1. What this document covers
This Privacy Policy explains how HOPPP! ("the app", "we", "us") handles information when you install and use it. It applies to the Android version distributed via Google Play. iOS, Desktop, and any future platforms will follow the same principles but may differ in the specific data flows described below.
The app is operated by kobar.co. You can reach us at privacy@kobar.co for anything in this document.
2. The short version
- Your goal, your blocked apps, and your attempt history live on your device.
- The reasons you type to the Archivist are sent to a third-party AI provider to generate a response. They are not stored by us.
- If you add a witness, they receive a notification via SMS or push containing only the fact that you caved — never the reason you typed.
- We don't sell your data. We don't show you ads. We don't track you across other apps.
- You can delete everything we hold about you at any time.
3. What data we collect
A. On-device data (not transmitted to us)The following is stored locally in the app and on the device's encrypted storage. It never leaves your phone unless you explicitly back it up:
- Your stated goals (the "one thing that matters today" and longer-term objectives).
- The list of apps you have chosen to block.
- The history of your attempts to open blocked apps: timestamp, app name, reason typed, verdict issued.
- Your character preference (which Archivist voice you use).
- App settings (notification preferences, cooldown durations, etc.).
B. Data sent to generate AI responsesWhen you type a reason to the Archivist, the following is sent to our AI provider to produce a ruling:
- The reason you typed.
- The current time and the app you tried to open.
- Your current goal (so the AI can judge your reason against it).
This request is processed and the response is returned to the app. We do not retain a copy of either the request or the response on our servers.
C. Account data (if you sign in)If you create an account to sync across devices, we store:
- Your email address.
- A hashed password (we never store plaintext).
- The on-device data listed in section 3.A, encrypted, so it can sync to your other devices.
D. Witness notificationsIf you add a witness, we store their phone number or push token so we can notify them when you cave. We do not contact them for any other purpose and do not share their contact with other users.
4. What we don't collect
- Your name, address, or any contact details (unless you provide them for an account).
- Location data. The Bridge feature may use approximate distance to suggest meetups, but the precise location is computed on-device and never sent to our servers.
- Device identifiers for advertising. We have no advertising SDKs.
- Crash analytics that include personal data. We use a minimal crash reporter that strips identifiers before submission.
5. How we use your data
The on-device data exists to make the app work — to remember your goal, to block the apps you asked us to block, to keep the record the Archivist judges against. The AI request data exists only to generate that turn's response. The account data exists only to sync across your devices.
We do not use any of this data to train models, build advertising profiles, or sell to third parties. We don't share data with anyone except:
- Our AI provider, which processes the prompt and returns a response under a data-processing agreement that prohibits retention or use for training.
- Our infrastructure providers (hosting, email delivery), which are bound by standard confidentiality terms.
- Law enforcement, if compelled by a valid legal process. We have not received such a request to date.
6. Your rights
You have the right to:
- Access — request a copy of all data we hold about you.
- Delete — request permanent deletion of your account and all associated data. See our data deletion page.
- Export — receive your data in a portable format (JSON).
- Correct — update or correct inaccurate data.
- Withdraw consent — stop using the app and have your data deleted.
To exercise any of these rights, email privacy@kobar.co from the address associated with your account. We respond within 30 days.
7. Children's privacy
HOPPP! is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact privacy@kobar.co and we will delete the account.
8. International transfers
Our servers are located in the European Union and the United States. If you use the app from elsewhere, your data may be transferred to and processed in these locations. Our AI provider processes prompts in the United States. We rely on Standard Contractual Clauses for transfers from the EEA, UK, and Switzerland.
9. Security
On-device data is protected by your device's encryption (Android FBE / iOS Data Protection). Account data is hashed with bcrypt and stored in encrypted databases. AI prompts are transmitted over HTTPS. We don't store AI responses.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities within 72 hours as required by GDPR.
10. Changes to this policy
If we change this policy in a way that affects your rights, we will notify you in-app and ask for renewed consent where required. The "Last updated" date at the top of this document reflects the most recent revision. Earlier versions are available on request.
11. Contact
For privacy questions, data requests, or complaints:
- Email: privacy@kobar.co
- WhatsApp: +62 881-0808-81097
If you are in the EEA and believe we have not handled your complaint adequately, you have the right to lodge a complaint with your national data protection authority.
12. Legal basis (GDPR)
For users in the EEA, we process your data under the following legal bases:
- Contract — to deliver the service you installed.
- Consent — for AI prompts (you type them; that is consent for that turn) and witness notifications (you add the witness; that is consent to contact them).
- Legitimate interest — for minimal crash reporting and security, balanced against your privacy.