Last updated 6 August 2026
Privacy Policy
KeptIt lets you make a commitment, put something at stake, and have the result settled by your own devices instead of by argument. To do that it needs to read some health data. This explains exactly what, why, and where it goes.
Who we are
KeptIt is an independent app made by Vivian Davila. Questions about anything here: the contact form.
What we collect
| What | Why |
|---|---|
| Email address and password | To create your account and sign you back in. Passwords are hashed by our authentication provider and are never visible to us. |
| Username and display name | So friends can find you and challenge you. Your username is visible to other signed-in users, which is how search works. |
| Health data: steps, walking and running distance, flights climbed, sleep duration, exercise minutes | Read from Apple Health, only for the metric a challenge is actually about. A steps challenge reads steps and nothing else. |
| Oura data: sleep duration, readiness score, heart rate variability, steps | Only if you connect an Oura Ring, and only for the metric a challenge is about. |
| Challenge details: type, goal, duration, dates, who is taking part, the amount at stake, and your daily progress values | To run the challenge and show both sides the same numbers. |
| Settlement records: who owes whom, amounts, whether it was marked paid or disputed, and any note you write on a dispute | To keep track of what is outstanding after a challenge ends. |
| Payment handles: your Venmo username or PayPal.me link | Optional, and only if you enter one. Used to open a payment app with the recipient prefilled. |
| Website: your name, email, and which challenge types you said interested you | Only if you fill in the form on this site. Used to email you once when KeptIt is ready to try, and to know which features people actually want. |
| Website: anything you write in the contact form, with your name and email | Only if you send us a message. Used to reply to you. |
| Subscription status | Handled by RevenueCat so we know whether you have KeptIt Pro. We never see your card details. Apple handles the payment. |
What we do not collect
- We do not collect your location.
- This website sets no cookies and runs no analytics. Nothing is stored unless you type it into a form and press the button.
- We do not use advertising SDKs or analytics trackers.
- We do not build advertising profiles.
- We never see your card or bank details.
We never sell your data
Not to advertisers, not to data brokers, not to insurers, not to anyone. Health data in particular is never shared for advertising or marketing, by us or by anyone we use.
Who else your data touches
Running the app requires a few services. Each one only gets what it needs to do its job:
- Supabase hosts the database and handles sign-in. Your account, challenges and daily values live here.
- RevenueCat manages subscription status.
- Apple processes any payment for KeptIt Pro, and provides Apple Health on your device.
- Oura, only if you choose to connect a ring.
We may also disclose information if the law requires it.
What other people can see
A challenge is between people, so some things are visible by design:
- Your username and display name are visible to signed-in users, so you can be found.
- People in a challenge with you can see your progress for that challenge's metric only, and whether you met the goal.
- Someone you owe, or who owes you, can see the amount and whether it has been settled.
Nobody else can see your health data. The database enforces this with row-level security rules: you can only write your own values, and you can only read values from challenges you are part of.
Apple Health
Health data is read from Apple Health only after you grant permission, and only for the metrics challenges need. You can withdraw any of it at any time in Settings โ Privacy & Security โ Health โ KeptIt. Data read from Apple Health is used solely to score your challenges. It is never used for advertising or marketing, and it is never sold or shared with a data broker.
Oura
If you connect an Oura Ring, KeptIt receives an access token from Oura. That token is stored on our server and is never sent to your phone. We request only the permissions needed to read sleep, readiness and daily activity. You can disconnect at any time in the app, or revoke access from your Oura account. Either one stops the sync and deletes the stored token.
Money
KeptIt never holds, transfers, or takes a cut of the money in a challenge. When you settle up, the app opens Venmo or PayPal with the amount and recipient filled in, and you pay through them. We cannot see inside those apps, which is why you tell us you have paid and the other person confirms it.
How long we keep it
We keep your account data while your account exists. Delete your account and everything tied to it goes too: profile, challenges, daily values, settlements and any Oura token.
Use the contact form to request deletion and we will action it within 72 hours.
Data read from Oura is kept only for as long as the challenge it belongs to needs it, meaning the challenge itself plus the seven-day settlement window. After that it is deleted. Disconnecting your ring deletes the stored token immediately and stops any further reading.
The waitlist
If you join the early-access list, we will email you about KeptIt: when it is ready to try, and occasionally about how it is going. We will not pass your address to anyone else. Ask us through the contact form and we will take you off it. You do not need to give a reason.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. If you are in the UK, EU, or a US state with a privacy law such as California, you have these rights by statute. Write to the address above; we will not charge you or make it difficult.
Children
KeptIt is not intended for anyone under 13, and we do not knowingly collect data from them. If you believe a child has given us data, contact us and we will delete it.
Security
Data is encrypted in transit and at rest by our hosting provider. Access to the database is restricted per user by row-level security. OAuth tokens are held in a table that the app itself has no permission to read.
No system is perfectly secure, and we will not pretend otherwise. If something goes wrong that affects you, we will tell you.
Changes
If this policy changes in a way that matters, we will update the date at the top and say so in the app.