Privacy Policy
This Privacy Policy explains what StarBlocker ("StarBlocker," "we," "us") collects when you use our applications for macOS, Windows, iOS and Android and our website, how we use it, and the choices you have. StarBlocker is a focus tool that looks at your own screen to help you stay on task. Because of what it does, we hold ourselves to a simple standard: see what's needed in the moment, keep as little as possible, and never sell your data.
1. Information we collect
Account information
When you create an account we collect your name, email address, and a securely hashed password. If you use the community forum, we also store the username you choose there. If you subscribe, our payment processor collects your billing details; we receive only a subscription status and non-sensitive metadata, never your full card number.
Screen content (processed, not stored)
To do its job, the StarBlocker app captures the visible screen about every ten seconds. It first reads text on the device and sends that text for classification. A downscaled image is sent only when the text check finds a concrete reason that the picture is needed to decide one of your active rules. We do not retain these images. Each capture is discarded after the decision and is never written to disk on your device or ours. The one exception is a block you are looking at: the frame that caused it stays in the app's memory while the app is running, so that you can appeal the decision, and it is not stored anywhere.
On Android, a scan can send the readable text of the screen instead of an image — that is what Android provides when its screen-recording permission has not been granted. That text is classified and discarded the same way.
What we keep is a lightweight activity log — text such as the detected activity, the app or site it was on, the rule (if any) it matched, a timestamp, which model answered, and token/cost accounting — so the dashboard can show your history and enforce your limits. When a scan was raised by a word from one of your own rules, the row also holds that word and up to 160 characters of the text around it, so a decision you think is wrong can be explained afterwards. Nothing else from the screen is kept.
On iPhone
iOS does not let one app see inside another, so StarBlocker works in two halves there. Safari is a full StarBlocker client: a Safari Web Extension captures the visible view about every ten seconds and sends it for classification, exactly as the desktop apps do. Other apps are governed through Apple's Family Controls (Screen Time) — they can be blocked or time-limited, but they are never judged. No screen content from an app other than Safari is captured or transmitted.
Family Controls needs an authorization you grant on the device itself. When you pick an app to block, Apple hands StarBlocker a sealed token that works only on that phone, and the token stays there. What reaches us is an opaque handle, the device it belongs to, and a count — not which apps you chose. If an app is covered by a time limit, the phone reports how many minutes it has been used, never what happened inside it.
Usage & device data
We collect basic operational data: device identifiers you register, last-seen timestamps, app version, and diagnostic logs needed to run the service.
Location & Wi-Fi
A rule can be limited to a place — a point and a radius — or to Wi-Fi networks you name. To make that work, your devices report the name of the network they are on and a coarse position (latitude, longitude and an accuracy figure) alongside their regular heartbeat. We keep the most recent of these on the device record with the time it was taken, and each new report replaces it; a position that has gone stale stops holding a location rule open. On iPhone, iOS will only tell an app the name of the current Wi-Fi network if that app has location permission, which is why a Wi-Fi rule there asks for it.
If you set a place by typing an address, we send that address to a geocoding provider — Google, or OpenStreetMap's Nominatim where no Google key is configured — to turn it into coordinates. When the dashboard names the place something happened in, it does the reverse, and the coordinate is first rounded to three decimal places, roughly 110 metres: enough to name a street, not enough to name a window. It is the rounded value that is sent, never the exact one, and each place is looked up once and remembered.
An event recorded for pattern warnings keeps the position and network name from the moment it happened, as part of what the warnings learn from.
Check-ins and how you're feeling
The daily check-in can record how you are feeling: up to six words from a fixed list, any word you add yourself, and a note in your own words. All of it is self-reported — nothing here is inferred from your screen. We use it to show you your own history and to power the pattern warnings, which learn which feelings, times and places tend to run ahead of a slip or lapse.
Notes and words you add are sent to an AI provider to be reduced to tags, so that the journal can be filtered and searched. The reply is tags only, and the note itself goes nowhere else. You can switch that off in settings; nothing else changes if you do.
Your feelings are not shared with your accountability partners. No partner-facing page or alert reads this data.
You can download everything the journal holds in one file, and delete it in one action — the check-ins, the notes, the words learned from them, and the free-text reflections written on a counter reset. Events already recorded for pattern warnings keep the feeling words that were current when they happened.
