Privacy Policy
Last updated: 3 August 2026 · Draft, pending legal review
This policy explains what personal data Dare collects, why, who we share it with, and the rights you have. Dare is an iPhone app that turns fitness goals into a commitment: if you miss a goal you set, Dare locks the apps you chose until you make it up.
The short version: we collect only what we need to run the app. Your activity data from Apple Health is used solely to verify your goals, never for advertising, and never sold. You can delete all of your data at any time from within the app.
Who we are
Dare is operated by Misto Design House Ltd, the data controller, a company registered in England & Wales with its registered office at C/O Unit 4, Kinetica, 13 Ramsgate Street, London, England, E8 2FD. Contact us any time at ifyoudare@idare.app.
What we collect and why
Account & identity
When you first open Dare we create an anonymous account so your data can sync. The name you give during onboarding is stored with your account so Dare can address you by it. If you sign in with Apple or Google, we receive a user identifier and your email address (with Sign in with Apple this may be a private relay address). We never receive your Apple or Google password. Purpose: to create and secure your account and sync your data. Lawful basis: performance of our contract with you.
Health & activity data (Apple Health)
With your permission, Dare reads activity data from Apple Health to check whether you met the goals you set, and to show you your own activity in the app. Specifically:
- Steps and walking / running distance
- Active energy (calories)
- Exercise minutes and workouts
- Flights of stairs climbed
- Heart rate and resting heart rate
- Sleep, for bedtime goals
The metrics used to verify a goal (for example, the step count on a given day) are stored as part of your synced account data, so your history and your streak survive reinstalls and new devices. Everything else is read when a screen needs it and is not sent anywhere.
This data is only ever used to verify your goals and to show them back to you. We do not use it for advertising or marketing, we do not sell it, and we do not share it with third parties except the infrastructure providers listed below who store it on our behalf. Dare never writes anything to Apple Health. Lawful basis: your consent (granted via Apple Health) and performance of our contract with you.
Screen Time (Apple Family Controls)
To lock the apps you put on the line, Dare uses Apple's Screen Time (Family Controls) framework. The apps and categories you select are represented by opaque tokens created by Apple. That token blob is stored with the rest of your account data, which is what lets your dares come back with their apps if you reinstall. The tokens are not human-readable and only resolve on the device that created them, so we cannot tell which apps you chose, and neither could anyone else who obtained them. They are used solely to apply and lift the locks you set. Lawful basis: your consent and performance of our contract with you.
Location
This version of Dare does not use your location. Every goal is verified from Apple Health. An earlier design included gym goals that detected visits to a gym you chose; those are not part of the app you can use today, so Dare does not ask for location access and does not collect it. If we bring them back, we will update this policy and ask for your permission first.
Subscriptions
Purchases are handled by Apple. We use RevenueCat to manage your subscription status and entitlement. We do not receive or store your payment card details. Lawful basis: performance of our contract with you.
Refund requests
If you request a refund from Apple, Apple asks us whether the subscription you paid for was delivered and used. We (via RevenueCat) answer with basic consumption facts: that the purchase exists in our records and that the paid features were made available to you. This never includes your health data, your goals, or your locked apps, only subscription delivery status. Apple makes the refund decision, not us. Lawful basis: our legitimate interest in preventing fraudulent refunds, balanced by the minimal, non-sensitive data shared.
Usage analytics
We use PostHog to understand how people use Dare (for example, which onboarding steps people complete) so we can improve it. These analytics are tied to your account identifier but deliberately exclude your health values and the names of the apps you lock. Lawful basis: our legitimate interest in improving the product.
Diagnostics & crash reports
We use Sentry to capture crashes and errors so we can fix them. Lawful basis: our legitimate interest in a stable, secure app.
Waitlist
If you join the pre-launch waitlist on this site, we store the email address you give us so we can tell you once when Dare is available. We do not use it for marketing, we do not share it, and you can ask us to delete it at any time by emailing ifyoudare@idare.app. The list is deleted once the launch email has been sent. Lawful basis: your consent.
Support & email
If you email us, we process your message and email address to respond (via Google Workspace). If in future we send you service or lifecycle emails, we will use Resend to deliver them; you will be able to opt out of any non-essential email. Lawful basis: performance of our contract and, for optional email, your consent.
Who processes your data
We share data only with providers who process it on our behalf, under contract:
- Supabase — account, authentication, and data storage (EU region).
- Apple — Sign in with Apple, Apple Health, Screen Time, and in-app purchases.
- Google — Sign in with Google.
- RevenueCat — subscription management (United States).
- PostHog — product analytics (United States).
- Sentry — crash and error diagnostics (EU region).
- Google Workspace — support email.
- Telegram — internal alert when you claim an earned free month, so we can apply it. Carries your account identifier and the claim details, never your email or your activity data.
- Resend — service/lifecycle email delivery (EU region), if and when introduced.
We do not sell your personal data, and we never use Apple Health data for advertising.
International transfers
Some providers (RevenueCat, PostHog) process data in the United States. Where data leaves the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
How long we keep it
We keep your data for as long as your account is active. You can erase everything at any time using Delete all data in the app, which wipes both the copy on your device and the copy on our servers and removes your account. Backups and logs are cleared on our routine cycles thereafter.
Your rights
Under UK GDPR you have the right to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent at any time. To exercise any of these, email ifyoudare@idare.app. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Children
Dare is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.
Security
Access to your synced data is protected by authentication and row-level security so that only you can read or write it. No system is perfectly secure, but we take reasonable measures to protect your information.
Changes to this policy
We may update this policy as the app evolves. We will change the "last updated" date above and, for material changes, notify you in the app.
Contact
Questions about your privacy? Email ifyoudare@idare.app.