Privacy Policy

What ByeFeed collects, what never leaves your phone, where your data is stored, who can see it, how long it is kept, and how to delete it.

Last updated: 25 September 2026

On this page

1. Introduction and scope

ByeFeed is an app, website and short-form feed blocker for Android, made by Bros Dolz LLC (“we”, “us”). This policy covers:

  • the ByeFeed Android app (package name com.byefeed.app), and
  • this website, byefeed.app.

It explains what information each of them handles, why, where it goes, how long it is kept and what choices you have. It doesn’t cover services you reach through the app that have their own privacy policies, such as Google Play and Google Sign-In.

Bros Dolz LLC is responsible for the data described here. You can reach us at [email protected], or by post at Bros Dolz LLC, 418 Broadway Ste N, Albany, NY 12207-2922, United States.

2. At a glance

  • Blocking happens on your phone. ByeFeed only watches for the triggers on your block list and ignores everything else. Nothing it checks is stored or uploaded.
  • An account is optional. Without one, nothing about you is uploaded to us.
  • With an account, we store your email address and one backup of your ByeFeed setup, so you can restore it and sync it across devices.
  • Payments go through Google Play. We never see your card or bank details.
  • No ads, no analytics, no tracking and no crash-reporting service. We don’t sell your data.
  • You can delete your account inside the app. It is deleted immediately.

3. Information we collect

What we hold depends on whether you have an account. If you choose Continue without an account during setup, nothing is created on our servers: your setup stays on your phone and there is no record of you with us.

An account is created only when you:

  • create one with an email address and password (confirmed with a 6-digit code we email you),
  • sign in with Google, or
  • redeem an unlock code while signed out. The code has to belong to an account, so the app creates one with no email address and no password on it. It asks you first.
InformationWhenWhyKept until
Account IDAny accountTo identify your account and link your backup and purchases to itYou delete the account
Email addressEmail or Google accountsTo sign you in and confirm requests are yoursYou delete the account
Password hashEmail accountsTo sign you inYou delete the account
Google sign-in detailsGoogle accountsTo sign you in without a passwordYou delete the account
Your ByeFeed setup (cloud backup)Any accountTo restore your setup and sync it across devicesYou delete the account
Purchase and subscription recordsPro bought while you have an accountTo confirm Pro and keep its status currentYou delete the account
Unlock code redemptionsYou redeem a codeTo grant Pro and stop codes being guessedYou delete the account (failed attempts: 24 hours)
Support emailsYou write to usTo answer youAs long as needed to help you

Accounts with no email address are also deleted automatically after 90 days without activity, unless they hold Pro (section 9).

Account information

  • Account ID. A random identifier (a UUID) created by our authentication provider, Supabase, when the account is created. It isn’t derived from your phone, phone number or advertising ID, and on its own it identifies nobody. The app shows it as Account ID on the account page of an account with no email address.
  • Email address, if you sign up with email or sign in with Google.
  • Records Supabase keeps about the account itself, such as when it was created and when it last signed in.

Authentication information

  • Password. If you create an account with email and password, Supabase stores only a one-way hash of your password (bcrypt), never the password itself. We can’t see it.
  • Google sign-in. If you choose Continue with Google, Google confirms who you are and passes ByeFeed a sign-in token with your Google account’s email address and the basic profile details Google includes, such as your name and profile picture link. Supabase keeps these with your account. No password is stored. ByeFeed doesn’t show or use your name or picture.
  • Verification codes. We email 6-digit codes to confirm a new account, reset a password or change an email address. Each code expires after 15 minutes. ByeFeed has no passwordless sign-in; codes are only used for these three things.
  • Sign-in session. Once you are signed in, a session token is kept in the app’s private storage on your phone so you stay signed in.

