Scope and controller
This Privacy Policy applies to the Volume Lock Android app developed and operated by Alexander Aizendorf as an individual developer. It explains information handled by the app, the Volume Lock Premium entitlement service, and service providers used to operate the app.
No Volume Lock account
Volume Lock does not require an app account. The app does not ask for your name, postal address, phone number, contacts, precise location, photos, microphone, camera, SMS messages, or call log. Google Play Billing does not automatically provide Volume Lock with your payment-card details, name, or Google email address.
Where Google Play's Data Safety disclosure references "User IDs" in the store listing, this means account-related identifiers that Google Mobile Ads may process when applicable. Volume Lock does not create a user account or receive your name or Google email address. The random installation ID and Android advertising identifier are declared separately as "Device or other IDs" in Google Play, not as Volume Lock account identifiers.
Information kept on your device
Core app settings remain on your device, including volume rules, schedules, profile settings, parental controls, theme choices, permission state, and background-operation preferences.
The Free app may also store a random installation ID and a server-signed Premium entitlement credential. It does not persist the raw Google Play purchase token on Android. Premium credential storage is excluded from Android backup, so reinstall and device restore require fresh Google Play discovery and server verification. Other selected preferences may be copied by Android backup or device-transfer features according to your device and Google settings.
Permissions and device access
Depending on your device and Android version, Volume Lock may request permissions to modify audio settings, show notifications, run a foreground service, restart protection after boot, observe network availability, schedule alarms, open manufacturer background-operation settings, and access Do Not Disturb controls. These permissions support app functionality and are not used to collect contacts, messages, photos, camera, microphone, or precise location data.
Premium purchase and entitlement processing
The Free app uses Google Play Billing to query current product and offer details, display the localized terms returned by Google Play, discover completed purchases, and receive subscription lifecycle updates. Google Play determines purchase availability, localized price, currency, taxes, trial eligibility, purchase state, and the Google account purchase context.
After Google Play reports a completed purchase or returns one during restore, the app sends the purchase token to the Volume Lock entitlement service. A request may also include package identity, app version, request ID, random installation ID, supported credential schema and signing-key IDs, and optional Play Integrity metadata. Premium access is granted only after server verification against Google Play succeeds.
Subscription backend records
The Volume Lock entitlement service runs on Cloudflare Workers and verifies purchases through the Google Play Developer API. It may process and store:
- Encrypted purchase-token material and keyed lookup hashes.
- Encrypted Google Play order IDs and keyed lookup hashes.
- Product, base plan, offer, test-purchase, acknowledgement, start, expiry, cancellation, grace, hold, refund, revocation, and linked-token state.
- Entitlement, signed-credential, installation-association, and idempotency metadata.
- Real-time Developer Notification event, retry, encrypted payload, quarantine, alert, and maintenance state.
- Sanitized network, reliability, and security metadata processed by Cloudflare.
Google Play is the purchase authority. The Volume Lock entitlement service is the authority for granting Premium inside the app. A Billing callback by itself does not grant access.
Ads, analytics, and consent
The Free app uses Google Mobile Ads, AdMob, Google Play services, Firebase Analytics, Google's User Messaging Platform, the Liftoff Monetize (Vungle), InMobi, and AppLovin mediation adapters. Liftoff and InMobi can be selected through the existing Google Mobile Ads request path. The AppLovin adapter is packaged but currently has no mapped ad unit in AdMob. The app does not operate separate fullscreen or banner ad managers for these providers.
Depending on region, device settings, consent choices, and available services, these providers and their advertising partners may process advertising or app-instance identifiers, IP address, approximate location derived from network information, device and operating-system information, app interactions, ad views, ad clicks, consent state, and diagnostics for app functionality, advertising, analytics, measurement, security, and fraud prevention.
When required, Google's User Messaging Platform presents privacy choices. Ads are requested only when the consent SDK reports that ads may be requested. Verified Premium suppresses the banner and fullscreen ad requests covered by Premium. Firebase Analytics remains enabled and is disclosed separately from advertising.
