Skip to content
Back to home

Privacy Policy

Last updated: 10 July 2026

Effective date: 10 July 2026

This is the privacy policy for Fluid Friction on Android. If you use Fluid Friction on iPhone or iPad, read the iOS privacy policy instead, because that version works differently.

The short version

Fluid Friction is a digital wellbeing app. To help you spend less time scrolling, it needs some data. We try to collect as little as possible, we never sell it, and you can delete it at any time.

  • Most data (per-app screen-time, friction events, behavioural patterns) stays on your device.
  • If you sign in to the Friends social layer, your nickname, friend code, streaks, health score, and content (haikus, stories) sync to Google Firebase so your friends can see them. If you also opt in to screen-time sharing, aggregated daily and weekly totals (never per-app detail or app names) sync too.
  • If you opt in to crash reporting or the AI wellbeing report, diagnostic data and report prompts are sent to Google (Firebase Crashlytics, Firebase AI Logic with Gemini). Both are off by default.
  • We do not run ads. We do not share data with data brokers. We do not sell your personal information.
  • You can delete your account and your server-side data at any time, see how.

The rest of this page is the complete, legally-binding version. It covers every data category Google Play's Data Safety form asks about, the sensitive Android permissions the app uses, the Firebase and AI services it relies on, and your rights under the GDPR, UK GDPR, CCPA / CPRA, LGPD, and PIPEDA.

Who we are

This privacy policy is issued by Manfred Mjengwa, trading as "Fluid Friction" (referred to in this policy as "we", "us", or "Fluid Friction"). Fluid Friction is the data controller for personal data processed through the Fluid Friction / Fluid OS Android app (Google Play package com.mjengwa.fluidfriction) and this website (fluidfriction.app).

For any privacy question, request, or complaint, contact us at [email protected]. We aim to respond within 30 days.

What this policy covers

This privacy policy applies to:

  • The Fluid Friction Android app, which also brands as Fluid OS when you set it as your default home launcher. Both are the same installation and the same privacy practices apply.
  • The fluidfriction.app website and any subdomain.
  • Any beta, preview, or test builds we distribute (internal testing, open testing, or direct APK).

This policy does not cover third-party apps you use alongside Fluid Friction (Instagram, TikTok, etc.), third-party accessibility services, or Google/Firebase policies that apply to your Google account itself.

Data Safety summary

This table mirrors Google Play's Data Safety form so you can see, at a glance, exactly what Fluid Friction collects, whether it leaves your device, and whether it is required for the app to work.

Data typeCollectedSharedPurpose
Email addressOptional (Friends sign-in)NoAccount sign-in, account recovery
Name (Google sign-in display name)Optional (Friends sign-in)NoAccount creation; you set a separate nickname
User IDs (Firebase UID, anonymous device ID)YesNoApp functionality, abuse prevention (Play Integrity)
Purchase history (Fluid Pro subscription)Yes, via Google Play BillingNoVerify your subscription entitlement
App interactions (scroll, friction, taps, session events)Yes, on deviceNoCore friction feature, behavioural analytics, wellbeing scoring
Screen-time totals (aggregated daily / weekly averages only, never app names)Optional (Friends screen-time sharing consent)With your friends, if you turn on sharingFriends leaderboard
Installed apps listYes, on deviceNoLauncher / app drawer, per-app friction rules
Other user-generated content (nickname, haiku, stories, theme choice, health score, streak, rank)Optional (Friends sign-in)With your friends, in-appFriends social layer
In-app search history (friend-code search)On device onlyNoFinding friends by friend code
Crash logs and diagnosticsOpt-in (off by default)With Google FirebaseFixing crashes and bugs
Approximate location (Wi-Fi SSID)Optional (Spatial Profiles feature)NoAuto-switch profile based on Wi-Fi network
Notification content (if you enable the Notification Listener feature)Optional, on deviceNoQuiet hours, priority-sender rules
Voice input (Todo speech-to-text)Ephemeral, handled by Android's system speech recogniser, not stored by usWith Google's speech recogniser (your device setting)Voice-to-text for quick task capture
Photos (camera or gallery)Optional; stored only on your device, never uploadedNoAttaching photos to todo items; scanning a QR-style friend code
AI wellbeing report prompts and responsesOpt-in (off by default)With Google (Firebase AI Logic / Gemini API) when cloud mode is usedGenerate the weekly wellbeing report and coach dialogue

