Oathly Privacy Policy

How Midknight Entertainment Ltd handles your information in the Oathly app.

Effective date: 12 August 2026 · Last updated: 6 September 2026

Material change, 6 September 2026. The app now includes one growth measurement tool, Layers, which counts how the app is used so we can see whether people come back. It is named in section 13 alongside every other company we work with, and the two places that previously said the app contained no analytics software have been corrected rather than left standing. What it receives is its own automatic events, a random identifier the app generates for the install, your device type and your operating system version. It is never given your email address, your display name, a pact title, a stake, a note or a photograph. Nothing else in this policy has changed, and nothing in it has weakened.

This policy applies to Oathly (“the app”), published by Midknight Entertainment Ltd (“we”, “us”, “our”). It replaces our general company privacy policy for this app, because Oathly works differently from our other apps: it has accounts, it stores your information on our servers, and it shows what you post to the friends you invite. Where the two policies differ, this one governs Oathly.

The one thing to understand before you start. Oathly is a shared app. A pact has other people in it, and everything you put into a pact (your display name, your check-ins, your photographs, your notes, what you owe and to whom) is shown to the other members of that pact. That is the entire point of the app: someone else is watching whether you kept your promise.

We cannot take that back for you. Once another member has seen a photograph, deleting it removes it from our systems, not from their memory or from any screenshot they took. Only put things in a pact that you are content for those people to see.

1. Who we are, and the law that applies

Midknight Entertainment Ltd is a company incorporated in the Province of Nova Scotia, Canada.

The law that governs how we handle personal information is Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to personal information that a private-sector organization collects, uses or discloses in the course of commercial activities. Nova Scotia has no private-sector privacy statute of general application, so PIPEDA is the law that applies to us.

PIPEDA works through ten fair information principles, and the first of them is accountability: we are responsible for the personal information under our control, including information we hand to someone else to process for us, and one person in the company is designated as accountable for our compliance: our Privacy Officer. You can reach them by emailing support@midknightltd.com, or by post at the address in section 21.

2. The short version

3. Your account

Oathly cannot work anonymously. A pact is an agreement between named people who need to recognize each other, and it has to survive you reinstalling the app, so it needs an account.

There are up to three ways to sign in, depending on your device:

After signing in for the first time you choose a display name and an emoji, pre-filled with your Apple name if you shared one, and editable before you continue. These are what other members of your pacts see. You may use a nickname; nothing checks whether it is your real name, and we would rather you used whatever you are comfortable with your friends seeing.

We do not ask for, and have no field for, your phone number, date of birth, address, gender or photograph of your face. There is no contacts permission and we never read your address book. Invitations work by you sending a link yourself, through whatever app you like.

4. What we collect, and why

WhatWhyWhere it goes
Your email address (or Apple relay address, or the email on your Google account if you use Google to sign in) and an account identifier. To sign you in, to keep your pacts attached to you across devices and reinstalls, and to contact you about your account or a safety matter if we have to. Stored on our servers, held by our hosting provider (section 13). Not shown to other users.
Your display name and emoji. So the other members of a pact know who checked in. Stored on our servers, and shown to people who share a pact with you.
Pacts you create or join: title, emoji, how often you have to check in, how long it runs, and the stake you wrote. It is the content of the app. Stored on our servers, and shown to the members of that pact.
Check-ins: the time, an optional note you type, and an optional photograph. To prove to the other members that you did the thing, and to work out your streak. Stored on our servers, and shown to the members of that pact. Photographs have their hidden metadata, including any location, removed on your phone before upload. We intend to delete each photograph 90 days after upload once the deletion job is scheduled; until then the image remains with the check-in (section 5).
Approvals: that you accepted or rejected someone else's check-in. It is how a pact decides whether proof counts. Stored on our servers, and shown to the members of that pact.
Forfeits and IOUs: that a period was missed, and the description of what you agreed you owe. To keep the shared record the pact is built on. Stored on our servers, and shown to the members of that pact. See section 7.
A push notification token for each device you sign in on. So we can tell you that a partner checked in, approved your proof, or missed a day, and send reminders you asked for. Collected by OneSignal when you opt in (section 8). We no longer store tokens on our own servers. Never shown to other users.
Reports and blocks you make. To review what you reported, act on it, and keep someone you blocked away from you. Stored on our servers, readable by us. See section 9.
Subscription state, held by our subscription-management provider against your Oathly account id, and a yes/no copy of it (whether Pro is currently active) stored on our own server against your account. To know whether the paid features are unlocked (on your device, and, for features we enforce on our server such as a group pact with three or more people, on our server too) and to make “restore purchases” work. Apple or Google take the payment; our subscription provider records the entitlement and tells our server whenever it starts, renews or ends. We never see or hold card or payment details. See section 10.

