Maintenance|Services will resume on September 1, 2026
Back to home

Legal

Privacy Policy

Effective 1 December 2025 · Last updated 16 August 2026

IMPORTANT: PLEASE READ THIS PRIVACY POLICY CAREFULLY

This Privacy Policy is part of our Terms of Service. By using Accustom, you agree to both this Privacy Policy and our Terms of Service.

We do not sell your personal information. We only share your data as described in this policy to provide and improve our Service.

Introduction

Accustom ("we," "us," or "our") operates a habit accountability platform that enables users to commit to personal goals with financial accountability. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and related services (collectively, the "Service"). Accustom is delivered as a web app, which you can install to your home screen as a progressive web app (PWA).

Our platform offers two distinct accountability methods:

  • Challenges: Competitive challenges where participants pay a Pledge to join. Participants who complete the challenge receive a full pledge return plus a share of the Bonus Reward Pool — that is, non-completers' pledges less the platform fee stated on that challenge (12% unless it says otherwise). Grace days are provided based on challenge duration and category, with additional grace days available for purchase within set limits.
  • Commits: Individual accountability commitments where you pay a Pledge either to Accustom (returned upon completion) or as a donation to charity (non-refundable if not completed).

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

Data Controller

For the purposes of applicable data protection laws (including the Australian Privacy Act 1988, GDPR, and UK GDPR), the data controller responsible for your personal information is:

Accustom

Melbourne, Victoria, Australia

General Inquiries: support@accustom.app

Privacy Inquiries: privacy@accustom.app

Information We Collect

We collect information that you provide directly to us, information we obtain automatically when you use the Service, and information from third-party sources when you choose to connect external services.

Information You Provide

Account Registration: When you create an account, we collect your name, email address, and timezone. Your timezone is essential for calculating check-in deadlines correctly, as all deadlines are based on your local time (midnight in your timezone).

Profile Information: You may optionally provide additional information such as a profile photo and notification preferences to customize your experience.

Challenge and Commit Details: When you join a Challenge or create a Commit, we collect the habit description, Pledge amount, schedule (daily or weekly reporting), duration, and verification method preferences. For Challenges, we track your participation status, grace days remaining, and verification results. For Commits, we record your chosen pledge destination (Accustom or charity donation).

Evidence Check-Ins: To verify habit completion, we collect evidence based on your chosen verification method:

  • Photo Check-In: Photos you capture or select from your device gallery
  • Timelapse Video: Video recordings up to 30 minutes in duration documenting your activity
  • Screenshots: Screen captures from apps (e.g., meditation apps, reading apps, language learning apps)
  • GitHub Integration: Commit data from connected GitHub repositories for coding-related habits
  • Honor System: Self-reported completion confirmations for trust-based verification

Wallet Address: Accustom settles Pledges and payouts in USDC on the Base network. You may sign in with a wallet you already control, or sign in by email or social login, in which case Privy creates a self-custodial wallet for you. We store the public smart account address associated with your account so that we can verify your deposits and send your payouts. We never hold, receive, or have the ability to recover your private keys or recovery phrase. See Wallet and Blockchain Data below for the full detail.

Transaction Records: When you pay Pledges for challenges or commits, purchase grace days, or receive payouts, we record transaction metadata including amounts, dates, on-chain transaction hashes, and status. We do not collect or store credit card numbers, CVV codes, bank details, or other payment credentials — we never see them.

Wallet Funding (Onramp): If you buy USDC through the in-app funding flow, that purchase is carried out by Meld and the licensed provider it routes you to. Any payment details and identity documents you supply go directly to that provider. Accustom does not receive, process, or store them. We receive only the resulting on-chain transfer into your wallet, which we observe in the same way as any other deposit.

Communications: When you contact our support team, we collect the content of your messages, your email address, and any attachments you provide to resolve your inquiry.

Information Collected Automatically

Device Information: We automatically collect device identifiers, device model, operating system type and version, app version, and language settings to ensure compatibility and troubleshoot technical issues.

