Backd Privacy Policy
Effective date: October 1, 2026 · Last updated: October 2, 2026
Backd is an accountability app. You set goals, submit proof (a photo or a written note) that you did them, and stay accountable to buddies or a small private group you choose. This policy explains, in plain language, what personal information Backd collects, why, who it is shared with, how long it is kept, and the choices and rights you have. It describes Backd's actual behavior — not aspirations. This policy is provided for transparency and may be updated as Backd evolves.
Backd is provided by Anson Antony, the developer of the Backd app, located at 1742 SW 38th Terrace, Gainesville, FL 32607 ("Backd", "we", "us", "our"). Backd is an app made by an individual, and business is done in his legal name. If you have questions, contact us at support@backd.dev.
Our guiding rule is private by default: your data is visible to you and only to the specific buddies or group members you choose to be accountable to. There are no public profiles, no global feed, and no discoverable groups.
1. The short version
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under California and similar U.S. state laws). We never have.
- We run no advertising, and we have no third-party advertising or attribution SDKs in the app. We use one product-analytics service, PostHog, to count a small set of named steps (for example "created a first goal" or "reached a 3-day streak") so we can see where people get stuck — never your goal titles, notes, proof or messages, no screen recording, no tap tracking, and no location. Crash reporting is separate and carries no account id. See Section 2, "Product analytics" and "Crash and error diagnostics".
- Every outside company that touches your data does so only as our service provider / processor under contract, to perform a function of the app (e.g. store your data, send a push, or automatically screen an uploaded proof photo for sexual or violent content before a buddy can see it).
- The highest-sensitivity flow is the optional AI proof / Coach feature: when it is used — by you, or by your buddy on your proof if you have allowed AI checks — your proof image, goal text, your note, and/or your free-text chat are sent to our AI service provider. For an Apple Health check-in the note is only the verdict "Verified via Apple Health." — no step count or other health value is sent. See Section 5.
- Money stakes are optional and only for adults 18+ in the United States. Trial stakes: no card, never charged. Once money stakes are live, if you back a goal with your own money you enter your card on a page run by our payment processor, Stripe, and Stripe charges it only under our Terms. Backd itself never receives or stores your full card number. See Section 2, "Money stakes and payment details".
- Precise location and Apple Health are used only after you opt in on a separate consent screen, and only for the proof types you choose (Sections 2 and 3). Location goals can't use a place near a health-care provider.
- Apple's age signal is used only for age limits and is never stored (Section 2, "Age range from Apple").
- You can delete your account and all associated data from inside the app at any time (Settings → Delete account). If you used money stakes, the records of your stakes and charges are kept after that, no longer linked to your account but still holding Stripe's identifiers, so they are not anonymous (Section 6).
2. Information we collect, the source, and why
We collect the categories below. The source is you (information you provide or generate in the app) and your device, unless otherwise noted.
Account information
- What: your email address and a display name. If you use Sign in with Apple, we receive the name and the email (which may be Apple's private relay address) you choose to share, and we keep a token from Apple only so that deleting your account can revoke Backd's access to your Apple Account.
- Why: to create and secure your account and identify you to buddies you invite.
- Referral code (optional): if you enter one when you sign up, it is saved with your account and can't be changed later. We count sign-ups and subscriptions per code so we can pay the person or partner who shared it. They get totals only, never your name, email or account.
Device time zone
- What: your device's IANA time zone name (for example,
America/New_York). Stored on your profile. - Why: so a "day" means *your* day. Check-ins, streaks and deadlines used to be stamped in UTC, which put an evening check-in on tomorrow's date for anyone west of UTC and made the whole screen read a day out. This is the *name of a zone*, not a location: it is coarse (hundreds of zones worldwide, many spanning whole continents), it is not GPS, and it is not the precise location described below. It is never shared with buddies or any third party beyond our backend host.
- When: written when you sign in and whenever your device's zone changes. Until it is set, Backd falls back to UTC.
Birth year and legal-acceptance records
- What: a birth year (a 4-digit year only — never your full date of birth), and a record of when you accepted these Terms and this Privacy Policy (document, version, timestamp).
- Why: the birth year is an age gate — accounts with a stated birth year under 13 cannot be created (see Section 9). Every account provides it regardless of sign-in method: at email sign-up directly, or on a one-time required screen for Sign in with Apple (which doesn't supply a birth year itself). The acceptance record is our evidence of which policy version you agreed to.
- How it's asked: with a year picker that has no preset value and gives no hint about any age limit.
- If the year shows you are under 13: the birth year you entered is discarded and never sent anywhere, and the app saves a flag in your device's Keychain so sign-up can't simply be tried again on that device. If Sign in with Apple had already created an account, that account is deleted with its data automatically within 72 hours (you can also delete it at once, after a confirmation; an email to support@backd.dev before then can stop a mistake). Until the age question is passed and Apple's age check (where your iOS has it) has finished, Backd sends no analytics or crash-report identifier; if the analytics SDK had already started, its id is reset when someone is blocked.
