LOCKI

LOCKI Privacy Policy

Last updated: 27 August 2026

LOCKI is a digital wellbeing app for personal focus locks and optional couple locks. We do not sell personal data or use it for advertising.

1. Identity and when the app communicates with us

LOCKI creates an anonymous Supabase Auth user and device identity when the app launches. The app may communicate with LOCKI before pairing to create or restore that identity, keep its session, and perform core service checks. Pairing is optional. Linking a Google account is also optional. If you link one, Supabase Auth may process the name, email address, and profile information provided by Google. We do not ask for a phone number.

2. Data used by LOCKI

Depending on the features you use, the service can process:

  • anonymous Auth/device identifiers, platform, locale, time zone, and Expo/FCM push-token data when notifications are enabled;
  • name, email address, and profile information when you link a Google account;
  • your optional marketing opt-in state, change time, and consent-copy version;
  • pair, invite, device, and couple-session metadata;
  • lock configuration and records, including themes, times, completion and unlock events;
  • ritual answers, couple-streak and weekly-report data;
  • custom unlock-request messages (up to 200 characters) when you include one.

The lock core uses selected apps or whole-device mode locally. LOCKI does not receive the contents of your apps, your screen contents, or text that you view while a lock is active. iOS app selections use opaque operating-system tokens. The first Android release blocks with Usage Access and display-over-other-apps permission. It does not transmit installed-app lists, package names, display names, or icons to our servers or analytics providers. It does not request microphone access or collect voice or audio. The current app has no photo upload or exchange interface and does not collect photos or videos.

A custom unlock-request message is stored with that request and shown to your paired partner in the app. It is not included in push notification payloads.

3. Service providers

Supabase hosts Auth and the database. Expo and FCM notification delivery can process push tokens and generalized notification payloads. RevenueCat processes subscription identity and entitlement state. From anonymous identity creation, PostHog processes the anonymous Supabase UID and only product events explicitly sent by LOCKI; automatic app-lifecycle capture, session replay, GeoIP, and default person properties are disabled. Sentry processes errors reported by the code with default PII disabled and user and request fields removed before sending.

The account-deletion job checkpoints each stage. After an interruption, it resumes from that checkpoint only when the user requests deletion again, with limited backoff; repeated failures are `marked for manual review`. After deletion of the RevenueCat customer and PostHog person and events completes, LOCKI deletes the account data. Automated Sentry deletion is not connected, so Sentry reports may remain under Sentry's retention, legal, and operational rules. Contact us to confirm the applicable retention or request deletion support.

4. Subscriptions

Subscriptions are purchased through Apple App Store or Google Play and their store terms control billing, trials, refunds, and cancellation. RevenueCat receives the app's subscription identity and entitlement information. Deleting a LOCKI account does not itself cancel a store subscription or issue a refund.

5. Unpairing and account deletion

Unpairing disconnects the pair and ends an active couple lock. It does not delete the anonymous account, solo lock history, or existing couple history; those are separate from the pair connection.

Account deletion is a separate, irreversible flow in Settings. After the authenticated deletion request succeeds, the server:

  1. derives the caller from the bearer token and never trusts a caller-supplied user ID;
  2. deletes the RevenueCat customer and requests deletion of the PostHog person and events;
  3. deletes account data such as pair, device, session, report, and ritual-answer records, then deletes the Auth user; and
  4. checkpoints each stage, resumes from that checkpoint with limited backoff when the user requests deletion again, and leaves repeated failures `marked for manual review`.

A service-only deletion receipt is retained for up to 7 days. It may contain the SHA-256 token hash (not the raw token), uid, storage-deletion context, provider/local stage status, opaque PostHog request ID, attempts/backoff, and lease/error/timestamps categories. These fields support authenticated request correlation, duplicate prevention, provider progress, user-triggered resume, and failure/manual review, after which the receipt is removed.

Only after the remote request succeeds does the app ask the native lock runtime to stop active locks, remove the SecureStore auth session, reset RevenueCat/PostHog/Sentry identities, clear personal in-memory stores, and remove personal MMKV data. A retry is safe. Account-deletion instructions are available at https://locki.waypion.com/account-deletion.

6. Retention

Account records are kept while needed to provide the service. Server retention jobs remove old pairing events and completed couple records. RevenueCat and PostHog deletion follows the process above. Store receipts, push-delivery logs, Sentry reports, and provider backups may be subject to the relevant provider's retention rules.

7. Children and changes

LOCKI is for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. We will update this policy and its date when the data practices change.

8. Contact

For deletion help, residual-data questions, or privacy requests, contact contact@waypion.com.