A permission health dashboard, not a mystery list
KaiZenly+ asks for sensitive permissions only when you enter a feature that needs them — mostly Zen Shield focus. In the app, permissions are organized like a health dashboard with visual status rings, required vs recommended groups, and one-tap access to Android settings. Here is exactly what each one is for.
Sensitive Android permissions are off by default. KaiZenly+ cannot silently enable Usage Access, Accessibility Service, Display over other apps, Device Admin, Notifications, Phone state, Microphone, or Battery optimization exemption. The user grants each one manually through Android settings or the Android permission prompt when a feature needs it.
Usage Access
android.permission.PACKAGE_USAGE_STATS
Lets Zen Shield notice when a distracting app is opened during a focus session, and powers on-device screen-time insights. You enable it yourself in Android settings; the app cannot grant it automatically.
Accessibility Service
android.permission.BIND_ACCESSIBILITY_SERVICE
Off by default and enabled only by the user in Android Accessibility settings. Used only during active focus sessions to detect blocked apps, recents, popup, and split-screen bypass attempts, then return you to Focus Space or trigger the session lock rule. It reads package and class names for enforcement — it does not read message text, passwords, keystrokes, or personal screen content.
Display over other apps
android.permission.SYSTEM_ALERT_WINDOW
Off by default and enabled only by the user in Android settings. Shows the full-screen Focus / Distraction Wall over a blocked app during an active session.
Device Admin
android.permission.BIND_DEVICE_ADMIN
Off by default and activated only by the user through Android Device Admin settings. Required to start protected Zen Shield focus sessions. During an active session, Device Admin lets KaiZenly+ lock the device after blocked-app or bypass violations, and helps prevent uninstall-based bypass while the session is running. It is explained before Android setup opens and is not used to erase data, change passwords, or control the phone outside an active session.
Exact alarms
android.permission.SCHEDULE_EXACT_ALARM
Helps local habit reminders and focus-session end alarms fire on time when Android allows exact scheduling. If exact alarms are not permitted, KaiZenly+ falls back to inexact scheduling instead of forcing the permission.
Notifications
android.permission.POST_NOTIFICATIONS
Off by default on newer Android versions until the user allows it. Shows habit reminders and the ongoing notification for an active Zen Shield focus session.
Foreground Service
android.permission.FOREGROUND_SERVICE (+ SPECIAL_USE)
Keeps an active focus session running reliably with a visible ongoing notification.
Phone state (call safety)
android.permission.READ_PHONE_STATE
Off by default until the user grants it. Lets focus mode detect an incoming call so it can step aside gracefully instead of blocking your phone during a call.
Microphone
android.permission.RECORD_AUDIO
Off by default until the user grants it. Used only when you record a voice note inside a journal entry. Recordings stay in app-private storage.
Battery optimization exemption
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
Off by default and approved only by the user in Android battery settings. Helps scheduled Zen Shield focus, bedtime mode, and reminders run on time without the system killing them in the background.
Run at startup
android.permission.RECEIVE_BOOT_COMPLETED
Lets an active focus session and schedules survive a device restart.
Internet
android.permission.INTERNET
Used only for optional Google account sign-in and manual Google Drive backup / restore. Normal use never needs the network.
Vibrate
android.permission.VIBRATE
Provides subtle haptic feedback, for example on focus completion.
Required vs recommended
The Permissions page separates permissions that are required for protected focus from permissions that improve reliability. Usage Access, Accessibility, Display over apps, and Device Admin are required for Zen Shield protection. Call state, Notifications, and Battery optimization are recommended for safer calls, visible sessions, reminders, and reliable scheduling.
Prominent disclosure
Before the app sends you to Android’s Accessibility or Device Admin settings, it shows the same clear disclosure from onboarding, Focus setup, and Profile permission health. The disclosure explains why the permission is needed, when it is active, what it does not collect or control. Normal habits, journal, mood, and insights still work without Zen Shield enforcement permissions, but protected Zen Shield sessions require Device Admin.
These permissions stay off unless the user grants them. KaiZenly+ can open the right Android settings screen or show the Android prompt, but the final decision is always made by the user.
Accessibility is limited to active focus enforcement and does not read messages, passwords, keystrokes, or personal screen content. Device Admin is required for protected Zen Shield sessions so KaiZenly+ can lock the device after blocked-app or bypass violations and reduce uninstall-based bypass while the session is running; it is not used to erase data, change passwords, or control the phone outside that session.
Future screenshot: permission health
Add a fresh screenshot here when available: Permissions page with visual status rings,
required and recommended sections, and one-tap Android settings actions. Suggested file:
69_permissions_health_dashboard.webp.
Allowed apps during focus
Zen Shield's allow-list is limited to installed approved essentials. Examples include the Phone app, Messaging/SMS app, WhatsApp, Gmail, Outlook, Google Keep, AI/productivity tools, and major banking/payment apps across regions where installed.
Zen Shield only shows installed apps that match the approved essential-app policy. It is designed for real-life essentials, not as a loophole for broad social or streaming apps. If your essential banking or productivity app is missing, request it from inside the app. The website does not publish every supported banking app name, because the in-app picker only shows the matching apps installed on that user's device.
Exact-alarm policy
KaiZenly+ uses SCHEDULE_EXACT_ALARM only for local reminders and focus-session
end timing. It does not request USE_EXACT_ALARM, which is
reserved for alarm-clock and calendar-style apps. If Android does not allow exact alarms,
KaiZenly+ falls back to inexact scheduling gracefully.