Your ByeFeed setup (cloud backup)

If you have an account, the app keeps one backup of your setup in our database, up to 2 MB, so you can restore it and use it on more than one device. It contains:

  • your block groups: the apps, websites, keywords and short-form feeds you chose to block, their schedules and session limits;
  • your protection and cooldown settings: countdown lengths, pause length, PIN attempt limit, which settings are PIN-protected, and the PIN-recovery amount you chose (a setting only; no payment is ever taken);
  • a SHA-256 hash of your PIN, never the PIN itself;
  • your default redirect site;
  • statistics counters: blocks today, focus time today, how many times you have paused blocking, and the date and app of the last pause;
  • your pause history: for each time you used Pause Blocking, the time, the app and the group;
  • how you labelled apps in your statistics (productive, neutral or distraction).

The websites and keywords in the backup are the ones you chose to block. They are part of your settings, not a record of anything you visited. The backup never contains the web addresses you open, your searches, the pages you view or your detailed app usage.

Purchase information

If you buy Pro, Google Play handles the payment. What we receive and keep is described in Payments and refunds. In short: the purchase token and product, your plan and its status, and the purchase record Google Play returns. Never your card details.

Support emails

If you email us, we receive your email address, your message and anything you choose to include, such as a problem report from the app. We use it only to help you.

4. Information processed on your phone only

Blocking is decided entirely on your phone. ByeFeed only watches for the triggers you set up, and ignores everything else. Nothing from these checks is stored, and nothing is sent to us or anyone else.

How ByeFeed detects what to block

ByeFeed uses Android’s accessibility service, the system feature for apps that respond to what happens on screen. It is turned on only after you accept a separate notice in the app, and you can turn it off at any time in Android’s Accessibility settings.

Android lets ByeFeed know when the app or screen in front of you changes. Each time, ByeFeed runs only the checks your block list needs:

  • Blocked apps. It checks which app just came to the front against the apps you chose to block.
  • Blocked websites and keywords. In supported browsers (Chrome, Samsung Internet, Firefox, Edge, Brave, Opera, DuckDuckGo, Vivaldi and Kiwi), it checks the address in the address bar against your blocked sites and keywords. While you are typing in the address bar it waits, so a half-typed address never counts.
  • Short-form feeds. In the apps where you switched a feed off, it looks for the specific screen elements that mark that feed, such as the Reels player, by their built-in names and labels. It stops as soon as it finds one.
  • Other apps’ built-in browsers, only if you turn this on. When you open a web page inside another app, it checks that page for your blocked sites and keywords.

If something matches, the block screen appears. If nothing matches, ByeFeed does nothing. Either way the result is used once and discarded: nothing is saved, logged or uploaded, no browsing history is built, and ByeFeed never records what you type.

Usage access

If you allow usage access, ByeFeed reads how long you spend in each app to show your statistics, and uses it to recognise the app in front of you more reliably. This usage data stays on your phone. Only the statistics counters listed above are part of the cloud backup.

Data stored on your phone

The app keeps its working data in its private storage on your phone: your block groups and settings, statistics, pause history, a log of blocks, per-app open counts, your PIN hash, and the Google Play purchase token (so Pro works offline and without an account). Other apps can’t read it. Uninstalling ByeFeed, clearing its data in Android’s settings, or using Delete account or Clear data removes it.

ByeFeed turns off Android’s automatic app backup, so none of this is copied to your Google Drive backup.

5. Information stored in our database

Our backend runs on Supabase, which provides the authentication service and a PostgreSQL database. This is every place data about an account is stored:

RecordWhat it containsWho can read it
AccountAccount ID, email address, password hash (email accounts), Google sign-in details (Google accounts), and when it was created and last signed inSupabase’s authentication service
ProfileAccount ID, whether Pro is on, and when it was created and updatedOur server functions only
BackupYour ByeFeed setup (see section 3), its format version and when it was last updatedOnly your own signed-in account
SubscriptionPlan, product, Google Play purchase token, status, auto-renew, end of the current period, start date, and the purchase record returned by Google PlayOur server functions only
Code redemptionsThe code you redeemed, when, and when its Pro endsOur server functions only
Redemption attemptsCodes tried and when, to stop guessing. Deleted after 24 hoursOur server functions only
Account transfer tokensA single-use token, used when you add an email or Google account that already has a ByeFeed account. No personal data; expires after 15 minutesOur server functions only

The database also holds housekeeping records with no personal data: counts of inactive accounts removed by the cleanup job described in section 9 (kept for two years, with no account IDs), and a heartbeat that keeps the database active.

