Backd Privacy Policy
Effective date: July 9, 2026 · Last updated: August 17, 2026
>
Backd is an accountability app. You set goals, submit proof (a photo or a written note) that you did them, and stay accountable to buddies or a small private group you choose. This policy explains, in plain language, what personal information Backd collects, why, who it is shared with, how long it is kept, and the choices and rights you have. It describes Backd's actual behavior — not aspirations. This policy is provided for transparency and may be updated as Backd evolves.
Backd is operated by the developers of the Backd app ("Backd", "we", "us", "our"). If you have questions, contact us at support@backd.dev.
Our guiding rule is private by default: your data is visible to you and only to the specific buddies or group members you choose to be accountable to. There are no public profiles, no global feed, and no discoverable groups.
1. The short version
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under California and similar U.S. state laws). We never have.
- We run no advertising, and we have no third-party advertising, analytics, or attribution SDKs in the app. There is one telemetry path and it is crash reporting only — no PII, no account id, nothing recorded while the app is working. See Section 2, "Crash and error diagnostics".
- Every outside company that touches your data does so only as our service provider / processor under contract, to perform a function you asked for (e.g. store your data, send a push).
- The highest-sensitivity flow is the optional AI proof / Coach feature: when you use it, your proof image, goal text, your note, and/or your free-text chat are sent to our AI service provider. See Section 5.
- You can delete your account and all associated data from inside the app at any time (Settings → Delete account).
2. Information we collect, the source, and why
We collect the categories below. The source is you (information you provide or generate in the app) and your device, unless otherwise noted.
Account information
Device time zone
Birth year and legal-acceptance records
Goals, schedules, and check-ins
Proof content (user-generated content)
Phone number (only if you opt into SMS reminders)
Precise location (optional, only for location proof)
Health data (optional, read-only, on-device only)
Buddies, groups, and invites
Notifications
Subscriptions (Backd Premium)
Connected-account tokens (optional integrations)
Screen Time / Focus Vault (optional, iOS)
Crash and error diagnostics
What we do not collect
3. Sensitive information
Some of the above is sensitive. We call it out plainly:
- Precise geolocation — a single foreground point at check-in, coarsened before storage, used only for location proof. Never sold, never shared for ads, never tracked in the background.
- Health information — read on-device only; raw samples never leave the device; only a derived boolean and a step count are stored.
- Phone number — only if you opt into SMS (not enabled today).
- Your proof photos and notes and goal/journal text — freeform content you create that may reveal sensitive things about you.
We use sensitive information only to provide the features you turned on. We do not use it to infer characteristics about you and do not use or disclose it for any purpose that would require a right to limit under U.S. state privacy laws.
4. How and why we use your information
We use personal information to:
- create, secure, and operate your account;
- run the core loop — goals, check-ins, proof, and buddy/group review;
- verify location- and health-based check-ins (as described above);
- send notifications, reminders, and buddy invites you enable;
- provide the optional AI proof/Coach features when you invoke them (Section 5);
- process subscriptions if you buy one;
- maintain security, prevent abuse, enforce rate limits, and debug; and
- comply with law.
We do not use your information for advertising, for building advertising or marketing profiles, or to train our own general-purpose models. (For third-party AI vendor training, see Section 5.)
5. Who receives your information
We do not sell or share your personal information, and we use no ad or analytics networks. The companies below are service providers / processors that receive only the data needed to perform a specific function for us. Each is named with exactly what it receives.
| Recipient | What it receives | Purpose | May it use your data to train AI? |
|---|---|---|---|
| Supabase (our backend: Postgres, Auth, Storage, Edge Functions) | All of the data described in this policy — account info, goals, proof media, check-in/location notes, phone number (if SMS on), connected-account tokens, push records, message/proof content | Hosts and runs the entire app | No |
| AI service provider — used only by the optional AI proof review and the Coach chat | The raw proof image, the goal text, and your note (AI proof review); and your free-text Coach chat messages plus your own goal/miss context (Coach). The image is fetched server-side via a short-lived signed URL and sent to the provider's API. | Returns an advisory proof result, or a coaching reply | We use the provider strictly as a service provider to return the result; its handling of API inputs is governed by its API terms. See the call-out below. |
| Sentry (error reporting) | Crash and error reports: the error type, a redacted message, the stack trace, app version, and device model / OS version. No account id, no email, no name, no goal or proof content — PII collection is disabled in the SDK and the message is redacted on-device before it is sent. | Find and fix crashes | No |
| Twilio (only if SMS reminders are ever enabled — currently off) | Your phone number and goal titles needed for the reminder text | Deliver SMS reminders you opted into | No |
| Expo push service → Apple (APNs) | Your device push token and the notification text | Deliver push notifications | No |
| Resend | The recipient's email address and your display name (inviter name) | Send a transactional buddy-invite email | No |
| RevenueCat | Your Backd user id as the subscription identifier, plus subscription state | Validate purchases and map your subscription to your account | No |
| Apple In-App Purchase | Handles the purchase itself; no card data reaches Backd | Process subscription payments | No |
| Google Calendar API (only if you connect it) | Your Google access token and the calendar events/goals involved in the action you requested | Read events you turn into goals; add goals to your calendar | No |
| Canvas LMS (only if you connect it) | Your Canvas URL and personal access token; reads your assignments | Read assignments you turn into goals | No |
The AI proof / Coach feature is the highest-sensitivity flow in Backd. When you tap "Run AI check," your proof photo, goal text, and note are sent to our AI service provider. When you chat with the Coach, your free-text messages are sent. These features run only when you explicitly invoke them — nothing scans your photos or messages automatically — and the result is always advisory: a human (you or your buddy) makes the real decision. We send the provider only what is needed to return the result and use it strictly as a service provider; its handling of API inputs is governed by its own API terms, and we will update this policy with provider-specific retention details as they are confirmed. If you'd rather not have this content processed by an AI provider at all, simply don't use these two optional features — Backd works fully without them.
