KeptIt

Last updated 6 August 2026

Privacy Policy

KeptIt lets you make a commitment, put something at stake, and have the result settled by your own devices instead of by argument. To do that it needs to read some health data. This explains exactly what, why, and where it goes.

Who we are

KeptIt is an independent app made by Vivian Davila. Questions about anything here: the contact form.

What we collect

WhatWhy
Email address and password To create your account and sign you back in. Passwords are hashed by our authentication provider and are never visible to us.
Username and display name So friends can find you and challenge you. Your username is visible to other signed-in users, which is how search works.
Health data: steps, walking and running distance, flights climbed, sleep duration, exercise minutes Read from Apple Health, only for the metric a challenge is actually about. A steps challenge reads steps and nothing else.
Oura data: sleep duration, readiness score, heart rate variability, steps Only if you connect an Oura Ring, and only for the metric a challenge is about.
Challenge details: type, goal, duration, dates, who is taking part, the amount at stake, and your daily progress values To run the challenge and show both sides the same numbers.
Settlement records: who owes whom, amounts, whether it was marked paid or disputed, and any note you write on a dispute To keep track of what is outstanding after a challenge ends.
Payment handles: your Venmo username or PayPal.me link Optional, and only if you enter one. Used to open a payment app with the recipient prefilled.
Website: your name, email, and which challenge types you said interested you Only if you fill in the form on this site. Used to email you once when KeptIt is ready to try, and to know which features people actually want.
Website: anything you write in the contact form, with your name and email Only if you send us a message. Used to reply to you.
Subscription status Handled by RevenueCat so we know whether you have KeptIt Pro. We never see your card details. Apple handles the payment.

What we do not collect

We never sell your data

Not to advertisers, not to data brokers, not to insurers, not to anyone. Health data in particular is never shared for advertising or marketing, by us or by anyone we use.

Who else your data touches

Running the app requires a few services. Each one only gets what it needs to do its job:

We may also disclose information if the law requires it.

What other people can see

A challenge is between people, so some things are visible by design:

Nobody else can see your health data. The database enforces this with row-level security rules: you can only write your own values, and you can only read values from challenges you are part of.

Apple Health

Health data is read from Apple Health only after you grant permission, and only for the metrics challenges need. You can withdraw any of it at any time in Settings โ†’ Privacy & Security โ†’ Health โ†’ KeptIt. Data read from Apple Health is used solely to score your challenges. It is never used for advertising or marketing, and it is never sold or shared with a data broker.

Oura

If you connect an Oura Ring, KeptIt receives an access token from Oura. That token is stored on our server and is never sent to your phone. We request only the permissions needed to read sleep, readiness and daily activity. You can disconnect at any time in the app, or revoke access from your Oura account. Either one stops the sync and deletes the stored token.

Money

KeptIt never holds, transfers, or takes a cut of the money in a challenge. When you settle up, the app opens Venmo or PayPal with the amount and recipient filled in, and you pay through them. We cannot see inside those apps, which is why you tell us you have paid and the other person confirms it.

How long we keep it

We keep your account data while your account exists. Delete your account and everything tied to it goes too: profile, challenges, daily values, settlements and any Oura token.

Use the contact form to request deletion and we will action it within 72 hours.

Data read from Oura is kept only for as long as the challenge it belongs to needs it, meaning the challenge itself plus the seven-day settlement window. After that it is deleted. Disconnecting your ring deletes the stored token immediately and stops any further reading.

The waitlist

If you join the early-access list, we will email you about KeptIt: when it is ready to try, and occasionally about how it is going. We will not pass your address to anyone else. Ask us through the contact form and we will take you off it. You do not need to give a reason.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. If you are in the UK, EU, or a US state with a privacy law such as California, you have these rights by statute. Write to the address above; we will not charge you or make it difficult.

Children

KeptIt is not intended for anyone under 13, and we do not knowingly collect data from them. If you believe a child has given us data, contact us and we will delete it.

Security

Data is encrypted in transit and at rest by our hosting provider. Access to the database is restricted per user by row-level security. OAuth tokens are held in a table that the app itself has no permission to read.

No system is perfectly secure, and we will not pretend otherwise. If something goes wrong that affects you, we will tell you.

Changes

If this policy changes in a way that matters, we will update the date at the top and say so in the app.