Equipt

Privacy Policy

How Equipt handles your information.

This policy explains what Apologia House LLC collects through the Equipt iOS app and related web services, why we use it, who helps us process it, and how you can exercise your privacy rights.

Effective date: August 12, 2026

Prefer the short version? Read the Simplified Privacy Notice.

Controller and Contact

Apologia House LLC is the controller of personal information processed for Equipt. Contact us at privacy@equiptfaith.com for privacy questions, rights requests, or account-deletion help.

Our Privacy Officer is responsible for Equipt's protection of personal information and is your point of contact for privacy rights and questions. You can reach the Privacy Officer at privacy@equiptfaith.com.

Information We Collect

We collect account information such as your authentication identifier, email address, sign-in provider identity claims, and profile details. If you use Sign in with Apple, Apple may provide a relay email address instead of your personal email address.

We record confirmation from an authentication action only when the same current attempt keeps its displayed policy statement through authenticated completion, or when you select Continue while authenticated. An asynchronous callback without that current policy witness records no confirmation from the original action. A valid recording contains only your authenticated account identifier, the immutable policy version you confirmed, and the server confirmation time. We do not record your exact age, date of birth, age band, a negative answer, residence, citizenship, device identifier, or the App Store storefront value.

We collect app-use information such as lesson progress, content access decisions, purchase and entitlement status, safe operational events, pseudonymous analytics events, feature-gate calls, and scrubbed crash diagnostics.

If you use Equipt's AI chat feature, we process the prompt text you submit, bounded prior conversation context for follow-up turns, and the assistant response generated for your prompt. We send that chat content through Equipt's server proxy to Apologist Fusion with anonymous metadata and without your email address or account identifier.

We do not collect payment-card numbers. In-app purchases are processed by Apple. RevenueCat helps us maintain subscription and entitlement state and process optional one-time support purchases. PostHog receives only coarse support surface and tier-selection events, not product identifiers, prices, receipts, transaction identifiers, or purchase-completion authority.

Why We Use Information

We process information to create and secure accounts, provide lessons and premium content, preserve lesson progress, manage purchases and founder access, prevent abuse, troubleshoot errors, improve product quality, and comply with legal and App Store obligations.

For users in the European Economic Area, United Kingdom, or Switzerland, our legal bases are contract performance, legitimate interests in operating and improving Equipt, legal obligations, and consent where a specific feature requests it.

Age Policy and Account Confirmation

Equipt initially applies an 18-or-older product policy. The app may relax that policy to 14 or older only when the current App Store storefront resolves outside the Philippines before you use the action. The storefront does not establish where you live, your citizenship, your physical location, or which law applies. An unresolved, unavailable, failed, or Philippines storefront keeps the 18-or-older policy.

Only a callback that validly establishes its bound session, or a matching duplicate in the same running app process, proceeds to authenticated Continue. An unsuccessful or mismatched callback, or one already consumed after the app restarts, uses a safe failure and return path without recording confirmation. For a restored account, a server read that confirms the record is absent, stale, or incompatible shows the current policy and Continue. A rate-limited, failed, or unreadable read uses account-check recovery and does not offer Continue.

We use the minimum valid confirmation record to demonstrate that the account holder confirmed Equipt's current access policy. The Equipt backend and Supabase process the record. It may be processed in the United States as described in the International Processing section below. An essential private Realtime channel carries no account-policy payload and only tells the app to check the authoritative record again after a relevant account change.

The confirmation remains until you remove it through Privacy & Data, delete the account, or replace a 14-or-older confirmation with a stronger compatible 18-or-older confirmation. Private account-policy limiter state is retained only for the bounded anti-abuse and recovery windows documented by Equipt and is not used to profile you. Account deletion cascades both the confirmation and limiter state.

You can access the confirmation through a verified-identity privacy request and receive it as structured data where portability applies. Selecting Remove in Privacy & Data suspends protected service and asks the server to delete the confirmation. If you decline, withdraw, or the authoritative read or write cannot be completed, protected parts of Equipt stay unavailable. Essential account, legal, privacy, support, subscription management, and account-deletion paths remain available.

If a confirmation write fails after authentication, your session remains signed in, but protected content and optional services stay unavailable until a later successful confirmation.

Sign-In Providers and Relay Email

If you use Sign in with Apple, your Equipt account is keyed to the Apple identity UUID that Apple gives us for this app, not to an email address. Apple only provides your name and email during the first authorization. If you choose Hide My Email, Apple gives us a relay address that you can disconnect through Apple. If the relay is disconnected, we may no longer be able to reach you by email, but your account remains linked to the Apple UUID.

If you use Sign in with Google, Google provides identity claims such as your Google account identifier, email address, and basic profile fields so we can create and secure your Equipt account.

Processors and Sharing

We share information with processors that help us operate Equipt. We provide information for the purposes listed below, and Equipt does not use the resulting processing for tracking.