6. Device and technical information

  • No device identifiers. ByeFeed doesn’t collect your advertising ID, Android ID, IMEI, serial number or phone number.
  • Problem reports are yours to send. A report from Report a problem contains technical details about your phone and the app (see section 19). It only reaches us if you choose to send it.
  • IP addresses. When the app connects to Supabase (to sign in, back up, verify a purchase or redeem a code), Supabase receives your IP address as part of the connection. It may keep it in its service logs for security and operation, and its sign-in log can include the IP address used. We don’t use IP addresses to locate you or build a profile of you.
  • Crash reports through Google. ByeFeed has no crash-reporting service of its own. If you allow your phone to share usage and diagnostics with Google, Android may report ByeFeed crashes to Google, and we can see them as crash reports in the Google Play Console. These contain technical details such as the phone model, Android version and the error, not your name or contact details.
  • No analytics. ByeFeed doesn’t measure how you use the app, and neither does this website.

7. Cookies and local storage

This website sets no cookies, runs no analytics and loads nothing from other companies: its fonts, images and scripts are all served from byefeed.app. Your browser’s local storage is used for two preferences, and only if you set them: the country you pick in the pricing section (bf-country) and the light or dark theme you choose with the theme button (bf-theme). They stay in your browser, are never sent to us, and you can clear them with your browser’s site data. The website is hosted by GitHub (GitHub Pages), which receives the standard information any web server sees, such as your IP address and browser type, in order to deliver the pages and keep them secure, under GitHub’s Privacy Statement.

The app uses no cookies or advertising identifiers. It stores its own data on your phone as described in section 4, including your sign-in session if you have an account.

8. Why we use it

InformationWhat we use it for
Account and sign-in detailsSigning you in, keeping your backup private to you, and confirming that a request about the account really comes from you
Cloud backupRestoring your setup on a new phone or after reinstalling, and keeping your devices in sync
Purchase recordsConfirming that a purchase is genuine and active, unlocking Pro, keeping its status current through renewals, cancellations and refunds, and stopping one purchase being claimed by two accounts
Code redemptionsGranting Pro for the code’s period and limiting guessing
On-phone blocking checks and usage timeEnforcing your blocks and limits and showing your own statistics
Support emails and problem reportsAnswering you and fixing problems

We don’t use any of it for advertising or to build profiles of you.

9. How long it is kept

  • Email and Google accounts, with their backup, purchase and redemption records: until you delete the account.
  • Accounts with no email address: until you delete them with Clear data, or automatically after 90 days without activity, unless the account holds Pro through a subscription or an unlock code. Activity means the app refreshing its sign-in, saving a backup or redeeming a code. The cleanup runs once a week.
  • Failed code attempts: 24 hours.
  • Account transfer tokens: they expire 15 minutes after they are created, and are deleted with the account they came from.
  • Verification codes: they expire after 15 minutes.
  • Support emails: as long as needed to help you and to keep a record of requests we acted on, such as deletion requests.
  • Data on your phone: until you delete your account, use Clear data, clear the app’s data in Android’s settings or uninstall ByeFeed.
  • Database backups: see section 17.
  • Records Google keeps about your purchase: kept by Google under its own policies.

10. Account and data deletion

You can delete your account yourself, inside the app, at any time:

  • Email or Google account: Settings → your email address under Account → Delete account.
  • Account with no email: Settings → No account attached → Clear data.

Both delete your account immediately. Deleting the account also deletes every record linked to it: your profile, cloud backup, subscription record, code redemptions and transfer tokens. The app then resets your phone to a fresh install of ByeFeed.

What deletion doesn’t touch:

  • Your Google Play subscription. It isn’t cancelled or refunded. Cancel it in the Play Store.
  • Google’s own records of your purchase, which Google keeps under its own policies.
  • Database backups made before the deletion, until they expire (see section 17).