Age range from Apple (iOS 26 and later)
- What: on iOS versions that offer Apple's Declared Age Range feature, Backd asks Apple which age range you are in (for example under 13, 13 to 15, 16 to 17, or 18 or older): when you sign up, and each time the app starts where Apple says age rules apply to you (elsewhere, once, and again when you open the stakes screen). On older iOS versions this is skipped.
- Why: only for age limits. If Apple says you are under 13, the account is blocked at once and deleted with its data within 72 hours; the app says so, and an email to support@backd.dev before then can stop a mistake. If Apple says you are under 18, you can't turn on a money stake, any stake you have turns off, and any stake charge not yet made is cancelled, whatever birth year you entered. One exception: if the account already had an adult birth year and was more than 30 days old when a device first reported it as under 13, we don't delete it. That device's Apple Account is probably a child's, not the account holder's, so Backd is blocked on that device and money stakes are turned off.
- What is kept: the age range itself is never stored, on our server or on your device. It is used in memory and then discarded. Our server keeps only which restriction applies (under 18: stakes off; under 13: the account is being deleted) and when it was set. A stake turned off because of it is recorded in the stake ledger only as "restricted", without saying why. The under-18 restriction is cleared when Apple's signal later says you are 18 or older; all of it is deleted with your account. For an automatic deletion we keep only the fact that an account was deleted and when: not whose, and not any age.
- Parental consent and App Store records (Texas and similar laws): where Apple says a parent's consent is needed for a significant change to the app (Texas minors today), the app asks the parent through Apple, and a minor can't use the app until the parent approves. So Backd can act on a parent withdrawing consent, the app registers its App Store transaction id (an Apple identifier for this download of the app) with our server, linked to your account. When Apple tells us a parent withdrew consent, every Backd account linked to that download is restricted: the app offers only signing out or deleting the account, stakes turn off, and any stake charge not yet made is cancelled. If the withdrawal reaches us before the app has registered that download, we keep the download id (no account and no age) for up to 2 years and apply the restriction when an account registers it. We keep the App Store transaction id link and the restriction times while your account exists, and delete them with your account. No age data is kept for this.
Goals, schedules, and check-ins
- What: the goals you create, their titles and schedules, and your check-in history and outcomes. Goal titles can be sensitive because you choose what they say.
- Why: this is the core function of the app.
Proof content (user-generated content)
- What: photos or screenshots and written notes you attach to a check-in. This is freeform content you create.
- Why: to record and let an assigned buddy review that you did the thing.
- Privacy measures: proof photos are re-encoded to a fresh JPEG on capture, which strips embedded EXIF/GPS metadata before the image is uploaded. Proof media is stored in a private storage bucket that is never public, and is reachable only through short-lived signed URLs (currently expiring in about 10 minutes; about 2 minutes for the server-side AI fetch). Only you and the buddy assigned to review that goal can generate a link to a given proof file.
- Automatic safety screening: before a buddy can see a proof photo, it is automatically screened for nudity/sexual content, gore and violence by our image-safety provider, Sightengine (see Section 5). Only the image is sent — no name, email, goal, note or account id — and no face or age analysis is performed. Sightengine deletes the image after checking it. A photo that passes becomes visible to your buddy; a photo that is flagged is held — kept, hidden from your buddy — for a person to review. It is not deleted automatically.
Phone number (only if you opt into SMS reminders)
- What: the phone number you provide.
- Why: to send SMS reminders you asked for. See Section 5 (Twilio).
- Status: SMS reminders are not enabled in the current release. No phone number is collected unless and until SMS is turned on and you opt in.
Precise location (optional, only for location proof)
- What: a single GPS point captured once, at the moment you tap to check in for a location-based goal (or when you tap "Use my current location" to set a goal's place — see "Goal places" below). We request foreground location permission only; we never track your location in the background.
- How it is stored: the captured coordinates are rounded to about three decimal places (roughly 110 meters) and saved as the human-readable text note for that check-in (for example, "Checked in near 40.713, -74.006"). Full-precision coordinates are never stored.
- Goal places: if you set a goal's place with "Use my current location," Backd reads your location once at that moment and stores that point with the goal, rounded to about four decimal places (roughly 11 meters). When you check in for a goal that has a place set, the check-in note records your approximate distance from that place (for example, "~37 m") rather than your coordinates, and that note is what your buddy sees.
- Why: so an assigned buddy can corroborate you were at a place (a gym, a library) without your exact spot — like a home address — being exposed.
- Note: Although we coarsen the value before storing it, the device reading we take at check-in is a precise reading, so we describe this honestly as precise location collection. It is sensitive data.
- Your consent first: before Backd first reads your location, it asks on its own screen, separate from any other permission: what is read, why, and what is stored, with a real "Not now". Your answer is recorded with its version. You can withdraw it at any time in Settings on your iPhone (turn off Location for Backd), and Backd stops reading your location.
- Staked location goals: for a goal backed by a stake, your phone sends its reading to Backd's server, which checks it against the goal's place. The server keeps only the result and the distance (and the reading's accuracy), not your coordinates.