Other disclosures. We may disclose information if required by law, to respond to lawful requests, to protect the rights, safety, or property of users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this policy or notify you).
We disclose personal information to these recipients as service providers only. Because there are no ad or analytics SDKs, there is no "sale" or "share" of personal information for advertising purposes.
6. How long we keep your information (retention)
| Category | Retention |
|---|---|
| Account info, goals, check-in history | Kept while your account is active; deleted when you delete your account |
| Crash and error diagnostics | Kept for the retention window configured on the error-reporting project (Sentry's default is 90 days for errors). They contain no account identifier, so they are not linked to you and cannot be retrieved by an account-level request. |
| Proof media (photos) | Governed by your Proof media retention setting: Never store media (0 days), 30, 60, or 90 days. Media past the chosen window is purged; your check-in record (that you checked in) can remain. You can also delete all proof media at any time without deleting your account. |
| Location check-in notes | The coarsened text note lives with the check-in and is deleted when the check-in or account is deleted |
| Health-derived values (boolean + step count) | Stored with the check-in; deleted with it or with the account |
| Phone number (if SMS on) | Kept while SMS is enabled; removed on account deletion |
| Push tokens | Kept while valid; invalid tokens are auto-disabled; removed on account deletion |
| Connected-account tokens (Google/Canvas) | Until you disconnect or delete your account |
| Subscription state | While the subscription/account is active |
| Data held by AI vendor | Determined by the AI vendor's policy for the configured endpoint — see Section 5 |
| Buddy-invite emails sent via Resend | As a transactional log per Resend's retention |
We may retain limited records longer where required to comply with law, resolve disputes, or enforce our agreements.
7. How we protect your information
- Every record is protected by Row-Level Security: by default only you can read or write your own data. The only cross-user access is the narrow, relationship-scoped buddy/group review described above.
- Proof media lives in a private bucket, reached only through short-lived signed URLs, and only by you or the buddy assigned to that goal.
- Proof photos are re-encoded to strip EXIF/GPS metadata before upload.
- Data is encrypted in transit.
- Connected-account tokens are stored in owner-only rows and are never shown to other users or written to logs.
No system is perfectly secure, and we cannot guarantee absolute security.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, and obtain a portable copy of your personal information, and to be free from discrimination for exercising these rights.
What you can do today, in the app:
- Delete your account and all associated data. Settings → Delete account runs a server function that removes your proof media from storage and cascades the deletion of all your database rows (goals, check-ins, stakes, trophies, buddy links, tokens, push records). This cannot be undone.
- Export your data. Settings → Export data produces a JSON file of your data (goals, check-ins, proof metadata, reflections, preferences, relationships, and more) delivered through the device share sheet.
- Delete proof media only (Settings → Delete all proof media), keeping your check-in history.
- Set proof-media retention, including "Never store media."
- Control what buddies can see, manage notification preferences, and disconnect Google Calendar or Canvas.
- Access and correct much of your information directly (your profile, goals, notes, settings).
- Revoke Location or Health permission anytime in your device's OS Settings.
Rights we cannot yet fully self-serve in the app (we honor them by request):
- Web-based deletion — deletion today is in-app only; there is no web deletion URL yet. To request deletion without the app, email support@backd.dev.
- Correction of anything not editable in-app — email support@backd.dev.
How to exercise a right: use the in-app controls above, or email support@backd.dev. We will verify your request using your account email and respond within the time required by applicable law. You may use an authorized agent where the law permits.
Because we do not sell or share personal information for advertising and do not use it for targeted advertising, there is nothing to opt out of in those categories.
9. Children's privacy
Backd is used by students, and we know some users may be under 13.
- Backd is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
- Every account collects a birth year (not a full date of birth) and blocks self-signup under 13. This applies regardless of sign-in method: email signup collects it directly; Sign in with Apple (which does not provide a birth year itself) routes the account through a mandatory, one-time screen before the app is reachable, requiring a birth year and blocking under-13 self-registration. This is enforced in every current build, not a planned future feature.
- If we learn we have collected personal information from a child under 13 without the required consent (for example, a birth year entered inaccurately), we will delete it. A parent or guardian can contact support@backd.dev to review, delete, or stop further collection of their child's information. -
10. International users
Backd is operated from the United States and stores data with U.S.-based infrastructure. If you use Backd from outside the U.S., your information will be processed in the U.S.
11. Changes to this policy
We will update this policy as the app changes and revise the effective date above. For material changes we will provide notice in the app or by email where appropriate.
12. Contact us
Backd Email: support@backd.dev