Signing out or uninstalling the app does not delete your account. If you can’t use the app, you can ask us to delete the account by email. The Delete Account page explains every route step by step.

11. Who can access your data

  • You, through the app. The database only lets a signed-in account read and write its own backup.
  • Bros Dolz LLC: the people who run ByeFeed can access the database through Supabase’s administration tools, and do so when needed to run the service, answer a support or privacy request, act on a deletion request, or look into a problem.
  • Our service providers (section 12), only as needed to provide their service to us.
  • Authorities, only where the law requires us to disclose information.

12. Third-party technologies and services

ByeFeed uses a small number of outside services. Each receives only what it needs to do its job:

ServiceWhat it does for ByeFeedWhat it may process
Supabase Accounts and sign-in, the PostgreSQL database, and the server functions that verify purchases and receive Google Play updates Account ID, email address, password hash, Google sign-in details, your cloud backup, purchase and redemption records, and the IP address of each connection
Google Sign-In Lets you sign in with your Google account, using the account picker on your phone Your Google account’s email address and basic profile, and the sign-in token. Covered by Google’s Privacy Policy
Google Play Billing and the Google Play Developer API Takes payments and runs subscriptions. Our server asks Google Play whether a purchase is genuine, and Google Play tells our server about renewals, cancellations and refunds Google handles your payment details. We exchange the purchase token and product with Google, and the app gives Google Play your Account ID with each purchase so Google can link the purchase to your account
Google Play and Android Distribute and update the app, and may send crash reports if you allow it As described by Google; see section 6
Google Workspace (email) Delivers the 6-digit codes we email you for sign-up, password reset and email changes Your email address and the email it delivers
GitHub (GitHub Pages) Hosts this website, byefeed.app Standard web request information, such as IP address and browser type. Covered by GitHub’s Privacy Statement

Email you send to [email protected] is received and handled by Bros Dolz LLC itself. ByeFeed also includes open-source libraries that run only on your phone and send nothing anywhere, for example its local database and its network-status check.

Not used: ByeFeed contains no analytics services (such as Firebase or Google Analytics), no crash-reporting services (such as Crashlytics or Sentry), no advertising networks or SDKs, no social-media SDKs and no AI services. Nothing you do in ByeFeed is sent to an AI model.

13. No selling, renting or advertising

We don’t sell, rent or trade personal data. We don’t share it with anyone for advertising or marketing. There is no advertising in ByeFeed and no advertising identifier is collected. ByeFeed is paid for by Pro, not by your data.

14. What ByeFeed does not do

  • It doesn’t show ads or include any advertising SDK.
  • It doesn’t include analytics, tracking or crash-reporting SDKs.
  • It doesn’t collect your advertising ID, Android ID, IMEI, serial number or phone number.
  • It doesn’t keep or upload your browsing history, searches or the pages you view.
  • It doesn’t keep or upload anything from its blocking checks.
  • It doesn’t record what you type.
  • It doesn’t access your location, camera, microphone, contacts, SMS, call logs, photos or files.
  • It doesn’t use your fingerprint, face or any other biometric data.
  • It doesn’t sell your data or share it for advertising.
  • It doesn’t send your data to AI services.
  • It doesn’t lock, wipe or otherwise control your phone.
  • It doesn’t copy its data into your Google Drive backup.

15. App permissions

ByeFeed is a blocker, so it asks for some powerful permissions. Each is asked for when a feature you are using needs it, and the app tells you whether that feature needs it or just works better with it. This is every permission the app declares:

