DitchList Privacy Policy
Last updated: August 2026
DitchList (“the app,” “we,” “us”) helps you save money by skipping small impulse purchases and putting that money toward a goal you actually want. This policy explains what data the app handles and how you stay in control of it.
The short version
- We do not ask for your name or phone number. The only contact info we ever hold is an email address you optionally add to save your account.
- We do not show ads inside DitchList, and we never sell your data.
- We advertise DitchList elsewhere, and we measure our own ads: if you installed the app after seeing one, an ad-measurement service (Tenjin) helps us learn which campaign brought you — see Ad attribution below. iOS lets you decline the tracking permission, and everything in the app works exactly the same if you do.
- We use privacy-first, first-party analytics to see how the app is used and improve it. This never includes your real dollar amounts — money is recorded only as broad ranges (e.g. “$50–150”) — and session recordings have all text and images masked. You can turn it off anytime in Settings.
- The data you create — your goals, the impulses you define, and the “ditches” you log — is stored against an anonymous account, and you can permanently delete it from inside the app at any time.
What we collect
When you first open DitchList, the app creates an anonymous account for you. This account is identified only by a randomly generated ID; it is not linked to your real-world identity, your Apple ID, or any contact information.
Against that anonymous account we store the data you enter:
- Goals — the name and dollar target of things you’re saving for.
- Impulses — the names and prices of recurring purchases you choose to track.
- Ditches — a record each time you skip an impulse, and the amount saved.
We do not collect your contacts, your photos, or your precise GPS location. We do collect anonymous, privacy-protected usage analytics (see Analytics and product improvement), and we measure our own ad campaigns with the help of device identifiers where you allow it (see Ad attribution).
Analytics and product improvement
To understand how DitchList is used and make it better, we use PostHog, a product-analytics service acting as our data processor. This is first-party analytics: we never use it for advertising targeting, never sell it to data brokers, and never share it with other apps. Measuring our own ads is handled separately — see Ad attribution below.
What this covers:
- Usage events — anonymous records of in-app actions (creating a goal, logging a ditch, opening a screen) and which buttons you tap.
- Ranges, not real amounts — your actual dollar figures never leave your device. Money is bucketed into broad ranges (for example “$50–150”) first, and squad progress is shared only as a percentage.
- Session recordings — anonymized recordings of app sessions that help us find confusing or broken flows. All text and images are masked (shown as placeholders), so amounts, goal names, and photos are never visible.
- Device and app info — app version, device model, OS version, language, and an approximate location (city/region) inferred from your IP address. We do not use precise GPS for analytics.
This data is tied to the same anonymous account ID described above and is hosted by PostHog in the United States. You can turn analytics off at any time:
Wish List → Settings (gear icon) → Share usage analytics
Turning it off stops all event collection and session recording on your device.
Ad attribution — how we measure our ads
We run ads to tell people DitchList exists, and we need to know which campaigns actually work. For that we use Tenjin, a mobile measurement partner acting as our data processor. In App Store “nutrition label” terms this counts as tracking, and we declare it there.
What Tenjin receives:
- Install and app-open signals with device information (device model, OS version, IP address) used to match your install to one of our ads.
- A device advertising identifier — only if you allow it in Apple’s tracking permission prompt. If you decline (or never see the prompt), no advertising identifier is used.
- A few milestone events — the same coarse ones as analytics (finished onboarding, created a goal, logged a ditch, won a goal), as bare event names. Never dollar amounts, goal names, or anything you typed.
- Apple SKAdNetwork results — Apple’s own privacy-preserving campaign numbers, which are aggregated and anonymous by design.
This data is used solely to measure and improve our own advertising. It is never sold, and never used to build a profile of you for anyone else’s ads. Tenjin’s own policy is at tenjin.com/privacy.
Your controls:
- Decline Apple’s tracking permission (or turn on Settings → Privacy & Security → Tracking → Ask App Not to Track globally) — the app works identically either way.
- Turn off Share usage analytics in DitchList’s Settings — this also stops attribution events from your device.
How your data is stored and protected
- Your data is stored in our backend (Supabase / PostgreSQL) and is protected by Row Level Security, so each account can only ever read or modify its own data.
- All communication between the app and the backend uses encrypted HTTPS (TLS).
- Your authentication token is stored in the device’s secure Keychain, not in plain storage.
Data retention and deletion
We keep your data only while your account exists. You can delete everything at any time:
Wish List → Settings (gear icon) → Delete account
Deleting your account permanently removes your account and all associated goals, impulses, and ditches from our backend. This action cannot be undone.
Children’s privacy
DitchList is not directed at children under 13 and does not knowingly collect personal information from them.
Changes to this policy
If we change this policy, we will update the “Last updated” date above and post the revised policy at the URL linked from within the app.
Contact
Questions about privacy? Email drew@theditchlist.com.