yoink
Privacy Policy
Last updated: 23 August 2026
This Privacy Policy explains how Yoink ("Yoink", "we", "us", or "our"), operated by
Devesh Duptala, an individual based in New Zealand, collects, uses,
and protects your information when you use the Yoink mobile app (the "App"). We are the data controller
for the purposes of applicable privacy law, including the New Zealand Privacy Act 2020, the EU/UK GDPR
(where it applies), and the California Consumer Privacy Act (CCPA, where it applies).
By using Yoink you agree to this Policy. If you do not agree, please don't use the App.
1. Who can use Yoink (age)
Yoink is intended for users aged 13 and over. During setup we ask for an optional
age band (a range, never a date of birth), see Section 2a. It is not directed to children under
13, and we do not knowingly collect personal information from anyone under 13. If you believe a child
under 13 has provided us personal information, contact us at support@yoinktime.com
and we will delete it.
2. Information we collect
a) Information you provide
- Phone number: used only to sign you in, via a one-time code
sent by SMS. It is held by our sign-in provider and is not stored in the main app
database or shared with your squad.
- Display name and handle: the name you choose at sign-up and an auto-generated
handle, shown to your squad.
- Onboarding answers: three optional, skippable questions asked during setup:
your age band (a range such as "18 to 24", never a date of birth),
what you have tried before to cut your screen time, and how you heard about
Yoink. Stored against your account and used for product analytics. They are
never shown to your squad, and skipping any of them is supported.
- Your own screen-time estimate: the rough daily figure you set on the slider
during setup. This is a number you tell us; it is not read from your device.
b) Information created as you play
- Group / squad data: your squad, shared screen-time "pool" balances, in-game
events (earns, yoinks, joins, kudos), in-game coins, subscription/trial status, and, if your squad runs a Strict Mode round, a record of
whether you opted in and until when (see the Terms for what Strict Mode does).
- Daily step totals: a per-day step count that powers in-game earning.
c) Health & fitness data (HealthKit)
With your permission, Yoink reads step count and workout data
(type, duration, start/end time) from Apple Health to let you earn screen-time minutes. See the
dedicated HealthKit section below.
d) Location data
With your permission, when you tap to check in at an "Explore" spot, Yoink reads your precise
device location once and sends those coordinates to our backend to verify your distance from
that spot. The coordinates are used for that request and are not stored in the check-in record; the
verified distance may be stored. We do not track location in the background or keep a
location history.
e) Camera and motion (processed on your device only)
- Camera: used to verify certain real-world earn actions, such as going outside. The camera feed is
analysed on your device for simple signals (colour/brightness, on-device body-pose
to count push-ups). No photos, video, or images are uploaded, stored, or sent anywhere.
- Motion & pedometer: live step counts from the device's motion sensor are
used on-device to track activity during the game.
f) Device & technical data
- Notification ID: if you turn notifications on, we store the identifier Apple
gives us for your device so we can send game alerts.
- Analytics events: see Section 4.
g) Screen Time & app blocking (Apple Family Controls)
Yoink's core game blocks the apps you choose using Apple's Family Controls / Screen Time
frameworks (FamilyControls and ManagedSettings). This matters for your privacy:
- When you pick apps to block, Apple does not tell Yoink which apps they are. We never see their
names or icons. Any name shown in the app is a label you type yourself.
- Your app selections and their locked or unlocked state stay only on your device.
They are never uploaded to our servers, never shared with your squad, and never sent to
analytics. When the squad feed shows an app was yoinked, it shows only
the label you chose (or "Mystery App" if you opted not to share the name).
- We use Screen Time solely to run the game (blocking and unlocking your chosen apps).
We do not use it for advertising, profiling, or any purpose beyond the game, and we do
not read your overall Screen Time usage reports.
- You can turn off app blocking any time in-app, and revoke Screen Time access in iOS Settings
→ Screen Time.
