Backd Privacy Policy

Effective date: October 1, 2026 · Last updated: October 2, 2026

Backd is an accountability app. You set goals, submit proof (a photo or a written note) that you did them, and stay accountable to buddies or a small private group you choose. This policy explains, in plain language, what personal information Backd collects, why, who it is shared with, how long it is kept, and the choices and rights you have. It describes Backd's actual behavior — not aspirations. This policy is provided for transparency and may be updated as Backd evolves.

Backd is provided by Anson Antony, the developer of the Backd app, located at 1742 SW 38th Terrace, Gainesville, FL 32607 ("Backd", "we", "us", "our"). Backd is an app made by an individual, and business is done in his legal name. If you have questions, contact us at support@backd.dev.

Our guiding rule is private by default: your data is visible to you and only to the specific buddies or group members you choose to be accountable to. There are no public profiles, no global feed, and no discoverable groups.


1. The short version


2. Information we collect, the source, and why

We collect the categories below. The source is you (information you provide or generate in the app) and your device, unless otherwise noted.

Account information

Device time zone

Birth year and legal-acceptance records

Age range from Apple (iOS 26 and later)

Goals, schedules, and check-ins

Proof content (user-generated content)

Phone number (only if you opt into SMS reminders)

Precise location (optional, only for location proof)

Health data (optional, read-only, on-device only)

Buddies, groups, and invites

Notifications

Subscriptions (Backd Premium)

Money stakes and payment details (optional; adults 18+ in the US only)

Money stakes are not available in the current version of the app. Nothing in this part is collected from anyone until they are offered. It describes what Backd would collect then.

Connected-account tokens (optional integrations)

Screen Time / Focus Vault (optional, iOS)

Crash and error diagnostics

Product analytics (usage events)

What we do not collect


3. Sensitive information

Some of the above is sensitive. We call it out plainly:

We use sensitive information only to provide the features you turned on. We do not use it to infer characteristics about you and do not use or disclose it for any purpose that would require a right to limit under U.S. state privacy laws.

We ask before we use it. Precise location and Apple Health each have their own consent screen, shown before Backd first uses them and not bundled with anything else. Connecticut's privacy law, like Washington's health-data law, requires that opt-in consent for sensitive data. Your answer is recorded with the version of the screen you saw. You can withdraw either consent at any time in Settings on your iPhone, and Backd stops collecting that data.


4. How and why we use your information

We use personal information to:

We do not use your information for advertising, for building advertising or marketing profiles, or to train our own general-purpose models. (For third-party AI vendor training, see Section 5.)


5. Who receives your information

We do not sell or share your personal information, and we use no ad networks. The companies below are service providers / processors that receive only the data needed to perform a specific function for us. Each is named with exactly what it receives. Each of them is bound, by its contract or terms with us, to give your information the same or equal protection as this policy, and to use it only to provide its service to Backd.

