Punish — Privacy Policy
Last updated 28 September 2026
Punish is a commitment app: you set a goal, stake money on it, and if you miss, that money goes to a charity you would rather not fund. This policy describes exactly what the app collects, what leaves your phone, and who else sees it.
There is no sign-up. Punish has no login, no email address and no password, and everything in sections 1 and 2 happens without you ever telling us who you are. Friends is the one exception and it is off until you turn it on: making a Friends account stores a display name you typed yourself, and nothing else about you. Section 3 says what that does and does not reach.
1. What stays on your phone
The great majority of what Punish knows about you never leaves your device. It is stored in the app's private storage, is not readable by other apps, and is deleted when you uninstall the app:
- Your goals — titles, deadlines, stakes, streaks, exceptions and check-in history.
- Your ledger — every forfeit you have owed, paid, declined or appealed.
- Screen-time measurements — how long the apps you have set limits on were in the foreground, read from Android's usage-access API and from the app's own accessibility service.
- Website timing — if you set a limit on a single website, the accessibility service reads the address bar of your browser so it can time that one site. The domains it sees are recorded on the device to measure your goal, and are pruned automatically.
- What that service does and does not do — it reads the address bar in browsers, and notes which app is in front so screen-time limits stay accurate when two apps share the screen. It can also put a full-screen Punish message over an app or site you have limited. On a goal that counts opens, that happens at three moments — one open left, your last free open, and the open that goes past the limit — at most three times a day per goal. On a goal that counts minutes, the last minute is a notification, one message appears in the final couple of seconds, and once the limit has run out a message appears each time you open that app again that day if money is at stake, or once that day if nothing is. While a forfeit on a goal is unpaid, a message appears on every open of that app until you settle it. Some messages ask you to press and hold before carrying on. None of them can block or close an app: the open is already counted before the message appears, and you can always continue past it. The service never taps, types, fills anything in, or reads the content of a page. What it observes stays on your device unless you switch measurement on, as described in the table below.
- Location — if a goal is settled by arriving somewhere, your position is compared to that place on the device. Punish makes no network request with your location, and no location data is ever sent to us or to anyone else.
- A contact you pick — if you choose to tell someone about a goal, or to send a buddy invite, Punish opens the system contact picker and uses only the single name and number you select. Your address book is never read in bulk and never uploaded. Messages to that person — including an invite code — are composed in your own SMS app; we do not send them, never see them, and never learn who you picked. An invite number is not stored at all.
- Proof photos — kept in the app's private folder (not your gallery, not the media scanner), capped at the 60 most recent, so a disputed check-in can be reviewed later.
2. What is sent to our server
Punish's backend runs at punish.mynight.co.il. It receives only this:
| What | When | What happens to it |
|---|---|---|
| A proof photo, plus the goal title and the description of the shot you agreed to take | When you submit a photo as proof | Passed straight to Google's Gemini API for a pass/fail verdict and returned to you. It is not written to disk and not kept — it exists only for the seconds the request takes. Our logs record the photo's size and how long the check took, never the image. |
| A goal title on its own | While you are creating a goal, to judge whether a photo could prove it | Sent to the same AI provider for a short text answer. The first 40 characters appear in our server log. |
| A forfeit record — goal title, amount, chosen charity, whether you missed by your own admission or by measurement, the stated reason, and timestamps | When a forfeit is created, declined, appealed or paid | Stored in our ledger file so a donation can be matched to it and an appeal can be decided. 30 days after a forfeit is paid, declined or cancelled on appeal, its device id and goal title are deleted from the ledger, and so is the reason where it quotes the goal title. |
| A device id | With photo checks, forfeits and charity boosts | An identifier your phone gives us, scoped to Punish — no other app is given the same value, and it is not your Google account, your advertising id, or anything that names you. It exists so usage limits apply per device and so an appeal decision can be matched to the phone that filed it. It normally survives uninstalling and reinstalling Punish, and that is deliberate: a forfeit you owe is not cancelled by deleting the app. If your phone will not give us that value we generate a random one instead, and that one does not survive a reinstall. |
