Effective October 5, 2026
Curfew Control Privacy Policy
This Privacy Policy explains how Serviceable Software ("Serviceable Software," "we," "us," or "our") handles information in the Curfew Control Android TV app and its Android and iPhone companion apps (together, "Curfew Control").
At a glance
- The TV app uses Google Account authorization to prevent repeated free trials, restore licensing after reinstalling, and associate support and purchase records. Curfew Control retains the verified Google email address encrypted at rest, but does not receive your Google password or retain your name or authorization tokens.
- Schedules, PIN-derived data, paired-device credentials, and app-usage totals are stored on your devices. A limited, optional push relay carries short-lived approval requests and responses when local-network delivery is unavailable.
- A limited online service validates free trials and Google Play purchases.
- Optional Firebase Crashlytics reports are off by default.
Information handled on your devices
The TV app accesses the list of launchable apps, package names, app labels and icons so you can select apps to manage. It stores schedules, exception dates, allowance usage, temporary approvals, settings, paired-controller information, and a one-way PIN verifier locally on the TV.
The companion app stores TV names, local network addresses and ports, certificate fingerprints, pairing credentials, schedules retrieved from the TV, settings, approval requests, and an app-specific one-way device identifier needed to recognize the same TV after the TV app is reinstalled. The raw Android device identifier is not sent to the phone or Serviceable Software, and the one-way identifier remains in platform-protected phone storage rather than the licensing service. Android credentials are protected with Android Keystore-backed encryption. iPhone credentials are stored in the iOS Keychain.
Curfew Control uses this information only to provide the features you request. Except for the limited push-notification information described below, it is not uploaded to the Curfew Control online service.
Approval relay and optional notifications
For a paired phone, Curfew Control keeps short-lived approval requests on its authenticated relay so the phone app can retrieve a missed request while open when the direct local-network connection is unavailable. If you enable approval notifications, Curfew Control also uses Firebase Cloud Messaging on Android or Apple Push Notification service on iPhone to alert you while the app is closed. The existing encrypted local-network connection remains available.
For this feature, the Curfew Control service processes a random per-pairing route identifier, a one-way keyed hash of its secret, platform and app identifiers, and last-contact time. When notifications are enabled, it also processes an encrypted provider device token and its keyed hash. A request may contain the TV name, approval type, app label or package name when relevant, requested access duration, a random request identifier, and short approval text. An Approve or Deny action is relayed back using the random route and request identifiers. The service does not receive the TV PIN, schedules, screen previews, installed-app list, or local-network pairing credential.
Accessibility service
The TV app uses an Android Accessibility service to identify the foreground app, enforce schedules and approvals, display restriction and timer overlays, and protect selected ordinary on-screen system Settings paths when you enable that optional protection. For those purposes, the service may inspect package names, window changes, key events, and limited visible text in system Settings or uninstall screens. Curfew Control does not use Accessibility data for advertising or profiling and does not intentionally include Accessibility event text in crash reports or transmit it to the licensing service.
Optional screen viewing
A person at the TV must first enable screen viewing in Curfew Control's TV Settings. An authenticated paired phone can then request low-rate screenshots over the encrypted local-network connection. Curfew Control does not capture audio or save screen-preview frames. The TV displays a "Screen view active" indicator using the opacity selected on the TV. Android and individual streaming apps may block screenshots of protected video.
Licensing, trials, and purchases
To start a trial, the TV shows a Google-provided address and short code that you approve on another device. Google returns a signed account identifier and verified email address to the licensing service. The service immediately discards the Google ID, access, and refresh tokens. It stores a keyed one-way hash of Google's stable issuer and subject identifier, plus the verified email address encrypted at rest and a keyed hash of that address. These records associate a trial or permanent purchase with the same Google Account after reinstalling Curfew Control or adding another TV, and help us locate purchase or support records. We do not request or store your name or use this information for advertising or profiling.
When the TV app activates or checks a trial or purchase, the Curfew Control licensing service may process:
- a keyed one-way hash of the stable Google Account identifier described above, a random internal account reference, and the verified Google email address stored encrypted at rest and as a keyed hash;
- a randomly generated installation public key and its hash;
- a keyed hash of the Google Play App Set ID, when available, to limit repeated trials;
- Google Play Integrity results, including app-recognition, licensing, device-integrity, and Device Recall results;
- trial start and expiration times, entitlement status, and last-contact time;
- Google Play product, order, purchase state, test-purchase, acknowledgement, revocation, and verification information; and
- purchase tokens, which are stored encrypted and also represented by a one-way hash.
