Privacy Policy
Privacy Policy
Version 2.0 — published 28 August 2026, effective 28 September 2026. It replaces the version dated 2 March 2026, which remains applicable until that date.
This document describes what Shortstop actually collects. It forms an integral part of the Terms of Service and Sale.
This policy is drafted in French. The French version is the authoritative one; this English text is provided for information.
1. Who is responsible for your data
Missyl, a French société par actions simplifiée with share capital of €100 Registered office: 35 avenue Jean Jaurès, 69780 Mions, France Company number (SIREN): 100 638 865 — RCS Lyon 100 638 865 — VAT: FR33 100638865 Legal representative: Paul Tuet, President
Contact for any question or request about your data: contact@missyl.fr
We have not appointed a data protection officer: we meet none of the criteria that would require one (Article 37 GDPR). Your requests are handled directly by the legal representative.
2. The principle: no account, and most things stay on your device
Shortstop does not ask you to create an account, or to provide your name or email address in order to work. We do not know who you are.
The blocking itself runs entirely on your device. To detect content to block, Android’s accessibility service gives Shortstop access to the on-screen structure of the monitored apps. That reading is local, immediate and not retained: it is used to decide whether to interrupt the display, then discarded.
We never receive the content of your screens — not your messages, not your photos, not the videos you watch, not the accounts you follow, not your social-network credentials. What leaves your device are events (“content was blocked on platform X at time Y”) and aggregate measurements, described in section 3.
That said, we do not claim to be anonymous. We generate a technical identifier tied to your installation, and data attached to that identifier is personal data under the GDPR. Section 5 sets out the detail.
3. What we collect, why, and on what basis
3.1 Data that stays on your device
Stored locally and never transmitted: your detailed blocking history over 14 days, your count of short-form minutes per platform over 60 days, your blocking preferences, schedules and scenarios.
You delete them by clearing the app’s data. Uninstalling alone does not guarantee they are gone: if Android’s automatic backup is enabled, they are restored on reinstall.
3.2 Usage data sent to our servers
| Data | Why | Legal basis |
|---|---|---|
| Blocking events: platform, surface type, timestamp | Measure whether the product works, detect blocking failures | Legitimate interest |
| In-app journey: screens viewed, buttons tapped, which onboarding and paywall variant was shown | Improve the product, compare two versions of a screen | Legitimate interest |
| Screen time: daily average on social networks, the three apps you spend most time in, and your peak time slot | Compute your score and show your progress | Legitimate interest |
| Onboarding questionnaire answers: sleep, feelings of guilt, loss of control, sense of addiction | Tailor onboarding and the goals offered | Legitimate interest |
| Device model, Android version, language, country, time zone | Run the app and diagnose issues | Legitimate interest |
| IP address | Inherent to any connection; security and abuse prevention | Legitimate interest |
The onboarding questionnaire is part of the setup flow and each answer is sent to us as soon as you select it; the flow currently has no button to skip it. You may object to this processing at any time by writing to contact@missyl.fr.
We have to be precise on one point. This data is not anonymous: it is attached to a persistent identifier. Taken together, it makes it possible to reconstruct, for a given device, which social networks are used and at what times of day. That is intimate information, and we treat it as such.
3.3 Purchase data
When you buy, Google Play takes the payment. We do not see your card number, your name or your billing address, and we have no access to them.
We do keep, on our servers: the Google Play order number, the purchase token, the product identifier, the amount and currency, the date, the subscription status, and your advertising identifier. That is what lets us restore your Premium access on a new device and run the programmes in section 3.5.
Legal basis: performance of the contract, and legal obligation for accounting retention.
Google Play also sends us real-time notifications about your subscription status (renewal, cancellation, refund, hold). We retain these.
3.4 Advertising, measurement and attribution
The app shows advertising to users of the free version, and we measure how well our acquisition campaigns perform. These are Shortstop’s most intrusive processing operations, and they rest on your consent.
They involve: your Google advertising identifier (GAID), ad-click identifiers (gclid,
gbraid, fbclid), a Meta identifier, and a set of technical characteristics of your device
(model, language, country, time zone, screen dimensions and density, CPU cores, storage) which
together constitute a device fingerprint.
We also transmit conversion events to our advertising partners: install, free-trial start, and purchase, including the amount actually paid and the currency.
Legal basis: your consent, collected at first launch through the Google UMP form. Section 9 explains how to give it, refuse it and withdraw it.
3.5 Refund programmes
| Programme | Data created |
|---|---|
| Referral | Your code, the link between your identifier and those of the people you refer, the order numbers concerned, progress status |
| Money-back guarantee | The refund made, the order number, your advertising identifier (to enforce single use), and the reason you select in the flow |
| Lifetime upgrade | The purchase, the refunded instalment, the order numbers |
Legal basis: performance of the contract (the rules are in the annexes to the Terms).
