Your Data. Your Terms.

    Privacy Policy

    The Pact is built around one principle: your body is a non-negotiable asset. We apply the same standard to your data. This policy explains clearly and completely what we collect, why we collect it, and what we will never do with it.

    Effective date: [Date]
    Contact: support@thepact.io

    What We Collect

    A. Information you provide directly

    • Your email address, submitted when you request early access or create an account
    • Written justifications entered during SOS Bypass events within the app
    • Any communications you send to us via support@thepact.io

    B. Information generated by your use of the app

    • Recovery session data — sessions completed, skipped, snoozed, or rescheduled
    • Enforcement budget usage — snooze, skip, and reschedule counts per day
    • SOS Bypass events — frequency, timestamps, and written justifications
    • Integrity and adherence metrics — used to generate your Weekly Integrity Report
    • Kiosk Mode interactions — lock activations, durations, and outcomes
    • App configuration data — Pact Flow settings, session types, working window preferences

    C. Calendar data (if you choose to enable Calendar Sync)

    • Read-only access to your Google or Outlook calendar events marked as “Busy”
    • We read event timing and availability status only — we do not read event titles, descriptions, attendees, or any content within calendar events
    • Calendar data is used exclusively to place recovery sessions intelligently within your working day
    • Calendar data is processed locally on your device wherever technically possible and is never sold or shared with third parties

    D. Technical data

    • Device type and operating system version
    • App version
    • Crash reports and error logs (anonymised)

    What We Do Not Collect

    • We do not monitor your work activity, keystrokes, screen content, or productivity
    • We do not collect financial information — payments are processed by third-party providers
    • We do not read calendar event titles, descriptions, or attendee information
    • We do not build advertising profiles
    • We do not collect data from children under the age of 16

    Why We Collect It

    DataPurpose
    Email addressAccount creation, early access communication, product updates
    Recovery session dataGenerating your Integrity Dashboard and Weekly Report
    SOS Bypass eventsAccountability logging as part of the enforcement system you agreed to
    Calendar dataIntelligent session placement in Smart Mode
    Technical dataApp stability, bug resolution, performance improvement

    We collect only what is necessary to operate the enforcement system you have chosen to use. Nothing more.

    Legal Basis for Processing

    Where GDPR or equivalent regulation applies, we process your data under the following legal bases:

    • Contractual necessity — processing required to deliver the service you signed up for
    • Legitimate interests — app improvement, security, and fraud prevention
    • Consent — for calendar access, which you may revoke at any time through your device or account settings

    How Long We Keep Your Data

    Data TypeRetention Period
    Account and email dataUntil you delete your account
    Recovery session and integrity dataUntil you delete your account
    SOS Bypass logsUntil you delete your account
    Calendar dataNot stored — processed in real time and discarded
    Technical and crash logs90 days

    Who We Share Data With

    We do not sell your data. We do not share your data with advertisers.

    We work with a limited number of third-party service providers who help us operate the product:

    • Payment processors — for subscription billing (they receive only what is necessary to process payment)
    • Cloud infrastructure providers — for secure data storage and app delivery
    • Analytics providers — for anonymised, aggregated app performance data only

    All third-party providers are contractually bound to process your data only for the purposes we specify and to maintain appropriate security standards.

    We may disclose data if required by law, court order, or regulatory authority.

    Your Rights

    Depending on your location, you may have the right to:

    • Access the personal data we hold about you
    • Correct inaccurate data
    • Delete your data and account
    • Withdraw consent for calendar access at any time
    • Export your data in a portable format
    • Object to certain types of processing
    • Lodge a complaint with your local data protection authority

    To exercise any of these rights, contact us at support@thepact.io. We will respond within 30 days.

    Data Security

    We apply industry-standard security measures including encryption in transit and at rest, access controls, and regular security reviews. No system is completely immune to risk. If a breach occurs that affects your data, we will notify you in accordance with applicable law.

    Calendar Access & Revocation

    Calendar Sync is optional. If you enable it, you can revoke access at any time by:

    • Disconnecting the integration within the app under Settings
    • Removing The Pact's permissions directly in your Google or Microsoft account settings

    Revoking calendar access switches your Pact Flows to Manual Mode. Your recovery enforcement continues uninterrupted.

    Changes to This Policy

    If we make material changes to this policy, we will notify you by email before the changes take effect. Continued use of The Pact after that date constitutes acceptance of the updated terms.

    Contact

    For any questions about this policy or your data:

    support@thepact.io