Daily Brave
Privacy policy
For Untried, Thick Skin and Comeback · in force since 19 September 2026
What Untried, Thick Skin and Comeback store about you, who else sees it, and how to get rid of it. No advertising, nothing sold to anybody, and no analytics in the apps unless you switch them on in the phone apps. The front page of unfck.it is the one place that is recorded without asking, by Microsoft Clarity — the rest of this page is the detail behind those claims.
Who holds your data
RL Now, Inc., a corporation registered in Delaware, USA, is the controller of the personal data described here.
The people who run the app at RL Now, Inc. can see account data, including what you log, through an internal tool that only they can sign in to. They use it to answer you, to fix problems and to act on reports.
651 N Broad St, Suite 201 · Middletown, DE 19709 · United States
hey@unfck.it
What we store
Your account. Your email address, an account identifier, and when the account was made. You sign in with Google, with Apple in the iOS app, or with a one-time link sent to your email — whichever way, there is no password, so there is no password for us to hold or lose.
Signing in with Google also puts the name and profile photo address on your Google account into the sign-in record Firebase keeps for you. The app never reads or shows them: your username and profile picture are the ones you choose here. Signing in with Apple asks Apple for your email address and nothing else — not your name — and what it shares is either your own address or a private relay address, if you chose to hide yours.
Your practice. The date you started, your time zone, your answer to the one calibration question at onboarding and the gentleness setting it produces, and your answers to the short questionnaire about yourself and what you want to work on — which choices you tapped, never anything typed. Your friends never see those answers. Then, per day: which prompts you were offered, which you turned down, which you took, and — when you log a day — the prompt and your answers to the form. If you start over, the earlier days are kept with your account as history, so you are not offered a prompt you already did or turned down. For streak freezes, we store when you last gave one to a friend and how many friends have given you.
In Untried, that form asks:
- Did you do it?
- What did you do?
- How new did it feel?
- Photo (optional) — optional
In Thick Skin, that form asks:
- Did you make the ask?
- What did you ask for?
- What happened
- How did it actually feel?
- Discomfort
In Comeback, that form asks:
- Did you attempt it?
- What happened?
- What did it teach you?
- Difficulty
Photos, if you add them. The pixel-art version that comes back, with smaller copies of it made so it loads quickly, until you delete your account, including any profile picture you have since replaced: earlier profile pictures are kept so you can switch back to one. The photo you upload is deleted as soon as its pixel-art version has been saved, or as soon as the transform fails or finds you have used up your allowance. One left behind anyway — because the app was closed before the transform finished, say — is removed by a clean-up that runs every day and deletes any upload more than an hour old, so no photo you upload is kept for more than 25 hours. A screenshot uploaded for a bug report that did not go through is cleared the same way. We also keep a count of how many photos you have had turned into pixel art, per month for a profile picture and per day for a day’s entry, so the allowance holds. A profile picture is up to you; a photo on a day’s entry comes with the AI Coach pass and is equally up to you. The app never opens your camera roll on its own.
The AI Coach pass. If you buy one, we store that you hold it, when it ends, when you last paid, and a record of each payment — the amount, the currency, and the customer reference Stripe gives it. A pass bought in a phone app is recorded with the App Store’s transaction number or Google Play’s order number instead, and the amount where the store reports one; so that the store can tell us which account bought it, we keep a random reference for your account and hand the store that, never your email or username. If you supported the app before the pass existed, the record of that payment says whether it was one-off or monthly. Your card number is never sent to us and we could not store it if we wanted to.
Notifications, if you turn them on. Your device’s notification token, whether it is a browser, an iPhone or an Android phone, your time zone, and which app it is for. That is enough to send these notifications and nothing else: a nudge at 9am where you are, a new friend request, a friend sharing a day, of which you get at most two a day however many friends share, a friend cheering one of your days, also at most two a day, a friend giving you a streak freeze, and a friend inviting you to do today’s task together or saying yes to your invite, at most two a day between them. The ones about friends can each be switched off; we store whether you did, and a count of today’s friend-day, cheer and invite notifications so the limits hold.
Your answer about the AI features. Whether you allowed them to send data to Google’s Gemini API, which version of that question you answered, and when — see What the AI sees.
Sign-in emails. To stop someone spamming link requests at an address, we keep a one-way hash of the address and a count. The address itself is not stored by that mechanism — a rate-limit table should not double as a mailing list.
