Privacy Policy

Pacts is a habit app for keeping small daily commitments — on your own, or with a partner or small circle. This policy explains what we collect, why, and the choices you have. We keep it short because we collect little.

What we collect

Account details: your email, name, and (optionally) a profile photo you upload. If you are an admin of a circle you can also upload a photo for that circle; it is shown to that circle's members the same way your profile photo is.

Circle activity: the pacts your circle creates, the check-ins you and your circle members record about each other (kept / missed, plus any short note), and disputes.

Notifications: a device push token, so we can tell you when you were marked, when someone asks to join your circle, or send a cheer.

Product analytics: first-party, minimal usage events (an event name plus ids and counters — never the text of your pacts or notes) so we can see which features work and fix what doesn't. There is no advertising SDK and no third-party product-analytics SDK — the analytics are ours. Crash reporting is separate, and is described below.

Feedback you send us in the app, and automatic crash / error reports so we can keep the app working. A crash report is technical: what went wrong and where in the code, your app version, and your device and OS type — plus the random identifier for your account, so we can tell whether one fault hit many people or one person many times. It never includes your name, your email, or the text of your pacts, notes, or messages. These reports are processed by Sentry, our crash-reporting provider.

Basic technical data needed to run the service (e.g. timestamps on the actions above).

If you choose to put health-related details in a pact or note, you're providing that information to run your pact; we don't ask for it, use it for anything else, or share it.

What we don't do

We do not sell your data. Ever.

We do not show ads and we do not share your data with advertisers.

We do not use your check-in data to build a profile of you beyond running the app.

How your data is used

To run the core loop: pacts and check-ins (you check yourself in, or circle members check each other), streaks, and disputes.

To send the notifications you enable (all are optional and can be turned off in Settings and your device).

Your name, your photos (your profile picture, and any circle photo you set as an admin), and your check-in record are visible only to members of the circles you belong to — access is enforced by database security rules, not just the app.

Where it's stored

Your data is stored with our backend provider (Supabase) on secure, access-controlled infrastructure. Access is restricted by row-level security so members only see their own circles.

Crash and error reports go to Sentry (sentry.io), our crash-reporting provider, and are stored on its EU infrastructure. They hold only the technical details and account identifier described above — never your pacts, notes, or messages.

Account emails — confirming your address, resetting your password — are delivered by Resend (resend.com), our email provider, on infrastructure in the United States. Sending an email necessarily discloses your email address to it; it receives nothing else about you, and we don't send marketing email.

If you subscribe, your subscription is handled by RevenueCat (revenuecat.com), our billing provider, which records which plan you're on and whether it's active. It receives the random identifier for your account and the purchase details from Apple or Google — never your name, your email, or the content of your pacts. Your card details go to Apple or Google, never to us: we never see or store a payment method.

How long we keep it

Your account data — your profile, pacts, and check-in history — stays until you delete your account, so your streaks and record are there when you come back.

Operational data like analytics events and crash / error reports is kept only as long as it's useful for running and fixing the app, then pruned periodically.

Deleting your data

You can delete your account at any time from Settings → Account → Delete account. This permanently removes your profile, memberships, check-ins, and push tokens.

You can also request deletion without using the app by emailing us at the address below.

Children

Pacts is for people aged 16 and over. It is not directed at children under that age, and you must be at least 16 to hold an account. If we learn an account belongs to someone younger, we may close it. Please don't use Pacts if you're under 16.

Changes & contact

If this policy changes materially we'll update the date above and note it in the app. Questions or deletion requests: support@getpacts.com.