Your settings and preferences (which reminders you set, whether you have finished onboarding, your chosen reminder hour) are kept in the app's own private storage on your device. The reminder hour is also stored on our servers, because it belongs to your membership of a pact.

5. Proof photographs in detail

A check-in can include a photograph. This is the most sensitive thing the app handles, so it is worth being precise.

A photograph still carries more than what you pointed the camera at. Removing the hidden metadata does not change what is actually in the picture: faces of people who did not agree to be in it, documents, screens, an address on an envelope, a view out of a window that someone recognises.

We cannot strip that, because it is the photograph. The members of your pact will see whatever you point the camera at, so point it at the thing you promised to do and not at anything else.

6. What other people can see

Being seen is the mechanism of the app, so this is the section to read twice.

People who share a pact with you can see: your display name and emoji; every check-in you make in that pact, including your notes and photographs; whether you approved or rejected their check-ins; every period you missed; what you owe as a result and whether it is settled; your streak; and when you used a Streak Repair to cancel a miss, which is shown to them as having been repaired rather than hidden. If either of you has blocked the other, the blocked person's active membership in that pact ends immediately, on the server. Losing that membership means the blocked person loses all access to that pact through the app. That includes not only the other member's check-ins and photographs, but their own as well, because what the app checks before showing you anything is whether you are still an active member of that pact, not who took the photograph. The person who did the blocking keeps their own membership and their own content, and in turn cannot see the blocked person's check-ins, photographs or profile through that pact. The historical rows remain on our servers so nothing is silently destroyed, but neither of you can read the other's rows through the app any more, and the removed person cannot read their own former rows in that pact either. A proof link issued before the block can continue to work only until its short expiry, which is no more than ten minutes. Removing the block afterward does not undo any of this. The membership that ended stays ended, and being in a pact with that person again would mean starting a new one.

Leaving a pact yourself ends your membership immediately, through the same mechanism a block uses. The moment you leave, you lose access to that pact through the app, including your own past check-ins and photographs in it, for the same reason as a block: access follows active membership, not who created the row. But leaving is not permanent the way a block is. If you leave a pact voluntarily, and there is no block between you and anyone still in it, a fresh invitation link to that same pact lets you rejoin it, and rejoining restores your membership and your access to everything in that pact, including what you posted before you left. A block does not work this way: once a block has ended someone's membership in a pact, no invitation link, old or new, can bring them back into that specific pact, and removing the block afterward does not change that.

People who share a pact with you cannot see: your email address; your pacts with anyone else; your ledger with anyone else; or anything about the device you use.

Someone holding an invitation link, who is not yet a member, can see only the pact's title, emoji, how often it requires a check-in, how many people are in it, and the display name of whoever invited them. The stake is deliberately not shown until they join, because an invitation link ends up in group chats and screenshots and a stake is meant to be embarrassing.

We do not publish anything. There is no public profile, no discoverable directory of users, no feed of strangers, and no way to search for a person. The only route into a pact is a link somebody sent you. You cannot look up another user's profile unless you already share a pact with them. That restriction is enforced on the server, not just hidden in the app.

7. Forfeits and the IOU ledger

When you miss a period, the app records a forfeit and writes what you agreed you owe into a shared ledger: “two coffees to Sam”, or whatever the two of you wrote when you made the pact.

Oathly is a notebook, not a payment service. It does not take, hold, transfer, escrow or process money, and it is not connected to any bank account, card, wallet or payment network for this purpose. The figures in the ledger are text that you and your friend agreed on. Marking an IOU as settled records that you say it is settled; it moves nothing.

Anything actually owed is settled between the two of you, outside the app, by whatever means you like. We are not a party to it, we cannot enforce it, and we take no cut of it.

Because a debt has two ends, an IOU is visible to both people named in it, and marking it settled is recorded against whoever did the marking.

8. Notifications

Oathly sends two different kinds of notification, and they are worth telling apart.

