Backd Privacy Policy

Effective date: July 9, 2026 · Last updated: August 17, 2026

>

Backd is an accountability app. You set goals, submit proof (a photo or a written note) that you did them, and stay accountable to buddies or a small private group you choose. This policy explains, in plain language, what personal information Backd collects, why, who it is shared with, how long it is kept, and the choices and rights you have. It describes Backd's actual behavior — not aspirations. This policy is provided for transparency and may be updated as Backd evolves.

Backd is operated by the developers of the Backd app ("Backd", "we", "us", "our"). If you have questions, contact us at support@backd.dev.

Our guiding rule is private by default: your data is visible to you and only to the specific buddies or group members you choose to be accountable to. There are no public profiles, no global feed, and no discoverable groups.


1. The short version


2. Information we collect, the source, and why

We collect the categories below. The source is you (information you provide or generate in the app) and your device, unless otherwise noted.

Account information

Device time zone

Birth year and legal-acceptance records

Goals, schedules, and check-ins

Proof content (user-generated content)

Phone number (only if you opt into SMS reminders)

Precise location (optional, only for location proof)

Health data (optional, read-only, on-device only)

Buddies, groups, and invites

Notifications

Subscriptions (Backd Premium)

Connected-account tokens (optional integrations)

Screen Time / Focus Vault (optional, iOS)

Crash and error diagnostics

What we do not collect


3. Sensitive information

Some of the above is sensitive. We call it out plainly:

We use sensitive information only to provide the features you turned on. We do not use it to infer characteristics about you and do not use or disclose it for any purpose that would require a right to limit under U.S. state privacy laws.


4. How and why we use your information

We use personal information to:

We do not use your information for advertising, for building advertising or marketing profiles, or to train our own general-purpose models. (For third-party AI vendor training, see Section 5.)


5. Who receives your information

We do not sell or share your personal information, and we use no ad or analytics networks. The companies below are service providers / processors that receive only the data needed to perform a specific function for us. Each is named with exactly what it receives.

RecipientWhat it receivesPurposeMay it use your data to train AI?
Supabase (our backend: Postgres, Auth, Storage, Edge Functions)All of the data described in this policy — account info, goals, proof media, check-in/location notes, phone number (if SMS on), connected-account tokens, push records, message/proof contentHosts and runs the entire appNo
AI service provider — used only by the optional AI proof review and the Coach chatThe raw proof image, the goal text, and your note (AI proof review); and your free-text Coach chat messages plus your own goal/miss context (Coach). The image is fetched server-side via a short-lived signed URL and sent to the provider's API.Returns an advisory proof result, or a coaching replyWe use the provider strictly as a service provider to return the result; its handling of API inputs is governed by its API terms. See the call-out below.
Sentry (error reporting)Crash and error reports: the error type, a redacted message, the stack trace, app version, and device model / OS version. No account id, no email, no name, no goal or proof content — PII collection is disabled in the SDK and the message is redacted on-device before it is sent.Find and fix crashesNo
Twilio (only if SMS reminders are ever enabled — currently off)Your phone number and goal titles needed for the reminder textDeliver SMS reminders you opted intoNo
Expo push service → Apple (APNs)Your device push token and the notification textDeliver push notificationsNo
ResendThe recipient's email address and your display name (inviter name)Send a transactional buddy-invite emailNo
RevenueCatYour Backd user id as the subscription identifier, plus subscription stateValidate purchases and map your subscription to your accountNo
Apple In-App PurchaseHandles the purchase itself; no card data reaches BackdProcess subscription paymentsNo
Google Calendar API (only if you connect it)Your Google access token and the calendar events/goals involved in the action you requestedRead events you turn into goals; add goals to your calendarNo
Canvas LMS (only if you connect it)Your Canvas URL and personal access token; reads your assignmentsRead assignments you turn into goalsNo
The AI proof / Coach feature is the highest-sensitivity flow in Backd. When you tap "Run AI check," your proof photo, goal text, and note are sent to our AI service provider. When you chat with the Coach, your free-text messages are sent. These features run only when you explicitly invoke them — nothing scans your photos or messages automatically — and the result is always advisory: a human (you or your buddy) makes the real decision. We send the provider only what is needed to return the result and use it strictly as a service provider; its handling of API inputs is governed by its own API terms, and we will update this policy with provider-specific retention details as they are confirmed. If you'd rather not have this content processed by an AI provider at all, simply don't use these two optional features — Backd works fully without them.

Other disclosures. We may disclose information if required by law, to respond to lawful requests, to protect the rights, safety, or property of users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this policy or notify you).

We disclose personal information to these recipients as service providers only. Because there are no ad or analytics SDKs, there is no "sale" or "share" of personal information for advertising purposes.


6. How long we keep your information (retention)

CategoryRetention
Account info, goals, check-in historyKept while your account is active; deleted when you delete your account
Crash and error diagnosticsKept for the retention window configured on the error-reporting project (Sentry's default is 90 days for errors). They contain no account identifier, so they are not linked to you and cannot be retrieved by an account-level request.
Proof media (photos)Governed by your Proof media retention setting: Never store media (0 days), 30, 60, or 90 days. Media past the chosen window is purged; your check-in record (that you checked in) can remain. You can also delete all proof media at any time without deleting your account.
Location check-in notesThe coarsened text note lives with the check-in and is deleted when the check-in or account is deleted
Health-derived values (boolean + step count)Stored with the check-in; deleted with it or with the account
Phone number (if SMS on)Kept while SMS is enabled; removed on account deletion
Push tokensKept while valid; invalid tokens are auto-disabled; removed on account deletion
Connected-account tokens (Google/Canvas)Until you disconnect or delete your account
Subscription stateWhile the subscription/account is active
Data held by AI vendorDetermined by the AI vendor's policy for the configured endpoint — see Section 5
Buddy-invite emails sent via ResendAs a transactional log per Resend's retention

We may retain limited records longer where required to comply with law, resolve disputes, or enforce our agreements.


7. How we protect your information

No system is perfectly secure, and we cannot guarantee absolute security.


8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, and obtain a portable copy of your personal information, and to be free from discrimination for exercising these rights.

What you can do today, in the app:

Rights we cannot yet fully self-serve in the app (we honor them by request):

How to exercise a right: use the in-app controls above, or email support@backd.dev. We will verify your request using your account email and respond within the time required by applicable law. You may use an authorized agent where the law permits.

Because we do not sell or share personal information for advertising and do not use it for targeted advertising, there is nothing to opt out of in those categories.


9. Children's privacy

Backd is used by students, and we know some users may be under 13.


10. International users

Backd is operated from the United States and stores data with U.S.-based infrastructure. If you use Backd from outside the U.S., your information will be processed in the U.S.


11. Changes to this policy

We will update this policy as the app changes and revise the effective date above. For material changes we will provide notice in the app or by email where appropriate.


12. Contact us

Backd Email: support@backd.dev