1. Who this covers
This policy covers the duomaxxing apps for iPhone and Android, the web app at duomaxx.ing, and the backend that serves them. "We" means the individual operator of duomaxxing; "you" means the person using it.
duomaxxing is a two-person daily challenge. Almost everything you put into it is shown to the one partner you have paired with. Read section 5 before you put anything into it that you would not want that person to see.
2. What we collect
| Data | Why we have it |
|---|---|
| Display name and avatar | To show you to your partner. You choose both. |
| Password | Stored only as a bcrypt hash. We never hold the password itself and cannot recover it for you. |
| Email address | Held only if you signed in with Google. Accounts created with a password do not store an email address at all. |
| Your submissions | Photos, notes, which pillar they belong to, when they were sent, and whether your partner approved or rejected them. |
| Location | Precise coordinates attached to a submission or memory, so the two of you can fill in a shared map. Optional — see section 4. |
| Other content you create | Memories, stories, reactions, chat messages, calendar events and to-dos. |
| Push tokens | A device identifier from Apple, Google or your browser, so we can send the notifications you turned on. |
| Usage and crash data | Which screens you open and what breaks. See section 6. |
We do not ask for your date of birth, phone number, contacts, health records, or payment details, because the app does not need them.
3. Camera and photo library
The app asks for camera access to take proof photos and photo library access to pick existing ones. It reads only the images you explicitly choose. Images are resized on your device and uploaded to our storage so your partner can see them.
Photos in a submission are visible to your partner. Photos you post as a story are visible to your partner until the story expires, or indefinitely if either of you saves it as a memory.
4. Location
Location is optional and off until you grant it. When granted, the app attaches the coordinates of a submission or memory at the moment you create it, which is what draws the shared map. We do not track your location in the background, and we do not build a movement history beyond the points you attached to something yourself.
You can revoke location access at any time in your device settings; everything else in the app keeps working, and existing pins stay until you delete the submission they belong to.
5. What your partner can see
This is the part most privacy policies bury, so: your paired partner can see everything you submit — every photo, every note, the location attached to it, your scores, your streak, your milestones, your mascot, and when you were last active. That is not a side effect. It is how verification works.
Nobody else can see it. There is no public feed, no discovery, no leaderboard beyond the two of you. Unpairing stops future sharing; it does not retract what your partner has already seen.
6. Analytics and crash reporting
We use PostHog for product analytics and crash reporting. It records which screens you open, which actions you take and what errors occur, linked to your account so we can tell one person's session from another's.
It is configured without advertising identifiers, and the data is never combined with data from any third party. In Apple's terms this is collection, not tracking, and the app's privacy manifest declares it that way.
7. Notifications
If you turn notifications on, we store a push token for your device and use it to send: a reminder in the evening for pillars still open, a final call before the day closes, and a nudge when your partner is waiting on you to verify something. Turning notifications off in your device settings stops all of it.
Push is delivered by Apple Push Notification service on iOS, Firebase Cloud Messaging on Android, and the Web Push protocol in browsers.
8. Who else touches your data
We use a small number of service providers, each doing one job. They process data on our behalf and are not permitted to use it for their own purposes. We do not sell data to anyone, and there are no advertising networks involved.
| Provider | What they hold |
|---|---|
| Neon | The PostgreSQL database — accounts, submissions, scores, messages. |
| Vercel | Hosting and the API, plus blob storage for uploaded images and a key-value store for short-lived state. |
| PostHog | Analytics and crash events (us.i.posthog.com). |
| Apple | Push delivery on iOS, and Sign in with Apple if you use it. |
Push delivery on Android via Firebase, and Google sign-in if you use it (scopes: openid email profile). |
We will disclose data if we are legally required to. If duomaxxing is ever transferred to someone else, we will say so here before it happens.
9. Where it is stored
The API runs in Vercel's Singapore region and the database and image storage sit alongside it. Analytics are processed in the United States. If you are in the UK, EEA or another region with data transfer rules, using the app means your data is handled in those places.
10. How long we keep it
- Account and content — until you delete it or delete your account.
- Stories — 24 hours, unless one of you saves it as a memory.
- Refresh tokens — until they expire or you log out.
- Analytics and crash events — retained by PostHog under its own retention policy, keyed to your account id.
11. Deleting your account
Profile → Delete account, in any of the apps. It runs immediately and permanently removes your profile, submissions, verifications you gave, memories, stories, reactions, messages, milestones, mascot unlocks, calendar events, to-dos, your pair link and your login tokens. There is no recovery window and no soft delete.
Deleting your account also removes your half of the pair. Your former partner keeps their own submissions and history.
12. Your rights
Wherever you live, you can ask us to show you what we hold, correct it, export it, or delete it, and you can withdraw consent for location or notifications at any time from your device settings. Most of this you can do yourself in the app; for anything you cannot, email us and we will action it within 30 days.
If you are in the UK or EEA, our lawful basis is contract for the data the app needs to function, and legitimate interest for analytics and crash reporting. You have the right to complain to your local data protection authority.
13. Children
duomaxxing is not intended for anyone under 13, and under 16 in regions where that is the threshold for consent. We do not knowingly collect data from children. If you believe a child has an account, email us and we will delete it.
14. Security
Passwords are hashed with bcrypt and never stored or logged in the clear. Sessions use signed tokens with a short-lived access token and a revocable refresh token. All traffic runs over TLS. Login attempts are rate limited.
No system is perfect. If you find a vulnerability, email us before disclosing it publicly and we will fix it.
15. Changes
If this policy changes in a way that affects what we collect or who we share it with, we will update the date at the top and tell you in the app before the change takes effect.
16. Contact
Privacy questions, data requests, account deletion help and security reports: privacy@duomaxx.ing.