If you choose not to sign in to Friends and you leave crash reporting, analytics, and the cloud AI report turned off, the only data that leaves your device is what Google Play itself needs to verify app integrity (Play Integrity token) and, if you buy Fluid Pro, your subscription status.

What we collect and why: the detail

1. Data you give us directly

  • Account credentials. If you sign in to Friends, you authenticate with your Google account (or continue as an anonymous guest). From Google sign-in we receive your email address and display name. These are handled by Google Firebase Authentication; we never see your Google password.
  • Nickname and friend code. You pick a display nickname and the app generates a short friend code you can share.
  • Content you create. Haikus, stories, replies, reactions ("bows"), and similar social content you write inside Friends.
  • PIN (if you enable Fluid Lock). Your PIN is hashed on your device with PBKDF2-HMAC-SHA256 (10,000 iterations) and a 16-byte random salt. The hash and salt are stored inside Android's EncryptedSharedPreferences (AES-256 GCM). We never see or transmit your PIN.
  • Settings and preferences. Friction intensity, blocking schedules, coach selection, theme, monitored apps, and similar configuration.

2. Data we generate on your device as you use the app

  • Scroll and friction events. When you cross the friction threshold, break through, accept or reject a suggestion card, start or end a focus session, open or close an app, etc. These events power the "health score", streaks, behavioural patterns, and the wellbeing report.
  • Screen-time ledger. With your grant of the Usage Access permission (PACKAGE_USAGE_STATS), Android tells us how long each app was in the foreground. We store a rolling ~30 to 90 days of daily totals and per-hour breakdowns in a local Room database so the app can show trends and pattern analysis. Per-app breakdowns and app names never leave your device; only aggregated daily and weekly totals can sync, and only with your explicit screen-time sharing consent in Friends.
  • Behavioural pattern profiles. Derived statistics (app chains, pickup times, session lengths, vulnerability windows) computed on your device from events and screen-time. Retained for up to 9 days.
  • Friction state and history. Daily "opens left" counters, blocking-mode history, intervention outcomes, rank progress, quest progress.

All of this is stored on your device. Nothing in this category is sent to us unless you explicitly enable Friends, the cloud AI report, crash reporting, or analytics.

3. Data sent to Google Firebase (only when features require it)

  • Firebase Authentication. When you sign in to Friends, your email, sign-in provider tokens, IP address, and user-agent are handled by Firebase Authentication for account management and abuse prevention.
  • Cloud Firestore (Friends). When you use Friends, we store your profile document (UID, nickname, friend code, theme ID, health score, streaks, rank tier, last-updated timestamp) and the social content you create (haikus, stories, replies, reactions). We also store friend-link records, friend codes, and referral records. If you opt in to screen-time sharing, we additionally store aggregated daily and weekly screen-time totals; never per-app breakdowns or app names.
  • Firebase App Check (Play Integrity). Before every Firestore call, the app attaches a short-lived attestation token so Google can verify the request came from an untampered build of Fluid Friction on a genuine Android device. This is device-level only; it does not identify you personally.
  • Firebase Crashlytics. If you opt in to crash reporting, we send anonymous crash stack traces, device model, Android version, app version, a Firebase Installation ID, and up to the last few minutes of breadcrumb logs. We strip accessibility event text, notification content, and message bodies before reporting. Retained by Firebase for 90 days.
  • Firebase Analytics. If you opt in, aggregate, non-identifying counters about app-lifecycle events (install, update, session start) and key feature usage. Advertising IDs are explicitly disabled for this app.
  • Firebase Remote Config. The app fetches JSON-based feature flags and defaults from Google; the request includes a Firebase Installation ID and app version. No personal data leaves your device as part of this call.
  • Firebase AI Logic (Gemini). If you enable the cloud wellbeing report or cloud coach dialogue, we send a structured prompt to Google's Gemini API that contains your screen-time totals for the relevant period, per-app breakdowns, your health score, and streaks, but not your identity, your messages, or your notifications. Google states that Gemini API prompts may be retained for up to 55 days for abuse detection. We do not use your prompts to train any model of our own and have not opted into any Google programme that uses paid API prompts for model training.
  • Google Play Billing. If you buy Fluid Pro, Google Play handles the payment. We receive a purchase token and the SKU that confirms your entitlement. We do not receive your card number, billing address, or full Google account identity.
  • Google Play Install Referrer. If you installed Fluid Friction via a referral link or campaign, Play passes us a short referrer string on first launch so we can attribute referral credit.

