Lockade — Privacy Policy
Effective date: 26 July 2026
Dekode (Pty) Ltd ("Dekode", "we", "us", or "our") operates the Lockade mobile application and the website at lockade.app (together, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, and the choices you have.
We are committed to protecting your privacy in accordance with the Protection of Personal Information Act, 2013 (POPIA) and other applicable data protection laws.
1. The short version
- Your medication names never leave your device. Which medications you take, their doses, and anything that could reveal a condition stay local, always. What our servers see is only adherence events: that a scheduled dose slot was logged or missed, and when.
- You choose an accountability buddy; they see your adherence, never your medications. A buddy you nominate can see your streaks, missed slots, and unlock requests — that visibility is the product. They cannot see what you take or why.
- We collect little, and we say so honestly. We use standard tools for sign-in, sync, analytics, and crash reporting (Firebase, PostHog, Sentry). We do not sell data and we show no ads.
2. Information We Collect
2.1 Account Information
When you sign in with Google or Apple, we receive the account details needed to create and identify your Lockade account — your name, email address, and profile photo where provided. Apple may provide your name and email only on the first successful sign-in. Your accountability buddy signs in the same way to use the buddy portal.
2.2 Medication Information (stays on your device)
You enter the medications you want to be reminded about, their schedules, and you record when you have taken a dose. Under POPIA this is health information, treated as special personal information.
Medication names, doses, and schedules are stored only on your device. They are never transmitted to our servers, never included in analytics or crash reports, and never visible to your buddy.
If you scan a medication package's barcode — when registering a medication or when using a barcode unlock — the barcode is read and checked on your device only. A barcode identifies a medication, so we treat it exactly like a medication name: it is never uploaded. Our servers learn at most that a barcode unlock was used, never which product was scanned.
2.3 Adherence Events (synced)
To power reminders across devices and the buddy features, we sync adherence events to our servers: which dose slot (for example "morning" or "20:00"), whether it was logged or missed, the timestamp, your current streak, and your unlock history — including which kind of unlock you used (for example a buddy grant or a barcode unlock), but never the content of one (never the barcode value or your answers to educational material). An adherence event does not identify any medication.
2.4 Accountability Buddy Data
If you nominate a buddy, we store the link between your account and theirs, pending buddy changes and when they take effect, unlock requests you initiate, and grants your buddy makes. See section 5 for exactly what your buddy can see.
2.5 Which Apps You Choose to Restrict
Lockade only restricts apps you select yourself.
- On iOS, app selection uses Apple's Screen Time framework (
FamilyControls). Apple returns only opaque tokens representing your choices — by design, Lockade never learns the names or identities of the apps you selected. Those tokens stay on your device. - On Android, Lockade reads the list of installed applications so it can show you a picker. This list is read locally to render that screen. Your selection stays on your device; it is not uploaded.
2.6 Foreground App Activity (Android only)
To cover a restricted app the moment you open it, Lockade uses an Android Accessibility Service. It observes only which application has come to the foreground.
Lockade does not read screen content. It does not read text you type, messages, passwords, form fields, or anything you view. It does not log your app usage history. The foreground app name is evaluated in the moment, used to decide whether to show the lock screen, and then discarded.
2.7 Usage & Analytics Data
We use PostHog to understand how the app is used — screens visited, features used, and performance metrics, associated with your account. We deliberately keep this minimal, and it never includes medication information (which the app cannot transmit) or the identities of apps you restrict.
2.8 Crash & Error Reports
We use Sentry to collect crash reports and error logs. These may include device model, operating system version, and stack traces. Crash reports help us identify and fix bugs.
2.9 Push Notification Tokens
If you enable push notifications, we store a Firebase Cloud Messaging (FCM) token linked to your account. This token is removed when you sign out.
3. How We Use Your Information
- Remind you when a dose is due, and restrict your chosen apps while a dose is overdue
- Maintain your streaks and your unlock history
- Deliver your unlock requests to your nominated buddy and apply their grants
- Show your buddy your adherence (section 5)
- Detect and prevent circumvention of the accountability features
- Analyse usage patterns to improve the app; diagnose and fix technical issues
- Communicate service updates or respond to support requests
4. Legal Basis for Processing (POPIA)
- Consent — You give explicit consent when you enter medication details (processed on-device), when you grant the Screen Time (iOS) or Accessibility (Android) permissions, and separately and explicitly when you nominate an accountability buddy, which is the act that authorises sharing your adherence data with that person. You can withdraw any of these at any time.