One clarification on referrals: a referrer sees the progress status of the people they referred, never their identity. Conversely, a referred friend does not know their referrer’s identity beyond what that person told them directly.
3.6 Email address — three cases, and only three
Your email address is never required to use Shortstop. We hold it only if you give it to us:
- Newsletter. You subscribe from within the app. We keep your address, proof of your consent (date, version of the text accepted) and the confirmation IP address. Double opt-in. One-click unsubscribe in every email. Legal basis: consent.
- Review programme. If you send us a screenshot of the review you left on the Play Store in order to receive the advertised reward, we receive your email address and that screenshot, in a dedicated mailbox that is read automatically. Legal basis: performance of the step you initiated.
- Interview invitation. If you accept, you are redirected to Cal.com to pick a slot; your details are then processed by that provider. Legal basis: consent.
3.7 Diagnostics and crash reports
If the app crashes, a technical report is sent to Firebase Crashlytics: stack trace, device model, Android version, app version, installation identifier. Legal basis: consent (collection is enabled together with section 3.4).
4. What we do not collect
We spell this out because the previous version of this document described collection that never took place.
- No geolocation. The app requests no location permission and does not use GPS. We infer a country from your IP address and your settings, nothing more.
- No banking data. No card number, no security code, no bank details. Everything is handled by Google Play.
- No account, no name, no password.
- No screen content. No messages, photos, videos or contacts, and nothing you post or view on social networks.
- No microphone, no camera, no address book, no SMS, no call logs.
- No remote notifications. The reminders you receive are generated locally by your device; we have no push notification channel.
- No special-category data within the meaning of Article 9 GDPR: no origin, opinions, religion, sexual orientation or health data. The onboarding questionnaire answers (section 3.2) concern your relationship with screens; we do not treat them as a diagnosis and they are not health data.
- We do not sell any data.
5. The identifiers we use
We do not identify you by name but through technical identifiers:
| Identifier | Origin | What it links |
|---|---|---|
| Tracking identifier | Randomly generated on your device at first launch | Your usage events, purchases, refund programmes |
| Onboarding identifier | Generated separately on your device | Your onboarding journey and the variant shown |
| Advertising identifier (GAID) | Provided by Android, resettable by you in Google settings | Advertising, attribution, and guarantee uniqueness |
| Our providers’ identifiers | Generated by RevenueCat, Firebase and Meta | Their respective processing |
Identifiers generated on your device are reset when you clear the app’s data (Android Settings → Apps → Shortstop → Storage → Clear data): the link with data already sent is then irreversibly broken, including for us.
Uninstalling alone is not enough, and we would rather say so. If Android’s automatic backup is enabled on your device, those identifiers — and your local statistics — are restored on reinstall, and the link picks up where it left off. Only clearing the data breaks it.
You can reset your advertising identifier at any time from Android Settings → Google → Ads.
6. Who your data is shared with
We neither sell nor rent your data. We entrust it to the following providers, and to them only:
| Recipient | Role | Country |
|---|---|---|
| Supabase Inc. | Hosting of our database and server functions | Data stored in Ireland (see section 7) |
| Cloudflare, Inc. | Traffic routing and protection | United States / global network |
| Netlify, Inc. | Hosting and delivery of the shortstop.app website | United States |
| Google Ireland Ltd / Google LLC | Play Billing, Play API, Firebase Analytics, Crashlytics, AdMob, Google Ads | Ireland / United States |
| Meta Platforms Ireland Ltd | Audience Network, SDK, Conversions API | Ireland / United States |
| Adjust GmbH | Attribution measurement | Germany |
| AppLovin Corporation | Ad mediation | United States |
| RevenueCat, Inc. | Subscription management | United States |
| Brevo (Sendinblue SAS) | Newsletter delivery | France |
| Cal.com, Inc. | Interview scheduling | United States |
We may also disclose data where the law requires it, or as part of a sale of our business — you would be informed.
One special case, which we prefer to name. For event data transmitted to Meta through its advertising tools, Meta and Missyl act as joint controllers within the meaning of Article 26 GDPR. Meta determines part of the purposes. You may exercise your rights against either of us.
7. Hosting and transfers outside the European Union
Our data is hosted in Ireland (European Union), with Supabase, on AWS infrastructure in
the eu-west-1 region. Backups are in the same region.
The previous version of this document stated that our servers were located in France. That was inaccurate, and we correct it here.
Two transfers outside the EU genuinely occur and we own them:
- Our server functions run close to the user. If you are in India, the United States or Australia, the code handling your request runs in that region, even though the data is then stored in Ireland.
- Several of our providers are established in the United States (section 6).
