Privacy Policy — Reset
Last updated: 14 August 2026
Applies to: the Reset mobile app for Android, version 1.0.0 and later.
---
The short version
- There is no account. No sign-up, no email, no password, no profile.
- There are no ads, no analytics, no crash reporting, and no third-party tracking SDKs.
- Everything you write — journal entries, sealed goals, tags, notes — stays on your phone. It is never uploaded, and there is no sync or cloud backup.
- The app sends one kind of message to a server: an anonymous "somebody, somewhere, finished something" ping that draws the Global Map. It carries no identifier and none of your writing.
- The location on that map comes from your phone's time zone setting, not from GPS. Reset never asks for location permission, because it does not need one.
- You can erase everything Reset holds by deleting the app.
The rest of this document is the detail behind those six lines.
---
1. Who is responsible
Reset is published by Magzumov Jasur Rustamovich, Uzbekistan, Tashkent, Uchtepa district, 100151.
For any question about this policy or your data: reset.app.feedback@gmail.com
---
2. What Reset does not do
Stated explicitly, because most of this policy is about absence:
- No user accounts, logins, or identifiers of any kind.
- No advertising, ad networks, or advertising IDs (no GAID, no IDFA).
- No analytics or telemetry SDKs (no Firebase Analytics, Google Analytics, Amplitude, Mixpanel, or similar).
- No crash- or performance-reporting service.
- No cookies or web trackers.
- No push notification service and no push tokens. Reminders are scheduled locally by your own phone.
- No location permission, no GPS, no Wi-Fi or Bluetooth scanning.
- No access to your microphone, camera, photos, contacts, calendar, files, or clipboard.
- No sale or sharing of personal information, in any sense, to anyone.
- No over-the-air update service, so the app makes no runtime connection to its build tooling.
- No profiling and no automated decision-making.
---
3. What is stored on your device, and only on your device
The following never leaves your phone. It is written to storage that is private to the app and is not transmitted, synced, or backed up to us.
| What | Where it is kept | What it actually contains |
|---|---|---|
| Journal entries | App-private storage | The time you logged it, an intensity value from 1 to 10, any tags you selected (stored as neutral keys such as `fatigue`, not as sentences), and your free-text note. Up to 1,000 entries; the oldest fall off the end. |
| Sealed goals — the words | Encrypted store (Android Keystore) | Your goal in your own words, your two-minute step, and which commitments you ticked. |
| Sealed goals — the index | App-private storage | When each goal was sealed, when its reminder is set for, how many commitments it has, and the OS handle for its reminder. None of your words. |
| Dopamine Bridge | App-private storage | The IDs of cards you have recently been shown, and how many things you finished today. |
| Streak | App-private storage | The date of your most recent active day and how many days in a row it ends. Not *what* you did on those days. |
| Language | App-private storage | Your chosen interface language, if you have picked one. |
| Map preference | App-private storage | Whether your phone can draw the 3D globe, so it is not asked to fail twice. |
How to delete it. Individual sealed goals can be released from inside the app, which also cancels their reminder. Everything else goes when you clear the app's data in your phone's settings, or uninstall Reset. There is no copy anywhere else for us to delete, because we never had one.
A note on backups. Sealed goal text is deliberately marked as *this device only*, so it does not ride an encrypted phone backup onto a new device. Depending on your OS settings, other app data may be included in a device backup made by Google — that backup is between you and Google, and we have no access to it.
---
4. The Global Map — the only thing that leaves your phone
Reset has a Global Map showing that other people are using it right now. That feature, and nothing else, involves a server.
What is sent
When you finish something, the app sends a single database row containing exactly:
- an event type — one of `reset_completed`, `goal_sealed`, `dopamine_bridge_completed`, or `map_opened`, and nothing else; and
- a latitude and longitude.
That is the entire payload.
Where the coordinates come from
They are derived from your device's time zone setting, looked up in a built-in table of time-zone cities. No location permission is requested, held, or needed. The resulting accuracy is roughly a thousand kilometres — a region, not a place — and this is deliberate, not a limitation waiting to be improved. A small random scatter (under one degree) is added before sending, so that many people in one time zone do not stack into a single blinking pixel.
What is *not* sent
No name, no email, no account, no device identifier, no advertising ID, no push token, no IP-derived location, no timestamp of your choosing — and nothing at all from your journal, your goals, your bridge cards, or your streak.
There is an event type in the code for saving a journal entry. It is deliberately never sent. The journal screen promises, in every language the app speaks, that what you write stays on your phone, and putting a packet on the wire at the moment you press Log would be close enough to breaking that promise that the promise would have to change first.
What the server keeps
Each row holds the event type, the two coordinates, a random row ID, and the server's own arrival time. There is no column that could tie two rows to the same phone, and the app stores no identifier that would make them tie-able. Rows are written through an anonymous role with no session; nothing session-shaped is written to your device.
What the app reads back
To draw the map, the app requests recent events and a count for the last hour, and listens for new ones over a live connection. It also makes one lightweight request per launch to read the server's clock, which corrects for phones whose date is wrong. That request carries no data in either direction beyond the headers.
About IP addresses
Any request to any server on the internet necessarily reveals your device's IP address to that server and its hosting provider. Reset does not put your IP in the events table, does not read it, and does not link it to your event. Our hosting provider may log connection metadata, including IP addresses, transiently for security, abuse prevention, and operational purposes, under its own privacy policy (see section 7).
Rate limits
Opening the map is throttled to at most one ping every four minutes, because navigating to a screen is not an accomplishment. The other three events are sent when the thing actually happens.