| A charity boost — the charity, the number of loops, and your country (read from your mobile network, or your SIM, or else your phone's region setting) | When you spend loops to boost a charity | The loops are added to a running total for that charity in your country, and the charity picker shows the most-boosted ones to other people in the same country as "Boosted near you". That total says nothing about who boosted. With each boost we also keep your device id and a one-way hash of your IP address for one day, only to cap how many loops one phone or one network can add in a day; after that day they are deleted. The per-country totals are kept. |
| Your answers in Discover charities — which answer you chose to each question you answered | When you finish Discover charities, if you answered at least one question | Each answer is added to a running total of how many people chose it, and nothing else is kept. Nothing that identifies you or your phone is sent with them: no device id, no account, no time. We keep no record of who answered, of when, or of which answers were given together. Your IP address is used in memory only, to cap how often one network can send answers, and is forgotten within the hour. |
| Donation statistics — for each forfeit: the day it was created, your phone's country (two letters, read from your mobile network, or your SIM, or else your phone's region setting), the amount, the charity and its category, the kind of goal (an app, a website, the whole phone, a task, a photo, a place or a call), whether the stake was fixed or per open, whether you admitted the miss or it was measured, how it ended (paid, declined, appealed, cancelled on appeal, or still open), roughly how long that took (the same day, within a week, or later), and the app version | When a forfeit is created, and when it is paid, declined or appealed | Kept in a statistics file separate from the forfeit ledger. It holds no device id, no goal title, no reason, no exact time and no forfeit id, and never your IP address or your location beyond the country. Until 30 days after a forfeit is paid, declined or cancelled on appeal, the ledger keeps a random reference to its statistics entry so the outcome can be added; after that the reference is deleted with the device id and goal title, and the two can no longer be matched. We look at these statistics only as totals, and only in groups of at least ten: a country, a charity or a month with fewer than ten forfeits is counted as "other" rather than shown. After 13 months the entries are merged into monthly totals and deleted. |
| Your IP address | On every request, as with any website | Held in memory only, to cap how many AI checks one caller can run. It ages out within 24 hours and is not stored in the ledger. It appears in a warning log line if a limit is hit. |
| Measurement events — goal created (type, stake, charity, goal title, the app or site targeted, the limit), a goal broken, the settle screen opened, checkout opened, a forfeit paid or refused, a goal staked again after paying, a crash, and once a day per goal: your limit, the minutes or opens measured against it, and whether you went over | Only if you switch it on. This is off when you install Punish. If you turn it on in Settings, events are batched and sent when the app is next opened | Written to an event log on our server, keyed to the same device id. It is how we find out whether the app works — in particular whether people who pay a forfeit set the goal again. See section 7. |
| Crash and failure reports — where in the app something failed, the error type and its message, and how many times it has happened. An error message is written by the app or by Android, not by you, but it can quote something it was working on at the time, such as a goal title or an address it failed to reach | Only if you switch measurement on. When the app crashes or a check fails, sent with the events above. A failure that repeats is reported occasionally rather than every time | Written to the same event log. Without it an app that crashes on your phone is indistinguishable from one you simply stopped using, and a measurement that silently stopped working looks exactly like a week you spent under your limit. |
| A display name, and what you choose to show each buddy — a name you type for friends to recognise you by, and, for each person you have linked to, the level you picked for them: how many of your goals you kept each day; your streak and last seven days; the title and daily result of each goal you have not hidden from buddies; the amount riding on those goals; the charity each of them pays | Only if you switch Friends on. When you make an account, when you save what a buddy sees, and when the app opens while you have at least one buddy | Held until you lower that person's level, hide a goal, remove them or delete the account, any of which removes what only they could see. A new buddy sees only the count. An amount of money is sent only at the fourth and fifth levels, and a charity only at the fifth, and the server keeps them only while a buddy at that level exists. A goal you hide from buddies is never sent, at any level, and is left out of the count; what one person may see is not visible to another. The app, the minutes, your notes and your photos never travel. |
| One word a day, per shared goal — kept, missed, or off | Only while a goal is shared with somebody. A day for a goal nobody can see is refused by the server rather than stored | Kept for 30 days, and deleted the moment you stop sharing that goal or remove that person. It carries no minutes, no opens, no app name, no money and no time of day. |
Location and contact data are not in this list, and no part of the app sends them anywhere; the nearest thing is your phone's country, with a charity boost and in the donation statistics. Proof photos are sent only for the seconds a check takes and are never stored.
