Privacy Policy
Effective 25 September 2026. This document is versioned in the repository that serves it; the date above changes when the text does.
iou is a points tracker for a group of people. You create a Network, name its currency, invite the people who belong in it, and send points back and forth. This policy describes every piece of information the app holds about you, why it holds it, and what happens to it when you leave.
It is written from the app's actual database schema rather than from a template. Where it says the app does not collect something, that is a statement about what exists in the schema, not a statement of intent.
Who is responsible
Noah Finn is the data controller for iou.
Contact: [email protected]
The short version
- The only thing you have to give iou to use it is an email address, and it exists so you can sign in.
- There is no advertising, no analytics, no crash reporting and no tracking of any kind. No third-party SDK in the app collects anything, because there is no third-party SDK in the app that collects anything.
- Everything else iou stores is something you typed or uploaded: a name, a Network, an amount, a note, a photo.
- You can export everything iou holds about you as a file from inside the app.
- You can delete your account from inside the app. What that does, and the one thing it cannot do, is described in full below.
What iou collects, and why
Your account
| What | Why |
|---|---|
| Email address | The only way to sign in. iou has no passwords: you enter your address, it sends an 8-digit code, and entering the code signs you in. The address is held by the authentication system and is not shown to other users. |
| Username | Your unique @handle. Other people use it to send you a friend request or invite you to a Network. |
| Display name | The name shown beside you in every Network you are in. |
| Profile picture | Optional. Without one, iou draws your initials. See Pictures are public below. |
| Language | The language used for your push notifications. It starts as the language your phone was set to when you created your account, and changes whenever you choose a different language in the app. |
| Notification preferences | Whether you want to hear about invites and friend requests. |
| Privacy preferences | Who may invite you, who may send you a friend request, and who may find you by username. |
| When you last opened your notifications | One timestamp. It is the whole of the unread indicator — iou does not record which individual notifications you have read. |
| When your account was created |
The Networks you are in
For each Network you create or join, iou stores the Network's name, its currency's name and symbol, its logo if it has one, and its settings — who may invite, whether members may send to each other, whether balances may go negative, and the rest.
For each membership, iou stores your role in that Network, which invite brought you in, when you joined, and — if you have left, been removed, or been banned — when that happened, who did it, and what your balance was at that moment.
The ledger
Every movement of points is a row: the amount, the type (a transfer, an issuance, a redemption, an adjustment or a burn), who it was from and to, an optional note of up to 5,000 characters, who created it, and when. Requests to send or redeem points are stored the same way, with their status.
Balances are not stored. A balance is worked out by adding up the ledger every time it is shown, which means a number in iou is always the sum of things that actually happened.
The ledger is append-only. Nothing in it can be edited or deleted, by you or by anyone else, including the person who wrote it. A mistake is corrected with a new, offsetting entry, so the history stays true. This matters for what deletion can and cannot do — see below.
Invites, friends and blocks
iou stores the invites you create (including the code in a shareable link, when it expires, and how many times it may be used), the friendships you have and the requests that have not been answered yet, and the accounts you have blocked.
Your friends list is the one list of people you know that iou holds. It is built only from requests sent and accepted inside iou, and it is what Apple's privacy label for the app counts as "Contacts".
A block is readable only by the person who set it. Being blocked is not something the blocked person is told.
Notifications
If you turn on push notifications, iou stores a device token for each device you have allowed them on, along with the platform and when the device was last seen. The token identifies an app installation, not you personally, and signing out deletes that device's token.
iou also records the events that notifications are generated from, so that a notification can be sent once rather than once per recipient, and it keeps what the push service said about each send long enough to learn whether a device token has stopped working.
If you are removed from or banned from a Network, iou records that fact in your in-app inbox, with the Network's name and logo as they were at that moment, and who removed you — because by then you can no longer read that Network's own records.
What iou does not collect
There is no advertising identifier, no analytics, no crash or error reporting, no third-party tracking SDK, and no data shared with a data broker. Nothing you do in iou is combined with data about you from other companies' apps or websites.
iou does not collect or have access to your location, your phone's contacts or address book, your health data, your browsing or search history, your purchases, or any payment information. The only list of people iou holds is the friends list you build inside the app, described above.
iou handles no money. The points in a Network are invented by that Network, have no monetary value, cannot be bought, sold or exchanged for money, and no payment of any kind passes through the app.
Why iou is allowed to hold it (legal bases)
Under the GDPR:
- Performance of a contract (Art. 6(1)(b)) — your account, your memberships, the ledger, and everything the app needs in order to be the app. You cannot have a shared points tracker without storing the points.
- Legitimate interests (Art. 6(1)(f)) — keeping the service working and resistant to abuse: rate limits on sign-in (which work from your IP address) and on the actions that could be used to flood someone, and the operational records that make notification delivery reliable.
- Consent (Art. 6(1)(a)) — push notifications, which only happen if you grant the permission, and which you can withdraw at any time in iOS Settings or in iou's own settings.
Pictures are public
Profile pictures and Network logos are stored in public buckets. That is a deliberate design decision and it has a consequence worth stating plainly: the URL of a picture is not a secret. Anyone who has the URL can open it without signing in, and the URL is derived from the account or Network's internal identifier rather than being random.
In practice a picture's URL reaches only the people who already see the picture in the app. But "public" here means genuinely public, and you should upload a profile picture on that basis.
