← Back to Lockin

Last updated: August 29, 2026

Privacy Policy

1. Information We Collect

1.1 Account Information

When you create an account with Lockin, we store your name, email address, optional profile image, account identifier, and the session data needed to keep you signed in. If you choose Sign in with Apple or Google, that provider sends us the identity token and profile fields you authorize; we do not receive your provider password.

1.2 Usage Data

We store the lock ins, goals, todos, notes, calendar days, streaks, completion history, and settings you save. This information is linked to your account so the app can show your progress across devices.

1.3 Device Information

We store your time zone, notification choices, and, if you enable push notifications, an Expo push token for the device. Production diagnostics sent to Sentry can include app and operating-system version, device model, crash details, and sampled performance traces. Default personal-information collection is disabled in the Sentry SDK.

1.4 Voice Notes and AI Drafting

Voice transcription is optional. When you use it, the recording is sent through Vercel AI Gateway to an OpenAI transcription model. Lockin does not store the recording in its database; it returns text, which is stored only if you save the note. When you ask Lockin to draft a challenge, the goal and onboarding answers you provide are sent through the same gateway to the selected model provider. Those requests require a zero-data-retention, no-prompt-training route; if no eligible route is available, the AI feature fails rather than sending the content under weaker terms.

1.5 Data Stored on Your Device

The app keeps guest progress, onboarding state, preferences, and a short-lived cache of account data on the device so screens can load reliably. Signing out, deleting the account, switching accounts, or receiving a confirmed expired session clears the active account-owned state before another identity can render; storage whose ownership cannot be established is not reused. Operating-system backups may retain app data according to your Apple or Google backup settings.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve Lockin
  • Track your progress and maintain your streaks
  • Deliver optional reminders and paid features
  • Transcribe audio or draft a lock in only when you request those features
  • Send you important updates about the service
  • Respond to your requests and support inquiries
  • Protect against fraud and unauthorized access

3. Payment Processing

In-app purchases are processed by the store for your platform (Apple App Store or Google Play, where available). RevenueCat receives an app user identifier, product and purchase status, and entitlement events so Lockin can determine whether Pro is active. Lockin does not receive or store your full payment-card number.

Deleting Lockin does not cancel a store subscription; subscriptions must be managed in your Apple or Google account. For more information about RevenueCat's processing, see RevenueCat's Privacy Policy.

4. Data Sharing

We do not sell your personal information. We may share your information with:

  • Vercel and Neon for API hosting and the account database
  • Apple and Google for the sign-in or store services you choose
  • RevenueCat for purchase and entitlement management
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging for optional push delivery; the push token and notification text, including the lock-in title and day number, pass through those services
  • Vercel AI Gateway and the selected AI providerfor optional drafting and transcription under the routing controls described above
  • Sentry for crash and performance diagnostics
  • Legal authorities when required by law or to protect our rights

5. Your Rights

Under applicable data protection laws (including GDPR), you have the right to:

  • Access your personal data we hold
  • Rectify inaccurate or incomplete data
  • Delete your personal data
  • Restrict processing of your data
  • Data portability - receive your data in a structured format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at julien@supacat.io.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide Lockin. When the in-app account deletion succeeds, the account, sessions, profile, lock ins, todos, notes, history, push token, and entitlement mirror are removed from Lockin's database, and local account state is cleared. This cannot be undone.

Account deletion does not itself erase records independently held by Apple, Google, RevenueCat, Sentry, or an operating-system backup, and it does not cancel a store subscription. Those providers keep or delete records under their own retention settings and legal obligations. Contact us if you want us to coordinate a downstream privacy request. We may retain narrowly required security, tax, or legal records for the period required by law, and we will identify that exception when responding to a request.

7. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

8. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this page.

9. Contact

If you have questions about this privacy policy or how we handle your data, contact us at julien@supacat.io.

© Supacat 2026PrivacyTerms