Skip to main content
DoYourBestie
HomeFeaturesSupport Download Now

Privacy Policy

Privacy Policy

Last updated: July 22, 2026

DoYourBestie is a daily accountability app for small groups. This policy explains what information we collect, why we collect it, how we use service providers such as PostHog, Apple Push Notification service, and infrastructure providers, what choices and rights you have, and how we handle data security and breaches.

1. Who We Are

DoYourBestie is operated by Marshall Matters Ventures Pte. Ltd., a Singapore company with UEN 202603347K. Our registered address is 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051. In this policy, "DoYourBestie", "we", "us", and "our" refer to Marshall Matters Ventures Pte. Ltd.. "You" refers to anyone who visits our website, uses our app, joins a challenge, contacts support, or otherwise interacts with our services.

For privacy questions or to exercise your rights, you can contact us at .

2. What This Policy Covers

This policy applies to the DoYourBestie iOS app, the website at doyourbestie.com, the backend API at api.doyourbestie.com, support communications, notifications, and product analytics used to understand and improve the service.

This policy does not cover third-party websites, app stores, device platforms, or services that we do not control. Those third parties may have their own privacy policies.

3. Information You Provide

We collect information you choose to provide when you use the app or contact us. This may include your display name, optional email address, challenge title, challenge rule, challenge duration, start date, invite code activity, check-in status, check-in notes if you add them, challenge membership, profile settings, support messages, screenshots you send to support, and any other details you choose to include in a message to us.

If you create or join a challenge with other people, some of your challenge activity is meant to be visible to the group. For example, other members may see your display name, whether you joined, whether you kept or missed a day, and relevant challenge activity such as streak milestones.

4. Account and Authentication Information

The app uses an authentication token so your device can access your account and challenge data. The token is stored on your device using the iOS Keychain. The backend stores a corresponding token so authenticated requests can be matched to your user record.

The app may also create a stable distinct identifier using iCloud key-value storage and local device storage. This identifier helps keep analytics and product behavior consistent across reinstallations and across your Apple devices where iCloud syncing is available. The identifier is not intended to be your name, email address, or other directly identifying personal information.

5. Challenge and Check-In Data

To run daily accountability challenges, we process challenge data such as challenge title, rule, duration, start date, owner, invite code, members, check-ins, missed days, kept days, activity events, and completion-related status. This information is required for the core service because the app needs to show the shared challenge state to everyone in the challenge.

Challenge invite codes are designed for sharing. Anyone with a valid invite code may be able to join the relevant challenge, so you should share codes only with people you want in the group.

6. Push Notifications

If you allow notifications, the app may register an Apple Push Notification service device token with our backend. We use that token to send notifications you have enabled or that are part of the challenge experience, such as join activity, check-in reminders, or streak milestones. The backend may store the device token, platform, locale, creation time, and update time.

You can control notification permissions in iOS Settings. If you turn notifications off at the operating system level, we may still keep a historical token until it is replaced, removed, or no longer useful.

7. Product Analytics

We use product analytics to understand whether the app is working, where people get stuck, which features are used, and how to improve onboarding, challenge creation, joining, check-ins, retention, and reliability. This may include analytics through PostHog and similar product analytics tools.

Analytics events may include information such as a distinct identifier, app version, device and operating system details, approximate timestamps, screen or feature names, button and flow events, challenge workflow events, notification permission state, error states, and other usage information. We do not need analytics to include the full text of your private challenge rule or support messages, and analytics should be configured to avoid collecting sensitive free-text content where possible.

PostHog and similar providers may process analytics data on our behalf to provide dashboards, funnels, retention analysis, feature usage reports, and debugging views. We use this information to make product decisions, identify broken flows, reduce friction, and decide what to improve next.

8. Website Analytics and Logs

When you visit doyourbestie.com, our hosting and delivery providers may process technical information such as IP address, request time, requested URL, referrer, browser, device information, response status, and error logs. We use this information to serve the website, secure it, troubleshoot problems, understand traffic patterns, and prevent abuse.

Our website is hosted through AWS services such as Amazon S3, Amazon CloudFront, AWS Certificate Manager, and Route53. These services may process request metadata as part of delivery, security, logging, and infrastructure operations. The website does not set advertising cookies and does not embed third-party advertising or cross-site tracking pixels.

9. Device and Technical Information

When you use the app, we may process technical information needed to operate and debug the service. This may include device type, operating system version, app version, locale, network request metadata, API error information, timestamps, and diagnostic information. Server logs may include IP addresses, request paths, response codes, and error details.

