Oath Privacy Policy

Effective Date: April 19, 2026

Related:Third-Party Services Notice

This Privacy Policy explains how Oath (“Oath,” “we,” “us,” “our”) collects, uses, shares, and protects information about you when you use our website, mobile apps, and related services (collectively, the “Service”).

By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

Plain-language note:

Oath uses Firebase Auth for sign-in, Stripe for payments, and Supabase Postgres for database storage. To verify an oath we use the source you choose for it — for example Apple Health (distance and steps), Strava, LeetCode, GitHub, or device location for gym check-ins. This data is used only to verify and settle your oaths, never for advertising, and is never sold. See sections E–H below for details.

1) Who we are and how to contact us

  • Controller: Oath
  • Privacy contact: support@joinoath.net

If you have questions, requests, or complaints about privacy, contact us at the email above.

2) Information we collect

A) Information you provide

  • Account information: name, email address, profile photo (as provided via Google sign-in), username or handle you choose, timezone preferences.
  • Social / friend features: invitations you send, friend relationships, messages or notes you submit (if enabled).
  • Support requests: information you send to customer support.

B) Information collected automatically

  • Device and usage data: IP address, device identifiers, browser type, app version, pages/screens viewed, actions taken (e.g., create contract, accept, check now), referring URLs, timestamps, and error logs.
  • Cookies and similar technologies: used for authentication/session management, security, and analytics (where enabled).

C) Payment and financial information

Oath does not store your full card number or bank account number. Payments are processed by Stripe (and its affiliates). We may receive and store:

  • Payment status and metadata: deposit amount, timestamps, payment method type (e.g., card), last 4 digits (if provided to us), payment intent/charge IDs, and dispute/chargeback indicators.
  • Wallet/ledger records: amounts credited, pending, reserved/locked, paid out, fees, and charity allocations.

D) Identity verification (KYC) for withdrawals

If you withdraw funds, our payment partners may require identity verification (e.g., legal name, address, date of birth, government ID). This is typically collected by Stripe in its onboarding flow.

We may receive limited status signals (e.g., “verification complete,” “payouts enabled,” requirement flags) needed to operate withdrawals.

E) Task verification data (MVP: LeetCode)

To verify discipline completion, we collect and process data associated with your LeetCode account, such as:

  • your LeetCode username/identifier you provide or link,
  • signals indicating whether you completed the required activity within checkpoint windows (e.g., solved count / timestamps, depending on what the integration provides),
  • logs about verification attempts (success/failure, timestamps) for auditability and debugging.

We do not control LeetCode’s privacy practices.

F) Strava integration (running and cycling oaths)

If you connect your Strava account to verify a running or cycling oath, we access your Strava data through Strava’s official API under your OAuth authorization. We collect and process:

  • Activity fields: activity type, distance, moving_time, start_date, and activity id.
  • Account identifiers: your Strava athlete ID.
  • OAuth credentials: access and refresh tokens, stored encrypted, used solely to call the Strava API on your behalf.

Purpose. Strava data is used only to verify completion of running and cycling oaths you have staked on. We apply data minimization: only fields necessary for oath verification are fetched, and only the staking user’s own activities are read.

Retention. Raw activity cache is purged within 7 days. Verification outcomes (a boolean pass/fail and the staked dollar amount) are retained indefinitely as part of the underlying oath record for audit, dispute resolution, and financial integrity.

Sharing. Opponents and group members never see another user’s Strava data. They see only the boolean win/loss outcome and the dollar amount associated with the oath.

User control. You can disconnect Strava at any time via Settings → Disconnect Strava, which calls Strava’s deauthorize endpoint and revokes our tokens. You may also revoke access directly at https://www.strava.com/settings/apps.

AI / ML disclaimer. Strava data is never used to train machine-learning models, build analytics products, or for any purpose other than verifying the specific oath the user has staked on.

We do not control Strava’s privacy practices.

G) Apple HealthKit (running and step-count oaths on iOS)

If you grant HealthKit permissions on iOS to verify a running or step-count oath, we read a narrow set of data via Apple’s HealthKit framework, limited to:

  • Walking and running distance samples for the specific oath window.
  • Daily step count samples for the specific oath window.

On-device by default. HealthKit data lives on your device. The Oath iOS app reads only the samples needed to verify your oath and transmits a minimal verification payload (aggregated distance or step total for the oath window) to our backend over TLS.

Purpose limitation. We use HealthKit data solely to verify completion of running and step-count oaths you have created. We do not use HealthKit data for advertising or marketing, we do not share it with third parties, and we do not use it to train machine-learning models.