Your username and friends, if you use them. The username you claim, the people you are friends with, and any requests waiting in either direction. When a friend cheers a day of yours, or you cheer theirs, we store who cheered which day, so the count can be shown to you and your friends; ending the friendship, blocking, or deleting your account removes those cheers. When you invite a friend to do today’s task with you, we store who invited whom, in which app, which task it was, when it was sent and when it lapses, both usernames, each of your day numbers and dates, and what happened to it — accepted, declined, cancelled, left, and the moment each of you logged that task. One copy is kept under each of your accounts. Ending the friendship, blocking, or deleting either account removes both copies. Claiming a username is optional; without one you cannot be found, cannot add anyone, and nothing you log goes anywhere.
People you block, if you block anyone. Who, and when. A matching note goes under their account too, so that the block can be cleaned up from either side; no one can read that note, including them.
Bug reports, if you send one. What you wrote, any screenshots you attached, and the technical details of the moment — which app and version, the screen you were on, your device and browser, and any errors the app logged. It is sent on to GitHub, where it becomes a ticket we work from, tagged with your account identifier so we can follow up. Your answers to the form above are never part of it.
Reports, if you send one or one is sent about you. When someone reports a shared day, a username or a profile picture, we store who sent the report, who it is about, the reason picked, the note if one was written, and a copy of what was reported as it was at that moment — the username and the picture, and for a shared day the task and the photo — so it can still be judged if it is changed or deleted afterwards. Reports are never sent to GitHub. An email tells us one is waiting; it says what kind of report it is and why, and carries none of what was reported.
On your own device. Before you have an account, your start date and a half-written entry are kept on the device so the sign-in detour does not throw them away — in the browser’s local storage on the web, and in the app’s own storage in the iOS and Android apps. The same place holds a few small things: whether your last share card included the photo, which day the daily animation last played and when the app was last open, a copy of the app’s levels so they load quickly, and which notification token this device registered; on the web also which reminders about the AI Coach pass you have dismissed, and in the phone apps your usage statistics choice. While a sign-in link is on its way, the address it was sent to is kept too — in local storage on the web, and in the phone’s secure storage (the iOS Keychain, or Android’s encrypted storage) in the apps. If you try to sign in with Google or Apple to an address that already has an account, the phone apps keep that sign-in in secure storage until you sign in the way you did before, so the two can be joined. None of it leaves your device. Clearing site data removes it on the web; uninstalling the app removes it on a phone.
The app’s settings. When it starts, at most about once an hour, the app asks Firebase Remote Config, a Google service, for a few settings that change how its screens are laid out. The request carries an identifier Firebase makes for that installation of the app, which app and version it is, and the device’s language — nothing that ties it to your account — and the answer is kept on the device until the next one.
What friends see
Nothing, until you claim a username and accept somebody. Friendship is mutual — a request from one side and an acceptance from the other — and either of you can end it.
When you log a day with the share box ticked, one card is copied into your friends’ feeds. It carries your username, your profile picture, which day of 100 you are on, the task itself, and the photo if you added one.
A friend who has notifications on may also get one saying your username and the day number — nothing more, because a notification can be read on a locked phone by whoever is holding it. Sending a friend request or giving a friend a streak freeze can notify that person the same way, with your username.
What you wrote in the form is not on that card and never reaches another person. That is not a policy we apply by hand — the server builds the card out of the task and the photo, and nothing else it reads is put on it. It does read one of your answers: whether you said the day happened. If you logged that it did not, no card goes out, and one that already went out is taken back. The box is ticked by default and is asked once per day, so a day you would rather keep costs one untick. (Stylising a photo is the one thing that sends those answers anywhere at all, and it sends them to Google, not to anybody you know — see What the AI sees.)
If you do today’s task with a friend, they see which task it is, that you invited them or said yes, whether you left, and whether you have logged that task. They never see what you wrote about it, and you never see theirs. An invite notification carries the username and nothing about the task.
Removing a friend removes your shared days from their feed and theirs from yours. Deleting your account removes both, everywhere, and hands your username back.
Blocking someone — a friend or not — does the same, drops any friend request between you, and stops either of you sending another. They are not told: a request from them is answered exactly as if no account matched. Unblocking lifts the block and restores nothing. Deleting either account removes the block.
Anyone who can see something of yours — a friend, or someone with a friend request waiting between you — can report it. Reports are read only by the people who run the app, and nobody is told who reported them. A reported day leaves the reporter’s own feed straight away; nothing else changes until we look. If it breaks the terms, we can take a shared day out of every feed and stop it being shared again, clear a profile picture along with the earlier ones kept, free a username, or disable an account.
