DTX is developed and operated as a digital wellbeing product. References to "DTX," "we," "us," or "our" in this policy refer to the DTX development team and its associated services. Our products consist of two Android applications: DTX (installed on the device being managed) and DTX Partner (installed on an accountability partner's device).
DTX is an app and website blocker built around accountability. It is used by individuals managing their own focus and digital wellbeing, by students and schools enforcing distraction-free study time, by professionals protecting deep work, and by parents safeguarding a child's device. DTX can be used on its own or paired with an accountability partner who approves or denies requests to lift an active block.
We collect only the information needed to deliver the app blocking and partner accountability features that DTX provides.
When you create a DTX account we collect your email address and a securely hashed password via Firebase Authentication. You may optionally provide a display name. We do not collect payment information directly — any future subscription billing is handled by the Google Play billing system.
On the managed device, DTX reads Android's UsageStats API to determine which apps are in use. This allows the enforcement engine to detect when a blocked app is opened and display the block screen. Usage data is stored locally and, where you have enabled the "Share Activity Insights" feature, summarised statistics (total screen time, most-used apps by duration) are synced to your account in Firestore so your accountability partner can view them.
We store the apps, websites, presets, and schedules you configure — including block start times, durations, and status — so that blocks persist across device restarts and sync between DTX and DTX Partner.
When the device user submits an unblock request, the written reason they provide is stored in Firestore and delivered to the partner. Both the request text and the partner's decision (approved or denied) are retained as part of the block history.
We collect limited technical data to operate the service, including your Android version, device model, and Firebase Cloud Messaging token (used to deliver push notifications). We do not collect device identifiers such as IMEI, advertising ID, or phone number.
| Data Type | Purpose | Stored Where |
|---|---|---|
| Email address | Account authentication and identification | Firebase Authentication |
| Display name | Shown to accountability partners | Cloud Firestore |
| App usage statistics | Enforcement + optional partner insights | On-device (Room DB) + Firestore (if shared) |
| Block configurations | Enforcing and syncing active blocks | On-device (Room DB) + Cloud Firestore |
| Unblock request text | Partner review and approval workflow | Cloud Firestore |
| FCM push token | Delivering real-time notifications | Cloud Firestore |
| Device model / OS version | Compatibility and enforcement | Cloud Firestore |
DTX requires several elevated Android permissions to deliver tamper-proof blocking. Below is an explanation of each permission and why it is necessary.
| Permission | Why DTX needs it |
|---|---|
| Usage Stats Access | Detects when a blocked app is opened so the block screen can be shown immediately |
| Accessibility Service | Monitors the foreground app in real time and enforces blocks even when apps are launched from third-party launchers or shortcuts |
| Device Administrator | Prevents DTX from being uninstalled while a block is active. This is what makes blocking tamper-proof |
| Display Over Other Apps | Shows the block wall screen on top of any blocked app that is opened |
| Boot Completed | Restores active blocks after a phone restart so enforcement resumes automatically |
| Internet / Network State | Syncs block state, unblock requests, and notifications with Firestore and FCM |
| Foreground Service | Keeps the enforcement service running in the background — required for persistent blocking on modern Android |
DTX does not access your camera, microphone, contacts, call logs, SMS messages, location, or photos. We request only the minimum permissions required for our core functionality.
We do not use your data for advertising, behavioural profiling, or sale to third parties.
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
By design, your activity data — including unblock requests, block events, tamper alerts, and (if enabled) usage insights — is shared with the partner accounts you have explicitly connected. You control which partners are connected and can disconnect them at any time.
We use Google Firebase (a Google LLC service) to power authentication, data storage, and push notifications. Firebase processes data under Google's privacy terms. No other third-party analytics, advertising, or data broker services are integrated.
We may disclose information if required by law, regulation, or valid legal process, or to protect the safety of our users or the public.
DTX is built on Google Firebase infrastructure. The following Firebase services are used:
DTX is designed for use by adults, including parents and guardians who manage a child's device on their behalf.
Most DTX users are individuals managing their own focus and digital wellbeing, or organisations such as schools. Where DTX is used to manage a child's device, the account is created and owned by a parent or guardian. The child does not create their own account and does not independently provide personal information to us.
The usage statistics we collect from a managed device relate to app activity, not to the identity of any individual. This data is linked to the account owner and is only accessible by connected accountability partners.
We do not knowingly collect personal information directly from children under the age of 13 (or the applicable age of digital consent in your jurisdiction). If you believe that a child has independently provided us with personal data without parental consent, please contact us at privacy@digitalwellbeingtechnologies.com and we will delete it promptly.
Where DTX is used on a child's device, parents and guardians should be aware that unblock request text written on the managed device is transmitted to Firestore for partner review. This is a core feature of the product and applies to every user — it is the sole instance in which the person using a managed device submits text content to our service, always reviewed by a connected partner account.
We retain your data for as long as your account is active and as reasonably necessary to provide the service. Specifically:
When you delete your DTX account, we delete all associated personal data from our servers within 30 days, except where retention is required by law.
We take the security of your data seriously. All data in transit between DTX and our Firebase backend is encrypted using TLS. Data at rest in Cloud Firestore is encrypted by Google. We use Firebase Security Rules to ensure that each user can only read and write their own data, and that partners can only access data explicitly shared with them.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
Depending on your location, you may have the following rights regarding your personal data:
Residents of South Africa have rights under the Protection of Personal Information Act (POPIA). Residents of the United Kingdom have rights under the UK GDPR. Residents of Australia have rights under the Privacy Act 1988. Residents of the United States may have rights under applicable state privacy laws.
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
DTX is available in South Africa, the United Kingdom, the United States, and Australia. Your data is stored on Google Firebase infrastructure, which may process data in data centres outside your country of residence. Google maintains standard contractual clauses and data processing agreements that govern these transfers in compliance with applicable data protection law.
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you via the app or by email. Your continued use of DTX after a change is posted constitutes your acceptance of the updated policy.
We encourage you to review this page periodically to stay informed about how we protect your information.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:
DTX Privacy
Email: privacy@digitalwellbeingtechnologies.com
General enquiries: hello@digitalwellbeingtechnologies.com
We aim to respond to all privacy-related enquiries within 5 business days.