Back to the main site

Check us out

We’re asking you to hand a small company administrative control of your phone, on the strength of a website. That’s a lot to ask. So here is what we end up knowing about you, and what we can’t know however we might feel about it one day. Then what happens to the phone if we ever stop answering.

WHAT WE CAN’T SEE

We can’t read your phone

Start with what it doesn’t get us. Android makes an app ask permission before it can reach any of the things below, and ours asks for none of them. That list is on your own phone, under the app’s settings, and it’s worth looking at again after an update — an app with this much control can be replaced with a new version, so a claim you can check beats a promise you can’t. Your accountability partner sees less than we do, never more.

  • Your messages, your calls, your contacts. No keystrokes, no screenshots, no microphone.
  • Where you are, or where you’ve been. There is no location permission on it, coarse or fine.
  • Which pages you visit. Browsing is held to a list the two of you agree. The list decides what opens, and nothing reports back on what you did with it.
  • Your photographs, your camera, your files, your other accounts.
  • What you do inside an app once it’s open. Every app on the phone is a closed door to us, the approved ones included.
  • How long you spend on any of it. No hours, no counts, no streak to break. There is nothing here that could be shown back to you later as a number you ought to feel bad about, because we never collected it.
WHAT WE DO SEE

What we know about you

The lock needs two facts to work: what has arrived on the phone, and what the two of you have decided about it. So the phone sends a short note when something installs, and asks us what’s been agreed. The app can see the whole list of what’s on the handset — that’s how it notices a new one — and only the new arrivals are sent to us. Nothing else is gathered in the background.

  • Your email address, and your name if you typed one in. Your partner’s too, which they gave us themselves.
  • The name of an app, the moment it lands. What the store calls it, what it calls itself on your home screen, and the time it appeared.
  • Whether it’s one of the medical and emergency apps nobody is asked to justify — a glucose monitor, an NHS app, a domestic abuse helpline. That says something about your health by implication, which is why it has a section of its own in the privacy policy, and why your partner isn’t shown it.
  • Whether you’ve asked for something to be released, plus the reason you picked off the list and the note you typed if you wrote one. Your partner reads it. So do we, in the sense that it sits in a database we run.
  • A web address you’ve asked to have opened, and why you want it. The one you asked for, not the ones you’ve been to.
  • What the two of you decided, and when. Released, refused, released until this evening, handed back early.
  • Which handset this is, and where to send it an instruction. Two identifiers that say nothing about you beyond which phone we’re talking to. Instructions travel through Google’s push service, so Google can see that a message went to your phone and when, though not what was in it.
  • If you used the transition aid before the reset, the list of what was on the old phone. You asked for that one: it exists so you can sort years of accumulation on a proper screen rather than a 6-inch one, at the single moment it’s all still there.

We can tell that something called Instagram landed on the phone on Tuesday. We can’t tell whether you ever opened it, and there’s no code in the app that could find out.

That’s the phone’s side of it. There’s an account side too — signing in, and the one payment — which records the ordinary things a website records, including an IP address. The privacy policy has that in full, along with how long each of it is kept.

THE OTHER DIRECTION

What goes back to the phone

Messages travel the other way too, and they’re short. An app has been released, or refused, or released until this evening. This site can open now. Now and then, a new version of the app itself. And, once a release has run its course, the big one: hand the phone back.

Almost all of it starts with one of you. The exception is us: we can release a phone from our side, it’s rare, it’s written to a ledger we can’t edit, and your partner is told unless telling them would put someone at risk. Both of you can read the decisions you had a say in, in the console, as they happen.

IF WE STOP ANSWERING

Your phone lets itself out after 15 days

The phone checks in with us as it goes about its work. If fifteen days go by without it checking in, it takes its own administrative hold off the handset, lifts every restriction and hands it back. The phone warns you on screen a couple of days before that happens, so it doesn’t arrive as a surprise. Your data is untouched throughout.