PermissionWhat ByeFeed uses it forNeeded?
Accessibility serviceDetecting the triggers you set (a blocked app opening, a blocked website or keyword in your browser, a short-form feed you switched off) and showing the block screen. How it worksYes, for blocking. You turn it on yourself after a separate notice
Usage accessMeasuring time in each app for your statistics, and recognising the app in front of you more reliablyFor statistics. Blocking works without it
Display over other appsShowing the block screen, session prompts and the session timer on top of other appsYes
Foreground serviceKeeping blocking running in the background, with the ongoing notification Android requiresYes
NotificationsThe “blocking is on” notification, time left in a session, blocking paused, and reminders about missing permissions. Each can be switched off in your phone’s settingsOptional
Ignore battery optimisationStopping Android from shutting down blocking in the backgroundOptional, recommended
Run at startupStarting blocking again after your phone restarts or the app updatesGranted automatically
Device adminOnly for Prevent Uninstall: stopping ByeFeed being uninstalled while that setting is on. It declares no other device-admin powersOptional, off unless you turn it on
Internet and network stateSigning in, backing up, verifying purchases, and retrying a backup when your connection comes backGranted automatically
Google Play billingBuying ProGranted automatically
Visibility of launchable appsListing the apps on your phone that have a launcher icon, so you can pick which to block. ByeFeed doesn’t request access to the full list of installed packagesGranted automatically
Biometric and fingerprintAdded automatically by Android’s Credential Manager library, which Google sign-in uses. ByeFeed itself never shows a fingerprint or face prompt and never uses your biometric dataNot used by ByeFeed
Internal app permissionCreated automatically by an Android support library so ByeFeed’s own components can signal each other privately. Only ByeFeed holds it, and it gives no access to your dataGranted automatically

Never requested: location, camera, microphone, contacts, SMS, call logs, calendar, photos, files or storage, and the full list of installed apps (QUERY_ALL_PACKAGES).

16. Security

  • Encryption. Everything the app sends to our backend travels over HTTPS (TLS). Supabase encrypts the database at rest.
  • Row-level security. Every table in the database has row-level security turned on. A signed-in account can read and write only its own backup. Purchase, profile and redemption records can’t be read or changed by the app at all, only by our server functions.
  • Least privilege. The app’s database roles hold only the permissions they use, and functions that run with extra rights are locked down. The administrative key for the database is never included in the app.
  • Verified purchases. Pro is unlocked only after our server confirms a purchase with Google Play, and one purchase can’t be claimed by two accounts.
  • Limits. Each backup is capped at 2 MB, and sign-in and code redemption are rate-limited.
  • Passwords and PIN. Passwords are stored as bcrypt hashes by Supabase. Your PIN is stored as a SHA-256 hash, never as the digits.
  • Reviews. We audited the backend’s access controls in July 2026 and fixed what we found.

No system is perfectly secure. If you believe you have found a security problem, please email [email protected].

17. Backups

“Backup” means two different things here:

  • Cloud backup is the app feature: the copy of your ByeFeed setup kept with your account (section 3). For an account with no email address, created by redeeming a code, it is kept for up to 90 days without activity (unless the account holds Pro). For an email or Google account, it is kept until you decide to delete the account. Either way, it is deleted the moment the account is.
  • Database backups are copies of the whole database that exist so it can be recovered after a hardware failure, a mistake or a security incident.

Our database is hosted by Supabase, and database backups are made by Supabase as part of its hosting service, according to the service plan we use. Before we change the structure of the database, we may also take a one-off backup through Supabase.

Database backups are kept only for a limited period and then expire on their own. If you delete your account, copies of its data can remain in database backups made before the deletion until those backups expire. Backups exist only so the service can be recovered.

18. Payments and refunds

Who processes payments

ByeFeed Pro is sold only through Google Play, using Google Play Billing. There is no other payment provider. Google processes the payment and holds your payment details under Google Payments’ privacy notice.

What ByeFeed receives

We never receive or store your card number, bank details or billing address. When you buy Pro:

  • Google Play gives the app a purchase token and the product you bought. The app keeps them on your phone, which lets Pro work offline and without an account. Without a network connection, Pro keeps working for up to 7 days before the purchase is checked again.
  • If you have an account, the app sends the token and product to our server, which asks Google Play whether the purchase is genuine and active. We then store your plan (monthly, yearly or lifetime), the product, the purchase token, its status (for example active, cancelled, expired or refunded), whether it auto-renews, the end of the current period and when it started, together with the purchase record Google Play returns. That record includes details such as the order number, the country of purchase, and the purchase, renewal and expiry times.
  • Google Play keeps our server informed about renewals, cancellations, refunds and other changes to that purchase.
  • With each purchase, the app gives Google Play your Account ID (if you have an account), so the purchase can be linked to your account.

