Privacy Policy · Last updated July 6, 2026

Privacy Policy

Thanks for using Curbox. This policy explains, in plain words, what the app does with your information. The short version is easy to remember: Curbox keeps your data on your phone. If you choose to use the optional sync, that data is end-to-end encrypted, so we still cannot read it, and neither can anyone else.

Curbox is a screen time and digital wellbeing app. It helps you block apps and websites, focus, and understand your own habits. To do that, the app needs to look at what is happening on your screen. We know that sounds sensitive, so we built Curbox so that your data stays yours: it lives on your device, and the only copy that can ever leave it is the encrypted one you choose to sync.

One app, three variants

The Curbox app comes in three variants. They share the same core, but a few features differ, and those differences matter for privacy:

Feature Playstore F-Droid Full (website)
SyncYesNoYes
Anti-uninstallNoYesYes
UI hiderNoYesYes
Internet permissionSync onlyNoneSync only

Only Sync ever touches the internet, so the privacy story is simple. The F-Droid variant has no internet permission at all and is fully offline. The Playstore and full variants can reach the internet for Sync and nothing else. Anti-uninstall and the UI hider work entirely on your device; you will find them explained in the permissions section below.

There is also a Curbox browser extension, which has its own section below.

The most important thing to know

Curbox does not collect your data. We cannot see it, and we cannot read what you sync.

The F-Droid variant does not have permission to use the internet. You can check this yourself in the app's permission list or in the source code. Because it cannot reach the internet, it is technically impossible for that variant to send your information to us, to a server, or to any other company.

The Playstore and full variants can use the internet for exactly one thing: the optional Sync feature. Sync is end-to-end encrypted with a phrase only you know, so even while your data passes through a server, we cannot read it. Everything else in these variants works exactly like the offline variant and stays on your phone.

The only login in Curbox is the optional Sync account. If you do not use Sync, there are no accounts and nothing to sign in to. And even when you do, your synced data is encrypted with a phrase we never see.

Sync (Playstore and full variants)

The Playstore and full variants include an optional Sync feature. It is off until you set it up, and the app works fully without it. The F-Droid variant does not include Sync at all.

Logging in. Sync is the only part of Curbox that asks you to create an account and log in. Everything else works without one. The account exists so your devices can find each other and your encrypted data. Your encryption phrase is separate from your login: the login identifies your account, while the phrase, which never leaves your devices, is what actually locks your data.

What it syncs. Sync keeps your Curbox configurations (things like your block lists, focus groups, and settings) and your usage stats the same across devices you own, including browsers running the Curbox extension.

Focus across devices. Sync also carries your focus sessions. When you start focus mode on one device, it automatically starts on all your phones and browsers where Curbox is installed and logged in to your Sync account. The signal that starts it travels through Sync and is encrypted like everything else.

End-to-end encryption. When you first set up Sync, you choose a phrase. Everything you sync is encrypted on your device with that phrase before it leaves your phone, and it can only be decrypted on your other devices with the same phrase. The cloud only ever stores encrypted data. We do not know your phrase, we cannot read your synced data, and we cannot reset the phrase or recover the data for you. If you forget your phrase, the synced copy is unreadable to everyone, including us.

How long data stays in the cloud. Your usage stats stay in the cloud for 28 days and are then deleted.

Turning it off. Sync is optional and you can stop using it at any time.

The Curbox browser extension

Curbox is also available as a browser extension. It blocks websites on the schedules you set, runs focus mode, and includes the same optional Sync feature as the Playstore and full app variants. This policy applies to the extension the same way it applies to the app.

What it uses. To block websites and follow your schedules, the extension looks at the address of the page you are on and matches it against your block lists. This matching happens inside your browser as you browse; the extension does not keep a history of the pages you visit. Your block lists, schedules, and focus sessions are stored locally in your browser.

Sync. If you set up Sync in the extension, it works under the same rules described above: everything is encrypted in your browser with your phrase before it leaves your device, we cannot read it, and usage stats in the cloud are deleted after 28 days.

Focus across devices. The extension takes part in cross-device focus. Start a focus session in the extension and it starts on your phones too; start one on your phone and the extension begins blocking in your browser. This works through the same encrypted Sync, on devices logged in to the same Sync account.

The Curbox API

Curbox includes an API that other apps on your device can use, but only if you give them permission first. Nothing can connect to it without your explicit approval, and if you never grant access, the API shares nothing.

An app you approve can read all of your usage stats, read your Curbox configurations, and change those configurations on your behalf, for example by editing a block list or a schedule. This exchange happens on your device, directly between Curbox and that app.

Once another app has your data, what it does with it is governed by that app's own privacy policy, not this one. Only grant access to apps you trust, and revoke access in Curbox whenever you want.

What information Curbox uses

Curbox works with a few kinds of information. All of it lives on your device in a local database and local settings files. If you turn on Sync, an end-to-end encrypted copy of your configurations and usage stats is also stored in the cloud under the rules in the Sync section above: we cannot read it, and usage stats there are deleted after 28 days.

App usage. The app records which apps you open, how long you use them, how many times you open them, and when you last used them. This is what powers your usage charts and screen time stats.

Website usage. When you browse in a supported browser, Curbox notes the website's domain and the section you are on (for example, youtube.com/shorts) along with how long you spend there. It does not save the full web address. Things like search terms, query parameters, and the rest of the link are dropped. We keep just enough to group your time by site.

Short video counts. If you turn on the reel counter, the app counts how many short videos (like Reels or Shorts) you scroll through, and stores a daily total.

Focus sessions. When you run a focus session, the app saves when it started, how long it was meant to last, when it actually ended, and whether you finished it.