- No health-care places: when you set or change a goal's place, Backd sends the place's coordinates to Apple Maps to check whether the place itself is a health-care provider: anything within 100 m that Apple Maps lists as a hospital or pharmacy, or whose name shows a clinic, urgent care, doctor, dentist, therapist, medical or health center, lab or similar. Such a place is refused, and you also confirm "This place isn't a health-care provider." We save the result with the goal's place: whether it passed, when, the point checked, and your confirmation. A place saved before October 1, 2026 is checked the next time it's used for a location check-in. See the Consumer Health Data Policy.
- Typed place lookups: if you set a goal's target place by typing an address instead of using your current location, the text you type is sent to your phone's built-in map service (Apple on iPhone, Google on Android) to turn it into coordinates. Your device location is not read for this, and Backd stores only the resulting place for the goal.
Health data (optional, read-only, on-device only)
- What: if you choose Apple Health as a goal's proof and allow it, Backd reads today's steps and workouts from Apple Health, on your device, when you verify that goal's check-in. You can connect it, and turn it off, in Backd under Settings → Connected apps → Apple Health.
- What is saved, and who sees it: only the result, "Verified with Apple Health", is saved with that check-in and shown to the buddy who reviews it. It records that Apple Health confirmed the check-in, not what it measured. Your step counts and workouts stay on your iPhone: they are shown to you on the check-in screen and are never sent to Backd, your buddy or anyone else. Apple Health check-ins are never sent for an AI check. We never write to Apple Health and never read medical records.
- Your consent first: the Apple Health verdict is consumer health data, which is sensitive. Before Backd first reads Apple Health, it asks on its own screen, separate from any other permission, with a real "Not now", and records your answer with its version. You can withdraw it at any time in Backd (Settings → Connected apps → Apple Health) or in the Health app (your profile → Privacy → Apps → Backd), and Backd stops reading Apple Health.
Buddies, groups, and invites
- What: the buddies/groups you connect with, which goals you assign a buddy to review, and the invites you send. An invite is a link with a short code that you share yourself, so we don't collect the other person's email address. An older invite that you addressed to an email keeps that address until it expires.
- Why: to operate the accountability relationships that are the point of the app.
- What buddies see: a buddy sees only the proof for goals you assign them, plus whatever you choose to expose in your visibility settings (e.g. streak numbers, trophies, recent activity, shared-goal titles). Your stakes, journal/reflection text, exact location, raw health data, connected-account tokens, and unshared goals are never shown to buddies or groups.
Notifications
- What: a device push token, and the text of notifications we send you.
- Why: to deliver reminders and accountability notifications you enable. Lock-screen copy is kept generic (no money figures, no shaming).
- Note: remote push is off by default and opt-in.
Subscriptions (Backd Premium)
- What: your subscription state (which plan, active/expired). The purchase itself runs through Apple In-App Purchase; for a subscription, no card or financial-account data reaches Backd. We use RevenueCat to validate the receipt and map the subscription to your account; the identifier shared with RevenueCat is your Backd (Supabase) user id.
- Status: Backd Premium is a live, paid auto-renewable subscription (monthly or yearly). Free-tier features remain fully usable without subscribing; Premium unlocks additional depth and never hides or deletes data you already created if you don't subscribe or a subscription lapses.
Money stakes and payment details (optional; adults 18+ in the US only)
Money stakes are not available in the current version of the app. Nothing in this part is collected from anyone until they are offered. It describes what Backd would collect then.
- Who this applies to: only people who choose to back a goal with their own money. Money stakes are not available to anyone under 18 (your birth year must show you are 18 or older, you must confirm it again each time you turn a stake on, and stakes are refused and turned off if Apple's age signal says you are under 18) and not available outside the United States (the card must be issued in the US, and the option to add one appears only in the US App Store). Symbolic stakes, which are self-tracked and never charged, collect nothing described here.
- Your card (only once money stakes are live): you enter your card on a secure page run by Stripe, our payment processor, not in the Backd app. Backd never receives or stores your full card number or security code. Backd stores only: the Stripe customer ID, the payment-method ID, the card brand, the last four digits, the expiry month and year, and the country where the card was issued.
- Your stakes and charges: for each goal you back, the amount, when you turned the stake on and off, who checks the goal (your buddy's account, or Apple Health or location proof), the time zone its days are counted in, for a location-checked stake the result of each check Backd's server makes against the goal's place (whether you were there and how far away, not your coordinates), and a copy of the exact agreement you confirmed (with its version, the app version and the time). For each missed check-in on a staked goal: the notice, the amount, its status (for example pending, appealed, charged, refunded, or cancelled), any appeal you file (your reason and any late proof you add), refund requests and our decisions, and Stripe's identifiers and error codes for the payment, refund or dispute. We also record the time you confirmed you are 18 or older.
