DebtBoss — iOS App

DebtBoss Privacy Policy

Last updated: 8 July 2026

1. Who we are

Bashboundgames Ltd ("we", "our", "DebtBoss") is a company registered in England and Wales (Company No. 15410686). We build the DebtBoss mobile app, which helps you pay off debt using game mechanics.

Contact: privacy@bashboundgames.com

DebtBoss is a planning and motivation tool. All figures in the app are illustrative estimates based on information you enter — DebtBoss does not provide financial advice, does not connect to your bank, and never touches your money.

2. What data we collect

CategoryExamplesPurpose
Account dataEmail address, password (hashed), optional nickname and avatar choiceAuthenticate you; sync your data across devices
Debt data (entered by you)Debt nicknames, balances, interest rates, minimum payments, due dates, promotional rate detailsThe core features of the app (progress tracking, projections, quests)
Activity dataPayments you log in the app, quests completed, streaks, XP, achievements, planned one-time boosts, your motivation noteShow your progress, calculate estimated interest saved, personalise quests and recaps
Purchase dataSubscription status and transaction identifiers (via Apple and RevenueCat)Unlock premium features; restore purchases. We never see your card details — payment is handled entirely by Apple.
NotificationsA device push token, if you enable notificationsDeliver payment reminders and quest alerts you have turned on
Device dataDevice model and OS version, where provided by Apple's standard crash and diagnostics reporting (only if you have opted in to sharing diagnostics with app developers in your iOS settings)Fixing crashes and bugs

What we do not collect: we do not connect to your bank accounts, we do not perform credit checks, we do not access your contacts, location, or photos, we do not use third-party advertising or tracking SDKs, and we do not sell your data to anyone.

Guest mode: if you use the app without creating an account, your data is stored only on your device. It is uploaded to our servers only if you later create an account and choose to keep that data.

3. How we use your data

  • Provide the app's features: debt tracking, payoff projections, quests, achievements, and progress history
  • Send notifications you have enabled (you can turn these off at any time in Settings or iOS Settings)
  • Generate AI coaching responses when you use the AI features (see section 5)
  • Process subscriptions and restore purchases
  • Maintain security and comply with legal obligations

We never sell your data and we do not show ads.

PurposeLegal basis
Operating the app and syncing your accountContract — we need this data to deliver the service
Push notificationsConsent — you enable them, and can disable them at any time
AI coaching featuresContract / consent — data is only sent when you actively use the feature
Subscription billingContract and legal obligation
Security and abuse preventionLegitimate interest

5. Third parties we use

ServiceWhat they receiveWhereNotes
Supabase (database and authentication)Your account and app dataUnited Kingdom (London region)Our primary data store. Data is encrypted at rest and in transit.
OpenAI (AI features)When you use the AI debt wizard or AI coach: your debt details (nicknames, balances, rates, payment amounts) needed to generate a response. Your email address and account identifiers are not sent.USATransfers are protected by Standard Contractual Clauses. OpenAI does not use API data to train its models. Tip: debt nicknames are visible to the AI feature, so avoid putting personal details in them.
RevenueCat (subscription management)Purchase receipts and an app user identifierUSAStandard Contractual Clauses.
ApplePayment processing, and crash/diagnostic data if you opted in via iOSGoverned by Apple's own privacy policy.
Expo (push notifications)Your device push token, if notifications are enabledUSAStandard Contractual Clauses.

Each provider is contractually bound to protect your data to GDPR-equivalent standards. We do not use any third-party analytics or advertising services.

6. How long we keep data

  • Account and app data: until you delete your account. Deleting your account (Settings → Delete Account) permanently and immediately removes your account, debts, payments, achievements, and all other personal data from our systems. This cannot be undone.
  • Subscription and transaction records: held by Apple and RevenueCat under their own retention policies; we retain minimal transaction records only as long as required for accounting and legal purposes.
  • Server logs: short-lived operational logs are retained by our infrastructure providers for a limited period for security and debugging.

7. Security

  • Encryption in transit (TLS) and at rest
  • Row-level security: our database is configured so each user's records can only be read or changed by that user
  • Least-privilege access controls on our systems

No system is perfectly secure, but we design the app so that we hold the minimum data needed to run it.

8. Your rights (UK GDPR / Data Protection Act 2018)

You may:

  • Access, correct, or delete your data — most of this is self-service in the app (edit any debt or payment; Settings → Delete Account), or email us
  • Request a copy of your data in a machine-readable format
  • Withdraw consent for notifications at any time in Settings
  • Complainto the UK Information Commissioner's Office (ico.org.uk) if you believe we have mishandled your data

We respond to requests within one month.

9. Children

DebtBoss is not directed at children under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.

10. International transfers

Your data is stored in the United Kingdom. Where a feature sends data outside the UK (OpenAI, RevenueCat, and Expo in the USA), we rely on Standard Contractual Clauses and send only the minimum data the feature needs.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the app and take effect 30 days after posting.

12. Contact