4. Data processed entirely on your device

  • ML Kit GenAI (on-device Gemini Nano). When available, your device can generate the wellbeing report or coach replies locally with Google's on-device model. In on-device mode the prompt and response never leave your device.
  • Wi-Fi SSID for Spatial Profiles. If you grant location permission and enable Spatial Profiles, we read the name of your current Wi-Fi network and match it against the profiles you've mapped (e.g. "HomeWifi → wind-down profile"). We do not read or store GPS coordinates. The SSID stays on your device.
  • NFC tags. If you set up NFC triggers, the tag ID is stored locally and matched to the profile you assigned.
  • Notification metadata. If you grant the Notification Listener permission, the app can read incoming notifications (title, text, package, category, priority) to apply quiet-hours and priority-sender rules. This is stored on your device and is not transmitted to us.

Sensitive permissions and in-app disclosures

Android considers some permissions "sensitive". For each one below, we describe exactly what we do with it, whether the feature is optional, and how you can revoke it.

Accessibility Service (BIND_ACCESSIBILITY_SERVICE)

This is the most sensitive permission on Android. Fluid Friction uses it for one purpose: powering the scroll friction and feed blocking you configure, in the apps you choose.

What the service does:

  • Detects when a monitored app is in the foreground (window state change events) and notices scroll events and scroll deltas, so the friction overlay appears at the right moment.
  • Reads on-screen UI element structure (view IDs, content descriptions, and the node hierarchy) to recognise specific screens, for example Instagram Reels or YouTube Shorts.
  • Dispatches scroll gestures when you break through the friction threshold you set.
  • Navigates away from short-form content screens when you have configured blocking (for example, tapping "Home" on YouTube).

What the service does not do:

  • It does not read text input fields, passwords, or anything you type.
  • It does not read your messages, emails, or chat content.
  • It does not store or transmit any data obtained from the accessibility API. Events and UI structure are processed in real time to detect app transitions and specific screens, then discarded.

Before any crash or log is reported, accessibility event data is passed through a sanitiser that strips any text and keeps only the event type and package name. We are not declared as an "accessibility tool"; we use the API for a permitted digital-wellbeing purpose. You can disable the service any time under Android Settings → Accessibility → Fluid Friction. If you do, friction stops working but the rest of the app keeps functioning.

System Alert Window (SYSTEM_ALERT_WINDOW)

Used to draw the friction wave / bubble overlay on top of other apps. The overlay is visual only and never transmits data.

Usage Access (PACKAGE_USAGE_STATS)

Used to read how long each app was in the foreground so we can show screen-time analytics, compute your wellbeing health score, and detect usage patterns. Data is stored on your device for up to ~90 days as daily totals and per-hour breakdowns. You can revoke this any time under Android Settings → Apps → Special Access → Usage Access.

Query All Packages (QUERY_ALL_PACKAGES)

Used for two core features: (1) the Fluid OS launcher's app drawer, which has to list every app installed on your device, and (2) per-app friction rules and feature-detection (so we know which app is open and whether Reels / Shorts is currently on screen). The list of apps stays on your device and is never transmitted.

