Skip to content
Doomate
Terms Privacy Contact

Doomate legal

Privacy Policy

Doomate uses personal information to run a private accountability service, enforce the rules you create, process purchases, keep the service safe, and—only when you choose it—ask an AI provider to review an access request. Detailed Screen Time activity is intended to stay on your device.

Effective September 20, 2026

1. Who is responsible

Doomate is currently operated by Hus Lucian-Antonio, an independent developer based in Romania ("Doomate," "we," "us," or "our"). For privacy questions or requests, email contact@doomate.app.

This Policy applies to the Doomate mobile applications, website, backend services, and related support. Third-party services have their own privacy notices.

2. Information we process

Account and profile information

We process your email address or Apple/Google sign-in identifier, provider-supplied email address when available, account ID, username, display name, age, profile picture, authentication records, and account settings. Passwordless codes are short-lived, and we store a protected digest rather than the code itself.

Onboarding and preferences

We process the goals, referral source, accountability preferences, privacy choices, and related onboarding answers you provide.

Screen Time and rules

On supported Apple devices, Doomate requests Family Controls authorization and uses Managed Settings, Device Activity Monitor, Device Activity Report, Shield Configuration, and Shield Action. These technologies let you select apps, view usage, configure limits, detect when a limit is reached, display a Doomate shield, and apply approved additional time.

Raw Screen Time activity, Apple Family Controls selection tokens, and detailed device activity are intended to remain on your device. Doomate's servers process the rule settings and managed-app labels or identifiers needed to synchronize the service, plus an accountability event or usage summary when you deliberately submit or share it. We do not receive your complete device app inventory. Other users see only information covered by your sharing settings and the particular request or message you send them.

Accountability and user content

We process partner invitations and relationships, blocks, visibility choices, access requests, reasons, requested duration, messages, votes, decisions, emergency exits, and associated timestamps. If media features are available, this also includes photos and voice messages you choose to send. Recipients can retain copies outside Doomate.

AI review information

When you affirmatively choose AI review, we process the request, relevant rule and profile context, messages, and votes needed to produce a decision. We record your disclosure choice, the policy version, the decision, its rationale, and safety flags. Do not include confidential, highly sensitive, or third-party information in a request sent for AI review.

Device, security, and diagnostics information

We process a Doomate-generated device identifier, platform, app version, locale, coarse enforcement capability and status, push token, session information, request ID, and security or rate-limit events. With your separate diagnostics choice, we may also receive device manufacturer, model, operating-system version, and technical failure codes. Our application logs are designed not to contain message text, AI context, tokens, or request bodies.

Purchases, support, and safety

We process subscription product, provider, transaction identifiers, entitlement, expiry or revocation status, support messages, reports, report descriptions, and moderation actions. Apple or Google processes your payment credentials; Doomate does not receive your full card details.

Website and network information

Our hosting and security providers may process IP address, browser or device type, requested page, date and time, referrer, and similar network records needed to deliver and protect the website. Doomate does not currently place advertising or product analytics cookies on this website.

3. Why we use information

  • Provide accounts, rules, accountability relationships, messaging, decisions, and device synchronization.
  • Apply privacy settings and deliver notifications to intended recipients.
  • Verify subscriptions and provide Plus or Pro features.
  • Provide optional AI review after a specific disclosure and affirmative choice.
  • Answer support requests and operate reporting, blocking, and moderation.
  • Secure the service, prevent abuse and fraud, troubleshoot failures, and maintain reliable operations.
  • Comply with law, enforce our Terms, and establish or defend legal claims.

4. Legal bases in the EEA, UK, and similar regions

We process information necessary to provide the service under our contract with you, including account, rule, request, messaging, notification, and subscription data. We rely on legitimate interests to secure and improve service reliability, prevent abuse, provide support, and enforce our Terms, after considering your rights. We rely on consent for optional diagnostics, AI disclosure, non-essential analytics, or similar optional processing where consent is required. You may withdraw consent prospectively in the relevant setting or by contacting us. We process information when necessary to comply with legal obligations and establish or defend claims.

You are not legally required to provide most information, but we cannot create or run an account without required account and service data. Optional permissions and consent can be declined, although the related feature will not work.

