Version 1.0 · Last updated August 2026
Afoot gives you one real-world thing worth doing, on a cadence you chose, and keeps the record of what you did. This policy explains what we do with your personal data. It is short because Afoot collects little: there is no feed, no friends, no messaging, and nothing you make in the app is shown to anyone else. Your Logbook is yours.
Afoot (“Afoot”, “we”, “us”) is a mobile application. This policy applies to the app and to any page we publish at afoot.app.
The data controller — who decides why and how your personal data is processed — is Afoot, based in Argentina. You can reach us for any data-protection matter at the address below.
For anything in this policy, including any request to exercise the rights in section 9, write to privacy@afoot.app. We answer within one month, or sooner where the law where you live requires it (see sections 10 and 11), and will tell you if we need longer.
We have not appointed a Data Protection Officer, and are not required to: we do not carry out large-scale monitoring, and we do not profile people.
| What | Detail | Optional? |
|---|---|---|
| Account | Your email address, and a password if you sign up that way — or an Apple or Google account if you sign in with one of those. A password is stored only as a hash; we never see it. | Required |
| Name | A display name you can set, used only to greet you in the app. | Optional |
| Your cadence | How often you want an experience, on which days and at what time. | Required to use the app |
| Commitments | The experiences you commit to and when you scheduled them. If you allow it, Afoot adds these to your device calendar — that write stays on your device and is not sent to us. | Optional |
| Field notes | After an experience you may add one photo, one line of text, and a mood. This is the content of your Logbook, and it is private to you. | Optional |
| Support requests | If you contact us from the app, the category you choose, the message you write, any screenshots you attach, and basic diagnostics (app version, device and OS) so we can reproduce the problem. | Optional |
| What | Detail |
|---|---|
| Product analytics | Which screens you open and which actions you take, sent to PostHog. Events carry identifiers, counts, booleans and fixed categories only — never your field-note text, a photo, or anything you wrote. Your internal user id is attached so activity belongs to one person; your email and name are not sent to our analytics provider. |
| IP address | Seen by our servers and by our analytics provider whenever your device connects. Used for security, abuse prevention and coarse, country-level analytics. Afoot does not collect your device location. |
| Device & app diagnostics | App version, build, platform, OS version, device model and language — and any crash or error the app hits, so we can fix it. |
| Subscription state | Whether you hold a paid subscription, its period and expiry, and the purchase events behind it, received from RevenueCat and the app stores. |
If you are in the UK, the EEA or another place with equivalent law, we must have a lawful basis for each purpose. Here they are.
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account; letting you sign in | Account, name | Performance of a contract with you |
| Delivering your experience on the cadence you set, and keeping your Logbook | Cadence, commitments, field notes | Performance of a contract |
| Sending reminders you asked for | Commitment times, notification settings | Consent, given by turning notifications on |
| Understanding how the app is used, and fixing crashes | Pseudonymous analytics events, internal user id, diagnostics | Consent, and legitimate interests in a working app |
| Taking payment and honouring your subscription | Subscription state, store purchase events | Performance of a contract, and legal obligation for records |
| Keeping the service secure and preventing abuse | IP address, diagnostics, account | Legitimate interests in a safe, available service |
| Responding to lawful requests and defending claims | Whatever is relevant | Legal obligation, and legitimate interests |
Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time under section 9. Where we rely on consent you can withdraw it at any time, in your device settings or in the app, without affecting anything done before you withdrew it.
Your field-note photos are held in private storage and served only to you through short-lived signed links. The only time anything leaves the app is when you choose to share a Logbook entry through your phone's share sheet — at which point it goes wherever you send it, under that app's rules rather than ours.
Processors. These act only on our instructions, under a data processing agreement, and may not use your data for their own purposes.
| Processor | What it does | What it sees | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage, and the account-deletion function | Effectively everything in section 2 that we store: account, name, cadence, commitments, field notes | United States |
| PostHog | Product analytics and crash reporting | Your internal user id, your usage events, diagnostics, and your IP address. Not your email, name or field notes | United States |
| RevenueCat | Subscription management | Your internal Afoot user id and your subscription state | United States |
Other recipients. These act for their own purposes under their own policies.
| Recipient | What it does | What it sees | Where |
|---|---|---|---|
| Apple and Google | App distribution, payment, and push transport on their own platform | Purchase and delivery data, as independent controllers | Global |
We may also disclose personal data where we are legally required to; to establish, exercise or defend legal claims; to protect the safety of a user or the public where we have a good-faith belief it is necessary; or to a buyer, if Afoot is ever sold — in which case we will tell you before your data becomes subject to a different policy.
