Privacy Policy

Last updated: February 2026

1. What We Collect

  • Account information: Email address for authentication (via email+password, Apple Sign-In, or Google Sign-In).
  • Payment information: Processed securely via Stripe. We store a Stripe customer ID and payment method ID on your profile. We never store your full card number.
  • Voice and audio data: When you use the mirror feature, your voice is streamed in real-time to ElevenLabs for speech-to-text transcription. Audio is processed in real-time and is not stored as audio files.
  • AI-processed data: Transcripts from voice input are sent to OpenAI to extract task descriptions. Only the text transcript is sent, not the audio.
  • Task and pact data: Your daily tasks, pact status, completion timestamps, and forfeit history.
  • Usage data: App interactions, timestamps, and navigation patterns.
  • Push notification tokens: If you enable notifications, we store your device push token via Expo's push notification service.
  • Country-level location: We use request headers (via Vercel) to determine your country for geo-gating purposes. We do not access GPS or precise location data.
  • Timezone: Your device timezone is stored to determine your daily deadline.

2. How We Use Your Data

  • To provide the accountability service (tracking tasks, processing forfeits)
  • To authenticate your account
  • To process payments when you break your pact
  • To send transactional emails (account verification, receipts)
  • To send push notifications (pact reminders, forfeit alerts)
  • To extract tasks from your voice input using AI
  • To restrict the Service to supported countries
  • To improve the app experience

3. Third-Party Services

We share data with the following services to operate BATSU:

  • Stripe: Payment processing and subscription management
  • Supabase: Authentication, database, and data storage
  • ElevenLabs: Real-time speech-to-text transcription
  • OpenAI: Task extraction from voice transcripts
  • Expo: Push notification delivery
  • AWS SES: Transactional email delivery
  • Vercel: Website hosting and analytics

We do not sell your personal data to any third party.

4. Data Storage & Processing

Your data is stored securely using industry-standard encryption. All data processing occurs on US-based servers. Supabase hosts our database and authentication. Voice data is processed in real-time and not persisted as audio.

5. Data Retention

We retain your data for as long as your account is active. Task history and forfeit records may be retained for billing and record-keeping purposes. You can request deletion at any time (see Your Rights below).

6. Your Rights

  • Request a copy of your data
  • Request deletion of your account and associated data
  • Opt out of non-essential communications

To exercise these rights, contact us at ak.labz.mvp@gmail.com

7. California Residents (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Delete your personal information
  • Opt out of the sale of your personal information — we do not sell your data
  • Non-discrimination for exercising your privacy rights

To make a request, email ak.labz.mvp@gmail.com with “CCPA Request” in the subject line.

8. Children's Privacy

BATSU is not intended for anyone under the age of 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us and we will delete it.

9. Changes

We may update this policy. Significant changes will be communicated via email or in-app notification.

10. Contact

Questions? Email ak.labz.mvp@gmail.com