Your Data. Your Terms.
Privacy Policy
The Pact is built around one principle: your body is a non-negotiable asset. We apply the same standard to your data. This policy explains clearly and completely what we collect, why we collect it, and what we will never do with it.
Effective date: [Date]
Contact: support@thepact.io
What We Collect
A. Information you provide directly
- Your email address, submitted when you request early access or create an account
- Written justifications entered during SOS Bypass events within the app
- Any communications you send to us via support@thepact.io
B. Information generated by your use of the app
- Recovery session data — sessions completed, skipped, snoozed, or rescheduled
- Enforcement budget usage — snooze, skip, and reschedule counts per day
- SOS Bypass events — frequency, timestamps, and written justifications
- Integrity and adherence metrics — used to generate your Weekly Integrity Report
- Kiosk Mode interactions — lock activations, durations, and outcomes
- App configuration data — Pact Flow settings, session types, working window preferences
C. Calendar data (if you choose to enable Calendar Sync)
- Read-only access to your Google or Outlook calendar events marked as “Busy”
- We read event timing and availability status only — we do not read event titles, descriptions, attendees, or any content within calendar events
- Calendar data is used exclusively to place recovery sessions intelligently within your working day
- Calendar data is processed locally on your device wherever technically possible and is never sold or shared with third parties
D. Technical data
- Device type and operating system version
- App version
- Crash reports and error logs (anonymised)
What We Do Not Collect
- We do not monitor your work activity, keystrokes, screen content, or productivity
- We do not collect financial information — payments are processed by third-party providers
- We do not read calendar event titles, descriptions, or attendee information
- We do not build advertising profiles
- We do not collect data from children under the age of 16
Why We Collect It
| Data | Purpose |
|---|---|
| Email address | Account creation, early access communication, product updates |
| Recovery session data | Generating your Integrity Dashboard and Weekly Report |
| SOS Bypass events | Accountability logging as part of the enforcement system you agreed to |
| Calendar data | Intelligent session placement in Smart Mode |
| Technical data | App stability, bug resolution, performance improvement |
We collect only what is necessary to operate the enforcement system you have chosen to use. Nothing more.
Legal Basis for Processing
Where GDPR or equivalent regulation applies, we process your data under the following legal bases:
- Contractual necessity — processing required to deliver the service you signed up for
- Legitimate interests — app improvement, security, and fraud prevention
- Consent — for calendar access, which you may revoke at any time through your device or account settings
How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Account and email data | Until you delete your account |
| Recovery session and integrity data | Until you delete your account |
| SOS Bypass logs | Until you delete your account |
| Calendar data | Not stored — processed in real time and discarded |
| Technical and crash logs | 90 days |
Who We Share Data With
We do not sell your data. We do not share your data with advertisers.
We work with a limited number of third-party service providers who help us operate the product:
- Payment processors — for subscription billing (they receive only what is necessary to process payment)
- Cloud infrastructure providers — for secure data storage and app delivery
- Analytics providers — for anonymised, aggregated app performance data only
All third-party providers are contractually bound to process your data only for the purposes we specify and to maintain appropriate security standards.
We may disclose data if required by law, court order, or regulatory authority.
Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data and account
- Withdraw consent for calendar access at any time
- Export your data in a portable format
- Object to certain types of processing
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at support@thepact.io. We will respond within 30 days.
Data Security
We apply industry-standard security measures including encryption in transit and at rest, access controls, and regular security reviews. No system is completely immune to risk. If a breach occurs that affects your data, we will notify you in accordance with applicable law.
Calendar Access & Revocation
Calendar Sync is optional. If you enable it, you can revoke access at any time by:
- Disconnecting the integration within the app under Settings
- Removing The Pact's permissions directly in your Google or Microsoft account settings
Revoking calendar access switches your Pact Flows to Manual Mode. Your recovery enforcement continues uninterrupted.
Changes to This Policy
If we make material changes to this policy, we will notify you by email before the changes take effect. Continued use of The Pact after that date constitutes acceptance of the updated terms.
Contact
For any questions about this policy or your data: