im-ok — Privacy Policy
Last updated: 1 October 2026
1. Who we are
im-ok is an iPhone app. Its privacy policy, terms and support page are published on emilalm.app, Emil Alm's personal website (section 19). The app is called "i’m ok: check in. stay safe." on the App Store (in Swedish, "i’m ok: checka in, sköt om dig") and "i’m ok" on your home screen. It is offered only on the App Store in the United States and Sweden. Separately, an account needs a Swedish (+46) or US (+1) mobile number (terms section 4). The app and these pages are provided by Emil Alm, an individual based in Sweden ("we", "us", "our"). Our postal address is in section 23 of our terms. Emil Alm is the controller of your personal data under the EU General Data Protection Regulation (GDPR).
For questions about this policy or your data, and to use any of your rights, email support@im-ok.com. We have not appointed a data protection officer; this address reaches the person responsible.
2. Scope, and what im-ok is not
This policy covers the im-ok app from version 2.0 and the im-ok pages on emilalm.app: this policy, the terms and the support page (section 19). The rest of emilalm.app is Emil Alm's personal website and not part of im-ok. For im-ok 1.x, which stopped working before im-ok 2.0 was released, section 3 says what happened to your data. This policy explains what we collect, how and why, who receives it, how long we keep it, and what you can do about it. This policy is written in English. You can write to us in English or Swedish.
im-ok is not an emergency service. Nobody monitors your check-ins, neither we nor an alarm centre, and im-ok never calls, texts or alerts emergency services. It only notifies the friends you have added, and only after your check-in window has passed. A notification or a location can arrive late or not at all, and your friends may not see it or be able to help. If you or someone else is in danger, call the emergency number where you are: 112 in Sweden, 911 in the United States. 112 also works in every other EU country. Do not wait for a missed check-in or for your friends to be alerted.
We do not give your personal data to data brokers. The optional ad is how im-ok earns money: Google pays us for the ads it shows, and Google's software on your phone sends Google the data listed in section 4.7. If you allow tracking when im-ok asks (Apple's App Tracking Transparency prompt), that includes your phone's advertising identifier, which Google and its ad partners may use to personalise ads and measure them across apps. Some US state laws give "sale", "sharing" and "targeted advertising" their own meanings, which may cover what Google receives. To turn tracking off, see section 12. If you live in the United States, see section 13.1.
3. What changed in im-ok 2.0
im-ok 2.0 is a new app, built from scratch, with a new server.
3.1 Moving to im-ok 2.0
If you used im-ok before:
- Your account was copied. In early September 2026, before im-ok 2.0 was released, we copied everything then stored for your 1.x account to im-ok 2.0's server: your phone number and name, your friends and friend requests, your check-ins from the last 12 months, your alerts, your streak and bubbles, your bubble ledger, your settings, your last stored position, your phone's notification token, your queued notifications, the notification, delivery, location capture and security logs described in sections 4.2, 4.3, 4.6 and 4.9, and the records described in section 4.12. The server is our own Supabase project in Stockholm, Sweden. You sign in again with your phone number. Anything you did in 1.x after the copy was made did not carry over (section 3.2). So when im-ok 2.0 is released, you may count as missed, and a friend alerted about it receives your stored position, which can still be the one from the copy, until you check in or start a pause (section 5).
- Your profile photo did not come along. im-ok 2.0 has no profile photos: you pick an animal instead (section 4.1), and until you do, your friends see a grey person. Your photo was not copied with your account. The link to it and the log of your photo uploads came along in the copy, and we deleted them from it before im-ok 2.0 was released. The photo was deleted with Lovable Cloud (section 3.2), and the copies of a few photos that we made while testing the move have been deleted too. The export files we keep as a backup of the move still contain the link and the log, but not the photo (section 3.2).
- What 2.0 no longer does. 2.0 has no support mode ("not ok"), no premium, no market (heart skins, bubble packs), no gifts, no nicknames and no in-app map. It never turns support mode on, and it records no purchases, gifts or reactions, no nicknames and no count of the maps you load. A friend's location opens in Apple Maps instead.
- If support mode was on when your account was copied. The copy kept it on until our server turned it off by itself, 3 hours or more after you turned it on in 1.x. Until then, your friends' apps could receive the time you turned it on. im-ok 2.0 never turns support mode on.
- Nothing is sold. Premium and the bubble packs from 1.x were removed from sale on 1 October 2026, before im-ok 2.0 was released. A premium subscription you already have is not renewed. Premium worked in im-ok 1.x until the period you paid for ended or im-ok 1.x stopped working (section 3.2), whichever came first. Apple sold and billed those purchases; refunds are through Apple (reportaproblem.apple.com). Bubbles you bought in 1.x stay on your balance in 2.0.
- RevenueCat, which handled 1.x purchases, now measures the optional ad. It still records any App Store transaction of yours that it sees, such as a premium subscription from 1.x (section 4.7).
- Your location reaches friends only after a miss. im-ok 2.0's server sends your last known position to a friend's app only while that friend has an open alert about your missed check-in (section 5). Before 2.0, friends' apps received it at any time, and showed it after a miss or while support mode was on.
3.2 What happened to im-ok 1.x
im-ok 1.x ran on our previous server provider, Lovable Cloud, where the data may have been stored in, or reached from, countries outside the EU/EEA. It did more than im-ok 2.0: it sent your last stored position to your friends' apps at any time, and its support mode (a premium feature) refreshed your position about every 2 minutes, for up to 3 hours, and showed it to all your friends. It also had premium through RevenueCat, bubble gifts, heart skins, nicknames, a map from Apple's MapKit, fonts from Google Fonts and profile photos.
im-ok 1.x stopped working before im-ok 2.0 was released, when we removed Lovable Cloud. The data on Lovable Cloud was deleted with it, including profile photos and their upload log. Anything done in 1.x after the copy was made in early September 2026 (section 3.1), including any account created after it, did not carry over to im-ok 2.0. We keep the copy of your account (sections 3.1 and 4.12) and, as a backup of the move, export files of the 1.x database (section 10). They hold the 1.x database as it was when they were made, which can include what was done in 1.x after your account was copied, and the links to profile photos and their upload log, but not the photos themselves.
If you used im-ok 1.x and cannot use im-ok 2.0, for example because your iPhone cannot run iOS 26 or the App Store does not offer im-ok in your country or region, email us at support@im-ok.com. We will delete the copy of your account, so that your friends are no longer alerted that you missed a check-in, and your phone stops getting notifications from our server.
4. Data we collect
4.1 Account and profile
- Phone number. This is how you sign in: we send a one-time code by SMS through Twilio Verify, and there is no password. Emil Alm also uses your number to send you a personal text message, from his own phone, about important changes to im-ok, this policy or the terms (section 20). Our sign-in system also stores an internal placeholder address made from your number (…@phone.im-ok.com). We never send anything to it.
- Display name and animal (both required). Your animal is one of the app's own drawings: you pick it after your name when you set up im-ok 2.0, and you can change it on your profile. We store only which drawing you picked. im-ok 2.0 has no profile photos, and it does not use your camera or photo library.
- Check-in window: the daily six-hour window you choose, and when and how often you change it.
- Time zone, read from your phone, and when it last changed.
- App language, so notifications reach you in it.
- Permission states: whether you allowed notifications and location.
- Marketing SMS choice, and when you switched it on (section 18).
- An account ID that we create, and when your account was created.
- Sign-in sessions: for each phone you are signed in on, our sign-in system (Supabase Auth) stores the session with the IP address and the app and iOS version it was last renewed from. It also keeps an audit log of sign-ins, session refreshes and sign-outs, with your account ID and phone number, and a name if one is stored with your sign-in record. Section 10 says how long.
4.2 Check-ins, alerts and pauses
- Check-ins: when you tapped, when our server received it, what it earned and, if you doubled its reward with the optional ad (section 4.7), when. A check-in made offline is sent later with its original time, if it reaches us within 6 hours. Your colour (green, blue or red) is worked out from your check-ins, your window and your time zone.
- Alerts: when you miss a check-in, we record an alert for each of your friends: who missed, who was alerted, when, and when and how it was resolved. A notification log records which reminder or alert went out in which daily cycle, so nothing is sent twice.
- Pauses of up to 14 days: when a pause starts and ends, and your status when it started. Your friends are notified when you pause and when you are back.
- Streak and bubbles: your current and longest streak, your bubble balances, how many times you tap the heart, how many of your check-ins came after a miss, and a short ledger of bubble credits. Bubbles are points: in 2.0 they cannot be bought, sold or sent, and they have no money value.
4.3 Location
We collect location only if you allow location access in iOS. im-ok does not share your live location and keeps no location history: we store one most recent position with its time, and each new one replaces it.
A position is captured:
- when you open the app, at most every 30 minutes (every time, while your check-in is missed);
- if you choose "Always", when iOS tells the app that you have moved a significant distance, or arrived at or left a place. The app then takes one fresh reading and sends it;
- when you miss a check-in: our server sends your phone one silent notification asking for a fresh reading. When the app is not open, this usually only works with "Always".
We keep only readings accurate to about 100 metres or better and less than a minute old, and discard the others. For readings sent in the background, we log which trigger fired and whether the reading was accepted, without the coordinates, for 14 days.
Notifications never contain your location. Setting location to "Never" stops new captures, but it does not delete the position already stored. That position stays until you delete your account or ask us at support@im-ok.com to delete it, and until then a friend who is alerted about your missed check-in still receives it. If you turn location on again, the next capture replaces it. Section 5 explains who receives your position. For the position copied from im-ok 1.x, see section 3.1.
4.4 Friends and friend requests
- Friendships: who, and since when.
- Friend requests: who asked whom, when, and the answer. A request stays after it is answered, and is marked if the friendship is later removed. We use your recent requests to limit how many you can send.
- If you send a request to a number that has no im-ok account, nothing is stored.
- While a request is pending, both of you see each other's name, animal and phone number.
