Skip to content
ClearHour
How it worksEssentialsSafetyFAQ
Request Android beta access

ClearHour · Cerevio Technologies

ClearHour Privacy Policy

Last updated: August 30, 2026

Effective date: 30 August 2026

Account deletion

Account control

Delete your ClearHour account in the app through Settings → Account → Delete account, then complete the confirmation steps.

Request account deletion by email

What account deletion removes

Confirmed deletion removes the ClearHour account, authentication-provider mappings, Firebase Authentication user, active purchase-ownership claims, paid entitlements, upgrade offers, promotional authority, and account-linked promotional redemption-throttle records.

Limited retention and subscriptions

Some narrowly limited records may remain temporarily for security, fraud prevention, operational reliability, legal obligations, or provider backup deletion, as described in the retention section below. Deleting a ClearHour account does not cancel a Google Play subscription; subscriptions must be managed separately through Google Play.

1. Who we are and what this policy covers

ClearHour: Dumbphone OS ("ClearHour", Android application ID io.clearhour) is provided by Wei Zhang, a sole proprietor trading as Cerevio Technologies (Einzelunternehmen), with a business address at Gertrud-Grunow-Str. 20, 80807 Munich, Germany ("Cerevio Technologies", "we", "us", or "our"). ClearHour is intended for worldwide distribution to people aged 18 or older.

This policy explains how the ClearHour Android app accesses, uses, stores, transmits, shares, and deletes information. It does not govern Android, Google Play, phone manufacturers, Firebase, Google Cloud, WhatsApp, email providers, or other apps and services that have their own privacy policies.

This policy also covers the limited technical data processed to deliver the public ClearHour website at clearhour.cereviogroup.com.

For privacy questions or requests, contact support@cereviogroup.com.

2. Privacy at a glance

ClearHour is designed to work primarily on the user's phone.

  • ClearHour checks installed apps and selected system-package facts on the phone so it can show

launcher apps, recognize reviewed phone features, and apply the rules chosen by the user.

  • The installed-app inventory, app rules, schedules, Accessibility observations, Recovery records,

and Weekly Proof history are not uploaded or synchronized to a ClearHour account.

  • ClearHour does not read typed text, passwords, messages, notifications, screen contents, or the

contents of other apps through Accessibility.

  • ClearHour contains no advertising SDK and no remote analytics or crash-reporting SDK.
  • A ClearHour account is optional for Free use and is required only to purchase or restore paid

access.

  • ClearHour uses the internet for optional account and purchase operations, signed compatibility

information, and a narrowly scoped phone-function compatibility report that the user explicitly reviews and submits.

  • ClearHour does not sell personal or sensitive information.

3. Information ClearHour handles on the phone

3.1 Installed apps and phone features

ClearHour uses Android package visibility, including the QUERY_ALL_PACKAGES permission, to perform its core app-control function. It may access:

  • installed package identifiers, application labels, icons, versions, enabled state, and current

launcher entries;

  • for specifically reviewed phone and system features, component identity, signer or signing

lineage, installer and system provenance, exported/enabled state, Android roles or defaults, and the result of narrowly defined capability checks; and

  • limited migration history recording a package identity and installation generation, its former

ClearHour state, the reason for a change, and whether the user acknowledged that change.

When the first ClearHour welcome screen is visible, ClearHour may begin preparing this information in process memory. It does not use the prepared information to authorize app access, publish a user-facing catalog, or enforce rules until the user continues setup. The installed-app inventory and migration history remain on the phone and are not included in account, billing, support, advertising, analytics, crash-reporting, or compatibility-report payloads.

ClearHour does not treat every package containing an Android Activity as a user app. It identifies current enabled launcher apps, applies only reviewed phone-feature or hidden-system definitions, and otherwise keeps packages without a launcher hidden and allowed.

3.2 Accessibility and foreground-app evidence

If the user enables ClearHour's Accessibility service, ClearHour processes the current foreground package and window-class identity, event and elapsed times, service-connection state, and limited evidence needed to decide whether to display ClearHour's interruption screen and to verify that protection is operating.

ClearHour does not use Accessibility to read or store node text, typed text, passwords, messages, notifications, URLs, screenshots, or the contents of another app. Accessibility observations are not transmitted off the phone.

