Privacy Policy

Last updated 3 September 2026

The short version

  • Oath does not track your screen time. It reads which app is in front of you, because that is the only way it can block one, and it keeps no record of your screen time. It does not hold Android's Usage Access permission at all.
  • What does leave your phone is what an Oath needs to work: your name and email from Google Sign-In, the rules you agree with your partner, and a record of when a rule was broken.
  • We do not sell your data, and Oath contains no advertising or analytics trackers. When the app breaks, we get a crash report telling us what went wrong and on what kind of phone, never what you were doing.
  • Your partner sees less than you might expect. They are not told when you break a rule. Details in "What your partner can see".

Our contact details

Name: Way Studio
E-mail: waystudio.apps@gmail.com

Way Studio is the name Immanuel Rajiv, an independent developer in the United Kingdom, makes Oath under. For the purposes of UK data protection law he is the "controller" of the personal data described in this policy. It covers the Oath Android app (package app.getoath.android) and this website.

Oath is published through a Google Play developer account held by a separate company. Google is the seller. That company does not decide how the personal data in this policy is used.

As an independent developer he is not required to appoint a Data Protection Officer, so please send all data protection queries to the address above.

The type of personal information we collect

What stays on your phone only

The following is stored in a database on your device and is never transmitted to us or anyone else. If you uninstall Oath, it is deleted with the app.

Oath used to record your app usage on this device, for screen-time charts it no longer shows. That collection was removed in September 2026, along with the Usage Access permission behind it. Oath does not ask for that permission and cannot read your usage figures.

What is sent to our servers

Oath uses Google Firebase to let two people share an Oath across two phones. Only the data below is sent.

DataWhy it is neededOur lawful basis
Google account details Your display name, email address, profile photo URL, and a Google-issued user ID. Used to sign you in and to show your partner who they are paired with. (b) Contract
Notification token A Firebase Cloud Messaging token identifying your device, so your partner's phone can reach yours with a notification. (a) Consent
Oath and rule content The rules you and your partner agree: the rule name, the time limits and windows, and the package names of the apps you name in a rule (for example com.instagram.android). Both partners must see the same rules, so they are stored centrally. (b) Contract
Breach records When a rule was broken, which rule, the app that triggered it, and how it was resolved. Also any note you type when requesting a key, and any note your partner types when declining. (b) Contract
Partner linkage Which two accounts are joined in an Oath, and the short invite code used to join. (b) Contract
Subscription status Whether your account is in a trial or has an active subscription, verified with Google Play. We never see your card details; Google handles payment. (b) Contract
Crash reports When Oath crashes, or hits an error it can recover from, Firebase sends us the technical details: what went wrong, where in the code, and your device model and Android version. We attach no name, email or account ID. Firebase attaches two identifiers of its own so it can count how many people one bug affected. It keeps all of it for 90 days and then deletes it. Test builds send nothing. (f) Legitimate interests
App integrity checks A Google Play Integrity token confirming the request came from a genuine, unmodified copy of Oath. This stops a tampered app forging a subscription or writing to someone else's Oath. (f) Legitimate interests

There are no usage figures for us to receive. What a rule you write does name is the apps it governs, and a breach record names the app that triggered it. If you would rather an app was not named on our servers, keep it out of a shared rule.

How we get your personal information and why we collect it

Most of the personal information we process is provided to us directly by you, when you sign in with Google, when you write a rule, and when you send a note to your partner. We also receive information indirectly from two sources: Google Sign-In gives us your name, email address and profile photo URL when you authorise it, and Google Play tells us whether your subscription is active.

We use that information to create and run your account, to keep your Oath in step across two phones, to let your partner grant you a key, to send the notifications described below, and to confirm you are entitled to the paid features.

The Accessibility Service

Oath cannot block an app without Android's Accessibility Service, so we ask you to turn it on. It is a powerful permission, so here is the whole of what Oath does with it.

Oath can see which apps on your device have an icon in your launcher, so you can choose apps when writing a rule. This is a declaration in the app rather than a permission you grant, and Android limits it to apps that can be opened. The list is used on your device to draw the picker and is not uploaded.

Our lawful bases

The table above names the lawful basis for each kind of data. Under the UK GDPR, those bases are:

What your partner can see

An Oath shows your partner less than most people expect. They can see:

Your partner is not sent a notification when you break a rule. Breaches are quiet by default. They are notified only when you ask them for a key, when you use a hammer to release yourself, when they decline a request, and when the Oath is paused, revived, or dissolved.

Your partner never sees your Timer sessions, or any app you have not named in a shared rule.

Who we share your information with

We use a small number of processors, and we do not sell data to anyone.

We may also disclose data where the law requires it, or to protect our rights or someone's safety.

Cookies. This website sets no cookies and contains no analytics or advertising trackers. Your visit is not tracked. The Oath app sets no cookies either.

How we store your personal information

Your information is stored with Google Firebase, in the eur3 European multi-region (Belgium and the Netherlands). Access to our database is governed by server-side security rules that restrict every record to the people party to it, and sensitive operations run as server functions rather than being trusted to the app. Subscription entitlements are verified on our server, not on your phone. Requests are checked with Google Play Integrity to confirm they come from a genuine, unmodified copy of Oath.

Our database region is in the EEA. Google, as our processor, may transfer or access data outside the UK and EEA in the course of running its infrastructure and support. Where that happens, transfers are covered by the UK International Data Transfer Addendum or Standard Contractual Clauses.

We keep your information for the following periods, after which it is deleted from our database:

What is left after you delete your account

Deleting your account removes your profile, your Oath, your rules and your breach history from our database. Three small records stay behind. Each holds a date and a reference code. None holds your name, your email address, or anything you wrote.

The reference code is made from your Google account identity using a key we hold. Nobody outside can read it, but we can still match it to you, so these are not anonymous records and we treat them as your personal data.

None has a fixed end date. Each lasts as long as the job it does: the deletion record, while an offline phone could still be applying rules for the deleted account; the trial record, while we offer one free trial per person; the subscription record, while Google can still restore the subscription. A timer on any of them would undo it. An expired trial record hands the same person a new trial each time they delete their account.

No service can promise perfect security, and we do not. If a breach occurs that puts your rights at risk, we will tell you and the ICO as the law requires.

Automated decision-making

We do not make automated decisions about you that produce legal effects or similarly significant effects, and we do not profile you.

Oath does apply your own rules automatically: when an app you named goes past a limit you agreed, that app is locked without anyone reviewing it first. It affects only that app, on your own phone, and is not used to judge or score you.

Your data protection rights

Under data protection law, you have rights including:

You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.

Please contact us at waystudio.apps@gmail.com if you wish to make a request.

To delete your account and the data attached to it, see Deleting your account.

How to complain

If you have any concerns about our use of your personal information, you can make a complaint to us at waystudio.apps@gmail.com. We would rather you told us first so we can put it right.

You can also complain to the ICO if you are unhappy with how we have used your data.

The ICO's address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk

Children

Oath is not designed for children and is not directed at them. You must be at least 18 to use it. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will tell you in the app before it takes effect.