- Invitations to people who are not on im-ok are sent by you, from Messages or another app you choose in the share sheet. We don't see them.
4.5 Contacts
If you allow it, the app reads the names and phone numbers in your contacts, and nothing else. It keeps a copy on your phone, encrypted by iOS and removed when you delete your account, so the add-friend list opens quickly. Names never leave your phone. To find which contacts already use im-ok, only the phone numbers are sent to our server, in batches, and compared with existing accounts. The server returns the accounts that match, with their account IDs and display names, and stores none of the numbers. Searching the add-friend list happens on your phone.
This also works the other way. Anyone on im-ok who has your phone number can find out that you use im-ok and see your display name.
We store your friend list (section 4.4), but not your address book.
If you deny or revoke contacts access, you can still add friends by their number.
4.6 Your phone and notifications
- For each phone you use im-ok on, we store:
- its Apple push notification token;
- Apple's identifier for vendors, a device identifier Apple gives each app maker (not the advertising identifier);
- the app version, and when the app last reached us;
- a hashed device secret that proves a background location reading really comes from your phone.
- The identifier for vendors is also sent with the app's requests to our server (not with background location readings), for the anti-abuse rules in section 4.9.
- We send a reminder when your window opens and a note if you missed. You also get your friends' alerts, returns, pauses and friend requests. These notifications contain your friends' names (and theirs contain yours), and they pass through Apple's Push Notification service. We keep each queued notification (title and text) for 14 days after it is sent. We also keep a delivery log: which kind of notification went to which account, who it was about, and Apple's answer.
4.7 Advertising, tracking and consent
im-ok is free. The only ad is optional. After a check-in that earns a reward, you can watch one rewarded ad from Google AdMob to double that check-in's reward, or keep it as it is. If you watch it to the end, our server credits the reward once more and records that it did (section 4.2). No check-in waits for an ad, and nothing in im-ok requires one.
When we ask. Right after a new account's first check-in, or when you open the app if you have used it before, im-ok asks for notifications, then for location while using the app. "Always" location is asked last, and only once you have a friend. None of these questions is about ads.
The questions about ads come the first time you tap "watch an ad", one after the other:
- Apple's App Tracking Transparency prompt;
- in the EU, the EEA, the UK and Switzerland, Google's consent form. Google's software works out from your approximate location whether the form applies to you. Elsewhere, including in the United States, no consent form from Google appears, and Apple's tracking prompt is the only question about ads.
Then im-ok loads the ad. While it loads, "keep it" still keeps your reward as it is.
im-ok starts nothing from Google on your phone until iOS has an answer to the tracking prompt: yours, or "no" if you have turned off "Allow Apps to Request to Track" in iOS Settings. Until then there is no consent check, Google's ad software is not started and no ad is requested. Google's ad software starts only after that and, where the consent form is shown, only after you have answered it. Once iOS has that answer, Google's consent software checks each time the app starts, and when you open your profile, whether the form applies to you and what you answered, without showing anything. When the questions that apply to you have been answered, later ads are loaded in advance, before you check in, while your window is open or after you have missed a check-in, so the offer doesn't wait for one. RevenueCat's software is different: it starts when the app opens, before any of these questions (below).
- App Tracking Transparency. If you allow tracking, Google and its ad partners may use your phone's advertising identifier (IDFA) to make the ad more relevant and to measure it across apps. If you choose "Ask App Not to Track", they don't get the IDFA, and im-ok still goes on to the consent form, where it applies, and to the ad; watching it still doubles the reward. im-ok's own code never reads the IDFA.
- Google's consent form (User Messaging Platform) asks whether Google and its partners may use your data for personalised ads and ad measurement. Whatever you answer to either question, check-ins, alerts and everything else in im-ok work the same. If you choose "Do not consent", Google may still show a non-personalised or limited ad, and watching it doubles the reward just the same. Fewer ads may be available then: if none can be shown, im-ok says that it couldn't show the ad and you keep the reward as it is, and later the ad may be offered less often. If you close the form without choosing, you keep the reward as it is, no ad is requested, and the form comes back the next time you tap "watch an ad".
- What Google collects. Google's privacy declaration for its ad software lists device identifiers (the IDFA only if you allowed tracking), an approximate location, which Google can estimate from your IP address, the ads you see and how you interact with them and with the app, and performance, crash and diagnostic data. Google uses these for advertising, ad measurement and analytics, as an independent controller under its own privacy policy. Google's consent software, which also checks whether the form applies to you, uses an approximate location, performance data and how you interact with the form. Ad networks may also use Apple's SKAdNetwork, which reports installs that followed an ad without identifying you.
- RevenueCat. We use RevenueCat to see what the optional ad earns. It is not used to personalise ads.
- RevenueCat's software starts when the app opens, wherever you are, before any of the questions above. Until you sign in, it knows your phone by a random ID that it creates. Once you sign in, it knows you by your account ID.
- Its requests carry your identifier for vendors, phone model, iOS and app version, language settings, App Store country and your answer to Apple's tracking prompt (not the IDFA) and, like any request, your IP address.