The app asks before it turns any of this on, and explains what it is for. You can turn notifications off in the app's Settings, or in your phone's settings, at any time. When you turn them off in the app, or sign out, we tell OneSignal to stop targeting your account from that device.

Reminders you set are capped at three per day and are not sent between 22:00 and 08:00 your local time. Notifications caused by another person acting are not capped, because suppressing them would break the thing the app is for, but they only ever happen because a member of one of your pacts did something.

We do not send marketing or promotional notifications, email or text messages of any kind. Canada's Anti-Spam Legislation (CASL) governs commercial electronic messages; the messages Oathly sends are the service you asked for, not commercial electronic messages, and we send no marketing.

The wording of a notification is chosen by our server from a fixed list. Another user cannot make the app send text of their choosing to your phone.

9. Reporting, blocking and moderation

Oathly shows you content created by other people, so it has to have a way to deal with content that should not be there.

Reports are kept until you delete your account, or until a person reviewing them deletes the row. There is no automatic purge of reports after a fixed number of days.

10. Purchases and subscriptions

11. What we do not collect or do

Stated plainly, because these are choices we made and intend to keep:

About IP addresses. Our own application code does not read or record your IP address. An IP address is a necessary part of any internet connection, so our hosting provider processes it in order to route your request and protect the service from attack. It does that as a service provider acting for us, and we do not use it to identify or track you.

PIPEDA requires us to identify the purposes for which we collect personal information and to obtain your consent. This is how consent works in Oathly:

WhatHow consent is given
Your email address and accountYou give it, deliberately, in order to sign in. Without it the app cannot function.
Your display name, pacts, check-ins, notes and photographsYou type or take each one and press a button to submit it, knowing, because the screen says so, that the members of the pact will see it.
Proof photographsExpress consent, twice over: the operating system's camera permission, after the app has explained why it wants it, and then your choice to submit that particular photograph.
Push notifications and push tokenExpress opt-in. The app explains what the notifications are for before asking, and you can withdraw at any time in Settings.
Reports you makeYou choose to report, having been shown what the report is for.
Keeping the service secure, applying free-plan limits, and preventing abuseImplied consent, for a purpose a reasonable person would consider appropriate: a shared social app has to be able to defend itself and its users.

You can withdraw your consent at any time, subject to legal and contractual restrictions and on reasonable notice. In practice: turn off notifications, revoke the camera permission, leave a pact, or delete your account (section 15). The consequence of withdrawing is that the feature concerned stops working. Because Oathly cannot operate without an account, withdrawing consent to hold your account means deleting it.

One limit we cannot get around: withdrawing consent does not remove what you already showed to other people. Deleting your account removes your rows and your photographs from our systems, but a person who already saw a photograph has already seen it.

13. Who else is involved

We keep the list short on purpose. Each of these processes information for us, under contract, and is not free to use it for its own purposes:

Beyond those, we may disclose personal information where the law requires it (a court order, a lawful demand from a public authority) or where it is necessary to protect someone from serious harm, or to establish or defend a legal claim. If a lawful demand is broader than it needs to be, our practice is to say so and to give only what is required.

If our business or a part of it were ever sold or reorganized, information could be transferred as part of that, and the recipient would be bound by this policy or one materially the same. We would say so here first.

Handing personal information to one of these organizations to process for us is a transfer for processing, not a disclosure to a new owner of it. Under PIPEDA's accountability principle the information stays our responsibility while they hold it.

We do not sell personal information, and we do not share it for advertising or marketing by anyone.

14. How long we keep things

WhatHow long
Proof photographsIntended 90 days from upload, then the image deleted and the check-in record kept. The deletion job is written and is not yet running; until it is, photographs remain until you delete your account.
Your account, profile, pacts, check-in records, forfeits and IOUsUntil you delete your account. This is a record shared with other people, so we do not expire it while you are still using the app.
Push tokensHeld by OneSignal, not by us. They are removed when you sign out, turn notifications off, or delete your account. OneSignal also removes a token if it becomes invalid.
ReportsUntil you delete your account, or a person reviewing them deletes the row. There is no automatic 90-day purge.
BlocksUntil you remove the block, or delete your account. Removing a block does not restore a membership that already ended. See section 6.
Subscription state held by our subscription-management provider, against your Oathly account idFor as long as the entitlement needs to be restorable, then in line with that provider's own retention policy.
The yes/no Pro flag we store ourselvesUntil the next entitlement change updates it, or until you delete your account, it lives on your account row and is removed with everything else in section 15.
Server logsAt most 7 days, the fixed maximum of the platform we use, not a setting of ours.

