Legal
Privacy Policy
This Privacy Policy explains how Oftring Ventures, LLC collects, uses, discloses, and retains information in connection with lock in.
1. Scope
This Privacy Policy applies to the lock in website, waitlist and account flows, and the native lock in iOS app. The website and iOS app have different payment and advertising practices where explained below.
lock in is operated by Oftring Ventures, LLC. The business website is oftring.io, but these disclosures apply to the lock in service itself.
2. Information we collect
We collect information directly from you, automatically from your device and browser, and from service providers that help us operate the product.
- Account, profile, and access data, such as your email address, name, handle, biography, profile photo, visibility choice, sign-in activity, and session information.
- Waitlist, support, and other content you provide, such as submitted email addresses, request metadata, support communications, appeals, and reviews.
- Commitment and rule data, such as titles, saved place names and physical addresses, coordinates, place-search queries, schedules, windows, penalty ladders, monthly caps, consent records, and configuration history.
- Check-in and precise geolocation data, such as latitude, longitude, accuracy, timestamp, optional altitude, heading and speed readings, permission and app context, check-in results, review actions, and related diagnostics captured during an active check-in or review flow.
- Screen Time configuration and event data, such as authorization and device status, device identifiers, app version, goal and limit configuration, selection counts, a locally generated selection identifier, threshold events, mercy-period events, revocation events, enforcement state, and timestamps.
- Billing and purchase-history data, such as Stripe customer and transaction identifiers, product-access, subscription, purchase, penalty, charge, refund and dispute states, payment-method readiness, and limited payment-method metadata. Full card numbers and security codes are entered on Stripe-hosted website checkout and are not collected through the native iOS app.
- Notification data, such as push tokens, the Apple vendor identifier, app version, email delivery records, reminder logs, and related device metadata.
- Product interaction, analytics, and technical data, such as feature events associated with your account, IP-derived or hashed signals, user-agent data, browser and app context, event identifiers, and security or troubleshooting events.
3. Sources of information
We collect information from you when you sign in, join the waitlist, create or manage commitments and Screen Time goals, check in, appeal an outcome, complete website checkout, or contact support.
We also receive information from your browser or device and from providers that support the service, including Apple, Supabase, Google Places, Stripe, PostHog, Vercel, Meta on the website when enabled, and communications or support providers.
4. How we use information
We use personal information to operate, secure, and improve lock in and to support the enforcement model that the service is built around.
- Provide sign-in, account access, and waitlist handling.
- Create, display, enforce, and manage commitments, Screen Time goals, and related scheduling data.
- Verify check-ins, evaluate borderline outcomes, investigate appeals, and explain historical results.
- Process website purchases, subscriptions, payment-method setup, missed-commitment charges, refunds, disputes, and billing support.
- Understand product use, diagnose failures, improve the service, and measure website advertising attribution and campaign performance where enabled.
- Send reminders, service messages, and support responses.
- Monitor availability, prevent abuse, enforce our Terms, comply with law, and improve product performance.
5. Precise geolocation
lock in uses precise geolocation to verify whether you were near the saved place during a scheduled check-in window and to support review, appeal, fraud prevention, and troubleshooting for that activity.
The iOS app requests foreground location for a check-in you initiate. It does not operate a continuous movement feed, and we do not use precise location for advertising or disclose it to data brokers.
6. Screen Time data
If you grant Apple's Family Controls authorization, the iOS app uses Apple's Screen Time frameworks to let you choose apps, categories, or websites for a goal and to apply the configured limits on your device.
The opaque Apple tokens that identify the specific apps, categories, and websites you select stay in the app's shared on-device storage and are not sent to lock in or PostHog. We receive the related configuration, counts, device and authorization status, and threshold, mercy, revocation, and enforcement events needed to synchronize and operate your goal.
We do not use Screen Time data for advertising, sell it, disclose it to data brokers, or combine it with third-party data to track you across other companies' apps or websites.
7. Analytics, website advertising, and tracking
The native iOS app has no advertising SDK, does not access the advertising identifier, and does not track you across other companies' apps or websites. Account-linked product and operational events from the service may be processed by PostHog for app functionality, analytics, reliability, and security.
The lock in website separately may use PostHog, Vercel Analytics, and, when enabled, the Meta Pixel and Meta Conversions API. Those website tools may process browser identifiers, cookies, IP address, user agent, visited URLs, event identifiers, registration or checkout events, campaign parameters, hashed email, and a hashed external account identifier for analytics and advertising measurement. Browser and device controls may limit cookies or similar technologies.
8. How we disclose information
We disclose information to service providers that process it for us to operate the service, including Apple for device and push services, Supabase for authentication, database and infrastructure, Google Places for place search, Stripe for website billing, PostHog for product and operational analytics, Vercel for website hosting and analytics, Meta for website advertising measurement when enabled, and communications or support providers.
We require service providers to handle information consistently with their role and applicable agreements. We may also disclose information if required by law, to protect rights and safety, investigate fraud or abuse, or as part of a merger, acquisition, financing, or similar business transaction.
We do not sell or rent personal information for money. We do not disclose precise location or Screen Time data for unrelated advertising or data-broker purposes.
9. Public profiles
If you deliberately enable a public profile or creator page, the profile fields and creator content shown in that experience can be viewed by others. You can use the product's visibility controls to keep a member profile private. Account deletion makes the profile private and removes identifying profile content as part of the deletion process.
10. Retention and account deletion
We keep information while your account is active and thereafter only for as long as reasonably necessary for the purposes described here, including account operation, transaction and tax records, disputes, refunds, fraud prevention, consent evidence, security, audits, and legal obligations. Operational logs and provider records may follow shorter or provider-specific retention periods, while legally required financial and authorization evidence may be retained longer.
Where the in-app deletion service is enabled, you can initiate account deletion from Settings in the iOS app. If the control reports that deletion is temporarily unavailable, contact support@lockin.im to request deletion. Once a confirmed request is accepted, lock in freezes new commitments, Screen Time events, notifications, and new billing activity, signs you out, and normally expects the automated process to complete within 24 hours. A payment already processing may delay completion until it reaches a safe final state.
Deletion removes or anonymizes account profile, location, check-in, Screen Time, push, device, and user-content data. We may retain the minimum de-identified transaction, tax, refund, dispute, fraud, consent, appeal, audit, and deletion-receipt facts permitted or required by law, without retaining full card data, precise location, Screen Time selections, or deleted profile content. Service-provider records are deleted, de-identified, or retained according to our instructions, applicable agreements, and legal requirements.
11. Your choices and requests
You can manage profile visibility and content, push permission and reminder preferences, Screen Time authorization, and certain other settings through the product. Website browser controls may limit cookies or similar technologies. Billing setup, purchases, and subscription management take place on the website.
When enabled for your account, you can request account deletion in iOS Settings. If in-app deletion is unavailable, or for other privacy questions and requests including access or correction where applicable, contact us at support@lockin.im. We may need to verify your identity and may retain limited records as permitted or required by law.
12. Security
We use administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
13. Minors
lock in is intended only for adults age 18 and older. We do not knowingly permit minors to use the service or knowingly collect personal information from children through the service.
14. Changes and contact
We may update this Privacy Policy from time to time. When we do, we will update the effective date and may provide additional notice if the changes are material.
Questions, requests, and notices may be sent to support@lockin.im.