- Each ad event (loaded, shown, opened, revenue, failed) is reported to RevenueCat under your account ID. The event carries a session ID, the time, the ad network, format, placement and ad unit, an impression ID, the estimated revenue and any error code.
- It also sees App Store transactions on your phone (for example a premium subscription or a bubble pack bought in im-ok 1.x) and records them under your account ID.
4.8 Crash and error diagnostics
We use Sentry to collect crash reports, the reports iOS makes about app freezes and heavy processor or storage use (Apple's MetricKit), server errors on the app's requests, a few error reports (notification setup, ads and ad consent), and app sessions (when the app starts and stops, to count how often it runs without crashing). Each report contains, for example:
- your phone model, your iOS and app version, and technical details such as free memory and storage, language and time zone;
- a random installation ID;
- technical breadcrumbs of what the app was doing, including the addresses of its recent network requests. We remove the query part of each address, with the account ID, identifier for vendors and push notification token that some requests carry there, and we replace any other ID in an address, such as your account ID in the addresses RevenueCat's software uses (section 4.7), with a placeholder;
- in a report about a request to our server that failed with a server error, its address, shortened in the same way, and its headers, without the ones that identify your phone or sign you in. Requests to other services are not reported this way.
Sentry does not receive your phone number, contacts or coordinates, and it takes no screenshots or screen recordings. It is set not to store IP addresses. It stores the data in its EU region (Frankfurt, Germany), for the period in section 10.
4.9 Security and anti-abuse
To protect im-ok and its users from SMS fraud ("SMS pumping"), spam sign-ups and misuse, we keep:
- a login-code log: every code request and every refused or wrong code, with the phone number, IP address, identifier for vendors, country (for code requests) and outcome;
- blocks: when a limit is exceeded, we automatically block an IP address or a device for 24 hours, or a phone number for 12 hours. We can also block manually. IP addresses and device identifiers are stored as they are, and phone numbers as a keyed hash;
- a deletion counter: a keyed hash of your phone number and how many times an account with that number has been deleted. After the third deletion, the number can no longer be used to create an account. If you got the number from your carrier recently, or think a block is wrong, write to us and a person will review it;
- internal security alerts when a limit is exceeded. They can contain an IP address or a device identifier, and may be sent to our own phone by SMS.
A keyed hash is not anonymous. We keep the key secret on our server, and whoever holds it can check whether a hash matches a given number.
4.10 Email and support
im-ok never emails you, and you don't need an email address to sign in. If you write to support@im-ok.com, we use your email address and your message to answer you. Namecheap hosts our mailbox (Private Email).
4.11 Aggregated service metrics
Each day we store counts to watch the health and cost of the service, such as the number of accounts, active users, check-ins, alerts, notifications sent and failed, and friend requests. They contain no individual profiles and are deleted after 365 days.
4.12 Records from im-ok 1.x
The copy from 1.x (section 3.1) includes records that 2.0 does not use:
- the bubble packs you bought: the product, the App Store transaction ID, the bubbles credited, the price and currency, and when;
- the bubbles you gifted or received, with any reaction, and the daily gift limits;
- the heart skins and other items you owned or had equipped;
- the nicknames you gave friends, and the ones friends gave you;
- how many maps you loaded;
- any records from 1.x's email system: which address an email went to, what kind of email it was and whether it arrived, and addresses that bounced or unsubscribed.
We keep them only to answer questions about them, for example a refund or bubbles credited twice, and to establish or defend legal claims. RevenueCat also tells our server about bubble packs bought in 1.x, so that a pack whose bubbles were never credited can still be credited.
4.13 Kept on your phone
The app also keeps these on your phone:
- your sign-in session, in the iOS Keychain (our sign-in system keeps its own record of it, section 4.1);
- check-ins, bubble credits and doubled rewards waiting to be sent while you are offline;
- the latest copy of your profile and your friends list, including a friend's last known position when your app has received one;
- your contacts copy;
- your appearance setting.
iOS data protection encrypts them. Signing out ends the session and keeps the rest for your next sign-in. Deleting your account removes that account's files and settings from the phone.
5. What your friends see
Your friends are the people whose friend request you accepted, or who accepted yours. Nobody else on im-ok sees your status.
Their app receives:
- your display name and your animal;
- your check-in window and time zone;
- the time of your latest check-in, and when you became friends;
- when your account was created and when your last pause ended, so their app can say how long ago you missed;
- whether you are paused, and until when.
Their app works out your colour from these.
Your last known position goes to a friend's app only while that friend has an open alert about your missed check-in. Our server checks once an hour. When it finds that you missed, it alerts each of your friends, and from then on sends that friend your position. So the alert comes within an hour after your window ends. Until it reaches them, their app may already show you as missed, but without your position. The alert ends when you check in or start a pause. It stays open for as long as you stay missed, however long that is. A friend you add while you are missed is alerted at the next hourly check. At all other times, our server does not send your position to anyone.
When a friend's app has your position, it shows how long ago it was captured ("last seen … ago") and an "open in maps" button. If there is no position, it says "no location shared this time".
