Deutsche Version
Privacy Policy – WSD (“What Should I Do”)
Last updated: August 31, 2026
1. Controller
Ragnar Konrand Michaelson Weisbach
Zeitzerstraße 22
07743 Jena, Germany
E-mail: wsd.app.support@gmail.com
2. Core principle: your data stays on your device
WSD is deliberately built without user accounts and works local-first:
everything you create in the app — tasks, habits, check-ins (e.g. your energy level),
reflections/journal entries, settings, and the list of “distracting apps” you selected — is stored
only locally on your device. We do not collect, transmit, sell, or share this data.
The app shows no ads and contains no advertising or marketing trackers.
This also covers, in particular: your to-do list, your task reminders, your blocking settings
(daily limit, per-app limits, sleep phase), your gem balance, and the names you type or pick from your
contacts for tasks such as “Call {name}” (see section 3).
The app still contains a disabled area for optional user accounts and cloud sync.
It is unreachable in the published version: there is no sign-in, and your content is not transmitted
to any server.
The exceptions to this core principle — the cases in which data does leave your device — are
described in full in section 4 (voluntary feedback, crash reports, product analytics).
3. Use of device permissions (on-device only)
For its core feature (detecting distracting apps and nudging you towards a meaningful activity),
WSD uses the following Android permissions. All resulting data is processed exclusively on
your device and is never transmitted to us or to third parties:
- Usage access: WSD reads locally which app is in the foreground and how long apps
have been used, in order to enforce the screen-time limits you set yourself.
- List of installed apps: So you can choose which apps to block, WSD reads
locally which launchable apps are installed on the device (name and icon). This list is used only
to render that picker and never leaves your device; only the apps you selected are
stored.
- Accessibility API (optional): If you explicitly enable this feature, WSD uses
Android's accessibility API solely to detect the package name of the app currently in the
foreground, so it can reliably block apps you chose in real time. WSD does not read screen
content, input, or any personal data through this API — the only exceptions are the two
separately enabled beta features described below. Information obtained via the
accessibility API is neither stored (beyond the moment of detection) nor transmitted or shared with
third parties. You can disable this at any time in your system settings.
- “Block Instagram Reels only” (optional, experimental): If you separately turn
on this beta feature and consent to it, WSD additionally reads Instagram's on-screen content
via the accessibility API, only while Instagram is in the foreground, for the sole purpose
of recognizing whether the Reels screen is open so it can block it. No other app is read; the
content is evaluated transiently on your device and is never stored, transmitted, or
shared. This feature is off by default and can be turned off anytime in the app.
- “Block YouTube Shorts only” (optional, experimental): If you separately turn
on this beta feature and consent to it, WSD additionally reads YouTube's on-screen content
via the accessibility API, only while YouTube is in the foreground, for the sole purpose
of recognizing whether the Shorts screen is open so it can block it. No other app is read; the
content is evaluated transiently on your device and is never stored, transmitted, or
shared. This feature is off by default and can be turned off anytime in the app.
- Display over other apps (overlay): only to show the nudge overlay on your device.
- Camera (optional): Only when you start a task with camera verification
(e.g. “20 push-ups” via motion detection or “photograph grass” via image recognition) does WSD
access the camera. Analysis runs entirely on your device using models bundled
with the app (Google ML Kit plus Google MediaPipe with an included image classifier) — this needs
no internet connection and no capture is sent to any service. No images,
video, or camera content is stored, transmitted, or shared with us or third parties; the
camera runs only in the foreground during the check. If you deny the permission, you can instead
mark the task done manually.
- Contacts (optional): For tasks such as “Call {name}” or “Text {name}” you can
pick a person via your system's contact picker instead of typing the name. WSD evaluates
only the entry you picked and takes from it exclusively the
display name plus an internal reference to that contact (its “lookup key”) — so
you can later call or message that person with one tap from the task. Both are stored
only locally on your device. WSD does not read or store phone numbers,
e-mail addresses, photos, or any other contact details, does not scan your address book,
and transmits no contact data to us or third parties. The permission is
optional: if you deny it, only the picker button goes away — you can still enter
names manually. You can revoke it at any time in your Android settings.
- Notifications: for task reminders and the persistent notification of the
screen-time service.
4. Data that may leave your device
4.1 Voluntary feedback
If you actively submit feedback in the app, we transmit the content you entered (category, rating,
title, description), an optional screenshot you attach, and technical details (device model, Android
version, app version) by e-mail to our support inbox. Delivery is handled via
Google Apps Script / Gmail (Google Ireland Ltd.) as our processor. If you
voluntarily provide your e-mail address (e.g. to be contacted as a beta tester), it is transmitted
as well. Legal basis:
Art. 6(1)(a) GDPR (consent by actively submitting). We use feedback solely to improve the app and
delete it once no longer needed, at the latest 12 months after receipt. You may withdraw your consent
at any time with future effect and request deletion of your feedback by e-mail.
