Punish — Privacy Policy

Last updated 28 September 2026

Punish is a commitment app: you set a goal, stake money on it, and if you miss, that money goes to a charity you would rather not fund. This policy describes exactly what the app collects, what leaves your phone, and who else sees it.

There is no sign-up. Punish has no login, no email address and no password, and everything in sections 1 and 2 happens without you ever telling us who you are. Friends is the one exception and it is off until you turn it on: making a Friends account stores a display name you typed yourself, and nothing else about you. Section 3 says what that does and does not reach.

1. What stays on your phone

The great majority of what Punish knows about you never leaves your device. It is stored in the app's private storage, is not readable by other apps, and is deleted when you uninstall the app:

2. What is sent to our server

Punish's backend runs at punish.mynight.co.il. It receives only this:

WhatWhenWhat happens to it
A proof photo, plus the goal title and the description of the shot you agreed to take When you submit a photo as proof Passed straight to Google's Gemini API for a pass/fail verdict and returned to you. It is not written to disk and not kept — it exists only for the seconds the request takes. Our logs record the photo's size and how long the check took, never the image.
A goal title on its own While you are creating a goal, to judge whether a photo could prove it Sent to the same AI provider for a short text answer. The first 40 characters appear in our server log.
A forfeit record — goal title, amount, chosen charity, whether you missed by your own admission or by measurement, the stated reason, and timestamps When a forfeit is created, declined, appealed or paid Stored in our ledger file so a donation can be matched to it and an appeal can be decided. 30 days after a forfeit is paid, declined or cancelled on appeal, its device id and goal title are deleted from the ledger, and so is the reason where it quotes the goal title.
A device id With photo checks, forfeits and charity boosts An identifier your phone gives us, scoped to Punish — no other app is given the same value, and it is not your Google account, your advertising id, or anything that names you. It exists so usage limits apply per device and so an appeal decision can be matched to the phone that filed it. It normally survives uninstalling and reinstalling Punish, and that is deliberate: a forfeit you owe is not cancelled by deleting the app. If your phone will not give us that value we generate a random one instead, and that one does not survive a reinstall.
A charity boost — the charity, the number of loops, and your country (read from your mobile network, or your SIM, or else your phone's region setting) When you spend loops to boost a charity The loops are added to a running total for that charity in your country, and the charity picker shows the most-boosted ones to other people in the same country as "Boosted near you". That total says nothing about who boosted. With each boost we also keep your device id and a one-way hash of your IP address for one day, only to cap how many loops one phone or one network can add in a day; after that day they are deleted. The per-country totals are kept.
Your answers in Discover charities — which answer you chose to each question you answered When you finish Discover charities, if you answered at least one question Each answer is added to a running total of how many people chose it, and nothing else is kept. Nothing that identifies you or your phone is sent with them: no device id, no account, no time. We keep no record of who answered, of when, or of which answers were given together. Your IP address is used in memory only, to cap how often one network can send answers, and is forgotten within the hour.
Donation statistics — for each forfeit: the day it was created, your phone's country (two letters, read from your mobile network, or your SIM, or else your phone's region setting), the amount, the charity and its category, the kind of goal (an app, a website, the whole phone, a task, a photo, a place or a call), whether the stake was fixed or per open, whether you admitted the miss or it was measured, how it ended (paid, declined, appealed, cancelled on appeal, or still open), roughly how long that took (the same day, within a week, or later), and the app version When a forfeit is created, and when it is paid, declined or appealed Kept in a statistics file separate from the forfeit ledger. It holds no device id, no goal title, no reason, no exact time and no forfeit id, and never your IP address or your location beyond the country. Until 30 days after a forfeit is paid, declined or cancelled on appeal, the ledger keeps a random reference to its statistics entry so the outcome can be added; after that the reference is deleted with the device id and goal title, and the two can no longer be matched. We look at these statistics only as totals, and only in groups of at least ten: a country, a charity or a month with fewer than ten forfeits is counted as "other" rather than shown. After 13 months the entries are merged into monthly totals and deleted.
Your IP address On every request, as with any website Held in memory only, to cap how many AI checks one caller can run. It ages out within 24 hours and is not stored in the ledger. It appears in a warning log line if a limit is hit.
Measurement events — goal created (type, stake, charity, goal title, the app or site targeted, the limit), a goal broken, the settle screen opened, checkout opened, a forfeit paid or refused, a goal staked again after paying, a crash, and once a day per goal: your limit, the minutes or opens measured against it, and whether you went over Only if you switch it on. This is off when you install Punish. If you turn it on in Settings, events are batched and sent when the app is next opened Written to an event log on our server, keyed to the same device id. It is how we find out whether the app works — in particular whether people who pay a forfeit set the goal again. See section 7.
Crash and failure reports — where in the app something failed, the error type and its message, and how many times it has happened. An error message is written by the app or by Android, not by you, but it can quote something it was working on at the time, such as a goal title or an address it failed to reach Only if you switch measurement on. When the app crashes or a check fails, sent with the events above. A failure that repeats is reported occasionally rather than every time Written to the same event log. Without it an app that crashes on your phone is indistinguishable from one you simply stopped using, and a measurement that silently stopped working looks exactly like a week you spent under your limit.
A display name, and what you choose to show each buddy — a name you type for friends to recognise you by, and, for each person you have linked to, the level you picked for them: how many of your goals you kept each day; your streak and last seven days; the title and daily result of each goal you have not hidden from buddies; the amount riding on those goals; the charity each of them pays Only if you switch Friends on. When you make an account, when you save what a buddy sees, and when the app opens while you have at least one buddy Held until you lower that person's level, hide a goal, remove them or delete the account, any of which removes what only they could see. A new buddy sees only the count. An amount of money is sent only at the fourth and fifth levels, and a charity only at the fifth, and the server keeps them only while a buddy at that level exists. A goal you hide from buddies is never sent, at any level, and is left out of the count; what one person may see is not visible to another. The app, the minutes, your notes and your photos never travel.
One word a day, per shared goal — kept, missed, or off Only while a goal is shared with somebody. A day for a goal nobody can see is refused by the server rather than stored Kept for 30 days, and deleted the moment you stop sharing that goal or remove that person. It carries no minutes, no opens, no app name, no money and no time of day.