- A friend who taps "open in maps" hands the coordinates to Apple Maps on their phone, under Apple's privacy policy.
- An alerted friend sees your stored position however old it is, together with its age. It could, for example, be one captured days ago, the last time you opened the app, or one captured before you set location to "Never" (section 4.3).
- A friend's phone keeps the last copy it received until it next refreshes, usually the next time they open im-ok.
The app does not show your friends your phone number (except while a friend request between you is pending), your streak, your bubbles or your earlier check-ins, and im-ok 2.0 does not fetch them. One exception is left over from im-ok 1.x: our server still has a function that a friend's account can call to get your bubble totals, how many of your check-ins came after a miss, your current and longest streak, and your typical check-in time over the last 90 days. im-ok 2.0 never calls it.
Your friends get a notification with your name when you miss a check-in, when you check in again after a miss, when you pause (with the number of days) and when you are back. Someone you send a friend request to gets one too.
6. If you are not on im-ok
We may process your phone number even if you don't use im-ok:
- when someone who has you in their contacts looks for friends in the app. Their app sends the numbers in their address book to our server, to find the ones that already use im-ok;
- when someone types your number to add you as a friend.
We compare the number with existing accounts and keep nothing: no record of your number, or of who has it, remains after the request. We do this in our users' and our legitimate interest in helping people find friends who already use im-ok (Art. 6(1)(f) GDPR). Because we keep nothing, we cannot tell you about it individually.
If someone enters your number when signing in, we send the code to your phone and keep your number in the login-code log for 30 days (section 4.9).
You still have the rights in section 13, including the right to object.
7. Why we use your data, and our legal bases
Your right to object. You can object at any time, on grounds relating to your particular situation, to any processing we base on legitimate interests (listed below): for example ad measurement, security and anti-abuse logging, crash diagnostics, delivery logs, service metrics and the hosting of the im-ok pages on emilalm.app. Email support@im-ok.com. We will then stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims.
We use your data only for the purposes below. We are based in Sweden, so the GDPR applies to everything we do with your data, wherever you live. Each purpose has a legal basis under Article 6(1) GDPR, the same for everyone:
- Your account and sign-in (phone number, login codes, account ID, sessions): contract (Art. 6(1)(b)). We cannot provide im-ok without them.
- Check-ins, reminders, streaks, bubbles and pauses: contract.
- Alerting your friends when you miss, telling them when you are back or paused, and showing them your name, animal and status: contract. This is what im-ok is for.
- Telling you about important changes to im-ok, this policy or the terms, by a personal text message from Emil Alm (terms, sections 15 and 20): contract, and legal obligation where the law requires us to tell you about a change to this policy.
- Location: your consent (Art. 6(1)(a)), given through the iOS location permission. It covers capturing your position, keeping the most recent one and giving it to friends who were alerted about your missed check-in (section 5). Setting location to "Never" stops new captures. The position already stored is deleted when you delete your account or ask us to delete it (section 4.3).
- Finding friends among your contacts: reading your contacts is based on your consent, given through the iOS contacts permission. For the phone numbers of the people in your contacts, the basis is our and your legitimate interest in finding friends who already use im-ok (section 6).
- Push notifications: your consent, through the iOS permission.
- Personalised ads and the IDFA: your consent, through Apple's tracking prompt and, where it is shown, Google's consent form. They are asked the first time you tap "watch an ad". im-ok starts nothing from Google before the tracking prompt has an answer, and where the consent form is shown, no ad is requested before you have answered it (section 4.7).
- Offering the optional ad: legitimate interest. Measuring what it earns (RevenueCat): legitimate interest, not the consent above: RevenueCat's software starts when the app opens, before either question is asked (section 4.7).
- Recording App Store transactions from im-ok 1.x (RevenueCat), and crediting bubble packs bought in 1.x: contract for purchases you made, otherwise legitimate interest.
- Copying your account from im-ok 1.x to 2.0: contract. It is how we keep providing im-ok to you.
- Security and abuse prevention (section 4.9, the sign-in audit log in section 4.1, and the identifier for vendors sent with the app's requests): legitimate interest.
- Crash diagnostics (Sentry) and notification delivery logs: legitimate interest.
- Aggregated service metrics: legitimate interest.
- Keeping the records from im-ok 1.x (section 4.12), and the export files of the 1.x database kept as a backup of the move (section 10): legitimate interest, and to establish or defend legal claims.
- Answering your emails: legitimate interest, or contract when you ask about your account.
- Marketing SMS: your consent. None are sent today (section 18).
- Hosting the im-ok pages on emilalm.app: legitimate interest (section 19).
- Meeting legal duties, such as answering a lawful request from an authority or handling your rights requests: legal obligation (Art. 6(1)(c)).