- Days under review: when a staked check-in couldn't be decided because its data didn't arrive or Backd failed (for example an Apple Health read that came back empty, a location error, a failed proof upload, the app not reaching our server, or an outage), we record what was tried, when, the kind of failure, and our review decision. A person at Backd reviews the day; it is never counted as missed automatically. We don't record any health value or your coordinates for this.
- Stake emails: when you turn a stake on, we email you a copy of the agreement you accepted (its version, the amount, the goal, how to turn the stake off, and support@backd.dev). When you turn a stake off, we email you a confirmation that says whether today's check-in still counts. These go to the email address on your account, through Resend. Our outbox keeps a copy of each stake email for 30 days, then deletes it; the agreement itself stays with your stake record.
- Why: to let you back a goal with money; to charge you only under the rules in our Terms; to send you notices, copies of your agreement and confirmations, and handle appeals, reviews, refunds and disputes; to prevent duplicate or fraudulent charges; and to keep the financial records that tax and accounting law require.
- Who sees it: you. Your stakes, amounts and charges are never shown to buddies or groups. Stripe receives what is listed in Section 5.
- Trials and demo accounts: when money stakes run as a trial, or on an App Review demo account, no card is collected or charged. The stake records above are still kept (including the trial agreement you confirmed and the amount each miss would have cost). A stake from the trial turns off when money stakes go live; it is never charged.
Connected-account tokens (optional integrations)
- Google Calendar: if you connect it, we store a Google access token privately and linked to your account. We use it, at your request, to read upcoming events you can turn into goals and to add your goals to your calendar. We do not retain your calendar contents beyond performing those actions.
- Canvas LMS: if you connect it, you provide your school's Canvas URL and your own personal access token, stored privately and linked to your account. We use it only to read your upcoming assignments so you can turn one into a goal (read-only; nothing is written back to Canvas, and nothing is created without your confirmation).
- Disconnecting either integration deletes the stored token. These tokens are never shown to buddies or groups.
Screen Time / Focus Vault (optional, iOS)
- The set of apps you choose to shield stays on your device as opaque system tokens Backd cannot read. We store only a count (e.g. "12 apps") and a label you type. Nothing identifying which apps you shield leaves your device.
Crash and error diagnostics
- What: when Backd hits an error, it reports the error's type, a redacted message, the stack trace (function/file/line — code locations, not your data), the app version, and the device model and OS version that the reporting SDK collects automatically.
- What is stripped before anything is sent: the message is run through a redactor that removes email addresses, phone numbers, access tokens and JWTs, any URL (which is what keeps signed proof-image links out), and long opaque strings. The raw error object is never handed to the SDK — a fresh error carrying only the redacted text is sent in its place, so nothing unredacted can escape even if the SDK's own configuration changes later.
- What is never attached: your account id, your email, your name, your goal titles, your notes, and your proof content. The SDK's "default PII" collection is explicitly turned off, and the only labels attached are fixed internal tags naming the code path that failed.
- Why: to find and fix crashes. It is not analytics — nothing is recorded when the app is working.
Product analytics (usage events)
- What: a fixed list of named events when you reach a step in the app — for example first opening the app, signing in (and whether by email or Apple), finishing onboarding, viewing or closing the subscription screen, starting a trial or subscribing (which plan), creating your first goal, your first proof or approval, inviting or accepting a buddy, reaching a 3- or 7-day streak, answering the notification-permission prompt (allowed or not), and when the app asked iOS to show its rating prompt. Each event carries only fixed labels, numbers and yes/no values, plus the app version, your device's operating system and version, and its screen size.
- Linked to you: events are tied to your Backd user id once you sign in. Nothing carrying an analytics or crash-report identifier is sent before the age question at sign-up has been passed; if someone is blocked there, the app resets the analytics id. When you sign out, the app forgets your user id and starts a new random id for this install. No email, no name, no goal titles, notes, proof content or messages, no location, no health data, and no contacts are ever sent.
- What is off: no session recording or screenshots, no automatic screen-view or tap tracking, no location (IP-based location lookup is disabled), no advertising identifier, and no cross-app tracking. Backd does not use this data to track you across other companies' apps or websites.
- Why: to understand which parts of the app help people get started and keep going, and to fix the steps where they drop off. It is not used for advertising. PostHog is set to discard the IP address of the connection, so it is not stored with events.
- Your choice: you can turn usage analytics off in Backd: Settings → Usage analytics → Share usage analytics. From then on the app sends no analytics events from this device, and the analytics id it used is reset.
What we do not collect
- No advertising identifiers, no cross-app tracking, no browsing or search history.
- No device address book / contacts.
- No full card numbers, card security codes or bank-account data held by Backd. If you use money stakes, your card number is entered on Stripe's page and held by Stripe; Backd keeps only the limited card details listed in "Money stakes and payment details" above.
- No ad-network or attribution data — none of those SDKs are in the app. Nothing records which screens you view, which buttons you tap, or how long you use Backd; the only usage data is the short list of named events in "Product analytics" above.
- Crash diagnostics are collected. See "Crash and error diagnostics" above.