RecipientWhat it receivesPurposeMay it use your data to train AI?
Supabase (our backend: Postgres, Auth, Storage, Edge Functions)All of the data described in this policy — account info, goals, proof media, check-in/location notes, phone number (if SMS on), connected-account tokens, push records, message/proof contentHosts and runs the entire appNo
AI service provider (currently Hugging Face Inference Providers, which routes the request to Featherless AI running the open Qwen3-VL-8B-Instruct vision model) — used only by the optional AI proof review and the Coach chatThe raw proof image, the goal text, the proof instructions you set, and your note (AI proof review), plus the goal's proof type and the check-in's deadline and submission time; and your free-text Coach chat messages plus your own goal/miss context (Coach). For a location check-in the note is the location note (a point rounded to about 110 m, or the place's label and your approximate distance from it); for an Apple Health check-in it is only "Verified via Apple Health." The image is fetched server-side via a short-lived signed URL and sent to the provider's API.Returns an advisory proof result, or a coaching replyWe use the providers strictly as service providers to return the result. Neither keeps the content of the request or trains on it (see the call-out below and Section 6).
Sightengine (image-safety screening)Each uploaded proof photo — the image only. No name, email, goal, note or account id is sent.Automatically screens every uploaded proof photo for nudity/sexual content, gore and violence before a buddy can see itNot kept: Sightengine deletes each image after checking it, and Backd uses none of its features that keep images (human review, feedback, image lists). Training: not yet confirmed
Sentry (error reporting)Crash and error reports: the error type, a redacted message, the stack trace, app version, and device model / OS version. No account id, no email, no name, no goal or proof content, no location and no health data — PII collection is disabled in the SDK and the message is redacted on-device before it is sent. No crash-report identifier is sent before the age question at sign-up is passed.Find and fix crashesNo
PostHog (product analytics)The named usage events in Section 2, "Product analytics", your Backd user id (or, when no one is signed in, a random install id; never before the age question at sign-up is passed), the app version, and your device's OS, OS version and screen size. No email, no name, no goal, note, proof or message content, no location and no health data. Session recording and IP-based location lookup are off.Understand where people get stuck in the app, in aggregateNo
Apple MapsWhen you set or change a goal's place: the coordinates of that place (if you set it with "Use my current location", that point is where you were)Look for health-care places nearby, so a goal place is never one (Section 2, "Precise location")Backd sends no account details with the request; Apple handles map requests under its own privacy policy.
Twilio (only if SMS reminders are ever enabled — currently off)Your phone number and goal titles needed for the reminder textDeliver SMS reminders you opted intoNo
Expo push service → Apple (APNs)Your device push token and the notification textDeliver push notificationsNo
ResendYour email address; and, for stake emails, the goal's title, the amount and the text of your stake agreement or turn-off confirmationDeliver account emails, such as password resets, and stake emails (a copy of your agreement when you turn a stake on, and a confirmation when you turn one off)No
RevenueCatYour Backd user id as the subscription identifier, plus subscription state. RevenueCat also receives Apple's App Store notifications for the app and passes them on to Backd, including Apple's notice that a parent withdrew consent.Validate purchases and map your subscription to your account; pass on Apple's noticesNo
Apple In-App PurchaseHandles the purchase itself; no card data reaches BackdProcess subscription paymentsNo
Stripe (payment processor — only if you turn on a money stake)Your email address (so Stripe can send your receipts), the card details you enter on Stripe's own page, your Backd user id, and, for each charge, the amount and internal ids for the charge and goal. Backd never sends or receives your full card number.Save your card, charge money stakes under our Terms, confirm payments your bank wants checked, issue refunds, email receipts, and prevent fraudStripe does not receive your goals, proof or notes. It uses payment data to run its own fraud-prevention systems under its own privacy policy.
Google Calendar API (only if you connect it)Your Google access token and the calendar events/goals involved in the action you requestedRead events you turn into goals; add goals to your calendarNo
Canvas LMS (only if you connect it)Your Canvas URL and personal access token; reads your assignmentsRead assignments you turn into goalsNo
The AI proof / Coach feature is the highest-sensitivity flow in Backd. When someone taps "Run AI check" on your proof — you, or the buddy reviewing it — your proof photo, goal text, proof instructions, and note are sent to our AI service provider, but only if both that person and you have allowed AI checks (turning AI proof review off in Settings withdraws your permission). Apple Health check-ins are never sent for an AI check. When you chat with the Coach, your free-text messages are sent. These features run only when someone explicitly invokes them — the AI check never runs on its own, although every uploaded proof photo is separately and automatically screened by our image-safety provider, Sightengine, before a buddy can see it (image only; see the table above) — and the AI result is always advisory: a human (you or your buddy) makes the real decision. We send only what is needed to return the result, and use the providers strictly as service providers. The request goes to Hugging Face, which routes it to Featherless AI. Hugging Face does not store request or response bodies and does not train on user data; its debugging logs are kept for up to 30 days and contain no user data. Featherless AI does not log or store prompts or completions, and keeps only usage counts. Neither keeps your photo, goal text or note after returning the result. If you'd rather not have this content processed by an AI provider at all, simply don't use these two optional features — Backd works fully without them.

Other disclosures. We may disclose information if required by law, to respond to lawful requests, to protect the rights, safety, or property of users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this policy or notify you).

We disclose personal information to these recipients as service providers only. Because there are no ad SDKs, and our analytics provider processes usage events only on our behalf, there is no "sale" or "share" of personal information for advertising purposes.