The service and its delivery providers receive network information such as an IP address when a request is made. Curfew Control stores a keyed hash of the request address briefly for challenge rate limiting; hosting and security providers may retain limited network logs to operate and protect the service.
Optional crash reports
Crash reporting is off by default and can be changed independently on each device. If you enable it, Google Firebase Crashlytics processes crash traces, relevant app state, app and device diagnostics, Crashlytics and Firebase installation identifiers, app version, operating-system information, device model and related technical information to provide crash-reporting services. Curfew Control adds only an app-role marker. We do not intentionally attach names, PINs, schedules, installed-app lists, controller details, LAN addresses, or Accessibility event text.
Service providers and sharing
We do not sell personal information. Information is shared only as needed with service providers that operate features you request:
- Google Sign-In, Google Play, and Google Play Integrity for protected account linking, app licensing, purchase validation, fraud prevention, and Device Recall where enabled;
- Google Firebase Crashlytics when you opt in to crash reporting; and
- Google Firebase Cloud Messaging and Apple Push Notification service when you enable approval notifications;
- YouTube (Google) to play the tour video on our homepage, in YouTube's privacy-enhanced mode and only after you press play; and
- Cloudflare and our hosting infrastructure to deliver and protect the public policy pages and licensing API.
We may also disclose information if required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
Retention and deletion
- Local app data remains until you remove it through the app, clear app storage, or uninstall the app.
- Screen-preview frames are not retained by Curfew Control.
- Licensing challenges expire after five minutes and are normally removed within approximately fifteen minutes after expiration.
- Google device-authorization codes expire within minutes. They are encrypted while authorization is pending, destroyed when linking completes, and their expired session records are normally removed within approximately 24 hours. Google ID, access, and refresh tokens are not retained.
- Push approval events and responses expire within minutes and are removed from the Curfew Control service within approximately 24 hours. Push device registrations and random routes that have not been refreshed for 180 days are removed.
- Licensing, purchase, security, and audit records are kept while reasonably needed to provide entitlements, prevent repeated-trial or purchase abuse, reconcile transactions, meet legal obligations, and resolve disputes. They are deleted or de-identified when no longer needed.
- Firebase states that Crashlytics keeps crash traces and associated identifiers for 90 days before beginning removal from live and backup systems.
Curfew Control does not store account credentials or your Google name. You can switch the Google Account linked to one TV without deleting the prior account record; trials and purchases stay with the Curfew Control account to which they were originally assigned and are not transferred. To request deletion of the linked Curfew Control account record, email [email protected]. See our account deletion page for request and verification details. Deletion removes the encrypted email, random account record, and its associations with installations. Google Play transaction records, security records, a keyed one-way purchase-ownership reference, and a keyed one-way trial-used marker may be retained where needed to restore a purchase to its original account, prevent repeated-trial or purchase abuse, process refunds, meet legal obligations, or resolve disputes. These retained references do not contain an email, name, Google token, or password.
Security
TV-to-phone communication uses TLS and certificate fingerprint verification. Pairing creates a revocable credential. Sensitive local phone data and cloud-route secrets use platform-protected storage. Online traffic uses HTTPS, scoped random route secrets, short-lived approval records, installation signatures, rate limits, and encrypted email, provider-token, and purchase-token storage. No security measure can guarantee absolute protection.
Your choices
You can leave crash reporting, screen viewing, wake-from-phone, approval notifications, app locking, and Curfew Control protection off. Turning approval notifications off disables the current FCM or APNs device registration; the paired app can still retrieve short-lived requests from the approval relay while open. Provider permission can also be withdrawn in system settings. You can revoke Curfew Control's Google authorization from your Google Account, revoke paired phones, and remove local data by clearing storage or uninstalling. Android system settings control Accessibility access, notification permission, camera permission, and battery-optimization exceptions.
Children
Curfew Control is intended for an adult household administrator and is not directed to children. It does not provide child accounts or knowingly collect a child's name, contact information, or advertising profile.
International processing
Our providers may process information in the United States and other countries where they operate, subject to their contractual and legal safeguards.
Changes to this policy
We may update this policy when Curfew Control or applicable requirements change. We will update the effective date above and provide additional notice when appropriate.
Contact
Serviceable Software is the developer of Curfew Control. Send privacy questions or requests to [email protected].