Skip to main content

Privacy policy

What we collect, where it lives, who else can see it, and how you get rid of it.

01.

The short version

We collect what we need to run the app: your email, your display name, your habit selection, your daily submissions, and your subscription status. We don't sell your data. We don't run ads. We don't share anything with anyone except the four sub-processors listed in section 04.

You can read the long version below, or just delete your accountif you'd rather not.

02.

What we collect

Account data: email, password (hashed by Supabase Auth), display name, date of birth, optional bio, preset avatar choice.

Habit data: your chosen habit, habit color, daily submission timestamps, optional 160-character submission notes, streak history, ⭐ balance (it floors at 0, it never goes negative).

Group data: which groups you belong to, plus your strikes and miss history within each group.

Support messages: if you write to us through the contact form, we keep your message, the category you picked, and the email address you choose to leave (if any) so we can write back.

Device data: push notification token (so we can deliver reminders you've opted into), platform (iOS/Android), and a generic version string.

Subscription data: purchase status from the App Store / Google Play, relayed via RevenueCat. We do not see your card details or store any payment information.

03.

What we don't collect

Location. Contacts. Photos library. Microphone audio. Calendar. Accessibility-service event streams. Health data. Browsing history outside Kleeve. We never ask for these permissions and the app's manifest reflects that.

04.

Sub-processors we use

Kleeve delegates specific functions to four sub-processors. Each one is contracted to handle data only on our instructions:

  • Supabase: database, authentication, storage, and realtime. Hosts your account data, habit data, and group data. Region: Singapore (sin1). Privacy: supabase.com/privacy
  • RevenueCat: subscription management. Receives anonymized purchase events from the App Store and Google Play; we use them to grant or revoke Premium access. Privacy: revenuecat.com/privacy
  • PostHog: anonymous product analytics. Receives event names (e.g. submission_created) tied to an anonymous user ID. No email, no display name, no submission content. You can opt out in Settings → Privacy. Privacy: posthog.com/privacy
  • Sentry: error monitoring with PII scrubbing. Captures crash stack traces from the app. A beforeSend filter strips email patterns and display-name strings before the event leaves your device. Privacy: sentry.io/privacy

We don't use any other third-party processor at v1.0. If that changes we'll update this page and notify you in the app at least 30 days before the new sub-processor is engaged.

05.

Who sees your data inside Kleeve

Members of your group(s) can see: your display name, your habit color, your submission timestamps, the optional note attached to a submission, your strikes-remaining count, and your group streak.

Nobody outside your group can see any of that. There is no public profile, no follower count, and no discovery surface. The founder (the one-person company operating Kleeve) has technical access to all data via the Supabase admin console and uses that access only for support requests and moderation review. Every admin query is logged in the Supabase audit log.

06.

How long we keep it

While your account is active, all of it. When you delete your account, your personal data (email, display name, bio, preset avatar, push token) is scrubbed after a 14-day grace period. Aggregate group history (submission timestamps, streak counts) is preserved in anonymized form so your former group's history doesn't break (your row reads “deleted user”).

07.

How to see, correct, or delete your data

See and edit: Settings → Account inside the app (display name, bio, email, push preferences).

Delete: Settings → Account → Delete Account inside the app, or the delete-account page from any browser without the app installed.

Export: ask through the contact formand pick “Data export request”. We'll send you a JSON export within 30 days.

08.

If you're under 18

Don't use Kleeve. We gate signup at 18+ via date-of-birth check and confirmation. If you've created an account anyway and you're under 18, reach us through the contact form, pick “Underage account”, and we'll delete it without a grace period.

09.

Reach the human

The contact formis how you reach us. One person reads every message (the founder), so it's a real human on the other end. Reply time is usually within 2 business days.