Notification Listener (BIND_NOTIFICATION_LISTENER_SERVICE)

Optional. Only active if you explicitly enable the Notification feature. When on, the app reads incoming notification metadata (title, text, package, category, priority) to apply quiet-hours and priority-sender rules. This information is stored locally and is never transmitted to us. You can revoke the listener any time under Android Settings → Notifications → Device & app notifications → Fluid Friction.

Location (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_BACKGROUND_LOCATION, ACCESS_WIFI_STATE)

Optional. Only used if you enable Spatial Profiles. Android requires a location permission to read the name of the current Wi-Fi network. We use only the Wi-Fi SSID; we do not request or store GPS coordinates. Background location is used so the active profile can switch automatically when you come and go from known networks. Revoke any time under Android Settings → Location. If you don't use Spatial Profiles, you never need to grant this.

Microphone (RECORD_AUDIO)

Optional. Used only for the voice-to-text quick-add button in the Todo tool. We hand the microphone off to Android's system speech recogniser (the same one used by Gboard); we do not record, save, or stream audio ourselves.

Camera

Optional. You can take or select photos to attach to todo items; these are stored only in the app's private storage on your device and are never uploaded or transmitted. Camera access is also used transiently for on-device features such as scanning a friend's friend-code QR. We do not record video.

NFC

Optional. Used when you set up and tap NFC trigger tags.

Notifications, foreground service, exact alarms, battery optimisation exemption

These permissions are needed to keep the accessibility service and sleep / focus timers running reliably, show a status notification when friction is active (Android requires this), and schedule exact alarms for sleep and Pomodoro timers.

In-app disclosure and consent

Each sensitive permission is gated behind an in-app prominent disclosure screen that explains what the permission is for before Android asks you to grant it. You can continue without granting a given permission; the dependent feature will simply be unavailable until you do.

AI features (Gemini, on-device and cloud)

Fluid Friction uses generative AI for two features: the weekly wellbeing report and the coach dialogue. Both are off by default.

On-device mode (preferred). When your device supports it, we use Google's ML Kit GenAI (Gemini Nano), which runs entirely on the device. No data leaves your phone.

Cloud mode (fallback, opt-in). If on-device inference is unavailable, and only if you have opted in to the cloud AI features, we use Google Firebase AI Logic with the Gemini API. The prompt contains your screen-time totals for the report period, per-app breakdowns, your health score, streak, and similar aggregated stats, but not your real name, email, notifications, messages, or raw screen content. Google states that Gemini API inputs may be retained for up to 55 days for abuse detection; thereafter they are deleted. We do not use your prompts to train any model, and we do not opt into any Google programme that would allow Google to use paid Gemini prompts for model training.

You can turn cloud AI off at any time in Settings → AI features. On-device AI can be disabled in the same screen. AI-generated text is transient: it is rendered in the coach UI or report view and is not kept in Firestore unless you explicitly share it.

Who we share data with

We share personal data only with the service providers ("subprocessors") listed below, and only to the extent needed to run the features you use. We never share data with advertising networks or data brokers, and we never sell your personal information.

  • Google Firebase (Google LLC / Google Ireland Ltd.): Authentication, Firestore, Crashlytics, Analytics, Remote Config, App Check, AI Logic. Governed by Google's Cloud Data Processing Addendum and Firebase Data Processing and Security Terms. firebase.google.com/support/privacy.
  • Google Play Billing: processes payments for Fluid Pro. Governed by Google Play's terms.
  • Google Play Install Referrer: passes referral attribution strings on install.
  • Google Speech Recogniser: the Android system speech-to-text service when you use the voice button in the Todo tool. Governed by the privacy policy you accepted when you enabled voice input on your device.
  • Your friends, in-app: if you sign in to Friends, your nickname, friend code, theme, health score, streak, rank, haikus, stories, replies, and reactions are visible to the people you've added as friends, and, in aggregate, to the Friends leaderboard. Aggregated screen-time totals are visible only if you turn on screen-time sharing, and you can turn it off again at any time.
  • Law enforcement and regulators: we will disclose data where required by a valid legal request, and only the minimum required to comply.
  • A successor in interest: if Fluid Friction is sold or merged, personal data may transfer to the acquirer, bound by this same policy or a materially equivalent one.