That one timer covers every worst case worth naming, and the ones nobody has thought of yet. It isn’t a promise. It’s a timer, on the handset in your pocket, and we aren’t in the loop when it fires.

Test it before you commit

Enrol a spare handset, leave it off the network and put it on a shelf for a fortnight. Either the restrictions come off by themselves or we’ve lied to you on this page. There’s no third outcome, and you don’t need our help to find out which.

It does mean a handset kept away from the network long enough ends up out of the lock. That’s the backstop read from the other end, and we’d rather say so than have you find it. It’s a poor way out: you give up the phone for a fortnight to get there, and going back into the lock afterwards means wiping the handset and starting again. If you want out, you can start the three-day release yourself, keep the phone working while it runs, and your partner is told when it starts.

DOING IT YOURSELF

You don’t have to take our word for it

None of this needs our permission, and most of it doesn’t need us at all. A spare handset and an afternoon will settle it.

  • Read the permissions. Your phone lists what any app is allowed to touch, ours included, and no location permission means no location whatever we’ve written here. It carries no advertising or analytics libraries at all.
  • Watch the traffic. Put a monitor between the phone and your router and you’ll see it talking to us: when, and how little of it there is. What’s inside stays encrypted, as your bank’s traffic is — it’s yours, and we’re not weakening that to make a web page easier to check.
  • Open the app up. The release build is an ordinary Android package, and the usual tools will show you what it asks for and where it talks to. We’d rather you looked than took our word for it.
  • Check what you downloaded. The download page carries the fingerprint of the file. Compare it with the one you’ve got.

Do any of that and find this page wrong, and we want to hear about it. We’ll fix the page or the software, whichever turns out to be at fault.

LEGAL ACCOUNTABILITY

Who you are dealing with

An anonymous website can’t be sued, or asked anything it doesn’t fancy answering. We’re a registered company operating entirely within the United Kingdom, and both registrations are public. You can look them up without asking us.

  • Corporate registration. Pandora’s Lid is a trading name of Graft and Craft Ltd, a private limited company registered in England and Wales. Company number 17461838.
  • Data protection. We’re registered as a data controller with the UK Information Commissioner’s Office. Registration number CSN8677762.
NOT YET DONE

What we can’t show you

Nobody independent has tested any of this. We haven’t commissioned a penetration test and we hold no security certification. Both cost more than this product has made. We’d rather say so than leave a badge-shaped gap on the page and let you draw the kinder conclusion.

The source stays closed, and the reason is narrow. What we keep back is how the lock decides what opens — publish that and we’ve handed a way round it to the person the lock is meant to hold, usually at eleven at night when they’re least glad of it. It buys nothing else. The hard part of the lock is Android’s own device management, which Google documents publicly and we didn’t write.

If you find a way through, or a way in, write to us before you write it up. Here’s how.

REPORTING A FLAW

Found a hole? Tell us first

Write to security@pandoras-lid.com. Plain email is fine. The steps to reproduce it help us most; a polished report helps us not at all.

What we’ll do:

  • Reply within three working days to say we have it. A person reads that inbox, not a bot.
  • Fix it, or tell you plainly why we won’t, and keep you posted while we work on it.
  • Credit you by name on this page once it’s fixed, if you’d like that.
  • Refund what you paid us, if you paid us anything.

What counts. The phone app, this website and the console, and the service behind them. A way for the holder to get out from under the lock without their partner counts, and it’s the report we most want: that’s the whole product failing, and the person it fails is the one who asked for it.

What doesn’t. Load and denial-of-service testing, spam and phishing, and anything that relies on having someone else’s device or credentials in hand.

Your side of it. Test on your own phone and your own account. Don’t read, change or delete anyone else’s data, and if you stumble into some, stop there and tell us. Give us 90 days before you publish, or less if we’ve fixed it sooner. Keep to that and we won’t take legal action over your research or complain about it to anyone.

There’s no bounty. We’d rather you knew that before you started than after you finished.