🔒 LockIn

Privacy Policy

Last updated 20 July 2026

LockIn ("we", "us") is a social accountability app operated from the United Kingdom. This policy explains what we collect, why, and your rights. Questions: admin@getlockin.me.

What we collect.

Account data: email address, handle, display name, password (stored as a salted hash; absent for Google sign-in), timezone. Content you create: proof photos, voice-memo and text excuses, check-in history, streaks, league memberships. Technical data: device push tokens, and short-lived server logs (IP addresses, request metadata) for security and debugging.

How we use it.

To run the service you signed up for (scheduling check-ins, verifying proof, showing your activity to your league), to send the notifications the app is built around, and to keep the service secure. Legal bases under UK GDPR: performance of our contract with you, and legitimate interests in securing and improving the service.

Who sees your content.

LockIn is social by design: members of a league you join can see your handle, display name, streaks, check-in outcomes, proof photos, and excuses (text and voice). Anyone you give an invite code to can join your league and see that content. Nothing you post is public beyond your leagues.

Processors we use.

Anthropic (automated verification of proof photos: your photo and your league's goal criteria are sent to Anthropic's API and are not used to train their models per their commercial terms); Google Firebase (push notifications and crash reporting); Amazon Web Services (photo and voice-memo storage); Railway (application hosting); Resend (transactional email). Each processes data on our instructions.

International transfers.

Our processors may store data outside the UK (including the US and EU) under appropriate safeguards such as the UK Addendum to Standard Contractual Clauses.

Retention.

Your data is kept while your account exists. When you delete your account (in the app: Settings → Delete account; or on the web: /delete-account), your profile is immediately and permanently de-identified, your sign-in credentials and push tokens are removed, and your proof photos and voice memos are deleted from storage within 30 days. Residual copies in encrypted backups and server logs expire within 90 days.

Your rights.

Under UK GDPR you can ask us for access to, correction of, or deletion of your data, object to or restrict processing, and request portability. Write to admin@getlockin.me. You can also complain to the Information Commissioner's Office (ico.org.uk).

Children.

LockIn is not for children under 13, and we do not knowingly collect their data.

Changes.

We'll update this page and the date above when the policy changes; material changes will be flagged in the app.

Privacy Policy · Terms · Delete your account