Untilt

Privacy

Last updated September 10, 2026

The short version: what you do in the app stays on your device unless you turn on syncing, paying happens at Stripe, and there is no analytics script, no ad pixel, and no third party watching you meditate. Once a week this app sends a few words about your device, described in full below down to what it cannot promise; it asks you first, sends nothing until you answer, and you can change your mind either way afterwards.

On your device

Your favorites, session history, check-in log, and settings live in your browser's own storage, on your device. None of it is uploaded unless you turn on syncing; until you do, no record of what you played, when you played them, or what you answered a check-in is sent anywhere. Turn syncing on and those three carry between your own devices, and nothing else does; the section below has the exact shape of it. You can erase all of it at any time from Settings.

The one measurement

We are trying to answer one question: do the people who use check-ins keep using the app longer than the people who do not? That decides what gets built next, and there is no way to answer it from a device that says nothing at all.

So, at most once a week, the app sends three words about this device. A fourth, whether you are paying, is read by the server from the session you already have, rather than sent by your device:

You are asked before any of it is sent. The switch that controls this starts on, and a switch starting on is a default rather than anything you agreed to -- so the app holds the first message and puts the question to you instead, in the app, with the same list you are reading here. Until you answer, nothing is sent. Answer either way and it is remembered; the switch in Settings changes it again whenever you like, and turning it off survives erasing your data, because a withdrawn answer is not ours to erase on your behalf.

The question waits for the first message to actually come due, which is a day after you install, rather than interrupting you the moment you open the app. Devices that were already reporting before this existed are asked too: the point of asking is that nobody ever had been.

That is the entire message. There is no name, no email, no account, no device id, no random identifier, no address and no time of day in it, and nothing in it says what you played or what you answered. What we keep is a tally: for each combination, how many devices said it. No message is stored, so two people who use the app the same way are, in everything we keep, the same single number.

Two things that would be easy to overclaim, so we will not.

It goes to our own server, not to an analytics company. There is no analytics script, no ad pixel and no third-party tag anywhere in this app. You can turn this off under Your data in Settings, and nothing is sent from then on, including after you erase your data, which does not switch it back on.

Syncing, if you turn it on

Syncing is off until you switch it on. With it on, your favorites, history, and check-in log are stored with our hosting provider (Netlify) so your other devices can fetch them. The stored copy is filed under an opaque code derived from your billing record rather than under your name or email; we hold the key that connects the two, so treat it as personal data, because we do. Turning syncing off stops uploads. Erasing your data from Settings offers to erase the stored copy with it, and it keeps offering that even if your purchase is later refunded: syncing is what you were paying for, and removing what it left behind is not. You can also write to support@untilt.poker from the address you paid with and we will remove it.

The switch travels with the data, so you set it once rather than on every device you own: turning syncing on makes it on wherever you are signed in, and turning it off turns it off there too. That is how a device you have never touched the switch on can start syncing (because you turned it on somewhere else), and the app says so on screen when it does. To make that possible, a device signed in to a purchase asks once when it opens whether you have turned syncing on. That question sends nothing about you: no favorites, no history, no check-ins, only the session you already have. Devices that could not sync anyway (not signed in, or signed in with a shared passcode) do not ask at all.

Paying

There are two ways to buy this and they keep different things, so both are described. Which one applies is simply where you bought it.

On the web, checkout and billing happen at Stripe. Your card number never touches our servers. Stripe keeps what payment processors keep: your email, your billing history, and, where you provided one, a billing address for tax. We add small notes of our own to your Stripe record, and this is all of them: whether you bought lifetime access and which offer you bought it under, the one-time value behind your most recent sign-in link and when that link stops working, when a link was last mailed to you, the same pair again for a code proving an address on an App Store purchase, a one-way keyed hash of your address that the three apps use as a name for you, and, if either has happened, that access was revoked or that you closed your account. There is no card number in any of it and nothing about what you listen to. Stripe's own privacy policy is at stripe.com/privacy.

In the iPhone app, ours or TiltProof's, the purchase happens at Apple. We never see a card, an email, a name or an address, because Apple does not send us one. What the app sends us is the App Store transaction id, and we ask Apple to confirm it rather than believing it.

We then keep one record of our own so the same purchase can unlock the library again on another device, or after a reinstall. It is held at Stripe, alongside the web records, and for an App Store purchase it holds four things: that transaction id, a note that this is lifetime access, the App Store country Apple reports the purchase came from, and which of the two apps it was bought in. There is no card on it and no way to contact you from it. Apple holds the money, and Apple's own privacy policy is at apple.com/legal/privacy.

The two paths do not meet on their own, and one consequence is worth stating plainly: an App Store purchase leaves no email address here, so a sign-in link has nothing to find it by. Restore a purchase in the app is what brings it back, and that asks Apple rather than us.

You can give us an address if you want to, and it is worth saying what that is for rather than leaving it as a form. One price covers three apps, and the other two have no way to know who you are without one, so an App Store purchase on its own reaches only this app. An address also gives you a way back in on a new device that does not go through Apple.

It is never taken on trust. We mail a code to the address and write nothing down until you type it back, so an address entered by mistake leaves no trace at all: while we are waiting, the only things on your record are a one-time value and when it stops working, neither of which is about you. Once you confirm it, the address goes on the record and so does the one-way keyed hash of it that the three apps use as a name for you. Nothing here happens unless you ask for it, and an App Store purchase you never name stays exactly as described above.

Signing in

Signing in works by emailing you a link. Your address is used to look up your billing record at Stripe and to send that one email, through our mail provider (Resend). We keep no list of addresses of our own, and the link in the mail carries no email address in it.

Once you are signed in, Settings can tell you which address your access is attached to, so you are not left guessing which of your mailboxes bought it. It is read from Stripe at the moment you look and kept nowhere afterwards: not in the cookie, not on the server, not on your device. An App Store purchase has no address on it at all, and Settings says so rather than leaving a blank.

The other two apps

One purchase covers Untilt, TiltProof and Log. They are three separate websites, so being signed in here does not sign you in there, and nothing passes between them on its own. Opening one of the others from Settings, or from the screen you see after buying, is you asking us to carry it across.

When you ask, we make a one-time code and send your browser to that app with it. The code is random and says nothing by itself. What it stands for is a short note on our server: which account it is for, which of our billing records to read your access from, and which one app is allowed to spend it. That note is filed under a one-way hash of the code, so it is of no use to anybody who reads the storage without holding the code, and it is deleted the moment the code is spent. It lasts ninety seconds either way.

The other app then receives a signed string saying who you are and what you may use. It carries the keyed hash of your address described under Paying, not the address itself, and it is good for thirty days. What each app keeps afterwards is its own business and its own privacy page: Log holds that string, because it needs it to sync; TiltProof reads what it says, unlocks the drills, and keeps nothing.

The code travels in the part of a web address that browsers never send to a server, so it does not appear in our logs, in the other app's logs, or in anything either page loads afterwards.

The one cookie

The site sets a single cookie that records what you may play: free or everything. It lasts thirty days and renews as you use the app. It identifies your entitlement, not your browsing; there are no tracking cookies here, ours or anyone else's.

Your choices