Privacy Policy

Last Updated: September 14, 2026

Introduction

Commit Contracts (“Commit,” “we,” “us,” or “our”) built Commit as an accountability app: you set a goal, choose how you’ll prove you kept it, and an AI coach reviews the evidence you submit to decide whether you did. This Privacy Policy explains what information we collect through the Commit mobile application and any related services (together, the “Service”), why we collect it, who we share it with, and what control you have over it.

By creating an account or otherwise using the Service, you agree to the collection and use of information as described here. If you don’t agree with this Policy, please don’t use Commit.

We may update this Policy from time to time. We’ll update the “Last Updated” date above, and for material changes we’ll make a reasonable effort to notify you in-app before they take effect. Continuing to use Commit after a change means you accept the update.


1. Information We Collect

1.1 Account Information

Name, email address, and any profile information you choose to add (photo, display name), collected when you create an account.

1.2 Goal & Evidence Data

This is the core of what Commit does, so we want to be specific about it. Depending on how you configure a goal, we may process:

Apple Health (HealthKit). If, and only if, you set up a goal that uses Apple Health as its proof, and you grant permission when iOS asks, Commit reads the following from Apple Health for the period being graded: step count, walking and running distance, exercise minutes, active energy burned, flights climbed, workouts, sleep, and mindful minutes. That is the complete list.

Retention: evidence is deleted within 90 days, or immediately if you turn on privacy mode. We don’t keep a permanent library of your photos, videos, screen recordings, or location history. By default, submitted media is deleted from our storage within 90 days of being submitted. Every goal also has an optional privacy mode. With it on, the media is deleted as soon as a verdict (approved, rejected, or clarify) has been reached, rather than waiting out the 90 days. Either way, we retain only the grading outcome (e.g., “approved,” “missed,” date, goal ID) as part of your goal history, never the underlying media.

1.3 AI Coach & Chat Data

Commit’s AI coach is powered by a third-party AI provider. When you chat with the coach, we process:

This data is sent to that provider to generate the coach’s responses. It is not used to train their models under our agreement with them (see Section 3).

If you tell the coach you may be about to hurt yourself, Commit shows you crisis-line information and the coach stops coaching. What we detect and what we do about it is written out in full in our AI Safety & Self-Harm Protocol.

1.4 Subscription & Payment Data

If you subscribe to premium through the Apple App Store, Apple processes the payment and we never see your card details; we receive only a record that the subscription is active, so we can unlock the features it covers.

Where a payment is processed by us rather than by Apple, we use Stripe, Inc. We store a Stripe customer token and limited metadata (for example card brand and last four digits); we do not store your full card number. Stripe’s own privacy policy governs how they handle the payment details you give them directly.

1.5 Device & Usage Data

Device type, operating system version, app version, crash logs, and general usage analytics (e.g., which features you open) to keep the app running and help us fix bugs.

1.6 Social & Friend Data

If you add friends within Commit, your friends can see the goals you’ve chosen to share and their status (on track / missed). We do not share your evidence media with friends; only status.

1.7 Support Chat Data

If you contact us through the in-app “talk to the founder” support chat, or if the AI coach files a bug report on your behalf, that conversation and any attached context (e.g., the relevant goal and evidence) is stored so our founder can review and respond to it.

1.8 Push Notification Tokens

If you enable push notifications, we store a device token (via APNs/FCM) to deliver alerts about grading results, coach messages, and missed deadlines. You can disable this in your device settings at any time.

1.9 App Blocking (Screen Time)

We never learn which apps you block. App Blocking goals use Apple’s Screen Time framework, which hands Commit opaque, device-local tokens and withholds the app names even from us. Your selection stays on your device and is never uploaded.

What does reach our servers is the shape of the rule, not its subject: how many apps and categories you picked (for example, “3 apps and 1 category”), the daily limit and which days it runs, how many emergency opens you allowed and for how long, and any exception wording you wrote yourself. When a missed goal triggers a lock, we store which goal caused it and the sentence shown on the block screen. None of that identifies an app.

1.10 Website Cookies & Analytics

This one is about commitcontracts.com rather than the app. Our marketing pages use PostHog, a product-analytics service, to count page views, see which links people follow, and catch browser errors. PostHog stores an identifier in your browser so that four pages read in one visit are counted as one person rather than four.

PostHog also records a replay of the marketing page you are looking at — the layout, what you click, how far you scroll — so we can see where the site confuses people. Input fields are masked before anything is stored, so what you type into a form, including an email address or a password, is never captured.

None of this runs on your account pages. /app and /account show real goals, evidence, charges and payment settings; analytics is switched off entirely there, so none of it reaches a third party.

We also set one cookie of our own, commit_region, which records only the country your request arrived from, so we know whether we are required to ask you before any of the above starts.

If you are in the EEA or the UK we ask first, and nothing is stored until you accept. Everywhere else analytics runs by default. Either way you can change your mind at any time using the Cookie choices link at the foot of any page; declining stops it immediately, not just on the next page.


2. How We Use Your Information

We use the information above to:

We do not use your evidence media, location data, or chat content for advertising, and we do not sell your personal data.


3. Who We Share Information With

We share information only as needed to run the Service:

We do not sell your personal data to third parties, and we do not share evidence media or chat content with advertisers.


4. Data Retention

If you delete your account, we delete your personal data and remaining evidence from live systems within 30 days, and from backups within 90 days, except where we’re legally required to retain something longer (e.g., financial records).


5. Security

We use industry-standard safeguards to protect your data, including encryption in transit (TLS) and at rest, access controls limiting who at Commit can see raw evidence or chat data, and regular review of our security practices. No system is perfectly secure, but we take this seriously given the sensitivity of evidence media and payment information.


6. Your Choices & Rights

Regional Rights

If you’re in the EEA, UK, California, or another jurisdiction with data-protection laws, you may have additional rights: access, correction, deletion, portability, restriction of processing, or objection. Contact us at the address below to exercise these.

California Residents

You may request disclosure of what categories of personal data we’ve collected and shared, and request deletion, subject to legal exceptions.


7. Children’s Privacy

Commit is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we’ll delete it.


8. International Data Transfers

We’re based in the United States and process data here and wherever our service providers (Stripe, Google/Firebase, our AI provider, Apple, PostHog) operate. Where required for transfers from the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards.


9. Third-Party Links

The Service may link to third-party sites or services (for example a payment processor’s hosted pages) not covered by this Policy. Review their privacy practices separately.


10. Contact Us

Questions about this Privacy Policy:

Commit Contracts
support@commitcontracts.com