These transfers are governed by the European Commission’s standard contractual clauses, and by the EU–US Data Privacy Framework for providers certified under it.
8. How long we keep your data
| Category | Period |
|---|---|
| Usage and journey events (section 3.2) | 25 months |
| Advertising and attribution data (section 3.4) | 13 months |
| Purchase data — order number, amount, currency | 10 years (accounting obligation) |
| Purchase data — purchase token, advertising identifier | Duration of your access + 13 months |
| Referral | End of your participation + 12 months |
| Guarantee — refund register | No limit: this register is what ensures the right is used only once per person. Kept to the minimum necessary |
| Newsletter | Until you unsubscribe, then 3 years of inactivity |
| Review programme, interviews | 12 months |
| Crash reports | 90 days |
Transparency about where we stand. These periods are our policy and we commit to them. No automatic purge enforces them today: deletions are carried out manually, on our own initiative or on request, and the automated mechanism that will enforce this table is under development. We would rather write that than let you assume a purge that does not yet exist. The one exception is the crash-reports line, whose 90 days are enforced by Firebase Crashlytics.
9. Advertising consent: giving it, refusing it, withdrawing it
At first launch, a Google UMP form asks whether you accept personalised advertising and the associated measurement. It governs the processing in sections 3.4 and 3.7.
If you refuse, you keep using Shortstop in exactly the same way: blocking, statistics and purchases work identically. You will see non-personalised ads instead of personalised ones.
To change your mind, at any time and in either direction:
- Settings → Privacy & ads in the app: the form reopens and your new answer applies immediately;
- Reset your advertising identifier (section 5), which breaks the link between data already transmitted and your device;
- Write to us at contact@missyl.fr: we will pass your withdrawal on to our advertising partners.
Withdrawing your consent is as easy as giving it, and has no effect on how the app works.
Processing based on our legitimate interest (section 3.2) is not covered by that form. You may object to it at any time by writing to us.
10. Your rights, and how to actually exercise them
You have the rights of access, rectification, erasure, restriction, objection and portability, together with the right to withdraw your consent and to give directions about what happens to your data after your death.
Write to contact@missyl.fr. We reply within one month.
How we can find you
Since we do not know your identity, we need something to match on. Depending on your situation:
- You have made a purchase: give us your Google Play order number (it is on the receipt Google emailed you). It lets us find and delete the data attached to your tracking identifier: your usage events, purchases and refund programmes. Events tied to your onboarding identifier (section 5) carry a separately generated identifier that nothing links to your purchase.
- You are subscribed to the newsletter: your email address is enough.
- You have neither purchased nor given us your address: we hold no means of identifying you. Under Article 11 GDPR, we are not required to keep or obtain additional information for the sole purpose of identifying you, and the rights of access, rectification, erasure and portability cannot then be exercised. You do, however, retain a complete and immediate remedy: clearing the app’s data (Android Settings → Apps → Shortstop → Storage → Clear data) resets your identifiers, which permanently makes it impossible — for us and for anyone else — to link data already transmitted to your device. Note: uninstalling without first clearing the data does not have that effect — Android’s automatic backup restores your identifiers on reinstall.
We are working on displaying your tracking identifier in the app’s settings, so that you can give it to us and exercise your rights without having made a purchase.
Complaints
You may at any time lodge a complaint with the French data protection authority, the CNIL — www.cnil.fr — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
11. Minors
Shortstop is intended for people aged 15 and over (section 4.1 of the Terms). We do not ask for your age and have no way of verifying it.
If you hold parental responsibility and become aware that a child under 15 is using Shortstop, write to us at contact@missyl.fr: we delete the data we can attach to that child, within the limits of section 10 — we need a Google Play order number or an email address. Without something to match on, we have no way of identifying the data concerned; clearing the app’s data on the child’s device then breaks the link immediately and permanently.
12. Security, and what we do in the event of a breach
Exchanges with our servers are encrypted. Access to the database is restricted, and sensitive on-device data is stored in an encrypted area.
No system is invulnerable. If a data breach is likely to create a risk to your rights, we will notify the CNIL within 72 hours and, where the risk is high, we will inform the people concerned directly by the means available to us — an announcement in the app and on this site, since we do not have your email address. Every breach is recorded in an internal register, whether notifiable or not.
13. The shortstop.app website
The website uses audience measurement and campaign-tracking tools. It sets no third-party advertising cookie. Website data is processed separately from app data and kept for 25 months.
14. Changes
We may amend this policy. Any substantial change is published on shortstop.app and flagged in the app’s release notes at least thirty (30) days before it takes effect. The version in force is always the one published here, with its number and date.
15. Contact
Missyl — 35 avenue Jean Jaurès, 69780 Mions, France contact@missyl.fr