Developer Pact

Privacy Policy

Last updated 2 September 2026. Applies to developerpact.com, the Developer Pact platform, and the Developer Pact SDK embedded in participating apps.

Developer Pact measures whether a tester is still present. It is built so that it cannot measure anything else, and this page describes the whole of what it holds.

Who is responsible

Developer Pact is operated by the individual developer reachable at multi.app.software@gmail.com. That address is the contact point for any question, correction or deletion request in this policy.

This website

The pages on developerpact.com set no cookies, run no analytics, embed no trackers, and load no fonts, scripts, styles or images from any other domain. Nothing on this site follows you. The web server keeps ordinary access logs — the requested path, the response code, the time, and the requesting IP address — for operational and security purposes; they are rotated and not used to build any profile.

What the platform collects

Account identity

When you sign in with Google, we receive and store your Google account email address and display name. They are used to identify you as a member, to show you to the other members of your cohort, and to send you notifications about your own pact. We do not receive your Google password, and we do not request access to your Gmail, Drive, Calendar or contacts.

Apps you register

If you register an app as a developer, we store the package name of that app and the Play Console track membership you choose to connect. Both are supplied by you, deliberately. We do not scan your account for other apps.

Heartbeats from the SDK

When an app carrying the Developer Pact SDK is opened by a tester who joined through this platform, the SDK sends a daily heartbeat containing:

This is presence, not behaviour. The heartbeat does not contain screens visited, buttons pressed, session length, in-app content, crash data, advertising identifiers, or any device identifier beyond what Play Integrity returns where it is enabled. It does not contain location. It does not contain contacts. There is no general-purpose event or track() function in the SDK for the app's developer to call, by design, so that this claim can be verified by reading the SDK's surface rather than by trusting this paragraph.

Play Integrity verdicts

Where an app has Play Integrity enabled, we receive and store the integrity verdict Google returns — device integrity (for example MEETS_DEVICE_INTEGRITY) and application integrity. It is used for exactly one purpose: confirming that a heartbeat came from a genuine install of the genuine app on a real device, rather than from a script. We do not use it to identify or fingerprint the device, and the verdict is not shared with anyone.

Evidence you submit yourself

The lower rungs of the evidence ladder are things you send on purpose: a daily check-in, an answer to a proof prompt written by the app's owner, or a screenshot carrying a one-time value. We store what you submit, associated with the obligation it belongs to, so that the fourteen-day record can be reconstructed. Only send screenshots you are comfortable sharing with the app's developer.

Email notifications

We send you email about your own cohort — an obligation about to lapse, a partner who has gone quiet, a cohort that has filled or finished. These are service messages about a commitment you entered into, not marketing. Your address is used for that and for answering you when you write to us.

What we never collect

Why we are allowed to hold it

Everything above is collected either to perform the arrangement you asked to join — a cohort cannot function without knowing who is in it and whether they are still present — or on the legitimate interest of keeping that arrangement honest and the service secure. Where consent is the basis, as with Google sign-in, you give it at the consent screen and can withdraw it by deleting your account.

Where it is stored, and who else sees it

Data is stored in Google Cloud Firestore, in a United States multi-region (nam5). If you are in the EU or UK, your data is transferred to and processed in the United States under Google Cloud's standard contractual clauses. The only third parties involved are:

Beyond those two, nothing is shared. We do not sell personal data. We do not share it for advertising. We do not disclose it to data brokers, to app stores other than the attestation described above, or to anyone else — other than where we are legally compelled to.

Members of your own cohort see what the arrangement requires them to see: your display name, the apps you registered, and whether your obligations to them are being met. They do not see your evidence for obligations they are not party to.

How long it is kept

Account data is retained for as long as your account exists. Pact and evidence records are retained while the account exists, because a completed pact is part of the standing you carry into the next one. Delete the account and they go with it. Install tokens stop being valid thirty days after the pact they belong to ends. Server access logs are rotated on a short cycle.

Your rights, and how to use them

You can ask for a copy of what we hold about you, ask for it to be corrected, ask for it to be deleted, or object to our holding it. Write to multi.app.software@gmail.com from the address on the account, and say what you want. Deletion removes your account, your registered apps and your evidence records. If you are in an active pact, deleting your account ends your obligations in it, and the other members are told that the slot is empty — the record they need to see for their own fourteen days is what happened, not who you were.

Children

Developer Pact is a tool for people publishing apps on Google Play, and is not intended for or directed at children under 16. We do not knowingly collect data from them.

Changes

If this policy changes, the date at the top changes with it. If a change means we would collect something materially new, members will be told by email before it takes effect, not after.

Not affiliated with Google

Developer Pact is an independent product. It is not endorsed by, sponsored by, or affiliated with Google LLC. Google Play, Play Console and Play Integrity are Google's services, referred to here only to describe what this platform does.


Contact: multi.app.software@gmail.com