Retention. Raw HealthKit samples are not stored on our servers beyond what is needed to compute the verification result. The verification outcome (boolean pass/fail and the staked dollar amount) is retained as part of the underlying oath record.

User control. You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → Oath.

H) Other verification sources (GitHub, Fitbit, geofence, photo proof)

  • GitHub: public commit and pull-request metadata for the user account you link, used to verify GitHub commit oaths.
  • Fitbit: calorie and activity data accessed via OAuth for calorie-tracking oaths; treated under the same minimization, retention, and AI/ML rules described above for Strava.
  • Geofence verification (Gym oaths): precise location samples taken during check-in, used solely to confirm presence within the geofenced gym location during the check-in window. Location data is not retained beyond the dispute window for that oath.
  • Photo proof (Custom and Gym oaths): images you upload as proof. Stored encrypted and retained for 90 days after oath settlement for dispute resolution, then deleted.

3) How we use information

We use your information to:

  • Provide the Service: create accounts, authenticate users, display dashboards, manage friends/invites, and run contracts.
  • Run verification and settlement: determine contract outcomes using verification sources and execute wallet updates.
  • Process payments and withdrawals: facilitate deposits, manage pending/available/reserved balances, and initiate payouts.
  • Prevent fraud and abuse: detect suspicious activity, enforce rules, and secure accounts.
  • Customer support: respond to requests and troubleshoot issues.
  • Improve the Service: analytics, debugging, testing, and product development.
  • Legal/compliance: comply with law, enforce our terms, and maintain records.

4) How we share information

We share information only as described below:

A) Service providers (processors)

We share information with vendors that help us run Oath, including:

  • Firebase (Google) for authentication (Google sign-in) and related services.
  • Stripe for payment processing (deposits) and payouts/withdrawals (Stripe Connect Express), including identity verification (KYC), AML/sanctions screening, and 1099-K issuance where applicable. Stripe acts as an independent controller for KYC, payment processing, and fraud screening data, governed by the Stripe Connected Account Agreement and Stripe Privacy Policy. Oath does not store full card numbers or bank account numbers.
  • Supabase (and underlying cloud providers) for hosting and database infrastructure (Postgres).
  • PostHog for product analytics and event tracking. PostHog data is used solely for product improvement, not for cross-context behavioral advertising.
  • Resend for transactional email delivery (account, verification, settlement notifications).
  • Firebase Cloud Messaging (FCM) for push notifications.
  • Vercel for web hosting and edge logging.

These providers process data under contractual obligations to protect it and use it only to provide services to us.

B) Verification sources

We access and process data from LeetCode (or related endpoints) to verify completion of contract tasks. We may store derived results (e.g., “completed/not completed for checkpoint X”) and related logs for auditability.

C) With other users (social features)

Depending on your settings and the features enabled:

  • other users may see your profile (e.g., name, username, photo),
  • contract participants can see contract-related status (e.g., whether you completed a checkpoint, contract outcome),
  • friends/invitees may see invitations you send and basic identifying info.

We do not share your full payment details with other users.

D) Legal, safety, and business transfers

We may share information if:

  • required by law or legal process,
  • needed to prevent fraud or security issues,
  • necessary to enforce our Terms or protect users,
  • part of a merger, acquisition, financing, or sale of assets (we’ll provide notice where required).

5) Cookies and tracking

  • We use cookies and similar technologies for authentication and session security, preventing abuse, remembering preferences, and analytics (if enabled).
  • You can control cookies through your browser settings, but some features may not work without them.

6) Data retention

We retain personal data only as long as necessary for the purposes described in this Policy or to comply with legal, accounting, dispute-resolution, and fraud-prevention obligations. Defensible retention periods by category:

CategoryRetentionReason
Account profile (name, email)Life of account + 30 days post-deletionOperational, dispute window
Authentication credentialsDeleted on account deletionSecurity
Transaction records (stake, payout, fees)7 yearsIRS and BSA recordkeeping
Oath records and outcomesLife of account + 1 yearDispute evidence
Photo proof uploads90 days post-settlementDispute window, then deleted
Geofence and GPS samples30 days post-settlementVerification, then deleted
Strava raw activity cache≤ 7 daysStrava API Agreement
HealthKit raw samplesNot stored beyond verification computeApple HealthKit guidance
Fitbit raw data≤ 7 days rawMirror of Strava minimization
Push notification tokensUntil invalidated or account deletedOperational
Email logs (Resend)90 daysDeliverability debugging
PostHog event data12 months, then aggregatedProduct analytics
Vercel access logs30 daysSecurity and abuse
Support communications3 yearsReference for repeat issues
Database backups35 days rollingDisaster recovery

You may request deletion at any time. We may need to retain limited records for legal compliance, ongoing disputes, fraud prevention, or to honor obligations to other users (for example, the counterparty's record of a joint oath).

7) Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data. You can also withdraw consent for processing based on consent, and delete your account directly in the iOS app under Settings → Account → Delete Account.

To submit a request, email support@joinoath.net with:

  • the email on your account,
  • the type of request (access, correction, deletion, portability, opt-out, restriction),
  • any additional context that helps us locate your records.

We respond within 30 days (extendable once for complex requests). We may verify your identity before fulfilling requests. If we cannot fulfill a request, we will explain why.

European Economic Area, United Kingdom, and Switzerland

If you are in the EEA, UK, or Switzerland, you have rights under the GDPR / UK GDPR including access, rectification, erasure, restriction of processing, portability, objection, withdrawal of consent, and the right to lodge a complaint with your local supervisory authority.

Our lawful bases for processing include: performance of a contract (account creation, oath settlement), legal obligation (KYC, tax records), legitimate interest (fraud prevention, product analytics), and your explicit consent (health and fitness data, marketing communications).

International transfers from the EEA, UK, or Switzerland to the United States are governed by the European Commission's Standard Contractual Clauses (Module 1 or 2 as applicable) and the UK International Data Transfer Addendum.

California (CCPA / CPRA)

California residents have rights to know, delete, correct, port, opt out of sale or sharing, and limit use of sensitive personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA / CPRA.

We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request from California residents.

Sensitive Personal Information we collect includes financial account information (handled by Stripe), precise geolocation (for gym geofence verification), and account login credentials. You may request that we limit our use of this information to providing the Service by emailing support@joinoath.net with subject line "Limit Use of Sensitive Personal Information."

You may also designate an authorized agent to make requests on your behalf with written, signed authorization.

Other US states (CO, CT, VA, UT, TX, OR, MT, DE, IA, NH, NJ)

Residents of these states have rights under their respective state privacy laws including access, deletion, correction, portability, and opt-out of targeted advertising or profiling. Submit requests through the email above. We honor universal opt-out signals where required by state law.

8) AI and machine-learning policy

We do not use your personal data, fitness data, photos, oath content, or messages to train, develop, or improve any artificial intelligence or machine-learning model. We do not provide your data to third parties for such purposes. Verification automation (deciding whether an oath was completed) is a deterministic rule-based check on third-party data, not a model trained on user data.

9) Automated decision-making

Oath verification is automated. When a verification source confirms or denies that you completed your oath, settlement (payout or forfeit) is processed automatically based on those signals. Stripe also runs automated fraud and risk checks on payments and payouts.

You can dispute an automated outcome by submitting a dispute through the in-app dispute flow. Disputed outcomes are reviewed by a human before final resolution.

10) Data breach notification

If a data breach involving your personal data occurs, we will notify the relevant supervisory authorities within 72 hours where required by GDPR or UK GDPR, and we will notify affected users without undue delay through email or in-app notification. We will provide details on the nature of the breach, the data involved, the likely consequences, and the steps we are taking to mitigate.

11) Security

We use administrative, technical, and physical safeguards designed to protect your data. However, no system is 100% secure. You are responsible for securing your account (e.g., protecting your Google account and devices).

12) Children's privacy

Oath is not intended for children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact us at the email above.

13) International users

Oath is currently intended for users in the United States. If you access the Service from outside the U.S., you understand your information may be processed and stored in the United States and other locations where our service providers operate.

14) Changes to this Privacy Policy

We may update this Policy from time to time. We will update the "Effective Date" and may provide additional notice (e.g., in-app or by email) for material changes. Your continued use of the Service after the update means you accept the revised Policy.

15) Quick reference: What we collect and why (summary)

  • Firebase Auth / Google sign-in: to authenticate you and secure accounts.
  • Stripe payment metadata (independent controller): to process deposits/withdrawals, KYC, AML, and 1099-K.
  • Supabase Postgres records: to store oaths, checkpoints, balances, and transaction audit trail.
  • LeetCode, GitHub, Strava, Fitbit, HealthKit signals: to verify oath completion only; never used to train ML models or for advertising.
  • Geofence + photo proof (Gym/Custom oaths): to verify in-person presence; deleted on retention schedule above.
  • PostHog, Vercel, Resend logs: to keep the Service reliable, debug, and prevent abuse.