Effective Date: April 19, 2026
This Privacy Policy explains how Oath (“Oath,” “we,” “us,” “our”) collects, uses, shares, and protects information about you when you use our website, mobile apps, and related services (collectively, the “Service”).
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
Plain-language note:
Oath uses Firebase Auth for sign-in, Stripe for payments, and Supabase Postgres for database storage. To verify an oath we use the source you choose for it — for example Apple Health (distance and steps), Strava, LeetCode, GitHub, or device location for gym check-ins. This data is used only to verify and settle your oaths, never for advertising, and is never sold. See sections E–H below for details.
If you have questions, requests, or complaints about privacy, contact us at the email above.
Oath does not store your full card number or bank account number. Payments are processed by Stripe (and its affiliates). We may receive and store:
If you withdraw funds, our payment partners may require identity verification (e.g., legal name, address, date of birth, government ID). This is typically collected by Stripe in its onboarding flow.
We may receive limited status signals (e.g., “verification complete,” “payouts enabled,” requirement flags) needed to operate withdrawals.
To verify discipline completion, we collect and process data associated with your LeetCode account, such as:
We do not control LeetCode’s privacy practices.
If you connect your Strava account to verify a running or cycling oath, we access your Strava data through Strava’s official API under your OAuth authorization. We collect and process:
activity type, distance, moving_time, start_date, and activity id.Purpose. Strava data is used only to verify completion of running and cycling oaths you have staked on. We apply data minimization: only fields necessary for oath verification are fetched, and only the staking user’s own activities are read.
Retention. Raw activity cache is purged within 7 days. Verification outcomes (a boolean pass/fail and the staked dollar amount) are retained indefinitely as part of the underlying oath record for audit, dispute resolution, and financial integrity.
Sharing. Opponents and group members never see another user’s Strava data. They see only the boolean win/loss outcome and the dollar amount associated with the oath.
User control. You can disconnect Strava at any time via Settings → Disconnect Strava, which calls Strava’s deauthorize endpoint and revokes our tokens. You may also revoke access directly at https://www.strava.com/settings/apps.
AI / ML disclaimer. Strava data is never used to train machine-learning models, build analytics products, or for any purpose other than verifying the specific oath the user has staked on.
We do not control Strava’s privacy practices.
If you grant HealthKit permissions on iOS to verify a running or step-count oath, we read a narrow set of data via Apple’s HealthKit framework, limited to:
On-device by default. HealthKit data lives on your device. The Oath iOS app reads only the samples needed to verify your oath and transmits a minimal verification payload (aggregated distance or step total for the oath window) to our backend over TLS.
Purpose limitation. We use HealthKit data solely to verify completion of running and step-count oaths you have created. We do not use HealthKit data for advertising or marketing, we do not share it with third parties, and we do not use it to train machine-learning models.
Retention. Raw HealthKit samples are not stored on our servers beyond what is needed to compute the verification result. The verification outcome (boolean pass/fail and the staked dollar amount) is retained as part of the underlying oath record.
User control. You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → Oath.
We use your information to:
We share information only as described below:
We share information with vendors that help us run Oath, including:
These providers process data under contractual obligations to protect it and use it only to provide services to us.
We access and process data from LeetCode (or related endpoints) to verify completion of contract tasks. We may store derived results (e.g., “completed/not completed for checkpoint X”) and related logs for auditability.
Depending on your settings and the features enabled:
We do not share your full payment details with other users.