Turning it off
There is currently no in-app switch for the Global Map ping. The app is fully functional offline: if you deny it network access — airplane mode, or your OS's per-app data setting — every feature except the Global Map continues to work exactly as before, and nothing is queued to be sent later.
---
5. Feedback by email
The "Send Feedback & Report Bugs" card opens a draft in whatever mail app you already use. It does not send anything. The draft is pre-filled with:
- the app version,
- your platform and OS/SDK version,
- your device name as your phone reports it,
- your active app language.
Nothing else. No journal entry, goal, tag, note, streak, or bridge card is ever included.
The draft sits under your control until you press send, and you can edit or delete any part of it first. If you do send it, we receive your email address and whatever you wrote, and we keep it for as long as it takes to deal with the report. Please do not include information in it that you would rather we did not have.
---
6. Permissions, and why each one exists
| Permission | Required? | What it is for |
|---|---|---|
| Notifications | Optional | One local reminder for each goal you seal, scheduled by your own phone's alarm scheduler. There is no push service and no token. If you refuse it, your goal is still sealed — the app tells you plainly that there will be no reminder rather than pretending otherwise. |
| Biometrics / device passcode | Optional | To unlock a sealed goal. The check is performed by the operating system; Reset receives only a yes or no, and never your fingerprint, face data, or passcode. If your phone has no screen lock, the app says so rather than implying a lock that is not there. |
| Audio playback | — | Playing the optional ambient sound, which is a file shipped inside the app. Recording is explicitly disabled in the app's configuration. |
| Internet | — | The Global Map, described in section 4. Nothing else uses it. |
Reset does not request location, microphone, camera, photos, contacts, calendar, or file access.
---
7. Service providers
- Supabase hosts the anonymous events database described in section 4, in the ap-southeast-2 (Oceania, Sydney) region. See <https://supabase.com/privacy>.
- Google Play distributes the app and independently collects its own data about downloads, purchases, and (where you have opted in at the OS level) crashes. That collection is governed by Google's privacy policy, not this one.
There are no other processors. No data is sold, shared, rented, or transferred to advertisers or data brokers.
---
8. Legal bases for processing (GDPR / UK GDPR)
For people in the European Economic Area or the United Kingdom:
- Everything in section 3 is processed solely on your own device and is never received by us. There is no controller-side processing to assign a basis to.
- The Global Map events (section 4) are, in our assessment, not personal data in our hands: they carry no identifier, no session, and only region-level coordinates, and cannot be attributed to an individual by us or by anyone with access to the table. To the extent this assessment does not hold in a given case, the basis is our legitimate interest (Art. 6(1)(f)) in operating a feature whose entire purpose is to show that other people are present, balanced against a payload built to carry as little as it possibly can.
- Connection metadata processed transiently by our host for security and abuse prevention rests on our legitimate interest in keeping the service available and unabused.
- Feedback email (section 5) is processed on the basis of your consent, given by choosing to press send, and to take steps at your request.
---
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal data, and to complain to your local data protection authority.
Two honest observations about how those rights apply here:
1. For everything in section 3, you already hold all of them directly. The data is on your device, in your possession. You can read it in the app, change it, and delete it without asking us — because we cannot reach it.
2. For the Global Map events, we cannot fulfil an individual request, and this is by design. The rows contain nothing that could identify which of them are yours. We cannot find them, export them, or delete them selectively, because there is no key to match them on. This is the same property that makes the feature anonymous in the first place. We would rather explain this plainly than build the identifier that would let us honour the request.
If you are in California, note that we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for data.
To ask anything about the above: reset.app.feedback@gmail.com
---
10. Children
Reset is not directed to children under 13 (or under 16 in the EEA, where local law sets that age), and we do not knowingly collect personal information from them. The app has no account system and collects no identifiers, so there is nothing to delete on request — but if you believe a child has sent us something through the feedback address, write to us and we will remove it.
---
11. Security
- Sealed goal text is encrypted with a key held in hardware-backed storage — the Android Keystore. The key never enters the app's JavaScript, is not derived from anything the app knows, and cannot be read from a backup or from a copied data directory. Values are stored as *this device only*.
- All other on-device data lives in the app's private storage, protected by the operating system's app sandbox and by your device's own encryption. It is not separately encrypted by Reset. A device without a screen lock, or one that has been rooted or jailbroken, weakens these protections in ways no app can compensate for.
- Anything sent over the network travels over HTTPS/TLS.
No system is perfectly secure, and we do not claim otherwise. What we do claim is that the material worth protecting — the things you actually write — is never on the wire to begin with.
---
12. Data retention
- On your device: until you delete it. The journal keeps up to 1,000 entries and then drops the oldest.
- Global Map events: retained for 24 hours, after which they are deleted. The map itself only ever reads the last hour; older rows serve no purpose in the app.
- Feedback emails: kept for as long as needed to answer and to fix what they report.
---
13. International transfers
The Global Map database is hosted in ap-southeast-2 (Oceania, Sydney). If you use Reset from outside that region, the anonymous event described in section 4 crosses a border on its way there.
---
14. Changes to this policy
If this policy changes in a way that affects what leaves your device, the "Last updated" date at the top will change and the new version will be published at https://doc-hosting.flycricket.io/reset-s-privacy-policy/74b0ba32-b66e-4815-9ca4-b31c842314fb/privacy before the change takes effect in a released version of the app. Continuing to use Reset after that means the new version applies.
---
15. Contact
reset.app.feedback@gmail.com
Reset is a small app built on the premise that somebody at three in the morning should be able to type the word "shame" into it without wondering where that word goes. If anything in this document reads as though it contradicts that, tell us — we would treat it as a bug.