Lock In ← Back to app

Privacy Policy

Last updated: 15 September 2026 · Version 2026-09-15.1

Lock In is built to be private by default: there is no backend, no account, and no server-side storage. This policy explains what the app does and does not do with your information, in plain language. It applies to the Lock In application, including its web, Android, and iOS versions, operated by Type-3 Studio ("we", "us", "our").

The short version
  • No accounts, no sign-up, no email required.
  • No analytics, no advertising, and no cross-site tracking.
  • All of your data stays on your device, inside your browser's local database.
  • Nothing is uploaded to us — there is no server to upload it to.
  • We do not sell or rent your personal information. Ever.

1. Who we are

Type-3 Studio is the data controller responsible for the Service. For privacy questions or requests, contact us at [email protected] or via type-3studio.com.

2. Information we do not collect

We do not collect or process, on our servers:

3. Information stored on your device

Lock In keeps everything on your device. Your goals, tasks, generated occurrences, notes, and the append-only history log are stored in your browser's IndexedDB database (managed by Dexie), and a couple of small display preferences are kept in localStorage. None of this is readable by us, and none of it leaves your device.

WhatWherePurpose
Goals, tasks, occurrences, notes, history, backupsIndexedDB database lock-inThe entire app state, including automatic pre-import backups.
Theme accentlock-in:accentYour chosen accent colour.
CRT modelock-in:crtWhether the optional retro scanline effect is on.

You can erase all of this at any time by clearing your browser's site data for this app (or uninstalling the installed app). Doing so resets the app to a first-run state. Because the data exists only on your device, you are responsible for it — use the Export feature to keep your own copy, and note that clearing site data is irreversible.

4. Offline use and the service worker

Lock In is an installable Progressive Web App. For offline use, a service worker caches the app's own files (HTML, CSS, JavaScript, icons) on your device. This cache contains no personal data and is not transmitted anywhere.

5. Third-party services

The app makes no other network requests. It does not embed third-party analytics, advertising, fonts, or social-media trackers.

6. Cookies and similar technologies

The app does not use cookies for tracking or advertising. It uses browser localStorage and IndexedDB (described above) solely to make the app work, and a service worker to cache app files for offline use. None of these identify you personally.

7. Analytics and advertising

We do not use analytics services and we do not show ads. We do not sell, rent, or trade your information to anyone.

8. Legal bases for processing (EEA/UK users)

Where the GDPR or UK GDPR applies, our only processing on our own systems is the processing of standard server logs by our hosting provider, which we rely on legitimate interests to do (security, availability, and fraud prevention). Everything else happens entirely on your device and is not processing on our behalf.

9. Your rights

Depending on where you live, you may have rights under laws such as the GDPR/UK GDPR, the California CCPA/CPRA, or similar laws. These may include the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent or lodge a complaint with your local supervisory authority. You also have the right not to be discriminated against for exercising your rights.

Because we do not collect or retain personal data about you on our servers, there is generally nothing for us to access, correct, or delete — the data is already under your control on your device (clear your browser's site data to remove it). If you have a request or question, contact us and we will respond as required by law.

10. Users in Iraq

We respect the right to privacy guaranteed under the Constitution of the Republic of Iraq (Article 17) and related provisions. Iraq does not currently have a comprehensive, standalone personal-data-protection statute, but the general protections of the Iraqi Civil Code (No. 40 of 1951) and the Electronic Signature and Electronic Transactions Law (No. 78 of 2012) apply to electronic dealings with the Service. Because the Service does not collect personal data centrally, the information you enter stays on your device under your control. If you have any privacy concern, contact us and we will address it promptly.

11. Children's privacy

The Service is not directed to children under 13 (or the minimum digital-consent age in your country, where higher), and we do not knowingly collect personal information from them. Because we do not collect personal information through the app, we do not maintain profiles of any users, including children.

12. Security and breach notification

We design the app to minimise risk by keeping data on your device and not collecting it centrally. No method of storage or transmission is completely secure, but because we hold no personal data about you, there is very little to compromise. Please keep your device and browser up to date. In the unlikely event of a security incident involving personal data we do hold, we will notify affected users and any relevant authorities as required by law.

13. Data retention

The data described above lives only on your device and remains there until you clear it or uninstall the app. Our hosting provider's server logs, if any, are retained only for as long as reasonably necessary for security and delivery purposes. We do not otherwise store or retain personal data about you.

14. International transfers

We do not transfer your data internationally, because we do not receive it in the first place. The only cross-border element is the ordinary delivery of the app's files to your browser by our hosting provider's global network.

15. Do Not Track and Global Privacy Control

We do not track you across sites, so "Do Not Track" (DNT) and Global Privacy Control (GPC) signals are respected by default: there is nothing to opt out of. Enabling or disabling these signals does not change how the Service behaves.

16. Changes to this policy

We may update this policy as the app evolves. When we make material changes, we will update the "Last updated" date and version above. The current version is always linked from within the app.

17. Contact

Questions or concerns? Email [email protected] or visit type-3studio.com. See also our Terms of Service.