Where available, you can revisit Google's advertising privacy choices through Volume Lock's in-app Privacy Options and can use Android or Google advertising controls supported by your device or account. Changing or withdrawing advertising consent affects future processing governed by that choice and does not affect processing already carried out lawfully. Advertising choices do not necessarily disable Firebase Analytics or processing required for purchase verification, security, fraud prevention, or legal compliance. Premium suppresses the covered banner and fullscreen ad requests; it is not a global opt-out from every analytics or provider operation.
Automated processing
Volume Lock does not use personal data to make solely automated decisions that produce legal or similarly significant effects. Entitlement decisions are rule-based checks of authoritative Google Play purchase state and determine only whether the app enables the purchased Premium benefit. Google advertising services may use automated systems for ad selection, measurement, or personalization under Google's privacy terms and your available consent and advertising controls.
Support requests
If you contact support, we receive information you choose to send, such as your email address, message, screenshots, device or app details, optional diagnostics, and a Google Play GPA.* order ID. Support uses this information to answer requests, verify transaction context, investigate issues, and meet legal or security obligations.
Never send a Google password, authentication code, payment-card details, bank information, or Google Play purchase token to support.
Purposes
Information is processed to provide app functionality, verify and acknowledge purchases, restore Premium, synchronize subscription lifecycle state, prevent abuse, maintain security, handle support and Google Play refund operations, comply with law, and improve service reliability.
Legal bases
Where applicable data-protection law requires a legal basis, Volume Lock processes information on one or more of the following grounds:
- Performance of a contract and steps requested before entering a contract. This includes querying a subscription offer at your request, verifying a completed purchase, granting and restoring Premium, maintaining entitlement state, and providing subscription support.
- Consent. This applies to personalized advertising and other optional processing where consent is required. You may withdraw consent prospectively without affecting processing that was lawful before withdrawal.
- Legitimate interests. Where permitted, Volume Lock processes limited information to prevent fraud and abuse, protect entitlement integrity, secure the service, diagnose failures, maintain reliability, and understand app performance, provided those interests are not overridden by your rights and consent is not required instead.
- Legal obligations and legal claims. This includes accounting, tax, refunds, valid legal requests, dispute resolution, and the establishment, exercise, or defense of legal claims.
Google, Cloudflare, and other providers may process information under their own legal bases and privacy terms where they act independently.
Service providers and international processing
Google provides Google Play distribution and Billing, the Google Play Developer API, Play Integrity, AdMob, the User Messaging Platform, and Firebase Analytics. Liftoff provides the Liftoff Monetize (Vungle) advertising service and demand-partner access through AdMob-managed bidding. InMobi provides InMobi advertising demand through AdMob-managed bidding. AppLovin provides an advertising mediation SDK that is packaged in the Free app but currently has no mapped AdMob ad unit. Cloudflare provides Workers, D1, Queues, and Workers Logs. The email provider processes support information you voluntarily send.
These providers may process data in multiple countries under their own safeguards and privacy terms. The configured subscription D1 databases use an EU jurisdiction restriction for persistent D1 storage. This does not mean Worker execution, Queue transit, Workers Logs, Google API calls, email, or all other processing occurs only in the EU.
Premium Lifetime processing
Authoritative language: English.
The Lifetime path uses the same purchase-authority and entitlement-authority separation. Provider vault fields hold protected purchase-verification material, keyed lookup values, provider and product classification, and verification timestamps. The verification workflow asks Google Play for current authoritative state before changing access. The authority ledger records bounded entitlement decisions and their source. Tombstones preserve the minimum terminal fact needed to prevent a refunded, revoked, or charged-back purchase from being treated as active again.
