Privacy Policy
Privacy Policy for AmniShield & AmniHaze
Effective Date: August 20, 2026 · Version: 2.0 (Zero-Knowledge Ecosystem Architecture)
1. Executive Summary & Fundamental Principles
Welcome to AmniShield and AmniHaze (developed by Al-Haq Studio, "we," "our," "us"). We build digital wellness, focus, and content moderation tools founded upon an uncompromising architectural principle: Zero-Knowledge & 100% On-Device Processing.
Unlike conventional monitoring or parental control software, AmniShield does not operate remote surveillance servers, does not inspect your browsing history on external clouds, and does not capture, store, or transmit your private screen frames.
Our Core Privacy Guarantees:
- 100% Local AI Vision Inference: All real-time visual moderation (LiteRT neural networks on Android, TensorFlow.js WASM in browser extensions) executes locally on your device's CPU/NPU/GPU. Zero pixels or camera frames are ever sent to the cloud.
- Zero Browsing History Telemetry: URL inspections and keyword detections occur strictly inside your local device memory. We never record, profile, or monetize your web traffic.
- Offline-First Cryptographic Licensing: Pro Supporter passes utilize offline NIST P-256 ECDSA digital signature verification (`SHA256withECDSA`). You can activate and use your license key completely disconnected from the internet.
- Ephemeral Device Pairing: Multi-device pairing uses random 6-digit PINs with an automatic 10-minute time-to-live (TTL), preventing unauthorized device association.
2. Information We Process & How It Is Handled
a. Data Processed Strictly On-Device (Never Leaves Your Hardware)
- Screen & Frame Buffer Analysis (AmniHaze / AmnGaze): Uses Android's
MediaProjectionAPI to detect sensitive visual regions (nudity, explicit content) and applies real-time Gaussian blur/mosaic overlays. Bitmaps are recycled in volatile memory and immediately discarded. - Active Package & Address Bar Inspection (AmniShield): Uses Android's
AccessibilityServiceAPI to inspect active app package names and browser address bars against local 50,000+ domain databases and user-defined blocklists. - Application Screen Time & Quotas: Uses Android's
UsageStatsManagerAPI to calculate daily app launch limits and Focus Mode timers. Data is stored in your private local SQLite/Room database. - Custom Keywords & App Blocklists: Your personal lists of restricted apps, words, and websites reside exclusively in encrypted local DataStore preferences on your device.
b. Data Managed Securely via Cloud Services (When Opted-In)
If you choose to create an account, synchronize family policies, or purchase a Pro Supporter Pass, the following minimal data is processed:
- Account Identifier & Authentication: Your email address is used for passwordless 6-digit OTP verification. Authentication is managed via Supabase Auth with industry-standard JWT encryption.
- Cloud Sync Policies (Optional): If you use Guardian / Admin Mode to sync rules across family devices, your custom blocklists and schedule configurations are stored in PostgreSQL under strict Row Level Security (RLS) policies scoped exclusively to your authenticated user ID (
auth.uid() = owner_id). - Device Pairing Records: Device nickname, platform type (Android, Windows, Extension), online heartbeat status, and ephemeral pairing tokens. No browsing data or activity logs are included.
- Payment Processing (Stripe): Payments for Supporter Passes (Monthly $4.99, Annual $39.99, Lifetime $89.99) are processed directly by Stripe via PCI-DSS Level 1 certified checkout. We never receive, process, or store your credit card numbers or banking credentials.
- Transactional Emails (Resend): Account sign-in OTP codes and purchase receipt emails containing your signed ECDSA license key are delivered via Resend's secure email API.
3. Android System Permissions & Technical Justification
AmniShield requires specific Android platform permissions to enforce system-wide distraction and content protection without relying on battery-draining VPN tunnels or remote proxy servers:
Used in real time to detect foreground app launches, read on-screen text for keyword blocking, and detect browser URLs. All inspection happens in volatile memory and is instantly discarded without logging.
Allows the on-device LiteRT neural network to capture screen frames for visual content moderation and render dynamic blur overlays. Frames never leave your device RAM.
Measures daily screen time and enforces scheduled Focus Mode locks. Aggregated stats remain on your local storage.
Renders the peaceful lock screen and PIN verification modal over blocked applications and adult websites.
Optionally enabled in Guardian / Strict Mode to prevent unauthorized uninstallation without entering the master PIN. Does not provide access to personal data.
4. Third-Party Disclosures & Zero-Data-Monetization Policy
- We do NOT sell, rent, or trade your personal data.
- We do NOT integrate advertising SDKs, tracking pixels, or data broker analytics.
- F-Droid / FOSS Flavor Guarantee: Our open-source releases on F-Droid and GitHub are strictly free of proprietary Google Mobile Services (GMS) binaries and third-party trackers.
5. Data Retention, Portability & Deletion Rights
- Local Device Data: You can completely erase all local blocklists, statistics, and preferences at any time by clearing app data in Android Settings or uninstalling the app.
- Cloud Account Deletion: You can request full deletion of your Supabase cloud profile, synced policies, and registered devices directly from the Web Console or by contacting our team. All associated records are permanently purged within 30 days.
6. Security Safeguards
We employ multi-layered security measures to protect your account and data:
- NIST P-256 ECDSA Digital Signatures: Offline license keys are cryptographically signed using private keys with zero shared secret exposure.
- End-to-End Database RLS: Every table in our PostgreSQL database enforces Row Level Security ensuring no user can read or modify another user's policy.
- R8 / ProGuard Minification: Production binaries are obfuscated and hardened against tampering and reverse engineering.
7. Children's Privacy & Guardian Mode
AmniShield includes a dedicated Guardian / Parental Control Mode designed to assist parents in protecting minors from explicit content, addictive social feeds, and digital distractions. Guardian mode operates with transparent device pairing (via 6-digit PIN / QR code) and does not secretly record personal keystrokes, messages, or webcam feeds.
8. Contact & Privacy Officer
If you have any questions, suggestions, or data requests regarding this Privacy Policy, please contact our team:
- Email: support@alhaq.uk / contact@alhaq.uk
- Studio: Al-Haq Studio, United Kingdom • alhaq.uk
- Initiative: Al-Haq Initiative