- Contract — Processing adherence events and buddy grants is necessary to provide the reminder, lockout, and accountability features you signed up for.
- Legitimate interest — We have a legitimate interest in preventing abuse of the unlock system, improving the app, and ensuring service reliability.
5. What Your Accountability Buddy Can See
Your buddy relationship is the heart of Lockade, so here is its exact shape:
- Your buddy sees: your display name, your adherence streaks, which dose slots you logged or missed and when, your unlock requests, and the unlocks they have granted you.
- Your buddy never sees: medication names, doses, schedules beyond slot times, any health condition, which apps you restrict, or anything you do on your device.
- Your buddy is notified only when you send them an unlock request. Lockade does not proactively tell your buddy about missed doses; anything else they learn, they learn by opening their dashboard themselves.
- You nominate your buddy yourself, and you can change or remove them at any time in the app. Changes take effect after a short cooling-off period (this is an anti-circumvention feature, and it also means a removed buddy retains visibility until the change takes effect).
- Sharing with a buddy is optional. Without one, Lockade works solo — the app's other unlock options are available to you directly.
6. Data Sharing
We do not sell your personal information. Beyond your nominated buddy (section 5), we share data only with service providers who process it on our behalf:
- Google Firebase — Authentication, database, cloud functions, and push notifications
- PostHog — Product analytics
- Sentry — Error and crash reporting
7. Device Permissions Explained
| Permission | Why Lockade needs it |
|---|---|
| Notifications | To deliver your dose reminders |
| Camera | Only to scan a medication package's barcode, on your device, at your request. No photos are stored and nothing from the camera is uploaded |
| Exact alarms (Android) | So reminders fire at the scheduled minute rather than being batched |
| Run after restart (Android) | To restore your reminder schedule after the device reboots |
| Query installed apps (Android) | To show you a list of apps to choose from when selecting what to restrict |
| Accessibility Service (Android) | To detect when a restricted app opens so it can be covered. Used only to read the foreground app name — never screen content |
| Screen Time / Family Controls (iOS) | To apply Apple's shield to the apps you selected |
Lockade's use of Screen Time and Accessibility APIs is entirely self-directed: you choose your own restrictions for your own device, and you choose your own buddy. Lockade is not a parental control product, is not an employee monitoring product, and is not device management software. A buddy cannot impose restrictions on you, add apps to your blocked list, or see your device — their only powers are viewing your adherence and granting you unlocks you asked for.
8. Data Retention and Deletion
- Medication information lives only on your device; uninstalling Lockade removes it.
- Account data, adherence events, and buddy links are retained while your account is active. If you delete your account, we remove your personal information from our systems within 30 days, except where law requires retention. Your former buddy's dashboard stops showing your data when the account is deleted.
- Aggregated, anonymised data (such as overall adherence rates) may be retained indefinitely for analytical purposes.
9. Data Security
We use industry-standard measures: encrypted connections (TLS), Firebase security rules, and server-side authentication. Unlock codes are single-use and short-lived. On your device, data is protected by the operating system's app sandbox. No method of electronic transmission or storage is 100% secure; we recommend keeping a device passcode enabled, and note that anyone with access to your unlocked device may be able to view your medication information in the app.
10. Your Rights
Under POPIA and applicable law, you have the right to access, correct, and delete your personal information, to object to processing based on legitimate interest, and to withdraw consent at any time — including withdrawing buddy sharing by removing your buddy in the app, and revoking Screen Time or Accessibility permissions in your device settings. You may lodge a complaint with the Information Regulator (South Africa).
To exercise any of these rights, contact us at privacy@lockade.app.
11. International Transfers
Our service providers (Google, PostHog, Sentry) may process data outside of South Africa. Where this occurs, we ensure appropriate safeguards are in place as required by POPIA Section 72.
12. Children
Lockade is intended for adults managing their own medication and is not directed at anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
13. Not Medical Advice
Lockade is a reminder and self-discipline tool. It does not provide medical advice, does not recommend medications, dosages, or schedules, and is not a medical device. Always follow the directions given by your doctor or pharmacist. Do not rely on Lockade as your only safeguard for medication that is critical to your health, and never change how you take a medication based on the app.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
15. Contact Us
- Email: privacy@lockade.app
- Entity: Dekode (Pty) Ltd, South Africa