Privacy
How LocknDial handles your data.
Effective: 26 April 2026
Controller
AllBlazing B.V. ("AllBlazing", "we", "us") is the data controller for LocknDial.
Scope
This privacy notice applies to the LocknDial iOS app, including sign-in, goals and plans, notes and drafts, habit progress, optional integrations, and support.
Data we process
- Account: email, authentication identifiers from your sign-in provider, and optional display name used on features such as the leaderboard.
- Content you create: text you enter in the app, drafts, post history, strategy and plan fields, and related timestamps.
- Progress and settings: challenge dates, daily habit grid state, reminders, and URLs you submit when the app offers optional posting verification.
- Optional integrations: GitHub (connection and commit-activity signals for the habit grid), Apple Health (workout duration to count "exercise" toward the grid, when you allow access), and any optional social or messaging links you enable in Settings. If WhatsApp capture is available in your build, the phone number and messages you send through that flow.
- Device and service reliability: app version, coarse diagnostics, and error information needed to run and protect the service.
What we do not do
LocknDial does not embed third-party "AI" features that send your content to a model provider. Processing uses your own inputs and, where applicable, the infrastructure of our data processors (for example cloud hosting and authentication) under a contract, not for training public AI models.
Purchases (if shown in the app)
- If in-app purchases are available: If in-app purchases are available, payment card details are processed only by Apple. We may receive product identifiers, entitlement status, and transaction metadata from Apple to unlock features - never your full card number.
- If the app is free with no IAP: The app is free to download and use as offered. We do not process purchase data in-app at this time.
Data minimisation
We process data needed to run the app, keep accounts secure, and meet legal duties. You can turn off optional integrations in Settings when supported.
Purposes and legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)): operating your account, storing your content, and delivering features you use.
- Legitimate interests (Art. 6(1)(f)): security, abuse prevention, improving reliability, and support - balanced against your rights.
- Consent (Art. 6(1)(a)): optional Health access and other integrations that require a permission prompt.
- Legal obligation (Art. 6(1)(c)): where the law requires records or reporting.
Automation
The app calculates scores, streaks, and progress from your actions (for example posting targets). This is not "profiling" in the high-risk sense: it does not produce legal or similarly significant effects on you.
Processors and sharing
We use service providers (for example for authentication and cloud data storage) under written terms that require appropriate security and, where they process personal data on our instructions, a processing agreement. We do not sell your personal data.
If data is stored or processed outside the EEA, we use safeguards such as the EU Standard Contractual Clauses or other mechanisms permitted by GDPR.
Retention
We keep data only as long as needed for the purposes above or to meet legal, tax, or security requirements. You can request deletion or exercise rights below, subject to law.
Your rights (EU/EEA/UK)
You may have the right to access, rectify, erase, restrict processing, data portability, and object, depending on the situation.
You may contact us at hello@lockndial.com. You may complain to a supervisory authority; in the Netherlands the Autoriteit Persoonsgegevens (ap.nl).
The EU's online dispute platform for consumers is at https://ec.europa.eu/odr (informational; you remain free to choose another competent process where the law allows).
Age and children
Under Dutch law, the GDPR's age for valid consent to information society services is set to 16. LocknDial is not aimed at children; we do not intend to process data of users under 16 without appropriate parental authority where the law requires it.
The general age of majority in the Netherlands is 18 for many contracts, but that does not replace the 16+ rule for this specific consent under national implementation of Art. 8 GDPR. If you believe we have data from a child, contact us.
Security
We apply technical and organisational measures appropriate to the risk. No online service is perfectly secure; use the app in line with your own device security (passcode, updates).
Breach handling
We will follow GDPR rules on personal data breach notification where they apply (authority and, in serious cases, individuals).
Changes
We may update this notice. This page will show a new effective date when we do.
Effective date
Effective: 26 April 2026.