Privacy Policy

Last Updated: September 12, 2026

Contents

The Doommate mobile application (the “App” or the “Service”) is developed and operated by Levente Bokor, a private individual residing at Siófoki utca 7, 8621 Zamárdi, Somogy, Hungary (“we”, “us”, or “our”).

This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service. We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

By using the Service, you consent to our data practices as described below.

1. Lawful Basis and Transparency

We process personal data based on:

We inform you of data collection via this Privacy Policy, which is linked from the App’s Settings screen. Processing is fair, and is not detrimental, unexpected, or misleading.

2. Information We Collect

We minimise data collection for specific purposes. We collect the following information to provide and improve the Service.

a. Account Registration

Data: Sign in with Apple is the only authentication method offered. The App requests your name and email address from Apple and transmits the resulting Apple identity token to our authentication provider. Our authentication provider stores the Apple-issued account identifier, the email address contained in that token, and a user identifier it generates for your account. If you use Apple’s “Hide My Email” feature, the address we receive is an Apple relay address and we do not receive your actual address.

Purpose: Account creation, authentication, and restoring your data on a new device.

Legal Basis: Contract.

Note: The App does not read, display, or transmit your name or email address. It uses only the user identifier. Sign-in is not required to use the Service; if you do not complete sign-in, the App operates in offline mode and no data is transmitted to us.

b. Operation and Activity Data

Data: Where you are signed in, the following records are stored against your user identifier:

Purpose: To deliver the Service and to restore your data when you install the App on a new device or reinstall it.

Legal Basis: Contract.

c. Screen Time Selections

Data: When you select applications or categories to block, iOS presents its own system picker and returns opaque tokens. These tokens are references issued by iOS; they do not contain application names, bundle identifiers, or icons, and cannot be resolved to them by us. The encoded selection is stored on our servers so that your configuration is restored on a new device.

Purpose: To apply and restore the blocking configuration you chose.

Legal Basis: Contract.

Note: Because application names are not available to the App, the record of a blocked selection is stored as a count, for example 4 apps and 2 categories, and not as a list of applications. The App does not request or receive Screen Time usage reports, and therefore does not collect any measurement of how long you spend in any application. Where iOS supplies the identity of an application to the App’s shield extension in order to display a block screen, that information is compared against the App itself and is otherwise discarded; it is not stored or transmitted.

d. Behavioural Metrics

Data: Ten measures derived from the records in section 2b: completion rate, intensity preference, daily consistency, effort profile, grade trajectory, routine stability, abandon pattern, directive diversity, return velocity, and clearance spending. Each is stored only as a value from 1 to 4, together with its previous value and a pending transition indicator.

Purpose: To adapt the App’s in-app messaging to your usage.

Legal Basis: Contract.

Note: Each metric has a minimum-data threshold below which no value is produced or stored.

e. Analytics Data

Data: A fixed set of product events, each recorded with your user identifier and the time it occurred on your device:

EventAccompanying data
onboarding_page_viewThe onboarding page reached.
onboarding_page_completeThe onboarding page completed.
reauth_completedNone.
activation_shownOperation duration in days; number of targets selected.
activation_cta_tappedNone.
directive_loggedDirective name; whether instant; duration in minutes.
op_startedIntensity name and ratio; duration in days; daily goal; daily free clearance.
op_endedOutcome; grade; days completed.
metric_bucket_changedMetric identifier; previous and new value; direction of change.

Purpose: To analyse onboarding completion and Service performance, and to improve the App.

Legal Basis: Legitimate interests.

Note: These events are stored in our own database. No third-party analytics software development kit is integrated into the App. Events are queued on your device, up to a maximum of 300, and transmitted when a connection and a signed-in session are available. Events generated during onboarding, before sign-in is complete, are transmitted under your user identifier once the account is created; if you do not sign in, they are never transmitted. Where a custom directive is logged, the directive_logged event includes the name you supplied for it.

f. Subscription Data

Data: Paid access is sold as an Apple in-app subscription. Payment is processed by Apple. Subscription state is managed by RevenueCat, to which the App transmits your user identifier so that entitlements follow your account rather than a single device. RevenueCat receives purchase and entitlement information from Apple.

