Commitment Privacy Policy
Effective August 24, 2026
This Privacy Policy applies to the Commitment Task Management Android application ("Commitment", "the app", "we", "us", or "our"). Commitment is a weekly planning and accountability app. This policy explains what information the app processes, why it is used, when it is shared, and the choices available to users.
Privacy contact: mmm.mor6164198@gmail.com.
Information processed
Information stored on your device
- Tasks and commitments, notes, schedules, completion history, categories, preferences, reminder settings, and Coach conversation history.
- A personal OpenAI API key, if you choose to provide one. The key is encrypted using Android Keystore, stored only on your device, excluded from Android backup, and is not sent to Commitment's servers.
Account and cloud information
Commitment initially uses Firebase Authentication to create a persistent anonymous user identifier. If you choose Sign in with Google, Google supplies basic account information such as your Google account identifier, name, email address, and profile image, and the anonymous Commitment identity is linked to that Google identity when possible.
After Google sign-in, Commitment creates a private Firebase backup of the app's task database and ordinary preferences and refreshes it periodically while the app is installed. This may include tasks, notes, schedules, history, categories, Coach history, and ordinary settings. The personal OpenAI API key is specifically excluded. Backup data is protected by Firebase security rules so it can be read or changed only by the signed-in Firebase identity.
If you use cloud or accountability features, Firebase may also process your identifier, chosen display name, circle membership and invite information, shared commitments, cancellation requests and decisions, and a Firebase Cloud Messaging token used to deliver relevant notifications. Information intentionally shared in a circle is visible to the other members of that circle.
Premium purchase information
When you buy or restore Premium, Google Play provides information needed to verify access, including the subscription product, purchase token, purchase state, acknowledgement state, and expiry time. Commitment stores a one-way hash of the purchase token together with entitlement status and related verification records. Commitment does not receive or store your full payment-card details.
AI information
When you choose to use an AI feature, the instruction and the task or app context needed to generate the response are sent to OpenAI:
- For Premium, the information is sent through Commitment's authenticated Firebase backend using the developer's OpenAI account.
- When you use a personal API key, the information is sent directly from your device to OpenAI under your OpenAI account.
The Premium backend does not intentionally store AI prompt bodies. It stores usage information such as request counts, estimated processing cost, the applicable usage period, and entitlement state to enforce subscription limits and prevent abuse. Premium API requests are configured with OpenAI response storage disabled. OpenAI may still process limited data according to its applicable service terms, privacy policy, and abuse-monitoring practices.
Technical information
Google Firebase, Google Cloud, Google Play, OpenAI, and network providers may automatically process technical information needed to operate and secure their services, such as IP address, timestamps, app and device identifiers, Firebase installation identifiers, request metadata, authentication information, errors, and security or abuse signals. Commitment does not use advertising SDKs and does not sell personal information.
How information is used
Information is used only as needed to:
- provide planning, reminders, local storage, synchronization, and accountability features;
- generate AI assistance that you request;
- verify, restore, and manage Premium access;
- deliver relevant service notifications;
- enforce request and cost limits, prevent fraud and abuse, maintain security, troubleshoot problems, and improve service reliability; and
- comply with legal obligations and enforce applicable terms.
When information is shared
Information is shared only as described in this policy:
- Google Firebase and Google Cloud provide authentication, database, messaging, server functions, secret management, hosting, logging, and security infrastructure.
- Google Play processes app distribution, subscription payments, purchase verification, and subscription management.
- OpenAI processes content submitted when an AI feature is requested.
- Accountability partners can see information you intentionally share in their circle.
- Information may be disclosed when required by law, to protect users and the service, or in connection with a lawful business transfer.
Commitment does not sell or rent user information.
Retention and deletion
- Device data remains until you delete it in the app, clear the app's storage, or uninstall the app.
- Private cloud backup is retained for the signed-in account until it is replaced by a newer backup or a verified deletion request is completed.
- Cloud accountability data is retained while needed to provide the features and until it is deleted or a verified deletion request is completed.
- Messaging tokens are retained while active and are replaced or removed when no longer needed or when a verified deletion request is completed.
- Premium entitlement and usage records are retained while needed to provide Premium, enforce limits, resolve disputes, prevent fraud, and meet accounting or legal obligations.
- AI prompt bodies are not intentionally retained by Commitment's Premium backend. Service-provider security logs may be retained under the provider's applicable policies.
Verified deletion requests are normally completed within 30 days. Residual copies may remain in protected backups for up to 90 days before being overwritten. Limited purchase, transaction, fraud-prevention, security, dispute, or accounting records may be retained longer where reasonably necessary or legally required; where possible, they will be isolated or de-identified.
To request deletion of your Firebase identity and associated cloud data, visit the Commitment account and data deletion page. Deleting cloud data does not automatically cancel a Google Play subscription; subscriptions can be managed in Google Play.
Your choices
- You can use core planning features without Google sign-in. Google sign-in is optional and enables private cloud backup and cross-device restoration.
- You can use planning features without intentionally sharing task content with accountability partners.
- You can choose whether to invoke AI features. You can remove a personal API key in Advanced options.
- You can control notification permission through Android settings.
- You can manage or cancel Premium through Google Play.
- You can request access, correction, or deletion of cloud-linked information by contacting the privacy email above. Applicable law may provide additional rights.
Security
Commitment uses HTTPS transport encryption, Firebase authentication and security rules, server-side purchase verification, Google Secret Manager for the developer API credential, one-way hashing for stored purchase-token references, and Android Keystore for a personal API key. No security system is perfect. Do not place passwords, financial credentials, medical records, or other highly sensitive secrets in tasks or Coach messages.
Children
Commitment is a general productivity app and is not directed to children under 13 or the higher minimum age required in their country. We do not knowingly collect personal information from children below that age. A parent or guardian who believes a child has provided personal information may contact us to request its deletion.
International processing
Service providers may process information in countries other than your own. Those countries may have different data-protection laws. We use established providers and appropriate security measures for such processing.
Changes to this policy
We may update this policy when the app, providers, or legal requirements change. The updated version will be published at this address with a revised effective date. Additional notice or consent will be provided when required.
Contact
Questions, privacy requests, or complaints can be sent to mmm.mor6164198@gmail.com.
Request account or data deletion ยท Commitment Premium terms