3. Sensitive information
Some of the above is sensitive. We call it out plainly:
- Precise geolocation — a single foreground point at check-in, coarsened before storage (to about 110 m; a goal place set from your current location is stored at about 11 m, and a check-in against it records only your approximate distance from it), used only for location proof. Never sold, never shared for ads, never tracked in the background.
- Health information (consumer health data) — read on-device only; neither raw samples nor any health value (step count, workout count) leaves the device. Only the result, "Verified with Apple Health", is stored with the check-in and shown to the buddy who reviews it. See the Consumer Health Data Policy.
- Phone number — only if you opt into SMS (not enabled today).
- Your proof photos and notes and goal/journal text — freeform content you create that may reveal sensitive things about you.
- Payment details — only if you use money stakes. Backd holds just the card brand, last four digits, expiry and issuing country plus Stripe's identifiers; the full card number and security code stay with Stripe and never reach Backd.
We use sensitive information only to provide the features you turned on. We do not use it to infer characteristics about you and do not use or disclose it for any purpose that would require a right to limit under U.S. state privacy laws.
We ask before we use it. Precise location and Apple Health each have their own consent screen, shown before Backd first uses them and not bundled with anything else. Connecticut's privacy law, like Washington's health-data law, requires that opt-in consent for sensitive data. Your answer is recorded with the version of the screen you saw. You can withdraw either consent at any time in Settings on your iPhone, and Backd stops collecting that data.
4. How and why we use your information
We use personal information to:
- create, secure, and operate your account;
- run the core loop — goals, check-ins, proof, and buddy/group review;
- verify location- and health-based check-ins (as described above);
- send the notifications and reminders you enable, and account emails such as password resets;
- provide the optional AI proof/Coach features when they are invoked with your permission (Section 5);
- process subscriptions if you buy one;
- if you turn on a money stake: charge your saved card only as our Terms allow, email you a copy of your agreement and a confirmation when you turn a stake off, send you the notice before a charge, review days that couldn't be decided, handle your appeals, refunds and disputes, prevent duplicate or fraudulent charges, and keep required financial records;
- apply age limits, using your birth year, Apple's age signal and a parent's consent through Apple (Section 2); we use age data for nothing else;
- refuse a goal place near a health-care provider (Section 2, "Precise location");
- maintain security, prevent abuse (including automatically screening uploaded proof photos for sexual or violent content before a buddy can see them), enforce rate limits, and debug; and
- comply with law.
We do not use your information for advertising, for building advertising or marketing profiles, or to train our own general-purpose models. (For third-party AI vendor training, see Section 5.)
5. Who receives your information
We do not sell or share your personal information, and we use no ad networks. The companies below are service providers / processors that receive only the data needed to perform a specific function for us. Each is named with exactly what it receives. Each of them is bound, by its contract or terms with us, to give your information the same or equal protection as this policy, and to use it only to provide its service to Backd.
| Recipient | What it receives | Purpose | May it use your data to train AI? |
|---|---|---|---|
| Supabase (our backend: Postgres, Auth, Storage, Edge Functions) | All of the data described in this policy — account info, goals, proof media, check-in/location notes, phone number (if SMS on), connected-account tokens, push records, message/proof content | Hosts and runs the entire app | No |
| AI service provider (currently Hugging Face Inference Providers, which routes the request to Featherless AI running the open Qwen3-VL-8B-Instruct vision model) — used only by the optional AI proof review and the Coach chat | The raw proof image, the goal text, the proof instructions you set, and your note (AI proof review), plus the goal's proof type and the check-in's deadline and submission time; and your free-text Coach chat messages plus your own goal/miss context (Coach). For a location check-in the note is the location note (a point rounded to about 110 m, or the place's label and your approximate distance from it); for an Apple Health check-in it is only "Verified via Apple Health." The image is fetched server-side via a short-lived signed URL and sent to the provider's API. | Returns an advisory proof result, or a coaching reply | We use the providers strictly as service providers to return the result. Neither keeps the content of the request or trains on it (see the call-out below and Section 6). |
| Sightengine (image-safety screening) | Each uploaded proof photo — the image only. No name, email, goal, note or account id is sent. | Automatically screens every uploaded proof photo for nudity/sexual content, gore and violence before a buddy can see it | Not kept: Sightengine deletes each image after checking it, and Backd uses none of its features that keep images (human review, feedback, image lists). Training: not yet confirmed |
| Sentry (error reporting) | Crash and error reports: the error type, a redacted message, the stack trace, app version, and device model / OS version. No account id, no email, no name, no goal or proof content, no location and no health data — PII collection is disabled in the SDK and the message is redacted on-device before it is sent. No crash-report identifier is sent before the age question at sign-up is passed. | Find and fix crashes | No |
| PostHog (product analytics) | The named usage events in Section 2, "Product analytics", your Backd user id (or, when no one is signed in, a random install id; never before the age question at sign-up is passed), the app version, and your device's OS, OS version and screen size. No email, no name, no goal, note, proof or message content, no location and no health data. Session recording and IP-based location lookup are off. | Understand where people get stuck in the app, in aggregate | No |