We use technical information to keep the app available, investigate bugs, improve performance, prevent abuse, and understand whether new releases are working as expected.

10. Support Communications

If you email us or otherwise contact support, we collect the information you send. This may include your email address, name, screenshots, device details, app version, description of the issue, and any other information in the message. We use support information to respond, troubleshoot, improve the product, and keep records of support issues.

11. How We Use Information

We use information to provide the service, create accounts, authenticate requests, create and join challenges, sync shared challenge status, record check-ins, display group activity, maintain challenge history, send requested or relevant notifications, respond to support requests, analyze product usage, debug problems, prevent abuse, enforce our terms, comply with legal obligations, and protect our rights and users.

12. Legal Bases for Processing

Depending on where you live, we may rely on different legal bases for processing personal information. For users in the European Economic Area and the United Kingdom, the bases we rely on under the GDPR map to our processing as follows:

  • Performance of a contract (Article 6(1)(b)): creating your account, authenticating requests, running challenges, syncing shared challenge status, recording check-ins, and maintaining challenge history — the core service you signed up for.
  • Legitimate interests (Article 6(1)(f)): product and website analytics, debugging, security, abuse prevention, and improving the service. Where we rely on legitimate interests, we balance them against your rights and you can object (see Your Privacy Rights).
  • Consent (Article 6(1)(a)): push notifications you enable. You can withdraw consent at any time, for example by disabling notifications in iOS Settings.
  • Legal obligation (Article 6(1)(c)): retaining records we are required to keep and responding to lawful requests.

Outside the EEA/UK, we rely on equivalent bases under applicable law, including consent and our legitimate interests in operating and improving the service, and steps taken at your request before or during a contract.

13. What We Don't Do

  • We do not sell your personal information.
  • We do not use Apple's advertising identifier (IDFA) or any third-party advertising or ad-tracking SDK.
  • We do not show you advertising inside the app, and we do not build advertising or behavioral profiles of you.
  • We do not track you across other companies' apps or websites, and we do not combine your data with data from other companies for advertising.
  • We do not share your information with advertising networks or data brokers.

We share information only with the service providers needed to run the app and website (see Service Providers), with other members of a challenge you join (see below), and where required by law.

14. Sharing Information With Other Challenge Members

DoYourBestie is built for shared accountability. If you participate in a challenge, certain information is shared with other members of that challenge. This can include your display name, whether you joined, check-in status, missed and kept days, activity events, and challenge progress. Do not join a challenge or enter information if you are not comfortable with relevant challenge members seeing it.

15. Service Providers

We may share information with service providers that help us run the app and website. These may include hosting providers, infrastructure providers, analytics providers such as PostHog, Apple services such as APNs and App Store related services, email or support tooling, security and diagnostics providers, and professional advisers.

Service providers are expected to process information only as needed to provide services to us, comply with law, protect their systems, and meet their own legal obligations.

16. Business and Legal Disclosures

We may disclose information if required by law, subpoena, court order, regulator request, or other legal process. We may also disclose information to protect our rights, enforce our terms, investigate abuse or security issues, prevent harm, or respond to claims.

If we are involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred or disclosed as part of that transaction, subject to appropriate confidentiality or legal protections where applicable.

17. International Transfers

We are based in Singapore, and our service providers may process information in Singapore, the United States, the European Economic Area, the United Kingdom, Australia, or other locations where they or their subprocessors operate. Our website and API infrastructure is hosted on Amazon Web Services in the US East (N. Virginia, us-east-1) region. Product analytics are processed by PostHog.

Where personal data of EEA, UK, or other protected users is transferred outside their region, we rely on appropriate safeguards such as Standard Contractual Clauses incorporated into our agreements with providers like AWS and PostHog, in accordance with GDPR Chapter V. By using the service, you understand that information may be processed outside your country of residence.

18. Retention

We keep information for as long as reasonably needed to provide the service, maintain challenge history, comply with legal obligations, resolve disputes, enforce agreements, preserve security, and improve the product. Retention periods vary depending on the type of data and why we keep it.

Challenge records may remain while the challenge or account is active, and for a reasonable period afterward for backup, dispute, legal, security, or operational reasons. Server logs and analytics records may be retained for a shorter or aggregated period depending on system configuration and operational needs.

19. Your Privacy Rights

Subject to applicable law, you have rights over the personal information we hold about you. To exercise any of these rights, contact us at . We may need to verify your identity before completing a request, and some information may be retained where we have a legal, security, fraud-prevention, dispute, accounting, or backup reason (see Retention and Deletion).

