Privacy
Last updated September 10, 2026
The short version: what you do in the app stays on your device unless you turn on syncing, paying happens at Stripe, and there is no analytics script, no ad pixel, and no third party watching you meditate. Once a week this app sends a few words about your device, described in full below down to what it cannot promise; it asks you first, sends nothing until you answer, and you can change your mind either way afterwards.
On your device
Your favorites, session history, check-in log, and settings live in your browser's own storage, on your device. None of it is uploaded unless you turn on syncing; until you do, no record of what you played, when you played them, or what you answered a check-in is sent anywhere. Turn syncing on and those three carry between your own devices, and nothing else does; the section below has the exact shape of it. You can erase all of it at any time from Settings.
The one measurement
We are trying to answer one question: do the people who use check-ins keep using the app longer than the people who do not? That decides what gets built next, and there is no way to answer it from a device that says nothing at all.
So, at most once a week, the app sends three words about this device. A fourth, whether you are paying, is read by the server from the session you already have, rather than sent by your device:
- whether you use check-ins: never, tried, or regular;
- roughly how long you have had the app: one of week, month, quarter, older;
- how many sessions you have played, as one of 0, 1, 2-5, 6-20, 21-50, 50+, so a small number is exact and a large one is only ever a band;
- whether you are on the free tier or a paid one. This one your device does not send at all: the server reads it from the cookie your browser already sends on every page, and writes down only free or paid.
You are asked before any of it is sent. The switch that controls this starts on, and a switch starting on is a default rather than anything you agreed to -- so the app holds the first message and puts the question to you instead, in the app, with the same list you are reading here. Until you answer, nothing is sent. Answer either way and it is remembered; the switch in Settings changes it again whenever you like, and turning it off survives erasing your data, because a withdrawn answer is not ours to erase on your behalf.
The question waits for the first message to actually come due, which is a day after you install, rather than interrupting you the moment you open the app. Devices that were already reporting before this existed are asked too: the point of asking is that nobody ever had been.
That is the entire message. There is no name, no email, no account, no device id, no random identifier, no address and no time of day in it, and nothing in it says what you played or what you answered. What we keep is a tally: for each combination, how many devices said it. No message is stored, so two people who use the app the same way are, in everything we keep, the same single number.
Two things that would be easy to overclaim, so we will not.
- The message travels over your ordinary session. It is an ordinary request from the app, so your browser sends the same cookie it sends when you load any page. If you have paid, that cookie identifies your billing record, which is how the server knows whether to write down free or paid. We do not record it, join it to anything, or keep it. But we could have, and a promise that we could not would not be true, so we are telling you what we actually do instead.
- The endpoint is rate limited, like our sign-in is. To stop somebody flooding it, the server keeps one counter per network address per endpoint (a number and the time the current window ends), filed under a one-way keyed hash of the address. It is overwritten rather than added to, so it is never a log of your visits, it holds nothing about you or your device, and it cannot be turned back into an address by someone who does not already have the address. It is the same counter that has always stood in front of sign-in and checkout. We do not delete these, and the storage they sit in has no automatic expiry, so you should assume the most recent one for your address is still there.
It goes to our own server, not to an analytics company. There is no analytics script, no ad pixel and no third-party tag anywhere in this app. You can turn this off under Your data in Settings, and nothing is sent from then on, including after you erase your data, which does not switch it back on.
Syncing, if you turn it on
Syncing is off until you switch it on. With it on, your favorites, history, and check-in log are stored with our hosting provider (Netlify) so your other devices can fetch them. The stored copy is filed under an opaque code derived from your billing record rather than under your name or email; we hold the key that connects the two, so treat it as personal data, because we do. Turning syncing off stops uploads. Erasing your data from Settings offers to erase the stored copy with it, and it keeps offering that even if your purchase is later refunded: syncing is what you were paying for, and removing what it left behind is not. You can also write to support@untilt.poker from the address you paid with and we will remove it.
The switch travels with the data, so you set it once rather than on every device you own: turning syncing on makes it on wherever you are signed in, and turning it off turns it off there too. That is how a device you have never touched the switch on can start syncing (because you turned it on somewhere else), and the app says so on screen when it does. To make that possible, a device signed in to a purchase asks once when it opens whether you have turned syncing on. That question sends nothing about you: no favorites, no history, no check-ins, only the session you already have. Devices that could not sync anyway (not signed in, or signed in with a shared passcode) do not ask at all.
Paying
There are two ways to buy this and they keep different things, so both are described. Which one applies is simply where you bought it.
