LimitX Blocker Logo
Home About Features Pricing Contact Help Center Download
Follow Us
Email
hello@limitx.xyz
MENU
MENU
CLOSE
CLOSE
DOWNLOAD LimitX
Privacy Policy

Your privacy, handled with care.

Last updated: August 27, 2026

This Privacy Policy explains how LimitX collects, uses, stores, and shares information when you use the Service.

Privacy Policy

This Privacy Policy explains how LimitX ("LimitX", "we", "us", or "our") collects, uses, stores, and shares information when you use the LimitX Android app, LimitX Browse, the protection features, subscriptions and passes, the referral programme, the in-app assistance chat, and the LimitX parental/accountability dashboard (together, the "Service").

Developer/operator: LimitX (Downlabs). Android package: com.downlabs.limitx.release.

For privacy questions, data access requests, or account deletion, contact support@limitx.xyz.

1. What LimitX Does

LimitX is a digital wellbeing and self-control app. It blocks or limits apps you choose, filters adult content in browsers and apps, counts and limits short-form video (Reels, Shorts, TikTok), enforces focus sessions, and can share your protection activity with an accountability partner or parent that you link yourself.

To do this, LimitX reads what is on your screen while protection is enabled. Section 3 explains exactly what that means, what leaves your device, and what does not.

2. The Short Version

We collect an account identifier, device and app-usage information, records of blocked content, purchase status, and product analytics. We do not sell personal information. We do not use your screen content for advertising.

Three things are worth reading in full because people are often surprised by them: LimitX reads screen content through Android's Accessibility Service (Section 3); a record of blocked content includes the word that was matched and a short snippet of surrounding text (Section 4); and if you use the in-app assistance chat, your messages are sent to OpenAI to generate a reply (Section 8).

3. Accessibility Service — Prominent Disclosure

LimitX uses Android's AccessibilityService API. This is the only way an app can enforce blocking across other apps and browsers on Android, and it is powerful, so we describe it plainly.

What it can read. While enabled, the service receives the text and content descriptions of on-screen elements in the apps and browsers you have chosen to protect, plus the address bar of supported browsers. This includes text you type into those fields.

What we do with it. The text is compared, on your device, against the blocklists and your own keywords. It is used only to decide whether to block, warn, redirect, or count a short video.

What leaves your device. Screen content is not uploaded, streamed, or stored in bulk. No screenshots are taken. The only screen-derived data that leaves your device is a blocked-content record when a block actually occurs, described in Section 4.

What it is never used for. We do not use accessibility data for advertising, profiling, or sale, and we do not read apps you have not selected for protection except where a browser address bar is being checked for filtering.

You can turn the Accessibility Service off at any time in Android Settings → Accessibility. Protection stops working when you do.

4. Blocked-Content Records

When LimitX blocks or warns you, it records the event so your dashboard, streaks, and any accountability partner reflect reality. Each record contains: the keyword or site that matched, a short snippet of the surrounding text for context, the app package and name, where it was detected, the action taken, a device identifier, and the time.

The matched word and the context snippet describe something you searched for or viewed. Treat these as sensitive. They are stored under your account and are visible to you and to any accountability partner you have linked. They are not sold, not used for advertising, and not shared with anyone else except as described in Section 9.

If you do not want these records leaving your device, do not link an accountability partner and sign out; blocking continues to work locally, though streaks and dashboards will not sync.

5. Account and Authentication

Creating an account stores your email address, a Firebase-generated user ID, sign-in method (email/password or Google Sign-In), and account timestamps. Passwords are handled by Firebase Authentication and are never stored by us in readable form. If you set a Protection PIN, it is stored on your device only, salted and hashed, inside Android's encrypted preferences — we never receive it and cannot recover it for you.

6. Device, App, and Usage Information

We collect a device identifier and device model/OS information, app version, language, and country. We collect app-usage statistics (which apps, for how long), short-video counts, focus-session activity, streaks, and protection status. Some of this is computed and kept on the device; the parts that power your dashboard, streaks, and accountability features sync to our servers under your account.

For the referral programme we derive a one-way hash of your Android device ID. We use it to stop one device claiming the same reward repeatedly. It is not reversible to your device identity and is not used for tracking you across apps.

If you install LimitX from a referral link, the Google Play Install Referrer tells us which invite code brought you, so the referrer can be credited.

7. Purchases, Subscriptions, and Passes

Purchases are processed by Google Play Billing. We never receive or store your card, bank, or payment details. We receive and store the purchase token, product and plan identifiers, purchase and expiry times, and subscription state, so we can grant and revoke access correctly. The same applies to promotional pricing offered in the assistance chat, and to time-limited free passes, where we also store when a pass was granted and to which account and device, so the offer cannot be claimed repeatedly.

8. In-App Assistance Chat and AI Processing

If you open the in-app assistance chat, the messages you type are sent to OpenAI, which generates the replies. What is sent: your typed messages (each truncated to 500 characters), the recent conversation history for context, your chosen chat language and country, and the plan options we may offer you. What is not sent: your email address, your blocked-content records, your app-usage data, or any payment information.

Conversations are stored under your account so the session can continue and so we can review the quality of the feature. Do not type anything into the chat you would not want processed by a third-party AI provider, and never type card or bank details — no part of LimitX will ever ask for them, and all payment happens inside Google Play.

The chat is clearly labelled as using AI inside the app.

9. Accountability and Parental Dashboard

Linking is opt-in and requires a pairing code entered on the protected device. Once linked, the partner or parent can see your protection alerts, blocked-content records (including the matched keyword), device name, streaks, and last activity. They cannot read your messages, your browsing history beyond what a blocked-content record contains, or your account credentials.

