Privacy Policy
Last updated 15 August 2026
DareStake is a two-person accountability app. You and one partner assign each other daily dares; missing a deadline adds a notional fine to a shared tally. This page describes exactly what data that requires, where it is stored, and who can see it.
DareStake is an independent personal project, not a company. There is no advertising, no analytics, no tracking pixels, and no third party is ever sold or given your data for marketing.
What we collect
Account information
When you sign in with Google we receive your name, email address, profile photo URL, and a Google account identifier. We use these to identify your account and to show your partner who you are. We do not receive or store your Google password.
App data you create
- Dares you assign or are assigned — title, optional description, date, deadline, any check-in time, and whether they were completed
- Your pairing — which account you are paired with, and a pair identifier
- Streak counts, number of dares completed, and your running fine total
- Gold Jar entries — the amount and date of each missed dare. This ledger is append-only by design: entries cannot be edited or deleted
- Emoji reactions and disputes raised on a completed dare
- Whether you have enabled notifications
Photo proof (stored in your own Google Drive)
If you attach a photo as proof of completing a dare, DareStake requests the narrow drive.file Google Drive permission and uploads the image to your own Google Drive. The file is not copied to any DareStake server or database — only a reference to it is stored so it can be displayed. The drive.file scope only grants access to files this app itself creates; it cannot read the rest of your Drive. This permission is requested at the moment you first attach a photo, not at sign-in.
What we do not collect
- No payment information. Fines in DareStake are a shared tally, not a transaction. No card, bank, or UPI details are ever requested, and no money moves through the app
- No location data
- No contacts, calendar, or device files
- No analytics, advertising, or cross-site tracking
Who can see your data
Your partner. This is the point of the app. Once paired, your partner can see your dares, whether you completed them, your streak, your fine total, and any photo proof you attach. Do not put anything in a dare title, description, or photo that you are not comfortable sharing with them.
Nobody else. Access is enforced at the database level: every document is scoped to your pair, and requests from outside it are rejected by security rules rather than merely hidden in the interface.
Service providers
DareStake runs on third-party infrastructure:
- Google Firebase (Authentication and Cloud Firestore) — stores your account and app data
- Google Drive API — stores photo proof in your own Drive, only if you use that feature
- Vercel — hosts the application and processes standard web server request logs
Each operates under its own privacy policy. Data is held in Google Cloud regions selected for the Firebase project.
Notifications
Notifications are generated by your own browser through a service worker. There is no push server, and notification content is never sent to a third party. You can revoke the permission at any time in your browser or operating system settings, or turn reminders off in Profile → Notifications.
Retention and deletion
Data persists while your account exists. Unpairing deactivates the pair and clears the link between the two accounts, but retains the dare history and the Gold Jar ledger belonging to that pair.
There is currently no self-service account deletion. To have your account and associated data deleted, email shivansh.goela13@gmail.com from the address you signed up with. Photo proof lives in your own Google Drive, so you can delete those files yourself at any time.
Security
Traffic is served over HTTPS. Authentication is handled by Google, so DareStake never sees your password. Database access is restricted by pair-scoped security rules. That said, this is a personal project rather than an audited commercial service — please treat it accordingly and avoid storing anything sensitive in it.
Children
DareStake is not intended for children under 13, and we do not knowingly collect their data.
Changes
If this policy changes materially, the “last updated” date above will change. Continuing to use the app after a change means you accept the revised policy.
Contact
Questions, or a deletion request: shivansh.goela13@gmail.com