Location and contact data are not in this list, and no part of the app sends them anywhere; the nearest thing is your phone's country, with a charity boost and in the donation statistics. Proof photos are sent only for the seconds a check takes and are never stored.

Screen-time figures are sent only if you switch measurement on, and then only as the daily summary described above: for each goal you set, the app or site it watches, the limit, the number measured against it, and the verdict. The underlying minute-by-minute usage, your browsing history, and the addresses of the pages you visit stay on the phone and are never sent. With measurement off — which is how Punish arrives — none of it is sent at all. See section 7.

3. Who else sees anything

Google (Gemini API)

Proof photos and goal text are processed by Google's Gemini API to produce the verdict. We do not retain them; Google's handling of API content is governed by Google's Gemini API terms and privacy policy. Do not photograph anything you would not want processed by a third-party AI service — a picture of the gym is the intended use; documents, screens and other people are not.

every.org

Donations are made on every.org's own hosted checkout. every.org is a US 501(c)(3) that acts as merchant of record, takes the payment, issues the receipt and disburses to the nonprofit. Punish never sees or handles your card details — no payment data touches our server or your phone's app storage. every.org tells us only that a given forfeit was paid, with a charge id and the net amount. What they collect from you is covered by every.org's privacy policy.

Google Play

Distribution and updates go through Google Play, which collects its own installation and crash statistics under its own policy. We can see aggregate install counts and crash reports through the Play Console. That is Google measuring the distribution, not Punish measuring you, and it happens whether or not you switch our own measurement on.

Nobody else

Punish contains no advertising, no third-party analytics SDK, no tracking SDK and no crash-reporting SDK. The measurement described in section 2 is our own code sending to our own server — it does not pass through Google Analytics, Firebase, Amplitude, Mixpanel or anything like them, and no third party receives it. We do not sell, rent or share your data with anyone, and there is nothing here to sell — unless you have made a Friends account, we do not know who you are. If you have, we know one thing: a display name you typed yourself, which we never check against anything real.

A friend you invited

Friends is off until you make an account. Each account has one standing code; giving it to somebody lets them ASK to be your buddy, and nothing happens until you say yes. A code in the wrong hands is therefore a request you refuse with one tap, not a connection — and you can replace your code at any time, which retires the old one immediately. There is no contact upload, and nobody can find you by name, number or email — see the next section for the one way a stranger can reach you, which is off until you switch it on.

