Privacy Policy
What Behind collects, why, and how to make it disappear.
Last updated September 22, 2026
This policy covers the Behind iPhone app and getbehind.app. Behind is run by [LEGAL ENTITY], [REGISTERED ADDRESS] ("we", "us"), the controller of the data described here. Write to support@getbehind.app about anything in it.
The short version
- Your selfie never leaves your phone, whether you take it with the camera or pick it from your photos. The face scan runs on the device, at every age, and only a single number is sent.
- We never collect photo pixels, face templates, message content, contacts, or your exact salary. The only protected characteristic we ask for is the gender that defines your cohort, and we ask for it plainly.
- Our product analytics are anonymous: a random id this install made, never your account or your email.
- We do not sell or share your personal information, show ads, or track you across other apps and websites.
- Deleting your account in the app erases your data right away.
What we collect
- Account. The account identifier from Sign in with Apple or Google, and whatever name or email the provider shares with us — with Apple you choose, and you can hide your email. Google also shares a link to your Google profile picture, which we store with your account but do not use. Those are the only two ways to sign in.
- Age and gender. Both decide your cohort: you are ranked against people worldwide born the same year, of the same gender. Behind is for people 13 and older. If the age you give is under 13, you are turned away and nothing is stored.
- Your answers. Bands and taps, never exact figures: height, follower range, savings band, your parents' education, the city you grew up in, and the quick-fire cards for privilege, bag, lore, popularity and brainrot. We never ask for your exact salary.
- Your lore. One sentence, up to 120 characters, about something you have done. It is the only free text in Behind. We show it back to you, we turn it into a typed signal for scoring, and we never show it to another person.
- A resume, if you upload one. The file is read on your phone. Only typed signals leave it — that something was built, led, won, earned or selected, and roughly at what scale. The document, employer names, dates of birth and addresses never leave your device.
- Your social handle, if you give one. Stored as a claim. If you ask us to check an Instagram, TikTok or Snapchat handle, we read that account's public profile and keep only the handle, its public display name, its follower count, how many accounts it follows, and whether it is private or verified. For a private account, that is all we read. For a public Instagram or TikTok account, we may also read its most recent public posts (up to twelve), only to count their likes and comments, and keep the results as a handful of numbers: posts read, average likes, average comment count, engagement rate, posts per week, the share that are videos, and days since the last post. We never read or store what a post says or shows, captions, hashtags, comment text, who commented or was tagged, messages, or who follows whom. These numbers are kept with the lookup, for 35 days or until you delete your account, and they are not part of your score. If you connect an Instagram account instead, Instagram tells us its id, username, account type and follower count, and nothing more.
- Screen time. Your daily total, read on your phone from a screenshot you pick. We never see which apps you opened. You can choose a range instead.
- Face score, if you scan. One number: a facial-symmetry percentile, calculated on your phone. See the face scan below.
- Purchases. Your Behind Pro subscription status and the transactions behind it, which Apple sends us through App Store Server Notifications. Apple takes the payment; we never see your card.
- Device and app data. Your storefront country, time zone, and language. A salted hash of your device's vendor identifier, used only to stop invite fraud. Your notification token, if you allow notifications.
- Invites. The invite links you create and whether they were used. You never see who used them, and they never see you.
- Anonymous usage events. Which screens and steps were reached, under a random install id. See analytics.
We do not buy data about you to enrich your profile behind your back. The only lookups that happen are the ones you ask for, and you choose which result is you.
The face scan, and why it is not like the others
The scan is offered at every age from 13, and it is optional every time. It reads a live camera frame or, if you prefer, one photo you pick from your library. Before the camera opens, the app says what it is about to do: we read symmetry and proportion on this phone, keep nothing, and send one number. You choose whether to go on.
The analysis happens entirely on your device:
- No image, crop, landmark set, embedding or derived template ever leaves the device or touches disk — not on success, not on failure, not if you cancel, not if you switch apps. The frames are read in memory and dropped.
- What leaves your phone is one number: a percentile, your position against a published reference distribution for your age and gender.
- That number is never cached in a log, never attached to a crash report, and never shown to anyone but you.
- Skip the scan and you still get a full card. The sub-score is estimated from your age and marked Estimated, and you can change your mind later.
Biometric laws
Some US states — Illinois (BIPA), Texas (CUBI), Washington — regulate collecting, storing, selling or profiting from biometric identifiers such as a scan of face geometry. Stated precisely: we do not collect, receive, store, or possess a biometric identifier or biometric information, and we never sell, lease, trade, or otherwise profit from one. The processing happens on your own device, under your control, and nothing derived from your face is transmitted to us or to anyone else. We never use face data to identify or verify who you are, and we never match your face against another person's. Because we hold nothing, there is no biometric retention schedule to publish and nothing to destroy — but if a jurisdiction treats the percentile itself as regulated, the same answer applies: it is deleted with your account.
