Commit logo

Commit

Legal

Privacy Policy

Effective July 25, 2026 · Last updated July 25, 2026

Commit (“Commit,” “we,” “us”) is an accountability app. This policy explains what we collect, why, who we share it with, and the choices you have. By using Commit, you agree to this policy.

1. Who you are to us

Commit does not require a name, password, or social login. When you first open the app we create an account tied to an anonymous device identifier generated on your device. Everything else you provide is optional.

2. What we collect

DataWhy we collect it
Anonymous device IDTo create and recognize your account without a login.
Onboarding answersYour chosen coach style and the focus area you selected, to personalize prompts.
Tasks you createThe task text and deadlines you commit to, to run the core feature.
Proof photosImages you submit to verify a completed task (see §4).
Progress dataStreaks, XP, and shields, to track your consistency.
Email & display name (optional)Only if you add them, e.g. for milestones or your profile.
Profile photo (optional)Only if you set an avatar.
DiagnosticsCrash reports and technical error data to keep the app stable.
Purchase statusWhether you have an active subscription. Apple handles payment; we never see your card details.

3. Service providers we share data with

We do not sell your personal data. We share only what's needed with the following processors, each under their own terms:

ProviderWhat they receive
OpenAIYour proof photos and the related task text, to run the AI verification (§4).
Cloudflare R2Storage of your proof photos and profile image (§4).
RailwayHosting of our backend and database (your tasks, progress, and account record).
SentryCrash and error diagnostics (United States).
AppleSubscriptions, billing, and receipt validation.

4. Photos and AI verification

When you submit proof for a task, the image is uploaded to our servers and sent to OpenAI, which analyzes it to judge whether it plausibly reflects the task. Photos are stored on Cloudflare R2 so you can review your history. Depending on our storage configuration, a stored photo may be retrievable by anyone who has its direct link.

Please do not submit photos containing sensitive personal information (documents, IDs, financial or medical details, or other people who haven't consented). You choose what to photograph; only submit images you're comfortable storing and having analyzed.

5. How long we keep data

Verification photos are automatically and permanently deleted 90 days after they are submitted. After that window the image is erased from our storage; only the task record (whether it was completed) is kept so your streak and history remain intact.

Your remaining data is kept while your account exists. When you delete your account (Profile → Delete Account), we delete your account record, tasks, progress, and any verification photos still within the 90-day window from our systems. Copies held by processors (e.g. backups, provider logs) are removed in the normal course of their retention cycles. Diagnostic data is retained per Sentry's standard retention.

6. Your choices and rights

7. Children

Commit is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we'll delete it. Where local law sets a higher age of digital consent, that age applies.

8. International transfers & security

Our providers may process data in the United States and elsewhere. We use reasonable technical and organizational measures to protect your data, but no method of transmission or storage is 100% secure.

9. Changes

We may update this policy. Material changes will be reflected by a new effective date, and where appropriate, notice in the app.

10. Contact

Questions or requests: commit.help@outlook.com, Commit.