Overcome is a habit-building and dopamine reset mobile application developed and operated by its co-founders, Digvijay Prashant Bhosale and Adari Yashwanth, as independent developers based in Bengaluru, Karnataka, India. We are not a registered company at this time. We intend to incorporate a company to operate Overcome; when we do, this Policy will transfer to that company on the same terms and we will notify you under Section 10 before it takes effect.
Overcome is currently available on Android via Google Play only.
Overcome is not a medical service, therapy platform, clinical treatment, or mental health provider of any kind. It is a habit and behavioural change tool.
For all privacy-related matters:
We collect only what is necessary to provide the Overcome experience.
| Data Type | Purpose |
|---|---|
| Email address | To create and manage your account, send important service communications, and process cashback claims. |
| Display name | To personalise your in-app experience. Can be any name — does not need to be your real name. |
| Password | To secure your account. Hashed using industry-standard encryption, never stored in plain text. Managed by Descope. |
| Data Type | Purpose |
|---|---|
| Current streak (days) | Self-reported. Used to establish your baseline and personalise your starting point. |
| Longest streak ever (days) | Self-reported. Used to understand your history and set appropriate programme targets. |
| Primary trigger type | Selected from a fixed list. Used to tailor challenge recommendations to your specific patterns. |
| Primary goal | Selected from a fixed list. Used to personalise your programme structure. |
| Data Type | Purpose |
|---|---|
| Daily challenge completion logs | Recorded automatically per challenge per day. Used to track progress, calculate your Clarity Score, and verify cashback eligibility. Cannot be edited by you, and not by us to your disadvantage — see Terms of Service Section 5.2 for the narrow technical-fault correction. |
| Streak data | Current streak, longest streak, and relapse log dates. Core programme tracking data. |
| Relapse logs | Date and dominant emotion selected at time of logging. Optional. Used for self-reflection and Clarity Score depth component. |
| Clarity Score history | Daily snapshots of your composite progress score. Used to display progress over time. |
| Wellbeing check-in ratings | Optional daily 1–5 self-rating of energy and clarity. Feeds the Clarity Score depth component. |
| Badge earn dates and IDs | Records of which badges you have earned and when. |
| App open timestamps and session frequency | Used to calculate the consistency component of your Clarity Score and to improve the app. |
| Device type and OS version | Collected automatically for crash reporting and compatibility. |
| Data Type | Purpose |
|---|---|
| Authentication data (Descope) | Email, display name, and hashed password processed by Descope at account creation and login. Used for identity verification only. Descope has no access to recovery data, streak logs, or challenge completions. |
| Subscription status and transaction ID (Google Play) | Collected when you purchase via Google Play. Used to manage plan access. We do not store payment card details. |
| Subscription status and transaction ID (RevenueCat) | RevenueCat manages subscription state on our behalf. Receives subscription status, transaction IDs, and a pseudonymous app user ID only — no name, email, or recovery data. |
| Usage events and crash data (Firebase) | Screen views, session data, and error logs, together with a Firebase app instance ID and device identifiers. This data is pseudonymised, not anonymous — it is not labelled with your name or email, but it can be traced back to your device and therefore to you. Used to improve performance and fix bugs. |
Founder's Chat is a private text channel between you and the Overcome founding team. It is a conversation between you and us only — it is not a channel between you and another user, and no other user can see any part of it.
Who can read your messages: you, and the founding team. Nobody else. Founder's Chat runs on infrastructure we operate ourselves, no third-party messaging provider is involved, and no third party receives the content of your messages.
| Data Type | Purpose |
|---|---|
| Message content | The free text you write to the founding team, and the replies sent to you. Stored on our own servers and readable by the founding team. Used only to respond to you, to operate and improve the app, and to enforce our Terms of Service. |
| Message metadata | Timestamps for when a message was sent, delivered, and read, message ordering, and the account the conversation belongs to. |
| Display name and account email | Shown to the founding team within the chat so we can identify you and reply. Your display name does not need to be your real name. |
| Push notification token | Your device token, used solely to notify you when a reply arrives. You can disable chat notifications in your device settings. |
Two further features are planned and are not available today. Neither collects any data at present. We are describing them here so the change is not a surprise, and this Policy will be updated with full detail, and notice given under Section 10, before either goes live.
Your Clarity Score is calculated automatically by the app, without human involvement, from your streak length, challenge completions, lifestyle inputs, and consistency of app use. It is displayed to you as a progress indicator.
Your weekly completion status is also recorded automatically, from your in-app challenge logs measured against the thresholds shown in the app. This one does carry a financial consequence: it determines whether you qualify for the Cashback Guarantee.
