Renura — Privacy Policy

Effective date: 30 August 2026 Last updated: 30 September 2026 Applies to: Renura for Android (com.renura.app), published by the Renura team. Published at: https://renura.co/privacy


The short version

Renura watches the rhythm of how you use your phone — how fast you scroll, how often you tap, how long you have been inside an app, how often you unlock — so it can notice when use has turned into autopilot and offer you a moment of choice.

It does not read what is on your screen. It does not read what you type. It has no internet permission, makes no network requests, contains no advertising, analytics or crash-reporting SDK, and sends nothing to us or to anyone else. Everything Renura senses is processed and stored on your device, encrypted, and you can erase all of it from inside the app.

We do not collect your data. There is no server to collect it to.


1. Who we are

Renura is an Android app that helps you notice compulsive phone use and step out of it. This policy explains exactly what the app accesses on your device, what it derives from that, what it keeps, and what happens to it.

Contact: privacy@renura.co Website: https://renura.co


2. The distinction this policy is built on

Renura draws a hard line between two different things:

Interaction signals — what Renura uses. The shape of your interaction: the magnitude of a scroll, the interval between taps, the number of characters that changed in a field, which app is in the foreground, when the screen was unlocked, how long a session has run, whether a notification arrived. These are measurements of motion and timing.

Content — what Renura never uses. The words on your screen, the text you type, the messages you read, the images you see, the pages you visit, the things you buy, the people you talk to. Renura does not read, capture, store or transmit any of this. It takes no screenshots and records no screen content.

Everything in this policy sits on the first side of that line.


3. What Renura accesses, and why

3.1 Accessibility service — AccessibilitySignalService

Renura runs an Android accessibility service. Renura is not an accessibility tool for people with disabilities, and the app declares isAccessibilityTool="false". It uses the Accessibility API because it is the only Android API that reports interaction rhythm as it happens; without it Renura cannot tell scrolling from reading, and its core feature does not work.

The service is subscribed to six event types and uses each of them:

EventWhat Renura takes from it
View scrolledScroll distance, normalized to "screens of content", and its timing
View clicked / long-clickedThat a tap happened, and when
View text changedThe number of characters that changed — never the characters
Window state changedWhich app package is in front
Window content changedThat the visible content changed
Windows changedWhether a keyboard is on screen, so Renura never interrupts typing

Alongside those measurements Renura reads the event's package name, the class name of the view, and the view's resource id (for example feed_recycler_view) so it can tell one scrolling surface from another. It does not read the text of any view, does not walk the view hierarchy for content, and does not capture the screen.

Password and secure fields are excluded before anything else happens. If an accessibility event is flagged as a password field, Renura discards it immediately — not even the character count is produced.

3.2 Usage access (PACKAGE_USAGE_STATS)

Renura polls Android's usage-event stream to learn when apps move to the foreground and background and when the device is unlocked. From this it derives session length per app, app-switch frequency, unlock frequency, and the delay between unlocking and opening an app. Renura reads app events, not app content.

3.3 Notification access — RenuraNotificationListenerService

Renura is notified when a notification is posted, updated or removed. It reads only structural metadata: the app's package name, the notification's system key, its channel id, its category (message, call, alarm…), and its importance or priority. It uses these to measure how often you are pulled back to your phone by alerts.

Renura never reads a notification's title, text, sender, images, actions or extras. This access is used only for timing and urgency. Notification access is required during first-run setup. If you revoke it later, the notification signal reads zero and the rest of the app continues.

3.4 Display over other apps (SYSTEM_ALERT_WINDOW)

Renura's check-in — an edge glow, then a full-screen moment with a Pause and a Continue — is drawn over the app you are in. That requires the "display over other apps" permission. It grants Renura no ability to read the app underneath; it only lets Renura draw on top of it.

3.5 Device motion sensors

Renura reads the accelerometer and gyroscope (no Android permission is required for these) and reduces them to one of three states: still, moving, or in transition. This tells Renura whether you are lying still with a phone or moving through the world, so a check-in does not arrive at a nonsensical moment. Raw sensor readings are not stored.

3.6 The list of apps on your device

Renura asks Android for the list of apps that have a launcher icon, so it can show you a picker for choosing which apps Renura should watch. It does not read anything else about those apps.

3.7 Notifications (POST_NOTIFICATIONS)

Renura posts a notification for exactly one reason: to tell you when protection has stopped working — for example because a permission was revoked, or because your phone's battery manager silently killed the service. It is fingerprinted so that the same problem is reported once, and cleared as soon as it is fixed. No promotional or behavioral notification is ever sent.

3.8 Vibration (VIBRATE) and start-at-boot (RECEIVE_BOOT_COMPLETED)

Vibration provides the check-in's haptic. Start-at-boot lets Renura restore its own health check after the phone restarts or the app updates — the two moments that otherwise leave protection silently dead.