Never collected, at any age
Photo pixels. Face templates or landmarks. Message content. Contacts. Your exact salary. And every protected characteristic except the gender that defines your cohort, which we ask for plainly and declare here and to Apple. Behind reads no health or fitness data, and asks for no precise location.
How we use it, and our legal basis
Everything above is used to run Behind: to calculate your eight sub-scores against published reference data for people your age and gender, to rank you against the worldwide population born your year (UN World Population Prospects 2024), to tell you when your rank moves, to manage your subscription, and to stop fraud and abuse. Your rank is a statistical position in the world population, not a comparison with other Behind users. No other user can see your card, your answers, or your lore unless you share the card yourself.
If you are in the EEA, the UK or Switzerland, our lawful bases are:
- Performing our contract with you — your account, your answers, your scores, your subscription, your invites. Without them there is no card to give you.
- Your consent — the camera for the face scan, notifications, connecting a social account, and any lookup you ask us to run. Withdraw it at any time, in iOS Settings or in the app; withdrawing does not undo what was lawful before.
- Our legitimate interests — anonymous product analytics, keeping the service secure, and stopping invite fraud, balanced against your interests and kept to the minimum that works.
- Legal obligation — keeping records we are required to keep, and answering lawful requests.
Your score is produced by a deterministic calculation, not by an AI making a decision about you, and it produces no legal or similarly significant effect. Nothing you write is used to train a model.
Analytics
We use PostHog to see which screens and steps people reach, and whether a step was answered or skipped. It is anonymous by construction:
- The id it uses is a random one this install made. It is never your account id, your email, or a device identifier, and it is thrown away when you delete your account — the next session is a stranger to analytics too.
- Event properties are closed lists of fixed values. No age, no score, no answer, no free text can reach them.
- Nothing is used to track you across other apps or websites. We never read the advertising identifier, so you will never see the App Tracking Transparency prompt, and we answer "no" to tracking on our App Store privacy label.
Who we share it with
We disclose personal information only to the companies that run Behind for us, each under a contract that limits them to our instructions, and only the part each one needs:
- Supabase — our database, authentication and server hosting. It holds everything we store.
- Apple — sign-in, purchases, age range, push notifications. Google — sign-in, if you use it.
- Superwall — decides which pay wall design you see. It is presentation only: we pass it no account id, no age, no answer and no score, only whether you currently have Pro. On a locked card we pass eight unlabeled bar lengths and colours, shuffled, with no number and no tile attached. Its SDK also sees ordinary device and app information, such as your iOS version and locale.
- PostHog — the anonymous product analytics described above.
- TypeSafe — reads your lore sentence, and nothing else, to turn it into a typed signal. It never sees your account, your age or your other answers, and no language model is ever part of scoring itself.
- Serper (web search) — when you tap "find my linkedin", the name you searched with, so candidate profiles come back for you to pick from; and when you ask us to check an Instagram or TikTok handle, that handle, so the account can be confirmed in a second or two. People Data Labs does the LinkedIn search job instead, when it is the provider in use. Nothing is kept unless you pick a result, and then only typed signals.
- Bright Data — only when you paste a LinkedIn address, pick a LinkedIn result, or ask us to check a handle: we send that public address or handle so the public profile can be read — and, for a public Instagram or TikTok account, its most recent public posts, reduced on our server to the counts described above, with everything else discarded. We keep only the counts, or typed signals, as described above.
- ScrapeCreators — the same job as Bright Data for the handles it covers (including Snapchat), when it is the provider in use.
- Meta — only if you choose to connect an Instagram account: you sign in to Instagram on Instagram's own page, and it sends us the four fields above.
We also disclose data when the law requires it, to respond to a lawful request, to enforce our Terms of Use, or to protect someone's safety — and, if Behind is ever sold or merged, to the buyer, who would be bound by this policy or would have to tell you before changing it.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in California and other US state privacy laws. We have never done either, at any age.
Where your data goes
Our service providers are mostly in the United States, so your data is processed there and in other countries where they operate. If you are in the EEA, the UK or Switzerland, that is a transfer out of your region: we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where it applies), together with each provider's own safeguards, and we keep the transfer to the minimum the feature needs.
How long we keep it
We keep your account and your answers until you delete your account. Inside that, the specific schedules are:
- Your account, answers and current scores — until you delete your account.
- Score history — one row a week, for 56 days. The history sheet shows six weeks; older rows are purged.
- Profile and handle lookups — 35 days, then purged. Search results are cached for 24 hours under a one-way hash of the query, not tied to you.
- Subscription notification records and failed-job records — 90 days.
- The salted hash of a deleted account's device — 90 days, so that deleting and reinstalling cannot be used to fake invites. It is a hash: it cannot be turned back into your device or your identity.
