Privacy Policy

Effective date: 16 June 2026

Patto ("we", "us", "our") operates the Patto mobile application and web app (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

1. Information We Collect

Account information. When you sign up or sign in, we collect your email address. We use email magic links for authentication — no password is required. You may optionally provide a display name during onboarding.

Profile information. You may optionally add a bio and upload a profile photo. We generate a unique username for you automatically.

User-generated content. This includes communities you create, habit check-in posts, photo uploads attached to check-ins, comments, and emoji reactions.

Usage data. We store habit completion logs (which habit, which community, and the date) to calculate streaks and community insights. We do not use third-party analytics or ad-tracking services.

Notifications. We store in-app notification records (e.g., when someone reacts to your post or joins your community) so you can view your activity feed.

Device tokens. If you enable push notifications, we store a device token to deliver notifications to your device via Apple Push Notification service (APNs) and Firebase Cloud Messaging.

Phone number (optional). If you choose to add a phone number — either during onboarding or later from Settings — we store it on your user profile so other users who already have your number in their contacts can find you on Patto. You can edit, remove, or hide your number at any time from Settings. Phone entry is entirely optional and you can use Patto fully without ever providing one.

Find Friends from Contacts (iOS, optional). When you tap "Find Friends from Contacts" we ask iOS for permission to read your address book on your device. We use those contacts only to compute one-way fingerprints (SHA-256 hashes) of phone numbers and send only those fingerprints — never names, emails, or raw numbers — to our backend to check which of your contacts already have a Patto account. We do not retain your contacts or those fingerprints on our servers after the lookup completes. You can revoke contacts access at any time from iOS Settings.

Apple Health data (optional). If you choose to attach activity to a check-in and grant permission, Patto reads selected data from Apple Health — workouts (including heart rate and, for outdoor workouts, your route), steps, sleep and wake times, time spent in daylight, and stand activity. We use this data only to display the activity on the check-ins you choose to post to your communities, and we store it on that post in your account. For outdoor workouts, the route is rendered into a map image on your device; we store only that map image and a set of points projected onto it — your raw GPS coordinates are never stored or transmitted. You grant access per data type through Apple's Health permission screen and can revoke it at any time in iOS Settings → Privacy & Security → Health. We never use Apple Health data for any purpose other than showing your own check-ins, never sell or share it with third parties, and never use it for advertising.

2. Information We Do Not Collect

3. How We Use Your Information

4. How Your Information Is Shared

With other users. Patto is a social accountability app. Your display name, username, avatar, and check-in posts are visible to other authenticated users. Communities you join and your habit completions are visible to members of those communities.

With service providers. We use Google Firebase (Cloud Firestore, Firebase Authentication, Cloud Storage, and Cloud Messaging) to operate the Service. Firebase processes your data on our behalf under Google Cloud's terms of service and data processing agreements.

Subscription payments. If you subscribe to Patto Pro, your purchase is processed by Apple via the App Store. We use RevenueCat to manage subscription status. RevenueCat receives your anonymised app user ID and subscription events. No payment card details are ever shared with us. RevenueCat's privacy policy is available at revenuecat.com/privacy.

We do not sell your data. We do not share your personal information with advertisers, data brokers, or any third parties for marketing purposes.

5. Data Storage and Security

Your data is stored on Google Firebase infrastructure. Firestore security rules restrict access so that users can only modify their own data. Authentication tokens are managed by Firebase Auth. All data is transmitted over HTTPS/TLS.

6. Data Retention

We retain your data for as long as your account is active. When you delete your account through the app, we permanently delete your user profile, all posts you created, your daily logs, and your community memberships. This deletion is immediate and irreversible.

7. Your Rights

8. Children's Privacy

Patto is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy within the app. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy, contact us at hello@pattosocial.com.