Privacy
Controller and scope
QW Studio LLC, a limited liability company formed in New Mexico, United States, on September 9, 2026. Articles of Organization filed with the New Mexico Secretary of State under file number 3298885. Principal business address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States. Contact: devqwiet@outlook.fr.
This notice covers the website, its waitlist and the native Uncap V2 apps for iOS and Android. Updated: 3 October 2026.
App account and programme
Sign-in uses a one-time email code sent through Resend on iOS and Android; Apple sign-in is also available on iOS. We process your Apple sign-in identifier or email address, plus the account and session identifiers needed for authentication. Uncap does not ask for a password. Email codes expire after ten minutes.
Questionnaire answers stay on your device before programme activation. At activation, your first name, declared age, chosen identity, goals and habit answers are sent to the server to build the programme. Your profile, nickname, personalised rules, time zone, arcs, daily completions and XP are stored to synchronise progress between devices.
The V2 flow does not request a portrait or an artificial-intelligence analysis and does not send this data to an AI provider. The focus timer and reminder preferences stay local. Reminders use your device’s notification permission where required; on iOS, widgets display a cache of your progress on your device.
Declared age and private profile
The Uncap programme is intended for people aged 13 and over. The age you declare in the questionnaire is sent to the server to determine your age group. The server retains the 13–14 or 15-and-over age group and the declaration date, without retaining the exact age from the questionnaire. We do not ask for your date of birth. This is a declaration, not identity-document verification of your age.
At ages 13 or 14, your profile stays private: the public leaderboard, score sharing with friends, adding new friends and new referrals are unavailable. An account with an unknown age group also stays private. From a declared age of 15, public leaderboard sharing and sharing with friends each require your explicit choice and acceptance of the current social rules. Every new age declaration resets both choices and that acceptance. Time passing never activates sharing automatically, and previous sharing choices are not automatically restored.
Leaderboard, friends and sharing
For eligible accounts aged 15 and over, the public leaderboard is optional: your chosen nickname and XP are visible when you agree to this sharing in the app. Sharing with friends requires a separate explicit choice. Before publishing a nickname visible to other people, you must also accept the terms and publishing rules. You can change or disable sharing at any time in profile settings and continue your private programme. The service stores the version and date of acceptance of the social rules and your visibility choices. It also stores friend relationships and referral information needed to calculate bonuses. Existing relationships remain accessible in settings to remove, block or report a friend, even if your profile becomes private; this list displays neither rank nor XP and uses an alias when the nickname can no longer be shared.
Data exports and progress images are shared with your chosen apps or people only when you initiate sharing on your device.
You can report or block a person from the leaderboard or friends list by pressing and holding their row or using its menu. Blocking hides your rows from each other in these areas without changing XP. Manage blocked people in settings. A report stores your account ID, the reported account ID, the displayed nickname, the reason, optional details, dates and review status. These details are not published and are used to review abuse. Reports are scheduled for deletion after 90 days, or when either account is deleted.
Purchases and security
Apple handles App Store payments on iOS; Google handles Google Play payments on Android. RevenueCat and our server process pseudonymous customer identifiers, transaction references or purchase tokens, purchased products, their environment and access status to verify purchases, restorations, expiry and refunds. We do not receive your payment-card details.
RevenueCat retains the transaction country or, if unavailable, a country derived from the last-seen IP address, plus the last connection time to its servers. This information and purchases feed revenue, country and active-user statistics. According to its documentation, RevenueCat discards the IP address after deriving the country. Uncap does not request GPS location.
Apple App Attest on iOS and Google Play Integrity on Android, installation identifiers, cryptographic proofs, technical counters and rate limits protect accounts, prevent purchase reuse and limit abuse. Session secrets are stored in the iOS Keychain or encrypted with a key protected by Android Keystore. A local cache displays previously synchronised data offline.
App service providers and hosting
Cloudflare Workers and D1 host the service and synchronised data. Apple supplies Apple sign-in, App Store purchases and App Attest on iOS; Google supplies Google Play purchases and Play Integrity on Android; RevenueCat verifies purchase entitlements; Resend receives the destination address and message needed to send a sign-in or deletion code. Support receives information you voluntarily send.
These providers may process data outside your country, including in the United States. We do not promise exclusive European residency for all data. The V2 flow does not integrate cross-app advertising tracking.
Account export, deletion and retention
In Settings → Data and privacy on iOS and Android, you can export your profile, arcs, daily completions and XP, manage the local cache or request account deletion. Actions on the cache do not delete synchronised data. You can also request deletion by email without reinstalling the app using the page linked below. For other access or correction requests, contact devqwiet@outlook.fr.
Deletion requires fresh identity verification. It removes the account profile, sign-in identifiers, arcs, completions, XP, friend relationships, blocks, reports involving the account and its sessions. Apple sign-in revocation may be retried when the network is unavailable. Technical records of completed deletions are scheduled for removal thirty days after the request; provider backups may remain temporarily.
Account data is kept to provide the service until account deletion. Some pseudonymised purchase, installation and referral references used to prevent abuse are not removed by account deletion and currently have no automatic purge. Purchases retained by Apple, Google or RevenueCat and support correspondence are not automatically deleted by this action. Contact us for a request covering these records.
Deleting an account does not cancel an App Store or Google Play subscription. Manage renewal separately in the store used for the purchase.
Waitlist registration
By submitting the form, you consent to an email when Uncap launches. We store your email, chosen platform (iOS or Android), language, referral and campaign parameters supplied in the link, and the consent version and date.
Registration is immediate. No verification email is sent and ownership of the address is not verified. Previously unsubscribed or suppressed addresses remain excluded; contact us to change this choice.
Waitlist retention and security
Registrations are kept to prepare the launch notification or until you request deletion. Cloudflare processes web data; exclusive EU residency is not promised. Previous contacts are not automatically imported and your data is not sold.
Salted hashes derived from the IP address or email limit automated requests. Counters expire within 24 hours and are purged daily. Admin events are kept for at most one year. Diagnostics exclude emails, tokens and secrets. Unfinished legacy verification requests are removed after 30 days; new direct registrations are not subject to that cleanup.
The public website adds no advertising tracker or individual browsing analytics. Private administration uses Cloudflare Access security cookies.
Withdrawal and rights
To withdraw consent, unsubscribe, delete your registration or request access, correction or portability, email devqwiet@outlook.fr from the registered address. Unexpired legacy management links remain usable.
You may complain to the French authority CNIL at cnil.fr. Provider backups may temporarily keep a previous copy after deletion.