The legitimate interests we rely on are:
- keeping im-ok secure, and stopping fraud, SMS pumping, spam sign-ups and repeated delete-and-recreate abuse, which cost money and put users at risk;
- keeping a safety app working, by finding and fixing crashes and failed notifications;
- keeping im-ok free, by offering the optional ad and knowing what it earns;
- knowing how many people use im-ok and what it costs to run;
- helping people find friends among their contacts;
- answering questions about past purchases and gifts and about the move from im-ok 1.x, and establishing or defending legal claims;
- publishing this policy, the terms and the support page on emilalm.app.
Withdrawing a consent does not affect what was done before you withdrew it. If we ever want to use your data for a new purpose, we will update this policy and tell you first.
8. Who receives your data
Service providers that process data on our behalf. They handle it for us, under the terms on which we use their services.
- Supabase Inc.: database, sign-in and server functions. The data is stored in Stockholm, Sweden (Amazon Web Services, region eu-north-1).
- Twilio Inc.: sends login codes by SMS (Twilio Verify), and may send our internal security alerts to our own phone. The personal texts about important changes (section 20) do not go through Twilio: Emil Alm sends them from his own phone.
- RevenueCat Inc.: measures the optional ad, and records App Store transactions from im-ok 1.x (sections 3.1 and 4.7).
- Functional Software Inc. (Sentry): crash and error diagnostics, in its EU region.
- Vercel Inc.: hosts emilalm.app, where this policy, the terms and the support page are published (section 19).
- Namecheap Inc.: hosts our support mailbox.
- Lovable: hosted im-ok 1.x's server on Lovable Cloud until we removed it, before im-ok 2.0 was released. The data on it was deleted then (section 3.2).
Apple delivers our push notifications through its Apple Push Notification service, including the silent notification that asks for a location reading, under Apple's own terms.
Companies that use data for their own purposes. These are independent controllers, working under their own privacy policies:
- Google (Google Ireland Limited in the EEA and Switzerland, Google LLC elsewhere): AdMob ads and the consent form. See how Google uses information from apps that use its services. Also Google Fonts in im-ok 1.x, until it stopped working (section 3.2).
- Apple: the App Store (which distributes im-ok and sold 1.x purchases), App Tracking Transparency, and Apple Maps when a friend opens your location. In im-ok 1.x, also Apple's MapKit, which drew its map.
Others: your friends (section 5); people on im-ok who have your phone number (section 4.5); and authorities, courts or others when the law requires it.
The companies we share your data with must protect it at least as well as this policy and the law require. They are bound by the terms under which we use their services.
9. Where your data is stored, and transfers outside the EU
Our database and sign-in system are in Stockholm, Sweden. Our server functions run on Supabase's network, by default in the Supabase region closest to whoever calls them, and read and write the data in Stockholm. For im-ok 1.x's former server, see section 3.2.
Some providers are based in, or reach data from, countries outside the EU/EEA, mainly the United States:
- Twilio, RevenueCat, Vercel, Namecheap, Google and Apple;
- Supabase and Sentry, for support and maintenance;
- Supabase also when one of its server functions runs in a region outside the EU, for example when you use im-ok from outside Europe.
Each provider's list of sub-processors names any other countries it uses.
Where such a transfer needs a safeguard under the GDPR, it relies on the EU–U.S. Data Privacy Framework (the European Commission's adequacy decision of 10 July 2023) for companies certified under it, and otherwise on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) in the provider's terms. You can ask us which one applies to a provider, and for a copy of these safeguards, at support@im-ok.com.
10. How long we keep your data
- Account and profile (phone number, name, animal, window, time zone, language, settings, streak, bubbles): until you delete your account.
- Sign-in sessions: until you sign out on that phone or delete your account. Sign-in audit log (section 4.1): kept for security, also after you delete your account, until we delete it or Supabase's own retention rules remove it.
- Last known position: one value, replaced on every update. It is deleted with your account, or earlier if you ask us. Setting location to "Never" does not delete it.
- Check-ins: 12 months, then deleted.
- Alerts: deleted 12 months after they were raised, once resolved. An open alert stays until you check in, pause or delete your account.
- Friendships: until either of you removes the friendship or deletes your account.
- Friend requests, answered ones included: until you or the other person deletes their account.
- Notification log: 14 days. Queued notifications: 14 days after they are sent.
- Notification delivery log: until you or the other person deletes their account.
- Push tokens: until you sign out or delete your account, or 30 days after the app last reached us from that phone.
- Location capture log (no coordinates): 14 days.
- Bubble credit ledger: 30 days.
- Records from im-ok 1.x (section 4.12): until you delete your account. Records from 1.x's email system stay until we delete them manually.
- Login-code log: 30 days, also after you delete your account.
- Automatic blocks: 12 hours for a phone number, 24 hours for an IP address or device. The record of a block stays after it ends, until we delete it manually. Manual blocks last until we lift them.
- Deletion counter, and the block after a third deletion: kept permanently, also after you delete your account, to stop delete-and-recreate abuse.
- Internal security alerts: for a limited time. We delete them when we no longer need them to protect the service.
- Crash diagnostics (Sentry): 30 days for crash and error reports; other diagnostics, such as session counts, for as long as Sentry's own retention rules say.
- RevenueCat: until you delete your account. When you do, we ask RevenueCat to delete your customer record.
