Privacy
Last updated: July 4, 2026
Overview
The Judge is a screen-time application. Most enforcement data stays on your device. Information leaves your device when you submit an appeal, verify a Google Play purchase or app installation, or when basic analytics events are recorded.
Information kept on your device
- Screen-time limits, remaining balances, reset schedules, selected limited or blocked apps, and granted time.
- Your guardian code, guardian instructions, representation settings, Judge selection, and recent chat history.
- Foreground-app activity used to determine whether a selected app is open. The Judge does not upload a continuous history of every app you use.
Guardian credentials and enforcement preferences are excluded from Android cloud backup and device-to-device transfer. Clearing the app's storage or uninstalling it removes this local information.
Appeals and Judge responses
When you submit an appeal, the app sends the following to The Judge server over HTTPS:
- Your appeal message and recent conversation turns.
- Relevant screen-time balances, the current appeal-target app, selected limited apps, local time, recent granted appeals, guardian instructions, and selected Judge personality.
- A random app-installation identifier and a Google Play Integrity token used for security and rate limiting.
The server sends the appeal and relevant case context to OpenAI to generate a ruling. It does not send your guardian code, purchase token, Play Integrity token, or installation identifier to OpenAI. Appeal text and Judge responses are processed for the request but are not written to The Judge's operational logs.
Purchases and app integrity
- For paid Judges, the product ID and Google Play purchase token are sent to The Judge server and verified with Google Play.
- The server stores a one-way SHA-256 hash of a verified purchase token to prevent reuse. It does not store the raw token.
- Google Play Integrity provides app-recognition, licensing, and device-integrity signals so the server can reject modified, sideloaded, or untrusted installations.
Analytics
Firebase Analytics may record events such as opening the app or chat, submitting an appeal, and accepting or declining an offer. Offer analytics may include grant type, duration, and number of affected apps. Analytics events do not contain appeal text, guardian instructions, guardian codes, chat history, purchase tokens, or Integrity tokens. Google may process device and app identifiers as part of Firebase Analytics.
Service providers
- OpenAI processes appeal content to generate Judge responses.
- Google processes billing, Play Integrity, and Firebase Analytics information.
- Hosting and network providers process encrypted requests and limited operational metadata needed to run the service.
Information is not sold and is not used by The Judge for targeted advertising.
Retention and security
- Operational server logs contain request IDs, timing, decision type, grant metadata, and error categories, not appeal content. They are retained for no more than 14 days and limited to 100 MB on the production server.
- Hashed purchase-token records are retained to restore purchases and prevent token reuse while the service operates.
- Provider retention is governed by the applicable OpenAI, Google Play, and Firebase terms and data controls.
- Information is encrypted in transit using HTTPS.
Permissions
- Usage access identifies when a selected app is in the foreground so its time can be counted.
- Overlay access displays the blocking screen when time expires.
- Notifications keep the foreground tracking service visible.
- Boot access restarts tracking after the phone restarts or the app is updated.
- Internet access supports appeals, purchases, app-integrity verification, updates, and analytics.
Deletion and contact
Clear The Judge's app storage or uninstall the app to remove local data. The Judge does not require an account. To ask a privacy question or request deletion of identifiable off-device support information, email support@thejudgescreentime.com. We may ask for information needed to locate the relevant record. Appeal content is not stored in The Judge's operational logs.