Push Notification Tokens: If you enable notifications, we collect device tokens to send deadline reminders, verification results, payout notifications, and other important alerts.

Usage Data: We collect information about how you interact with the Service, including features used, screens viewed, and actions taken. This helps us understand user behavior and improve the Service.

Log Data: Our servers automatically record information when you access the Service, including IP address, browser type, referring/exit pages, and timestamps. This data is used for security monitoring and troubleshooting.

Browser Permissions

Accustom runs in your web browser. To provide the Service, it may ask your browser for access to certain capabilities. Your browser will prompt you before granting any of these, and you can review or revoke them at any time in your browser's site settings:

  • Camera: Required to capture photo and timelapse video evidence for habit verification. Only requested at the moment you actively submit evidence.
  • File Selection: Required to attach an existing photo or screenshot as evidence. We receive only the file you explicitly choose — the Service cannot browse your device.
  • Notifications: Used to send deadline reminders, verification results, payout notifications, and other important alerts. You can disable these in your browser or in the app's notification preferences.

We do not access your camera or microphone in the background. Camera access is requested only when you actively initiate a check-in, and it stops when the check-in is complete.

Legal Basis for Processing

For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions that require a legal basis for processing personal data, we rely on the following legal bases:

  • Contract Performance: Processing necessary to provide the Service, including managing your account, processing Pledges and payouts, verifying evidence check-ins, and tracking challenge/commit progress.
  • Legitimate Interests: Processing for purposes including fraud prevention, security monitoring, service improvement, analytics, and ensuring the integrity of Challenges (e.g., preventing cheating).
  • Legal Obligations: Processing required to comply with applicable laws, such as retaining financial transaction records for tax and regulatory purposes.
  • Consent: Processing based on your explicit consent, such as sending marketing communications or enabling optional integrations like GitHub. You may withdraw consent at any time.

How We Use Your Information

We use the information we collect for the following purposes:

Operating the Service

We use your account information to create and maintain your account, authenticate your identity, and personalize your experience. Your timezone information ensures that all check-in deadlines are calculated correctly based on your local time.

Managing Challenges and Commits

We use your challenge and commit data to track your participation, monitor progress, calculate grace days remaining (for Challenges), and determine completion status. This information is essential for determining achievers in Challenges and whether Pledges should be returned or retained in Commits.

Verifying Evidence

Your submitted evidence (photos, videos, screenshots, GitHub data, or honor confirmations) is reviewed by our moderation team to verify that you have completed your daily or weekly habit requirements. Verified check-ins count toward your progress; rejected check-ins may result in a missed day unless you use a grace day (Challenges only).

Processing Payments

We use your wallet address and transaction records to move Pledges into escrow when you join challenges or create commits, to handle grace day purchases (for Challenges), and to distribute pledge returns and Bonus Reward payouts to successful participants. For Challenges, achievers receive their original Pledge (pledge return) plus a proportional share of the non-refundable pledges from participants who did not complete the challenge, less the platform fee stated on that challenge (12% unless it says otherwise). That fee is retained by the platform. See Wallet and Blockchain Data below for how this information is handled on-chain.

Communications

We use your contact information and notification preferences to send deadline reminders before check-ins are due, notify you of verification results, alert you when payouts are available, and communicate important account or service updates. You can manage notification preferences in your account settings.

Community Features

In Challenges, we display your first name and progress status on challenge leaderboards visible to other participants. This creates transparency and mutual accountability among challenge participants.

Improving the Service

We analyze usage patterns and aggregated data to understand how users interact with the Service, identify areas for improvement, fix bugs, and develop new features. This analysis uses anonymized or aggregated data whenever possible.

Safety and Security

We use your information to detect and prevent fraud, abuse, and violations of our Terms of Service. Given the financial nature of our platform, we monitor for suspicious activity to protect both individual users and the integrity of the challenge system.

