Privacy Policy
Privacy Policy
Push Up Screen Time App (also referred to as “RepLock”, the “App”)
Last updated: 17 July 2026
This Privacy Policy explains how Seyfi Can Zeyrek, trading as Morrowline Apps (“we”, “us”, “Developer”) — an individual developer, not a registered company — collects, uses, shares, and protects information when you use the App distributed on the Apple App Store and Google Play, and related websites such as https://replock.morrowline.app/.
Our Terms of Use are a separate document and describe the rules for using the App.
1. Introduction
We built the App as a voluntary digital wellbeing tool: you select apps to limit, earn screen time through exercise tracked on your device, and optionally subscribe to Premium. This Policy describes our actual data practices based on the App’s code and configuration.
2. Controller / who we are
| Field | Details |
|---|---|
| Legal name | Seyfi Can Zeyrek (individual / natural person) |
| Brand name | Morrowline Apps (brand only — not a registered company) |
| Address | Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye |
| Country | Türkiye |
| Privacy email | sczgamesinfo@gmail.com |
| Support email | sczgamesinfo@gmail.com |
| Phone | +90 555 027 76 81 |
| DPO | No separate DPO appointed — contact the privacy email |
| EU trader (DSA) | Yes — contact details above apply for EU Digital Services Act trader identification (individual trader) |
For users in Türkiye, a separate KVKK aydınlatma (information notice) is also provided.
3. Scope
This Policy applies to the mobile App (Android and iOS), in-App services, and the privacy contact channels above. It does not cover third-party apps you choose to block or websites you open outside our control.
4. Information we collect
4.1 On your device (core product data)
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Behavioral | Blocked app package names and labels; usage events; wallet balance; daily stats | Provide blocking and earned-time wallet | On device (SQLite / Drift) | Until uninstall or account deletion | Not shared |
| Fitness | Exercise type, reps/steps, duration, session timestamps | Award earned screen time | On device | Until uninstall or account deletion | Not shared |
| Preferences | Settings, onboarding progress | Configure the App | On device (SharedPreferences) | Until uninstall or account deletion | Not shared |
| Credentials | Optional emergency bypass PIN | Emergency unlock of blocking | On device (secure storage) | Until cleared or account deletion | Not shared |
4.2 Identifiers and cloud (limited)
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Anonymous account | Firebase Auth anonymous UID | Link push tokens and subscriptions | Device + Google Firebase | Until account deletion | Google (Firebase Auth) |
| Push tokens | FCM token, platform, timestamp | Deliver reminders you allow | Firestore users/{uid}/device_tokens/ |
Until rotate, revoke, or deletion | Google (FCM / Firestore) |
| Analytics | Event names/parameters, app instance id | Measure usage and improve the App | Google Firebase Analytics | Per Google product retention | |
| Crash data | Stack traces, device info, user identifier | Diagnose and fix crashes | Google Firebase Crashlytics | Per Google product retention | |
| Remote config / App Check | Config metadata; integrity tokens | Feature config and abuse protection | Google Firebase | Per Google product retention | |
| Subscriptions | App user id, entitlements, product identifiers | Premium billing and restore | RevenueCat + Apple/Google | Per store / RevenueCat policies | RevenueCat, Apple, Google Play |
4.3 Camera and motion
Camera frames are used for on-device pose detection to count exercise reps. Frames and video are not uploaded to our servers. Motion/step data is used for walking workouts and stored as local session summaries.
4.4 Advertising (V1)
The App includes Google Mobile Ads / UMP code, but ads are not initialized or requested in the current V1 configuration. Sample AdMob application IDs may appear in platform config for build requirements. If ads are enabled later, this Policy will describe ad signals and consent accordingly.
5. How we collect information
- Directly from you (settings, blocked app selection, PIN, support emails)
- Automatically from device APIs you authorize (camera, motion, usage access, accessibility foreground package, notifications)
- From SDKs listed in Section 9 (Firebase, RevenueCat; AdMob if enabled)
6. Why we use information
- Provide blocking, wallet spend, and exercise reward features
- Link Premium subscriptions and restore purchases
- Deliver reminders if you allow notifications
- Measure product usage and fix crashes
- Secure the App (App Check) and operate remote configuration
- Comply with law and respond to requests
7. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: contract (providing the App you request); legitimate interests (security, analytics, crash diagnostics, improvement — balanced against your rights); and consent (e.g. notifications; certain permissions; advertising consent if ads are enabled). You may withdraw consent without affecting prior lawful processing.