We do not: run ads, embed advertising SDKs (AdMob, etc.), embed social-network SDKs (Meta, X, TikTok, etc.), sell data to data brokers, or share data for cross-context behavioural advertising.

How long we keep data

  • On your device. Settings and preferences stay until you change them, clear the app's data, or uninstall the app. Screen-time history is capped at ~30 to 90 days of rolling daily totals. Behavioural events are kept for up to 14 days. Behavioural pattern profiles are kept for up to 9 days. Notification metadata is kept only as long as needed to apply your rules.
  • Friends profile in Firestore. Kept until you delete your account. When you delete your account we remove your user document, friend links, friend-code entry, rank entry, referral record, haikus, stories, replies, and reactions from live systems as quickly as our pipeline allows, and from Google's backups within Google's published 180-day window.
  • Firebase Authentication records. Retained by Google for up to 180 days after you delete the account, per Firebase's published policy.
  • Firebase Crashlytics. 90 days (Firebase default), then automatically purged.
  • Firebase Remote Config / App Check tokens. Short-lived request metadata retained per Firebase's published policy (Remote Config up to 180 days, App Check tokens up to 7 days).
  • Gemini API prompts (cloud AI). Up to 55 days, held by Google for abuse detection, then deleted.
  • Purchase records. Retained by Google Play Billing for as long as Google's tax, accounting, and consumer-protection obligations require.
  • Support email. Email threads with [email protected] are retained for up to 24 months so we can follow up on multi-step issues, then deleted.

Legal bases for processing (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following Article 6(1) legal bases:

  • Contract (Art. 6(1)(b)). Core app functionality (friction, screen-time, blocking, pomodoro, todo, sleep tools), Fluid Pro subscription entitlement, account management.
  • Consent (Art. 6(1)(a)). Crash reporting, analytics, cloud AI features, accessibility service activation, notification listener activation, location-based Spatial Profiles, and marketing communications where applicable. You can withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)). Abuse and fraud prevention (Play Integrity / App Check), securing the service, responding to support requests, defending legal claims. We've balanced these interests against your rights and do not think any of them override your privacy expectations.
  • Legal obligation (Art. 6(1)(c)). Responding to valid legal demands and keeping tax / accounting records for paid subscriptions.

Your rights

Depending on where you live, you may have some or all of the following rights. You can exercise any of them by emailing [email protected] with the subject "Privacy request". We'll respond within 30 days (or the local statutory window, whichever is shorter) and we won't charge you a fee for a reasonable request.

  • Access. Ask for a copy of the personal data we hold about you in Firestore and Firebase Auth.
  • Rectification. Ask us to correct anything that is wrong. (Most profile fields, such as nickname and theme, you can edit yourself inside the app.)
  • Deletion ("right to be forgotten"). Delete your account and server-side data at any time, either inside the app or via /delete-account. See that page for exactly what is deleted and what is retained.
  • Portability. Receive your Firestore profile and user-generated content in a machine-readable format (JSON).
  • Object / restrict processing. Object to legitimate-interest processing and ask us to restrict it pending review.
  • Withdraw consent. Turn off any opt-in feature (crash reporting, analytics, cloud AI, accessibility service, notification listener, Spatial Profiles) at any time in Settings; doing so stops future collection, though it does not retroactively delete data already sent. You can follow up with a deletion request for that.
  • Complain. Lodge a complaint with your national data-protection authority. For EU residents this is typically your local DPA; for UK residents this is the ICO (ico.org.uk).