3.3 Rules, reliability, and proof information

ClearHour stores app-private information needed to operate the product, including:

  • the Clear Hour schedule, selected Utility Slots, Timed Access settings, quota and grants,

activation time, and optional Uninstall Protection choice;

  • permission and reliability evidence, such as notification status, battery-optimization status,

OEM startup confirmation, Accessibility health, interruption proof, and Device Administrator status;

  • Recovery Pass allowance, timestamps, and the reason entered by the user;
  • Weekly Proof events, including an event identifier and type, time evidence, process and boot

identity, relevant package identity, duration, and completeness or gap evidence;

  • signed compatibility-catalog revision and update information; and
  • local release diagnostics consisting only of a fixed diagnostic code and a coarse hour. These

diagnostics contain no stack trace, app/package identity, user text, or network upload.

3.4 Support preview and user-directed sharing

When the user opens Setup Support, ClearHour can build a temporary, editable preview containing the user's problem description, ClearHour permission-health results and issue codes, and device facts such as manufacturer, brand, model, device code, OEM and Android versions, security/update level, ClearHour version, build type, time zone, and timestamp.

This preview excludes the installed-app inventory, foreground-app history, ClearHour rules and schedules, notification content, URLs, screen contents, serial number, Android ID, device name, and stable advertising identifiers. ClearHour does not retain or send the preview automatically. The user must review it and choose to copy it or pass it to an email or messaging app.

The user may also choose to share selected Weekly Proof aggregates through Android's share sheet. The default share text excludes app/package names, exact event times, schedules, Recovery reasons, permission history, and account identity. The receiving app and the Android clipboard apply their own privacy and retention practices.

4. Information collected when an account is used

ClearHour Free works without an account. If the user chooses to purchase or restore paid access, ClearHour supports Google sign-in and passwordless verified email-link sign-in through Firebase Authentication.

For account operation, ClearHour and its service providers process:

  • a random internal ClearHour user identifier;
  • the Firebase Authentication subject and verified Google or email-link provider association;
  • the verified email address supplied by the authentication provider, which may be displayed in

the app;

  • for Google sign-in, profile information returned by Google and held by Firebase Authentication,

which may include a display name and profile-photo URL even though ClearHour does not use those fields for product decisions;

  • authentication and session-security information needed to verify, link, revoke, and delete the

account; and

  • minimal account creation, provider-linking, and deletion state.

Email is not used as the primary ClearHour database key, and ClearHour does not merge accounts merely because two providers report the same email address. Raw sign-in tokens and magic links are not logged by ClearHour.

ClearHour accounts do not upload or synchronize installed apps, rules, schedules, settings, Recovery records, Weekly Proof, Accessibility observations, or usage history.

5. Purchases and subscriptions

Purchases are processed by Google Play Billing under Google's terms and privacy policy. ClearHour does not receive or store the user's full payment-card or bank-account details.

To verify and restore paid access, the app sends an opaque Google Play purchase token to the ClearHour billing service together with an authenticated ClearHour session. The service verifies the purchase with Google Play and associates the verified product, base plan, subscription status, trial status where applicable, and entitlement with the random ClearHour user identifier. The raw purchase token is not logged; the service keeps a token-derived ownership record so that a purchase cannot be claimed by multiple ClearHour accounts.

Deleting a ClearHour account does not cancel a Google Play subscription. Subscriptions must be managed separately in Google Play.

6. Compatibility information and optional reports

6.1 Signed compatibility information

ClearHour may download a signed compatibility catalog from an HTTPS endpoint controlled by Cerevio Technologies. The catalog contains reviewed phone and system-component rules. The request exposes ordinary network metadata to the service, such as IP address, request time, and app user-agent. It does not include the phone's installed-app inventory or ClearHour rules.

6.2 User-submitted phone-function reports

If ClearHour may have blocked a basic phone function, the user may choose to create one technical compatibility report. Before submission, ClearHour shows a specific disclosure and asks the user to select the affected function and confirm submission. Reports are never created or sent merely because the user views an ordinary app, and they are never submitted automatically without this choice.

A submitted report may contain:

  • a random report identifier, consent time, and selected phone-function category;
  • ClearHour version and compatibility-catalog revision;
  • phone manufacturer, brand, model, Android API level, and build fingerprint;
  • the single affected app's label, package and component, version, system-app status,

enabled/exported/resolvable state, signer digests, and matching reviewed Android actions;

  • the relevant local recognition proof and ClearHour policy decision; and
  • a restricted transition containing only the affected component and, when available, its

immediately preceding system component.

The report does not contain the complete installed-app inventory, Accessibility text, screenshots, messages, notifications, URLs, typed text, ClearHour schedules, Recovery reasons, or Weekly Proof history.

When a report is received, a private operational alert may be sent to the ClearHour support team. That alert is limited to the report identifier, device model, affected package, function category, system-app flag, and a protected internal review link. It does not contain the raw report or its private deletion proof.