6. How long we keep your information (retention)

CategoryRetention
Account info, goals, check-in historyKept while your account is active; deleted when you delete your account
Crash and error diagnosticsKept for the retention window configured on the error-reporting project (Sentry's default is 90 days for errors). They contain no account identifier, so they are not linked to you and cannot be retrieved by an account-level request.
Proof media (photos)Deleted once your proof has been reviewed. An approved photo is deleted shortly after the decision (typically within 30 minutes); a photo that was sent back is kept for 48 hours so you can appeal or re-submit, then deleted. Your Proof media retention setting is the outside limit for a photo that nobody ever reviews: Never store media (0 days) means the photo is never uploaded at all — only your note is sent — and 30, 60, or 90 days is the point past which the photo is purged whether it was reviewed or not. In every case your check-in record and the review decision remain — only the image is deleted. You can also delete all proof media at any time without deleting your account. Exception — photos held for safety review: a photo that the automatic image-safety screening flagged is kept, hidden from your buddy, for a person to review. While it is under review it is excluded from this schedule and from "Delete all proof media", and if it is reported under 18 U.S.C. § 2258A it is preserved for as long as that law requires (one year).
Location check-in notesThe coarsened text note lives with the check-in and is deleted when the check-in or account is deleted
Apple Health result ("Verified with Apple Health"; no health value)Stored with the check-in; deleted with it or with the account
Phone number (if SMS on)Kept while SMS is enabled; removed on account deletion
Push tokensKept while valid; invalid tokens are auto-disabled; removed on account deletion
Connected-account tokens (Google/Canvas)Until you disconnect or delete your account
Sign in with Apple tokenUntil you delete your account, when Backd asks Apple to revoke it and deletes it
Subscription stateWhile the subscription/account is active
Saved-card details for money stakes (Stripe customer and payment-method ids, card brand, last four, expiry, issuing country)Kept while a card is saved. The card details (brand, last four, expiry, issuing country) are deleted when you remove the card or delete your account. Deleting your account deletes the rest and removes your card and customer record from Stripe.
Money-stake payment ledger (each stake you turned on and the exact agreement you confirmed, each charge and payment with its amount, dates and status, refunds, disputes, and Stripe's identifiers)Kept for 7 years (from when the charge or payment was made, or from when the stake was turned off), then deleted automatically. This is the only stake data kept that long. If you delete your account first, any charge not yet made is cancelled, and these records are kept no longer linked to your account. They are not anonymous: they still hold Stripe's identifiers, which can be traced to your card and payments. We keep them for tax and accounting, to handle disputes and chargebacks, and to establish or defend legal claims.
Appeal and refund text, stake notices and logs, days under review, attempt reports and the server's location checks (what you wrote in an appeal or refund request, our written decisions, the notices and log entries about your stakes, the record of each day under review and our decision, the reports of check-ins that didn't get through, and the result and distance of each staked location check)2 years, then deleted automatically; a day still under review is kept until it's decided. The ledger keeps only the amounts, dates, statuses and ids. Our outbox copy of a stake email is deleted after 30 days. A late-proof photo attached to an appeal follows the proof-media rules above and is deleted with your account.
Apple age-signal restriction, App Store transaction id link, automatic deletionsThe age range itself is never stored. The restriction it causes and when it was set are kept until Apple's signal says you are 18 or older (under-18 restriction) or until the account is deleted. An account Apple says is under 13, or that the age screen turned away, is deleted within 72 hours; afterwards only the fact and the time of the deletion are kept. An account that never finished signing up (more than 30 days old, no birth year, the Terms never accepted, no goals or check-ins) is deleted automatically, keeping the same: the fact and the time. The link between your account and the app's App Store transaction id is kept while your account exists and deleted with it. A parent's withdrawal for a download no account had registered yet is kept (the download id only) for up to 2 years.
Health-care check for a goal's place (passed or not, when, the point checked, your confirmation)Kept with the goal's place; deleted with the goal or your account.
Consent records (your answers on the location, Apple Health and AI-review consent screens, with their versions)Kept while your account exists; deleted with your account. The agreement you confirmed for a stake is part of the payment ledger above.
Payment records held by StripeStripe keeps its own records of your payments and refunds (including the email address a receipt went to) under its own privacy policy and legal obligations, even after your card or account is removed from Backd.
Proof photos checked by SightengineNot kept. Sightengine deletes each image after checking it.
Data held by AI vendorsNot kept. Hugging Face does not store request or response bodies and does not train on user data; its debugging logs are kept for up to 30 days and contain no user data. Featherless AI does not log or store prompts or completions, and keeps only usage counts. Neither trains on it.
Product analytics events (PostHog)Kept for 1 year, then deleted. When you delete your account the app stops sending events for it at once; to have events already sent erased sooner, email support@backd.dev.
Account and stake emails sent via ResendAs a transactional log per Resend's retention

We may retain limited records longer where required to comply with law, resolve disputes, or enforce our agreements.


7. How we protect your information

No system is perfectly secure, and we cannot guarantee absolute security.


8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, and obtain a portable copy of your personal information, and to be free from discrimination for exercising these rights.

What you can do today, in the app:

Rights we cannot yet fully self-serve in the app (we honor them by request):

How to exercise a right: use the in-app controls above, or email support@backd.dev. We will verify your request using your account email and respond within the time required by applicable law. You may use an authorized agent where the law permits.

Because we do not sell or share personal information for advertising and do not use it for targeted advertising, there is nothing to opt out of in those categories.

Connecticut residents

If you live in Connecticut, the Connecticut Data Privacy Act gives you the right to:

To use a right, use the in-app controls above or email support@backd.dev. There is no charge. We will respond within 45 days; if we need longer (up to 45 more days), we will tell you why within the first 45 days.

Appeals. If we decline to act on your request, we will tell you why. You can appeal by replying to our decision or by emailing support@backd.dev with "Appeal" in the subject line. We will answer your appeal in writing within 60 days, saying what we did and why. If we deny your appeal, you can contact the Connecticut Attorney General to submit a complaint.


9. Children and teens

Backd is used by students, and we know some users may be under 13.

Children under 13

Teens (13 to 17)

Teens can use Backd. A few things are different:


10. International users

Backd is operated from the United States and stores data with U.S.-based infrastructure. If you use Backd from outside the U.S., your information will be processed in the U.S. Money stakes are offered only in the United States, with a US-issued card.


11. Changes to this policy

We will update this policy as the app changes and revise the effective date above. For material changes we will provide notice in the app or by email where appropriate.


12. Contact us

Anson Antony, the developer of the Backd app 1742 SW 38th Terrace, Gainesville, FL 32607 Email: support@backd.dev