4. What Renura stores

All of the following is stored only on your device, in Renura's private app storage, which other apps cannot read.

Encrypted at rest. Every behavioral artifact below is encrypted with AES-256-GCM under a non-exportable key held in the Android Keystore. The key never enters the app's memory space and never touches disk; on devices with a secure element it is held there.

WhatContents
Learned rhythm profileRolling averages and variances of your scroll speed, scroll acceleration, tap cadence, motion jitter, micro-idle gaps, app-switch rate, unlock rate and notification-recheck timing, plus long-term drift and recovery rates. Numbers only.
Check-in memoryOne record per check-in Renura showed: when it happened, which app it happened in and that app's name, how long the session had run, the engagement state, which named signals fired and how strongly, the sentence Renura displayed, and what you chose (Pause, Continue, or interrupted).
Quiet holds and settlesTimestamps only: when Renura got ready to speak and decided not to, and when your own usage settled on its own.
Adaptation statePer-app and per-hour adjustments learned from your Pause/Continue choices, and the baseline Renura measures you against.
Check-in cooldown stateWhen Renura last spoke, so it stays quiet afterwards.
Your settingsWhich apps you asked Renura to watch, which you marked as shopping apps, your sensitivity choice, quiet hours, sound and haptic preferences, and the fact that you accepted the disclosure.
Diagnostics journalThe last 60 lifecycle facts — service connected, service killed, engine started, engine stalled, crash reason. No behavioral data, no app names, no content.

Renura does not store raw accessibility events, notification content, screen content, text, screenshots, precise location, contacts, identifiers, or an advertising ID. Renura does not create or use any device or user identifier.


5. Where processing happens

Entirely on your device, in the app's own process. Every measurement, every inference, and every decision about whether to speak is computed locally.

Renura's Android package does not request the INTERNET permission. The app therefore cannot open a network connection, and there is no Renura server, account, login, sync or cloud component of any kind.


6. Sharing and transmission

Renura does not transmit your data, and does not share it with anyone.

The only moment Renura hands anything to another app is when you tap the privacy policy link, which opens this page in your browser.


7. Third-party software

Renura is built with these software libraries, all of which run entirely on your device and none of which collect or transmit data in Renura's configuration:

Renura contains no advertising SDK, no analytics SDK, no crash-reporting SDK, and no attribution or A/B-testing SDK.

For completeness: WorkManager contributes three permissions to Renura's installed manifest — WAKE_LOCK (to keep the CPU awake for the seconds the health check runs), ACCESS_NETWORK_STATE (to read whether the device has connectivity) and FOREGROUND_SERVICE (for a WorkManager component Renura never starts). None of them lets anything be sent anywhere: without the INTERNET permission, Android will not allow the app to open a network connection at all.


8. Retention

Renura keeps what it has learned for as long as the app is installed and you do not erase it. Several stores are self-limiting by design:

There is nothing to retain on our side, because nothing reaches us.


9. Erasing your data

Inside the app: Settings → Data → Reset learned profile, then confirm with a second tap. This erases the learned rhythm profile, every remembered check-in and its context, the quiet-hold and settle ledgers, the per-app and per-hour adaptation, the mediation baseline, and the check-in cooldown state. Your own configuration — the apps you chose to watch, your sensitivity, quiet hours — is your setup, not learned data, and is left alone; you can change it on the same screen at any time.

Uninstalling Renura deletes all of it, including your settings. Android removes the app's private storage, and the encryption key is destroyed with it.

Because nothing ever leaves the device, deleting it on the device is complete deletion. There is no copy anywhere else, and no request to make to us.


10. Backups and transferring to a new phone

Renura sets allowBackup="false", which switches off Android Auto Backup and adb backup for the app. It additionally excludes every behavioral artifact listed in section 4 from Android's device-to-device transfer, so what Renura learned about you does not follow you onto a new phone via "copy apps & data".

This is deliberate. A learned behavioral profile is a personal record; it stays on the device where it was formed.


11. Security

No security measure is absolute; if you have physical access to an unlocked device you have access to what is on it.


12. Children

Renura is not directed to children. It is intended for adults who want to change their own relationship with their phone, and it is rated accordingly on Google Play. We do not knowingly collect data from children — in fact we do not collect data from anyone, since nothing leaves the device.


13. Your rights

Privacy laws such as the GDPR and the CCPA/CPRA give you rights to access, correct, delete, and port your personal data, and to object to its processing.

Renura is built so those rights are exercised directly and immediately rather than through a request:

We are not able to fulfil an access or deletion request on your behalf, because we hold no copy of your data and have no way to identify you. If you have a question about any of this, write to privacy@renura.co.


14. Changes to this policy

If Renura's data practices change, this policy is updated before the change ships, and the "Last updated" date above changes with it. A change that would expand what Renura senses or where it goes will be presented in the app for your consent, not applied silently.


15. Contact

privacy@renura.co — privacy questions support@renura.co — everything else https://renura.co