| Apple Maps | When you set or change a goal's place: the coordinates of that place (if you set it with "Use my current location", that point is where you were) | Look for health-care places nearby, so a goal place is never one (Section 2, "Precise location") | Backd sends no account details with the request; Apple handles map requests under its own privacy policy. |
| Twilio (only if SMS reminders are ever enabled — currently off) | Your phone number and goal titles needed for the reminder text | Deliver SMS reminders you opted into | No |
| Expo push service → Apple (APNs) | Your device push token and the notification text | Deliver push notifications | No |
| Resend | Your email address; and, for stake emails, the goal's title, the amount and the text of your stake agreement or turn-off confirmation | Deliver account emails, such as password resets, and stake emails (a copy of your agreement when you turn a stake on, and a confirmation when you turn one off) | No |
| RevenueCat | Your Backd user id as the subscription identifier, plus subscription state. RevenueCat also receives Apple's App Store notifications for the app and passes them on to Backd, including Apple's notice that a parent withdrew consent. | Validate purchases and map your subscription to your account; pass on Apple's notices | No |
| Apple In-App Purchase | Handles the purchase itself; no card data reaches Backd | Process subscription payments | No |
| Stripe (payment processor — only if you turn on a money stake) | Your email address (so Stripe can send your receipts), the card details you enter on Stripe's own page, your Backd user id, and, for each charge, the amount and internal ids for the charge and goal. Backd never sends or receives your full card number. | Save your card, charge money stakes under our Terms, confirm payments your bank wants checked, issue refunds, email receipts, and prevent fraud | Stripe does not receive your goals, proof or notes. It uses payment data to run its own fraud-prevention systems under its own privacy policy. |
| Google Calendar API (only if you connect it) | Your Google access token and the calendar events/goals involved in the action you requested | Read events you turn into goals; add goals to your calendar | No |
| Canvas LMS (only if you connect it) | Your Canvas URL and personal access token; reads your assignments | Read assignments you turn into goals | No |
The AI proof / Coach feature is the highest-sensitivity flow in Backd. When someone taps "Run AI check" on your proof — you, or the buddy reviewing it — your proof photo, goal text, proof instructions, and note are sent to our AI service provider, but only if both that person and you have allowed AI checks (turning AI proof review off in Settings withdraws your permission). Apple Health check-ins are never sent for an AI check. When you chat with the Coach, your free-text messages are sent. These features run only when someone explicitly invokes them — the AI check never runs on its own, although every uploaded proof photo is separately and automatically screened by our image-safety provider, Sightengine, before a buddy can see it (image only; see the table above) — and the AI result is always advisory: a human (you or your buddy) makes the real decision. We send only what is needed to return the result, and use the providers strictly as service providers. The request goes to Hugging Face, which routes it to Featherless AI. Hugging Face does not store request or response bodies and does not train on user data; its debugging logs are kept for up to 30 days and contain no user data. Featherless AI does not log or store prompts or completions, and keeps only usage counts. Neither keeps your photo, goal text or note after returning the result. If you'd rather not have this content processed by an AI provider at all, simply don't use these two optional features — Backd works fully without them.
Other disclosures. We may disclose information if required by law, to respond to lawful requests, to protect the rights, safety, or property of users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this policy or notify you).
We disclose personal information to these recipients as service providers only. Because there are no ad SDKs, and our analytics provider processes usage events only on our behalf, there is no "sale" or "share" of personal information for advertising purposes.
6. How long we keep your information (retention)
| Category | Retention |
|---|---|
| Account info, goals, check-in history | Kept while your account is active; deleted when you delete your account |
| Crash and error diagnostics | Kept for the retention window configured on the error-reporting project (Sentry's default is 90 days for errors). They contain no account identifier, so they are not linked to you and cannot be retrieved by an account-level request. |
| Proof media (photos) | Deleted once your proof has been reviewed. An approved photo is deleted shortly after the decision (typically within 30 minutes); a photo that was sent back is kept for 48 hours so you can appeal or re-submit, then deleted. Your Proof media retention setting is the outside limit for a photo that nobody ever reviews: Never store media (0 days) means the photo is never uploaded at all — only your note is sent — and 30, 60, or 90 days is the point past which the photo is purged whether it was reviewed or not. In every case your check-in record and the review decision remain — only the image is deleted. You can also delete all proof media at any time without deleting your account. Exception — photos held for safety review: a photo that the automatic image-safety screening flagged is kept, hidden from your buddy, for a person to review. While it is under review it is excluded from this schedule and from "Delete all proof media", and if it is reported under 18 U.S.C. § 2258A it is preserved for as long as that law requires (one year). |
| Location check-in notes | The coarsened text note lives with the check-in and is deleted when the check-in or account is deleted |
| Apple Health result ("Verified with Apple Health"; no health value) | Stored with the check-in; deleted with it or with the account |
| Phone number (if SMS on) | Kept while SMS is enabled; removed on account deletion |
