OVERSERVED

Legal

OverServed — Privacy Policy

Effective: July 27, 2026
Last updated: 2026-09-11
Contact: privacy@overserved.app

The short version #

This policy covers the Android app and the public website.

  • We do not sell your data. Ever. To anyone.
  • The Android app has no OverServed account, analytics SDK, ad network, or user-data backend.
  • The app does not remove or rewrite contacts and does not ship a contact-restore feature.
  • Spotter schedules local check-back reminders on this device. Buddy alerts and location delivery are not in this release.
  • The public homepage has no email signup form. Previously collected waitlist data remains subject to the controls below.
  • OverServed cannot detect drugs, and it is not a medical or safety-certification device. See “Spotter” below.

What stays on your device (never transmitted) #

Data that stays on your device
DataWhyWhere it lives
Selected contacts and phone numbers Local matching for protected-call redirection App-private storage on your phone; contact records are not changed
Text you enter into Slosh Check Generate a local typing-pattern advisory Handled inside the app; not uploaded to OverServed
Selected apps and current foreground app package Choose and locally enforce app blocking during an active session On your phone; not sent to OverServed
Arm-session state, reaction-gate results, and recorded session aggregates Run the local features and show Morning After aggregates App-private local storage
Spotter check-back session and reminder schedule Local reminders and the three-miss attempt to arm configured protection App-private local storage; not sent to OverServed

The Android app does not transmit this application data to OverServed. It has local Spotter reminders, but no buddy-delivery, location-delivery, billing, or account service.

Legacy waitlist and support data #

The public homepage links directly to Google Play and has no email signup form. This section covers earlier waitlist submissions and support messages, not a new homepage signup.

Legacy waitlist. If you previously joined the waitlist and consented to one availability email, the submitted data includes:

  • The normalized email address encrypted with AES-256-GCM, its encryption-key ID, consent version, and consent time.
  • A keyed one-way email token used to prevent duplicate rows when the separate rate-limit or encryption secrets rotate. We still treat this token as personal data.
  • A keyed one-way connection token and request count used for abuse control. It is valid for one ten-minute window, ignored after that window, and removed during later cleanup.

Cloudflare Pages and D1 host and process legacy waitlist data for us. The endpoint does not log submitted addresses or return them in browser messages, and D1 does not store the address as plaintext. For any retained legacy record, we keep the encrypted address until we send the single availability email, you ask us to remove it, or we retire the waitlist. There is no newsletter subscription.

Support email. If you email support or privacy, we receive the address and content you choose to send through our email provider. Do not send contact names, phone numbers, exports, passwords, or other unnecessary sensitive information.

This website uses no advertising, analytics, tracking pixels, or non-essential cookies.

Permissions, in plain language #

PermissionWhat we do with itWhat we never do
Contacts (read only) Let you select a number for local protected-call matching Never modify or upload your address book
Usage access See which app is in the foreground so we can show the Cut Off screen Never log your browsing or app history to a server
Display over other apps Let Android show OverServed's own Cut Off activity above an app you selected during an armed session Never read, record, or capture the selected app's screen
Call redirection Handle outgoing calls to locally selected numbers during a ready, active session Never listen to, record, or log call content
Notifications Show local session, Cut Off recovery, and readiness status while Android notification routes are enabled Never claim a remote alert was delivered or a drawer notice appeared after every route was disabled

Display over other apps is required for selected-app blocking because Android restricts an app from launching an activity while it is in the background. OverServed requests the user-controlled special access only as a readiness prerequisite for its own Cut Off activity during an explicitly armed session. You can revoke it in Android settings; OverServed must then report app blocking as degraded instead of claiming it remains active.

App blocking also requires app notification permission and the On duty and Cut Off alerts channels when you arm. If you later disable one, OverServed reports a degraded runtime/UI state and uses an enabled route for recovery when one exists. If you disable app notifications and both channels, Android cannot display a notification-drawer notice; opening OverServed still shows the degraded state.

The Android app does not request location or contact-write access. It is designed to exclude emergency, dialer, map, ride, and OverServed paths from local app blocking, but it is not an emergency service and cannot guarantee device or network availability.

Spotter — important limitations #

Spotter schedules local check-back reminders on this device. After three failed memory checks, it attempts to arm your configured protection. The current build does not contact a buddy, transmit location, or confirm reminder delivery.

Spotter cannot detect drugs. Nothing on a phone can. Silence from Spotter never means you are safe.

Android may delay or suppress reminders. Do not treat silence as safety. Spotter is not a safety guarantee, not a medical device, and not a substitute for emergency services. If you believe you are in danger, contact local emergency services.

Your rights and controls #

  • App data: use Android's standard app-data controls or uninstall the app to remove its local selections, settings, and history. The Android app has no OverServed account or server-side incident record.
  • Contacts: the current build does not mutate contacts and therefore has no restore feature. See contact safety guidance.
  • Legacy waitlist: email privacy@overserved.app from the address you previously submitted to request access to or removal of that row.
  • California (CCPA/CPRA): we do not sell or share personal information as those terms are defined.
  • EU/UK (GDPR): legacy waitlist processing is based on consent, which you may withdraw at any time. Contact privacy@overserved.app for access, correction, erasure, or other applicable rights. You may also contact your supervisory authority.

Age #

OverServed is for adults of legal drinking age. It is not directed to children and we do not knowingly collect data from anyone under 18.

Changes #

We will update the effective or last-updated date when this policy changes. Material changes will be presented where affected users can reasonably see them before they apply.

Contact #

privacy@overserved.app