Under Singapore PDPA

You may request access to, and correction of, the personal data we hold about you, and you may withdraw consent for processing that relies on consent. We will respond in accordance with the Personal Data Protection Act 2012.

Under EU/UK GDPR

If you are in the European Economic Area or the United Kingdom, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, as well as the right to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

Under CCPA/CPRA (California)

We do not sell or share your personal information as those terms are defined under California law. California residents may request to know the categories and specific pieces of personal information we hold, request deletion, and exercise these rights without discriminatory treatment.

20. Deletion and Account Requests

You can delete your account and its data directly in the app: open the Profile tab, tap "Delete everything", then confirm "Delete my account for good". The app deletes your account on our servers first and then clears the data stored on your device. The same screen also offers a lighter option that signs you out and clears only the data on that phone while keeping the account.

If you purchased a Pro subscription, a limited purchase record survives account deletion: the Apple transaction identifier, the app account token, the product identifier, the subscription status, the App Store environment, the expiry date, and the deletion time. It contains no name, email address, or other account details. We keep this record so that the same Apple purchaser can restore their subscription onto a new account; it is removed when the purchase is bound to a new account, and otherwise retained (there is currently no automatic purge), alongside the legal, fraud-prevention, and accounting reasons described in Retention.

You may also contact us to request access, correction, export, or deletion of personal information where applicable. We may need to verify your identity before completing a request. Some information may not be deleted immediately if we need it for legal, security, fraud prevention, dispute, accounting, or backup reasons.

Because challenges involve multiple people, deleting your information may not remove all challenge records visible to other members if those records are needed to preserve the integrity of shared challenge history. Where appropriate, we may delete, anonymize, or limit information instead of deleting an entire shared record.

21. Data Breach Notification

If a data breach affects your personal information, we will notify the relevant authorities and affected users in accordance with applicable law.

  • Under the GDPR, we will notify the competent supervisory authority within 72 hours of becoming aware of a qualifying breach.
  • Under Singapore's PDPA, we will comply with the mandatory breach notification requirements under the Personal Data Protection (Notification of Data Breaches) Regulations 2021.

We will notify affected users without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

22. Security

We use reasonable technical and organizational measures designed to protect information. These may include HTTPS, authentication tokens, iOS Keychain storage for app tokens, restricted production configuration, database access controls, provider security controls, and operational practices intended to reduce unauthorized access.

No system is perfectly secure. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.

23. Children

DoYourBestie is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us and we will take appropriate steps.

24. Health, Fitness, and Personal Challenge Content

Users may create challenges related to health, habits, fitness, sleep, alcohol, sugar, phone use, routines, or other personal goals. The app is an accountability tool. It does not provide medical, fitness, mental health, financial, legal, or professional advice. You should avoid entering sensitive information unless you are comfortable storing it in the app and sharing relevant challenge activity with your chosen group.

25. App Store and Platform Providers

If you download DoYourBestie from the Apple App Store, Apple may process information related to your download, device, account, crash reports, and app usage according to Apple's own policies. We do not control Apple's processing.

If you purchase a DoYourBestie Pro subscription, the payment is processed by Apple through your Apple Account, and we do not receive or store your payment card details. To provide Pro features, our backend stores subscription records linked to your account: the Apple transaction identifier for the purchase, an app account token used to bind the purchase to your account, the product identifier, the subscription status, the App Store environment, the expiry date, the time we last verified the subscription with Apple, record timestamps, and the most recent decoded transaction and renewal details from Apple's signed purchase information.

26. Do Not Track and Similar Signals

Some browsers or devices offer "Do Not Track" or similar signals. There is no consistent industry standard for how these signals should be interpreted, so our website and app may not respond to them. Where legally required, we will honor applicable privacy choices through the mechanisms required in that jurisdiction.

27. Changes to This Policy

We may update this policy from time to time. If we make material changes, we may notify you through the app, website, email, or another reasonable method. The "Last updated" date shows when this policy was last revised.

28. Contact

If you have questions, requests, or complaints about this policy or our privacy practices, contact us at .

Marshall Matters Ventures Pte. Ltd.
UEN: 202603347K
60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051

DoYourBestie

Keep promises with your people.

Women: want to lose weight and feel better? FastingBestie syncs fasting to your cycle.

FeaturesSupportPrivacyTerms

© 2026 Marshall Matters Ventures Pte. Ltd.

UEN: 202603347K

60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051