Headcount — Privacy Policy
Effective date: 11 August 2026
Who we are
Headcount is operated by Nathan Barth. If you have a question about this policy, about your data, or about something you have reported, email support@getheadcount.app. That address is read by a person.
This policy describes exactly what the app does. It does not contain placeholder clauses for things we don't do — if something isn't mentioned here, we don't do it.
What Headcount is
Each group you belong to has one message, chosen when the group is created, and one button. Pressing the button sends everyone else in the group a notification containing that message. They react with one of six emoji. That's the app.
There is no free-text messaging, no feed of strangers, no search, and no ads.
What we collect, and why
Your email address and password. Needed to create an account and sign you in. We email you a 6-digit code to confirm your address and to reset your password. Your email address is never shown to other users and is never used for marketing.
Your display name. You choose it, it's 2–24 characters, and it's shown to everyone in the groups you belong to. It appears in the app, in push notifications sent to your groups ("Alex pinged Sunday Walk"), and in moderation records if someone reports you.
No profile photos. Headcount has no avatar upload. Your picture next to a reaction is your initials, drawn from your display name. We never ask for photo library or camera access, and there is nothing to upload.
Your groups and what happens in them. The group's name, the group's message, who is a member, who is an admin, invite codes and who redeemed them, when each ping was sent and by whom, which emoji you reacted with and when, and the streak counters calculated from all of that. This is the app working.
Your notification settings and push token. If you allow notifications, we store a push token identifying your device, plus whether it's iOS or Android, and your per-group mute and "notify me about every reaction" preferences. The token is deleted when you sign out, when you delete your account, and automatically when Apple or Google tells us the device is gone. Resetting your password deletes the tokens for your other devices, so a device you've been signed out of stops receiving notifications too.
People you block. Who you've blocked is stored, and is visible only to you — never to the person blocked.
Reports you file. The content you reported, the reason you wrote (up to 500 characters), and a snapshot of the reported content as it stood at the moment you reported it. See Reported content is preserved.
Whether your profile has been flagged. If a report about your display name is upheld, we set a flag on your profile that replaces the name with "(name removed)" in the app, and "Someone" in notifications, until it's resolved. The flag isn't shown to other users as such — but the replacement text is, so people in your groups can see that something changed. It can be cleared.
How the app is used. Which actions are taken — "sent a ping", "created a group", "reported content" — along with your account ID and, in some cases, a group ID, which emoji was used, or a short code describing why something failed. We do not record the content of group messages, display names, or anything you type. We do not record which screens you open, and we do not record your screen.
Crash and error reports. When the app crashes or hits an error, we receive the error, a stack trace, your device model, OS version, app version, and a trail of recent actions. Your account ID is attached so we can tell whether a crash is affecting one person or everyone. Email addresses, sign-in tokens and API keys are stripped out on your device before the report is sent.
Your IP address, briefly. Every request the app makes to our servers arrives with an IP address attached, and our hosting provider records it in server logs. We use those logs to rate-limit abuse and to investigate problems. We don't use your IP address to work out where you are, and we don't store it alongside your profile. Logs are retained by our provider on a rolling window measured in days.
What we don't collect
No location — no GPS, and no approximate location derived from your IP address; we've turned that inference off at our analytics provider. No contacts or address book. No health, fitness or financial data. No browsing or search history. No advertising identifier (IDFA). No microphone or audio. No screen recordings or screenshots.
We don't sell your data, share it with advertisers, build advertising profiles, or track you across other companies' apps and websites. Headcount shows no ads and has no in-app purchases.
Who can see what
This is the part worth reading twice.
Visible to every member of a group you're in:
- The group's message. This is shared by the whole group and set when the group is created.
- Your display name.
- Every ping you send, and when you sent it.
- Every reaction you leave, and which emoji it was.
- Your individual streak, and the group's streak.
Visible only to you:
- Your email address. No other user can see it, ever.
- Your password. It reaches our authentication provider over an encrypted connection and is stored hashed — we never store it in a form anyone could read.
- Who you've blocked.
- The reports you've filed.
Visible to us: everything above, plus the analytics and crash data described earlier. In practice we look at group content only when a report comes in.
Blocking hides content in both directions. You and the person you blocked stop seeing each other's pings and reactions, and neither of you sends push notifications to the other, even while you're both still in the same group. The person you blocked isn't told.
Leaving or being removed from a group stops your access to it. Pings you already sent stay in that group's history, and your reactions stay attached to pings you reacted to.
Push notifications appear on lock screens
When someone presses the button in one of your groups, the notification title is that group's message, in full — "off work", "landed", whatever the group chose — and the body names the sender and the group: "Alex pinged Sunday Walk". Reaction notifications show the emoji and either a count or the reactor's name.
On most phones, notification content is readable on the lock screen without unlocking the device, by anyone who can see the screen. That's deliberate — the message is the entire point of the notification — but it means group messages and display names are as private as your lock screen is.
To deliver a notification, we send that text, along with your device's push token, to Expo's push service, which forwards it to Apple's Push Notification service (or Google's, on Android). Those services necessarily see the notification's contents in transit.
If that isn't what you want: mute any group individually in that group's settings, or turn notifications off for Headcount entirely in your phone's settings. The app works either way — every ping still appears in the in-app feed, which is the source of truth.
