Bounty Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains how Bounty Accountability LLC ("Bounty," "we," "us," or "our") collects, uses, and shares information when you use the Bounty mobile application and related services (the "Service").
By using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, do not use the Service.
1. Who we are
The Service is operated by Bounty Accountability LLC. For any privacy questions or requests, contact us at bountyacctblty@gmail.com.
2. Information we collect
Information you provide
- Account information: first and last name, username, email address, and phone number.
- Profile information: optional bio and profile photo.
- Goal and commitment data: the goals you create, the penalty amounts you agree to, check-in schedules, and the commitment terms you accept.
- Payment information: to charge a penalty when you fail a commitment, you provide payment details. Card and bank details are collected and processed directly by Stripe; we do not store full card or bank numbers on our servers. We retain Stripe identifiers (such as a customer ID and payment-intent references) and records of charges and penalties (amounts, currency, status, and date).
Information we collect to verify check-ins
Depending on the goals you set up and the permissions you grant, we may collect:
- Photos you submit as proof of a check-in, whether captured with your camera or selected from your photo library. These are stored in Microsoft Azure Blob Storage and may be sent to OpenAI for automated verification of whether the submission matches your goal.
- Location data, collected only while you are actively using the app to complete a location-based check-in. We do not collect your location in the background.
- Apple Health data, for goals you verify with Apple Health. The metric you choose (for example steps, exercise minutes, workouts, sleep, or running/walking distance and duration) is read from Apple Health on your device; we receive only that day's total for the one metric your goal tracks, plus the bundle identifier of the app that recorded it (used to detect hand-entered or fabricated data). We do not send Apple Health data to OpenAI or any other AI provider, use it for advertising, or share it with data brokers.
- Screen Time data, for goals you verify with Screen Time. If your goal checks in automatically, your device compares your app usage against your target and sends us only a pass/fail result for each day — the amount of time you spent in an app is never sent to or stored on our servers; we do store timestamps showing whether on-device monitoring is currently active, so a broken connection isn't mistaken for a missed goal. If you use manual verification instead, the screenshot you choose to submit is stored in Microsoft Azure Blob Storage and sent to OpenAI for automated review.
- Time-lapse check-in frames, for goals you verify with time-lapse. While you record a check-in, the app captures still camera frames and uploads them to our servers as you go, stored in Microsoft Azure Blob Storage. A subset of frames is sent to OpenAI to verify the check-in and to screen it for content that isn't safe for a general audience — only frames that pass this screening can ever be shown to other users (see Section 4). We also record the time received, file size, and a hash for each frame to help detect tampering. If you never finish a recording, its frames are deleted within about 48 hours; if a recording is submitted but fails verification, its frames are deleted within 7 days.
We collect this information only in connection with goals you set up and check-ins you choose to perform.
Information collected automatically
- Device and usage data, including a push-notification device token, app interactions, and diagnostic and performance data (for example, through Microsoft Application Insights) used to operate and improve the Service.
- Authentication identifiers, including an Apple user identifier or Google user identifier if you sign in with Apple or Google.
Information stored only on your device
If you enable biometric (Face ID / Touch ID) sign-in, your login credentials are encrypted and stored in your device's secure storage. This information is not transmitted to or stored on our servers, and we do not collect your biometric data.
The same is true of the detail behind your Apple Health and Screen Time check-ins: your individual Health samples, and which apps you used and for how long, are read and compared entirely on your device. Only the single summary value described above — a daily total, or a pass/fail result — is ever sent to us.
3. How we use information
We use the information we collect to:
- create and manage your account and authenticate you;
- operate the core commitment feature, including verifying check-ins — by photo, location, Apple Health, Screen Time, or time-lapse video, depending on the goal — and determining whether a commitment was met;
- process penalty charges and related payments through Stripe when a commitment is not met;
- record a charitable donation, made by Bounty from its own funds, when you designate a charity for a commitment (see the Terms of Service for how this works);
- send you transactional messages and notifications (for example, reminders, account messages, and password resets) by push notification or email;
- provide customer support;
- monitor, secure, debug, and improve the Service; and
- comply with legal obligations.
4. How we share information
With other users
Bounty includes social features such as friend connections, profiles, an activity feed, and comments. Information you choose to share — including your username, profile photo, bio, the goals and check-ins you make visible, the photos or time-lapse frames attached to those check-ins, and your comments — may be visible to other users of the Service. Time-lapse frames are only ever shown to other users if they passed the automated content-safety screening described in Section 2; frames that don't pass, or that were never screened, are visible only to you. Please do not share content you would not want others to see.