Human review. If you believe an automated calculation has recorded something other than what you actually did, you can ask a person to look at it. Email overcomeapp0@gmail.com with the subject line "Log Correction Request". A co-founder will review the underlying records and correct them where a technical fault is confirmed. If a cashback claim has already been rejected, the appeal route in Terms of Service Section 5.9 applies.
| Data | Retention Period |
|---|---|
| Account and profile data | Duration of active account. On a deletion request: removed from live systems within 30 days, and from backups within 90 days. |
| Challenge completion and streak logs | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. |
| Relapse logs | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. |
| Wellbeing check-in ratings | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. |
| Clarity Score history | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. |
| Badge earn dates and IDs | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. |
| Founder's Chat messages | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. This includes the copy held in the founding team's view of the conversation. |
| Push notification tokens | Until you disable notifications, uninstall the app, or your account is deleted. Removed within 30 days of a deletion request. |
| Device type, OS version, and session timestamps | Duration of active account. On a deletion request: live within 30 days, backups within 90 days. |
| Firebase analytics data | Retained for up to 14 months under Firebase's standard retention policy. On a deletion request we submit a deletion instruction to Firebase for your app instance identifier; Google's own processing timelines then apply. |
| Payment and transaction records | 7 years as required under Indian accounting and tax law. Cannot be deleted on request. |
| Support correspondence | 2 years from the date of last communication. |
We do not sell your data. We do not share your data with advertisers or data brokers. We share data only with the following third parties, to the extent necessary to operate the app:
We may disclose your data to law enforcement if required by applicable law.
Founder's Chat message content is not shared with any of the parties listed above. It is stored on infrastructure we operate and is readable only by you and the founding team. DigitalOcean hosts the server but does not access message content. If this ever changes — for example when Recovery Mentor Chat launches and a mentor becomes a recipient — we will update this Policy and notify you under Section 10 before it takes effect.
You may request a copy of all personal data we hold about you within 30 days of your verified request.
You may request correction of inaccurate or incomplete data. Most profile data can be updated in-app. For anything else, email us and we will correct it within 14 days.
You may request complete deletion of your account and all associated personal data at any time. Account deletion is processed by email only.
Alternatively, email overcomeapp0@gmail.com directly with subject line "Data Deletion Request" and include your account email address.
Data held by Descope, Firebase, and RevenueCat is subject to their own deletion processes. We will initiate requests with these providers on your behalf.
You may withdraw consent by requesting account deletion as described in Section 5.3. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You may nominate another individual to exercise your data rights on your behalf. Email overcomeapp0@gmail.com with subject line "Nominee Registration".
If unresolved, you may approach the Data Protection Board of India once operationally established under DPDPA 2023.
In the event of a data breach likely to cause harm, we will notify you and relevant authorities within timeframes required by DPDPA 2023.
Your personal data is primarily stored on Vultr servers in Mumbai, India, in compliance with DPDPA 2023 data localisation principles.
DigitalOcean hosts the Founder's Chat service. Your message content and chat metadata are stored on DigitalOcean servers located in India, in line with the same DPDPA 2023 data localisation principles that apply to the rest of your data. Founder's Chat message content is not transferred outside India.
Firebase (Google) is configured to the asia-south1 (Mumbai) region. Some data may be processed on Google's global infrastructure per Google's data processing terms.
RevenueCat may process subscription data on servers outside India. See revenuecat.com/privacy for details.
Descope processes authentication data on servers in the United States. Your email address and hashed password are transferred to and stored in the United States on account creation and login. Descope maintains SOC 2 Type II compliance. See descope.com/privacy for details.
Under the DPDPA 2023, consent must be free, specific, informed, unconditional, and given by clear affirmative action. We therefore ask you to consent to this transfer separately, at the point of sign-up, by an explicit action — not by your continued use of the app and not by acceptance of this Policy as a whole. You can withdraw that consent at any time under Section 5.4, though because authentication depends on Descope, withdrawing it means we can no longer maintain your account.
India does not currently restrict transfers of personal data to the United States. Section 16 of the DPDPA operates on a restricted-country basis, and the United States is not a restricted country at the date of this Policy.
Overcome is for users aged 18 and above only. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us immediately at overcomeapp0@gmail.com and we will delete it without delay.
Pseudonymised usage data — screen views, session length, and feature usage, recorded against a Firebase app instance identifier. It does not carry your name or email address, but it is not anonymous: it can be linked back to your device and therefore to you, and it is treated as personal data under this Policy. Configured to asia-south1 (Mumbai).
Automatic crash reports including device type, OS version, device identifiers, and error stack traces. Used exclusively to fix technical issues. Like Firebase Analytics, this data is pseudonymised rather than anonymous.
Subscription lifecycle events (purchases, renewals, cancellations, refunds). No access to recovery data, relapse logs, or onboarding responses.
Authentication events (sign-up, login, logout, password reset). No access to in-app recovery data, challenge completions, streak logs, or habit-related content.
We do not use advertising SDKs, ad networks, attribution SDKs, or marketing trackers. We do not serve ads inside Overcome. We do not permit advertisers to access your data. No advertising company is told that you installed Overcome, opened it, or paid for it.
When we advertise Overcome, we do so by paying for clicks on a link to our Google Play listing. Nothing is installed in the app to report back, and the advertising platform is not told what happened after the click.
We want to be accurate about what the available controls actually do.
We are working on an in-app toggle to switch analytics off. When it exists, we will update this Section.
Continued use after changes take effect constitutes acceptance.