Last updated: July 13, 2026
App: ChallengeMe
Android package ID: com.yancom.challenge_me
iOS Bundle ID: com.yancom.challengeMe
Website: https://doubleshot.digital
This Privacy Policy explains how Double Shot OÜ ("Double Shot", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use the ChallengeMe mobile application, website, support services, and related features (together, the "Service").
ChallengeMe allows users to create, join, and complete challenges with tasks, progress tracking, interactive widgets, comments, reactions, shared content, media uploads, location-based tasks, push notifications, individual paid subscription features, and company-sponsored access.
By using ChallengeMe, you acknowledge that we collect, use, store, and share information as described in this Privacy Policy. If you do not want your information to be processed as described here, please do not use the Service.
1. Who We Are
The data controller responsible for your personal data is:
Double Shot OÜ
Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
Company registration number: 17485987
VAT number: No VAT number
Email: sergey@doubleshot.digital
Website: https://doubleshot.digital
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us at sergey@doubleshot.digital.
2. Scope of This Privacy Policy
This Privacy Policy applies to ChallengeMe on iOS and Android, including:
the ChallengeMe mobile application;
user accounts, profiles, challenges, tasks, comments, reactions, reports, and uploaded content;
free and paid features, including individual subscriptions and company subscriptions purchased through Stripe;
company-sponsored access based on eligible work email addresses and company email domains;
push notifications and support communications;
analytics, crash reporting, security, and attribution systems;
our website and support pages where they relate to ChallengeMe.
This Privacy Policy does not apply to third-party websites, platforms, app stores, payment processors, videos, maps, links, embedded web pages, or services that are not controlled by Double Shot OÜ. Those services have their own privacy policies.
3. Availability and Users
ChallengeMe is available in many countries and regions through the Apple App Store and Google Play, subject to store availability and local restrictions.
ChallengeMe is a general-audience application. It is not directed to children under 13. Users who are under the age of digital consent in their country or region should use the Service only with permission and supervision from a parent or legal guardian.
Because ChallengeMe includes user-generated content, public and private challenges, comments, reactions, media uploads, and user interaction features, parents and guardians should supervise use by minors.
4. Information We Collect
We collect information that you provide directly, information generated when you use the Service, and information processed by our third-party service providers.
4.1 Account and Profile Information
Depending on how you use ChallengeMe, we may collect:
email address;
username, display name, or profile name;
profile photo or avatar;
authentication information;
user ID and internal account identifiers;
account settings, language, country or region, and preferences;
subscription status and access rights;
work email address and email domain;
company or organisation name, company-sponsored eligibility, work email verification status, and related entitlement information.
You may be able to use some limited parts of the app without creating a full account. However, an account may be required for features such as creating challenges, joining challenges, saving progress, uploading content, interacting with other users, using paid features, or syncing data across devices.
4.2 User-Generated Content
ChallengeMe is built around user-created and shared content. We may collect and store content that you create, upload, publish, submit, send, or interact with, including:
challenges and challenge descriptions;
tasks, goals, instructions, progress, completion records, and timestamps;
text, notes, comments, chat-style messages, captions, and descriptions;
photos, images, videos, audio files, documents, and other uploaded files;
polls, quizzes, questions, answers, widgets, timers, counters, scratch cards, hidden text, maps, and other interactive content;
likes, reactions, shares, reports, moderation requests, and abuse reports;
public or private challenge visibility settings;
content shared with other users or through other apps.
Some content may be public or visible to other users depending on the privacy settings, challenge type, and sharing choices you select. Do not upload or publish information that you do not want others to see.
4.3 Media, Camera, Gallery, Microphone, and Files
With your permission, ChallengeMe may access your device camera, photo library, gallery, microphone, video picker, document picker, storage, or file system to let you create and complete challenges.
We may process and store uploaded media and files, including photos, videos, audio recordings, documents, and related metadata. Uploaded media may be stored in services such as Firebase Storage or Supabase and may remain stored until you delete the content, delete your account, or ask us to delete it, subject to backup, legal, security, and technical retention periods.