There is no public profile, no follower list and no way to browse for people. A username can only be looked up by someone who already knows it or your email address, and a request has to be accepted before anything is shared.
What we do not collect
No advertising identifiers, and no profile built for marketing. There is no analytics SDK in the web app — not a privacy-preserving one, not one at all. The iOS and Android apps carry one, and only if you switch it on; the front page of unfck.it carries Microsoft Clarity. The next two sections say exactly what each sends.
No location. The app does not ask for it and does not store it. A future version of the Coach may offer city-level suggestions, and if that is ever built it will be opt-in and this page will describe it before it ships.
No selling or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, in the sense California law gives those terms or in any other sense.
Analytics in the phone apps
The iOS and Android apps include Google Analytics for Firebase. It is off until you switch it on, under Avatar → Usage statistics, and the choice is kept on that device. Switching it off stops anything more being sent from it.
While it is on, Google receives that the app was opened, which screens you visited — by the screen’s name, never what was on it — which of the apps it is, its version and build, and the device details Google collects with every app: model, operating system, language, and a rough region worked out from the connection. It gets an identifier for that installation of the app, and nothing that ties it to your account: no account id, no username, no email, nothing you write, and no advertising identifier. The app tells Google that advertising use of this data is not permitted.
If you buy the AI Coach pass in the app while it is on, Google Analytics records that purchase by itself — which product, its price and currency — as it does for every app that includes it; there is no setting that turns only this off. It is tied to the same installation identifier and not to your account. Buying with it off sends nothing.
We use it to see how many people use the apps, on what, and whether they come back. It is not used for advertising. The website and the web app send none of this.
The front page of unfck.it
The front page of unfck.it — the one that lists the three apps — runs Microsoft Clarity. Nothing else does: not the other pages of unfck.it, such as its terms and this policy, not the web apps, and not the phone apps.
Clarity records how the page is used: how far you scroll, where you click, and what the page looked like on your screen, so we can see which parts people read. With it, Microsoft receives your IP address, your browser and device details, the page that sent you, and a rough location worked out from the connection. The page has no sign-in and no form, so nothing it records is tied to an account.
The page tells Clarity not to store anything on your device, for analytics or for advertising, so it sets no cookies and cannot link one visit to the next: each visit is recorded on its own.
Microsoft receives this as a company in its own right, not only on our behalf, and its terms let it use it for its own purposes under its own policy, advertising among them.
What the AI sees
Two features send data to Google’s Gemini API, and it is worth being exact about which data.
Nothing is sent until you allow it. The first time you add a photo, change your profile picture or ask the Coach for something else, the app says what that feature sends and asks; one answer covers all of them. If you say no, nothing is sent and the practice carries on exactly as before. You can withdraw permission at any time on the account screen, and from then on nothing more is sent until you allow it again. If what these features send ever changes, you will be asked again.
Photo stylising. The photo you chose is sent, and with it the day’s task, how hard that task is rated (a number from 1 to 5), and whatever you had typed into the form at that moment — the picture is meant to show what happened, and it cannot without them. If you have an avatar, it goes too, so that you appear in the picture. A pixel-art picture comes back. Nothing else goes: not your name, not your account identifier, not your other days.
The Coach (with the AI Coach pass) sends: which day of 100 you are on, your difficulty ceiling and whether you asked for gentler prompts, your answers to the questionnaire about yourself (the wording of each question and the choices you tapped), the wording of tasks you have already completed (including ones you wrote yourself), every prompt you have turned down in that app, and the list of prompts it is allowed to choose from. It does not send what you wrote in a reflection, your email address, your account identifier, your photos, or anything about your device. It can only pick from a pre-approved list — it does not write prompts.
We use Gemini’s paid tier, where Google’s terms say submitted content is not used to train their models. We do not train any model on your data ourselves.
Who else touches it
Everyone else who handles your data, and what each is there for. None of them may use your data for their own purposes, with two exceptions. Whoever sells you the pass, Stripe on the web or Apple or Google in the phone apps, is the seller, and keeps its own record of the sale under its own policy. And Microsoft uses what Clarity records on the front page of unfck.it under its own policy too.
- Google (Firebase) — Sign-in, the database, file storage, notifications and the servers the app runs on. Most of what the app stores lives here. Their policy.
- Google (Analytics for Firebase) — Counts app opens, screen names and device details in the iOS and Android apps, only if you switch usage statistics on. Never your account, your username or anything you write. Their policy.