You can buy Pro without an account. In that case nothing about the purchase is sent to us; Google Play confirms it on your phone.

Subscriptions and one-time purchases

Pro is available as a monthly or yearly subscription, or as a one-time lifetime purchase that doesn’t renew or expire. Subscriptions renew automatically until you cancel. Prices are set per country and shown by Google Play before you confirm; if Google Play offers you a free trial, it shows its length and when you will be charged.

Cancellation

Cancel at any time in the Play Store (Payments & subscriptions → Subscriptions) or at play.google.com/store/account/subscriptions. Manage subscription in the app opens the same page. Pro stays on until the end of the period you have paid for. Uninstalling ByeFeed or deleting your ByeFeed account doesn’t cancel a subscription.

Refunds

Refunds are handled under Google Play’s refund policy. To request one, find the purchase in your Google Play order history and choose Request a refund, or follow Google’s guide, Get refunds on Google Play purchases. If a purchase is refunded, Google Play tells our server and the purchase is marked as refunded, so Pro ends for that purchase.

Bros Dolz LLC has not published separate refund terms of its own. If you think you were charged by mistake, or Google can’t help, email [email protected] with your Google Play order number (it starts with GPA.) and we will look into it. Never send us card details.

19. Support and diagnostics

Contacting support

Email [email protected]. Include what is needed to help you: a description of the problem, your phone model and Android version, and for account or purchase questions, the email address on the account, your Account ID if you have one, or your Google Play order number. Never send your password, PIN, a verification code or card details. We will never ask for them.

Problem reports

In the app, Settings → About → Report a problem builds a report you can read before doing anything with it. It contains:

  • the date and time, the app version and build number;
  • your phone’s manufacturer and model, Android version, and technical build details (build fingerprint and processor type);
  • up to 20 recent events inside the app, such as a sign-in error message;
  • the details of the last crash, if there was one.

Email report opens a pre-filled email to us in your own email app, and Copy report copies the report. Nothing is sent unless you send it.

What is collected automatically

ByeFeed doesn’t send diagnostic information automatically. If the app crashes, the crash details are saved only on your phone, so they can go into the next problem report you choose to send. Separately, Android may report crashes to Google if you allow your phone to share diagnostics (section 6).

How diagnostic information is used

Only to understand and fix the problem you reported, and to reply to you.

20. Your rights and requests

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy of it, object to or restrict how we use it, and complain to your local data protection authority.

  • Delete: do it yourself in the app, immediately (section 10), or ask us.
  • Correct: change your email address or password in the app under your account, or ask us.
  • Access or copy: the app has no export feature, so email us and we will send you the data held about your account.
  • Other requests: email [email protected].

So that we act only for the account holder, we reply to the email address on the account. An account with no email address can be identified by the Account ID shown on its account page, or by a Google Play order number if you bought Pro with it. We will ask for nothing more than we need to find the right account.

21. Children

ByeFeed is not directed at children and is intended for people aged 18 and over. We don’t knowingly collect personal data from children. If you believe a child has created an account, email us so we can delete it.

22. Where data is processed

Bros Dolz LLC is based in the United States. ByeFeed’s accounts and database are hosted by Supabase in its East US (Ohio) region, us-east-2, in the United States. If you use ByeFeed from another country, your account data is transferred to and stored in the United States. Google and GitHub may process data in other countries under their own privacy policies.

23. Changes to this policy

We may update this policy as ByeFeed changes. The “Last updated” date at the top shows when it last changed.

24. AI disclosure

ByeFeed was built with the help of AI-assisted development tools. This does not change what data the app collects or how it is handled; those practices are described above.

25. Contact

Questions, requests or concerns about privacy: [email protected].

By post: Bros Dolz LLC, 418 Broadway Ste N, Albany, NY 12207-2922, United States.