Daily Brave
PRIVACY POLICY
For Untried · in force since 10 September 2026
What Untried stores about you, who else sees it, and how to get rid of it. No analytics, no advertising, no trackers, and nothing sold to anybody — the rest of this page is the detail behind those four claims.
Who holds your data
RL Now, inc, a limited liability company registered in Delaware, USA, is the controller of the personal data described here.
651 N Broad St, Suite 201 · Middletown, DE 19709 · United States
hey@unfck.it
What we store
Your account. Your email address, an account identifier, and when the account was made. You sign in with Google or with a one-time link sent to your email — either way there is no password, so there is no password for us to hold or lose.
Your practice. The date you started, your time zone, your answer to the one calibration question at onboarding and the gentleness setting it produces. Then, per day: which prompts you were offered, which you turned down, which you took, and — when you log a day — the prompt and your answers to the form.
In Untried, that form asks:
- Did you do it?
- What did you do?
- How new did it feel?
- Photo (optional) — optional
Photos, if you add them. Both the photo you upload and the pixel-art version that comes back. A profile picture is up to you; a photo on a day’s entry is a supporter extra and equally up to you. The app never opens your camera roll on its own.
Support. If you contribute, we store that you are a supporter, when, and a record of the contribution — the amount, the currency, whether it was one-off or monthly, and the customer reference Stripe gives it. Your card number is never sent to us and we could not store it if we wanted to.
Notifications, if you turn them on. Your device’s notification token, your time zone, and which app it is for — enough to send one nudge at 9am where you are, and nothing else.
Sign-in emails. To stop someone spamming link requests at an address, we keep a one-way hash of the address and a count. The address itself is not stored by that mechanism — a rate-limit table should not double as a mailing list.
Your username and friends, if you use them. The username you claim, the people you are friends with, and any requests waiting in either direction. Claiming a username is optional; without one you cannot be found, cannot add anyone, and nothing you log goes anywhere.
Bug reports, if you send one. What you wrote, any screenshots you attached, and the technical details of the moment — which app and version, the screen you were on, your device and browser, and any errors the app logged. It is sent on to GitHub, where it becomes a ticket we work from, tagged with your account identifier so we can follow up. Your answers to the form above are never part of it.
On your own device. Before you have an account, your start date and a half-written entry are held in your browser’s local storage so the sign-in detour does not throw them away. Which donation asks you have dismissed lives there too. It stays on your device, and clearing site data removes it.
What friends see
Nothing, until you claim a username and accept somebody. Friendship is mutual — a request from one side and an acceptance from the other — and either of you can end it.
When you log a day with the share box ticked, one card is copied into your friends’ feeds. It carries your username, your profile picture, which day of 100 you are on, the task itself, and the photo if you added one.
What you wrote in the form is not on that card and never reaches another person. That is not a policy we apply by hand — the server builds the card out of the task and the photo, and nothing else it reads is put on it. It does read one of your answers: whether you said the day happened. If you logged that it did not, no card goes out, and one that already went out is taken back. The box is ticked by default and is asked once per day, so a day you would rather keep costs one untick. (Stylising a photo is the one thing that sends those answers anywhere at all, and it sends them to Google, not to anybody you know — see What the AI sees.)
Removing a friend removes your shared days from their feed and theirs from yours. Deleting your account removes both, everywhere, and hands your username back.
There is no public profile, no follower list and no way to browse for people. A username can only be looked up by someone who already knows it or your email address, and a request has to be accepted before anything is shared.
What we do not collect
No analytics, no advertising identifiers, no third-party tracking scripts, and no profile built for marketing. There is no analytics SDK in the app — not a privacy-preserving one, not one at all.
No location. The app does not ask for it and does not store it. A future version of the Coach may offer city-level suggestions, and if that is ever built it will be opt-in and this page will describe it before it ships.
No selling or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, in the sense California law gives those terms or in any other sense.
What the AI sees
Two features send data to Google’s Gemini API, and it is worth being exact about which data.