The 90-day photograph limit is the cutoff the deletion job will apply once a schedule is installed. Until that schedule exists, the cutoff is configuration, not a running process.

15. Deleting your account

There is a Delete account button in the app's Settings. It is not a request form and it does not email us. It deletes the account. You are asked to confirm twice, because it cannot be undone.

When you delete your account we remove: your profile and display name, your sign-in credentials, every photograph you uploaded, your check-ins and notes, your approvals, your memberships of pacts, your forfeits, your IOUs, your reports, your blocks, and your push tokens.

Two consequences worth knowing before you press it.

First, your IOUs disappear from your friends' ledgers as well as your own, because each one is a record about both of you. Anything genuinely owed is a matter between you and them, outside the app.

Second, deleting your account does not cancel a paid subscription. Only your Apple or Google store account can do that. Cancel it there first, or you will keep being charged.

You can leave an individual pact at any time without deleting your whole account. See section 6 for exactly what that does and does not remove. There is no way today to delete a single check-in on its own; the only way to remove one is to delete the whole account.

Can't get into the app to press the button? Use our web deletion-request page, or email adrian@midknightltd.com from the address you signed up with, with the subject “Delete my Oathly account”. We handle a request made this way the same as any other, within 30 days, as section 18 commits to.

16. Sending information outside Canada

Some of the organizations we rely on operate internationally, and processing takes place in the United States and in other countries where our service providers operate. That includes where your proof photographs are stored.

PIPEDA does not forbid sending information to other countries. Unlike some other privacy laws, it has no list of approved countries and no standard transfer contract. Its rule is the accountability principle: we stay responsible for your information after we hand it to a provider, wherever that provider processes it, and we must use contracts or other measures to give it protection comparable to the protection it has with us.

You should know that while information is in another country it may be accessible to the courts, law enforcement and national security authorities of that country under that country's law.

17. Security, and what we do if there is a breach

No system is perfectly secure, and we will not pretend otherwise. PIPEDA requires us to keep records of breaches of security safeguards, to report a breach to the Office of the Privacy Commissioner of Canada where it creates a real risk of significant harm, and to notify affected individuals in that case. We will do so without unreasonable delay, and we will tell you plainly what happened and what you should do.

18. Your rights, and how to challenge us

Under PIPEDA you have the right to:

To protect you, we have to be satisfied that a request is really from you before we act on it, so we will ask you to write from the email address on the account.

Being honest about what the law gives you: PIPEDA gives rights of access, correction and challenging compliance. It does not give a general statutory right to erasure, portability, restriction or objection of the kind some other laws do. We nonetheless offer deletion, in the app and on request, as our practice, and Apple requires it of any app with accounts. We would rather tell you the difference than let you believe you are relying on a statutory right you do not have here.

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada: priv.gc.ca, 1-800-282-1376. Nova Scotia's provincial commissioner has no jurisdiction over a private company's commercial activities, so the federal office is the right one.

19. Children

Oathly is not directed at children and is intended for people aged 13 or over. It is rated accordingly. We do not knowingly collect personal information from children under 13.

If you believe a child under 13 is using the app, tell us at support@midknightltd.com and we will delete the account and its content. Because the app shows user-created photographs to other users, we treat this as a safety matter and act quickly.

If you are between 13 and the age of majority where you live, please read this policy with a parent or guardian, and think carefully about what you photograph and who you agree a pact with.

20. Changes to this policy

We may change this policy when the app changes or the law does. The “last updated” date at the top always tells you when it last changed.

If a change is material (if we begin collecting something new, use your information for a genuinely new purpose, add a service provider that holds your content, or change how long we keep photographs) we will say so prominently at the top of this page, and in the app, before the change takes effect, and where PIPEDA requires fresh consent for a new purpose we will ask for it rather than assume it.

21. Contact

Midknight Entertainment Ltd, Province of Nova Scotia, Canada.

Privacy Officer: support@midknightltd.com

For anything in this policy, a request about your information, a complaint, or to report content or a safety concern, use that address. We answer access and deletion requests within 30 days.