Afoot's database, storage, analytics and subscription providers are United States companies. If you are in the UK or the EEA, your personal data is therefore transferred outside your country. The United States has not been found to provide protection equivalent to the UK or EU regime for all transfers, so we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where relevant. For transfers of Argentine personal data we rely on the clauses in Anexo II of Disposición 60-E/2016. You can ask us for a copy of the safeguards that apply to a particular transfer by writing to privacy@afoot.app.
| Data | Kept for |
|---|---|
| Account, name, cadence | Until you delete your account |
| Commitments and field notes (your Logbook) | Until you delete them, or delete your account |
| Support requests and their screenshots | Until you delete your account |
| Analytics events and diagnostics | Up to 12 months |
| Payment and subscription records | As long as tax and accounting law requires, typically 5–10 years depending on jurisdiction |
| Server and security logs, including IP address | Up to 90 days |
You can delete your account from Settings inside the app. We do not require you to email us, and we do not try to talk you out of it.
Everything you made is erased. Because Afoot keeps nothing of yours on a public map, there is nothing to retain. Deleting your account removes, in one operation:
You can also ask us to delete your account by writing to privacy@afoot.app, and we erase or anonymise your data within 30 calendar days of the request. Your pseudonymous analytics events, which carry no name or email, age out within the retention window in section 7. Anything we are legally required to keep, such as payment records, is unaffected, as are aggregate counts that cannot identify you.
Wherever you live, you can ask us to do any of the following, free of charge, by writing to privacy@afoot.app. We may ask you to confirm you control the account, but nothing more.
| Right | What it means here |
|---|---|
| Access | A copy of the personal data we hold about you |
| Portability | That copy in a structured, machine-readable format |
| Rectification | Correct anything inaccurate — your name you can change yourself |
| Erasure | Delete your account and data (section 8) |
| Restriction | Pause our use of your data while a dispute about it is resolved |
| Objection | Object to processing we base on legitimate interests |
| Withdraw consent | Turn off notifications or analytics, in your device settings or in the app |
We will not treat you differently for exercising any of these, and we do not offer financial incentives in exchange for personal data.
If you live in California, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and to opt out of sale or sharing.
Categories we collect, using the statute's own labels: identifiers; commercial information (subscription state); internet or network activity (usage events); and visual information (your field-note photos). We collect these from you, from your device, from your app store, and from our service providers. Retention for each is in section 7. We collect one category of sensitive personal information — your account log-in credentials — and use it only to provide the service and secure your account, never to infer characteristics about you, so we are not required to offer a “Limit the Use of My Sensitive Personal Information” control.
You may exercise your rights using the contact in section 9, or through an authorised agent with written proof of authority; on our website we honour the Global Privacy Control signal as a valid opt-out. If we refuse a request we will tell you why and you may appeal by replying. Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana and other states with comprehensive privacy laws have the same rights of access, correction, deletion, portability, opt-out and appeal.
If Argentine data protection law applies to you, Ley N° 25.326 and Decreto N° 1558/2001 give you rights of access, rectification, updating and suppression, overseen by the Agencia de Acceso a la Información Pública (AAIP). Requests go to the address in section 9. We answer an access request within 10 calendar days, and a rectification, updating or suppression request within 5 working days — shorter than the one month in section 1, and they take precedence for you.
We register our databases with the AAIP as Ley N° 25.326 requires. Because our infrastructure is in the United States, which the AAIP does not treat as adequate, we transfer Argentine personal data under the model contractual clauses in Anexo II of Disposición 60-E/2016.
You must be at least 16 to use Afoot. The service is not directed at younger children, we do not knowingly collect their data, and we have no features aimed at them. If you are 16 or 17, you may use Afoot only with the consent of a parent, legal representative or guardian.
If you believe someone under that age has an account, write to privacy@afoot.app and we will delete it.
Traffic is encrypted in transit and data is encrypted at rest. Passwords are stored only as salted hashes. Access to the database is constrained by row-level security, so one account cannot read another's data, and field-note photos live in a private bucket reachable only through short-lived signed links scoped to your own account. No system is perfectly secure. If we discover a breach likely to risk your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk is high.
We will update this page when what we do changes. The effective date at the top always reflects the current version. If a change materially reduces your rights or materially expands what we collect, we will tell you in the app or by email at least 30 days before it takes effect, and where the law requires consent we will ask for it rather than assume it.
If you think we have handled your personal data unlawfully, please raise it with us first at privacy@afoot.app — most things are a misunderstanding we can fix quickly. You also have the right to complain to a supervisory authority directly: in the EEA, the authority where you live or work; in the UK, the Information Commissioner's Office; in Argentina, the Agencia de Acceso a la Información Pública.