1. Who is responsible
Doomate is currently operated by Hus Lucian-Antonio, an independent developer based in Romania ("Doomate," "we," "us," or "our"). For privacy questions or requests, email contact@doomate.app.
This Policy applies to the Doomate mobile applications, website, backend services, and related support. Third-party services have their own privacy notices.
2. Information we process
Account and profile information
We process your email address or Apple/Google sign-in identifier, provider-supplied email address when available, account ID, username, display name, age, profile picture, authentication records, and account settings. Passwordless codes are short-lived, and we store a protected digest rather than the code itself.
Onboarding and preferences
We process the goals, referral source, accountability preferences, privacy choices, and related onboarding answers you provide.
Screen Time and rules
On supported Apple devices, Doomate requests Family Controls authorization and uses Managed Settings, Device Activity Monitor, Device Activity Report, Shield Configuration, and Shield Action. These technologies let you select apps, view usage, configure limits, detect when a limit is reached, display a Doomate shield, and apply approved additional time.
Raw Screen Time activity, Apple Family Controls selection tokens, and detailed device activity are intended to remain on your device. Doomate's servers process the rule settings and managed-app labels or identifiers needed to synchronize the service, plus an accountability event or usage summary when you deliberately submit or share it. We do not receive your complete device app inventory. Other users see only information covered by your sharing settings and the particular request or message you send them.
Accountability and user content
We process partner invitations and relationships, blocks, visibility choices, access requests, reasons, requested duration, messages, votes, decisions, emergency exits, and associated timestamps. If media features are available, this also includes photos and voice messages you choose to send. Recipients can retain copies outside Doomate.
AI review information
When you affirmatively choose AI review, we process the request, relevant rule and profile context, messages, and votes needed to produce a decision. We record your disclosure choice, the policy version, the decision, its rationale, and safety flags. Do not include confidential, highly sensitive, or third-party information in a request sent for AI review.
Device, security, and diagnostics information
We process a Doomate-generated device identifier, platform, app version, locale, coarse enforcement capability and status, push token, session information, request ID, and security or rate-limit events. With your separate diagnostics choice, we may also receive device manufacturer, model, operating-system version, and technical failure codes. Our application logs are designed not to contain message text, AI context, tokens, or request bodies.
Purchases, support, and safety
We process subscription product, provider, transaction identifiers, entitlement, expiry or revocation status, support messages, reports, report descriptions, and moderation actions. Apple or Google processes your payment credentials; Doomate does not receive your full card details.
Website and network information
Our hosting and security providers may process IP address, browser or device type, requested page, date and time, referrer, and similar network records needed to deliver and protect the website. Doomate does not currently place advertising or product analytics cookies on this website.
3. Why we use information
- Provide accounts, rules, accountability relationships, messaging, decisions, and device synchronization.
- Apply privacy settings and deliver notifications to intended recipients.
- Verify subscriptions and provide Plus or Pro features.
- Provide optional AI review after a specific disclosure and affirmative choice.
- Answer support requests and operate reporting, blocking, and moderation.
- Secure the service, prevent abuse and fraud, troubleshoot failures, and maintain reliable operations.
- Comply with law, enforce our Terms, and establish or defend legal claims.
4. Legal bases in the EEA, UK, and similar regions
We process information necessary to provide the service under our contract with you, including account, rule, request, messaging, notification, and subscription data. We rely on legitimate interests to secure and improve service reliability, prevent abuse, provide support, and enforce our Terms, after considering your rights. We rely on consent for optional diagnostics, AI disclosure, non-essential analytics, or similar optional processing where consent is required. You may withdraw consent prospectively in the relevant setting or by contacting us. We process information when necessary to comply with legal obligations and establish or defend claims.
You are not legally required to provide most information, but we cannot create or run an account without required account and service data. Optional permissions and consent can be declined, although the related feature will not work.
6. AI decisions
AI review evaluates a limited access request against Doomate's configured policy and returns an approval or denial, possible duration, and rationale. It does not make decisions about employment, credit, housing, education, healthcare, insurance, legal rights, or another similarly significant matter. AI can be wrong. It is an optional accountability feature, and provider failure returns the request to human review. You can avoid AI review and use human accountability or an available emergency exit.
7. How long we keep information
Our intended baseline schedule is:
- Account content and relationships: while the account is active, followed by the 14-day deletion cancellation period and up to 30 additional days to remove active-system copies.
- Expired authentication challenges: no longer than 24 hours after they cease to be operationally necessary.
- Routine operational logs: generally 30 days.
- AI request payloads and provider responses held by Doomate: up to 90 days, unless retained with the underlying request or needed for safety or a dispute. Providers may apply their disclosed retention.
- Optional product analytics, if introduced: no more than 12 months by default.
- Support cases: up to two years after closure.
- Moderation and safety records: up to three years after resolution when needed to prevent repeat abuse or establish claims.
- Backups: designed to expire within 35 days and used only for disaster recovery.
- Billing, fraud, security, and accounting records: only as long as legally or operationally necessary, potentially up to ten years where law requires it.
We may retain a restricted record longer during litigation, a legal hold, an active safety investigation, or when law requires it. We will delete or de-identify it when that reason ends.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing; withdraw consent; and appeal a refusal. Doomate provides an account export and an in-app deletion request with a 14-day cancellation period. You may also email contact@doomate.app. We may need to verify your account before completing a request.
EEA users may complain to their local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing. UK and other regions have their own privacy regulators. You will not be discriminated against for exercising an applicable privacy right.
9. Younger users
Doomate is not for children under 13, and we do not knowingly collect their personal information. If you are between 13 and the age at which you can validly agree to the service or optional data processing where you live, a parent or legal guardian must review and authorize your use where local law requires it. We may restrict registration in a country until an appropriate parental-authorization process is available.
Accounts known to belong to minors receive private sharing defaults. We do not use a known minor's personal information for profiling-based advertising. If you believe a child is using Doomate contrary to these rules, contact us.
10. International transfers
Doomate is operated from Romania and intends to host core infrastructure in Germany. Some providers, including Apple, Google, Vercel, Resend, OpenRouter, NVIDIA, and their subprocessors, may process information in the United States or other countries. Where required, we rely on adequacy decisions, standard contractual clauses, or another valid transfer mechanism and apply supplementary safeguards appropriate to the data.
11. Security
We use measures designed to protect information, including encrypted transport, protected credentials, private media storage, short-lived access tokens, access controls, rate limits, and security auditing. No service is completely secure. Protect your device and account, and contact us if you suspect unauthorized access.
12. Changes to this Policy
We may update this Policy as Doomate changes. We will revise the effective date and provide additional notice or request a new choice when required for a material change. Previous versions will be made available on request.
13. Contact
Hus Lucian-Antonio
Romania
contact@doomate.app