Avert Privacy Policy
Last updated: 16 September 2026
Avert is a content filter for Android that blocks adult websites and apps on the device, published by Clearpoint Studios. This policy explains what the app reads, what stays on your phone, what leaves it and when, and how long anything is kept.
Contact: clearpointstudios@proton.me
The short version
Your rules, your activity list and your lock live in the app’s own storage on your phone. There is no account for any of it and no copy anywhere else. Avert sends no blocked address, no search term and no app name off the device, ever.
Until you open the partner card, Avert has no connection to any server of ours. The only traffic the filter itself produces is DNS lookups to Cloudflare’s family resolver, which is how the filter works.
There are no ads, no advertising identifiers, no ad networks and no analytics SDK in the app. We do not sell data and we do not share it with data brokers.
What the app reads, and what it does with it
Avert has three protection layers. Each one reads exactly what it needs and nothing more:
- DNS filter: a local VPN service on your phone intercepts name lookups. Lookups for blocked domains are answered on the device with a loopback address. Every other lookup is forwarded to Cloudflare’s family resolver (1.1.1.3 and 1.0.0.3). No page content, no app traffic and no other data goes through this tunnel, and nothing is proxied through a server of ours.
- Screen watcher: Android’s accessibility service lets Avert read the address bar and the search field of your browser, so it can block a page before it loads. It also notices when a blocked app comes to the foreground, and when a settings screen opens that would switch Avert off while your lock is armed. The address is classified on the device and then discarded. Avert does not read anything else on screen, does not record what you type, does not take screenshots, and never sends any of this off your phone.
- App guard: Avert checks which app is in the foreground against your block list. The list of installed apps is read to build that block list and stays on the device.
When a layer blocks something, the activity list on your phone records the category of the match, the source (which layer) and the time. The blocked address itself is stored only if you switch on “Show blocked addresses” in Profile, and then only on your own device.
What stays on your device
Stored in the app’s private storage, readable only by Avert:
- Your block rules, custom lists and the apps you chose to block
- The activity list
- The lock, its wait time, hard mode, and any change that is waiting to come due
- Your settings and the app lock, if you use it
Uninstalling the app removes all of it. You can also erase it from inside the app under Profile, Delete my data.
Cloudflare’s family resolver
Name lookups that are not blocked locally go to Cloudflare’s 1.1.1.1 for Families resolver, which filters adult content upstream as well. Cloudflare sees the domain names your phone looks up and your IP address, as any DNS resolver does. Cloudflare states that it does not sell this data and that query logs are limited. Its policy is at developers.cloudflare.com/1.1.1.1/privacy. Switching the DNS layer off stops these lookups.
The partner, and only if you connect one
The partner feature runs on a Supabase project we operate. Avert has no connection to it until you open the partner card on the Lock tab. That is the moment an anonymous account is created for your install.
From then on, the app sends your chosen name and six state signals: whether the filter is on, your protected time, the number of blocked attempts today, whether the lock is armed, your wait time, and whether hard mode is on. When you ask for a change that the partner has to approve, the request and the partner’s decision are stored as well. Never an address, a search term or an app name.
Your partner sees those signals and your requests. Disconnecting the partner and deleting your data remove these rows from the server.
Purchases
Avert Pro is sold through Google Play and handled by RevenueCat, which manages the subscription state. When the app starts, the RevenueCat SDK issues an anonymous app user identifier for your install and receives your entitlement status. Google handles the payment. We never see your payment details, your card or your billing address.
RevenueCat’s policy: revenuecat.com/privacy
Notifications
Local notifications (the filter running, a change coming due) are created on your phone and involve no server. Push notifications go through Firebase Cloud Messaging and exist only for two things: a partner’s decision, and a reply to a support conversation. Automatic initialisation is switched off, so Firebase issues an installation identifier and a token only after you have connected a partner or written to support. We store that token to deliver those two kinds of messages, and nothing else.
Feedback you send us
If you write to us through the in-app support, we receive the message you wrote, the app version, your device model and Android version, and your language. This is only sent when you press send. The app does not contact the support service before your first message. Tickets are removed on request, see below.
Invites
If you open the invite screen or use an invite code, our referral service receives your anonymous store identifier and a one way hash of your Android identifier, so a code cannot be redeemed repeatedly from the same device. The identifier itself is not stored. If you installed Avert through an invite link, Google Play passes us the referrer string from that link. Nothing in this carries a rule, an address or a line from your activity list.
Permissions and why they exist
- VPN service: the local DNS filter. The connection stays on your device and routes only name lookups.
- Accessibility service: the screen watcher, as described above. You enable it yourself in Android settings and can disable it there at any time.
- Device administrator: makes uninstalling Avert harder while your lock is armed. You can disable it in Android settings at any time. Avert never blocks that and has no device owner or provisioning role.
- Foreground service, special use: keeps the DNS filter running with a permanent notification while you want to be protected.
- Notifications: the filter status, changes coming due and, if you opt in, partner and support messages.
- Exact alarms: a scheduled change comes due at the moment you chose.
- Ignore battery optimisations: so Android does not stop the filter in the background. Asked for, never required.
- Biometrics: the optional app lock, verified on the device.
- Boot completed: restarting the filter and restoring scheduled changes after a restart.
- Internet: DNS lookups, purchases and, if you use them, partner, support and invites.
Legal basis and where data is processed
Where the GDPR applies, we process the partner data on the basis of your consent, given by opening the partner card, and to perform the service you asked for. Feedback and invite data are processed on the basis of your consent. Purchase state is processed to fulfil the contract.
Our Supabase project and the referral and feedback services run on infrastructure in the European Union and the United States. Where data reaches the United States, the transfer is covered by the standard contractual clauses of the respective providers.
Data retention
How long each kind of data is kept, and what ends the retention:
- Rules, activity list, lock and settings on your phone: kept until you delete them in the app or uninstall Avert. They are never copied to a server.
- Partner account, name, state signals, change requests and decisions: kept while the partner connection exists. Deleted immediately when you tap Delete my data in the app, and within 30 days of an email request.
- Push notification tokens: deleted when you delete your data, or when the token stops working.
- Support tickets and messages: kept while the conversation is open. Closed tickets are deleted no later than 12 months after the last message, or earlier on request.
- Invite records (your invite code, the hash of your device identifier): kept while the invite programme runs, deleted on request.
- Purchase state: RevenueCat keeps the anonymous app user identifier and entitlement status for as long as the subscription or lifetime purchase exists, according to its own policy. Google Play keeps the transaction under your Google account.
- DNS lookups at Cloudflare: governed by Cloudflare’s resolver policy linked above. We receive none of it.
- Server backups: database backups exist for disaster recovery only and are overwritten within 30 days, so deleted data disappears from them within that window.
Data deletion happens on the server itself, not by hiding records. The steps for deleting without the app are at avert-block.pages.dev/delete.
Your rights
You can delete your local data and, with it, your server data from inside the app under Profile, Delete my data. If you no longer have the app, the steps are at avert-block.pages.dev/delete. Under the GDPR you can also ask us for access, correction, deletion, restriction, portability, and you can object to processing. Write to clearpointstudios@proton.me and we will answer. You can complain to your local data protection authority.
Children
Avert is intended for adults and is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has sent us data, write to us and we will delete it.
Changes
If this policy changes, the date at the top changes with it, and material changes will be pointed out in the app.
Contact
Clearpoint Studios
clearpointstudios@proton.me