You can unlink at any time from Linked accounts, which stops further sharing. Records already delivered to a linked account remain with that account.

10. Email and Notifications

If you have an account, we send service and lifecycle email — welcome, setup help, trial and billing notices, receipts, and occasional re-engagement or offer messages. Our email includes an invisible image and rewritten links so we can tell whether a message was opened and which link was clicked. We use this to stop sending mail people do not read, not to build a profile.

Every non-transactional message has a one-click unsubscribe. Billing and account notices are transactional and continue regardless, because they concern money and access.

Push notifications are delivered through Firebase Cloud Messaging and require a device token, which we store against your account. You can disable notifications in Android Settings at any time.

11. Analytics

We record product events — screens viewed, features enabled, purchase funnel steps, notification interactions — with your user ID, app version, platform, language, and country. We use Google Analytics for Firebase for install and uninstall measurement. These tell us which parts of the product work. We do not attach your screen content, blocked keywords, or message text to analytics events.

12. Web Filtering and SafeSearch

When adult-content filtering is on, LimitX inspects the address bar and page context of supported browsers on your device. If a search on a supported engine is not already filtered, LimitX may rewrite the address to add that engine's own SafeSearch parameter, which means the search is re-run in the engine's filtered mode. Your search terms are not sent to us in that process; only a blocked-content record is created if something is actually blocked.

13. How We Use Information

To operate blocking and filtering; to sync your dashboard, streaks and stats; to deliver accountability features you have enabled; to grant, restore, and revoke subscriptions and passes; to run the referral programme and prevent its abuse; to send service and lifecycle email and notifications; to provide the assistance chat; to detect fraud and abuse; to improve the product; and to comply with law.

14. When We Share Information

We do not sell personal information. We share only with the processors that make the Service work, each for the purpose named:

Google Firebase (authentication, database, cloud functions, messaging, analytics, crash reporting) — the primary infrastructure holding your account data. Google Play Billing — purchases and subscription state. OpenAI — assistance-chat messages, as described in Section 8. Our email provider — delivery of the messages described in Section 10. An accountability partner you link — as described in Section 9.

We may also disclose information where legally required, or to protect the rights, safety, and security of users and the Service.

Earlier versions of this policy referred to Supabase. LimitX no longer uses Supabase; account data is held in Google Firebase.

15. Permissions We Request

Accessibility Service — enforce blocking and count short videos (Section 3). Usage Access — measure app usage and enforce limits. Display over other apps — show the blocking and warning screens. Notifications — protection alerts and reminders. Device administrator (optional) — uninstall protection, so protection cannot be removed on impulse. Query installed apps — list apps so you can choose which to protect. Battery optimisation exemption — keep protection running in the background.

Every one of these can be revoked in Android Settings. Revoking a permission disables the feature that depends on it rather than the whole app.

16. Local Storage

Your blocklists, keywords, schedules, Protection PIN, and cached statistics are stored on your device. Sensitive local state, including the Protection PIN and app-blocker configuration, is kept in Android's encrypted preferences. Clearing app data or uninstalling erases local state, including the Protection PIN, which cannot be recovered.

17. Retention

Account data is kept while your account exists. Blocked-content records and activity history are kept so your dashboard and streaks remain meaningful, and are deleted with your account. Purchase and billing records are kept as long as needed for entitlement, refunds, tax, and dispute handling. Email delivery logs and suppression records are kept so we can honour unsubscribes and diagnose delivery. Assistance-chat sessions are kept under your account and deleted with it.

18. Your Choices, Access, and Deletion

You can turn off any protection feature, revoke any permission, unlink an accountability partner, unsubscribe from non-transactional email, and disable notifications, at any time.

Account and data deletion. To delete your LimitX account and the data associated with it, email support@limitx.xyz from the address on the account, or write to us from the app's support option. We will delete your account, blocked-content records, activity history, referral records, and assistance-chat sessions. We may retain purchase and billing records where law requires, and email suppression entries so an unsubscribe continues to be honoured. Deleting your account does not cancel a Google Play subscription — cancel that in Google Play, or it will continue to bill.

You may also request a copy of your data, correction of inaccurate data, or restriction of processing, using the same address. Depending on where you live you may have additional rights under laws such as the GDPR or CCPA, and you may complain to your local data protection authority.

19. Children and Family Use

LimitX is not directed to children under 13, and we do not knowingly collect their personal information. LimitX is frequently installed by a parent on a teenager's device; where that happens, the parent is responsible for consenting on the child's behalf where local law requires it, and for the accountability data they will receive. If you believe a child under 13 has created an account, contact us and we will delete it.

20. International Processing

LimitX is operated from Pakistan and uses infrastructure operated by Google and other providers whose servers may be located in the United States and elsewhere. Using the Service means your information may be transferred to and processed in countries other than your own, under safeguards appropriate to those transfers.

21. Security

Access to your data requires authentication, server-side rules restrict every read and write to the account that owns the data, and administrative functions are restricted to authorised operators. Sensitive local state is encrypted on the device. No system is perfectly secure, and we cannot guarantee absolute security.

22. Changes to This Privacy Policy

We update this policy when the product changes. The "Last updated" date shows when it was last revised. Material changes will be signalled in the app. Continuing to use the Service after a change means you accept the revised policy.

23. Contact

LimitX — support@limitx.xyz. For privacy requests, please write from the email address on your account so we can verify it is you.

LimitX Blocker Symbol
LimitX blocks adult content, NSFW sites, Reels, and distracting apps so your phone feels cleaner, calmer, and easier to control.
Home About Features Pricing Contact Download
Privacy Policy Terms Of Use
Get In Touch
hello@limitx.xyz
Follow Us
©2026 LimitX Blocker. All rights reserved.