itsme — Privacy Policy

Last updated: June 1, 2026

This Privacy Policy explains what information itsme ("the app", "we", "us") collects, how it's used, who it's shared with, and the choices you have. It's written to be clear and plain. If anything is confusing, email tobypenk@gmail.com and we'll explain.

1. Who we are

itsme is a personal identity-verification app for family and trusted-circle use. It is operated as a sole-proprietorship by the developer, contactable at tobypenk@gmail.com.

itsme is currently offered only in the United States.

2. What we collect

To create your account:

Optional, only if you provide it:

Generated through use:

Subscription information (if you upgrade):

Anonymous diagnostics:

What we do NOT collect:

3. How we use it

We use what we collect only to operate the service — sending you OTP codes, showing you your circle's daily phrase, delivering push notifications to the people you ask, and recording your verification history so you can look back on it.

We do not profile you or use your data for any purpose unrelated to the app's core function.

4. Sub-processors

itsme relies on third-party services to operate. They have access only to what they need:

ProviderUsed forWhere the data lives
Supabase (US)Database, auth, storage, edge functionsUnited States
Twilio (US)SMS one-time codes for sign-inUnited States
Expo / Apple PushDelivering push notificationsUnited States
RevenueCat (US)Subscription management for Apple In-App PurchasesUnited States
AppleApp distribution, in-app purchase processingUnited States
Sentry (US)Crash reporting and error diagnostics. PII disabled — we send error stack traces and a hashed user ID, never your name, phone number, or content.United States
PostHog (US)Anonymous product analytics. IP-address collection and session recording disabled. We send event names and a hashed user ID, never your name, phone number, photo, or circle content.United States

5. How long we keep it

We keep your data for as long as your account is active. If you delete your account (Settings → Privacy → Delete my account), we permanently remove:

This is irreversible and happens within 30 days at the latest; most deletions are immediate.

Verification events where you were the recipient (not initiator) may be retained on the initiator's account history; we do not delete other users' history when you leave.

6. Your rights

Regardless of where you live, you have the following rights in itsme:

If you live in California, you have additional rights under CCPA, including the right to know what we collect and not be discriminated against for exercising your rights. The exports and deletion flows above satisfy these.

7. Children

itsme is intended for users 13 and older. We do not knowingly collect information from anyone under 13. If you believe a child under 13 has created an account, email tobypenk@gmail.com and we will delete it.

8. Security

We use TLS in transit for all network traffic. Database access is restricted via Row-Level Security so users can only read and write data within their own circles. Auth tokens are stored in the device's secure keychain. No security is perfect, but we keep what we collect minimal so there is less to expose.

9. Changes

If we change this policy, we will update the "Last updated" date and notify active users in-app at next sign-in. Material changes will be announced more prominently.

10. Contact

Email tobypenk@gmail.com for any privacy question, including data access, correction, deletion, or complaint.