Who we share data with
We use a small number of service providers. Each one gets only what it needs to do its job. None of them is permitted to use your data for their own purposes.
| Provider | What they do | What they receive |
|---|---|---|
| Supabase | Database, authentication, server functions, hosting | Everything: your email and hashed password, display name, groups, pings, reactions, streaks, blocks, reports, push tokens |
| Resend | Sends our email | Your email address and the 6-digit confirmation or password-reset code. Also delivers moderation alerts to us, which contain the reported content, the reporter's and target's display names, and the reason given |
| Expo | Push notification delivery | Your push token, the group's message, the sender's display name, and the group name |
| Apple (APNs) | Push notification delivery to iOS devices | The same notification content, plus your device's push token |
| PostHog | Product analytics | Your account ID, event names, group IDs, and simple counts, flags and error codes. Never message content or display names |
| Sentry | Crash reporting | Crash and error reports, stack traces, device model, OS and app version, recent-action breadcrumbs, and your account ID |
| Netlify | Serves getheadcount.app, where these policies and our support page live | The IP address and browser details of anyone who visits the site. Nothing from your Headcount account |
Those are the providers that receive your personal data. We may also use infrastructure services — hosting, content delivery, uptime monitoring — that handle data in transit on our instructions and don't get access to your account content. We don't sell or rent data to anyone, and if a new provider starts receiving a category of your data, we'll update this table and tell you in the app first.
We may also disclose data if we're legally required to, or where it's necessary to investigate abuse or protect someone's safety.
If Headcount is ever transferred to someone else — sold, or handed over because the operator can no longer run it — your data goes with it, and the new operator is bound by this policy until they tell you otherwise. We'll say so in the app before that happens.
Where your data is processed
Our database runs on Supabase infrastructure in Canada (AWS ca-central-1,
Montréal). Our analytics, crash reporting and email providers process data in
the United States.
Headcount is offered in the United States. Your data is stored in Canada and processed by some of our providers in the United States, as set out above. If we make the app available in other countries, we'll update this policy first.
How long we keep things
While your account exists, we keep your account and group data, because that's the app functioning.
Pings and reactions stay in a group's history. If you delete your account, your reactions are deleted with it, and pings you sent remain in the group with your name detached — the group's history stays intact but stops pointing at you.
Unused invite codes expire after 48 hours and are deleted automatically a week after that.
Push tokens are deleted when you sign out or delete your account, and are removed automatically when the device stops being reachable.
Reports are kept for three years after they're resolved, including after the reporter deletes their account, and then deleted — see below.
Analytics and crash data are kept by PostHog and Sentry on their own schedules. Sentry deletes crash and error events within 90 days. PostHog keeps product analytics far longer — measured in years, not months. If you want your analytics history removed sooner, email us and we'll request it.
Reported content is preserved
When someone reports a group message, a profile, or a ping, we save a snapshot of that content exactly as it read at the moment it was reported, in the same step that creates the report. That snapshot is kept even if the original is later edited, taken down, or deleted, and even if the account that created it is deleted.
This is on purpose. Without it, anyone could file a report and immediately erase the evidence, or change a display name after being reported and leave nothing to review. It also means we can act on a report we haven't got to yet.
The practical consequence, stated plainly: deleting your account does not delete a snapshot of your content that someone had already reported. That snapshot can include a display name you used or a group message you wrote. We keep it as a moderation record. It's detached from your account, it isn't used for anything except reviewing that report, and it's deleted on the schedule above — but we're not going to pretend it stops being information about you.
Snapshots are deleted three years after the report they belong to is resolved.
Deleting your account
Open Settings → Delete account in the app. It takes two confirmations and completes immediately. You don't need to email us or wait for approval.
Deletion removes:
- Your login: email address and password
- Your profile: your display name
- All of your reactions
- Your individual streak
- Every group membership you have
- All of your push tokens
- Every block you made, and every block made against you
Deletion does not remove:
- Pings you sent. They stay in each group's history with your name removed — the group's streak and record don't collapse because someone left.
- Groups you created. A group belongs to its members, not its creator. If you're the admin, the longest-standing remaining member becomes admin. If you were the only member left, the group is deleted with you.
- Reports you filed, and reports filed about your content. Your identity is removed from reports you filed, but the report, the reason and the snapshot are kept as moderation records. See above.
- Analytics and crash events already collected, which are keyed to your account ID at PostHog and Sentry until their retention windows expire. Email support@getheadcount.app if you want those deleted sooner and we'll request it.
- Emails already sent to you, which have already been delivered.
Account deletion cannot be undone. There's no recovery period and no archive.
Your rights
You can do most of this yourself, in the app: change your display name on the profile screen, leave a group, block someone from the member list, and delete your account from Settings.
Beyond what you can do in the app, email support@getheadcount.app and we'll help you get a copy of your data, correct something that's wrong, or delete something the in-app tools don't reach. We'll respond within 30 days.
You can also object to our product analytics — email us and we'll exclude your account.
Age
You must be 18 or older to use Headcount. The app isn't directed at children or teenagers, and we don't knowingly collect data from anyone under that age. If we learn that someone under 18 has created an account, we'll delete it. If you believe a child has given us their data, email support@getheadcount.app and we'll remove it.
Changes to this policy
If this policy changes, we'll update this page and change the effective date at the top. If the change is material — a new provider receiving your data, a new category of data collected, or a change to how long we keep something — we'll also tell you inside the app before the change takes effect.
Contact
support@getheadcount.app