Last updated: August 29, 2026
When you create an account with Lockin, we store your name, email address, optional profile image, account identifier, and the session data needed to keep you signed in. If you choose Sign in with Apple or Google, that provider sends us the identity token and profile fields you authorize; we do not receive your provider password.
We store the lock ins, goals, todos, notes, calendar days, streaks, completion history, and settings you save. This information is linked to your account so the app can show your progress across devices.
We store your time zone, notification choices, and, if you enable push notifications, an Expo push token for the device. Production diagnostics sent to Sentry can include app and operating-system version, device model, crash details, and sampled performance traces. Default personal-information collection is disabled in the Sentry SDK.
Voice transcription is optional. When you use it, the recording is sent through Vercel AI Gateway to an OpenAI transcription model. Lockin does not store the recording in its database; it returns text, which is stored only if you save the note. When you ask Lockin to draft a challenge, the goal and onboarding answers you provide are sent through the same gateway to the selected model provider. Those requests require a zero-data-retention, no-prompt-training route; if no eligible route is available, the AI feature fails rather than sending the content under weaker terms.
The app keeps guest progress, onboarding state, preferences, and a short-lived cache of account data on the device so screens can load reliably. Signing out, deleting the account, switching accounts, or receiving a confirmed expired session clears the active account-owned state before another identity can render; storage whose ownership cannot be established is not reused. Operating-system backups may retain app data according to your Apple or Google backup settings.
We use the information we collect to:
In-app purchases are processed by the store for your platform (Apple App Store or Google Play, where available). RevenueCat receives an app user identifier, product and purchase status, and entitlement events so Lockin can determine whether Pro is active. Lockin does not receive or store your full payment-card number.
Deleting Lockin does not cancel a store subscription; subscriptions must be managed in your Apple or Google account. For more information about RevenueCat's processing, see RevenueCat's Privacy Policy.
We do not sell your personal information. We may share your information with:
Under applicable data protection laws (including GDPR), you have the right to:
To exercise these rights, contact us at julien@supacat.io.
We retain your personal data for as long as your account is active or as needed to provide Lockin. When the in-app account deletion succeeds, the account, sessions, profile, lock ins, todos, notes, history, push token, and entitlement mirror are removed from Lockin's database, and local account state is cleared. This cannot be undone.
Account deletion does not itself erase records independently held by Apple, Google, RevenueCat, Sentry, or an operating-system backup, and it does not cancel a store subscription. Those providers keep or delete records under their own retention settings and legal obligations. Contact us if you want us to coordinate a downstream privacy request. We may retain narrowly required security, tax, or legal records for the period required by law, and we will identify that exception when responding to a request.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
We may update this privacy policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this page.
If you have questions about this privacy policy or how we handle your data, contact us at julien@supacat.io.