CamLockComing to Google Play

Privacy

Privacy policy

Last updated 2026-09-25.

CamLock is for parents or guardians using their own Android phone. It processes enrolled children's face data on that phone to decide when to show a lock screen. Local processing still involves personal and biometric data. This policy explains that processing, the history files you can export, and the separate information involved when you visit this website or contact support.

Who to contact

Contact the CamLock developer about the app, this website or a privacy request at camlock-studio@proton.me. The app has no user accounts or developer-operated service that receives its face checks.

Data processed on your phone

  • Face templates. During enrolment, CamLock turns camera frames or photos you select into numeric measurements used for matching. Saved templates are encrypted with an Android Keystore key. They are sensitive biometric data, not anonymous data; encryption is not a guarantee against every form of misuse or reconstruction.
  • Child profiles. A name you enter, an app-generated identifier, enrolment and update dates, face templates, and options such as an enabled profile, tracking-only mode or a custom lock message. Profiles and templates are stored together in an encrypted app-private file.
  • Activity history. Records can include time, event type, child name and identifier, the reason for a check or lock, match similarity, frame count and trigger source. Events include checks, locks, unlocks, protection changes, call access, tamper detections and profile changes. History is kept in an app-private database, separate from the encrypted profile file.
  • Settings and diagnostics. Your preferences and local status information help CamLock operate and show you problems. These are not sent to an analytics or crash reporting service by the app. Android diagnostic logs can include foreground app package names and protection events. Android controls those logs separately from the app's history.

The current app has no internet permission, advertising SDK, analytics SDK or remote crash-reporting SDK. Its face detection and matching models run locally. Android backup and device-transfer backup are disabled for the app's stored data.

Camera and selected photos

With protection enabled, a check briefly uses the front camera, typically for about 2.5 seconds. Checks can be triggered by starting protection, screen or unlock events, an app switch, a follow-up or a scheduled check, depending on your settings. CamLock processes the frames in memory and does not save camera photos or video. Supported Android versions display their camera-use indicator.

Photos selected for enrolment are read to create templates; CamLock does not keep a copy of the selected images. The originals remain in your gallery or chosen photo service and are not deleted by CamLock. Any syncing of those originals is controlled by that service.

Permissions and access

  • Camera — enrolment and face checks.
  • Usage Access — notice the foreground app and restore the lock over apps that hide overlays. It does not read screen contents or browser history; foreground app identifiers can appear in local diagnostic logs.
  • Display over other apps — show the child-facing lock screen.
  • Notifications — show protection status, reboot reminders, tamper alerts and optional daily summaries.
  • Phone state — respond to Android's ringing or active-call status. CamLock does not read phone numbers or call recordings.
  • Biometrics — ask Android to authenticate the parent. CamLock receives the authentication result, not your fingerprint data.
  • Battery settings — optionally open Android's battery optimisation settings. This is not a battery-exemption permission requested by the app.

History exports and other apps

Exporting history is optional and starts only when you choose it. CamLock writes a CSV through Android's file picker to the destination you select. It can contain timestamps, child names and identifiers, event types, reasons, similarity scores, frame counts and trigger sources. It does not contain photos or face templates. The CSV is plain text, not encrypted by CamLock.

The picker may offer local storage or a cloud provider. Choosing a cloud destination can send the file off the phone through that provider, under its own privacy and retention rules. Choose a destination you trust and restrict who can access the file. Copies you later share are also outside CamLock's control.

Opening a support email or a website link launches another app. Your email provider, browser and the destination service handle that interaction under their own policies. CamLock does not automatically attach profiles, face templates or history to a support email.

Retention and deletion

  • Remove a child deletes the saved profile and templates. Earlier history can still contain that child's name and identifier, including the removal event.
  • Reset face samples removes a child's templates while keeping their profile. Earlier history remains.
  • History retention defaults to 90 days and is configurable. Cleanup is scheduled daily but depends on Android allowing it to run, so older entries may remain until the next successful cleanup.
  • Delete history clears the app's recorded history while keeping profiles and settings.
  • Delete all data in Settings stops protection and clears the app's profiles, templates, history and settings when the operation completes successfully.
  • Uninstalling removes CamLock's app-private data.

Deleting data in CamLock or uninstalling does not delete exported CSV files, copies held by other people or cloud providers, original gallery photos, or emails sent to support. Delete those separately at their destination. We cannot remotely access or erase the app-private records on your phone.

Children and biometric information

CamLock is intended for adults managing their own phone, not as an app for children to administer. Only enrol children for whom you are responsible and explain the face checks in a way they can understand. CamLock does not upload their face templates or camera frames to the developer. Face recognition can make mistakes, especially with similar faces; it is not proof of identity.

This website

The website is hosted on GitHub Pages. Your browser sends technical information to the host when it requests pages and files. GitHub records visitors' IP addresses for security, including when visitors are not signed into GitHub. See GitHub Pages data collection and the GitHub privacy statementfor its handling, retention and international-transfer information.

We use Cloudflare Web Analytics to count visits. It sets no cookies, does not use local storage and does not build a profile of you across sites. Your browser loads a script from Cloudflare, which receives the page address, the referring page, your browser and device type, and your IP address, which Cloudflare uses to estimate your country. We see only aggregated counts. See the Cloudflare Web Analytics page and the Cloudflare privacy policy.

We have not added advertising trackers, tracking cookies or external font requests to this website. Fonts come from your device. Links to other services are opened only when you follow them; their privacy policies then apply.

Support and privacy enquiries

If you email us, we receive your email address, message and any attachments you choose to send, such as your phone model, Android version or a description of a problem. Please do not send children's photographs, face templates, ID documents or unredacted history. We use the information to answer your request, troubleshoot, handle complaints and protect the service. We do not sell it or use support messages for advertising.

We use Proton Mail for the support mailbox. Email is handled by Proton and your own mail provider; see Proton Mail's privacy policy. A normal support email should not be assumed to have end-to-end encryption between every provider. Send only what is needed for your request.

Where European data-protection law applies, ordinary support processing is based on our legitimate interest in answering enquiries and keeping the service working, or on handling your contract where the request concerns it. We retain correspondence while needed to resolve the request and related follow-up, and longer only when required for a legal obligation or a dispute. The reason and applicable obligation determine that period.

Your rights and security

Depending on the applicable law, you may request access, correction, deletion, restriction or portability of information we hold, and object to processing based on legitimate interests. Contact the email above. These requests concern information we hold, such as correspondence; use the app controls for records stored only on your phone. You can also complain to your local data-protection authority, including AZOP in Croatia.

Saved profiles and face templates use AES-GCM encryption with an Android Keystore key. Opening the app and dismissing its lock require a strong Android biometric with no device PIN fallback. Keep your phone and account access secure: app-private storage, encryption and biometrics cannot guarantee protection against every attack.

Changes

We will publish changes on this page and update the date above when these practices change.