8. Sensitive permissions and APIs
Accessibility (Android)
We use an Accessibility Service solely to detect when a user-selected blocked app is in the foreground so we can show the block screen. We do not read passwords, typed text, messages, notification content, or other screen content. Window content retrieval is disabled (canRetrieveWindowContent=false). The service is not declared as an Accessibility Tool.
Usage Access (Android)
We use Usage Access to measure time spent in apps you chose to block. Content inside those apps is not read.
Display over other apps (Android)
Used to present the block overlay/screen.
Camera / Motion
Used for on-device rep and step counting as described above.
Notifications
Used for goal/streak reminders and service notifications. With permission, an FCM token may be stored in Firestore.
Before Accessibility settings are opened, the App shows a prominent disclosure requiring affirmative consent (checkbox + continue).
9. Sharing and processors
We share personal data with service providers who process it on our behalf:
| Recipient | Role |
|---|---|
| Google (Firebase Auth, Analytics, Crashlytics, Firestore, Cloud Messaging, Remote Config, App Check) | Auth, analytics, crash reporting, token storage, config, security |
| Google (ML Kit Pose Detection) | On-device pose estimation (no frame upload by our App) |
| RevenueCat | Subscription entitlement management |
| Apple / Google Play | Payment processing and store entitlements |
| Google Mobile Ads | Present in binary; inactive in V1 |
We do not sell personal information for money. See California notice below regarding “share” for advertising/analytics concepts.
10. International transfers
Google and RevenueCat may process data in the United States and other countries. Where required, transfers use adequacy decisions and/or Standard Contractual Clauses (or equivalent).
11. Retention
| Data | Retention |
|---|---|
| Local Drift / preferences / PIN | Until uninstall or in-App account deletion |
| Firestore device tokens | Until token change, permission revoke, or account deletion |
| Analytics / Crashlytics | Per Google product retention |
| Subscription records | Per RevenueCat and store policies |
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, port, or object to certain processing, and to withdraw consent. EEA/UK users may lodge a complaint with a supervisory authority (including the ICO in the UK). California residents: see Section 12.1. Turkish users: see the KVKK aydınlatma and KVKK Article 11 rights.
How to exercise: use Delete account in the App (You / Settings), and/or email sczgamesinfo@gmail.com.
12.1 California (CCPA/CPRA)
We collect the categories listed in Section 4. Sources include you, your device, and processors in Section 9. Purposes are listed in Section 6. We do not sell personal information for money. Analytics and (if ads are enabled) advertising technologies may constitute “sharing” under CPRA. To opt out of sale/share where applicable, email sczgamesinfo@gmail.com with subject “Do Not Sell or Share”. You may request to know, delete, correct, or limit sensitive PI as provided by law. We will not discriminate against you for exercising rights.
12.2 EEA/UK summary
Controller details are in Section 2. Legal bases in Section 7. Automated decision-making producing legal or similarly significant effects is not used. Full rights and complaint avenues are described above.
13. Account and deletion
The App uses an anonymous Firebase identifier (not a traditional email account). Delete account clears local database data, preferences, and the emergency PIN; deletes Firestore users/{uid} device token data where possible; signs out Firebase Auth; and logs out RevenueCat when configured. Some processor logs may persist for a limited period per their policies.
14. Children
The App is intended for users 18 years of age or older. We do not knowingly collect personal information from children. If you believe a minor has used the App, contact us to delete data.
15. Security
We use platform secure storage for the emergency PIN, TLS for network calls to processors, and Firebase App Check. No method of transmission or storage is 100% secure.
16. Automated decisions
We do not engage in solely automated decision-making that produces legal or similarly significant effects concerning you.
17. Changes
We may update this Policy. The “Last updated” date will change, and we may provide in-App or store listing notice for material changes.
18. Contact
Seyfi Can Zeyrek, trading as Morrowline Apps
Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye
Email: sczgamesinfo@gmail.com
Phone: +90 555 027 76 81
Website: https://replock.morrowline.app/
Related: Terms of Use (separate document); KVKK Aydınlatma Metni (Turkish information notice).

