Privacy Policy
Lock In Twin · Last updated: September 29, 2026
Lock In Twin is a two-person accountability app. You and one other person ("your twin") agree to a weekly goal, check in with photos, and confirm each other's check-ins. This policy explains what we collect, why, and what we do with it.
The short version: your photos are not posted to a public feed. Photos you send to a deal are shared with that partner. Authorized service providers process them, and reported content may be reviewed for safety. We don't sell your data, we don't show ads, and we don't share your information with advertisers or data brokers.
What we collect
- Phone number. Used to create your account and sign you in. We use Firebase Authentication (Google) to send verification codes and manage sessions.
- Display name. Shown to your twin.
- Check-in photos. Taken inside the app with the camera. A check-in cannot be an existing image. These are stored in your personal record. When you send one to a deal, that partner receives a copy and it appears in your shared archive.
- Punishment proof photos. Taken with the camera or chosen from your photo library. If you choose from your library, iOS shows you its own picker and the app receives only the single image you select — it never gets access to your library.
- Location for location-based goals. With your iOS permission, we request a location fix when you set a saved goal or deal location and when you check in for a location-based goal, such as gym, running or weightlifting. The coordinates may be precise when Precise Location is enabled, or approximate when iOS supplies reduced-accuracy location; we store the coordinates received from iOS without rounding them ourselves. We compare a check-in with the saved location and display a distance indicator. When you send that check-in to a deal, its coordinates are stored in a record that both members can access, even though the app displays the distance rather than a map of the check-in. We do not collect a continuous route or track your location in the background.
- Goals, exercise progress and challenge settings. Your category, weekly target, wake time and leeway window (for the Wake Up Early goal), punishment cards (including text you write), challenge results, card draws, re-rolls and pact history. Exercise goals and their completion records are fitness information you provide; we do not read Apple Health or HealthKit.
- Your deal connections. We store which accounts you invite and pair with, so each person can access their shared challenges and history. This is the relationship graph you create in Lock In Twin; we do not import your phone address book. We use deal membership and results to understand whether pairs get started and continue using the app.
- Check-in and settlement records. Timestamps, approvals, rejections, reactions, streaks, and outstanding punishments.
- Setup in version 1.1.4. This version does not collect anonymous introduction, goal-selection or sign-in funnel events. It has no anonymous setup analytics token or switch. Requests needed to show an invitation, authenticate you or operate the app still reach our service providers and can create operational logs. Signed-in usage analytics, purchase processing and service diagnostics are separate, as described below.
- Usage analytics. A small, fixed set of product events (for example: account setup completed, a deal-creation step was reached, an invite share completed, a check-in was submitted, which built-in punishment cards were shown or selected, and which cards a re-roll replaced) used to understand where the app works or loses people. These events are stored with your Lock In Twin account. Card analytics use fixed identifiers for our supplied cards; custom cards are counted only as a category, without their text. We use this information to improve the card collection. We also analyze account and deal records, including exercise progress, challenge results, punishments and verified purchases, to understand whether pairs get started and continue. Display names help us exclude demo and test accounts from these internal reports; we do not use them for advertising. The fixed event payloads do not include names, message or card text, deal identifiers, photos, location, or advertising identifiers. Review timing is recorded in coarse buckets rather than exact durations. We also record app build and distribution-channel labels on new deals and check-ins to separate testing from customer usage. These labels are linked to the corresponding account activity; coarse channel labels remain with shared history.
- Installation and notification identifiers. Firebase Messaging processes app installation identifiers and notification tokens to deliver notifications. We associate notification tokens with your account so notifications reach the right device. iOS notification permission controls alerts; it is not a switch for all service-provider identifiers or diagnostics.
- Service and SDK diagnostics. Our cloud services record request metadata, including IP addresses, request times, response status and latency, for operation, security and troubleshooting. Firebase and RevenueCat also process app, SDK, device and operating-system information for service delivery, reliability and SDK analytics. Firebase describes its SDK user-agent metadata as unlinked to a user or device identifier. Operational logs containing raw IP addresses are not anonymous daily totals.
- Crash reports. We collect limited crash diagnostics to fix faults: exception and signal codes, termination reason, call stack, app build, operating-system version and receipt time. Our crash documents do not include an account, deal, phone or device identifier. We do not collect MetricKit usage or performance payloads.
- Reports. If you report content, we store the report, what was reported, and the reason.
