1. What this document covers
This Privacy Policy explains how HOPPP! ("the app", "we", "us") handles information when you install and use it. It applies to the Android version distributed via Google Play. iOS, Desktop, and any future platforms will follow the same principles but may differ in the specific data flows described below.
The app is operated by kobar.co. You can reach us at privacy@kobar.co for anything in this document.
2. The short version
- What the blocker enforces — the apps and sites you sealed, the session deadline, the ledger of your attempts — stays on your device.
- The reason you type at the gate is sent from your device to Google's Gemini API to produce a ruling, along with your goal and the record it is being judged against. We do not proxy it and we do not keep a copy.
- Your case file (what you answered at intake) is mirrored to Google Cloud Firestore under your account, so it survives a reinstall.
- Analogue is public by design. An outing you host or join shows your first name to the other people at it. Your debrief is not shown to anyone.
- We run no servers of our own. Everything above is Google (Firebase) and RevenueCat, listed in section 5.
- No ads, no advertising SDKs, no tracking you across other apps, nothing sold to anyone — ever.
- You can delete everything at any time.
3. What data we collect
A. On-device data (not transmitted)The following is stored locally by the app and never leaves your phone:
- The session policy the blocker enforces: the apps and the website domains you sealed, and when the session ends.
- Your daily goal (the "one thing that would make today feel like it mattered").
- The event log the Record is built from: session starts and stops, each unlock request, the verdict, the app or domain, and the time. This is an append-only file on the device.
- Which gatekeeper you hired.
- A log of which device permissions you granted or declined, and when.
B. Sent to the AI provider to produce a rulingWhen you petition the gate, your device calls Google's Gemini API directly. The request contains:
- The reason you just typed.
- Your stated goal for the week, so the reason can be judged against it.
- The app or site you asked for, how many times you have asked today, and which turn of the petition you are on.
- The earlier reasons in this petition, and reasons already denied — a reworded excuse is meant to be recognised as one.
Google processes that request under its API terms and returns a ruling. The traffic does not pass through any server of ours, and neither the request nor the reply is stored anywhere but your own device's event log. If the call fails, the app rules offline instead, with the same rubric — no network, no ruling data leaving the phone at all.
C. AccountAccounts are handled by Firebase Authentication. The app creates an anonymous account during onboarding so your answers have somewhere to live, and upgrades it in place when you register. Depending on how you sign in, that means an email address, or the basic profile Google returns for Google Sign-In. Passwords are set and verified by Firebase; we never see or store one.
Your case file is mirrored to Cloud Firestore under that account: your objective, the habits you named at intake, your estimated screen hours and how many are for work, your age, occupation, who the app is for, your chosen gatekeeper, and your case number. Security rules restrict that document to your own account.
D. AnalogueBefore you can join an outing you supply a first name, an age, and a city. Analogue is closed to anyone under 16.
- Your identity record (name, age, city, and whether the city came from your device's location) is stored in Firestore and readable only by you.
- An outing you host or join is a shared document: its title, venue, city, day, time, number of spots, and the first names of the host and everyone who has taken a spot. Any signed-in user browsing the board can read it — that is what a board is for. Do not put anything in a title or venue you would not want a stranger to read.
- Your post-outing debrief — the vibe, the note, whether you'd meet again — is stored under your own account only. It is never shown to the group or to the other attendees. It exists to teach the matcher.
E. SubscriptionHOPPP! Unlimited is sold through Google Play and managed by RevenueCat, which records the purchase against your account id so it survives a reinstall. Google Play handles the payment; we never see your card.
F. Diagnostics and notificationsCrashes are reported through Firebase Crashlytics (stack traces and device model, no petition text). If you allow notifications, Firebase Cloud Messaging issues your device a push token.
3a. Device permissions, and what they can see
An app blocker has to watch the things it blocks. This is the part worth reading twice.
- Accessibility. To enforce a seal, the app reads which app is in the foreground and, in a browser, the address in the address bar. This happens entirely on your device, in memory, and is compared against the list you sealed. Addresses are not logged, not stored, and never transmitted. Your browsing history is not collected.
- Usage access. Also used to detect the app in the foreground. On-device only.
- Display over apps and full-screen alerts. Used to draw the gate on top of the app you tried to open.