Screen-time figures are sent only if you switch measurement on, and then only as the daily summary described above: for each goal you set, the app or site it watches, the limit, the number measured against it, and the verdict. The underlying minute-by-minute usage, your browsing history, and the addresses of the pages you visit stay on the phone and are never sent. With measurement off — which is how Punish arrives — none of it is sent at all. See section 7.
3. Who else sees anything
Google (Gemini API)
Proof photos and goal text are processed by Google's Gemini API to produce the verdict. We do not retain them; Google's handling of API content is governed by Google's Gemini API terms and privacy policy. Do not photograph anything you would not want processed by a third-party AI service — a picture of the gym is the intended use; documents, screens and other people are not.
every.org
Donations are made on every.org's own hosted checkout. every.org is a US 501(c)(3) that acts as merchant of record, takes the payment, issues the receipt and disburses to the nonprofit. Punish never sees or handles your card details — no payment data touches our server or your phone's app storage. every.org tells us only that a given forfeit was paid, with a charge id and the net amount. What they collect from you is covered by every.org's privacy policy.
Google Play
Distribution and updates go through Google Play, which collects its own installation and crash statistics under its own policy. We can see aggregate install counts and crash reports through the Play Console. That is Google measuring the distribution, not Punish measuring you, and it happens whether or not you switch our own measurement on.
Nobody else
Punish contains no advertising, no third-party analytics SDK, no tracking SDK and no crash-reporting SDK. The measurement described in section 2 is our own code sending to our own server — it does not pass through Google Analytics, Firebase, Amplitude, Mixpanel or anything like them, and no third party receives it. We do not sell, rent or share your data with anyone, and there is nothing here to sell — unless you have made a Friends account, we do not know who you are. If you have, we know one thing: a display name you typed yourself, which we never check against anything real.
A friend you invited
Friends is off until you make an account. Each account has one standing code; giving it to somebody lets them ASK to be your buddy, and nothing happens until you say yes. A code in the wrong hands is therefore a request you refuse with one tap, not a connection — and you can replace your code at any time, which retires the old one immediately. There is no contact upload, and nobody can find you by name, number or email — see the next section for the one way a stranger can reach you, which is off until you switch it on.
What a buddy sees is up to you, person by person, on a scale of five levels, each adding to the one before: (1) how many of your goals you kept on your last finished day — where every new buddy starts; (2) your current streak and the last seven days, as kept, missed or off; (3) your goals, by the title you wrote, and one word a day for each: kept, missed, or off; (4) the amount riding on each of those goals, and their total; (5) the charity each of those goals pays. Any goal can be hidden from buddies — from the sharing screen or from the goal itself — and a hidden goal is hidden from every buddy at every level: it is never sent, and it is left out of the count, the streak and the last seven days you show. Before you save, the app shows you the card exactly as that person will see it, and nothing is sent until you save. The level is enforced by our server, which gives each buddy only what their level allows, whatever the app asks for. Choose what you share accordingly: a goal's title says what you are working on, so hide the ones you do not want read. They never see any app name, any number of minutes, your notes or your photos, because none of those reach our server at all. They see no amount of money and no charity unless you pick the fourth or fifth level for them — and then only for goals you have not hidden; the one other place an amount appears is a pact, described below. Buddies who had goals shared with them before the levels existed were moved to the third level, which is exactly what they were already seeing. Removing someone deletes what they could see, both ways and at once.
Two things a buddy can do
Being linked to somebody lets them do two things and no others. None of them can move money, and none of them creates a link — the people who can do these things are exactly the people you already said yes to.
Hand you a streak shield. Shields live on your phone; the server only carries the message that one is coming, and deletes it the moment your phone collects it. At most two can be waiting for you at a time.
Make a pact with you — the same object whether it is called a pact, a challenge or a team. It holds a title somebody wrote, who is in it, and what each member put on it. That last one is the one exception to the rule above that you do not set with a buddy's level: the other members of a pact see the amount you staked on it, because a promise nobody can see the weight of is a promise with no weight. It is a number you choose for that pact, it is shown only to the people in it, and no other amount of money you have ever staked is visible to anybody, except to a buddy you gave the fourth or fifth level. Each member is judged alone and pays their own forfeit — there is no shared pot and nobody else's day can cost you anything. You can leave at any time, and the others are shown that you did.
