Privacy Notice
Effective and last updated: August 8, 2026
1. Controller and contact
Isaac Andrey Vinluan Ulanday, an individual in Malta operating as Pledged, is the controller for the personal data described here unless another party is identified for a specific activity.
Correspondence address: Oakscourt, Triq id-Dolmen, Marsaskala, Malta.
Privacy requests: pledged-privacy.turkey923@simplelogin.com
General support: pledged-support.strainer662@simplelogin.com
2. Scope
This notice covers the Pledged mobile app, account and authentication services, commitments, notifications, subscriptions, optional consequence payments, product analytics, support, and related public pages.
Apple, Google, Stripe, RevenueCat, Supabase, Expo, your bank, and other independent services may also process information under their own notices.
3. Data we collect
- Account and profile: user ID, email, username, self-declared age band, authentication state, timezone, settings, and onboarding state.
- Commitments: habit and task details, schedules, deadlines, thresholds, verification and miss records, leeway, appeals, status history, and accountability text you choose.
- Subscriptions: product, entitlement, provider identifiers, status, trial, renewal, cancellation, and expiration data.
- Optional financial consequences: amount, currency, Stripe identifiers, authorization state, payment attempts, refunds, and consequence history. Stripe, not Pledged, collects full card details.
- Notifications and installations: push token, installation identifier, platform, permission state, delivery state, timezone, and interactions.
- Limited analytics and attribution: random installation/session IDs, event and screen names, timestamps, onboarding responses, selected values, and campaign/referrer parameters when present.
- Security and communications: authentication events, errors, provider logs, fraud-prevention signals, support messages, privacy requests, and appeal communications.
Do not place passwords, full payment details, health information, or other unnecessary sensitive information in free-text fields.
4. Why we use data
- Contract and requested steps: create and secure accounts, provide commitments and appeals, manage paid access, prepare requested payment authorization, and perform deletion.
- Legitimate interests: secure the service, prevent fraud and abuse, diagnose failures, maintain audit integrity, respond to support, and improve reliability through proportionate analytics.
- Consent or device choice: send push notifications and use optional permissions where permission is required.
- Legal obligations and claims: retain or disclose limited records where required for tax, accounting, payment, consumer protection, regulation, disputes, or security.
5. Automated commitment and payment logic
Pledged compares server time and recorded completion state with the schedule, timezone, thresholds, and consequence you selected. A threshold can create a consequence case and, after the displayed review process, initiate the exact authorized charge.
Safeguards include a pre-activation summary, locked material settings, the displayed review period, eligible appeals, available leeway, provider authentication when required, payment idempotency, and support for correcting technical or unauthorized charges.
6. Processors and recipients
- Supabase: authentication, database, server functions, logs, and infrastructure.
- Apple and Google: distribution, store purchases, subscriptions, device services, and platform security.
- RevenueCat: purchase validation and entitlement lifecycle.
- Stripe and payment networks: optional payment-method setup, authentication, charges, refunds, and fraud prevention.
- Expo: app updates and push-notification delivery infrastructure.
- Advisers, authorities, courts, or a legitimate acquirer: only when reasonably necessary for advice, law, safety, claims, or a lawful business transfer.
We do not sell personal data, use it for third-party targeted advertising, or use third-party advertising trackers.
7. International transfers
Some providers may process information outside Malta, the European Economic Area, or your country. Where transfer rules apply, we rely on an adequacy decision, approved contractual safeguards such as standard contractual clauses, or another lawful mechanism.
8. Retention
- Account, profile, age-band, and commitment data is kept while the account exists and is removed from active Pledged systems through account deletion, subject to the limited exceptions below.
- Server analytics and attribution are kept only while reasonably needed to understand onboarding, improve reliability, troubleshoot failures, or prevent abuse, then deleted or converted into statistics that no longer identify a user.
- Support, privacy, and complaint correspondence is kept while needed to respond, follow up, protect users, resolve a dispute, or establish or defend a legal claim.
- Security and abuse-prevention logs are kept while reasonably needed to investigate incidents, protect the service, prevent repeated abuse, or meet applicable legal requirements. Provider log periods may be shorter.
- Transaction, refund, consequence-payment, tax, and accounting records are kept for the period required by applicable law and while reasonably needed for an unresolved payment, fraud, chargeback, dispute, or legal claim.
- Provider recovery copies, fraud records, and logs follow the provider's documented technical or legal retention cycle and remain access-restricted.
We determine retention from the purpose of the record, whether the account or matter remains active, provider technical limits, and applicable legal requirements. Records kept after account deletion are restricted to those purposes and removed when the reason for keeping them ends.
9. Security
Pledged uses encrypted transport, provider-managed encryption at rest, authenticated sessions, row-level access controls, least-privilege service roles, protected payment identifiers, idempotent payment operations, and restricted administrative functions. No service can guarantee absolute security.
10. Your choices and rights
Where applicable, you may access, correct, delete, restrict, object to, or receive a portable copy of personal data, and withdraw consent for optional processing. You may also complain to the Malta Information and Data Protection Commissioner or another competent supervisory authority.
Send requests to pledged-privacy.turkey923@simplelogin.com. We may need to verify account ownership.
11. Account deletion
Delete your account in the app or use the public account deletion page. Deletion removes the authentication account and associated app data from active systems, subject to limited legally required payment, tax, fraud, dispute, and security records. Deleting Pledged does not cancel an Apple or Google subscription.
13. Age policy
Pledged is for ages 13 and older and is not intended for children under 13. The app asks for a self-declared age range and blocks an under-13 declaration. Users aged 13-17 may use paid access and non-financial accountability features, but V1 does not allow them to create financial or hybrid consequences.
Self-declaration is not identity verification. If we learn that an age declaration is inaccurate, we may restrict the account, stop future financial activity, investigate existing authorizations or charges, and request appropriate adult or guardian involvement. A parent or guardian who believes a child under 13 supplied personal data should contact the privacy address.
14. Changes and contact
We may update this notice when the product, providers, law, or data practices change. We will update the effective date and provide additional notice or request consent where required.
Privacy: pledged-privacy.turkey923@simplelogin.com
Support: pledged-support.strainer662@simplelogin.com
Legal notices: pledged-legal.parkway277@simplelogin.fr
This Privacy Notice is a launch draft pending appropriate Malta/EU legal review and verification against the exact released product and provider configuration.