ChallengeMe does not require you to upload sensitive content. However, because users control what they upload, user content may accidentally or voluntarily include sensitive information, such as faces, voices, children, health-related information, private addresses, documents, personal opinions, or other private data. Please do not upload sensitive personal data unless it is necessary for your use of the Service and you are comfortable with how the content may be processed and shared according to your settings.
4.4 Location Data
With your permission, ChallengeMe may access your device location to support maps and location-based challenge features. This may include precise or approximate location data depending on your device settings.
We may use location data to:
show your position on a map;
help create or complete location-based tasks;
verify or support challenge progress;
display nearby or relevant map information;
improve app functionality and security.
We do not intentionally share your live device location with other users by default. However, if you create public content, location-based tasks, map content, screenshots, descriptions, or other content that includes location information, that information may become visible to other users according to your sharing settings.
You can control location permissions in your device settings.
4.5 Device, App, Usage, and Diagnostic Information
We may collect technical and usage information, including:
device model and device type;
operating system and version;
app version and build number;
language, locale, country, or region;
device identifiers, app instance identifiers, Firebase installation ID, user ID, and internal identifiers;
Android Advertising ID or similar advertising/attribution identifiers where available and permitted;
crash logs, error logs, diagnostics, performance data, and debugging information;
usage events, screens viewed, features used, interactions, session information, and engagement data;
push notification tokens;
connectivity and security-related signals.
Although we do not use IP address as a normal profile field, IP addresses and network information may be processed automatically by app stores, cloud infrastructure, analytics providers, security systems, link preview systems, maps, webviews, external websites, and other service providers as part of ordinary internet communication, security, logging, fraud prevention, and service delivery.
4.6 Purchase, Company, and Subscription Information
ChallengeMe is free to download and may offer individual paid subscriptions, company subscriptions, or paid content. Individual payments may be processed by Apple App Store, Google Play, and subscription infrastructure such as RevenueCat. Company subscriptions are processed through Stripe or another authorised payment provider.
For a company subscription, we may collect or receive information from the company customer, its authorised representative, eligible employees, and Stripe, including:
company or organisation name;
authorised representative's name, business contact details, and role;
work email addresses and approved company email domain or domains;
work email verification and company-sponsored eligibility status;
billing address, country or region, and tax or VAT information;
Stripe customer, subscription, invoice, payment, product, price, and transaction identifiers;
subscription status, billing period, renewal date, expiration date, cancellation status, payment status, and entitlement status.
We do not receive or store full payment card numbers, complete bank account credentials, or card security codes entered into payment interfaces controlled by Apple, Google, Stripe, or another payment provider. Those providers process payment credentials under their own privacy terms. We may receive limited payment method information, such as card brand, last four digits, or payment status, where made available for billing, support, fraud prevention, and recordkeeping.
We use a user's work email address and email domain to verify whether the user is eligible for company-sponsored access and to maintain that access while the relevant company subscription remains active. Purchasing a company subscription does not by itself give the company access to an employee's private challenges, private content, or individual app activity. If we introduce company administrator reporting or other company-visible features, we will describe the relevant data sharing in the feature, an applicable agreement, or an updated privacy notice.
4.7 Support Communications
If you contact us for support, privacy requests, account deletion, abuse reports, business inquiries, or other questions, we may collect your email address, message content, attachments, screenshots, device/app details, and any information you choose to provide.
Support communications may be retained for customer support, legal protection, security, fraud prevention, and recordkeeping purposes.
4.8 Calendar, Links, WebView, and External Content
ChallengeMe may allow you to add challenge reminders or events to your device calendar. Calendar actions are typically handled on your device and may require device permission.
ChallengeMe may also include links, link previews, embedded web pages, YouTube videos, external websites, or content opened through a browser or webview. When you interact with external content, third-party services may collect information according to their own privacy policies. We are not responsible for the privacy practices of third-party websites or services.
