Privacy Policy
Last updated: 15 September 2026 · Version 2026-09-15.1
Lock In is built to be private by default: there is no backend, no account, and no server-side storage. This policy explains what the app does and does not do with your information, in plain language. It applies to the Lock In application, including its web, Android, and iOS versions, operated by Type-3 Studio ("we", "us", "our").
- No accounts, no sign-up, no email required.
- No analytics, no advertising, and no cross-site tracking.
- All of your data stays on your device, inside your browser's local database.
- Nothing is uploaded to us — there is no server to upload it to.
- We do not sell or rent your personal information. Ever.
1. Who we are
Type-3 Studio is the data controller responsible for the Service. For privacy questions or requests, contact us at [email protected] or via type-3studio.com.
2. Information we do not collect
We do not collect or process, on our servers:
- Your name, email address, or any account credentials (there are no accounts).
- The goals, deadlines, tasks, notes, or list items you create in the app.
- Your contacts, calendar, photos, or files.
- Advertising identifiers or behavioural profiles.
- Analytics or usage telemetry about how you use the app.
3. Information stored on your device
Lock In keeps everything on your device. Your goals, tasks, generated occurrences,
notes, and the append-only history log are stored in your browser's
IndexedDB database (managed by Dexie), and a couple of small display
preferences are kept in localStorage. None of this is readable by us, and
none of it leaves your device.
| What | Where | Purpose |
|---|---|---|
| Goals, tasks, occurrences, notes, history, backups | IndexedDB database lock-in | The entire app state, including automatic pre-import backups. |
| Theme accent | lock-in:accent | Your chosen accent colour. |
| CRT mode | lock-in:crt | Whether the optional retro scanline effect is on. |
You can erase all of this at any time by clearing your browser's site data for this app (or uninstalling the installed app). Doing so resets the app to a first-run state. Because the data exists only on your device, you are responsible for it — use the Export feature to keep your own copy, and note that clearing site data is irreversible.
4. Offline use and the service worker
Lock In is an installable Progressive Web App. For offline use, a service worker caches the app's own files (HTML, CSS, JavaScript, icons) on your device. This cache contains no personal data and is not transmitted anywhere.
5. Third-party services
- Your hosting/CDN provider — like any website, the app is served by a hosting provider that may process standard server logs (such as IP address and request time) for security and delivery. We do not use these logs to identify you.
The app makes no other network requests. It does not embed third-party analytics, advertising, fonts, or social-media trackers.
6. Cookies and similar technologies
The app does not use cookies for tracking or advertising. It uses browser
localStorage and IndexedDB (described above) solely to make the app work,
and a service worker to cache app files for offline use. None of these identify you
personally.
7. Analytics and advertising
We do not use analytics services and we do not show ads. We do not sell, rent, or trade your information to anyone.
8. Legal bases for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, our only processing on our own systems is the processing of standard server logs by our hosting provider, which we rely on legitimate interests to do (security, availability, and fraud prevention). Everything else happens entirely on your device and is not processing on our behalf.
9. Your rights
Depending on where you live, you may have rights under laws such as the GDPR/UK GDPR, the California CCPA/CPRA, or similar laws. These may include the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent or lodge a complaint with your local supervisory authority. You also have the right not to be discriminated against for exercising your rights.
Because we do not collect or retain personal data about you on our servers, there is generally nothing for us to access, correct, or delete — the data is already under your control on your device (clear your browser's site data to remove it). If you have a request or question, contact us and we will respond as required by law.
10. Users in Iraq
We respect the right to privacy guaranteed under the Constitution of the Republic of Iraq (Article 17) and related provisions. Iraq does not currently have a comprehensive, standalone personal-data-protection statute, but the general protections of the Iraqi Civil Code (No. 40 of 1951) and the Electronic Signature and Electronic Transactions Law (No. 78 of 2012) apply to electronic dealings with the Service. Because the Service does not collect personal data centrally, the information you enter stays on your device under your control. If you have any privacy concern, contact us and we will address it promptly.
11. Children's privacy
The Service is not directed to children under 13 (or the minimum digital-consent age in your country, where higher), and we do not knowingly collect personal information from them. Because we do not collect personal information through the app, we do not maintain profiles of any users, including children.
12. Security and breach notification
We design the app to minimise risk by keeping data on your device and not collecting it centrally. No method of storage or transmission is completely secure, but because we hold no personal data about you, there is very little to compromise. Please keep your device and browser up to date. In the unlikely event of a security incident involving personal data we do hold, we will notify affected users and any relevant authorities as required by law.
13. Data retention
The data described above lives only on your device and remains there until you clear it or uninstall the app. Our hosting provider's server logs, if any, are retained only for as long as reasonably necessary for security and delivery purposes. We do not otherwise store or retain personal data about you.
14. International transfers
We do not transfer your data internationally, because we do not receive it in the first place. The only cross-border element is the ordinary delivery of the app's files to your browser by our hosting provider's global network.
15. Do Not Track and Global Privacy Control
We do not track you across sites, so "Do Not Track" (DNT) and Global Privacy Control (GPC) signals are respected by default: there is nothing to opt out of. Enabling or disabling these signals does not change how the Service behaves.
16. Changes to this policy
We may update this policy as the app evolves. When we make material changes, we will update the "Last updated" date and version above. The current version is always linked from within the app.
17. Contact
Questions or concerns? Email [email protected] or visit type-3studio.com. See also our Terms of Service.