With service providers
We do not sell your personal information. We share information with the following categories of third parties to operate the Service:
| Provider | Purpose | Information shared |
|---|---|---|
| Stripe | Payment processing and payouts | Payment details (collected by Stripe), name, email, charge and payout records |
| OpenAI | Automated verification of check-in submissions, and content-safety screening of photos and time-lapse frames before they can appear on the activity feed | Submitted check-in photos, screenshots submitted for manual Screen Time verification, a sampled subset of time-lapse frames, and your goal description |
| Pledge (Pledgeling Technologies, Inc.) | Recording charitable donations made by Bounty when you designate a charity | The donation amount and the charity you selected. We do not share your name, email, or any other personal information with Pledge or the charity — Bounty is the donor of record. |
| Email provider (SMTP) | Transactional email | Email address and message content |
| Microsoft Azure | Hosting, database, file storage, and push delivery | Account data, uploaded media, device push tokens |
| Apple / Google | Sign-in and push delivery | Authentication identifiers, device tokens |
| Cloudflare | Network and security provider for our marketing website — including determining your country from your IP address for waitlist acquisition analytics, and, when enabled, bot protection on the waitlist form (see Section 12) | As the network provider sitting in front of our marketing website, Cloudflare receives your IP address and browser characteristics for requests to that site. When Turnstile bot protection is enabled, we also send Cloudflare the verification token it produces, along with our secret key, to confirm the submission isn't automated |
We may also disclose information to comply with applicable law, to enforce our Terms, or to protect the rights, safety, and property of Bounty, our users, or others. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
5. Data retention
We retain your information for as long as your account is active or as needed to provide the Service, and as required to comply with our legal obligations, resolve disputes, and enforce our agreements. We retain records of charges and penalties as needed for financial, accounting, and legal purposes. Uploaded media and verification data (including check-in photos, Screen Time screenshots, and time-lapse frames) are retained as needed to provide and support the Service — for example, an approved time-lapse frame is kept for as long as its check-in remains part of your goal history. Time-lapse frames are deleted sooner when a recording never becomes a real check-in: within about 48 hours if you never submit it, and within 7 days if it's submitted but fails verification.
Deleting your account removes your sign-in credentials and personal profile information, and ends your active goals. It does not automatically delete content you already submitted for a check-in — such as photos, Screen Time screenshots, or time-lapse frames — or the Apple Health or Screen Time values recorded for past check-ins; we may retain that information, associated with your deleted account, for the reasons described above. Contact us at the email in Section 1 if you'd like previously submitted check-in content removed.
6. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at bountyacctblty@gmail.com. You can also:
- manage app permissions (camera, location, photos, Health, and Screen Time) in your device settings;
- update profile information in the app;
- remove a saved payment method in the app's Settings; and
- delete your account directly in the app, from the Settings screen — see Section 5 for what this does and does not remove. You may also request deletion by contacting us at the email above.
We will respond to verified requests as required by applicable law. We will not discriminate against you for exercising your privacy rights.
7. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and reliance on Stripe for payment data. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
8. Children's privacy
The Service is intended only for adults. You must be at least 18 years old (or the age of majority in your jurisdiction) to use the Service, as described in our Terms of Service. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact us at bountyacctblty@gmail.com and we will take appropriate steps to delete it.
9. International users
We operate the Service in the United States. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States, where data-protection laws may differ from those in your country.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
11. Contact us
Bounty Accountability LLC Email: bountyacctblty@gmail.com
12. Website waitlist
This section covers the waitlist signup form on our marketing website (bountylockin.com), which is separate from the mobile app account described above. Waitlist information is stored using the same Microsoft Azure hosting and database infrastructure described in Section 4.
What we collect. If you join the waitlist, we collect the email address you provide. When the form has bot protection enabled, we also use Cloudflare Turnstile to verify you're not an automated submission — see Section 4 for what that involves. If a phone number field is enabled on the form, providing a phone number is optional, and checking a separate, unchecked-by-default box is required before we will send text messages — joining the waitlist with only your email does not sign you up for texts.
Acquisition analytics. We also automatically collect some information about how you found the waitlist page and what you're using to view it: the referring website, but only when it's another site (we don't record a referrer when you're just navigating within bountylockin.com); any utm_source, utm_medium, or utm_campaign values present in the link you followed; a general device-type category — mobile, tablet, or desktop — derived from your browser's User-Agent header, which identifies a kind of device, not your specific device; and your country, determined from your IP address by Cloudflare, our network provider — we store only the two-letter country code Cloudflare gives us, not your IP address. We use this information to understand how people find Bounty.
Who can see it. Waitlist entries, including the acquisition analytics described above, are visible only to authorized Bounty administrators.
Why we collect it. We use this information to notify you when Bounty launches and to send related product updates, and, if you've separately consented, to text you about the same.
SMS consent is separate. Text message consent is never implied by submitting the form with an email address alone. It requires its own opt-in, and you can decline it while still joining the waitlist by email.
Retention. A waitlist signup isn't tied to an account, so it doesn't age off the way account data does under Section 5. We keep your waitlist information for as long as it's needed to send the launch and product notifications described above, or as required to comply with our legal obligations. If you unsubscribe, we don't delete your signup — we change its status to unsubscribed and keep a record of that request so we don't contact you again. Your waitlist information is deleted only if you request it, as described below.
Unsubscribing or requesting deletion. To unsubscribe from waitlist emails or texts, or to request deletion of your waitlist information, contact us at bountyacctblty@gmail.com.