Privacy Policy

Lock In Twin · Last updated: September 29, 2026

Lock In Twin is a two-person accountability app. You and one other person ("your twin") agree to a weekly goal, check in with photos, and confirm each other's check-ins. This policy explains what we collect, why, and what we do with it.

The short version: your photos are not posted to a public feed. Photos you send to a deal are shared with that partner. Authorized service providers process them, and reported content may be reviewed for safety. We don't sell your data, we don't show ads, and we don't share your information with advertisers or data brokers.

What we collect

What we don't collect

Who can see your information

How long we keep things

Operational logs. Request logs in our Google Cloud project's default logging bucket are retained for 30 days. They can include IP addresses, request times, HTTP status and latency. This is separate from any aggregate product totals. Authentication, purchase and other provider records follow the retention rules needed to deliver their services and meet legal obligations; the 30-day period is not a promise that every provider record is removed then.

Earlier setup experiment. Anonymous setup collection is disabled for this release. Any remaining temporary experiment records expire no later than two days after the start of their UTC day and are removed by scheduled cleanup; infrastructure delays can delay physical deletion. Any retained daily experiment totals contain no attempt or account identifier. The temporary-record expiry does not apply to separate operational logs, and disabling collection does not recall previously received requests. We do not use those logs to link experimental setup attempts to accounts.

Your pact archive is designed to last — it's a record you and your twin build together, and both of you keep access to it even after a pact ends.

If you delete your account, we delete your account and your personal data. Photos you already shared into a pact archive remain visible to your twin, with your identity reduced to your first name — this is so one person deleting their account doesn't erase the other person's record of their own year. If you want content you contributed removed as well, contact us and we'll remove it.

Your choices and rights

Children

Lock In Twin is not intended for anyone under 13, and we do not knowingly collect information from children under 13. If you believe a child has created an account, contact us and we'll remove it.

Security

Data is transmitted over encrypted connections and stored using Google Cloud infrastructure with client access rules restricting each pact's data to its two members, alongside authorized service and administrative access described above. No system is perfectly secure, but we don't ask for more than the app needs, and we do not publish photos to a public feed.

Changes

If we change this policy materially, we'll update the date above and notify you in the app.

Contact

Questions, requests, or reports: support@lockintwin.app