Holdout

Privacy policy

Effective 6 October 2026. Holdout is made by Gautam Khosla, Ottawa, Ontario, Canada ("we").

The short version

What we collect and why

DataWhyKept
Your phone's public key and an ID derived from itTo check that requests really come from your phone (no passwords exist)Until you delete or 180 days unused
Display name and spark color you chooseSo your squad knows who's whoSame
Squads you create or join, their names and invite codesThe core featureUntil the last member leaves
Holdout events: started, joined, escaped, ended early, held, with timesYour squad's streak, history and share cardsWith the squad; your name is removed if you delete your account
Sparks, skins, plan remindersRewards and remindersUntil you delete
Holdout+ purchase: product, expiry, and a one-way hash of Google's purchase tokenTo confirm your purchase with Google PlayUntil you delete
Reports and blocks you makeSafety and moderationUntil resolved or you delete
Beta sign-up email (website only, with your consent)To send the beta invite and launch newsUntil you ask, or 30 days after public launch
A daily, salted hash of your IP addressRate limiting against abuse. The IP itself is never storedMinutes to one hour

What stays on your phone

The list of apps you choose to keep closed, which app is in front during a holdout, your settings, and the private half of your key (held in Android's secure keystore, never exportable). The app turns off Android backup so none of this is copied off your phone.

The Accessibility Service

Holdout asks you to turn on an Android Accessibility Service, with a full explanation first. It listens only for "a different app came to the front" and reads only that app's package name. It cannot read your screen, your messages or what you type (it is configured without access to window content). It does nothing outside a holdout you started or joined. Your squad learns only that you ended a holdout, never which app you opened.

Who processes data for us

We do not sell personal information and do not share it for cross-context advertising.

Your rights

Under Canada's PIPEDA, and laws such as the GDPR and California's CCPA where they apply, you can ask to access, correct or delete your data, and to withdraw consent. Most of this is built in: edit your name in the app, and use Settings › Delete my data to erase your account immediately. For anything else, or to remove a beta email, write to us below. We answer within 30 days. You can also complain to the Office of the Privacy Commissioner of Canada or your local authority.

Children

Holdout is not directed to children under 13 and we do not knowingly collect their data. If you believe a child under 13 is using it, contact us and we will delete the account.

Security

Every request is signed by a key that never leaves your phone and expires after 5 minutes, so it can't be replayed. Traffic is HTTPS only. The server stores no passwords, no IP addresses and no purchase tokens in readable form, and inputs are strictly validated. If we ever learn of a breach affecting you, we will notify you and the regulator as the law requires.

Changes

We'll post changes here with a new date, and tell you in the app if they matter.

Contact

Gautam Khosla, Ottawa, Ontario, Canada · developwith.gt@gmail.com