Privacy Policy
Last updated 2 September 2026. Applies to
developerpact.com, the Developer Pact platform, and the Developer
Pact SDK embedded in participating apps.
Developer Pact measures whether a tester is still present. It is built so that it cannot measure anything else, and this page describes the whole of what it holds.
Who is responsible
Developer Pact is operated by the individual developer reachable at multi.app.software@gmail.com. That address is the contact point for any question, correction or deletion request in this policy.
This website
The pages on developerpact.com set no cookies, run no analytics,
embed no trackers, and load no fonts, scripts, styles or images from any other
domain. Nothing on this site follows you. The web server keeps ordinary access
logs — the requested path, the response code, the time, and the requesting IP
address — for operational and security purposes; they are rotated and not used to
build any profile.
What the platform collects
Account identity
When you sign in with Google, we receive and store your Google account email address and display name. They are used to identify you as a member, to show you to the other members of your cohort, and to send you notifications about your own pact. We do not receive your Google password, and we do not request access to your Gmail, Drive, Calendar or contacts.
Apps you register
If you register an app as a developer, we store the package name of that app and the Play Console track membership you choose to connect. Both are supplied by you, deliberately. We do not scan your account for other apps.
Heartbeats from the SDK
When an app carrying the Developer Pact SDK is opened by a tester who joined through this platform, the SDK sends a daily heartbeat containing:
- a pact token — an opaque random value that identifies which obligation this install belongs to, and carries no data inside it;
- the package name of the app;
- a coarse timestamp — enough to answer "was this app opened on this day", and no finer.
This is presence, not behaviour. The heartbeat does not contain screens
visited, buttons pressed, session length, in-app content, crash data, advertising
identifiers, or any device identifier beyond what Play Integrity returns where it
is enabled. It does not contain location. It does not contain contacts. There is
no general-purpose event or track() function in the SDK for the app's
developer to call, by design, so that this claim can be verified by reading the
SDK's surface rather than by trusting this paragraph.
Play Integrity verdicts
Where an app has Play Integrity enabled, we receive and store the integrity
verdict Google returns — device integrity (for example
MEETS_DEVICE_INTEGRITY) and application integrity. It is used for
exactly one purpose: confirming that a heartbeat came from a genuine install of
the genuine app on a real device, rather than from a script. We do not use it to
identify or fingerprint the device, and the verdict is not shared with anyone.
Evidence you submit yourself
The lower rungs of the evidence ladder are things you send on purpose: a daily check-in, an answer to a proof prompt written by the app's owner, or a screenshot carrying a one-time value. We store what you submit, associated with the obligation it belongs to, so that the fourteen-day record can be reconstructed. Only send screenshots you are comfortable sharing with the app's developer.
Email notifications
We send you email about your own cohort — an obligation about to lapse, a partner who has gone quiet, a cohort that has filled or finished. These are service messages about a commitment you entered into, not marketing. Your address is used for that and for answering you when you write to us.
What we never collect
- No location data, of any precision.
- No contacts, calendar, photos, files or message content.
- No advertising identifiers, and no device identifiers beyond a Play Integrity verdict.
- No analytics of any kind on a tester's device.
- No content or usage data from inside the apps being tested.
- No payment details — there is no payment.
Why we are allowed to hold it
Everything above is collected either to perform the arrangement you asked to join — a cohort cannot function without knowing who is in it and whether they are still present — or on the legitimate interest of keeping that arrangement honest and the service secure. Where consent is the basis, as with Google sign-in, you give it at the consent screen and can withdraw it by deleting your account.
Where it is stored, and who else sees it
Data is stored in Google Cloud Firestore, in a United States
multi-region (nam5). If you are in the EU or UK, your data
is transferred to and processed in the United States under Google Cloud's
standard contractual clauses. The only third parties involved are:
- Google Cloud Platform, as the hosting and database provider, and Google's identity and Play Integrity services for sign-in and attestation;
- an email delivery provider, which handles the notification messages described above and therefore sees your email address and the text of those messages.
Beyond those two, nothing is shared. We do not sell personal data. We do not share it for advertising. We do not disclose it to data brokers, to app stores other than the attestation described above, or to anyone else — other than where we are legally compelled to.
Members of your own cohort see what the arrangement requires them to see: your display name, the apps you registered, and whether your obligations to them are being met. They do not see your evidence for obligations they are not party to.
How long it is kept
Account data is retained for as long as your account exists. Pact and evidence records are retained while the account exists, because a completed pact is part of the standing you carry into the next one. Delete the account and they go with it. Install tokens stop being valid thirty days after the pact they belong to ends. Server access logs are rotated on a short cycle.
Your rights, and how to use them
You can ask for a copy of what we hold about you, ask for it to be corrected, ask for it to be deleted, or object to our holding it. Write to multi.app.software@gmail.com from the address on the account, and say what you want. Deletion removes your account, your registered apps and your evidence records. If you are in an active pact, deleting your account ends your obligations in it, and the other members are told that the slot is empty — the record they need to see for their own fourteen days is what happened, not who you were.
Children
Developer Pact is a tool for people publishing apps on Google Play, and is not intended for or directed at children under 16. We do not knowingly collect data from them.
Changes
If this policy changes, the date at the top changes with it. If a change means we would collect something materially new, members will be told by email before it takes effect, not after.
Not affiliated with Google
Developer Pact is an independent product. It is not endorsed by, sponsored by, or affiliated with Google LLC. Google Play, Play Console and Play Integrity are Google's services, referred to here only to describe what this platform does.
Contact: multi.app.software@gmail.com