Plain-language summary: Commit exists to make posting irreversible on purpose. We collect your account details, the content you seal, who's in your circle, and the technical data needed to deliver on time. Once something ships — or you pay to cancel it — a record of that stays visible to your circle by design. We don't run ads, we don't use your data to train AI, and we don't sell your personal information. Cancellation fees are real payments, taken through Apple's App Store — Apple processes them, and we never see your card details.
1. Who we are
Commit is a product of Queri Labs and is powered by the Queri Platform. The service is operated by Queri K.K., a company organized under the laws of Japan ("Commit," "we," "us," or "our"). This Privacy Policy explains how we handle information when you use the Commit mobile application and the sayitpostitcommitit.com website (together, the "Service"; the legacy commit.queriapp.com addresses redirect there). Questions: hello@sayitpostitcommitit.com.
2. What Commit is (and why it matters for your data)
Commit is a communication app for delayed, irreversible posting. You write a post, direct message, or letter now and lock it to a future delivery time. Once sealed:
It cannot be edited or deleted. The only way to stop delivery is to cancel and incur the cancellation price you set yourself when sealing.
If you cancel, the item's content is permanently hidden, but a redacted "receipt" remains visible to the original audience, showing that you cancelled and the amount of your cancellation price.
Your friends ("witnesses") can see that something sealed is coming — the countdown, the kind of item, and your cancellation price — before it ships, and can react and comment on it.
Delivered posts remain on your record, and your kept/cancelled history (including totals paid to cancel) is visible to your circle, for example on the "Class of Fail" board.
This permanence is the product, not a side effect. Please post accordingly.
3. Information we collect
Information you provide
Account — the username (handle) and display name you choose, your email address (verified with a one-time code at sign-up, and used for password reset and account-related messages), a password (stored only as a salted hash), and optionally a short bio and a profile photo. We do not collect a phone number.
Content you create — posts, direct messages, and letters (including presentation choices such as letter penmanship, envelope, and signature style); comments, replies, likes, and emoji reactions; photos and videos you attach from your library or capture in-app with your camera; each item's scheduled delivery time, audience, self-set cancellation price, and optional add-ons (such as the last-minutes price-doubling add-on).
Your connections — friend requests, your friends list, and the private "inner circle" groups you create to filter your own feed (inner-circle membership is visible only to you, never to the members).
Reports — if you report content or an account, we collect the report, your selected reason, and the reported material.
Website forms — if you join the waitlist on our website, we collect your email address and language preference and use them to contact you about access to the app. If you contact support or request account deletion from the website, we collect what you submit there (name, email address, and your message).
Information created by using the Service
Cancellation ledger — a record of each cancellation ("bail") including the amount of your self-set price and, when it was paid for, the App Store transaction identifier for that purchase (never your card details). A cancellation paid with a Golden Ticket is recorded the same way, at an amount of zero. See Section 6.
Engagement records — which sealed posts you interacted with, and which ones you paid to look at early. A paid look is recorded once per person per post: the author of that post can see that you looked, and when; everyone else sees only how many people did.
In-app game activity — your plays in the crane game (when you played, what each play won), the collectibles and cosmetic unlocks on your account, and play credits you send to or receive from other users. This is bookkeeping for a free game: none of it is purchasable and none of it has monetary value — see Section 7 of the Terms.
Notifications & push tokens — in-app notification history and, if you enable push notifications, your device push token.
Device & log data — app version, device platform, language preference, authentication tokens, and server logs (timestamps, IP addresses, request metadata) used to operate and secure the Service.
Usage & diagnostics: which screens you opened and for how long, which buttons you tapped, when a session started and ended, and crash and error reports (the error type and the code path it came from). This is product measurement: it records names and numbers, never the contents of a post, letter, or DM.
Advertising and analytics. We serve no ads in the app. For product analytics we use PostHog, which processes the usage and diagnostics data described above on our behalf. Where we use identifiers or usage data in a way Apple classifies as tracking, we do so only with your permission. On iOS the app asks for your permission through Apple's App Tracking Transparency prompt before sending anything to PostHog; if you decline, nothing is sent to PostHog at all, and you can change your answer at any time in iOS Settings → Privacy & Security → Tracking. Our own first-party measurement (the same events, stored on our own servers alongside your account) continues either way, and is covered by Section 9 (retention) and Section 14 (your rights) like everything else we hold.
4. How we use information
To run the core mechanic: deliver your sealed items exactly when scheduled, show countdowns to their audience, and maintain the permanent record described in Section 2.
To notify you and your circle about sealed, arriving, and delivered items and activity from your circle (mentions, comments, likes, friend requests).
To record cancellations and apply the pricing rules you chose at sealing.
To review reported content, keep the Service safe, prevent abuse, and enforce our Terms of Service.
To diagnose problems, secure, and improve the Service.
To comply with legal obligations.
5. Legal bases
Where laws such as the EU GDPR apply, we rely on: performance of a contract (running the Service you signed up for, including its intentional permanence), legitimate interests (safety, security, anti-abuse, service improvement), consent (push notifications, camera, microphone and photo-library access, and, on iOS, sending usage data to PostHog: each requested via your operating system and revocable in system settings), and legal obligation.
6. Payments — important, please read
Cancelling costs real money. Cancellation prices ("bail," "cowardice fee") and the optional price-doubling add-on are charged as in-app purchases through Apple's App Store. Apple processes the payment; we never receive or store your card number. Two other things also charge: a paid look at a sealed photo or video, and a stake on someone's cancellation pool. See Sections 5 and 6 of the Terms for what each one does.
What we receive. When you pay a cancellation fee, Apple sends the app a signed confirmation of the purchase, which the app passes to us. From it we store the transaction identifier, the amount, and whether the purchase was made in Apple's production or sandbox environment — enough to release the cancellation, keep your record accurate, and stop the same purchase being reused. We do not receive your payment-card number, billing address, or Apple ID password.