Payments are processed by Apple, with RevenueCat
used to manage subscription entitlements. We do not receive or store your card or payment
details. RevenueCat receives App Store purchase and subscription lifecycle information, and we store
subscription status, product, expiry, and an Apple transaction identifier needed to keep your Squad Pass
in sync. We do not collect
your contacts, photo library, advertising identifiers (IDFA), or use any cross-app/website tracking.
3. How we use your information
- To create and operate your account and squad, and run the screen-time game.
- To send push notifications about game activity (if enabled).
- To provide and manage subscriptions and the free trial.
- To understand product usage and improve the App (analytics, Section 4).
- To keep the service secure, prevent abuse (e.g. trial abuse), and comply with the law.
4. Analytics
We use PostHog and Sentry to understand product use and diagnose
errors. Product events (such as "onboarding_completed" or "group_created") and crash reports may be
linked to your internal, pseudonymous app user ID. We do not send your name, phone
number, blocked-app names, or message content to analytics. Analytics and error monitoring data are
processed on EU infrastructure. We do not use them for advertising or cross-app tracking.
5. HealthKit
- Yoink reads step and workout data from HealthKit only with your explicit permission,
solely to let you earn in-game screen-time minutes.
- We never use HealthKit data for advertising or marketing, and never
sell or share it with third parties.
- We store a simple daily step total to run the game; we do not store your detailed
health records on our servers.
- Revoke Health access any time in iOS Settings → Privacy & Security → Health → Yoink.
6. Who we share information with
We don't sell your personal information. We share it only with service providers who help us run
Yoink, under contract and only as needed:
- Apple: App Store, in-app purchases, and delivering notifications.
- Supabase: backend database and authentication.
- Twilio: sends the one-time sign-in codes by SMS.
- RevenueCat: subscription purchase and entitlement management.
- PostHog: product analytics (EU hosted), using a pseudonymous app user ID.
- Sentry: crash reporting and error monitoring (EU hosted).
We may also disclose information if required by law, to enforce our Terms, or to protect rights and
safety.
7. Where your data is processed (data residency)
Your account and game data are currently processed and stored in Australia (our
backend runs in the Supabase Sydney region). Analytics are processed in the EU. As our
infrastructure evolves, we may process data in other regions; if our primary region changes, we will
update this Policy. Data may be transferred internationally with appropriate safeguards under applicable
law.
8. How long we keep data
- Account data: kept while your account exists. Includes your onboarding answers, deleted with your account.
- In-game event feed: automatically pruned after 90 days.
- Trial records: so the free trial can only be used once per person, we keep a
scrambled version of your phone number in a trial list, and this survives account
deletion. It cannot be turned back into your number or used to contact you.
- When you delete your account, we delete your account and the personal data attached to it, apart
from records we have to keep for legal, security, or anti-abuse reasons, such as that trial record.
- Analytics and crash data: retained according to our configured provider settings
and contracts; you may request deletion of data linked to your account using the contact below.
9. Your choices and rights
- Delete your account in-app: Profile → Settings (gear icon) → Danger zone → Delete account.
- Permissions: grant or revoke Health, Location, Camera, Motion, and Notifications
any time in iOS Settings.
- Depending on where you live, you may have rights to access, correct, delete, or port
your data, to object to or restrict processing, and to withdraw consent.
NZ users have rights under the Privacy Act 2020; EU/UK users under the GDPR; California users under the
CCPA, including the right not to be treated differently for exercising those rights (and we do
not sell personal information). To exercise a right, email
support@yoinktime.com.
- You may complain to your local regulator (in NZ, the Office of the Privacy Commissioner).
10. Security
We use industry-standard measures (encryption in transit via HTTPS, access controls, database-level
security rules) to protect your information. No method is 100% secure, but we work to protect your data.
11. Changes to this Policy
We may update this Policy from time to time. We will revise the "Last updated" date above and, for
material changes, provide notice in the App or by other reasonable means.
12. Contact
Questions or requests about privacy: support@yoinktime.com