Privacy Policy
Effective August 6, 2026
Coact ("we," "us," or "our") provides the Coact mobile app (the "App") and the website getcoact.com (the "Site") — together, the "Service". Coact is currently operated as a sole proprietorship pending incorporation, and its operator is the data controller for the personal information described in this policy. This policy explains what we collect, how we use it, what other users can see, and your rights. For any privacy question or request, contact help@getcoact.com.
Information We Collect
- Account & profile — username, email address, password (stored only as a salted hash, never in plain text), display name, birth year (we ask for your date of birth at signup to confirm you can use the Service, but keep only the year — it is never shown to other users), and optional bio, profile photo, banner, and featured badges.
- Challenges & activity — the goals you choose, challenges you create or join (type, duration, members), daily check-in records (date and time), streaks, trophies, badges, and battle pass progress.
- Photos & captions — your profile photo, optional check-in photos, and captions on posts.
- Messages — direct messages you send and receive, with timestamps and read status.
- Settings & preferences — your privacy choices (private account; who can message you, see your posts, or add you as a friend), activity-status and read-receipt settings, notification preferences and quiet hours, theme, and content settings.
- Notifications & devices — if you turn on push notifications, a device push token from Apple or Google so we can deliver them; we also record when you were last active to power activity status, which you can turn off.
- Social & safety — friends, follows, follow requests, blocks, mutes, reports you file (and reports about your content), and dispute votes.
- Rewards & shop — the sparks you earn and spend, a ledger of those transactions, and the items you own or have equipped. Everything in the shop is digital, so we do not ask for a delivery address. If an item has to be issued by hand, we record the request and its status.
- In-app activity analytics — the App records first-party product-usage events against your account (for example: a screen opened, a challenge created, a post shared), together with your platform (iOS or Android). We use these only to understand how the App is used and to fix problems. They are ours alone: they are not sent to any advertising or third-party analytics service.
- Site data — your email address when you join the waitlist (with your explicit consent), and — only after you accept analytics via the cookie banner — a randomly generated session ID, device type, referring URL, and on-page events.
- Technical — our hosting providers keep standard server request logs (IP address, user agent, timestamps) for security and operations. We also keep our own error logs, which may record the account involved in a failed request, to diagnose faults.
The App contains no advertising and no third-party analytics SDKs. We do not collect precise location, your contacts, payment information, or government identifiers.
Sensitive Goals
Some goals can reveal information about your health or lifestyle — for example "No Alcohol", "No Vaping", "No Smoking", "No Weed", or "No Adult Content". We use this information only to run your challenges and the features you choose, relying on the explicit consent you give by selecting the goal and its visibility. We never use it for advertising and never sell it.
You control who sees it: solo and private challenges keep your goal between you and your challenge members, while open clubs, the matchmaking pool, and feed posts can show other users which goal you are working on. Choose a visibility you are comfortable with.
Check-in Photos
Photos are optional. When you attach one to a check-in, it is sent to our server and stored as part of that check-in, then shown to the other members of that challenge — and, if you post it, in the feed — according to your visibility settings.
We do not run automated verification, facial recognition, or biometric identification on your photos: we do not try to identify who you are, and we do not create or store biometric identifiers such as faceprints. We may review a photo if it is reported or as needed to enforce our rules.
What Other Users Can See
- Your profile — username, display name, bio, avatar, banner, trophies, badges, streak, and post/follower/friend counts are visible to signed-in users. If you make your account private, people must request to follow you, and only approved followers and friends can see your posts.
- Leaderboards — your username, display name, avatar, and trophies are visible to everyone in the App.
- Feed posts — by default, posting a check-in to the feed makes it visible to all users in the discovery feed, together with the goal name; you can limit your posts to friends only in settings.
- Check-ins — including any attached photo, visible to the other members of that challenge.
- Matchmaking pool — while you wait for a random opponent, your username, avatar, trophies, and the goal you queued for are visible to other users browsing the pool.
- Disputes — if an opponent disputes your check-in, up to 10 mutual friends may be shown that check-in to vote on whether it looks legitimate.
- Activity status & read receipts — other users may see when you were last active and when you have read their messages, unless you turn these off in your privacy settings.
- Direct messages — visible to the recipient, who can report them to us. Who may start a conversation with you depends on your "who can message you" setting.
Messages and other content are stored on our servers and are not end-to-end encrypted; our systems (and, where required, we) can access them — for example when reviewing a report.
How We Use Information
We use your information to: provide and operate the Service (challenges, feeds, messaging, leaderboards, seasons); keep the Service safe (moderation, anti-cheating, blocking, muting, security); communicate with you (service emails about your account; push and in-app notifications you have enabled, such as messages, friend activity, cheers, comments, and reminders; and launch updates if you joined the waitlist); honor the privacy, visibility, and notification settings you choose; improve the Service using aggregated or de-identified usage; and comply with law.
Legal Bases For Processing (GDPR / UK GDPR)
- Contract (Art. 6(1)(b)) — providing the App and its features.
- Consent (Art. 6(1)(a)) — the waitlist, Site analytics, and optional photos. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and keeping the Service operational.
- Legal obligation (Art. 6(1)(c)) — where applicable.
- Explicit consent (Art. 9(2)(a)) — where a goal implies health information (e.g. substance cessation), given when you select that goal and its visibility; withdraw it by leaving the challenge or deleting your account.
