Privacy Policy
Written from the code rather than from a template. Every claim here is checkable against the app.
Last updated
Wick is a habit tracker for iOS and Android. This policy describes exactly what the app collects, what it deliberately does not collect, and who else sees any of it.
It is written to be specific rather than reassuring. Where something is more identifying than you might expect, it says so.
Who is responsible: Stalin Pereira, trading as iMateFX, India. Under India’s Digital Personal Data Protection Act, 2023, that makes iMateFX the Data Fiduciary for your data and you the Data Principal. Contact, including for any grievance: support-wick@imatefx.com
The short version
- Your habits and your progress sync to Wick’s own server so they survive a new phone. Habit names are stored as you typed them.
- An account is created for you automatically, without an email address, the first time the app syncs. You only give an email if you choose to.
- Usage analytics are limited to six events that carry counts and fixed labels — never your habit names, notes, or check-ins. You can switch this off in Settings.
- Your daily check-in’s energy answer never leaves your device.
- Wick shows no adverts, contains no advertising or attribution SDKs, and sells nothing to anyone.
The account you did not ask for
The first time the app talks to the server, it creates an anonymous account for you. There is no sign-up screen and no email address involved — it exists so that your data has an owner and so the database can keep it separate from everybody else’s.
If you later choose to add an email address (Settings → sign in), we send a one-time code to it and attach it to that same account. The email address is then stored by our authentication provider so you can sign in on another device. That is the only reason we hold it, and it is the only personal identifier the app ever asks for.
If you sign out without having added an email, the account still exists on the server but you can no longer reach it — there is nothing left to prove it was yours. Your device starts a new one.
What is stored on Wick’s server
Wick’s backend runs on Supabase. Every row is scoped to your account by database policy, so one account cannot read another’s data.
Things you wrote:
- Habit names, exactly as you typed them
- The “smaller version” text for a habit, if you set one
- Your reminder anchor text — the “after coffee” note — exactly as you typed it
Things the app derived:
- Which habits you completed, and on which dates
- Your schedules, reminder times or windows, and your device’s time zone
- Day records, quiet periods and returns, the match ledger, and offers the app made you
- The dates you checked in (see below for what is not included)
- Your settings: week start, tone, accent, notification cap, and the accommodation switches
- Whether you have a Pro subscription, once purchasing exists
Things stored by the authentication provider: your email address, only if you added one.
We do not sell, rent or share any of it. Nobody outside the operation of the service sees it.
What never leaves your device
- The energy answer on your check-in — low, okay or good. The app uses it in the same moment to decide how small a next step to offer, and then it stays put. Both apps explicitly send an empty value to the server for this field. A daily self-reported energy level is the most health-adjacent thing this app could keep, so it does not keep it.
- Your analytics preference itself. Whether you opted out is a fact about you, so it is not sent anywhere as an account setting. It stays on each device separately.
- Your theme choice, sound preference, and the queue of changes waiting to sync.
Analytics
Wick uses PostHog (United States region) to understand which parts of the app get used. It is on by default and can be switched off in Settings → “Share anonymous usage data”.
There are exactly six events, and this is all of them:
| Event | What it carries |
|---|---|
| App opened | Nothing |
| Habit created | How many habits you now have — a number, never the name |
| Habit completed | Which surface you used (widget, app, notification, ramp, sync), and whether it was the smaller version |
| Notification delivered | Whether it was a reminder or a return nudge (Android only) |
| Notification actioned | The same label |
| Sync failed | A one-word reason such as “network” or “auth” |
The app is built so that nothing else is expressible: the event type is a closed list in code, there is no way to attach free text, and a check is run before sending that discards anything unexpected.
What is deliberately absent. There is no event for a check-in, and none for progress, streaks, matches, quiet periods or returns. There is no automatic capture of taps or screens, no session recording, no heatmaps, and no console logging. These are switched off both in the app and on the server.
Your identity in the analytics. Events are sent under a random identifier that is not connected to your Wick account. It resets if you reinstall or clear the app’s data — deliberately, because an identifier that survived a reinstall would be a device fingerprint.
Your IP address is visible to PostHog and is used to derive an approximate country. We have not switched this off, and we would rather say so than imply the analytics are more anonymous than they are. It is the most identifying thing in this section.
Crash reports
If the app crashes, a report is sent through the same analytics connection: the type of error, and the list of source files and line numbers involved.
The error message itself is replaced on your device before the report is sent, with a fixed placeholder. Error messages are the one place your habit names could plausibly end up, so they are removed rather than trusted. Switching off analytics switches off crash reports too.
When you send a problem report
Settings → “Report a problem” builds a short diagnostic summary: your app and OS version, how many habits you have (a count), how many changes are waiting to sync, and how long since the last sync. It contains no habit names, notes or check-ins, and there is an automated test that plants a sensitive-looking habit name in a database and proves it cannot reach the report.
You see the whole report before anything happens, and you send it yourself from your own mail app. It is never collected automatically, and it can never be triggered remotely.
Who else is involved
| Who | What for | What they get |
|---|---|---|
| Supabase | Database, sync and sign-in | Everything in “stored on Wick’s server”, plus your email if you added one |
| PostHog | Usage analytics and crash reports | The six events above, the redacted crash reports, and your IP address |
That is the complete list today. There is no advertising network, no attribution or tracking SDK, and no push-notification service — reminders are scheduled by your own device, so no server ever needs to know when to reach you.
When paid subscriptions launch, a payments provider will be added here and this page will be updated before that happens.
Security, stated plainly
Everything travels over HTTPS, and database policies isolate each account’s rows so one account cannot query another’s.
Your sign-in token is currently stored in your device’s standard app-private storage rather than in the operating system’s dedicated secure store. That storage is still private to Wick on a non-compromised device, but it is a weaker guarantee than a keychain, and moving it is planned work. We would rather list it than let you assume otherwise.
Your choices and rights
- Switch analytics off at any time in Settings. It takes effect immediately.
- Turn off any accommodation individually — every one of them is a switch.
- Get a copy of your data, or have it erased. Write to support-wick@imatefx.com, or use the deletion request page.
- Uninstalling removes everything held on that device and resets the analytics identifier. It does not remove what is on the server — use the deletion route for that.
If you are in India, the Digital Personal Data Protection Act gives you the right to access a summary of your data, to have it corrected or erased, to nominate someone to exercise these rights if you die or become incapacitated, and to have a grievance answered. Write to the address above — it is the grievance contact — and if you are not satisfied you may approach the Data Protection Board of India.
If you are in the UK, EU or another region with equivalent law, you also have the right to object to processing, to data portability, and to complain to your data protection authority.
Depending on the choice, our lawful bases are performance of the contract (syncing your habits so the app works), and consent (analytics, which you can withdraw at any time).
Children
Wick is intended for people aged 18 and over.
That is higher than the 13 many apps use, and it is a consequence of where we are: India’s Digital Personal Data Protection Act defines anyone under 18 as a child and requires verifiable consent from a parent before their data may be processed. Wick has no way to verify that, and building one would mean collecting far more about everybody than the app currently does — which would be a strange trade for a habit tracker.
We do not knowingly collect data from anyone under 18. If you believe a child has provided us with data, write to us and we will erase it.
Changes
If this policy changes materially, the date at the top changes and we will note it in the app before the change takes effect. Past versions are visible in the project’s public commit history.