Privacy Policy

Last updated: June 17, 2026

Borify ("we", "our", or "us") is a screen-time and digital-wellbeing app developed by day2day.app. This Privacy Policy explains what information we collect, how we use it, where it is stored, and your rights regarding your data when you use the Borify mobile application (the "App").

By creating an account and using Borify, you agree to the collection and use of information as described in this policy.

ℹ️ This document is a good-faith description of how the App handles data. It is not legal advice — we recommend a qualified legal professional reviews it before publication, especially for GDPR (EEA/UK) and CCPA (California) compliance.

1. Information We Collect

Account information. When you create an account we collect your email address, a display name, and your age (provided during onboarding). You may sign in with Google, in which case we receive your Google account name and email address.

Progress & gamification data. Your streak count, Borify Score, shields, vacation credits and scheduled vacation dates, daily check-in dates, your limit settings (session/Borify/block caps, screen-time goals), and the list of apps you choose to track are collected and synced to our servers so they survive reinstalls, work across the daily evaluation, and drive the accountability system.

Check-in (ritual) responses. The text of your daily check-in answers is stored only on your device (encrypted local storage). The date you checked in is synced to our servers to maintain your streak.

App usage data. Borify uses Android's Usage Access (UsageStats) to detect which tracked apps are in the foreground and for how long, so it can enforce the limits you set and apply the grayscale effect. Detailed moment-to-moment usage is processed on your device; the aggregate progress it produces (e.g. your streak/score) is synced as described above. We do not collect a browsing history of your activity inside other apps.

X / Twitter account & tokens. Borify's accountability system can post on your behalf to X (Twitter). When you connect your X account, your X handle and OAuth access/refresh tokens are encrypted and stored on our servers (not on your device), so our server can post on your behalf when triggered by the App's rules. You can disconnect X at any time, which removes these tokens.

Challenge partner. If you add a challenge partner, we store the name and X handle you provide. If your partner also uses Borify, we may send them a push notification when your streak breaks.

Push notification token. We store a Firebase Cloud Messaging (FCM) token for your device to deliver reminders and alerts.

Subscription data. Purchases are processed by Google Play. We do not receive or store your payment details. We receive your subscription status (active/trial/expired) from Google Play via RevenueCat.

Technical data. We store your account creation date and device time zone (to schedule reminders and accountability posts in your local evening), and an append-only score-event ledger used to detect and correct tampering.

2. Where Your Data Is Stored

Stored only on your device (encrypted local storage / MMKV) Stored on our servers (Firebase)
Daily check-in answer text
Detailed on-device usage timers / session state
Local copies of your settings
Email, display name, age, account creation date
Streak, Borify Score, shields, vacation credits & dates
Check-in dates, limit settings, tracked-app list
Challenge-partner name & handle, time zone
FCM push token, subscription status
X handle + encrypted OAuth tokens, score-event ledger

Some of our features run server-side via Firebase Cloud Functions even when the App is closed — for example, evaluating whether you completed your daily ritual and posting accountability updates. This requires the synced data above.

3. How We Use Your Information

We do not sell your personal data. We do not use your data for advertising or remarketing.

4. Device Permissions

Borify requests the following permissions, used solely for core functionality:

You can revoke any permission in your device settings; some features will stop working without them.

5. Data Storage & Security

On-device data is held in encrypted local storage (MMKV). Server-side data is stored in Firebase (operated by Google), and X OAuth tokens are encrypted at rest on our servers. We take reasonable technical measures to protect your information, but no method of transmission or storage is 100% secure.

6. Third-Party Services

Borify relies on the following third-party services, each with its own privacy policy:

7. Accountability Posts to X / Twitter

If you connect X, Borify will publicly post on your behalf when its accountability rules are triggered (for example, breaking your streak with no shields left, exceeding your screen-time goal, removing a tracked app, or repeatedly extending limits). These posts are visible to your followers and cannot be recalled once sent. You can stop all future posts at any time by disconnecting X in Profile settings. This feature is optional but is part of the core accountability design.

8. Children's Privacy

Borify is not directed at children under 13 (or the minimum age of digital consent in your country, where higher). We do not knowingly collect personal information from children under that age. If you believe a child has provided us with personal information, contact us and we will delete it promptly.

9. Your Rights

You have the right to:

If you are in the EEA/UK (GDPR) or California (CCPA), you may have additional rights, including data portability and the right to object to processing. To exercise any right, contact us at the email below.

Note: Deleting your Borify account does not cancel your Google Play subscription. Manage or cancel that separately in Google Play → Subscriptions.

10. Data Retention

Server-side data is retained until you delete your account, after which it is permanently removed from our systems. On-device data is removed when you delete your account, reset the app, or uninstall it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact Us

Questions or requests regarding this Privacy Policy:

Email: support@day2day.app