Removing your picture in the app removes the file itself, not only the reference to it: an automatic sweep runs hourly and deletes every stored image that no account or Network still points at.
Who else is involved
These are processors acting on iou's instructions, not partners iou shares data with. They are named rather than hidden behind "service providers":
| Who | What they do | Where |
|---|---|---|
| Supabase | Hosts the database, the authentication system and the stored images. Everything iou stores lives here. The authentication system also keeps its own logs of sign-ins, which include your email address and your IP address, used for security and for the sign-in rate limits. | European Union |
| Resend | Sends the sign-in code to your email address. Receives your address and the code. | Processes outside the EEA under Standard Contractual Clauses |
| Expo | Relays push notifications to Apple's delivery service. Receives a device token, a random installation identifier the app creates when it first registers for notifications, and the text of the notification — which, for a Network notification, includes the Network's name and the sentence shown on your lock screen. | Processes outside the EEA under Standard Contractual Clauses |
Apple delivers the notification to your device once Expo hands it over, and Apple's own terms apply to that step.
How long it is kept
Your account and everything attached to it is kept for as long as the account exists. There is no automatic expiry: an account nobody has signed into stays as it is until somebody deletes it.
Device tokens are removed when you sign out on that device, and automatically when the push service reports that the app is no longer installed.
Supabase's sign-in logs are kept for Supabase's own log retention period, not for the life of the account, and then they are gone.
What happens when you delete your account is below.
Deleting your account
You can delete your account from inside iou: Profile ▸ Danger zone ▸ Delete account. The full path, including what to do if you can no longer install the app, is at bessta.com/work/iou/delete-account.
The shape of it:
- iou emails you a code and you enter it, so that an unlocked phone on a table cannot close your account.
- The request starts a 30-day grace period. During it your account is completely ordinary — you can send, receive and be invited, and nobody else is told anything. A banner in the app shows the date and offers one tap to cancel.
- If you have not cancelled after 30 days, an automatic process erases you.
What "erased" means, exactly
Your profile is anonymised: your username is replaced with a meaningless generated one, your display name becomes "Deleted User", your profile picture is deleted from storage, and your language and preferences are reset to defaults. Your sign-in identity is removed, so the email address can no longer sign in. Your device tokens, your friendships, your blocks, your in-app inbox and the counters behind rate limits are deleted outright. Your memberships are set to "left", exactly as though you had left every Network at once.
The one thing deletion does not do
The transactions stay. This is the part of iou a careful reader will want to know about, so it is said plainly:
A transaction has two ends. If you sent 50 points to someone, that is half of their balance and half of their history as much as it is yours. Deleting the row because you closed your account would silently change somebody else's balance and remove a record they rely on — so iou does not do it.
What happens instead is that your name comes off. The row stays, the amount stays, the note stays, and the end that used to be you becomes an anonymous, permanently inactive member. Your email address, username, display name and picture are no longer attached to it anywhere in iou.
Three things outlive the account, and you should know about them:
- Notes stay exactly as they were written. iou does not read notes, so a note you wrote — or one someone else wrote about you — keeps whatever it says, including a name if one was typed into it.
- Invites keep the anonymous identifier in your place, both the ones you created and the ones you were sent, because a Network's invite history is the Network's. That identifier no longer leads to an email address, a username or a picture.
- Supabase's sign-in logs keep your email address and IP address until their retention period runs out. iou does not remove individual entries from them.
Your rights
You can exercise the first three without writing to anyone:
-
Access and portability (Art. 15, Art. 20) — Profile ▸ About & Legal ▸ Download my data builds a JSON file and hands it to you through the iOS share sheet. It holds your profile, email address and preferences, every Network you are or were a member of, and every transaction and request you were part of, with its note. It is assembled on your device at the moment you ask; there is no link, no email, and nothing to expire. It contains your own records only: where a transaction involves someone else, that person is named — because that is your record of who you paid — and nothing further about them travels.
It also holds your invites (sent and received), friends and friend requests, the people you have blocked, the devices signed in to receive notifications, your in-app inbox and the Networks you created. Two things are left out on purpose: whether anyone has blocked you — telling you would undo the block — and the notification tokens themselves, which are working keys to a phone and say nothing the listed devices and dates do not.
-
Erasure (Art. 17) — the deletion flow above.
-
Rectification (Art. 16) — your username, display name, picture, language, and notification and privacy preferences are all editable in the app at any time.
For anything else — objecting to processing, restricting it, or a question this document does not answer — write to [email protected].
If you believe iou has handled your data unlawfully, you may complain to your national data protection authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).
Children
iou may be used by children under 13 with the consent of a parent or guardian, who is responsible for that use. iou does not ask for a date of birth and has no technical mechanism for verifying a parent's consent, so a parent or guardian giving that consent should expect to supervise the account themselves.
A child's account holds exactly what any other account holds, described above. A parent or guardian may exercise every right in this document on the child's behalf by writing to [email protected].
Security
Access to everything in iou is controlled at the database level rather than in the app, so what you are allowed to see is enforced by the server on every request rather than hidden by the interface. All traffic is encrypted in transit.
Two things are worth being honest about. Pictures are public, as described above. And iou is built and run by one person; it has the security posture of a small independent app, not of a bank.
Changes to this policy
If this policy changes, the effective date at the top changes with it, and earlier versions are available on request from [email protected]. A change that materially affects how your data is used will be announced in the app before it takes effect.