7. How we use information

We use information only as needed to:

  • provide the app-control, schedule, Timed Access, Recovery, Weekly Proof, local app search, and

permission-health features requested by the user;

  • recognize reviewed essential phone functions and keep package decisions accurate after installs,

updates, launcher changes, and removals;

  • authenticate accounts, prevent unsafe account merging, verify purchases, restore paid access,

and handle account deletion;

  • provide signed compatibility updates and investigate a compatibility report the user chose to

submit;

  • secure, maintain, troubleshoot, and defend ClearHour and its services; and
  • comply with applicable legal obligations.

ClearHour does not use installed-app or Accessibility information for advertising, marketing profiles, or sale to data brokers.

8. Service providers and disclosure

Depending on the features used, information may be processed by:

  • Google Firebase Authentication, for Google and passwordless email-link authentication;
  • Google Cloud services, for ClearHour's account, billing, compatibility, and support backend;
  • Google Play, for purchases, subscriptions, purchase verification, and entitlement status; and
  • Cloudflare, to deliver and protect the public ClearHour website. Cloudflare may process

ordinary request metadata such as IP address, request time, requested URL, user-agent information, and security information. The website does not use analytics, advertising trackers, or non-essential cookies in this implementation; and

  • an email, messaging, clipboard, or share-sheet destination selected by the user for an explicit

support or Weekly Proof share.

These providers process information under their own terms or under agreements with Cerevio Technologies, as applicable. We may also disclose information where required by applicable law, a valid legal process, or to protect users, ClearHour, Cerevio Technologies, or others from fraud, abuse, or security threats.

We do not sell personal or sensitive information and do not share it for cross-context behavioral advertising.

9. Retention

  • Installed-app evidence, ClearHour settings, permission/reliability state, Recovery records, and

non-authorizing migration history remain locally until replaced by current evidence, reset by the user, cleared through Android, or deleted when the app is uninstalled.

  • Weekly Proof events are retained locally for no more than 35 days and no more than 10,000 events.
  • Local release diagnostics retain no more than 50 distinct diagnostic-code/coarse-hour entries.
  • A compatibility report waiting to be sent remains on the phone until accepted by the service,

deleted by the user after a failed submission, Android app data is cleared, or ClearHour is uninstalled. A rejected report is shown as Not submitted and is not treated as received.

  • An accepted compatibility report is retained by Cerevio Technologies for no more than 90 days

unless the user requests earlier deletion from ClearHour Settings. The reporting phone stores a private deletion token and payload proof until deletion succeeds, app data is cleared, or ClearHour is uninstalled.

  • Account and verified-provider mappings are retained until the ClearHour account is deleted.
  • Billing purchase-ownership claims, entitlements, upgrade offers, and promotional authority are

removed from ClearHour's active datastore when confirmed account deletion completes.

  • Promotional-code redemption throttles are retained only until the end of their 15-minute rate-

limit window and are then removed through an active datastore expiry policy. They use a pseudonymous document key, and any throttle associated with an account is also removed during account deletion.

  • When an account that redeemed a promotional code is deleted, the code record is detached from the

internal user identifier. The resulting digest-based code record may be retained for no more than 180 days for campaign reconciliation and abuse prevention. It contains no email, raw code, or ClearHour user identifier and is removed through an active datastore expiry policy.

  • Promotional operator-audit records may be retained for no more than 180 days for security and

campaign accountability. They may identify the authorized operator but contain no app user's identifier or email, raw promotional code, or code digest, and are removed through an active datastore expiry policy.

  • Google Play real-time billing-delivery metadata used for deduplication and reliable entitlement

updates is retained for no more than 30 days through an active datastore expiry policy.

  • Ordinary application and request logs in the production Google Cloud project's default log

bucket are retained for 30 days. Google-required administrator and system audit logs are retained for 400 days. ClearHour does not intentionally log raw authentication, deletion, or purchase tokens.

  • The active Firestore database uses a European multi-region and has no configured backups or

point-in-time recovery. With point-in-time recovery disabled, historical database versions may remain available to the service provider for up to one hour after a write or deletion.

  • Firebase Authentication may retain sign-in security logs, including IP addresses, for a few

weeks. After Cerevio Technologies deletes a Firebase Authentication user, Google states that the associated authentication information is removed from live and backup systems within 180 days.

  • Privacy or support correspondence and the minimal case record needed to document the request and

response may be retained in a restricted mailbox for up to 24 months after the case is closed, then deleted unless a longer period is required for a legal claim or obligation.