Golden Tickets. A cancellation paid with a Golden Ticket involves no purchase and no payment data at all; only the cancellation itself is recorded.
Apple's handling of your payment is governed by Apple's own privacy policy and terms, not this one. Refund requests for App Store purchases go to Apple.
7. How information is shared with other users (by design)
Your profile (handle, display name, bio, photo, and kept/cancelled statistics) is visible to other users; a private-account setting limits who can follow your record.
Posts are visible to your accepted friends; DMs and letters are visible to their recipient.
Countdown metadata for sealed items (that something is coming, its kind, its cancellation price, aggregate reactions/comments/"already paid" counts) is visible to the item's future audience before delivery. The content stays hidden, except that a sealed photo or video can be shown briefly to someone who pays for a look — see Section 5 of the Terms. Sealed text, voice notes, DMs and letters are never visible before delivery.
If someone pays to look at your sealed photo or video, you can see who they were and when they looked.
Cancellation receipts (the fact of cancellation and the amount) remain visible to the original audience. Totals paid to cancel appear on your circle's "Class of Fail" board.
If you gift crane play credits to someone in your circle, they are told who sent them.
8. How we share information with third parties
Infrastructure — the Service runs on Amazon Web Services in the Asia-Pacific (Tokyo) region (ap-northeast-1). Media files are stored in Amazon S3 and served through Amazon CloudFront using signed, expiring URLs.
Push notifications — device push tokens are registered with AWS SNS, which delivers notifications through Apple's Push Notification service (on iOS) and Google's Firebase Cloud Messaging (on Android). Notification payloads necessarily transit Apple or Google.
Product analytics: usage and diagnostics data is sent to PostHog, Inc. (US region), which processes it as our service provider and is not permitted to use it for its own purposes. On iOS this happens only if you allowed it at the App Tracking Transparency prompt. PostHog never receives the contents of a post, letter, or DM.
Safety review — when content is reported, a review card (including the reported content and reporter context) is forwarded to a private Slack workspace used by our operations team. Slack, Inc. processes that data as our service provider.
Legal — when required by law, or to protect the rights, safety, and property of our users, the public, or us.
Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use your content or personal information to train AI models.
9. Retention — and the deletion tension you should understand
We keep your information while your account exists and as needed to provide the Service. Because permanence is the product, delivered content and cancellation receipts are intended to remain on the record indefinitely, including as they appear to other users.
When your account is deleted, your profile and content are removed from the Service, and we delete or de-identify associated personal information within a reasonable period, except where retention is required for legal compliance, dispute resolution, or fraud and abuse prevention. You can delete your account yourself at any time in the app under Settings → Delete account, which closes it immediately. If you cannot reach the app, you can request deletion here, where we also set out exactly what is removed and what we retain.
10. Security
The Service is hosted on Amazon Web Services in the Asia-Pacific (Tokyo) region. All traffic between your device and our servers is encrypted in transit with TLS. Stored media (photos, videos, voice notes) is encrypted at rest with AES-256, sits in private storage that blocks all public access, and is served only through signed URLs that expire within the hour. Passwords are stored only as salted bcrypt hashes, which means we cannot read them. Sessions use signed, expiring tokens kept in your device's secure keychain. Payments are processed by Apple, so your card details never touch our systems (Section 6).
Commit is not end-to-end encrypted. The Service has to hold your sealed content on our servers in order to deliver it at the exact moment you chose; that is the mechanic. Access to stored content is limited to what operating the Service requires, plus the safety review described in Section 11. On top of that, two commitments: we do not use your content or personal information to train AI models, and we do not sell your data to any third party.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but the safeguards above are how we run every day.
11. Malicious use: reporting, review, and paused delivery
We respect your freedom in what you transmit, and we do not screen or approve content before it ships. We also know the mechanic can be turned against people: because cancelling has a price, a commit sealed on a hacked account, or created in your name by someone else, or written to harass, would otherwise leave the person on the receiving end paying to stop it. Nobody should have to buy their way out of someone else's malice, so the Service is built with a clear exit:
Reporting is free, and it sits right next to the money. The report option is placed directly beside the payment and cancellation controls, visible at the exact moment you would otherwise be charged.
You tell us what happened. A report asks you to pick a reason (account hacked, a commit you did not create, bullying or harassment, harmful or dangerous content, private content shared without consent, or something else) and lets you add context.
The clock stops immediately. A reported commit is paused: its countdown freezes, it is hidden, and it will not ship or appear in any feed while it is under review. No cancellation fee is charged.
A person reviews every case. If the report holds up, the commit is removed and never delivers. If it does not, the commit resumes with exactly the time it had left.
The report sheet in the app. The timer stops, a person reviews it, no charge.
Deliberately false reports, including reporting your own commit to stall its delivery, are a misuse of the Service and may lead to enforcement under the Terms.
12. Children
The Service is not directed to children under 13 (or the higher minimum age your jurisdiction requires), and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
13. International transfers
Our infrastructure is located in Japan. If you use the Service from elsewhere, your information is transferred to and processed in Japan (which holds an EU adequacy decision) and by the service providers listed in Section 8. Where required, we implement appropriate safeguards for transfers.
14. Your rights
Depending on where you live (including under Japan's APPI, the EU/UK GDPR, and the California CCPA/CPRA), you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. Exercise them via hello@sayitpostitcommitit.com; we will verify your request against your account. We do not discriminate against you for exercising rights.
15. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the date above and, where appropriate, provide additional notice in the app.
16. Contact
Queri K.K. — Commit privacy team: hello@sayitpostitcommitit.com.
Commit is a product of Queri Labs, powered by the Queri Platform.