On the web, checkout and billing happen at Stripe. Your card number never touches our servers. Stripe keeps what payment processors keep: your email, your billing history, and, where you provided one, a billing address for tax. We add small notes of our own to your Stripe record, and this is all of them: whether you bought lifetime access and which offer you bought it under, the one-time value behind your most recent sign-in link and when that link stops working, when a link was last mailed to you, the same pair again for a code proving an address on an App Store purchase, a one-way keyed hash of your address that the three apps use as a name for you, and, if either has happened, that access was revoked or that you closed your account. There is no card number in any of it and nothing about what you listen to. Stripe's own privacy policy is at stripe.com/privacy.
In the iPhone app, ours or TiltProof's, the purchase happens at Apple. We never see a card, an email, a name or an address, because Apple does not send us one. What the app sends us is the App Store transaction id, and we ask Apple to confirm it rather than believing it.
We then keep one record of our own so the same purchase can unlock the library again on another device, or after a reinstall. It is held at Stripe, alongside the web records, and for an App Store purchase it holds four things: that transaction id, a note that this is lifetime access, the App Store country Apple reports the purchase came from, and which of the two apps it was bought in. There is no card on it and no way to contact you from it. Apple holds the money, and Apple's own privacy policy is at apple.com/legal/privacy.
The two paths do not meet on their own, and one consequence is worth stating plainly: an App Store purchase leaves no email address here, so a sign-in link has nothing to find it by. Restore a purchase in the app is what brings it back, and that asks Apple rather than us.
You can give us an address if you want to, and it is worth saying what that is for rather than leaving it as a form. One price covers three apps, and the other two have no way to know who you are without one, so an App Store purchase on its own reaches only this app. An address also gives you a way back in on a new device that does not go through Apple.
It is never taken on trust. We mail a code to the address and write nothing down until you type it back, so an address entered by mistake leaves no trace at all: while we are waiting, the only things on your record are a one-time value and when it stops working, neither of which is about you. Once you confirm it, the address goes on the record and so does the one-way keyed hash of it that the three apps use as a name for you. Nothing here happens unless you ask for it, and an App Store purchase you never name stays exactly as described above.
Signing in
Signing in works by emailing you a link. Your address is used to look up your billing record at Stripe and to send that one email, through our mail provider (Resend). We keep no list of addresses of our own, and the link in the mail carries no email address in it.
Once you are signed in, Settings can tell you which address your access is attached to, so you are not left guessing which of your mailboxes bought it. It is read from Stripe at the moment you look and kept nowhere afterwards: not in the cookie, not on the server, not on your device. An App Store purchase has no address on it at all, and Settings says so rather than leaving a blank.
The other two apps
One purchase covers Untilt, TiltProof and Log. They are three separate websites, so being signed in here does not sign you in there, and nothing passes between them on its own. Opening one of the others from Settings, or from the screen you see after buying, is you asking us to carry it across.
When you ask, we make a one-time code and send your browser to that app with it. The code is random and says nothing by itself. What it stands for is a short note on our server: which account it is for, which of our billing records to read your access from, and which one app is allowed to spend it. That note is filed under a one-way hash of the code, so it is of no use to anybody who reads the storage without holding the code, and it is deleted the moment the code is spent. It lasts ninety seconds either way.
The other app then receives a signed string saying who you are and what you may use. It carries the keyed hash of your address described under Paying, not the address itself, and it is good for thirty days. What each app keeps afterwards is its own business and its own privacy page: Log holds that string, because it needs it to sync; TiltProof reads what it says, unlocks the drills, and keeps nothing.
The code travels in the part of a web address that browsers never send to a server, so it does not appear in our logs, in the other app's logs, or in anything either page loads afterwards.
The one cookie
The site sets a single cookie that records what you may play: free or everything. It lasts thirty days and renews as you use the app. It identifies your entitlement, not your browsing; there are no tracking cookies here, ours or anyone else's.
Your choices
- Erase everything on a device from Settings, any time.
- Turn syncing off, any time, and erase the stored copy from Settings including after a purchase is refunded, or ask us to.
- Close your account from Settings, which ends access, erases the stored copy and signs this device out. Billing records stay at Stripe for as long as tax law requires.
- Turn the weekly measurement off in Settings, any time, and erasing your data will not turn it back on. There is no message of yours to delete afterwards, because none is stored and nothing in one identifies you. If you want the rate-limit counter described above removed as well, write to us with the address it was made from and we will remove it.
- Ask what we hold about you, or ask for it to go away: support@untilt.poker. Billing records at Stripe are kept as long as tax law makes us.