Permissions
Appcognito asks for a lot of permissions on paper and almost none in practice. Which ones you see depends on what you set up.
Only what you use
There is no checklist to clear before the app works. Each ask comes from what the rule you just built actually does.
- A charging rule never mentions alarms. Nothing about it is clock-driven.
- A rule that only cuts internet never mentions the accessibility service.
- A Group with no keywords in it never mentions screen reading.
The trade-off is that you meet permissions gradually. To see them all at once, open Settings, Block settings, Permissions, which lists every one and lets you switch things on early.
The blocking permissions
| Permission | Shown as | What it does | Needed for |
|---|---|---|---|
| VPN | Block apps and sites | Filters traffic on your device so blocked sites do not load and blocked apps get no internet. | Internet blocking and all website blocking. |
| Display over other apps | Block apps you pick | Draws the block screen over a blocked app when you open it. | App blocking, with Usage access. |
| Usage access | App usage | Notices when a blocked app opens, and measures how long apps and the screen are used. | App blocking, plus usage, screen time and open limit triggers. |
| Alarms and reminders | On-time blocking | Wakes the app at the exact moment a block should start or lift. | Clock-driven Actions. Without it, blocks run up to ten minutes late. |
| Battery | Run in the background | Stops Android killing the background work that runs your rules. | Every Action, since they all run with the app closed. |
What a trigger needs
Only ever asked for by the Action using it, when you enable it.
| Permission | Used by | Why |
|---|---|---|
| Location | Wi-Fi and Location | Android hides the Wi-Fi network name behind location permission. Allow all the time lets both survive a reboot. |
| Calendar, read only | Meetings | Reads timed events from your phone's calendar. Nothing is written. |
| Physical activity | Movement | Tells walking from running from driving, on device. |
| Nearby devices | Bluetooth | Sees which Bluetooth device is connected, usually your car. |
| Accessibility | Off topic | Reads on-screen text to tell studying from drifting. |
Optional and Pro
| Permission | For |
|---|---|
| Notifications | Blocking alerts, habit reminders, and the small notice while blocking is on. |
| Camera | Scanning a parent's QR code. Nothing else uses the camera. |
| Device admin | Uninstall protection. Survives a restart. Pro. |
| Accessibility | Keyword blocking. Recommended, not required. See below. |
Permanently deny a permission and Android stops showing its dialog. Appcognito notices and sends you to the right page in system settings, instead of leaving you tapping a dead Allow button.
About Accessibility
This is the one people are most wary of. Fair enough, so here is exactly where it stands.
App blocking no longer uses it
It used to, because the service was the only way to notice a blocked app opening. That made a screen reader mandatory for the app's core feature, and it had a real cost: banking and payment apps in several regions refuse to run while an accessibility service is on. Blocking your distractions could break your banking.
App blocking now runs on two ordinary permissions instead, the overlay and usage access. Neither is visible to the apps being blocked.
What it is still used for
Off topic guard Required
Its whole job is reading the screen to tell studying from drifting. Without the service it cannot fire at all, so it is not offered without it.
Keyword blocking Recommended
Catching a word needs screen text. But a Group is apps plus sites plus words, and many people want the first two only. So this never blocks you from saving. Apps and sites block anyway, and keywords start working the day you turn the service on.
What happens to what it reads
On-screen text is matched against your own keyword list, in memory, on your phone. Not stored, not logged, not sent. There is no account and no server to send it to.
About the VPN
Android shows a key icon whenever a VPN is active, and Appcognito's filter uses that API, so you will see it while blocking is on.
It is a local filter, not a tunnel. Nothing goes to a remote server, nothing is decrypted, nothing is logged. It exists so a blocked domain can be dropped before it loads, in every browser at once.
If one gets switched off
Android sometimes revokes special access on its own, usually after an OS update or an aggressive battery optimiser. Rather than letting your blocks silently stop working, Appcognito tells you. It names the exact one that is missing and says plainly that blocked apps can be opened again until you turn it back on.
Settings, Block settings, Permissions shows how many are on, and every row can be fixed from there.