How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We share your information only in the following circumstances:

With Other Challenge Participants

When you join a Challenge, other participants in the same challenge can see limited information about you: your first name, verification status for each day (verified or missed), and grace days remaining. This visibility is essential to the competitive and accountability nature of Challenges. Your email address, full name, financial details, Pledge amounts, and submitted evidence are never shared with other participants.

With Service Providers

We share information with third-party service providers who perform services on our behalf. These providers are contractually obligated to protect your information and may only use it to provide services to us:

  • Privy (Horkos, LLC d/b/a Privy): Handles sign-in and provides the embedded self-custodial wallet. When you sign in, Privy receives your email address or the identifier from the social login you choose, and it manages the key material for your embedded wallet. Privy then issues a credential that establishes your Accustom session. See Privy's Privacy Policy and User Terms of Service
  • Google Firebase: Holds your authenticated session (Firebase Authentication, established from the Privy credential above) and provides database storage (Firestore), cloud storage for evidence files (photos, videos), backend functions, and notification infrastructure
  • Meld (Meld Universal Inc.): Routes in-app USDC purchases to a licensed third-party provider. Accustom does not receive your card, bank, or identity-verification details — those go to Meld and the provider that fulfils your purchase. See Meld's Privacy Policy
  • Base network infrastructure: We read from and write to the Base blockchain through RPC providers and use Blockscout to display your transaction history. These providers may observe your wallet address and IP address when your device queries them

Third-Party Integrations

If you choose to connect your GitHub account for verification purposes, we share authentication credentials with GitHub and receive commit data from your connected repositories. This integration is optional and can be disconnected at any time through your account settings. Disconnecting will prevent you from using GitHub-based verification for future check-ins.

Legal Requirements and Safety

We may disclose your information if required to do so by law, court order, or governmental regulation, or when we believe in good faith that disclosure is necessary to: (a) comply with legal obligations; (b) protect and defend our rights or property; (c) prevent fraud or illegal activity; (d) protect the personal safety of users or the public; or (e) protect against legal liability.

Business Transfers

If Accustom is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service of any change in ownership or uses of your personal information, as well as any choices you may have regarding your information.

Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Given that Accustom handles financial transactions and sensitive personal evidence, security is a top priority.

Technical Safeguards

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security) encryption
  • Encryption at Rest: Data stored in our databases is encrypted using industry-standard encryption protocols
  • Secure Cloud Infrastructure: We use Google Firebase's secure cloud infrastructure, which maintains SOC 1, SOC 2, and SOC 3 compliance
  • Payment Security: All payment processing is handled by PCI DSS compliant providers. We never store complete credit card numbers, CVV codes, or other sensitive payment credentials

Organizational Safeguards

  • Access Controls: Access to personal information is restricted to authorized team members who need it to perform their job functions
  • Security Monitoring: We monitor our systems for potential vulnerabilities and attacks
  • Incident Response: We have procedures in place to detect, respond to, and recover from security incidents

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users as required by applicable law.

Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:

  • Account Information: Retained while your account is active. Upon account deletion request, personal data is permanently deleted within 30 days, except where retention is required for legal compliance
  • Evidence Check-Ins: Photos, videos, screenshots, and other evidence are automatically deleted within 15 days after the associated challenge or commit ends. This ensures your personal media is not retained longer than necessary for verification purposes
  • Transaction Records: Pledge and transaction history is retained for up to 7 years as required by tax laws and financial regulations
  • On-Chain Records: Deposits and payouts written to the Base blockchain are permanent. They cannot be deleted or amended by Accustom, by you, or by anyone else, and they persist regardless of whether you delete your account
  • Support Communications: Customer support interactions are retained for 3 years to help resolve any follow-up issues and improve our support services
  • Aggregated Analytics: Anonymized, aggregated data that cannot be used to identify individuals may be retained indefinitely for analytics and service improvement purposes

Your Rights and Choices

We believe you should have control over your personal information. Depending on your location, you may have certain rights regarding your data:

All Users

  • Access and Update: You can view and update your profile information, notification preferences, and account settings at any time through the app
  • Data Export: You may request a copy of your personal data by emailing support@accustom.app
  • Account Deletion: You may delete your account directly within the app by going to Profile → Delete Account. You will be asked to confirm by typing "delete my account". Upon confirmation, your account and personal data will be permanently deleted within 30 days, except where retention is required for legal compliance (such as financial transaction records). Deleting your account does not remove past transactions from the blockchain, which cannot be erased, and does not delete the wallet itself — your wallet and any funds in it remain yours
  • Data Deletion Without Account Deletion: If you wish to delete specific data (such as evidence check-ins or support chat history) while keeping your account active, you may request this by emailing support@accustom.app
  • Third-Party Connections: You may disconnect GitHub integration at any time through your account settings
  • Marketing Communications: You may opt out of marketing emails while continuing to receive essential notifications about your challenges, commits, and account
  • Push Notifications: You may disable push notifications through your device settings or the app's notification preferences

Important: If you have active Challenges or Commits with pending Pledges, we recommend completing them or waiting for them to end before deleting your account. Pledges from incomplete challenges may become non-refundable according to the challenge rules.

California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
  • No Sale of Personal Information: We do not sell personal information to third parties

Australian Residents (Privacy Act 1988)

Accustom is based in Melbourne, Victoria, Australia, and we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As an Australian user, you have the following rights:

  • Right to Access: You may request access to the personal information we hold about you (APP 12)
  • Right to Correction: You may request correction of your personal information if it is inaccurate, incomplete, or out of date (APP 13)
  • Right to Anonymity: Where practicable, you have the option of not identifying yourself or using a pseudonym when dealing with us (APP 2)
  • Right to Complain: You may lodge a complaint about our handling of your personal information

Complaints: If you believe we have breached the APPs or mishandled your personal information, you can lodge a complaint by emailing privacy@accustom.app. We will investigate and respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by phone at 1300 363 992.

European Union and UK Residents (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation (GDPR):

  • Right of Access: You may request a copy of your personal data
  • Right to Rectification: You may request correction of inaccurate personal data
  • Right to Erasure: You may request deletion of your personal data in certain circumstances. This right cannot be exercised over data recorded on a public blockchain, which is technically impossible for us to erase
  • Right to Restriction: You may request restriction of processing in certain circumstances
  • Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format
  • Right to Object: You may object to processing based on legitimate interests
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time
  • Right to Lodge a Complaint: You may file a complaint with your local data protection supervisory authority

To exercise any of these rights, please contact us at privacy@accustom.app. We will respond to your request within 30 days.

International Data Transfers

Accustom is based in Melbourne, Victoria, Australia. However, we use cloud service providers whose servers may be located in other countries, including the United States (Google Firebase, Privy, Meld) and other jurisdictions. Blockchain networks are distributed globally by design, so on-chain transaction data is replicated across nodes worldwide and is not confined to any single jurisdiction.

Your personal information may be transferred to and processed in countries other than your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • For Australian Users: Cross-border transfers comply with APP 8 of the Australian Privacy Principles. We take reasonable steps to ensure overseas recipients handle your information in accordance with the APPs.
  • For EEA/UK Users: Transfers are protected by Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms.
  • All Users: Our service providers (Firebase, Privy, Meld) maintain appropriate data protection certifications and contractual obligations.
  • On-Chain Data: Data written to the Base blockchain is replicated globally and is not subject to these transfer mechanisms. Only your wallet address and transaction amounts are written on-chain — never your name, email, or evidence.

Children's Privacy

Accustom is not intended for users under 18 years of age. The financial nature of our platform, which involves paying Pledges for habit accountability programs, requires users to be of legal age to enter into financial agreements.

We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information immediately. If you believe we have collected information from a child under 13, please contact us at support@accustom.app.

Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for basic website functionality, such as maintaining your session and remembering your preferences
  • Analytics Cookies: Help us understand how visitors interact with our website, which pages are most popular, and how we can improve the user experience

You can control cookie settings through your browser. Disabling certain cookies may limit website functionality.

The app uses browser local storage and similar technologies to keep you signed in, remember your preferences, and deliver notifications.