Habits, day counters and streaks
If you use them, we store the habits you define and the weekdays each is due, the dates you check them off, and the start and reset dates of each day counter. These are your own entries, not observations of your screen. A counter can be shared with an accountability partner; that is off unless you turn it on.
Community forum
Posts in the forum are visible to every other signed-in StarBlocker member. You appear as a username you choose, with your longest streak as a bare number and whichever badge you have chosen to wear — never which counter the streak belongs to or what it counts. Your email address is never shown, and nothing from your screen ever appears in the forum. Posts, and reports other members make about them, are kept so they can be moderated.
The forum's rules keep contact details out of public posts. If another member asks to connect and you approve, you decide what contact information to hand over; only then is it stored and passed to them.
2. How AI processing works, and where your data lives
StarBlocker sends production AI requests through OpenRouter. Readable screen text and the other text-assisted features described below use a pinned Venice Gemma endpoint. A possible infraction is never decided from text alone: its screenshot is confirmed by Gemini 3.1 Flash-Lite on a pinned Google Vertex U.S. endpoint. Both routes require zero data retention, deny data collection, and disable provider fallback. The selected endpoint receives only the content needed to answer that request. Our own servers and databases are hosted in the United States; third-party processing location is governed by the selected provider and endpoint.
Models are also used away from the screen: every forum post is checked against the forum's rules before it is stored, check-in notes are reduced to tags, and the in-app help bot answers questions you type. In each case what is sent is the text in question and nothing else.
3. How we use information
- To operate StarBlocker: classify screen content against your rules and enforce the limits you set.
- To maintain your account, process your subscription, and provide support.
- To show you your own history, and to warn you when a pattern in it points at a hard moment ahead.
- To run the community forum, including moderating what is posted there.
- To send transactional email (verification, password resets, notifications you enabled).
- To secure the service, prevent abuse, and meet legal obligations.
We do not sell your personal information, and we do not use your screen content for advertising.
4. Accountability partners
If you invite an accountability partner, they receive events — such as "a rule was triggered" — never the underlying screen content, URLs, or images. Beyond those events, a partner can read the names of your rules and when each one applies — never a rule's keywords or its AI instruction, which can name the very things the rule exists to keep off your screen. You control whether your activity history is visible to your partners.
You can remove a partner at any time. Removal completes 24 hours after you ask, and your partner is told as soon as you ask — see the Terms for why.
5. Sharing
We share information only with service providers who help us run StarBlocker (AI model providers, our hosting and email providers, and our payment processor), each under contract and only as needed. We may disclose information if required by law or to protect the rights and safety of our users and the service.
6. Data retention and account deletion
Screen images are never stored. Full text records for scans marked clean are kept for 90 days. When an older clean day has no infraction, StarBlocker keeps only its earliest and latest scan markers so lifetime streaks, perfect-day totals, and active-day counts do not shrink as detailed history expires. Rule infractions, mission strays, time-limit events, check-ins, and the small records used to explain long-term patterns remain while your account is active. They are deleted with the account. Security and billing records that do not contain screen content may be retained only when law or fraud prevention requires it.
You can delete your account yourself, at any time, from inside the app — Plan & Billing, at the bottom. It asks twice, and then it removes your account and the data attached to it: your rules, your devices, your activity history, your journal, your counters and habits, your forum posts, and your accountability-partner links. Any active subscription is cancelled as part of the same step, and you are signed out on every device. It cannot be undone, and we do not keep a copy for ourselves. Where the law obliges us to retain a limited record — a billing record for tax and accounting purposes, held by our payment processor as merchant of record — that record is what remains, and nothing in it is screen content.
The journal does not wait on a request. Your check-ins, their notes, the words learned from them and the reflections written on a counter reset can be deleted by you at any time, in one action, from inside the app.
7. Security
We use encryption in transit, hashed passwords, scoped access tokens, and access controls. No system is perfectly secure, but not storing screen images materially reduces what is ever at risk.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these, contact us at the address below. We will not discriminate against you for exercising your rights.
Three of these you can exercise yourself, without asking us. The journal — every check-in, note and tag — downloads as a single file in one click, and deletes in one action. The whole account deletes in one action too, from the bottom of Plan & Billing (see section 6). You can also switch off the AI tagging of your notes, and the forum is opt-in: an account that never opens it has no username.
9. Children
StarBlocker is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information.
10. Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice.
11. Contact
Questions about this policy or your data: support@starblocker.io.