- Notifications. The ongoing session notification, and the gate itself.
- Notification access. While a session runs, notifications from the apps you sealed are dismissed, so a sealed app can't tap you on the shoulder. The app checks only which app posted a notification — it does not read titles, message text, or any other content, and nothing about your notifications is stored or sent.
- Battery exemption. Stops Android's power manager from killing the blocker mid-session. Grants no access to data.
- Start at boot. A session you armed survives a restart instead of quietly ending.
- Approximate location. Asked for only when you verify for Analogue, and only to resolve a city name. The coordinates stay on the device; the city is what gets stored.
4. What we don't collect
- Your browsing history. The address bar is read to compare against your own blocklist and is discarded immediately.
- Precise location. Coarse location is used once, to name a city, and only if you ask it to.
- Your contacts, your messages, your photos, or the contents of any app you unlock.
- Advertising identifiers. The app contains no advertising or attribution SDKs.
- Your name or address, beyond the first name you choose to show on Analogue.
5. How we use your data, and who else touches it
The on-device data exists to make the blocker work and to build your Record. The request in 3.B exists only to produce that turn's ruling. The account data exists so your file survives a reinstall. Analogue data exists so three or four people can meet in a café.
We do not use any of it to train models, build advertising profiles, or sell to anyone. We run no servers of our own; these are the processors involved:
- Google — Firebase Authentication, Cloud Firestore, Cloud Messaging, Crashlytics. Accounts, your case file, Analogue outings and identity, push, crash reports.
- Google — Gemini API. Receives the petition described in 3.B and returns a ruling, under Google's API terms for paid services, which do not use the content to train its models.
- RevenueCat. Subscription entitlement status tied to your account id.
- Google Play. Distribution and payment.
- Law enforcement, if compelled by valid legal process. We have not received such a request to date.
6. Your rights
You have the right to:
- Access — request a copy of all data we hold about you.
- Delete — request permanent deletion of your account and all associated data. See our data deletion page.
- Export — receive your data in a portable format (JSON).
- Correct — update or correct inaccurate data.
- Withdraw consent — stop using the app and have your data deleted.
To exercise any of these rights, email privacy@kobar.co from the address associated with your account. We respond within 30 days.
7. Children's privacy
HOPPP! is not directed at children under 13, and we do not knowingly collect data from them. Analogue — the meetup half of the app — is closed to anyone under 16, the EU digital-consent floor; the app asks for an age and refuses below it. Age is self-declared today, which we say plainly rather than pretend otherwise; a third-party identity check is planned. If you believe a child under 13 has an account, or that someone under 16 has joined an outing, contact privacy@kobar.co and we will remove it.
8. International transfers
We operate no servers. Your data is processed on infrastructure run by the providers in section 5 — principally Google — in the United States and elsewhere, according to their own regional policies. Gemini API requests are processed by Google in the United States. For transfers out of the EEA, UK, and Switzerland we rely on those providers' Standard Contractual Clauses.
9. Security
On-device data is protected by your device's encryption (Android FBE). Credentials are handled entirely by Firebase Authentication — we never see or store a password. Access to your case file, your Analogue identity, and your debriefs is restricted to your own account by Firestore security rules; an outing document is deliberately readable by signed-in users browsing the board, and can only be edited by its host or by someone taking a spot. All traffic, including the AI request, is over HTTPS.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities within 72 hours as required by GDPR.
10. Changes to this policy
If we change this policy in a way that affects your rights, we will notify you in-app and ask for renewed consent where required. The "Last updated" date at the top of this document reflects the most recent revision. Earlier versions are available on request.
11. Contact
For privacy questions, data requests, or complaints:
- Email: privacy@kobar.co
- WhatsApp: +62 881-0808-81097
If you are in the EEA and believe we have not handled your complaint adequately, you have the right to lodge a complaint with your national data protection authority.
12. Legal basis (GDPR)
For users in the EEA, we process your data under the following legal bases:
- Contract — to deliver the service you installed.
- Consent — for the petition sent to the AI provider (you type it and submit it; that is consent for that turn), for Analogue identity and outing data, for approximate location, and for notifications.
- Legitimate interest — for crash reporting and security, balanced against your privacy.