Back to the main site

Data protection & privacy

What we store, and what we can’t see

Last revised: 6 September 2026 · Version 1.2 · Compliant with UK & EU GDPR

A lock, not a monitor

Pandora’s Lid governs which apps can open. It has no interest in what you do inside the ones that do. We don’t read your messages, log your keystrokes, track where you are, or count your hours. That isn’t a promise we could break later. The software holds no permission to do any of it, and you can check that from the manifest before you install.

Every call the phone makes is listed, field by field, on the page on checking us, along with how to watch it happen through a proxy.

1. What We Never Collect

The software on the phone requests no Android permission that would let it reach any of the following, so neither the handset software nor the console can capture:

Communications & SMS (no reading text messages or chat contents)
Personal Media (no access to photographs, videos, or camera)
Geolocation (no GPS coordinate tracking or Wi-Fi location logging)
Keystroke Logging (no keyboard monitoring or input snooping)
In-App Activity (no visibility into documents, emails, or transactions)
Microphone Audio (no ambient listening or audio recordings)

2. What We Collect and Why

We collect what the arrangement between the two of you can’t work without, and nothing beyond it:

  • Email Address: Used solely to authenticate your identity via passwordless magic links and send transactional notifications (e.g. partner pairing requests, escrow cooling-off alerts).
  • Device identifiers: The handset’s hardware serial, which is unique to that phone and not anonymous, and the push token Google issues to this install. Both are needed to tell your phone apart from everyone else’s and to send it policy instructions. When an enrolment ends we null the serial, so the handset can be enrolled again later.
  • Application Identifiers: Reverse-domain package names (such as com.spotify.music) and public Play Store labels intercepted when software is installed, to display them in the dual-signature review queue.
  • Requested Web Domains: Fully qualified domain names and wildcard patterns (such as *.hsbc.co.uk) requested for browser allowlisting.
  • Audit Timestamps & Signatures: Records of approval, denial, transition countdowns, and break-glass escrows to preserve mutual transparency.
GDPR Article 9 Special Category Data Notice

3. Health and Medical Applications

Pandora’s Lid includes hardcoded on-device exemptions for continuous glucose monitors (CGMs) and emergency welfare applications (including Dexcom G6/G7/ONE, Abbott FreeStyle Libre 1/2/3, Medtronic MiniMed, the NHS app, and Bright Sky domestic welfare assistance).

Zero Health Data Processing:

While the package names of these tools may indirectly suggest a medical condition (such as Type 1 Diabetes), the software processes this solely on the local handset to prevent interruption of glucose alarms. Our servers never receive, store, or transmit glucose telemetry, sensor readings, prescription details, or clinical logs.

4. Data Retention and Erasure

Approval history and device pairings are kept for as long as the enrolment is live, because both of you need to be able to read back what was agreed and when. Unenrol cooperatively, or take the emergency release, and the pairing is marked revoked and the hardware serial cleared. The history of what the two of you decided stays until you ask us to delete it.

Under Article 17 of the UK and EU GDPR you can have all of it erased. There’s a Delete account button in Settings — type your email address to confirm and it happens straight away. You’ll need to unenrol any device you’re still carrying first: the button won’t let you delete your way out of an arrangement you’re still holding a phone under.

Lost access to your account and can’t reach Settings? Write to us instead and we’ll verify who you are and erase it on your behalf, active device or not.

5. Contact & Data Controller

The Data Controller is Graft and Craft Ltd trading as Pandora's Lid.

Company No. 17461838 (Registered in England and Wales).
Registered Office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

For our comprehensive company privacy policy and data protection framework, please visit the Graft and Craft Legal hub .

Pandora’s Lid is built and run in the United Kingdom, and your data is held here and in the EU. For a subject access request, an erasure request, or anything else about how we handle your data under this product, write to support@pandoras-lid.com. A person reads it. We answer inside the statutory month, and usually the same week.