PRIVACY · POLICY

what we collect, why, and your rights over it.

Effective 29 June 2026

GamFree Shield (“we”, “us”) is the data controller for the personal data described below. This policy covers what we collect, why, who else processes it, and what you can ask us to do about it. If anything is unclear, or you want to exercise any of the rights below, email support@gamfree.app.

01

Summary

The short version, for people who want the gist:

  • We collect the minimum needed to run the service: your Google account email + name, your subscription state, the accountability partners you’ve paired, and a record of blocked-site attempts when an attempt fires a partner ping.
  • The full activity log of blocked attempts lives on your deviceonly. We don’t keep a server-side history of every page you tried to open.
  • We do not sell your data, run advertising on you, or share it with anyone outside the processors listed below.
  • You can export or delete your account at any time by emailing us.
02

What we collect

Account & identity

From your Google sign-in: email address, full name, and Google profile picture (if set). We don’t receive your Google password.

Subscription & billing

Plan, status, current period end, and the Lemon Squeezy order / subscription IDs that link your account to your payment record. Card numbers, addresses and tax info are held by Lemon Squeezy as the merchant of record; we never see them.

Commitment state

The chosen plan duration and its end date, kept both in our database (server-authoritative) and on your device (so the app works offline). On macOS the on-device copy lives in the Keychain.

Accountability partners

For each partner you invite: their Telegram chat ID (after they message the bot), the pairing code they used, when they were added, and (if they leave the bot) the fact that they did. We do not collect their phone number, email, or any other Telegram profile data.

Blocked-attempt log

When the blocker stops a request to a gambling site, the device records the hostname locally so you can see your own activity feed. If accountability partners are configured, the same hostname is sent to our server to be relayed to them (see Blocked-site reporting). The server keeps a short throttle record per (account, hostname), used to avoid re-spamming partners about the same site within 60 seconds. Not a long-term browsing history.

Device context attached to partner notifications

So a partner knows which device an attempt came from: device name (e.g. “Logan’s MacBook”), OS version (e.g. “macOS 26.0”), and, only if you opt in in Settings, the foreground app at the moment of the attempt (Mac/Android), coarse location (Android/iOS). We never read the contents of any non-blocked site you visit.

Diagnostics & bug reports

When you press Report a problem in the app, we collect a diagnostic snapshot (whether each blocking layer is up, recent self-repair events, app/OS version, your account email) plus the message you write. Sent only when you tap Send.

Server logs

Standard request logs from our hosting providers, IP address, user-agent, timestamps, path, kept briefly for security and abuse-prevention.

03

Why we collect it (legal bases)

Where data-protection law (GDPR, UK GDPR, similar frameworks) asks us to point to a legal basis:

  • Performance of a contract: running the service you’ve subscribed to (account, subscription, commitment lock, partner notifications, the app working at all).
  • Consent: opt-in features like foreground-app sharing and location attachment in partner notifications. You can withdraw consent in app Settings at any time.
  • Legitimate interests: keeping the service secure, debugging, abuse prevention. Balanced against your interests in not having unnecessary data collected.
  • Legal obligation: keeping the financial records tax law requires us to keep.
04

Accountability partners

Partner pairing happens via a single-use code that produces at.me/<bot>?start=<code>link. When the partner messages the bot, Telegram tells the bot their chat ID; we store that chat ID against your account so we can send them messages on your behalf.

Partners can leave at any time by sending the bot /stop or by blocking the bot in Telegram. We also remove them automatically if Telegram tells us they’ve blocked the bot (HTTP 403). You can remove them from your dashboard at any time, which deletes the chat-ID row.

Please only invite people who consent to being your accountability partner. The system is designed for support, not surveillance.

05

Blocked-site reporting: what does and doesn't leave your device

The blocker watches DNS and TLS handshakes locally on your device. It records, locally, every blocked attempt, with the hostname, time and (on macOS) which application requested it. The full activity feed in the app reads from that local store and does not reach our servers.

A blocked attempt only causes an outbound network call from your device to our servers when you have at least one accountability partner paired. In that case the device POSTs the hostname plus the device-context fields described above to our /notify-partners endpoint, which formats a short Telegram message and sends it to each partner.

Hostnames of non-gambling sites you visit never reach the server. Gambling-domain matching happens locally against a fixed list shipped with the app.

06

Who else processes it

We rely on a small number of vendors. Each is a processor acting on our instructions; none of them sell your data:

  • Supabase: authentication, database, edge functions. Hosts the account, subscription, partner, and throttle tables.
  • Google: federated sign-in. We receive the basic profile fields described above; Google applies their own privacy policy to the sign-in itself.
  • Lemon Squeezy: merchant of record for payments. Holds card details, billing addresses and tax info; we receive plan, status and order references.
  • Vercel: hosting for the website and the API endpoints.
  • Telegram: partner-notification transport. We send messages from our bot to the chat IDs partners have shared with the bot.
  • Cloudflare: only for the iOS DNS-over-HTTPS resolver each iOS subscriber gets a subdomain under, when iOS is in use.

These vendors may store data in countries that are not your country of residence. Where data is transferred out of the EEA / UK, we rely on the vendors’ Standard Contractual Clauses or equivalent safeguards.

07

Cookies & local storage

The website uses strictly necessary cookies to keep you signed in (the Supabase auth cookies). The macOS / iOS / Android apps do not use cookies; they store sign-in state in the system Keychain / equivalent.

We do not use third-party analytics cookies, advertising cookies or trackers on the website.

08

How long we keep it

  • Account & subscription data: for as long as your account is active, plus the period required by tax / accounting law (typically 7 years for financial records, local rules vary).
  • Blocked-attempt throttle rows: kept while needed for the 60-second throttle window; pruned on a rolling basis.
  • Bug reports: kept while needed to investigate and respond, normally up to 12 months.
  • Server logs: typically 30 days, longer if needed for a specific abuse / security investigation.
09

Your rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you.
  • Correct anything that’s inaccurate.
  • Delete your account (we keep only what tax or fraud rules require us to keep).
  • Export your data in a portable format.
  • Withdraw consent for opt-in features (Settings → Partner notifications → toggle off).
  • Lodge a complaint with your local data-protection authority.

To exercise any of these, email support@gamfree.app from the address on your account. We aim to respond within 30 days.

Heads-up: requesting account deletion while a commitment lock is active will end the lock at the same time your account is erased, that’s a side-effect of removing the server-side state the lock depends on. Your accountability partners will receive a final notification of the disable event, the same as for any deliberate disable.

10

Security

We use TLS for everything in transit, signed code on every platform, and store sign-in tokens in OS-native secure enclaves where available (Keychain on macOS/iOS, EncryptedSharedPreferences on Android). Internal access to production data is restricted to the smallest practical group and logged. No system is invulnerable; if we ever have to notify you of a security incident, we will.

11

Children

GamFree Shield is for adults (see the eligibility section in our Terms of Service) and is not directed at children. We do not knowingly collect data from anyone under 18 / the age of majority in their country.

12

Changes

We update this policy when the way we handle data changes. Material updates get a new effective date at the top and, for existing subscribers, an email summary. Minor wording fixes (clarity, typos) won’t bump the date.

13

Contact

Email support@gamfree.app for anything privacy-related, access requests, deletion, questions about this policy, or to flag something we should be handling differently.

Effective 29 June 2026. support@gamfree.app