Legal

Privacy Policy

Last updated: June 21, 2026

Onzy ("we," "us," or "our") is operated by DryDev Professional Services LLC. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our service at onzy.app and our mobile applications.

1. Information We Collect

Account information: When you sign up, we collect your email address, password (hashed — never stored in plain text), and date of birth (for COPPA age verification).

Profile information: Your display name, avatar, and any profile details you choose to provide.

Usage data: Task data, streak counts, vibe check entries, broadcast history, and Spotter connections you create within the app.

Device and technical data: Browser type, operating system, IP address, and app version, collected automatically for security and performance monitoring.

Communications: If you contact us for support, we retain that correspondence.

2. How We Use Your Information

We do not sell your personal information to third parties. We do not use your data to train AI models.

3. Spotter Data Sharing

Onzy is a social accountability app. When you connect with a Spotter, that person can see:

Your Spotters cannot see your individual task content, vibe check notes, or billing information.

4. AI Features

Vibe Check coaching and AI Day Plan features send anonymized prompts to third-party AI providers (currently Google Gemini). We do not include your name, email, or identifiable information in these requests. AI provider data handling is subject to their own privacy policies.

5. Data Storage and Security

Your data is stored in Supabase (PostgreSQL) hosted in the United States. We use row-level security to ensure users can only access their own data. All data is encrypted in transit (TLS) and at rest. We support multi-factor authentication (TOTP) for additional account security.

6. Data Retention and Deletion

You may delete your account at any time from within the app (Settings → Account → Delete Account). Account deletion soft-deletes your record for 30 days (allowing recovery), then permanently purges all personal data. You may also request data export or deletion by emailing privacy@onzy.app.

7. Children's Privacy (COPPA)

Onzy is not directed to children under 13. We collect date of birth at signup and block registration for users under 13. If we become aware that a child under 13 has provided personal information, we will delete it promptly. Contact privacy@onzy.app if you believe this has occurred.

8. Cookies and Tracking

We use session cookies for authentication. We may use analytics tools (such as PostHog) to understand product usage — these tools collect anonymized behavioral data only. We do not use advertising cookies or cross-site tracking.

9. Third-Party Services

10. Your Rights (GDPR / CCPA)

Depending on your location, you may have the right to: access your data, correct inaccurate data, request deletion, restrict processing, or data portability. To exercise these rights, email privacy@onzy.app. We will respond within 30 days.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notice at least 14 days before the change takes effect. Continued use of Onzy after the effective date constitutes acceptance.

12. Contact

Questions about this policy: privacy@onzy.app
DryDev Professional Services LLC
United States