| Push tokens | Kept while valid; invalid tokens are auto-disabled; removed on account deletion |
| Connected-account tokens (Google/Canvas) | Until you disconnect or delete your account |
| Sign in with Apple token | Until you delete your account, when Backd asks Apple to revoke it and deletes it |
| Subscription state | While the subscription/account is active |
| Saved-card details for money stakes (Stripe customer and payment-method ids, card brand, last four, expiry, issuing country) | Kept while a card is saved. The card details (brand, last four, expiry, issuing country) are deleted when you remove the card or delete your account. Deleting your account deletes the rest and removes your card and customer record from Stripe. |
| Money-stake payment ledger (each stake you turned on and the exact agreement you confirmed, each charge and payment with its amount, dates and status, refunds, disputes, and Stripe's identifiers) | Kept for 7 years (from when the charge or payment was made, or from when the stake was turned off), then deleted automatically. This is the only stake data kept that long. If you delete your account first, any charge not yet made is cancelled, and these records are kept no longer linked to your account. They are not anonymous: they still hold Stripe's identifiers, which can be traced to your card and payments. We keep them for tax and accounting, to handle disputes and chargebacks, and to establish or defend legal claims. |
| Appeal and refund text, stake notices and logs, days under review, attempt reports and the server's location checks (what you wrote in an appeal or refund request, our written decisions, the notices and log entries about your stakes, the record of each day under review and our decision, the reports of check-ins that didn't get through, and the result and distance of each staked location check) | 2 years, then deleted automatically; a day still under review is kept until it's decided. The ledger keeps only the amounts, dates, statuses and ids. Our outbox copy of a stake email is deleted after 30 days. A late-proof photo attached to an appeal follows the proof-media rules above and is deleted with your account. |
| Apple age-signal restriction, App Store transaction id link, automatic deletions | The age range itself is never stored. The restriction it causes and when it was set are kept until Apple's signal says you are 18 or older (under-18 restriction) or until the account is deleted. An account Apple says is under 13, or that the age screen turned away, is deleted within 72 hours; afterwards only the fact and the time of the deletion are kept. An account that never finished signing up (more than 30 days old, no birth year, the Terms never accepted, no goals or check-ins) is deleted automatically, keeping the same: the fact and the time. The link between your account and the app's App Store transaction id is kept while your account exists and deleted with it. A parent's withdrawal for a download no account had registered yet is kept (the download id only) for up to 2 years. |
| Health-care check for a goal's place (passed or not, when, the point checked, your confirmation) | Kept with the goal's place; deleted with the goal or your account. |
| Consent records (your answers on the location, Apple Health and AI-review consent screens, with their versions) | Kept while your account exists; deleted with your account. The agreement you confirmed for a stake is part of the payment ledger above. |
| Payment records held by Stripe | Stripe keeps its own records of your payments and refunds (including the email address a receipt went to) under its own privacy policy and legal obligations, even after your card or account is removed from Backd. |
| Proof photos checked by Sightengine | Not kept. Sightengine deletes each image after checking it. |
| Data held by AI vendors | Not kept. Hugging Face does not store request or response bodies and does not train on user data; its debugging logs are kept for up to 30 days and contain no user data. Featherless AI does not log or store prompts or completions, and keeps only usage counts. Neither trains on it. |
| Product analytics events (PostHog) | Kept for 1 year, then deleted. When you delete your account the app stops sending events for it at once; to have events already sent erased sooner, email support@backd.dev. |
| Account and stake emails sent via Resend | As a transactional log per Resend's retention |
We may retain limited records longer where required to comply with law, resolve disputes, or enforce our agreements.
7. How we protect your information
- Every record is protected by Row-Level Security: by default only you can read or write your own data. The only cross-user access is the narrow, relationship-scoped buddy/group review described above.
- Proof media lives in a private bucket, reached only through short-lived signed URLs, and only by you or the buddy assigned to that goal — and by the buddy only once the photo has passed the automatic safety screening.
- Proof photos are re-encoded to strip EXIF/GPS metadata before upload.
- Data is encrypted in transit.
- Connected-account tokens are stored in owner-only rows and are never shown to other users or written to logs.
No system is perfectly secure, and we cannot guarantee absolute security.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, and obtain a portable copy of your personal information, and to be free from discrimination for exercising these rights.
What you can do today, in the app:
- Delete your account and all associated data. Settings → Delete account runs a server function that removes your proof media from storage and cascades the deletion of all your database rows (goals, check-ins, stakes, trophies, buddy links, tokens, push records). If you used money stakes, it first cancels every charge not yet made and removes your saved card from Stripe; the records of your stakes and charges are then kept, no longer linked to your account but not anonymous (they still hold Stripe's identifiers), as Section 6 describes. Deleting your account also deletes the App Store transaction id link and any age-signal restriction. This cannot be undone.
- Remove your saved card (money stakes only) from the app at any time no charge is pending and no staked check-in day is still under way. Removing it turns off all of your money stakes.