Photo stylising. The photo you chose is sent, and with it the day’s task and whatever you had typed into the form at that moment — the picture is meant to show what happened, and it cannot without them. Pixel art comes back. Nothing else goes: not your name, not your account identifier, not your other days.
The Coach (supporters only) sends: which day of 100 you are on, your difficulty ceiling and whether you asked for gentler prompts, the wording of prompts you have already completed, any you turned down today, and the list of prompts it is allowed to choose from. It does not send what you wrote in a reflection, your email address, your account identifier, your photos, or anything about your device. It can only pick from a pre-approved list — it does not write prompts.
We use Gemini’s paid tier, where Google’s terms say submitted content is not used to train their models. We do not train any model on your data ourselves.
Who else touches it
Four companies, each doing one job. None of them may use your data for their own purposes.
- Google (Firebase) — Sign-in, the database, file storage, notifications and the servers the app runs on. Most of what the app stores lives here. Their policy.
- Google (Gemini API) — Turns a photo you upload into pixel art, and — for supporters — picks the Coach's daily suggestion. Their policy.
- Stripe — Takes the payment when you support the app. Card details go to Stripe directly and never reach us. Their policy.
- Resend — Delivers the sign-in email, when you ask for a link instead of using Google. Their policy.
- GitHub — Receives a bug report when you send one, so it becomes a ticket we can work from. Your reflections are never part of it. Their policy.
The app also uses Google’s App Check with reCAPTCHA Enterprise, which looks at signals from your browser to tell a real visitor from a bot hammering the servers. It is a security control, not a tracker, and it is the one thing here that would still run if you never signed in.
We will hand data to a court or a regulator when we are legally obliged to, and not otherwise.
Cookies
There are no advertising or analytics cookies, so there is no cookie banner to click past. What is stored on your device is the sign-in session that keeps you logged in, the local storage described above, an offline cache so the app opens without a connection, and whatever reCAPTCHA needs to decide you are a person. All of it is necessary for the app to work; none of it follows you anywhere else.
Where it is kept
On Google Cloud infrastructure, with our own server code running in the European Union. Google, Stripe, Resend and the Gemini API are US companies and process data in the United States and elsewhere; each publishes the transfer safeguards it relies on for data leaving the EU or UK, and those are linked above.
How long
Your account and everything in it stay until you delete them — this is a hundred-day practice with a recap at the end, and quietly expiring someone’s day 60 would defeat the point.
Deleting your account removes your profile, your entries, your photos, your friendships, every day you shared into someone else’s feed, your notification tokens and your bug reports, immediately and for good. Your username is released and can be claimed by somebody else. One exception, and it is deliberate: records of contributions are kept as financial records, stripped of anything that names you — the amount and the date survive, your identity does not. Stripe keeps its own copy of every payment under its own legal obligations, which we cannot delete on your behalf.
If you reported a bug, the ticket it became stays on our side — it describes a defect in the app, and it may still be waiting to be fixed. What you wrote about the problem stays with it. Any screenshots you attached are deleted along with your other photos, and the account identifier on the ticket is left pointing at an account that no longer exists.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask for it in a portable form, object to a particular use, or ask us to restrict one. Email hey@unfck.it and you will get an answer within 30 days. There is no charge and no penalty for asking.
Deletion needs no email at all — the account screen does it yourself, in full, on the spot. That is the fastest route, and it is meant to be.
Where the GDPR applies, we rely on: performing our agreement with you (running the practice and keeping your entries), your consent (notifications, photos, and the calibration answer), our legitimate interest in keeping the service standing up (App Check, rate limits), and legal obligation (financial records). You can withdraw consent at any time without affecting what came before, and you can complain to your national data protection authority if we get this wrong.
Children
The app is for people 18 and over, and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has an account, write to us and it will be removed.
If something goes wrong
If a breach ever puts your data at risk, we will tell you and the relevant regulator within the deadlines the law sets, and we will say what actually happened rather than issue a statement about how seriously we take security.
Changes
The date at the top is when this version took effect. If what we collect ever materially changes, this page changes first and the app will tell you. See also the terms of use.