  • Supabase: Hosted database, authentication, storage, and server infrastructure. Data: Authentication, profile records, lesson progress, entitlement records, account-policy confirmation and limiter state, and operational events.
  • RevenueCat: Subscription, entitlement, and one-time support purchase processing. Data: Auth user identifier as App User ID, purchase identifiers, product identifiers, entitlement status, subscription events, and one-time support purchase events.
  • PostHog: Product analytics with autocapture and replay disabled. Data: Pseudonymous install identifier and allowlisted product analytics events, including coarse support surface opens and support tier selections.
  • Sentry: Error monitoring and crash diagnostics. Data: Scrubbed crash reports and diagnostics.
  • Statsig: Feature gates and controlled rollout decisions. Data: Pseudonymous device identifier and server environment identifier used for feature-gate evaluation.
  • Apologist Fusion: AI chat responses when the chat feature is enabled. Data: AI chat prompt text, bounded prior conversation context for follow-up turns, and generated assistant responses, sent through Equipt with anonymous metadata and no account identifier.
  • Expo EAS Update: Over-the-air app update delivery. Data: App-update request metadata, EAS client ID, request IDs and headers, and bounded prior-fatal-error diagnostics.
  • Axiom: Runtime log and operational-event monitoring. Data: Safe operational-event fields from server route handlers.
  • Mux: Video hosting and playback delivery. Data: Signed playback URLs and video-delivery metadata for lessons.
  • Cloudflare: DNS proxying, WAF, cache-bypass, and source-IP rate limiting. Data: Production request metadata, including IP address, host, path, method, and request headers needed for edge security.
  • Vercel: Hosting the Equipt website and server API routes; Equipt does not use this processing for tracking. Data: Web and API request metadata, including IP address, host, path, method, and request headers, plus applicable account, user-content, purchase, usage, and diagnostic information submitted to Equipt server routes.

Your Rights

Depending on where you live, including under GDPR-style laws, you may have the following rights:

  • Access the personal information we hold about you.
  • Correct inaccurate profile or account information.
  • Delete your account from inside the app, or contact us for help with deletion.
  • Object to or restrict certain processing where applicable law gives you that right.
  • Withdraw consent where our processing depends on consent.
  • Receive a portable copy of information you provided, where required by law.
  • Appeal or complain to your local data-protection authority if you believe your rights were not honored.

We also honor CCPA and CPRA-style access, deletion, correction, and opt-out requests as a voluntary best practice for United States users, even when a specific state law does not require that exact process. Equipt does not sell personal information or use it for cross-context behavioral advertising.

Canada and Quebec (PIPEDA and Law 25)

Equipt is operated from the United States. The processors listed above may process your personal information in the United States. If you use Equipt from Canada, including Quebec, your personal information may be processed in the United States. When it is processed there, it may be subject to lawful access by United States courts, law enforcement, or government authorities under United States legal process.

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25 (the Act respecting the protection of personal information in the private sector), you may access the personal information we hold about you, request correction of inaccurate information, withdraw your consent where our processing depends on consent, and receive a portable copy of the computerized personal information you provided to us. To exercise these rights, contact our Privacy Officer at privacy@equiptfaith.com. You can also delete your account and its associated data from inside the app, as described in Account Deletion and Retention below.

If we experience a confidentiality incident that creates a real risk of significant harm under PIPEDA or a risk of serious injury under Law 25, we will notify affected individuals and the appropriate regulator and keep a record of the incident as required by law.

If you believe your privacy rights were not honored, you may complain to the Office of the Privacy Commissioner of Canada (OPC), or, for Quebec residents, to the Commission d'accès à l'information du Québec (CAI).

Philippines

We treat the claimed minimum-age confirmation conservatively as sensitive personal information. We rely on your specific consent for the eligibility purpose described above. You may request access, correction, erasure or blocking, and data portability, and may withdraw consent through Privacy & Data or by contacting our Privacy Officer. You may also complain to the National Privacy Commission.

If a personal data breach meets the Philippine notification threshold, we will notify the National Privacy Commission and affected people within the period required by applicable law.

Account Deletion and Retention

You can delete your account from inside the app while signed in. Deletion removes the auth user and clears cascading records such as lesson progress, auth events, operational events, and sudo sessions.

Some records are anonymized or tombstoned instead of fully erased, including profile, entitlement, RevenueCat, founder, and audit records. We keep those limited records for billing reconciliation, anti-abuse, founder-cohort integrity, legal claims, and audit accountability. Founder slots are consumed when claimed and are not reclaimed after deletion.

Security, Transfers, and Changes

We use technical and organizational safeguards to protect Equipt, including access controls, server-side secret boundaries, and privacy scrubbing for diagnostics. Some processors operate in the United States or other countries, so information may be processed outside your home jurisdiction.

We may update this policy as Equipt changes. If a change is material, we will update the effective date and provide notice appropriate to the change.