UpHeld Privacy Policy
UpHeld is a habit-verification app made by Upheld Corp ("we," "us"). This policy explains what information UpHeld collects, how it is used, and the choices you have. If anything here is unclear, email us at jayden@upheldcorp.com.
The short version
- Verification photos are analyzed by AI and then discarded — never stored.
- UpHeld never accesses your photo library. The camera is used only when you actively take a verification photo.
- Your account and habit data live in a secured database that only your account can read.
- Payments are handled by Apple. We never see your card number.
- The device-lock feature is voluntary and only affects your own device with your permission.
1. Verification photos
To verify a task, you take a photo inside the app. That photo is sent over an encrypted connection to our server, analyzed by an AI model (currently provided by Anthropic) solely to decide whether it shows the task being done, and then discarded. The photo is never written to disk, never saved to any storage bucket, and never retained by us after the verification decision is made. What we keep is only the outcome: whether the check-in was verified, the timestamp, and the attempt count.
UpHeld requests camera access only. It never requests, and has no code path for, photo-library access — you cannot upload an existing photo, and the app cannot see your camera roll.
2. Information we store
Your account data is stored with Supabase, our database and authentication provider. This includes:
- Account: email address, birthdate (used once to confirm you are 13 or older), and timezone.
- Tasks and check-ins: the tasks you create, their schedules, and each occurrence's outcome (verified, missed, or skipped) with timestamps.
- Streaks and badges: your streak counts and earned badges.
- Subscription state: your current plan tier and subscription status (see Payments below).
- Enforcement events: if you enable the device-lock feature, records of when locks engaged and how they lifted, plus tamper-detection signals (for example, that a required permission was revoked).
- Support messages: messages you send through in-app support.
Every table is protected by row-level security: database rules ensure your data can be read and written only by your own authenticated account.
3. Payments
Subscriptions are billed by Apple through your App Store account. We use RevenueCat to manage subscription state. We receive subscription status (plan, renewal, expiration, billing issues) — never your payment card details. To cancel, use your App Store subscription settings; deleting the app does not cancel a subscription.
4. The voluntary device-lock feature
UpHeld's enforcement feature can temporarily limit access to other apps on your device when a task deadline passes unverified. This feature is off by default and entirely opt-in. On iOS it uses Apple's Family Controls framework under individual authorization — meaning you authorize it for your own device, for yourself. Apple's screen-time frameworks process which apps are limited on-device; UpHeld does not receive a list of the apps you use. Locks are time-bounded and always release automatically. Emergency calls always work.
5. Error monitoring
We use Sentry to collect crash and error reports so we can fix bugs. These reports include technical information such as device model, OS version, and the state of the app when the error occurred. They are used only for diagnosing and fixing problems.
6. Under 13
UpHeld accounts require you to be at least 13 years old. We ask for your birthdate at sign-up and refuse account creation under 13. We do not knowingly collect personal information from children under 13; if you believe a child under 13 has created an account, contact us and we will delete it. A future family plan (not yet available) will introduce parent-managed child profiles; this policy will be updated before that feature launches.
7. What we don't do
- We do not sell your personal information.
- We do not access your photo library, contacts, or location.
- We do not store verification photos.
- We do not use your data to train AI models.
8. Service providers
We share data only with the processors needed to run the app: Supabase (database, authentication, serverless functions), Anthropic (transient AI analysis of verification photos and powering the in-app support assistant), RevenueCat (subscription management), Sentry (error monitoring), and Apple (billing, notifications). Each receives only what its function requires.
9. Your choices and rights
- You can view and edit your tasks and account data in the app.
- You can disable the device-lock feature, reminders, and sounds at any time in Settings.
- You can request access to, correction of, or deletion of your account data by emailing jayden@upheldcorp.com. Deleting your account removes your personal data from our systems.
- Depending on where you live, you may have additional rights under local privacy law; contact us to exercise them.
10. Security
Data is encrypted in transit. Database access is gated by authenticated row-level security, and privileged operations (verification decisions, badge grants, subscription state) run only on the server — the app itself can never award or change them.
11. Changes
We will update this policy as the app evolves (for example, when family profiles launch) and will note the new effective date at the top. Material changes will be communicated in the app.
12. Contact
Upheld Corp — jayden@upheldcorp.com