What a buddy sees is up to you, person by person, on a scale of five levels, each adding to the one before: (1) how many of your goals you kept on your last finished day — where every new buddy starts; (2) your current streak and the last seven days, as kept, missed or off; (3) your goals, by the title you wrote, and one word a day for each: kept, missed, or off; (4) the amount riding on each of those goals, and their total; (5) the charity each of those goals pays. Any goal can be hidden from buddies — from the sharing screen or from the goal itself — and a hidden goal is hidden from every buddy at every level: it is never sent, and it is left out of the count, the streak and the last seven days you show. Before you save, the app shows you the card exactly as that person will see it, and nothing is sent until you save. The level is enforced by our server, which gives each buddy only what their level allows, whatever the app asks for. Choose what you share accordingly: a goal's title says what you are working on, so hide the ones you do not want read. They never see any app name, any number of minutes, your notes or your photos, because none of those reach our server at all. They see no amount of money and no charity unless you pick the fourth or fifth level for them — and then only for goals you have not hidden; the one other place an amount appears is a pact, described below. Buddies who had goals shared with them before the levels existed were moved to the third level, which is exactly what they were already seeing. Removing someone deletes what they could see, both ways and at once.

Two things a buddy can do

Being linked to somebody lets them do two things and no others. None of them can move money, and none of them creates a link — the people who can do these things are exactly the people you already said yes to.

Hand you a streak shield. Shields live on your phone; the server only carries the message that one is coming, and deletes it the moment your phone collects it. At most two can be waiting for you at a time.

Make a pact with you — the same object whether it is called a pact, a challenge or a team. It holds a title somebody wrote, who is in it, and what each member put on it. That last one is the one exception to the rule above that you do not set with a buddy's level: the other members of a pact see the amount you staked on it, because a promise nobody can see the weight of is a promise with no weight. It is a number you choose for that pact, it is shown only to the people in it, and no other amount of money you have ever staked is visible to anybody, except to a buddy you gave the fourth or fifth level. Each member is judged alone and pays their own forfeit — there is no shared pot and nobody else's day can cost you anything. You can leave at any time, and the others are shown that you did.

A stranger, only if you ask to be found

You are not listed anywhere until you say so, and you are never listed by using the rest of the app. Two separate switches, both off by default: Let others find me puts you on a short list newcomers can see, and Offer to sponsor adds you to the shorter list of people a newcomer can be matched with. The second turns the first on, because an offer nobody can see is not an offer. Turning the first off turns both off, at once and completely — the listing is gone on the next request, not queued, not archived.

A listing carries a display name and one number: how many days you have kept. Not a goal, not a title, not a word of what you wrote, not an amount, not a charity, not a streak of anything else. Somebody who finds you learns that a person exists, calls themselves something, and has kept some days.

Being found is not being connected. Discovery produces the same request a code does: it arrives for you to answer, and nothing is shared until you say yes — and then only how many of your goals you kept, until you choose to show that person more. The same ceiling applies — after three refusals that person cannot ask again. Being matched as a sponsor is likewise an ask that lands with the sponsor, never a pairing made for either of you.

4. Permissions and why they exist

PermissionWhy
Accessibility serviceTimes websites by reading the browser address bar, records which app is in focus so screen-time goals stay accurate in split screen, and puts Punish's own full-screen messages over apps and sites you have limited, at the moments described in section 1. It never blocks, taps, types, or reads page content. What it observes stays on the device unless you switch measurement on (section 2).
Usage accessReads Android's app-usage statistics to measure screen-time goals.
CameraTaking proof photos. Only photos you deliberately capture and submit are used.
LocationOptional, only for goals settled by arriving at a place. Compared on-device.
ContactsOptional, only to let you pick one person to tell about a goal. Only the chosen name and number are kept, on the device.
NotificationsDeadline reminders and the live budget notification.

Every optional permission can be refused, and the rest of the app keeps working without it.

5. Keeping and deleting data

6. Children

Punish stakes real money and is not directed at children. It is not intended for anyone under 18, and we do not knowingly collect anything from them.

7. Measurement, and what it would mean if you switched it on

Appeals against an automatically detected miss are approved automatically after a short delay, and every appeal is recorded so we can see what people contest. Appeal records carry the same data as forfeit records and nothing more.

Punish can also collect the measurement events listed in section 2. This is off when you install the app and stays off unless you go and switch it on.

Being straight about what switching it on would mean: taken together those events describe which apps and sites you set goals against, how much money you were willing to stake, when you failed, and whether you paid — tied to a single device id that normally survives a reinstall. That is a meaningful picture of your habits. We ask for it because the alternative is guessing at whether the product works, and we would rather ask than guess.

Four commitments about it:

8. Changes

If this policy changes materially, the date at the top changes and the new version appears at this address.

9. Contact

Punish is built and run by Itai Hoffman, an independent developer, in Israel. Questions, deletion requests and complaints: support@punishapp.com.