PACK

Privacy Policy

Last updated: August 29, 2026

Pack is a daily check-in app for small workout crews of up to seven friends. No email or password is required, and there is no advertising or tracking. The app automatically creates a private guest account so your group membership and check-ins can be protected and synchronized. This page explains exactly what we store and why.

What Pack collects

What Pack does not collect

Who can see your data

Only the up-to-seven members of your group can see each other's display names, daily check-ins, and group activity. This is enforced at the database level using row-level security policies, not just at the app level. There is no global feed, no public profile, no discovery surface, no leaderboard, and no way for a non-member to see anything about your group.

Where it's stored

Data is stored in a managed PostgreSQL database hosted by Supabase. All connections from the app to the database are encrypted (HTTPS and WSS). Supabase processes data on our behalf as a service provider; their privacy practices are described at supabase.com/privacy.

How long it's retained

Your guest account, active membership, and check-ins remain in the live service until you use the deletion controls described below. Leaving a group immediately deletes that membership and its check-ins from the live database. Deleting the account removes the guest Auth user and all data associated with its membership from the live database. We do not retain a separate analytics or advertising copy.

Supabase may retain encrypted database copies for a limited, plan-dependent disaster-recovery backup period. Backup copies are not available in the app or used for advertising or analytics, and they expire according to Supabase's backup schedule.

How to delete your data

To remove your membership and check-in history while keeping the private guest account available for a new group, open group settings and tap Leave Group. If you were the last member, the group is also deleted.

To delete the complete guest account and its associated data, open group settings and tap Delete Account & Data. If you are not in a group, use Delete Account at the bottom of the create-or-join screen. The app deletes the Supabase Auth user, membership, and check-ins from the live service. Groups with other members remain, without a link to the deleted creator account. The deletion cannot be undone in the app.

Uninstalling the app is not a substitute for account deletion. iOS may retain credentials in Keychain, and the server cannot detect that an app was uninstalled. Use the in-app deletion control before uninstalling if you want the guest account removed from the server.

Children's privacy

Pack is rated 4+ on the App Store and is not directed at children under 13. We do not knowingly collect data from children under 13. Because the app does not request a birth date or contact information, we have no way to confirm a user's age.

Changes to this policy

If we change this policy, we'll update the "Last updated" date above and ship the change in a new version of the app. Material changes — anything that affects how data is collected, used, or shared — will be highlighted in the app's release notes.

Contact

Questions or concerns: matt@algorithmicresearchgroup.com