- Export your data. Settings → Export data produces a JSON file of your data (goals, check-ins, proof metadata, reflections, preferences, relationships, and more) delivered through the device share sheet.
- Delete proof media only (Settings → Delete all proof media), keeping your check-in history. A photo held for safety review is kept until that review ends (see Section 6).
- Set proof-media retention, including "Never store media."
- Control what buddies can see, manage notification preferences, and disconnect Google Calendar or Canvas.
- Access and correct much of your information directly (your profile, goals, notes, settings).
- Withdraw your Location or Apple Health consent anytime in Backd's Settings → Location & Apple Health (recorded in our consent log), or turn off Backd's access in your device's Settings. Either way, Backd stops reading them.
Rights we cannot yet fully self-serve in the app (we honor them by request):
- Web-based deletion — deletion today is in-app only; there is no web deletion URL yet. To request deletion without the app, email support@backd.dev.
- Correction of anything not editable in-app — email support@backd.dev.
How to exercise a right: use the in-app controls above, or email support@backd.dev. We will verify your request using your account email and respond within the time required by applicable law. You may use an authorized agent where the law permits.
Because we do not sell or share personal information for advertising and do not use it for targeted advertising, there is nothing to opt out of in those categories.
Connecticut residents
If you live in Connecticut, the Connecticut Data Privacy Act gives you the right to:
- confirm whether we process your personal data, and access it;
- correct inaccurate personal data;
- delete personal data you gave us or that we hold about you (except records the law lets us keep, such as the stake payment ledger in Section 6);
- get a copy of your personal data in a portable format (Settings → Export data does this in the app);
- opt out of targeted advertising, the sale of personal data, and profiling used for decisions that have legal or similarly significant effects on you. We do none of these, so there is nothing to opt out of. If that ever changed, we would add a way to opt out before it started; and
- withdraw your consent to our use of sensitive data (precise location and Apple Health), as Section 3 describes.
To use a right, use the in-app controls above or email support@backd.dev. There is no charge. We will respond within 45 days; if we need longer (up to 45 more days), we will tell you why within the first 45 days.
Appeals. If we decline to act on your request, we will tell you why. You can appeal by replying to our decision or by emailing support@backd.dev with "Appeal" in the subject line. We will answer your appeal in writing within 60 days, saying what we did and why. If we deny your appeal, you can contact the Connecticut Attorney General to submit a complaint.
9. Children and teens
Backd is used by students, and we know some users may be under 13.
Children under 13
- Backd is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
- Every account collects a birth year (not a full date of birth) and blocks self-signup under 13. This applies regardless of sign-in method: email signup collects it directly; Sign in with Apple (which does not provide a birth year itself) routes the account through a mandatory, one-time screen before the app is reachable, requiring a birth year and blocking under-13 self-registration. The question is neutral: a year picker with no preset value and no hint about any age limit.
- When someone is blocked, the birth year they entered is discarded, a flag in the device's Keychain stops sign-up being retried on that device, and an account that Sign in with Apple had already created is deleted with its data automatically within 72 hours (or at once, if the person confirms). No analytics or crash-report identifier is sent before the age question is passed and Apple's age check (where available) has finished. If Apple's age signal says a user is under 13, the account is blocked at once and deleted with its data within 72 hours (unless it is an established adult account, as described in Section 2). An account the age screen turned away whose deletion request never reached us is still caught: an account that never finished signing up is deleted automatically after 30 days.
- If we learn we have collected personal information from a child under 13 without the required consent (for example, a birth year entered inaccurately), we will delete it. A parent or guardian can contact support@backd.dev to review, delete, or stop further collection of their child's information.
Teens (13 to 17)
Teens can use Backd. A few things are different:
- No stakes. Money stakes, including trial stakes, are only for adults 18 or older. A stake can be turned on only when the account's birth year shows the user is 18 or older and the user confirms it each time, and stakes are refused and turned off whenever Apple's age signal says the user is under 18, whatever birth year was entered. So Backd does not knowingly collect payment details from a minor.
- Apple's age signal. On iOS versions that offer it, Backd asks Apple for the user's age range and uses it only for these age limits. The age range is never stored (Section 2).
- Parental consent through Apple (Texas). Where Apple says the law requires a parent's consent (Texas today), the app asks a parent or guardian, through Apple, to approve significant changes to the app, such as stakes or a change in how Backd makes money. The app waits for that approval before a minor can use it, and if a parent withdraws consent, the account is restricted to signing out or deleting the account.
- Parents and guardians can contact us at support@backd.dev to ask what we hold about their teen, to have it deleted, or with any concern.
10. International users
Backd is operated from the United States and stores data with U.S.-based infrastructure. If you use Backd from outside the U.S., your information will be processed in the U.S. Money stakes are offered only in the United States, with a US-issued card.
11. Changes to this policy
We will update this policy as the app changes and revise the effective date above. For material changes we will provide notice in the app or by email where appropriate.
12. Contact us
Anson Antony, the developer of the Backd app 1742 SW 38th Terrace, Gainesville, FL 32607 Email: support@backd.dev