Last updated: 2026-08-15
HandOff is an Android app that lets you hand your phone to someone (a child, a friend, a store clerk) while restricting what they can access. This policy explains what data the app touches and, more importantly, what it does not touch.
To enforce a Borrow Mode session, HandOff needs to read certain things locally on your phone. None of this leaves your device.
| Data | Why the app reads it | Where it goes |
|---|---|---|
| Usage Access (foreground app package name) | To detect when the guest opens an app that is not on the allowed list, so it can be blocked. | Held in memory only. Never written to disk, never sent anywhere. |
| Installed apps list | To show you the list of apps you can choose to allow during a Borrow Mode session. | Read on demand from the OS. Never written to disk, never sent. |
| Notification content (while Notification Access is on and “Hide Notifications” is enabled) | To cancel notifications from disallowed apps so the guest can’t see private previews. | Notifications are cancelled in place. Content is never stored or transmitted. |
| Incoming call events (while Call Screening is on and “Block Incoming Calls” is enabled) | To reject calls that aren’t from starred contacts during a session. | Only the reject action is taken. Nothing is stored or transmitted. |
| Your unlock PIN | To gate the “End Session” action so the guest can’t end Borrow Mode without your permission. | Stored hashed in the app’s private SharedPreferences on your device. Never sent anywhere. |
| Session configuration (profile, duration, allowed apps, restrictions) | To remember your Borrow Mode setup between sessions. | Stored in the app’s private SharedPreferences on your device. Never sent anywhere. |
PACKAGE_USAGE_STATS) — required to detect the
foreground app so disallowed apps can be blocked.SYSTEM_ALERT_WINDOW) — required to
render the block screen on top of a disallowed app and to render the
optional touch-lock overlay.POST_NOTIFICATIONS) — required to show the
persistent notification that lets you end a session or toggle touch
lock.QUERY_ALL_PACKAGES) — required to list your
installed apps in the picker so you can choose which to allow.HandOff uses no third-party services. There is no advertising SDK, no analytics SDK, no crash reporter, and no cloud sync.
HandOff is designed to be handed to children by their parents. The app itself does not collect any data from anyone, including children. If you are a parent using HandOff to hand your phone to a child, review Google Play’s family policies to make sure that any allowed apps you select are appropriate.
If this policy changes, the “Last updated” date at the top of this file will change. The current version is always available at:
https://github.com/ajaykumarmaurya/handoff-legal/blob/main/PRIVACY.md
For privacy questions, contact: ajay10790@gmail.com