- Google: under Google's own policies.
- Marketing SMS consent time: while the switch is on. Switching it off in im-ok 2.0 deletes it. A time copied from 1.x for a switch that is off is deleted once it is 12 months old.
- Aggregated service metrics: 365 days.
- Support email: in our mailbox until we delete it manually.
- Personal texts about important changes (section 20): in the messages on Emil Alm's own phone, until he deletes them.
- Our providers' logs and backups (for example Supabase's backups of our database, Twilio's message logs and Vercel's request logs): for as long as each provider's own retention rules say.
- im-ok 1.x on Lovable Cloud, including profile photos and their upload log: deleted when we removed Lovable Cloud, before im-ok 2.0 was released (section 3.2), except what the export files below contain.
- Copies made when we moved off Lovable Cloud (export files of the 1.x database): kept by us only as a backup of the move, and deleted when we no longer need them for that.
11. Deleting your account
In the app, go to profile → account → "delete account" and type "delete" to confirm. This deletes, straight away:
- your profile (phone number, name, animal, window, settings, streak, bubbles and stored position);
- your check-ins, the alerts about you and to you, and your friendships and friend requests;
- your push tokens, your queued notifications, and the notification and delivery logs about you;
- your bubble ledger, and the records from im-ok 1.x (section 4.12) except those listed below;
- the location capture log for your account;
- your sign-in record and sessions; we also ask RevenueCat to delete your customer record (section 10).
The app also removes the account's files and settings from your phone. Deleting the app alone does not delete your account.
What remains afterwards:
- the login-code log, for up to 30 days;
- sign-in audit log entries with your account ID and phone number, and a name if one was stored with your sign-in record (section 10);
- the deletion counter and any block records (section 4.9);
- internal security alerts (section 10);
- any records from 1.x's email system (section 10);
- if you used im-ok 1.x, your data in the export files of the 1.x database that we keep as a backup of the move (section 10);
- any personal text Emil Alm sent you about an important change, on his own phone (section 10);
- crash reports in Sentry, until they expire;
- what Google holds under its own policies;
- our providers' logs and backups, until they expire (section 10);
- your name and animal on your friends' phones, until their app next refreshes;
- your number, account ID and display name in the contacts copy on the phones of im-ok users who have you in their contacts, until their app next refreshes that list.
If you can't use the app, email support@im-ok.com and we will delete your account for you. We may ask you to confirm that the request comes from the owner of the account's phone number.
12. Your choices, and how to withdraw consent
- Location: Settings → Apps → i’m ok → Location ("Never", "While Using the App" or "Always"). "Never" stops new captures. The position already stored stays until you delete your account or email us to have it deleted (section 4.3).
- Contacts: Settings → Apps → i’m ok → Contacts.
- Notifications: Settings → Apps → i’m ok → Notifications. Without them you get no reminders, and you won't hear when a friend misses.
- Tracking: in the app, profile → privacy → "tracking in ios" opens the app's page in Settings, with the "Allow Tracking" switch. The row appears once iOS has your answer to the tracking prompt (section 4.7). You can also use Settings → Privacy & Security → Tracking.
- Ad consent: profile → privacy → "ad settings" opens Google's privacy options, where you can change your answer to Google's consent form. The row appears where Google offers that change, once iOS has your answer to the tracking prompt (section 4.7).
- Marketing SMS: profile → privacy → "marketing sms".
- Everything: delete your account (section 11).
13. Your rights
Under the GDPR, which applies to what we do with your data wherever you live (section 7), you have the right to:
- access your data and get a copy of it;
- rectification: correct it. You can change your name, animal and check-in window in the app. Write to us for anything else, such as a new phone number;
- erasure: delete your account in the app (section 11), or ask us to;
- restriction of processing;
- object to processing based on legitimate interests, at any time, on grounds relating to your particular situation (section 7);
- data portability: a copy of the data you gave us, in a machine-readable format;
- withdraw consent at any time (section 12).
Using your rights is free of charge. To use them, email support@im-ok.com. We answer within one month. Complex requests may take up to two more months, and we will tell you if so. We may ask you to confirm that the request comes from the owner of the account's phone number.
Complaints. You can complain to a data protection authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, www.imy.se. In the UK it is the Information Commissioner's Office, ico.org.uk. In Switzerland it is the Federal Data Protection and Information Commissioner, edoeb.admin.ch. You can also complain to the authority where you live or work. We would appreciate the chance to put it right first.
13.1 If you live in the United States
The rights in section 13 are yours too. Some US state privacy laws also give their residents rights over their personal data. We honour the requests below from anyone in the United States, whichever state you live in. You can:
-
find out what personal data we hold about you, and get a copy (sections 4, 7 and 8 say where it comes from, why we use it and who receives it);
-
have it corrected;
-
have it deleted;
-
limit how Google and its ad partners may use your data for advertising, by turning tracking off (see "Turning tracking off" below).