Blocked attempts. When a block stops you from opening something, the app may log that moment so you can review it later in the analytics screen. This can include the name of the app you tried to open and how long it was unblocked for.

Your settings. This includes your block lists, focus groups, keyword lists, warning messages, mindful messages, and the apps you have chosen to manage.

Screen content, while the app is running. Curbox uses Android's Accessibility service. This lets the app read what is on your screen, such as the name of the app in front of you or the address in your browser bar. The app reads this in the moment to decide whether to block something or count it. It is processed on your device as it happens and is not collected into a profile or sent anywhere.

What Curbox does not do

Permissions and why they are needed

Curbox asks for a number of permissions so it can do its job. None of them are used to gather data about you for anyone else. Below is each permission, what it actually does inside the app, and why the app would not work properly without it. You stay in control and can turn most of these off in your phone's settings, though the related feature will stop working when you do.

The Accessibility service

Curbox runs one Accessibility service, the App Blocker service. It reads screen information only while it is running, only to do the two jobs described here, and only on your device. Nothing it sees is stored as a profile.

Blocking. The service watches which app or website is in front of you so it can act on it the moment it appears. This powers app blocking, website and keyword blocking, short video (reel) blocking, focus mode, and the warning and mindful message screens. When it sees something on your block list, it can press back or home for you, or show a block screen on top, so you are gently pulled away from it. To stay quick and reliable, it reads the current screen as events happen and decides in that instant whether a block is needed.

Usage tracking. The same service also measures how you actually spend your time so the app can show you honest stats. It records how long you stay in each app, how many times you open it, and when. For supported browsers it notes the website domain and section you are on (not the full link) and how long you spend there. It also counts short videos for the reel counter if you turn that on. All of this is written to a database on your phone and used to draw your charts and history. If you turn on Sync, an end-to-end encrypted copy of these stats is synced across your devices as well.

The service is core functionality, not an optional extra. Without Accessibility access, Curbox cannot block anything or measure anything, and the app cannot do its job.

Foreground service

Run as a foreground service (special use). Curbox runs its blocking and tracking work as a foreground service. On Android, a foreground service is one that stays active in the background with a visible notification, instead of being quietly killed by the system. Curbox needs this because blocking and tracking have to keep working the whole time you use your phone, not just while the app is open on screen. The "special use" type tells Android, and you, that the service exists for digital wellbeing: app blocking and usage monitoring. This permission is about staying alive to do its job. It does not collect any extra information.

Other permissions

See other apps installed (query all packages). Curbox shows you a list of the apps on your phone so you can choose which ones to block, track, or include in a focus session. To build that list and to match the app in front of you against your block list, it needs to know which apps are installed. The list of your apps stays on your device.

Display over other apps (system alert window). This lets Curbox draw on top of whatever you are using. It is how block screens, warnings, mindful messages, and the reel counter overlay appear over the app you are trying to open. Without it, Curbox could decide to block something but would have no way to show you the screen that stops you.

Notifications. Android requires a foreground service to show a notification, and the app uses notifications to tell you what it is doing, such as that a focus session is running. This keeps the background work honest and visible to you.

Do Not Disturb access. This is used by the Auto DND feature so the app can turn Do Not Disturb on and off for you on the schedule you set. It only changes the Do Not Disturb state. It does not read your notifications.

Vibrate. Used for small haptic feedback inside the app, such as a light buzz when something is blocked or confirmed.

Camera. Used in only one place: if you set up an unlock that asks you to scan a QR code or barcode before a block lifts (for example, scanning a code on a product box in another room to add a moment of friction before unlocking). The camera turns on live only while you are scanning, and turns off right after. No photos are taken, and nothing from the camera is saved or sent anywhere.

Internet (Playstore and full variants only). Used for one purpose: the optional Sync feature described above. Data sent through it is always end-to-end encrypted before it leaves your phone. The F-Droid variant does not include this permission at all.

Device administrator (F-Droid and full variants). Used by anti-uninstall protection to make the app harder to remove in a moment of impulse while your blocks are active. It is used only to resist uninstalling. It does not lock your device, wipe anything, or collect any data. You can deactivate it in your phone's settings, though on some phones this may require restarting into safe mode first; after that, the app uninstalls normally. The Playstore variant never asks for it.

The UI hider (F-Droid and full variants). Not a separate permission: it uses the same Accessibility and overlay access described above to hide distracting interface elements inside other apps, such as a feed or a recommendations row. It works entirely on your device and stores nothing beyond your own list of what to hide.

Shizuku (optional). If you choose to connect Shizuku, Curbox can use it for features like turning your screen grayscale or pausing apps during a focus session. These run as local system commands on your own device. Shizuku is a separate tool with its own setup, and nothing about it sends data over a network.

Crash logs

If the app ever crashes, it may save a crash log file on your phone to help with fixing bugs. This file stays on your device. We never receive it automatically. If you want to help us fix a problem, you can choose to share a crash log yourself using your phone's normal share menu, and pick where it goes (for example, a chat app or email). That is entirely your decision, and once you send it through another app, that app's own privacy rules apply.

Children

Curbox is not designed for or directed at children under 13. It is a tool for managing your own screen habits. Because the app does not collect or transmit any personal data, it does not knowingly gather information from children.

Your control over your data

Whichever variant you use, you are always in charge:

Open source

Curbox is open source. If you ever doubt anything in this policy, you can read the code yourself and confirm how the app handles your information.

Changes to this policy

If we change how the app works in a way that affects your privacy, we will update this policy and change the date at the top. The best way to stay current is to check this page, the app's listing, or its public repository.

Contact

If you have questions about this policy or how Curbox handles data, please reach out:

We are happy to help.