  • We may retain a record longer only where required to comply with law, establish or defend legal

claims, or respond to fraud or security abuse. If that applies, access is restricted and the record is removed when the exception no longer applies.

Android cloud backup and device-to-device transfer are disabled for ClearHour app data.

10. Deletion and user choices

10.1 Delete local ClearHour data

Users can delete local ClearHour data by clearing ClearHour's storage in Android Settings or by uninstalling ClearHour. If optional Uninstall Protection is active, the user must first disable ClearHour as a Device Administrator through the authorized in-app flow and Android settings. Clearing storage removes local rules, schedules, Recovery records, permission confirmations, Weekly Proof, diagnostics, and locally pending compatibility reports. Android permissions and special access may need to be removed separately in Android settings.

10.2 Delete a compatibility report

A user can delete a failed, not-submitted report locally. For an accepted report, the reporting phone can request early remote deletion from Settings → Phone-function reports while its private deletion token is still available. Accepted reports are removed automatically after no more than 90 days even if that token has been lost by clearing app data or uninstalling.

10.3 Delete a ClearHour account

Users can request permanent account deletion in Settings → Account → Delete account or through the public account-deletion section. Deletion requires recent authentication and removes the ClearHour account, authentication-provider mappings, and Firebase Authentication user. It does not delete local settings from the phone and does not cancel a Google Play subscription.

During confirmed deletion, ClearHour deletes active purchase-ownership claims, entitlements, upgrade offers, promotional authority, and promotional redemption throttles. Redeemed promotional code records are revoked and detached from the internal user identifier. The limited deidentified and operational-retention exceptions, including service-provider deletion periods, are described in Section 9.

11. Security

ClearHour stores local information in Android app-private storage protected by Android's application sandbox. Android backup and device transfer are disabled. Cleartext network traffic is disabled, and supported network operations use HTTPS. Compatibility catalogs are cryptographically verified before use. Authentication and deletion operations require verified sessions, and sensitive raw authentication, deletion, and purchase tokens are not intentionally logged.

We use access controls and service boundaries intended to restrict remote information to authorized operations and personnel. No storage or transmission method is completely secure. A compromised, rooted, ADB-authorized, or physically unlocked device may expose local information.

12. Legal bases and privacy rights

Where the EEA, United Kingdom, or another jurisdiction requiring a legal basis applies, we expect to rely on:

  • performance of a contract or steps requested by the user to provide accounts, purchases, and

paid entitlements;

  • the user's consent for optional compatibility-report submission and user-directed sharing;
  • legitimate interests in operating, securing, and improving compatibility of ClearHour, where

those interests are not overridden by the user's rights; and

  • compliance with legal obligations where required.

Depending on local law, users may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a competent data-protection authority. To exercise a right, contact support@cereviogroup.com. We may need to verify the requester's identity. Withdrawing consent does not affect processing already carried out lawfully. We aim to acknowledge privacy inquiries within seven business days. Applicable legal deadlines govern the complete response.

Users may also lodge a complaint with a competent supervisory authority. For Cerevio Technologies in Bavaria, this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

13. International processing

ClearHour's production Firestore database is configured in Google's eur3 European multi-region, and its account, billing, compatibility, and support services run in europe-west1 (Belgium). Firebase Authentication is operated by Google from the United States, and Google Cloud logging, support, security, and subprocessor operations may process information in other countries.

Where European data-protection law applies to a restricted international transfer, Cerevio Technologies relies on the safeguards in Google's Cloud Data Processing Addendum, including applicable Standard Contractual Clauses or another recognized transfer solution. Google Play and other user-selected apps may process information under their own privacy terms and transfer safeguards.

14. Children's privacy

ClearHour is intended only for people aged 18 or older. It is not a parental-control service, is not directed to children, and is not designed to monitor another person's device. Official Google Play distribution selects Ages 18 and over as the only target audience and enables Restrict Minor Access. We do not knowingly collect personal data from anyone under 18. Anyone who believes that a person under 18 has provided personal data to ClearHour may contact support@cereviogroup.com to request its deletion.

15. Changes to this policy

We may update this policy when ClearHour's features, service providers, or legal obligations change. We will update the date at the top of the policy and, where required, provide additional notice in the app or through the store listing before a material change takes effect.

16. Contact

ClearHour privacy contact and data controller

  • Controller: Wei Zhang, sole proprietor trading as Cerevio Technologies (Einzelunternehmen)
  • Address: Gertrud-Grunow-Str. 20, 80807 Munich, Germany
  • Email: support@cereviogroup.com
Account deletionContact support
ClearHour

Dumbphone Mode for Android

Privacy Policy· Delete Account· Imprint· Support