Effective date: June 10, 2026
Instead Of ("Instead", "we", "our", or "us") is a mobile application that helps you replace unwanted habits with healthier alternatives. This policy explains what data we collect, why, and how we protect it.
When you sign up via Apple, Google, or email, we store your email address, display name, and a generated username. We never see or store your Apple or Google password.
To provide the core service, we collect data you enter about:
If you grant permission, we read the following from Apple HealthKit:
Health data you authorize is synced from HealthKit to your account in our database, so your health trends are saved and available when you sign in. It is never sold, shared with advertisers, or used for marketing. We do not write to HealthKit. You can disconnect HealthKit at any time in your device settings, and deleting your account deletes all health records we hold.
If you choose to connect your bank account via Plaid, we receive:
We never see your bank login credentials — those are handled entirely by Plaid. We use transaction data solely to identify spending related to your habits and calculate savings. Bank connection tokens are stored server-side in our database, which is encrypted at rest. You can disconnect your bank at any time, and deleting your account asks Plaid to revoke the connection.
If you participate in groups, challenges, or the community feed, we store your posts, comments, reactions, group memberships, and challenge progress. Content you post in public groups is visible to other users.
We collect your push notification token (to send notifications you opt into) and device platform (iOS/Android).
We collect first-party product analytics so we can understand which features are used and improve the app. Each event records: the action taken (for example, opening the app, completing onboarding, logging a swap, or checking in), your account ID when you are signed in, a randomly generated per-install identifier, your device platform, and the app version. This data is stored in our own database, is used only for product analytics, and is never used for advertising or sold. Events linked to your account are deleted when you delete your account.
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, server functions | All app data (hosted infrastructure) |
| Plaid | Bank account connection | User ID; Plaid handles credentials directly |
| RevenueCat | Subscription management | User ID, purchase/entitlement status |
| Expo | Push notifications | Push token, notification content |
| Apple / Google | Authentication | Sign-in tokens (standard OAuth) |
We do not use third-party analytics, advertising, or tracking SDKs. The usage analytics described above are collected by us directly and stored in our own database. We do not sell your data to anyone.
We do not use your data for advertising, profiling, or sale to third parties.
You can view all your data within the app. To request a full data export, contact us at the address below.
You can delete your account from the Profile screen (Profile > Account > Delete Account). Deletion runs on our servers and permanently removes your sign-in account and all data linked to it: your profile, habits, swaps, check-ins, slips, health records, bank connections and transactions, posts, comments, reactions, group memberships, partnerships and encouragements, badges and progress, push notification tokens, and analytics events linked to your account. Groups and challenges you created are also deleted. If you connected a bank, we ask Plaid to revoke the connection. Deletion is immediate and irreversible, and frees your email address for future use.
Instead is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
We retain your data for as long as your account is active. If you delete your account, all associated data is permanently deleted from our live database immediately. Residual copies may persist in our hosting provider's encrypted backups for a limited period before being purged automatically.
We may update this policy from time to time. If we make material changes, we will notify you via the app or email. The effective date at the top of this page indicates when the policy was last revised.
If you have questions about this privacy policy or your data, contact us at:
Email: support@insteadof.app
Website: insteadof.app