5. When information is shared

  • People you choose. Partners and request recipients receive content and activity covered by the relevant relationship, request, and privacy settings.
  • Hosting and storage. We intend to use Google Cloud infrastructure in Frankfurt, Germany, for application hosting, databases, cache, and private media storage. Vercel hosts the public website.
  • Account and communication providers. Apple and Google support sign-in; Resend delivers passwordless email; Apple Push Notification service and Firebase Cloud Messaging deliver notifications.
  • Stores and billing. Apple and Google process subscriptions and send verified purchase status to Doomate.
  • AI providers. An AI review is routed through OpenRouter to the selected model provider, currently expected to be NVIDIA. OpenRouter and the model provider may process prompts and outputs under their terms. Provider retention and training practices can differ, which is why AI review is optional.
  • Safety and law. We may disclose information when reasonably necessary to comply with law, respond to lawful process, protect a person, investigate abuse, or defend Doomate's rights.
  • Business changes. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to applicable notice and safeguards.

We do not sell personal information for money. We do not currently share Doomate account or Screen Time information for targeted advertising. If advertising, analytics, or crash-reporting providers are enabled later, we will update this Policy and obtain any required consent before their collection begins.

6. AI decisions

AI review evaluates a limited access request against Doomate's configured policy and returns an approval or denial, possible duration, and rationale. It does not make decisions about employment, credit, housing, education, healthcare, insurance, legal rights, or another similarly significant matter. AI can be wrong. It is an optional accountability feature, and provider failure returns the request to human review. You can avoid AI review and use human accountability or an available emergency exit.

7. How long we keep information

Our intended baseline schedule is:

  • Account content and relationships: while the account is active, followed by the 14-day deletion cancellation period and up to 30 additional days to remove active-system copies.
  • Expired authentication challenges: no longer than 24 hours after they cease to be operationally necessary.
  • Routine operational logs: generally 30 days.
  • AI request payloads and provider responses held by Doomate: up to 90 days, unless retained with the underlying request or needed for safety or a dispute. Providers may apply their disclosed retention.
  • Optional product analytics, if introduced: no more than 12 months by default.
  • Support cases: up to two years after closure.
  • Moderation and safety records: up to three years after resolution when needed to prevent repeat abuse or establish claims.
  • Backups: designed to expire within 35 days and used only for disaster recovery.
  • Billing, fraud, security, and accounting records: only as long as legally or operationally necessary, potentially up to ten years where law requires it.

We may retain a restricted record longer during litigation, a legal hold, an active safety investigation, or when law requires it. We will delete or de-identify it when that reason ends.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing; withdraw consent; and appeal a refusal. Doomate provides an account export and an in-app deletion request with a 14-day cancellation period. You may also email contact@doomate.app. We may need to verify your account before completing a request.

EEA users may complain to their local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing. UK and other regions have their own privacy regulators. You will not be discriminated against for exercising an applicable privacy right.

9. Younger users

Doomate is not for children under 13, and we do not knowingly collect their personal information. If you are between 13 and the age at which you can validly agree to the service or optional data processing where you live, a parent or legal guardian must review and authorize your use where local law requires it. We may restrict registration in a country until an appropriate parental-authorization process is available.

Accounts known to belong to minors receive private sharing defaults. We do not use a known minor's personal information for profiling-based advertising. If you believe a child is using Doomate contrary to these rules, contact us.

10. International transfers

Doomate is operated from Romania and intends to host core infrastructure in Germany. Some providers, including Apple, Google, Vercel, Resend, OpenRouter, NVIDIA, and their subprocessors, may process information in the United States or other countries. Where required, we rely on adequacy decisions, standard contractual clauses, or another valid transfer mechanism and apply supplementary safeguards appropriate to the data.

11. Security

We use measures designed to protect information, including encrypted transport, protected credentials, private media storage, short-lived access tokens, access controls, rate limits, and security auditing. No service is completely secure. Protect your device and account, and contact us if you suspect unauthorized access.

12. Changes to this Policy

We may update this Policy as Doomate changes. We will revise the effective date and provide additional notice or request a new choice when required for a material change. Previous versions will be made available on request.

13. Contact

Hus Lucian-Antonio
Romania
contact@doomate.app

© 2026 Doomate
Home Terms Contact