- Anonymous analytics events — held by PostHog for as long as our PostHog plan keeps events, then deleted by PostHog. They carry no account id, so they cannot be linked back to you or deleted by account.
Deleting your account — settings › delete account — erases your account, answers, scores, invites and notification tokens immediately, and resets the anonymous analytics id. If you signed in with Apple, the app signs in once more during deletion so that your Apple sign-in tokens can be revoked with Apple; no Apple token is ever stored. Backups held by our hosting provider expire on their own schedule.
Behind Pro
Behind Pro is one plan: $3.99 a week, auto-renewing, sold and billed by Apple through the App Store. You manage or cancel it in the Settings app, under your name › Subscriptions. Whether you have it is told to us by Apple's App Store Server Notifications; that status, and the transaction history behind it, is all we store about the purchase.
Children and teens
Behind is not for children under 13, and we do not knowingly collect anything from them. Under 13 is a hard stop: if the age you give is under 13, no account is created, nothing is stored, and there is no retry. If you believe a child under 13 has given us data anyway, write to support@getbehind.app and we will delete it.
People aged 13 to 17 can use Behind, buy Pro, and unlock invites like everyone else. If you are under the age of digital consent where you live — 16 in much of Europe — use Behind only with a parent's or guardian's permission, and they may exercise the rights below on your behalf. Purchases go through Apple, including Ask to Buy where a family has turned it on. Two things that matter for a teenager: the face scan is optional at every age and never sends an image, and nothing you write is ever shown to another person.
We do not sell or share the personal information of anyone under 16, and we never have.
Your rights
Wherever you live, you can:
- See and correct your answers in the app, and change any of them.
- Delete everything — settings › delete account — or ask us to.
- Skip any question. A skipped answer is estimated from your age and marked Estimated.
- Turn off camera or notification access at any time in iOS Settings.
To make a request by writing to us, email support@getbehind.app from the address on your account, or tell us enough to find it. We answer within 45 days (extendable once by 45 more, if we tell you why), or within a month in the EEA and UK. We do not charge for this and we will not treat you worse for asking. An authorised agent may act for you with written proof; we may still ask you to confirm it yourself.
California
Under the CCPA as amended by the CPRA, the categories of personal information we collect are the ones listed under What we collect — identifiers, commercial information (your subscription), internet or app activity, inferences (your scores), and, where a state law reads them that way, sensitive personal information (your account log-in and your gender). We collect them from you; from Apple and Google when you sign in or buy; and, only when you ask, from the public profile you point us to. We use them for the purposes above, and disclose them for a business purpose to the providers named above. We have not sold or shared personal information in the preceding twelve months, and we do not sell or share it, so there is no "Do Not Sell or Share My Personal Information" link to give you; we do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. You have the rights to know, access, correct, delete, and portability, and the right not to be discriminated against for using them.
Other US states
If you live in a state with a consumer privacy law — Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — you have the rights to confirm, access, correct, delete, and receive a portable copy of your data, and to opt out of targeted advertising, sale, and profiling with legal effects. We do none of those three. If we refuse a request you may appeal by replying to our answer; we will decide within 45 days and tell you how to contact your attorney general if you are still unhappy. Behind reads no HealthKit or medical data, receives no biometric identifier, and never collects precise location, so we do not knowingly process consumer health data under Washington's My Health My Data Act or Nevada's SB 370.
EEA, UK and Switzerland
You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent at any time. You may also complain to your supervisory authority — in the UK, the Information Commissioner's Office — though we would rather you told us first.
Do Not Track and Global Privacy Control
Behind and getbehind.app do not track you across other apps or websites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. getbehind.app runs no scripts, sets no cookies and loads no trackers; its fonts come from Google Fonts, which sees your IP address as any web request does.
Links to other services
Behind links to Apple, Google, Instagram, LinkedIn and others. What happens on their pages is governed by their own privacy policies, not this one.
Security
Data is encrypted in transit. Database access is restricted so that a signed-in person's queries can only reach their own rows, and the keys that could read everyone's data never ship inside the app. Every value the app sends is checked on the server for type, range and length, and rejected if it is wrong. No system is perfectly secure, and we do not promise one is.
We do not use a crash-reporting service today. If we add one, its reports will carry the error type, file, line, stack, and the app and OS version — never an answer, a score, your age, or anything from a face scan — and this policy will say so before it starts.
If a breach affects your personal data, we will notify you and the relevant regulator as the law requires — in the EEA and UK, within 72 hours of becoming aware, where the rules call for it.
Changes
If this policy changes in a way that matters, we will tell you in the app before the change takes effect, and the date at the top of this page changes with it. Smaller corrections are made here, with the date updated.
Contact
support@getbehind.app · [LEGAL ENTITY], [REGISTERED ADDRESS]