Privacy Policy — Identity First
This Privacy Policy explains how Identity First (“the App”, “we”, “us”, “our”) collects, uses, stores, and shares your information. It is written to be accurate to what the App actually does. By creating an account and using the App, you agree to the practices described here.
1. Who we are
Identity First is a habit- and identity-building app. The data controller responsible for your information is Daniel Spencer.
For any privacy question or request, contact us at support@identityfirst.co.
2. A note on the data you create
Identity First lets you write free-text identities and habits. You decide what to put there. Because this text is yours to write, it may sometimes include sensitive details (for example, references to health, beliefs, or personal circumstances). We do not require or ask for such information, and we recommend you only record what you are comfortable storing. We treat this content as private to your account.
3. What we collect and why
3.1 Account information
- Email address — to create your account, sign you in, recover access, and send essential transactional emails (e.g. confirmation, password reset).
- Password — to authenticate you. It is hashed and salted by our authentication provider; we never see or store it in plain text.
- Account identifier (user ID) and email-confirmation status / timestamps — to manage your account and secure it.
- Session and security metadata — including IP address, sign-in times, and session tokens, processed by our backend provider to keep your account secure and prevent abuse.
3.2 Profile
- Display name (optional) — to personalise the App (e.g. greetings).
- Avatar reference (optional) — to display a profile image, if set.
- Notification-consent timestamp — a record of when you agreed to receive push notifications.
3.3 Your content (identities, habits, completions)
- Identities you create (title, icon, colour, reminder settings).
- Habits / daily actions you create (title, frequency, schedule, reminder settings).
- Completions (“evidence”) you log, including the date/time.
- Habit exemptions — a date and a reason you select from a fixed list (recovery/illness, travel, or family/life) to pause a streak without penalty.
We use this content to provide the core function of the App: tracking your habits, calculating streaks and progress, and showing your history.
3.4 Notifications
- Push notification token — a device identifier issued by Apple so we can deliver notifications to your device.
- Timezone — to schedule notifications at the right local time.
- Notification preferences — quiet hours and an optional evening check-in time.
- Notification history — records of which notifications were sent, when, and where they link, to avoid duplicates and respect your settings.
3.5 Purchases
- If you buy a subscription or in-app purchase, your account identifier is shared with our subscription provider (RevenueCat) so your purchase syncs across your devices, and purchase/receipt information is processed by RevenueCat and Apple to validate and manage your subscription. We do not receive or store your full payment card details; payment is handled by Apple.
3.6 Information stored only on your device
- Biometric lock preference (whether Face ID / Touch ID is enabled to lock the App), stored securely in the device keychain.
- A local cache of your identities, habits, profile, and interface preferences, to load quickly and work offline. (Your logged completions and push token are excluded from this local cache by design.)
3.7 Derived information
We calculate streaks, scores, trends, and momentum from your habits and completions to display your progress and tailor notifications. This is computed from the data above.
4. What we do not collect
- We do not use third-party analytics or advertising SDKs, and we do not serve ads or track you across other apps or websites.
- We do not collect precise location, your contacts, photos, microphone, or camera.
- We do not sell your personal information.
5. How your information is stored and protected
Your data is stored with our backend provider (Supabase) and protected by row-level security so that you can only access your own records. Passwords are hashed, connections are encrypted in transit, and the biometric lock preference is held in the device’s secure keychain. No method of storage or transmission is 100% secure, but we take reasonable measures to protect your information.
6. Who we share information with (service providers)
We share data only with the service providers needed to run the App:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Backend database, authentication, server functions | Account data, profile, your content, notification settings; server logs including IP address |
| Apple Push Notification service (APNs) | Delivering notifications | Push token and notification content (title/body) |
| RevenueCat | Subscription management | Your account identifier and purchase/receipt data |
| Apple App Store | Processing payments | Purchase and payment data |
Each provider processes data under its own privacy terms. We do not share your data with any other third parties except where required by law.
7. International transfers
Your information may be processed on servers located outside your country, including by the providers listed above. Where required, we rely on appropriate safeguards for such transfers.
8. How long we keep your data
We keep your account and content for as long as your account is active. You can delete your account at any time in the App’s settings. When you do, the personal data associated with your account — your profile, identities, habits, completions, habit exemptions, notification settings, and notification history — is deleted from our database. Some records may persist for a limited period in encrypted backups and provider logs before being overwritten. Purchase records held by Apple and RevenueCat are retained under their respective policies.
9. Your rights and choices
Depending on where you live, you have some or all of the following rights over your personal data. You can exercise most of them directly in the App:
- Access / portability — you can export your data (identities, habits, completions, notification settings, and history) as a file from the App’s settings. For any access request the export doesn’t cover, email us.
- Correction — you can edit your display name, identities, and habits directly in the App at any time.
- Deletion — you can permanently delete your account and its associated data from the App’s settings.
- Withdraw consent — you can disable push notifications in the App or in your device settings.
- Object to or restrict certain processing — email us and we will respond.
For any request you can’t complete in the App, contact us at support@identityfirst.co. We will respond within the timeframe required by applicable law, and we won’t discriminate against you for exercising your rights.
If you are in the UK or EU, our legal bases for processing are: performance of a contract (providing the App), consent (e.g. push notifications), and our legitimate interests (keeping the service secure and reliable). You also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office).
If you are a California resident, you have rights under the CCPA/CPRA to know, access, delete, and correct the personal information we hold about you, and the right not to be discriminated against for exercising them. We do not sell or share your personal information for cross-context behavioural advertising. Because the App does not track you across other apps or websites, we do not respond to “Do Not Track” browser signals — there is no cross-site tracking to disable.
10. Children’s privacy
Identity First is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, where appropriate, notify you in the App. Continued use of the App after changes take effect constitutes acceptance of the revised policy.
12. Contact
Questions or requests regarding this policy or your data:
Daniel Spencer Email: support@identityfirst.co
This policy is governed by the laws of England and Wales.