We may share information if:
We retain personal data only as long as necessary for the purposes described in this Policy or to comply with legal, accounting, dispute-resolution, and fraud-prevention obligations. Defensible retention periods by category:
| Category | Retention | Reason |
|---|---|---|
| Account profile (name, email) | Life of account + 30 days post-deletion | Operational, dispute window |
| Authentication credentials | Deleted on account deletion | Security |
| Transaction records (stake, payout, fees) | 7 years | IRS and BSA recordkeeping |
| Oath records and outcomes | Life of account + 1 year | Dispute evidence |
| Photo proof uploads | 90 days post-settlement | Dispute window, then deleted |
| Geofence and GPS samples | 30 days post-settlement | Verification, then deleted |
| Strava raw activity cache | ≤ 7 days | Strava API Agreement |
| HealthKit raw samples | Not stored beyond verification compute | Apple HealthKit guidance |
| Fitbit raw data | ≤ 7 days raw | Mirror of Strava minimization |
| Push notification tokens | Until invalidated or account deleted | Operational |
| Email logs (Resend) | 90 days | Deliverability debugging |
| PostHog event data | 12 months, then aggregated | Product analytics |
| Vercel access logs | 30 days | Security and abuse |
| Support communications | 3 years | Reference for repeat issues |
| Database backups | 35 days rolling | Disaster recovery |
You may request deletion at any time. We may need to retain limited records for legal compliance, ongoing disputes, fraud prevention, or to honor obligations to other users (for example, the counterparty's record of a joint oath).
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data. You can also withdraw consent for processing based on consent, and delete your account directly in the iOS app under Settings → Account → Delete Account.
To submit a request, email support@joinoath.net with:
We respond within 30 days (extendable once for complex requests). We may verify your identity before fulfilling requests. If we cannot fulfill a request, we will explain why.
If you are in the EEA, UK, or Switzerland, you have rights under the GDPR / UK GDPR including access, rectification, erasure, restriction of processing, portability, objection, withdrawal of consent, and the right to lodge a complaint with your local supervisory authority.
Our lawful bases for processing include: performance of a contract (account creation, oath settlement), legal obligation (KYC, tax records), legitimate interest (fraud prevention, product analytics), and your explicit consent (health and fitness data, marketing communications).
International transfers from the EEA, UK, or Switzerland to the United States are governed by the European Commission's Standard Contractual Clauses (Module 1 or 2 as applicable) and the UK International Data Transfer Addendum.
California residents have rights to know, delete, correct, port, opt out of sale or sharing, and limit use of sensitive personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA / CPRA.
We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request from California residents.
Sensitive Personal Information we collect includes financial account information (handled by Stripe), precise geolocation (for gym geofence verification), and account login credentials. You may request that we limit our use of this information to providing the Service by emailing support@joinoath.net with subject line "Limit Use of Sensitive Personal Information."
You may also designate an authorized agent to make requests on your behalf with written, signed authorization.
Residents of these states have rights under their respective state privacy laws including access, deletion, correction, portability, and opt-out of targeted advertising or profiling. Submit requests through the email above. We honor universal opt-out signals where required by state law.
We do not use your personal data, fitness data, photos, oath content, or messages to train, develop, or improve any artificial intelligence or machine-learning model. We do not provide your data to third parties for such purposes. Verification automation (deciding whether an oath was completed) is a deterministic rule-based check on third-party data, not a model trained on user data.
Oath verification is automated. When a verification source confirms or denies that you completed your oath, settlement (payout or forfeit) is processed automatically based on those signals. Stripe also runs automated fraud and risk checks on payments and payouts.
You can dispute an automated outcome by submitting a dispute through the in-app dispute flow. Disputed outcomes are reviewed by a human before final resolution.
If a data breach involving your personal data occurs, we will notify the relevant supervisory authorities within 72 hours where required by GDPR or UK GDPR, and we will notify affected users without undue delay through email or in-app notification. We will provide details on the nature of the breach, the data involved, the likely consequences, and the steps we are taking to mitigate.
We use administrative, technical, and physical safeguards designed to protect your data. However, no system is 100% secure. You are responsible for securing your account (e.g., protecting your Google account and devices).
Oath is not intended for children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact us at the email above.
Oath is currently intended for users in the United States. If you access the Service from outside the U.S., you understand your information may be processed and stored in the United States and other locations where our service providers operate.
We may update this Policy from time to time. We will update the "Effective Date" and may provide additional notice (e.g., in-app or by email) for material changes. Your continued use of the Service after the update means you accept the revised Policy.