These record types have distinct retention purposes. Active authority state is kept only while it is needed to provide and restore verified access. Protected verification material and lookup values support verification and fraud prevention. Historical authority events support lifecycle reconciliation, support, refunds, disputes, and audit. Tombstones support terminal-state safety. Applicable deletion, legal-hold, and approved retention controls remain separate for each record type; Lifetime does not expand a retention period or authorize indefinite storage.
The explicit bounded custom telemetry uses enumerated lifecycle kind, provider class, outcome, block reason, duration bucket, and configuration bucket values. It does not add raw or hashed purchase tokens, order references, installation identifiers, credentials, price, currency, backend payloads, exception text, or account identifiers. Firebase automatic purchase events are separate provider processing and remain subject to the existing Firebase and Google Play disclosures. Publication of this policy does not by itself submit or change a Google Play Data Safety declaration.
Sharing
Volume Lock does not sell personal information. Information may be processed by the service providers above to operate the app and subscription system. Information may also be disclosed when required by law, to respond to valid legal requests, protect rights and safety, prevent abuse, or resolve a transaction or support dispute.
Retention
- Current entitlement state and minimal linked-token lineage: while operationally required and no more than 24 months after final closure.
- Historical Google Play order rows: rolling 24 months from each authoritative Google Play order timestamp.
- Historical entitlement lifecycle events: rolling 24 months from each verified event timestamp.
- Purchase-token ciphertext and lookup hashes: 60 days after final verified expiry once terminal denial and acknowledgement work are complete.
- Closed-entitlement installation associations: 90 days after last use.
- Idempotency and credential-response metadata: 24 hours, with active processing leases limited to 2 minutes.
- Encrypted Real-time Developer Notification payloads: 7 days.
- Resolved notification, quarantine, and inactive-alert metadata: 90 days.
- Main Queue and dead-letter Queue transport messages: up to 1 day.
- Cloudflare Workers Logs: up to 7 days under the deployed plan, with no approved long-term export.
- Support and refund evidence: 24 months after the related case or dispute closes.
A documented legal, security, fraud, chargeback, refund, or unresolved-support hold may preserve only the records required for that purpose until the hold is reviewed and released. Google Play, Google advertising and analytics services, Cloudflare, and the email provider may also retain information under their own controls and policies.
Deletion and privacy requests
Clearing app storage or uninstalling removes local app data as applicable, but does not cancel a Google Play subscription or erase provider records. Manage or cancel Premium through Google Play subscriptions.
You may request access to, correction of, or deletion of records Volume Lock reasonably controls by emailing volumelockkapp@gmail.com. Because Volume Lock has no app account, support may ask for a GPA.* order ID plus a matching non-public receipt or subscription property. An order ID alone is not sufficient to disclose records. Limited records may be retained where required for active Premium, legal compliance, accounting, refunds, security, fraud prevention, an unresolved dispute, or a documented hold.
A privacy request does not cancel a subscription and does not create a refund. Cancellation and refund requests are handled through Google Play.
Your rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review by a competent supervisory authority. Withdrawal does not affect the lawfulness of processing completed before withdrawal. Contact support to exercise rights that apply to information Volume Lock controls.
Children
Volume Lock is intended for adult users and parents. It is not directed or marketed directly to children below the minimum age required to consent to data processing in their jurisdiction. A parent or guardian who believes a child provided personal information may contact support for review and deletion where applicable.
Security
Volume Lock uses encrypted transport, authenticated requests, authenticated encryption for sensitive backend fields, signed and bounded entitlement credentials, access controls, key rotation, and sanitized logs. Volume Lock investigates and contains confirmed personal-data incidents within its control. Affected users and competent authorities are notified where required by applicable law and within the time required by that law. No app, device, or internet service can guarantee absolute security.
Changes
This policy may be updated when the app, subscription service, providers, legal requirements, or operating practices change. Material changes will be posted on this page with a revised effective date and, where applicable law requires it, communicated through an in-app or other appropriate notice.
Contact
The controller is Alexander Aizendorf, acting as an individual developer operating Volume Lock.