4.2 Crash reports (Firebase Crashlytics)
To detect and fix crashes and errors, WSD uses Firebase Crashlytics (Google Ireland
Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). On a crash or error, the following is
transmitted: crash stack trace, device information (model, OS version, memory state), app version,
and a Crashlytics-generated installation ID. No contents of your tasks, reflections, or your app
usage data are transmitted. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable app).
Google typically retains crash data for 90 days. Data may be transferred to the USA; Google is
certified under the EU-US Data Privacy Framework. More information:
firebase.google.com/support/privacy.
4.3 Product analytics (PostHog)
To understand which features are actually used and where flows break down, WSD uses the product
analytics tool PostHog. We deliberately use PostHog's EU instance
(eu.i.posthog.com), which is operated in Frankfurt am Main, Germany (AWS region
eu-central-1).
What is transmitted:
- Events about actions in the app — each with a fixed name and a limited set of
technical attributes (numbers, yes/no values, fixed identifiers). Examples: onboarding completed
(number of interests chosen, number of blocked apps, limit configured), task completed (task
identifier, type of verification, gems awarded), habit saved or deleted, to-do created or
completed, reminder set (yes/no), check-in submitted (number of questions answered), reflection
saved (mood selected), screen time purchased (pack size, gem price), blocking overlay shown
(trigger, whether skippable, which overlay variant, session length where applicable), feedback
submitted (type, rating, whether a screenshot was attached).
- Automatic technical attributes that the PostHog SDK adds to every event: app
version and build number, device manufacturer, device model and type, operating system and its
version, screen size and density, language setting, time zone, connection type or mobile carrier,
user agent, and the analytics library version.
- Automatic app lifecycle events from the SDK: install, update, opening and
backgrounding the app, screens changed within the app, and app links opened.
- A pseudonymous installation identifier — a random ID generated by the SDK and
stored locally in the app. It is not the Android advertising ID, contains no
name, no e-mail address and no manufacturer device identifier, and is not shared with other
services or apps. It only serves to group several events from one usage, and it is reset when you
uninstall the app or clear its data.
- Error events: if the app crashes or hits an unhandled error, PostHog also
receives the technical error report (error type, error message, stack trace) — in parallel to
section 4.2. These reports describe the program flow; they are not intended to contain
content you entered.
- IP address: for technical reasons PostHog receives the IP address of your
internet connection when an event is sent. We do not evaluate it and do not use it to identify
you; at most it serves a coarse country assignment.
Explicitly not transmitted: the text of your tasks, to-dos, notes, and
reflections; names or references from your contacts; screenshots, photos, or camera content; the
names or package names of the apps you block or open; your screen-time measurements; and advertising
IDs. WSD uses no session recording (no “session replay”, no screen capture), no
cross-app tracking, and passes nothing to advertising networks.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving and stabilizing
the app). In balancing interests we take into account that the data is pseudonymous, contains none of
the content you wrote, is not used for advertising, and is not combined with other sources.
Retention: we keep analytics data only as long as we need it to improve the product —
at most 12 months from collection.
International transfers: processing takes place in the EU (Germany). PostHog is a
US company; access from the US — e.g. by their support — cannot be entirely ruled out. PostHog relies
on the EU Standard Contractual Clauses (SCCs) for such transfers. More information:
posthog.com/privacy,
posthog.com/dpa, and
posthog.com/subprocessors.
Objection: you may object to this processing at any time (Art. 21 GDPR) — an
e-mail to wsd.app.support@gmail.com is enough, no
reason required. Independently of that, collection stops immediately when you uninstall the app;
clearing the app's data in Android settings additionally resets the installation identifier.
5. Recipients / processors
- Google Ireland Ltd. (Google Apps Script / Gmail) — only for voluntarily submitted feedback (delivery to our support inbox).
- Google Ireland Ltd. (Firebase Crashlytics) — only for crash reports.
- PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA —
product analytics and error reports, processed on the EU instance in Frankfurt am Main
(section 4.3).
No other personal data is shared. We do not sell data. Advertising networks and marketing service
providers receive no data from the app.
6. Your rights (Art. 15–21 GDPR)
You have the right to access, rectification, erasure, restriction of processing, data portability,
and to object to processing based on legitimate interests. You may withdraw any consent at any time
with future effect. Contact us at
wsd.app.support@gmail.com. You also have the right to
lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
You may object at any time, without giving reasons, to the product analytics (section 4.3) and
the crash reports (section 4.2) — both of which rest on a legitimate interest.
Note: since all app content is stored locally, you delete it completely by uninstalling the app or
clearing its data in Android settings.
7. Children
WSD is not directed at children under 16. We do not knowingly collect data from children.
8. Changes to this policy
We will update this privacy policy when the app or legal requirements change. The current version
is always available at this address and inside the app (Profile → Privacy Policy).