California residents (CCPA / CPRA)

We do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is no "Do Not Sell or Share My Personal Information" signal to honour, we already don't. You have the right to know what personal information we collect, how we use it, to whom we disclose it, to delete it, to correct it, to limit our use of sensitive personal information, and not to be discriminated against for exercising these rights. Sensitive personal information we process includes your account login credentials (for the Friends sign-in) and, with your consent, your approximate location (Wi-Fi SSID). We use sensitive personal information only to provide the features you've asked for; you may direct us to limit our use to those purposes at any time by emailing us.

Brazil (LGPD), Canada (PIPEDA), and other jurisdictions

Residents of Brazil, Canada, and other jurisdictions with equivalent laws (South Africa POPIA, Australia Privacy Act, India DPDP Act, etc.) have analogous rights. Use the same contact email to exercise them.

Children and minors

Fluid Friction is not directed at children under 13 and is not designed as a children's app for the purposes of the Google Play Families policy or the US Children's Online Privacy Protection Act (COPPA). You must be at least 13 years old to use the app (16 in countries where the GDPR requires a higher digital-consent age without parental consent).

During onboarding, signing in to the Friends social layer requires you to confirm you meet the age requirement. If you are under 18, you confirm you have your parent or guardian's permission to sign in.

We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, email us at [email protected] and we will delete the account and all associated data.

If you use the PIN lock as a parental / accountability lock on behalf of a minor in your care, you remain responsible for the minor's use of the device and for obtaining any consents required under your local law.

Security

  • In transit. All network traffic between the app and Google Firebase is encrypted with TLS 1.2 or higher.
  • At rest. Firestore, Firebase Auth, Crashlytics, and Play Billing data are encrypted at rest by Google.
  • On-device. Your Fluid Lock PIN is never stored as plain text, only as a PBKDF2-HMAC-SHA256 hash with a random per-device salt, stored inside Android's EncryptedSharedPreferences (AES-256 GCM). Settings are stored in SharedPreferences and the Room database; you can clear them at any time via Android Settings → Apps → Fluid Friction → Storage.
  • Integrity. Firebase App Check with Play Integrity protects the backend from untampered-client attacks.
  • Minimisation. We sanitise accessibility event data before any log or crash report leaves the device.

No system is perfectly secure. If you suspect your account has been compromised, email [email protected] and we'll investigate.

International data transfers

Firebase Authentication runs exclusively in Google's United States data centres. Other Firebase services (Firestore, AI Logic, Crashlytics, Analytics) may process data in any Google Cloud region. If you are in the EEA, the UK, or Switzerland, Google's Standard Contractual Clauses provide the legal basis for the transfer. You can review Google's full transfer mechanisms at firebase.google.com/support/privacy.

The fluidfriction.app website

This website uses Google Analytics 4 to measure aggregate visitor counts and which pages are popular. Google Analytics sets first-party cookies on your browser and reports IP-derived coarse geolocation back to us in aggregate form only. We have not enabled Google Signals or ad-personalisation features, and we have not connected Analytics to any ad account.

The website does not sell data, does not embed third-party advertising pixels, and does not share visitor data with social networks. If you are in the EEA or the UK and want to opt out of Google Analytics, you can use Google's opt-out browser add-on or block the site's scripts in your browser.

Links to third parties

Fluid Friction and this website link to external services including Google Play, Instagram, and Google's own privacy documentation. Once you follow an external link we have no control over the data the third party collects; please read their privacy notices.

Changes to this policy

We may update this policy to reflect new features, new legal obligations, or new service providers. When we make a material change, we'll update the "Last updated" date at the top and, for Friends users, we'll surface an in-app notice on next launch. Continued use of Fluid Friction after the effective date means you accept the updated policy.

Contact

Privacy questions, rights requests, or complaints: [email protected]. We aim to respond within 30 days.

Developer of record: Manfred Mjengwa, trading as Fluid Friction. If you would like a postal address for a formal legal notice, request it by email and we will provide it.