app, "the app") handles your information. SvarLock is developed by Laplap apps ("we", "us"). This policy applies to the SvarLock Android application and to nothing else. Links or apps from other companies are governed by their own policies.
SvarLock does not request the Android Internet permission, so SvarLock cannot open its own network connection. Google Play Billing is a separate system used for Pro purchases. The app has no advertising libraries, analytics, or crash-reporting services.
We do not automatically collect, receive, store on our servers, or share any of the following:
We have no servers and no back end. There is nothing for us to see, unless you choose to email us directly, see section 15.
This is separate from Google Play itself. Google Play handles Pro purchases and may process payment, account, order, and tax information under Google's own privacy policy. If you've opted in to sharing diagnostics with Google on your device, the Play Store platform may also collect basic technical data (such as crash or app-not-responding reports) about apps you've installed, including SvarLock. Those collections happen outside our control and are governed by Google's policy, not this one.
To do its job, SvarLock keeps a small amount of data in its own private storage on your device. Most of it is held by Android Jetpack DataStore. This data never leaves the device on its own. It includes:
| What | Why it exists | Notes |
|---|---|---|
| A salted hash of your PIN | To check your PIN when you unlock | We store a SHA-256 hash combined with a random salt, never your actual PIN. The PIN cannot be read back from what is stored. |
| Your security questions, if you set them | So you can set a new PIN if you forget it | We store which two questions you picked, and a salted hash of each answer, never the answers themselves. Your answers cannot be read back from what is stored, not by us and not by the app. We also store how many wrong answers you have given in a row, and the time until the next attempt is allowed, so nobody can find your PIN by guessing over and over. |
| The list of apps you choose to lock | So SvarLock knows what to protect | Stored as Android package names (e.g. com.whatsapp) on the device only. |
| Your settings | To remember your choices | For example: whether biometric unlock is on, your relock timeout, whether uninstall protection is on, setup-completion flags, whether Protection alerts is on, whether you've already been shown a protection-off alert, whether you've already been shown the keep-alive notice, your theme choice (Light, Dark, or the system setting), when the last background protection check ran, and whether Pro is active. |
| A small local diagnostic buffer | To help you troubleshoot if protection misbehaves | An in-memory list of recent app-detection events, cleared when SvarLock restarts. Only present in copies of SvarLock distributed to internal and closed testers, not in the version available to the public on Google Play. See section 6. |
| A small scheduling database | To run the background protection checks described in section 5 | Created by Android Jetpack WorkManager, the standard Android library for background work. It holds only the timing of those checks. It holds no personal data. |
SvarLock also turns off Android's automatic backup for this data, so none of it goes to a cloud backup. SvarLock is left out of Android's phone-to-phone transfer as well. A new phone starts with a fresh setup. You set your PIN again, and you pick your locked apps again. Some phone brands supply their own copy tool. Those tools work outside Android's rules, so we cannot promise the same result on every brand.
If you turn on fingerprint or face unlock, SvarLock uses the standard Android BiometricPrompt system. Your biometric data is held by your device's secure hardware and the Android operating system. SvarLock never sees, receives, or stores your fingerprint or face data. All we keep is a simple on/off setting recording that you enabled biometric unlock.
SvarLock asks only for the permissions it needs to lock apps. Each is explained in the app before you are prompted.
WAKE_LOCK and ACCESS_NETWORK_STATE to the app. WAKE_LOCK lets a check finish before the device goes back to sleep. ACCESS_NETWORK_STATE only lets the library read whether the device is online. Neither one sends anything, and neither one can open a connection. Without the internet permission, no part of the app can reach the network.We do not request location, contacts, microphone, SMS, or storage permissions for your media. SvarLock does not request the Camera permission either, see the background checks section below for the one camera-related signal it does use.
SvarLock periodically checks, entirely on your device, that protection is still running, roughly every few minutes, so it can restart itself if a phone's battery-saving system killed it in the background. This check reads no personal data and never leaves the device.
If you turn on the optional Protection alerts toggle in Settings, SvarLock shows a notification when one of these checks finds that protection is off, so you can fix it without having to keep opening the app. This is off by default and only asks for the notification permission described above when you turn it on.
Some camera apps can open faster than SvarLock's normal check can catch. To close that gap, SvarLock also listens for a simple on or off signal from Android: is the camera being used right now, not what it's pointed at or what it sees. This needs no Camera permission and gives SvarLock no access to any photo, video, or image, ever. SvarLock only uses this signal to decide whether to show the lock screen.