- Microsoft (Clarity) — Records how the front page of unfck.it is used — scrolling, clicks, and what the page looked like on your screen — with your browser, device and rough location. Nowhere else: not the other pages of unfck.it, not the apps. It never sees your account. Their policy.
- Google (Gemini API) — Turns a photo you upload into pixel art, and — with the AI Coach pass — picks the Coach's daily suggestion. Their policy.
- Stripe — Sells and takes payment for the AI Coach pass, through its Managed Payments service. Card details go to Stripe directly and never reach us. Their policy.
- Apple (App Store) — Sells the AI Coach pass in the iOS app and takes payment for it. We get the transaction number, and Apple gets a random reference to your account from us so the purchase can be matched to it — never your email or username. Apple tells us if it refunds one. Their policy.
- Google (Google Play) — Sells the AI Coach pass in the Android app and takes payment for it. We get the order number, and Google gets a random reference to your account from us so the purchase can be matched to it — never your email or username. Google tells us if it refunds one. Their policy.
- Resend — Delivers the sign-in email, when you ask for a link instead of using Google. Their policy.
- GitHub — Receives a bug report when you send one, so it becomes a ticket we can work from. Your reflections are never part of it. Their policy.
We will hand data to a court or a regulator when we are legally obliged to, and not otherwise.
Where it is kept
On Google Cloud infrastructure, with our own server code running in the European Union. Google (Firebase, the Gemini API and Google Play), Apple, Microsoft, Stripe, Resend and GitHub are US companies and process data in the United States and elsewhere; each publishes the transfer safeguards it relies on for data leaving the EU or UK, and those are linked above.
How long
Your account and everything in it stay until you delete them — this is a hundred-day practice with a recap at the end, and quietly expiring someone’s day 60 would defeat the point.
Deleting your account removes your profile, your entries, your photos — the pixel art and any upload still held — the counts behind your photo allowance, your friendships, every day you shared into someone else’s feed, both copies of every invite to do a task together, your notification tokens, your bug reports, and every report you sent or that was sent about you, immediately and for good. Your username is released and can be claimed by somebody else. One exception, and it is deliberate: records of payments are kept as financial records, stripped of anything that names you — the amount and the date survive, your identity does not. Stripe, Apple and Google keep their own copies of every payment they took under their own legal obligations, which we cannot delete on your behalf.
If you signed in with Apple, deleting your account in the iOS app first asks Apple to revoke the app’s access to your Apple ID, so it no longer appears among the apps using Sign in with Apple. Apple shows its own confirmation for this; closing it stops the deletion before anything is removed. If Apple cannot be reached or refuses, your account is deleted anyway, and you can remove the app yourself in your Apple ID settings.
If you reported a bug, the ticket it became stays on our side — it describes a defect in the app, and it may still be waiting to be fixed. What you wrote about the problem stays with it. Any screenshots you attached are deleted along with your other photos, and the account identifier on the ticket is left pointing at an account that no longer exists.
Usage statistics from the phone apps, if you switched them on, carry nothing that points to your account, so deleting it cannot find them. Google holds them under the data retention setting on our Analytics property. The same is true of what Clarity recorded on the front page of unfck.it, which Microsoft holds under its own policy.
A report is kept after it has been answered, as the record of what was decided, for as long as both accounts exist. Deleting either the account that sent it or the account it is about deletes it.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask for it in a portable form, object to a particular use, or ask us to restrict one. Email hey@unfck.it and you will get an answer within 30 days. There is no charge and no penalty for asking.
Deletion needs no email at all — the account screen does it yourself, in full, on the spot. That is the fastest route, and it is meant to be.
Where the GDPR applies, we rely on: performing our agreement with you (running the practice and keeping your entries, including the questionnaire about yourself that shapes it), your consent (notifications, photos, sending data to the AI features, and the calibration answer), our legitimate interest in keeping the service standing up (rate limits, and acting on reports), and legal obligation (financial records). You can withdraw consent at any time without affecting what came before, and you can complain to your national data protection authority if we get this wrong.
Children
The app is for people 18 and over, and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has an account, write to us and it will be removed.
If something goes wrong
If a breach ever puts your data at risk, we will tell you and the relevant regulator within the deadlines the law sets, and we will say what actually happened rather than issue a statement about how seriously we take security.
Changes
The date at the top is when this version took effect. If what we collect ever materially changes, this page changes first. See also the terms of use.