Doen (“we,” “us,” or “the app”) helps you build habits with photo and video proof, AI verification, and optional social sharing. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information we collect
Depending on how you use the app, we may collect:
- Account information — email address and display name (and related auth identifiers).
- Proof media — photos and videos you capture in the app as habit check-in evidence.
- Check-in and habit data — habits you create, verification results, streaks, captions, and sharing settings.
- Device push token — so we can send notifications you enable (for example reminders).
- Timezone — to schedule reminders and evaluate daily streaks correctly for your local day.
- Social graph data — friends, circle memberships, communities, and reactions/comments you make on shared posts.
- Profile details you choose to add — such as bio or avatar, if you set them.
We do not currently offer a self-serve “download all my data” export inside the app. If you need a copy of your information, contact us at the email below.
2. How we use proof photos and videos
- AI verification — proof media is sent to OpenAI so their vision models can assess whether the media matches the habit you are checking in for.
- Storage — media is stored in our cloud storage (currently Supabase storage) so the app can show your history and shared posts.
- Visibility — who can see a given proof depends on the sharing choice you make for that check-in (for example private, friends, circles, public, or communities). We do not publish private proofs beyond what you select.
3. How we use other information
We use the information above to:
- Operate accounts, authentication, and the core habit loop.
- Maintain streaks, freezes, and related progress features.
- Power social features you opt into (friends, circles, feed).
- Send push notifications you allow.
- Maintain security, prevent abuse, and improve reliability.
- Respond to support requests you send us.
4. Third parties we share data with
We share data with service providers only as needed to run the product:
- OpenAI — AI verification of proof media.
- Supabase (and related hosting/database/storage) — account data, app data, and media storage.
- Expo / Firebase Cloud Messaging (FCM) — delivery of push notifications using your device push token.
These providers process data under their own terms and privacy policies. We do not sell your personal information.
5. Retention and account deletion
You can delete your account from the app (Settings → delete account) by typing DELETE to confirm. When you do:
- Your profile is soft-deleted and shown as “Deleted user” where shared content remains for others’ history.
- Private check-ins, friendships, circle memberships, push tokens, and related private data are removed or cleared as part of that process.
- Shared (non-private) completions are anonymized so the author appears as “Deleted user” rather than hard-deleting other people’s feed history.
- We intend a 30-day recovery window before permanent hard deletion / final purge. Note: the scheduling fields exist in the product; automated hard-purge must be confirmed against the live system before you treat this as guaranteed.
You may also request deletion by emailing hello@getdoen.app.
6. Children’s privacy
Doen is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we will take steps to delete it.
7. Your rights and choices
- Sharing controls — choose privacy per check-in.
- Notifications — manage push permissions in system settings and in-app preferences where available.
- Account deletion — use in-app deletion or email hello@getdoen.app.
- Access / correction — update profile fields in the app, or contact us for help.
Depending on where you live, you may have additional rights under local law (for example access, deletion, or objection). Contact us to exercise them. We do not currently provide an automated data-export download in the app.
8. Security
We use industry-standard measures appropriate to our stack (including authenticated APIs and cloud provider controls). No method of transmission or storage is 100% secure.
9. Changes to this policy
We may update this Privacy Policy as the product evolves. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated in-app or by email when appropriate.
10. Contact
Questions about privacy: hello@getdoen.app
More help: Support · Terms of Service