Purpose: To determine and restore your access to paid features.

Legal Basis: Contract.

Note: We do not receive or store your payment card details, billing address, or Apple Account credentials. The App does not transmit your name, email address, or any record described in section 2b to RevenueCat, and does not enable RevenueCat’s device-identifier or advertising-attribution collection features.

g. Data Stored Only on Your Device

The following is retained locally by the App and is not transmitted to us:

h. Information We Do Not Collect

3. Purpose and Data Minimisation

We collect only data necessary for the declared purposes. Records that can be derived on your device are not stored on our servers. Screen Time selections are stored in the encoded form issued by iOS and are not resolved into application names. Behavioural metrics are stored only as bucketed values and not as the underlying calculations. We do not process data beyond the purposes stated in this Policy, and we do not process any of it for advertising.

4. Data Accuracy and Security

Accuracy: Your data is generated by your own use of the App and can be corrected or removed through the controls described in section 8. Contact [email protected] to correct inaccuracies.

Security: We implement technical and organisational measures to protect your data, including:

No system is fully secure, and we cannot guarantee absolute security.

5. Storage Limitation

We retain personal information as follows:

Data held only on your device, as described in section 2g, is removed when you delete the App.

6. Privacy by Design

We embed privacy by design through:

7. Controller–Processor Contracts

We maintain contracts with the following processors:

Contracts stipulate processor responsibilities, security measures, and the return or deletion of data upon termination.

8. Data Subject Rights

You have the following rights:

The App provides the following controls in its Settings screen:

Subscriptions: Deleting your account does not cancel an Apple subscription. Subscriptions must be cancelled through Apple, either from the Manage Subscription screen in the App or in iOS Settings.

You may also exercise your rights by contacting [email protected]. We respond within one month, which may be extended where a request is complex. Requests may be refused where legally permitted, for example where identity cannot be verified.

9. Data Protection Inquiries

For data protection inquiries or supervisory authority interactions, contact us at [email protected].

10. International Data Transfers

Your data is stored with Supabase, Inc. on servers located in Ireland, within the European Union. If the hosting location changes, we will update this Policy. Where a third-party service processes data outside your jurisdiction, including transfers to the United States, we rely on appropriate safeguards such as Standard Contractual Clauses. Apple and RevenueCat process data in accordance with their own published privacy policies.

11. Data Breach Reporting

If a breach presents a risk to your rights and freedoms, we will notify the competent supervisory authority, the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), within 72 hours, and affected users without undue delay. Processors are required to notify us without delay.

12. How We Use Your Information

We process your information on the legal bases set out in section 1. Uses include:

13. Sharing Your Information

We share information as follows:

No Sale: We do not sell personal information as defined by the CCPA, and we do not share personal information for cross-context behavioural advertising. We do not disclose any personal information to advertising networks or data brokers.

14. Child Users

The Service is not directed at children under 13, and we do not knowingly collect their personal information. You must be at least 13 years old to use the Service. If we learn that a user is under 13, we will terminate the account and delete the associated data.

15. Updates to This Policy

We may update this Policy to reflect changes to the Service or legal requirements. Updates will be published at the address linked from the App’s Settings screen before taking effect, with in-app notice for material changes where required. Continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.

16. Contact

Levente Bokor is the data controller under GDPR.

Contact us at:

Levente Bokor
Siófoki utca 7
8621 Zamárdi
Somogy, Hungary

Email: [email protected]

For EU users, you may lodge a complaint with the NAIH (naih.hu) or with the supervisory authority of your country of residence. For UK users, you may contact the Information Commissioner’s Office at ico.org.uk. For California residents, you may contact the California Attorney General.

17. Additional Information for California Residents

Under the CCPA, California residents have specific rights:

see also → Terms of Use