OkiPaca
Pricing Privacy Support Download

Privacy Policy

Last updated: August 6, 2026

OkiPaca is designed around local proof alarms. The app uses device capabilities such as AlarmKit, camera scanning, Core NFC, local AI Object validation, notifications, and optional Screen Time controls.

Data stored on your device

OkiPaca stores alarms, proof records, wake history, diagnostic attempts, settings, and optional Morning Block choices locally on your iPhone.

Camera and AI Object proof

AI Object proof runs locally on device. OkiPaca does not upload or persist original camera photos. Camera access is used only when you register, test, or complete proof missions that require it.

Anonymous onboarding profile

If you accept the data notice in the long onboarding, OkiPaca automatically creates a private anonymous Supabase identity and uploads selected answer categories as you continue. These can include age range, self-description, morning habits and feelings, coarse wake-time and repeat-day categories, mission and sound preferences, onboarding progress, commitment completion, and experiment assignment. OkiPaca does not upload exact wake times, signature strokes or images, camera photos, proof secrets, alarm labels, or free-text answers in this onboarding copy.

Each onboarding flow has a random identifier. OkiPaca retains no more than eight flow responses per identity, and each response expires 180 days after its most recent substantive update unless you delete it sooner. You can delete all uploaded onboarding answers from onboarding or from the app's account settings. Answer-only deletion keeps the private identity available for purchase access and optional account linking; it does not remove local alarms or proofs.

Optional account and cloud restore

You may link the anonymous onboarding identity to Sign in with Apple or Google, or explicitly choose an existing account. Normal linking keeps the same private profile connected to your account. If you choose an existing account, OkiPaca deletes the uploaded anonymous answers first, keeps the draft on this iPhone, signs in, and uploads the permitted answer copy under that account. OkiPaca blocks account switching until uploaded answers are deleted.

Creating or signing into an account does not automatically upload your alarm data. If you separately turn on Account Backup, OkiPaca stores an authenticated cloud copy of portable alarm settings, including alarm labels, exact alarm time, repeat days, sound and wake options; supported proof names and privacy-safe verifier or configuration data; and finalized wake history used to restore Stats. OkiPaca does not back up active system-alarm identifiers, enabled or ringing state, permission state, Screen Time selections, camera images, Photo Match data, raw scanned QR or barcode values, or raw NFC identifiers. For an OkiPaca-generated QR, backup includes enough generated secret data to recreate and reprint that same QR; scanned external codes cannot be recreated.

Account Backup remains stored until you delete it or delete your account. Turning backup off stops future uploads but leaves the existing cloud copy available for restore. You can use Delete Cloud Copy in account settings to remove the current account backup while keeping local alarms, proofs, and Stats on this iPhone. Full account deletion removes account backup records together with the other account data described below. Restored alarms always return off with no system schedule, and restored proofs must be tested on the new iPhone before an alarm can be enabled.

Payments and subscriptions

Purchases are processed by Apple and managed through RevenueCat. OkiPaca may store RevenueCat customer identifiers, product identifiers, purchase events, renewal state, trial state, and subscription status needed to unlock OkiPaca Plus and provide support.

Website analytics

On OkiPaca's public website pages, OkiPaca uses PostHog in cookieless mode to understand page visits and whether visitors use the App Store or How It Works links. Website events can include the normalized public page path, a referrer domain without its path or query, allowlisted campaign tags, the location of the selected link, and coarse browser or device information supplied by the analytics SDK. OkiPaca does not send website query strings, URL fragments, link text, form contents, email addresses, or account data to PostHog.

Website analytics does not store a PostHog identifier in cookies, local storage, or session storage; does not identify visitors or create person profiles; and does not enable autocapture, heatmaps, surveys, feature flags, session replay, or automatic error capture. PostHog temporarily processes the network IP address, user agent, and hostname to calculate a privacy-preserving identifier that changes daily, then strips the IP address before GeoIP enrichment. This means the same visitor can be counted again on another day. OkiPaca also honors the browser's Do Not Track setting.

The account-confirmation and password-help routes under /auth/ do not load the website analytics client because those routes can carry secure account callback information. If website analytics configuration is missing or invalid, collection remains off.

App product analytics

Product analytics is on by default. If you previously chose or later choose to stop sharing, that opt-out remains in effect unless you turn sharing back on or clear all local app data. At launch, OkiPaca reads the saved Privacy & Data preference before initializing PostHog so an opt-out is honored before product-analytics SDK calls begin. If the preference cannot be loaded or saved, product analytics stays off.

While product analytics sharing is active, OkiPaca uses PostHog for limited product analytics. Analytics events can include onboarding progress, proof type, coarse mission result, paywall steps, purchase or restore result, app version, build number, and a pseudonymous app identity. If you link an account, that analytics identity may be associated with your OkiPaca account identifier; OkiPaca does not send your email address to PostHog. OkiPaca does not send raw QR codes, raw barcode values, raw NFC identifiers, generated QR payloads, camera images, alarm labels, exact alarm times, or support messages to PostHog.

Like most hosted services, PostHog receives the network IP address used to deliver analytics requests and may derive approximate country or region information for analytics and OkiPaca marketing-attribution measurement. OkiPaca does not request your iPhone's Location Services permission for this purpose, does not collect precise location through PostHog, and does not use this information to track you across other companies' apps or websites. Because this product analytics is not used for cross-company tracking, OkiPaca does not request App Tracking Transparency permission for it.

You can see the current status, review what is shared, and select Stop sharing analytics at any time in Settings → Privacy & Data. Stopping sharing prevents future product-analytics calls; it does not remove local Wake History or affect alarm operation. You can select Share analytics there if you later want to resume. To request deletion of analytics that can be associated with a linked OkiPaca account, email privacy@okipaca.com. Anonymous analytics may not be linkable back to an individual.

Crash and error diagnostics

OkiPaca uses Sentry to diagnose crashes, errors, and performance problems. Diagnostic reports can include the app version and build, device and operating-system information, stack traces, limited feature breadcrumbs, and performance timing. Signed-out reports remain anonymous. If you sign in to an optional OkiPaca account, Sentry may receive your OkiPaca user identifier and account email so support can investigate account-specific failures. OkiPaca does not send proof payloads, camera images, alarm labels, exact alarm times, or onboarding answer contents to Sentry.

Email

Signed-in users with an email address may receive account, trial, payment, subscription, and support emails from OkiPaca through Resend. An anonymous purchaser may optionally save a reminder email before purchase for eligible trial and subscription messages; without that optional contact, OkiPaca uses only Apple/App Store subscription communication and in-app or local reminders.

Account deletion

You can request account deletion from the app or from the account deletion page. Deletion removes OkiPaca account records, including linked onboarding responses, and disables future OkiPaca lifecycle emails. To prevent later RevenueCat subscription events from recreating deleted records, OkiPaca retains only one-way hashes of known billing identifiers in a restricted suppression list; it does not retain the original identifiers or billing-event contents in that list. You can also delete only the uploaded onboarding answers from the app. Apple subscriptions must still be managed through Apple.

Contact

Email privacy@okipaca.com for privacy questions.

© 2026 OkiPaca. Built for iPhone.

Privacy Terms Support Subscriptions Account deletion