Summary of Data We Collect

For quick reference, here is a summary of what we collect and how it is handled. This summary does not replace the detailed sections above.

Data Types Collected

  • Personal Information: Name, email address (required for account), timezone
  • Wallet Address: Your public wallet address, used to verify deposits and send payouts. We never hold your private keys
  • Transaction Records: Pledge and payout amounts, dates, and on-chain transaction hashes. We never see or store card or bank details
  • Photos and Videos: Photos and timelapse videos submitted as evidence (user-initiated uploads only)
  • App Activity: Challenge/commit participation, verification check-ins, app interactions

Data Sharing

Data is shared with service providers (Firebase, Privy, Meld) for app functionality. We do not sell personal data or share it with third parties for advertising purposes. Wallet addresses and transaction amounts are additionally published to the Base blockchain, where they are permanently and publicly visible.

Data Security

All data is encrypted in transit using TLS. We do not receive or store payment credentials — wallet funding is handled entirely by third-party providers.

Data Deletion

You can delete your account and data in the app (Profile → Delete Account) or by contacting support@accustom.app. Off-chain data is deleted within 30 days of request, except financial records retained for regulatory compliance. On-chain transaction records cannot be deleted by anyone, including us.

Wallet and Blockchain Data

⚠️ Blockchain data is public and permanent

Accustom settles Pledges and payouts on Base, a public blockchain. Transactions written to a public blockchain are visible to anyone and cannot be edited or deleted — not by you, and not by us. This is a property of the network itself, and it means the rights described elsewhere in this policy (deletion, correction, erasure) cannot be applied to on-chain data.

Your Wallet

You may sign in with an existing wallet you already control. If you sign in by email or a social login instead, Privy creates a wallet for you automatically. That wallet has two parts:

  • A signing key held in Privy's embedded wallet infrastructure. This is what authorises transactions.
  • A smart contract account on the Base network, controlled by that signing key. This is the address that holds your funds and the address we store against your account.

We store your public smart account address and link it to your account so we can verify your Pledge deposits and send your payouts.

We never have access to your private keys or recovery phrase. Key material is handled by Privy's wallet infrastructure. Accustom cannot move funds out of your wallet, cannot recover it on your behalf, and cannot sign transactions for you.

Transaction Relay Infrastructure

Because your wallet is a smart contract account, your transactions are submitted through third-party relay infrastructure (commonly called bundlers, and where gas is sponsored, paymasters) rather than sent directly to the network by your browser. This infrastructure is operated by our wallet provider and its subprocessors.

When a transaction is relayed, that infrastructure necessarily observes the transaction contents and may observe your IP address. It does not receive your name, email address, or any evidence you have submitted. Privy publishes the list of subprocessors it uses at trust.privy.io/subprocessors.

What Becomes Public

The following information is written to the Base blockchain and is permanently and publicly readable by anyone, including through block explorers:

  • Your wallet address
  • The amount of each Pledge you deposit into the escrow contract, and the date and time
  • The amount of each payout you receive, and the date and time
  • Any other transaction your wallet makes, including activity unrelated to Accustom

Your name, email address, evidence check-ins, habit descriptions, and support communications are never written to the blockchain. However, a wallet address is a persistent identifier: if you publicly associate your identity with your wallet address elsewhere, or if you fund it from an account that identifies you, third parties may be able to connect your on-chain Accustom activity to you. We recommend using a wallet dedicated to Accustom if this concerns you.

Payouts

  • Destination: Payouts (Challenge Bonus Rewards and pledge returns) are released from the escrow smart contract in USDC to the wallet address associated with your account
  • Data We Share: To make a payout we submit your wallet address and the payout amount to the Base network. No other personal information is included in the transaction
  • Irreversibility: Once broadcast, a payout transaction cannot be recalled or reversed
  • Record Retention: We retain our own off-chain payout records for up to 7 years for tax and regulatory compliance. The corresponding on-chain records persist indefinitely and are outside our control

Funding Your Wallet

If you buy USDC through the in-app funding flow, that purchase is handled by Meld and the licensed provider it routes you to. Those providers collect your payment details and, in most cases, identity verification documents (KYC) directly from you.