A stranger, only if you ask to be found
You are not listed anywhere until you say so, and you are never listed by using the rest of the app. Two separate switches, both off by default: Let others find me puts you on a short list newcomers can see, and Offer to sponsor adds you to the shorter list of people a newcomer can be matched with. The second turns the first on, because an offer nobody can see is not an offer. Turning the first off turns both off, at once and completely — the listing is gone on the next request, not queued, not archived.
A listing carries a display name and one number: how many days you have kept. Not a goal, not a title, not a word of what you wrote, not an amount, not a charity, not a streak of anything else. Somebody who finds you learns that a person exists, calls themselves something, and has kept some days.
Being found is not being connected. Discovery produces the same request a code does: it arrives for you to answer, and nothing is shared until you say yes — and then only how many of your goals you kept, until you choose to show that person more. The same ceiling applies — after three refusals that person cannot ask again. Being matched as a sponsor is likewise an ask that lands with the sponsor, never a pairing made for either of you.
4. Permissions and why they exist
| Permission | Why |
|---|---|
| Accessibility service | Times websites by reading the browser address bar, records which app is in focus so screen-time goals stay accurate in split screen, and puts Punish's own full-screen messages over apps and sites you have limited, at the moments described in section 1. It never blocks, taps, types, or reads page content. What it observes stays on the device unless you switch measurement on (section 2). |
| Usage access | Reads Android's app-usage statistics to measure screen-time goals. |
| Camera | Taking proof photos. Only photos you deliberately capture and submit are used. |
| Location | Optional, only for goals settled by arriving at a place. Compared on-device. |
| Contacts | Optional, only to let you pick one person to tell about a goal. Only the chosen name and number are kept, on the device. |
| Notifications | Deadline reminders and the live budget notification. |
Every optional permission can be refused, and the rest of the app keeps working without it.
5. Keeping and deleting data
- On your phone: uninstalling Punish deletes everything the app stored — goals, ledger, measurements, proof photos. There is no cloud backup, and for the same reason there is no way to move your data to a new phone.
- On our server: forfeit records are kept for as long as Punish runs, because they are the ledger the app is built around — a debt that vanished when we tidied up would not be a debt. A record holds no name, email or address — only the goal title, the amount, the charity and the device id, and 30 days after the forfeit is paid, declined or cancelled on appeal the goal title and device id are deleted from it. Delete them at any time by asking; see below.
- A Friends account: delete it from inside the app, at any time, without asking anyone. It takes the display name, every link, every share in both directions and every shared day with it, in one pass — nothing is flagged and kept. Because we hold no email, there is no way to recover an account from a phone you have lost or wiped, and no way for us to tell that a person asking is the person who made it. That is the price of not collecting an address, and the app says so before you make one rather than leaving you to find out.
- Deletion on request: email support@punishapp.com. Because we hold no name or email, say roughly when you used the app and what the goal was called, and we will find the matching records and delete them — or reply with your install id if you have it. We will confirm once it is done.
6. Children
Punish stakes real money and is not directed at children. It is not intended for anyone under 18, and we do not knowingly collect anything from them.
7. Measurement, and what it would mean if you switched it on
Appeals against an automatically detected miss are approved automatically after a short delay, and every appeal is recorded so we can see what people contest. Appeal records carry the same data as forfeit records and nothing more.
Punish can also collect the measurement events listed in section 2. This is off when you install the app and stays off unless you go and switch it on.
Being straight about what switching it on would mean: taken together those events describe which apps and sites you set goals against, how much money you were willing to stake, when you failed, and whether you paid — tied to a single device id that normally survives a reinstall. That is a meaningful picture of your habits. We ask for it because the alternative is guessing at whether the product works, and we would rather ask than guess.
Four commitments about it:
- Off is the default. Install Punish, use it for a year, never open Settings, and none of this is ever collected.
- You can turn it off again from Settings, at any point, without reinstalling and without losing your goals. Nothing else in the app changes when you do, and anything still waiting to be sent is thrown away rather than held.
- Your goals are judged the same either way. Measurement never decides whether you kept a goal or what you owe — that is all worked out on your phone.
- It deletes with everything else. A deletion request under section 5 removes these events too, not just the forfeit records.
8. Changes
If this policy changes materially, the date at the top changes and the new version appears at this address.
9. Contact
Punish is built and run by Itai Hoffman, an independent developer, in Israel. Questions, deletion requests and complaints: support@punishapp.com.