1. Who we are
Dopi ("we", "us") is a self-control app for iPhone and Apple Watch, available at dopiapp.com. This policy explains what data the Dopi app and this website handle, and how. It applies to the Dopi iOS app, the Dopi Apple Watch companion app, and this website.
2. Data that never leaves your device
The following is processed and stored only on your iPhone (or, where applicable, your Apple Watch), and is never transmitted to us or anyone else:
- Your shielded app and website selections. Dopi uses Apple's Screen Time (Family Controls) technology, which gives apps opaque, privacy-preserving tokens. Dopi cannot see which apps you selected, and the tokens are stored only on your device.
- Camera frames and body-pose data. Camera-based challenges (such as squats and planks) process video frames in memory on-device using Apple's Vision framework. Frames and pose coordinates are discarded immediately after processing. Nothing is recorded, stored, logged, or uploaded - ever.
- Everything you write. Friction Journal reflections, Grateful Gateway entries, and any other text you enter in challenges are stored in protected storage on your iPhone only. They are never synced, uploaded, analyzed, or included in analytics.
- Alarm details. Exercise Alarm labels and exact schedules stay on your device.
- Usage inside other apps. Dopi never sees what you do inside the apps it shields. Apple's Screen Time architecture makes this technically impossible for us.
- Motion and step data. Step-based challenges read the pedometer on-device only; motion data is not uploaded.
- Apple Health data (workouts, sleep, steps). With your explicit permission, the optional Health Auto Rewards feature (Dopi Plus) reads workouts, sleep duration, and step counts from Apple Health to grant rewards automatically. This reading happens entirely on your device; your Health data is never uploaded, stored in the cloud, analyzed off-device, or shared with anyone. Only a minimal reward record (module identifier and timestamps - never quantities and never the underlying Health data) is stored like any other challenge completion. Dopi never writes to Apple Health, and you can revoke access at any time in iOS Settings → Health.
3. Your personal iCloud (optional)
Your self-reported activity log (runs, walks, workouts you record in the Log tab) can sync through your own Apple iCloud key-value storage so your history follows your Apple Account across devices. This data belongs to you and lives in your iCloud, governed by Apple's privacy terms; we do not have access to it.
4. If you sign in (optional)
Dopi works fully without an account. If you choose to sign in with Apple, we create a cloud profile that stores:
- Your name and email, if you choose to share them with Sign in with Apple, used for account administration and personalizing your greeting.
- Coarse challenge statistics: counts of completed challenges, module identifiers, timestamps, scores, and reward minutes. Never the content of what you did - no camera data, no journal text. Where Health Auto Rewards is enabled, the cloud record only notes that a health reward happened (module identifier and timestamps). Health-derived quantities such as workout minutes, sleep duration, or step counts never leave your device, and the underlying Apple Health samples are never uploaded.
- Coarse activity aggregates: current streak days and lifetime active/rewarded minutes.
- Your membership tier and any reward inventory.
Cloud data is stored using Google Firebase (Authentication and Cloud Firestore). Your profile is readable only by you, enforced by server-side security rules.
5. Analytics and crash reporting
Dopi uses Firebase Analytics and Crashlytics to understand aggregate feature usage and fix crashes. Analytics are anonymous and strictly allowlisted:
- No names, emails, Apple identifiers, or account IDs are used as analytics identifiers.
- No free-form text, journal content, selected-app identities, location, or camera-related data is ever sent.
- Events use closed allowlists - anything not on the list is discarded.
- You can turn analytics off at any time in Dopi → Settings. Analytics defaults to on for new installations.
- Crashlytics collects crash reports and related diagnostic data (device model, OS version, stack traces) so we can fix bugs. Crash reports are not linked to your identity and never contain challenge content, Health data, or your shielded-app selections.
6. Purchases
Subscriptions and the lifetime purchase are processed entirely by Apple through the App Store. We never see or store your payment details. See Apple's privacy policy for how Apple handles purchase data.
7. This website
This website does not use advertising trackers and does not require cookies for browsing. If you use the support form, we collect the name, email address, support topic, optional app version, and message you submit. The form is processed by our private website API and Resend solely to deliver the message to our support inbox and reply to you. It is not used for marketing.
8. Data retention and deletion
- On-device data is deleted when you delete the app (or via in-app maintenance actions).
- Cloud account data can be permanently deleted in-app: Dopi → Settings → Delete Account. This deletes your cloud profile, challenge records, and authentication user, and revokes the Sign in with Apple link. We do not silently recreate accounts after deletion.
- iCloud activity log data is under your control through your Apple Account and device iCloud settings.
- Support correspondence is retained only for as long as reasonably necessary to answer your request, maintain support history, and meet legal obligations.
9. Not a health or medical service
Dopi is a habit and self-control tool. It is not a healthcare, medical, therapeutic, or fitness-coaching product, and nothing in the app or on this site constitutes medical advice, diagnosis, or treatment. Activity data handled by Dopi (repetition counts, session durations, self-reported logs, hydration check-ins) exists solely to power the app's unlock logic and your personal statistics - it is not shared with health providers or insurers. Where Apple Health is connected, Dopi only reads (never writes) Health data, on-device, for the sole purpose of granting rewards, and never uses it for advertising or any other purpose. Always consult a qualified professional about your health, and only perform activities appropriate for your body.
10. Children
Dopi is a voluntary self-control tool intended for users aged 13 and over. It is not a parental control product and is not directed at children.
11. Third-party services
The app and website use the following third-party services, only as described above: Apple (App Store, Sign in with Apple, iCloud, Screen Time technology), Google Firebase (Authentication, Cloud Firestore, Analytics, Crashlytics, App Check, Remote Config), and Resend (delivery of support-form email). Each processes data under its own privacy terms.
12. Changes to this policy
If we make material changes, we will update this page and the effective date above. Continued use of the app after changes take effect constitutes acceptance of the updated policy.
13. Contact
For privacy questions or requests, contact us through the support form at dopiapp.com/support and choose the Privacy question topic.