Privacy Policy

Effective 2026-07-22 · Contact: [email protected]

DONIT is a social challenge app: you create challenges, log your progress, and friends verify your proof. This page explains what data that requires and how it's handled.

What we collect

We do not collect your location, your contacts, health data, or any payment information — DONIT has no payments of any kind.

How we use it

To run the core product: creating challenges, verifying logs, computing streaks and XP, and sending notifications. For challenges without a friend to verify them (solo / AI-checked mode), your proof photo may be reviewed by an automated AI model as a fallback check — this is a product feature, not profiling or advertising, and it is never the primary way a challenge gets verified.

Who else sees it

We use a small number of infrastructure providers to run DONIT. None of them may use your data for their own purposes — they process it only to provide the service to you:

We do not sell your data or use it for advertising. Crash diagnostics, described next, are the only technical monitoring DONIT does, and they identify you personally in no way.

Crash reports

DONIT sends crash and error reports to Sentry by default, so we can find and fix bugs. A report contains your app version and build, OS version, device model, locale, timestamp, and the technical stack trace of the crash. It never contains your email, display name, Supabase account id, or anything you've written or photographed in the app — challenge notes, logs, and proof photos are never included. You can turn crash reporting off at any time with the toggle on the Profile tab; once it's off, no further reports are sent.

Sentry is a data processor for this data only, not an owner of it: it doesn't use crash reports for its own purposes, doesn't sell them, and doesn't use them for advertising or tracking. Our Sentry organization runs in Sentry's EU region, so this data is processed and stored in Germany. Sentry's default retention for this data is 30 days, after which it's deleted.

What other users see

Your username, display name, avatar, bio, and level/badges are visible to other users as part of the social product. A proof photo is visible only to people who can verify that specific log — your fellow challenge participants, or nobody at all for a solo challenge.

How long we keep it

Log, verification, and XP history is kept as a permanent record, since your streaks and level are computed from it — the same way a fitness app keeps your activity history. You can ask us to delete your account and this data at any time (see below).

Your rights

You can ask us to access, correct, or delete your account and its data by emailing [email protected]. We will act on deletion requests within 30 days.

Children

DONIT is not directed at children under 13, and we do not knowingly collect data from anyone under that age.

Changes

If this policy changes in a way that matters, we'll update the effective date above.