What we don't collect
- We don't request broad photo-library access, contacts, microphone access, or access to Apple Health/HealthKit. The system photo picker shares only a proof image you choose. Exercise goals and progress that you enter are collected as described above.
- We request location for saved goal/deal locations and location-based check-ins, not for background tracking.
- We don't receive or store your card or bank details. Purchases are processed by Apple; we receive purchase status, transaction identifiers, environment, price and entitlement information through RevenueCat. We use verified transaction information to distinguish paid purchases from sandbox tests and free redemptions.
- We don't buy data about you from third parties.
Who can see your information
- Your twin sees your check-in photos, punishment proof photos, distance indicator, display name, goal progress, streaks, and outstanding punishments. That is the entire point of the app.
- No public photo feed. We do not make photos searchable by other users or publish them to a public feed. Your chosen deal partners receive the photos you send to them. Authorized providers process stored photos to run the service. Authorized reviewers may access reported content to investigate abuse, enforce our rules or protect safety. If you export or share an image outside the app, you choose who receives that copy.
- Service providers. We use Google Firebase for authentication, database and file storage, and push notifications. Product analytics are stored in that same database rather than sent to an advertising or cross-app analytics service. We use RevenueCat to validate purchases and entitlements. RevenueCat starts when you open the app, before you sign up. It receives your Apple identifier for vendor (IDFV), a RevenueCat-generated app user ID, and purchase and transaction data when available, to provide purchase services. After sign-in, we associate its customer record with your Lock In Twin account ID. Cloudflare hosts our public website, invitation-link pages and legal pages, and processes web-request metadata for delivery and security. These providers process service data under their applicable data-processing terms; their SDK diagnostics and purchase analytics are described above. We require our processors to protect data under those terms and applicable law. See Firebase's privacy information and RevenueCat's privacy policy.
- Legal. We may disclose information if required by law, or to investigate reported abuse or protect someone's safety.
- We never sell your personal information and do not share it for cross-context behavioral advertising.
How long we keep things
Operational logs. Request logs in our Google Cloud project's default logging bucket are retained for 30 days. They can include IP addresses, request times, HTTP status and latency. This is separate from any aggregate product totals. Authentication, purchase and other provider records follow the retention rules needed to deliver their services and meet legal obligations; the 30-day period is not a promise that every provider record is removed then.
Earlier setup experiment. Anonymous setup collection is disabled for this release. Any remaining temporary experiment records expire no later than two days after the start of their UTC day and are removed by scheduled cleanup; infrastructure delays can delay physical deletion. Any retained daily experiment totals contain no attempt or account identifier. The temporary-record expiry does not apply to separate operational logs, and disabling collection does not recall previously received requests. We do not use those logs to link experimental setup attempts to accounts.
Your pact archive is designed to last — it's a record you and your twin build together, and both of you keep access to it even after a pact ends.
If you delete your account, we delete your account and your personal data. Photos you already shared into a pact archive remain visible to your twin, with your identity reduced to your first name — this is so one person deleting their account doesn't erase the other person's record of their own year. If you want content you contributed removed as well, contact us and we'll remove it.
Your choices and rights
- Delete your account at any time in Settings. This is available in the app; you don't need to email us.
- Turn off notifications or location in your iOS settings. Some goals won't work without them.
- Access, correction, and portability. In version 1.1.4 and later, Settings → Export my data gives you a copy of your account data, including the app build and distribution-channel labels described above. You can also contact us for a copy or to correct anything.
- If you're in the EU/UK: our legal basis for processing is performance of a contract (running the app you signed up for) and legitimate interests (safety, abuse prevention, understanding whether the app works). You have rights of access, rectification, erasure, restriction, objection, and portability, and may complain to your local supervisory authority.
- If you're in California: you have the right to know, delete, correct, and opt out of sale or sharing. We don't sell or share personal information as those terms are defined under the CCPA/CPRA. We will not discriminate against you for exercising your rights.
Children
Lock In Twin is not intended for anyone under 13, and we do not knowingly collect information from children under 13. If you believe a child has created an account, contact us and we'll remove it.
Security
Data is transmitted over encrypted connections and stored using Google Cloud infrastructure with client access rules restricting each pact's data to its two members, alongside authorized service and administrative access described above. No system is perfectly secure, but we don't ask for more than the app needs, and we do not publish photos to a public feed.
Changes
If we change this policy materially, we'll update the date above and notify you in the app.
Contact
Questions, requests, or reports: support@lockintwin.app