Overcome: Dopamine Reset for Men

Privacy Policy

Effective Date: 20 March 2026  |  Last Updated: 20 April 2026
This Privacy Policy explains how Overcome collects, uses, stores, and protects your personal data when you use our application on Android (Google Play) or iOS (App Store). By using the app, you agree to the practices described in this document. Please read it carefully.

1. Who We Are

Overcome is a habit-building and dopamine reset mobile application developed and operated by its co-founders as independent developers based in Bengaluru, Karnataka, India. We are not a registered company at this time.

Overcome is not a medical service, therapy platform, clinical treatment, or mental health provider of any kind. It is a habit and behavioural change tool.

For all privacy-related matters:

2. What Data We Collect and Why

We collect only what is necessary to provide the Overcome experience.

2.1 Data You Provide at Account Creation

Data TypePurpose
Email addressTo create and manage your account, send important service communications, and process cashback claims.
Display nameTo personalise your in-app experience. Can be any name — does not need to be your real name.
PasswordTo secure your account. Hashed using industry-standard encryption, never stored in plain text. Managed by Descope.

2.2 Data You Provide During Onboarding

Data TypePurpose
Current streak (days)Self-reported. Used to establish your baseline and personalise your starting point.
Longest streak ever (days)Self-reported. Used to understand your history and set appropriate programme targets.
Primary trigger typeSelected from a fixed list. Used to tailor challenge recommendations to your specific patterns.
Primary goalSelected from a fixed list. Used to personalise your programme structure.

2.3 Data Generated During App Use

Data TypePurpose
Daily challenge completion logsRecorded automatically per challenge per day. Used to track progress, calculate your Clarity Score, and verify cashback eligibility. Immutable — cannot be retroactively edited.
Streak dataCurrent streak, longest streak, and relapse log dates. Core programme tracking data.
Relapse logsDate and dominant emotion selected at time of logging. Optional. Used for self-reflection and Clarity Score depth component.
Clarity Score historyDaily snapshots of your composite progress score. Used to display progress over time.
Wellbeing check-in ratingsOptional daily 1–5 self-rating of energy and clarity. Feeds the Clarity Score depth component.
Badge earn dates and IDsRecords of which badges you have earned and when.
App open timestamps and session frequencyUsed to calculate the consistency component of your Clarity Score and to improve the app.
Device type and OS versionCollected automatically for crash reporting and compatibility.

2.4 Data Collected via Third-Party Services

Data TypePurpose
Authentication data (Descope)Email, display name, and hashed password processed by Descope at account creation and login. Used for identity verification only. Descope has no access to recovery data, streak logs, or challenge completions.
Subscription status and transaction ID (Google Play)Collected when you purchase via Google Play. Used to manage plan access. We do not store payment card details.
Subscription status and transaction ID (RevenueCat)RevenueCat manages subscription state on our behalf. Receives subscription status, transaction IDs, and anonymised app user ID only.
Usage events and crash data (Firebase)Anonymised screen views, session data, and error logs. Used to improve performance and fix bugs.
We never collect your precise location, contacts, photos, microphone input, or any data unrelated to your use of Overcome. We never store information that could publicly identify your engagement with habit recovery content.

3. How Long We Retain Your Data

DataRetention Period
Account and profile dataDuration of active account, plus 90 days after deletion request.
Challenge completion and streak logsDuration of active account. Deleted within 30 days of deletion request.
Relapse logsDuration of account. Deleted immediately upon deletion request.
Wellbeing check-in ratingsDuration of account. Deleted within 30 days of deletion request.
Payment and transaction records7 years as required under Indian accounting and tax law. Cannot be deleted on request.
Firebase analytics dataAnonymised after 14 months per Firebase's standard retention policy.
Support correspondence2 years from the date of last communication.

4. Who We Share Your Data With

We do not sell your data. We do not share your data with advertisers or data brokers. We share data only with the following third parties, to the extent necessary to operate the app:

We may disclose your data to law enforcement if required by applicable law.

We will never share information that reveals your engagement with habit or addiction recovery content with any employer, insurer, advertiser, family member, or third party not listed above.

5. Your Rights Under India's DPDPA 2023

5.1 Right to Access

You may request a copy of all personal data we hold about you within 30 days of your verified request.

5.2 Right to Correction

You may request correction of inaccurate or incomplete data. Most profile data can be updated in-app. For anything else, email us and we will correct it within 14 days.

5.3 Right to Erasure (Account Deletion)

You may request complete deletion of your account and all associated personal data at any time. Account deletion is processed by email only.

How to request account deletion:

  1. Tap "Request Account Deletion" on your Profile Page in the app. This opens a pre-filled email to overcomeapp0@gmail.com.
  2. Send the email without modifying the subject line.
  3. We will confirm receipt within 48 hours.
  4. Your account and all associated data will be permanently deleted within 30 days.

Alternatively, email overcomeapp0@gmail.com directly with subject line "Data Deletion Request" and include your account email address.

What gets deleted: Account data, recovery data, streak logs, relapse logs, challenge completion logs, wellbeing ratings, and badge data.

What is retained: Payment and transaction records are retained for 7 years as required by Indian law and cannot be deleted on request.

Data held by Descope, Firebase, and RevenueCat is subject to their own deletion processes. We will initiate requests with these providers on your behalf.

5.4 Right to Withdraw Consent

You may withdraw consent by requesting account deletion as described in Section 5.3. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

5.5 Right to Nominate

You may nominate another individual to exercise your data rights on your behalf. Email overcomeapp0@gmail.com with subject line "Nominee Registration".

5.6 Grievance Redressal

If unresolved, you may approach the Data Protection Board of India once operationally established under DPDPA 2023.

6. How We Protect Your Data

In the event of a data breach likely to cause harm, we will notify you and relevant authorities within timeframes required by DPDPA 2023.

7. Data Storage and Location

Your personal data is primarily stored on Vultr servers in Mumbai, India, in compliance with DPDPA 2023 data localisation principles.

Firebase (Google) is configured to the asia-south1 (Mumbai) region. Some data may be processed on Google's global infrastructure per Google's data processing terms.

RevenueCat may process subscription data on servers outside India. See revenuecat.com/privacy for details.

Descope processes authentication data on servers in the United States. Your email address and hashed password are transferred to and stored in the United States on account creation and login. Descope maintains SOC 2 Type II compliance. By creating an account, you consent to this transfer. See descope.com/privacy for details.

8. Children's Privacy

Overcome is for users aged 18 and above only. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us immediately at overcomeapp0@gmail.com and we will delete it without delay.

9. Analytics, Tracking, and Cookies

9.1 Firebase Analytics

Anonymised, aggregated usage data — screen views, session length, feature usage. Does not identify you personally. Configured to asia-south1 (Mumbai).

9.2 Firebase Crashlytics

Automatic crash reports including device type, OS version, and error stack traces. Used exclusively to fix technical issues.

9.3 RevenueCat

Subscription lifecycle events (purchases, renewals, cancellations, refunds). No access to recovery data, relapse logs, or onboarding responses.

9.4 Descope

Authentication events (sign-up, login, logout, password reset). No access to in-app recovery data, challenge completions, streak logs, or habit-related content.

9.5 No Advertising Trackers

We do not use advertising SDKs, ad networks, or marketing trackers. We do not serve ads. We do not permit advertisers to access your data.

9.6 Limiting Analytics Collection

Enable "Opt out of Ads Personalisation" in Android device settings (Settings > Google > Ads) to limit Firebase Analytics collection. Does not affect app functionality.

10. Changes to This Privacy Policy

Continued use after changes take effect constitutes acceptance.

11. Contact and Grievances