-
How to ask. Email support@im-ok.com. We may ask you to confirm that the request comes from the owner of the account's phone number. We answer within one month; if a request is complex, we tell you so within that month and take at most 45 more days. You can also delete your account in the app (section 11), and change your name, animal and check-in window there.
-
Turning tracking off. Choose "Ask App Not to Track" when im-ok asks. If you allowed tracking, turn it off under profile → privacy → "tracking in ios", or in Settings → Privacy & Security → Tracking. Google and its ad partners then don't get your phone's advertising identifier. Google's software still sends Google the other data in section 4.7, such as an approximate location it can estimate from your IP address, and Google uses it under its own policies.
-
No discrimination. Using these rights costs nothing, and we will not treat you differently for it. im-ok stays free, and check-ins, alerts and everything else work the same. With tracking off, watching the optional ad still doubles your reward, but Google may have fewer ads to show, so the offer may come less often (section 4.7).
-
Appeals. If we turn down your request, in whole or in part, reply to our answer to appeal. Within 45 days we will look at it again and tell you in writing what we decided and why, and, if you still disagree, how to contact your state's attorney general.
im-ok is not for anyone under 16 (section 17).
14. What you must provide, and what is optional
- To have an account you must give a phone number (to sign in) and a display name, and pick an animal and a check-in window. Your time zone is read from your phone. Without these we cannot provide im-ok.
- To work and stay secure, our server also needs your IP address and app version. The app also sends your identifier for vendors, which we use against abuse.
- Everything else is optional:
- location. Without it, no new position is captured. A position stored earlier stays, and still reaches an alerted friend, until you delete your account or ask us to delete it (section 4.3). If none is stored, an alerted friend sees "no location shared this time";
- contacts. You can add friends by number instead;
- notifications. Without them you get no reminders and won't hear when a friend misses;
- tracking and ad consent. Check-ins and alerts work the same either way;
- marketing SMS.
15. Automated decisions
im-ok makes no decisions about you that have legal or similarly significant effects. Some things are automatic: your colour and your friends' alerts follow your window and your check-ins, and the anti-abuse rules in section 4.9 can block a sign-in, including the block after a number's third account deletion. If you think a block is wrong, write to us and a person will review it.
16. Security
- HTTPS for all traffic between the app and our servers.
- Row-level security on every database table, so an account can read only what it is entitled to. Friendships and friend requests can only be changed through checked server functions.
- One-time sign-in codes, rate limits and automatic blocking of abusive traffic.
- Keyed hashing of phone numbers in the block lists.
- A per-device secret that background location readings must carry.
- The sign-in session stored in the iOS Keychain, and the app's copies on your phone encrypted by iOS data protection.
- Administrative tools restricted to a small number of administrator accounts through role-based permissions. Service keys are kept on the server only.
No system is 100% secure. If a breach is likely to put your rights at risk, we will report it to IMY, and tell you directly if the risk is high, as the law requires.
17. Children
im-ok is not intended for anyone under 16. We do not knowingly collect personal data from anyone under 16. If you believe someone under 16 has signed up, contact support@im-ok.com and we will delete the account.
18. Marketing SMS
The app has an opt-in switch for marketing SMS (profile → privacy → "marketing sms"), off by default. If you opted in at sign-in in im-ok 1.x, that choice was copied and the switch shows as on. We do not currently send marketing SMS. If we ever do, we will:
- send them only to people who switched it on;
- first ask everyone who switched it on, including in im-ok 1.x, to confirm by SMS;
- send them through Twilio;
- include a way to stop in each one;
- update this policy first.
While the switch is on, we keep the time you switched it on, as proof of consent. Switching it off in im-ok 2.0 deletes that time. Login codes, and Emil Alm's personal texts about important changes to im-ok, this policy or the terms (section 20), are not marketing. You need the codes to sign in.
19. The im-ok pages on emilalm.app
This policy, the terms and the support page are published at emilalm.app/im-ok/privacy, emilalm.app/im-ok/terms and emilalm.app/im-ok/support. emilalm.app is Emil Alm's personal website. The rest of it is not part of im-ok. Links in the app and in its invitations use addresses on im-ok.com, which is also ours.
- Hosting. Vercel hosts emilalm.app. Like any web server, it receives your IP address and browser details to deliver the pages, and keeps request logs (section 10).
- No analytics or cookies. These pages use no analytics, set no cookies and store nothing in your browser, so we don't ask for cookie consent. They load nothing from other companies.
- Fonts. The text is set in fonts from your device or from emilalm.app itself. Your browser does not contact Google Fonts or any other font service.
- Links. A link to another website, such as Apple's or Google's, takes you there, under that site's own privacy policy.
- Do Not Track. We do not respond to Do Not Track signals, because these pages do not track you across other sites. In the app, Google and its partners may do so only if you allow tracking (section 4.7).
20. Changes to this policy
We may update this policy. The current version is always at https://emilalm.app/im-ok/privacy, with its date at the top. Before a material change takes effect, we will tell you about it in the app or on this page. If you already have an account, Emil Alm will also tell you by a personal text message to the phone number on your account.
21. Contact
Questions about this policy or your personal data: support@im-ok.com.