  • Accustom does not receive, process, or store your payment details or identity documents
  • The provider that fulfils your purchase acts as an independent controller of the identity and payment information you give it, in order to meet its own regulatory obligations. Its handling of that information is governed by its own privacy policy, not this one
  • Meld operates as a routing layer between you and that provider. For some of the processing it performs in connection with the Accustom integration, Meld acts as a processor on our behalf, and we remain the controller of that data
  • We observe only the resulting USDC transfer into your wallet, in the same way we observe any other on-chain deposit

Which provider fulfils your purchase is selected by Meld at the time of the transaction and may differ between purchases.

Charity Donations

When you create a Commit with a charity donation option and the Pledge is donated:

  • Donation Processing: Non-refundable fees are donated to our partner charity organizations
  • Information Shared: We may share aggregated donation amounts with charity partners. Your personal information is not shared with charity organizations
  • Tax Documentation: We maintain records of charitable donations for reporting purposes. You may request documentation for your own tax records by contacting support
  • Partner Charities: Information about our current charity partners is available in the app during commit creation

Biometric and Sensitive Data

Our Service may collect certain sensitive information as part of evidence check-ins:

Photos and Videos

Photos and timelapse videos you submit as evidence may contain:

  • Your likeness or images of you
  • Images of your surroundings, possessions, or location
  • Metadata including capture time and device information

We do not use facial recognition technology or extract biometric identifiers from your photos or videos. Evidence is reviewed manually by moderators solely to verify completion of your stated habit. Evidence is automatically deleted within 15 days of challenge/commit completion.

Health and Fitness Information

If you create habits related to health, fitness, diet, or wellness, the evidence you submit may contain health-related information. We:

  • Only use health-related evidence for verification purposes
  • Do not share health-related information with third parties for marketing or insurance purposes
  • Delete evidence according to our standard retention policy (15 days after challenge completion)
  • Do not make health decisions based on your check-ins or provide health advice

Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no uniform standard for how DNT signals should be interpreted, our website does not currently respond to DNT signals. However:

  • We do not track users across third-party websites for advertising purposes
  • We do not sell your personal information to advertisers or data brokers
  • You can control cookies through your browser settings as described in the Cookies section

Data Portability

You have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format. Upon request, we can provide:

  • Your account information and profile data
  • Your challenge and commit participation history
  • Your transaction history (Pledges, payouts, purchases)
  • Your notification preferences and settings

To request a data export, email support@accustom.app with the subject line "Data Export Request". We will provide your data within 30 days in JSON or CSV format.

Third-Party Links and Services

The Service may contain links to third-party websites or services that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. This includes:

  • Wallet and funding providers (Privy, Meld, and the onramp provider that fulfils your purchase)
  • Blockchain explorers such as Blockscout, used to view transaction history
  • Social media platforms linked from our website
  • External resources or articles we may reference
  • Optional integrations you choose to connect (GitHub, Strava)

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:

  • Sending an email to the address associated with your account
  • Displaying a prominent notice within the app
  • Updating the "Last Updated" date at the top of this policy

Material changes will become effective 30 days after notification, giving you time to review the updates. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree with any changes, you should stop using the Service and delete your account before the changes take effect.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Accustom

General Privacy Inquiries:
privacy@accustom.app

General Support:
support@accustom.app

Data Protection Officer (GDPR/UK):
For EU and UK residents with GDPR-specific inquiries:
dpo@accustom.app

Data Deletion Requests:
Delete Account |Request Data Deletion

Response Times:

  • Privacy requests (access, deletion, export): Within 30 days
  • GDPR/CCPA rights requests: Within 30 days (or 45 days with notice for complex requests)
  • General inquiries: Within 2-3 business days
  • Security concerns: Within 24 hours

Effective Date: December 1, 2025 | Last Updated: August 16, 2026