PRIVACY POLICY

Private by design, clear about what leaves your device.

This policy explains how the 8billion website and iPhone and Android apps handle on-device scenarios, accounts, purchases and optional Member Twin activity.

Last updated · 17 August 2026
01

What this website collects

The current website does not ask for income, employer, offer, address, phone number or payment information. It does not create an 8billion account.

If you choose an email link, your message is handled by your email provider and is received only for the purpose shown in that link.

02

On-device private context

Free calculations can be explored without an account. Exact income, employer, offer and raise values, work pattern, commute, household details, private scenarios, calculated outputs and Decision Brief PDFs are designed to stay on the device and are not displayed on a public profile.

Nothing is saved unless you choose a device-save control. You can remove app-owned copies with Clear private device data. A copy exported to Files, email or another service is controlled by that destination.

03

Accounts, purchases and service providers

The core private flow works without an account. A purchase, restore or real Member Twin opt-in requires the platform sign-in offered in the app: Sign in with Apple on iPhone or Google sign-in on Android. If Google or Apple provides an email address, Supabase stores it with the authentication account for sign-in, account security and support. It is never shown to another member.

Apple or Google processes store billing. RevenueCat and Supabase receive the minimum platform account identifier, internal account identifier, product, transaction, purchase status, entitlement and delivery state needed to deliver or restore eligible access and prevent duplicate delivery. When a signed-in member creates a private decision, the device sends Supabase the decision kind and a salted SHA-256 decision fingerprint; Supabase creates a random decision ID. The random salt stays on the device, and the fingerprint does not contain the readable income, raise or scenario inputs. It is used to bind one Kit delivery to one decision. 8billion does not receive a full payment-card or bank-account number.

Supabase provides authentication, protected database access and server functions. RevenueCat validates store purchases and access state. Apple and Google provide sign-in, distribution and billing. These providers may process technical request information under their own terms; none receives exact income or private decision inputs from 8billion.

04

Optional Member Twin

Member Twin is free, off by default and requires a signed-in member to opt in separately. The service may process consent and sharing choices, a member pseudonym, broad occupation, current or destination region, weekly-hours band, household band, work mode, matching purpose, selected journey milestones, match and action state, prepared questions, fixed responses, blocks and structured safety reports. Only the broad fields separately approved for sharing can appear to a match.

Exact income, employer, offers, address, email, phone, contact details and private scenarios are excluded. There is no public directory, open chat, link sharing, money request or meeting feature. Members can withdraw, block or report, and no match or reply is guaranteed.

05

Security, retention and deletion

8billion uses access controls, authenticated server functions and service-provider protections to limit account-linked data to its stated purpose. No online service can promise absolute security.

Account and authentication records, account-linked purchase delivery records and active Member Twin records are kept while the account is active and as needed to provide sign-in, purchase delivery or restore, optional matching and member-safety controls. Other records are retained only to the limited extent needed for a legal obligation, transaction or refund reconciliation, fraud or security prevention, dispute handling, privacy-request evidence or member safety. Access to such records is restricted, and they are removed or de-identified when that purpose no longer requires them.

You can clear private device data, withdraw from Member Twin and start permanent account deletion inside the app. Confirmed deletion removes the live Supabase account and account-linked service records and requests deletion of the RevenueCat customer record. A minimized, de-identified safety or compliance record may remain only where one of the limited reasons above requires it. Deleted data may also remain temporarily in protected provider backups until the provider completes its normal backup rotation; backup copies are not available for ordinary app access. Store billing records remain under Apple or Google terms. Full instructions are at https://8billion.app/support/account-deletion.

06

No ads, sale or cross-app tracking

8billion has no advertising SDK, does not sell financial data and does not use account, purchase, scenario or Member Twin information to track people across apps or websites owned by other companies.

07

Provider and contact

8billion is responsible for the personal data described in this policy. Privacy, legal and support questions can be sent to privacy@8billion.app or hello@8billion.app. Do not email exact income, income documents, passwords, two-factor authentication codes or full payment-card details.

Need a direct answer?

Contact 8billion