Cookies and Local Storage (Site)
We store a consent preference and (after consent) a randomly generated session identifier in your browser's local storage. No tracking or analytics identifiers are set before you accept analytics. You can withdraw consent at any time by clicking "Decline" on the cookie banner or clearing your browser's local storage for getcoact.com.
Service Providers and Third Parties
We do not sell, rent, or share your personal information with any third party for their own marketing. We share information only with:
- Service providers (processors) — Railway, which hosts our API and database, including waitlist entries and consented Site analytics (privacy policy); Cloudflare, whose R2 object storage holds check-in and profile images where enabled (privacy policy); Vercel, which hosts the Site and provides cookieless, aggregate visitor analytics (privacy policy); Bunny Fonts, which serves Site fonts without logging IPs; Resend, which sends waitlist emails (when enabled); and Expo, our app build and update tooling and push-notification delivery service. Push notifications are routed via Expo to Apple Push Notification service and Google Firebase Cloud Messaging using a device token. They process data on our instructions under contractual safeguards.
- Other users — as described in "What Other Users Can See".
- Legal & safety — when required by law or to protect users, including reporting child sexual abuse material to NCMEC and law enforcement.
- Business transfer — if Coact is incorporated, merged, or acquired, data may transfer to the successor under this policy; we will notify you of material changes.
International Data Transfers
We are U.S.-based and process data in the United States. For transfers of EEA, UK, or Swiss personal data to the U.S., we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK / Swiss safeguards through our processors' data processing agreements. You can request a copy of the relevant safeguards by emailing us.
Data Retention
- Account and profile data — kept while your account is active.
- Check-ins (including attached photos) — kept as part of your challenge history until you delete them or your account. Removing a post from the feed un-shares it; the check-in record remains until deleted.
- Messages — kept until your account (or the other person's) is deleted.
- Reports, moderation actions, and account-security logs (such as password, email, username, and account-status changes) — up to 2 years, for safety, security, and legal compliance.
- Device push tokens — until you sign out, turn off notifications, or the device unregisters.
- Waitlist emails — until the App launches and we have notified you, plus 30 days, or until you request deletion.
- Spark ledger and shop records — kept as a record of what was earned, spent and issued, including after an account is deleted, so balances can be accounted for.
- In-app activity analytics and Site analytics — up to 24 months.
- Error logs — 30 days.
Residual copies may persist in encrypted backups for up to approximately 30 days after deletion.
Your Privacy Controls
You can manage what others see and how we contact you in Profile → Settings:
- Private account — require your approval before someone can follow you.
- Who can message you / see your posts / add you as a friend — limit each to everyone, friends, or no one.
- Activity status & read receipts — stop sharing when you were last active or whether you have read a message.
- Appear in search — control whether others can find you by name or username.
- Block & mute — block someone to mutually cut off contact, or mute them to quietly hide their content; manage both lists under Settings → Privacy & safety.
- Notifications — choose which push and email notifications you receive, and set quiet hours.
- Download your data — get a portable copy of your account data from Settings → Download my data.
Your Rights
Depending on where you live, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your information ("right to erasure").
- Restrict or object to our processing.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time, for any consent-based processing.
To exercise any of these rights, email help@getcoact.com from your account email address (that is how we verify requests). We respond within 30 days (45 days where some U.S. state laws apply, extendable with notice) and will not discriminate against you for exercising your rights. Authorized agents may submit requests where the law allows. If we deny a request, you may appeal by replying to our response.
EEA / UK residents — you also have the right to lodge a complaint with your local supervisory authority (edpb.europa.eu; UK: ico.org.uk).
California residents — under the CCPA/CPRA, we collect identifiers, photos/audiovisual content, internet activity, and inferences (progress stats) as described above. We do not sell or "share" personal information for cross-context behavioral advertising, and we use sensitive personal information only to provide the Service. You have the rights to know, delete, correct, and limit sensitive-PI use, exercisable at the email above.
Consumer Health Data (Washington / Nevada)
Goal selections and check-in activity may indicate health status (for example substance cessation or fitness habits) and may qualify as consumer health data. We collect it only from you, use it only to run your challenges and the features you choose, share it only with the service providers listed above — we never sell it and never use it for advertising — and we do not use geofencing. You may access it, withdraw consent, or have it deleted by emailing help@getcoact.com.
Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from anyone under 13 (United States) or under the applicable age of digital consent in your country (13–16 in the EEA; 13 in the UK). The App asks for your date of birth at signup and refuses to create an account for anyone under 13; a date of birth entered on a refused signup is not stored. If we learn an account belongs to an underage user, we will delete it. If you believe a child is using Coact, contact us and we will delete their information promptly.
Security
We use transport-layer encryption (HTTPS), salted password hashing, and access controls to protect your information. No system is perfectly secure; if a breach affects your data, we will notify you and the relevant authorities as required by law.
Deleting Your Account
You can delete your account directly in the app (Profile → Settings → Delete account, confirmed with your password), or email help@getcoact.com from your account email. We delete or de-identify your personal information within 30 days, except where we must retain it (for example, open safety or legal matters). You can also download a portable copy of your data at any time from Profile → Settings → Download my data.
Changes to This Policy
We may update this policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will provide additional notice (such as an in-app notice or an email) before the change takes effect. Continued use of the Service after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy or to exercise your rights, email help@getcoact.com.