Effective date: 6 September 2026 · App: Revive (com.revive.app) · Contact: support@revive-support.com
Revive is developed and operated by an independent developer based in the United Kingdom ("we", "us"). This policy explains what Revive does with information, in plain language. Where a section says on your device only, that information never leaves your phone.
Revive helps people who want to stop compulsive use of certain websites, keywords or apps. It blocks the things you list, protects those settings behind a PIN and two-factor authentication, and — optionally — lets a person you trust (an "accountability partner") know if you switch that protection off.
The following is stored in Android's encrypted app storage (backed by the device Keystore) and is never transmitted to us or anyone else:
| Data | Notes |
|---|---|
| Your PIN | Stored only as a salted hash; the PIN itself is never stored. |
| Authenticator (TOTP) secrets — yours and your partner's | Used to verify codes on the device. |
| Backup / one-time codes | Stored hashed. |
| Blocklists — domains, keywords, apps | Your configuration. |
| Habit, lapse and focus-timer records | Your personal progress data. |
| Your PIN-recovery email address | Stored encrypted on the device; see section 5 for the one moment it is transmitted. |
| Settings and preferences |
Accessibility service. To enforce your blocklist, Revive's accessibility service observes which app is in the foreground and reads the browser's address bar. This information is used instantly to decide whether to show a block screen or close a tab. It is not stored and not transmitted.
VPN service. Revive runs a local VPN on the device to filter DNS lookups against your blocklist. No browsing traffic is routed through any remote server, and nothing about your browsing is logged or sent anywhere.
Accountability mode is optional and off by default. When you enable it, you enter details of a partner and the app tells you clearly that this person will be asked to accept and will then be notified about your protection status.
While Accountability mode is active, the app sends the following to our server:
| Data | Why |
|---|---|
| A random device identifier generated by the app | To match events to your install. It is not linked to your Google account, phone number, IMEI, or advertising ID. |
| Your phone's model name | Shown in alerts so the partner knows which device. |
| Your partner's name, email address and mobile number | To ask for their consent and address the alerts. |
| Protection events: protection turned off, a block removed, Accountability switched off, the app force-stopped, the app going silent (possible uninstall), or a data-deletion request — with the time and the delivery channel used | The purpose of the feature. |
| A liveness signal roughly every 15 minutes: whether protection, the VPN and the accessibility service are running, and the app version | Solely so that sustained silence can be turned into a single "the app may have been uninstalled" alert. The signal itself is never sent to your partner. |
Where it is stored. On infrastructure provided by Supabase in Stockholm, Sweden (European Union). Access is restricted by row-level security: the app can only write its own events, and no app install can read another's data.
How alerts reach your partner. By SMS through Twilio and by email through Resend. These providers process your partner's phone number or email address only to deliver the message.
Your partner's consent. Your partner is a third party who has not used the app, so before any alert is sent they are asked: one text message ("Reply YES to accept, STOP to decline") and one email with Accept / Decline buttons, each linking to this policy. Alerts are sent on a channel only after they accept it. Every alert text ends with "Reply STOP to opt out" and every alert email carries an unsubscribe link; either withdraws that channel immediately. We record each request and response (channel, outcome, time) as evidence of consent. If your partner declines or opts out on every channel, the app tells you so you can choose a different partner.
Partner SMS approval codes (optional). Sensitive actions can be approved with a one-time code texted to your partner. To send it, the app passes your partner's mobile number to our server, which texts the code through Twilio and stores only a masked version of the number, a hashed code, a hashed device identifier and the action description, for 15 minutes plus a short purge window. The authenticator-app method works entirely offline and is always available as an alternative.
Only alerts: the type of event (for example, "protection was turned off"), the time, and your device's model name. Your partner never receives your blocklists, browsing activity, PIN, or any content.
You provide a recovery email address during setup. It is stored encrypted on your device only. If you use "Forgot PIN → Email me a code", the app sends that address and a one-time six-digit code to our server, which emails the code to you via Resend. The server records only your device identifier and the time of the request (to limit abuse to five requests per hour) — the address itself is not stored on our server, and those request records are deleted within an hour. Codes expire after 15 minutes.
Revive uses Firebase Crashlytics (Google) to collect crash reports so we can fix bugs. A report contains the crash stack trace, device model, Android version and app version. It does not contain your PIN, blocklists, partner details, or browsing information. Crash reporting is on by default; turn it off at any time in Settings → About → Crash reporting.
Requests to our server carry a Firebase App Check token that lets the server recognise the genuine Revive app. The token contains no personal information. Requests without a valid token are still served; the check is used only to detect abuse.
Some providers (Twilio, Google) may process data outside the UK/EU; where they do, transfers are covered by their standard contractual protections.
| Where | Retention |
|---|---|
| On your device | Until you delete it in the app or uninstall Revive. |
| Server — device record, events, liveness | While Accountability mode is active. Leaving Accountability mode clears your partner's details from our server straight away. Settings → Privacy & data → Delete my data removes everything we hold: immediately in Solo mode; in Accountability mode after a 7-day cooling-off period — your partner is told, alerts continue meanwhile, and you can cancel at any time before the deadline (this protects the accountability relationship from being ended impulsively). If the app is uninstalled or goes silent, your partner receives at most one final "the app may have been uninstalled" alert and the record is deleted automatically 30 days later. You can also request deletion by emailing support@revive-support.com — we act within 30 days. |
| Server — alert history | Deleted automatically after 90 days. |
| Server — your partner's consent records | Kept while the accountability relationship exists (evidence of consent); deleted with the device record. |
| Server — PIN-recovery request log | Deleted automatically within about an hour. |
| Server — SMS approval codes | Deleted automatically after expiry (15 minutes) plus a short purge window. |
| Crash reports | Retained by Firebase Crashlytics for 90 days. |
Information is encrypted in transit (TLS) and at rest. On-device secrets are protected by the Android Keystore; where a device cannot provide secure storage, Revive refuses to set up features that would require storing a secret unsafely. Server data is protected by row-level security and access keys that are never included in the app. Our servers hold no information that would allow anyone to unlock the app remotely.
Revive is intended for adults (18+). We do not knowingly collect information from anyone under 18.
If you are in the UK or EU you have the right to access, correct, delete, restrict or object to our processing of your personal information, and to data portability. Our lawful bases are your consent (Accountability mode and partner details, which you can withdraw by switching to Solo mode or deleting your data) and our legitimate interests in keeping the app reliable and secure (crash reports, abuse prevention). To exercise any right, email support@revive-support.com. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local data-protection authority.
We will update this page and change the effective date when the policy changes. Material changes will be highlighted in the app's release notes.