This section applies only to copies of SvarLock distributed to internal and closed testers. In the version available to the public on Google Play's Production track, this feature is turned off and unreachable: a build flag disables it, so nothing in that build can collect or export a diagnostic log.
In those test builds, SvarLock keeps an in-memory, on-device diagnostic buffer of recent app-detection events to help testers and us troubleshoot reliability problems. This stays on the device unless you choose to export it. While a test build runs, SvarLock also writes the same lines to the Android system log. Other apps cannot read that log. A computer joined to the phone by USB cable, with developer debugging turned on, can read it.
If you tap Export diagnostic log in Settings, SvarLock writes the buffer to a file and opens Android's standard share sheet so you can send it wherever you choose (for example, to email it to support). That file may include the names or package IDs of apps recently detected in the foreground, the names of screens SvarLock showed, camera on or off events from the signal described in section 5 (never a photo, video, or image), and your device manufacturer, model, and Android version, to help with troubleshooting. Once you share it, the file is handled by whatever app or service you send it to, under that service's terms. We cannot access the file unless you choose to send it to us. The file also stays in SvarLock's private cache folder on your device. Each new export replaces it. To remove it, open Android Settings → Apps → SvarLock → Storage and clear the cache. It also goes when you remove the app.
Because we don't automatically collect your app data, we have nothing to share, sell, rent, or disclose to third parties or advertisers. Google Play processes Pro purchases separately, as described in section 8. Information you choose to email us is processed by Google, our email provider, as described in section 15. SvarLock contains no advertising or marketing trackers.
SvarLock is free and lets you lock up to 3 apps. SvarLock Pro is a one-time Google Play purchase that removes this limit and includes future Pro features. Google Play processes the payment and may handle payment, account, order, and tax information under Google's privacy policy. SvarLock does not receive your card, bank, or billing details.
SvarLock receives product and purchase status from Google Play to confirm your Pro entitlement. It may use a purchase token while confirming and acknowledging the purchase, but it does not save that token or send it to our servers. SvarLock stores only the Pro entitlement in the app's private storage. Google Play's handling of purchases is governed by Google's own terms and privacy policy.
Your data stays on your device until you remove it. You are always in control:
Since none of your data reaches us automatically, there is no copy on our side to request or delete, other than anything you've chosen to email us. See section 15 for how to have that removed.
SvarLock is a general-purpose utility and is not directed to children. SvarLock itself collects no personal information from anyone, including children. Google Play handles purchases under its own terms and privacy policy.
This section is written with reference to India's Digital Personal Data Protection Act (DPDP Act), since that is the law that governs this policy (section 14). Under it, you have the right to access information about how your personal data is processed, the right to correction and erasure of your personal data, the right to grievance redressal, and the right to nominate someone to exercise these rights on your behalf if you die or become incapacitated. SvarLock holds no personal data about you on any server, except anything you've chosen to email us. Beyond that, there is nothing for us to retrieve, correct, or erase on our end. All of your data already lives solely on your device and is entirely under your control, as described in section 9. If you believe you need to exercise a privacy right, contact us using the details below and we will respond as required.
Your PIN is never stored in plain form. Only a salted SHA-256 hash is kept, and the plain PIN itself is not stored anywhere. If you set security questions, your answers are protected the same way: each is stored as a salted PBKDF2 hash, and the answers themselves are not stored anywhere. All app data is held in SvarLock's private, sandboxed storage. It is excluded from cloud backup, and from Android's phone-to-phone transfer, so the stored PIN hash stays on the phone that created it. No system can guarantee perfect security, but because SvarLock keeps your app data on-device and does not send it to our servers, the exposure surface is intentionally minimal.
If we change how SvarLock handles data, we will update this policy and revise the "Last updated" date above. Material changes will be reflected in the app's store listing. Continuing to use the app after an update means you accept the revised policy.
This policy is governed by the laws of India, without regard to its conflict-of-laws rules.
Questions about this policy or your privacy? Contact:
SvarLock by Laplap apps
Email: svarlock.app@gmail.com
If you contact support, send feedback, or (in test builds) email us a diagnostic log, we receive whatever you choose to send us: your email address, your message, and any attachment. Our email provider, Google, processes and stores support messages on our behalf, under Google's own privacy policy. We use what you send only to reply to you and to troubleshoot the issue you raised. We do not sell it, use it for advertising, or share it with third parties. We keep support emails for as long as we need them to help you and to keep a record of past issues; if you'd like us to delete one, contact us and we will remove it.