5. How We Use Information
We use personal data for the following purposes:
to provide, operate, maintain, and improve ChallengeMe;
to create and manage user accounts and authentication;
to let users create, join, complete, share, and track challenges;
to store and display user-generated content according to user settings;
to enable comments, reactions, reporting, moderation, and community safety features;
to process photos, videos, audio, documents, and other uploaded files;
to provide maps and location-based tasks;
to send push notifications, reminders, updates, and service messages;
to manage subscriptions, purchases, entitlements, refunds, support, and fraud prevention;
to create and administer company subscriptions, process Stripe billing, verify approved company email domains, and provide eligible employees with company-sponsored access;
to confirm whether a work email remains eligible and to suspend or end company-sponsored access when the company subscription or employee eligibility ends;
to personalize app experience, language, and content;
to analyze app performance, crashes, usage trends, and feature effectiveness;
to detect, prevent, and respond to abuse, fraud, spam, security incidents, and policy violations;
to measure installs, referrals, affiliate campaigns, purchase conversions, and partner commissions;
to comply with legal obligations and enforce our rights, terms, and policies.
6. Legal Bases for Processing Personal Data
If you are located in the European Economic Area, the United Kingdom, Switzerland, or another region with similar privacy laws, we rely on one or more legal bases to process your personal data:
Performance of a contract: to provide ChallengeMe features you request, manage your account, store your content, process individual and company subscriptions, verify company-sponsored eligibility, and deliver the Service.
Consent: where you grant device permissions, enable push notifications, allow access to location, camera, microphone, photos, files, or other optional features, or where consent is required for certain analytics, advertising, or tracking practices.
Legitimate interests: to maintain, secure, improve, debug, analyze, and protect the Service; administer company access; verify work email eligibility; prevent abuse; moderate content; respond to support requests; and understand app performance.
Legal obligations: to comply with tax, accounting, consumer protection, app store, law enforcement, and regulatory obligations.
Protection of rights and safety: to protect users, the public, Double Shot OÜ, and third parties from fraud, abuse, security threats, or unlawful activity.
You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that occurred before withdrawal.
7. Public Content, Private Content, and User Responsibility
ChallengeMe may allow both public and private challenges. Content visibility depends on the feature, challenge settings, sharing settings, and your actions.
Public content may be visible to other users and may include your display name, avatar, challenge content, uploaded media, comments, reactions, progress, or other information connected with the public challenge.
Private content is intended to be available only to permitted users or participants, but no online system can guarantee absolute privacy. Users who have access to private content may copy, screenshot, save, or share information outside the app.
You are responsible for the content you upload, publish, or share. Do not upload content that violates the rights of others, contains private information without permission, or is inappropriate, illegal, harmful, abusive, or unsafe.
8. Moderation, Reports, and Safety
ChallengeMe may moderate content and user activity to protect users and enforce our policies. Moderation may include automated checks, manual review, user reports, account restrictions, content removal, or other safety actions.
When users report content or accounts, we may process the reported content, reporting reason, user IDs, timestamps, screenshots, messages, comments, media, and other relevant information. We use this information to investigate abuse, protect users, enforce policies, and comply with legal obligations.
We cannot guarantee that all harmful or inappropriate content will be detected or removed immediately.
9. Advertising, Referral, Affiliate, and Attribution Practices
ChallengeMe may show ads, promotions, partner offers, referral links, affiliate links, or other promotional content. We do not currently use a third-party advertising SDK, but we may use referral, affiliate, deep-linking, and attribution technologies to measure campaigns and calculate partner commissions.
This may involve processing or sharing limited information such as:
app install or app open events;
deep link or referral link information;
campaign, creator, partner, or affiliate identifiers;
purchase or subscription conversion events;
subscription status or product ID;
transaction or receipt identifiers;
Android Advertising ID or other attribution identifiers where available and permitted;
app instance IDs, user IDs, device/app information, country or region, and timestamps.
We do not currently use Apple IDFA on iOS. If we introduce IDFA or other tracking that requires App Tracking Transparency permission, we will request permission where required.
Under some privacy laws, sharing data for affiliate attribution, targeted advertising, cross-context behavioral advertising, or similar measurement may be considered a "sale", "sharing", or "targeted advertising" even if we do not sell personal data for money. You may contact us at sergey@doubleshot.digital to request an opt-out where applicable.
You can also limit advertising identifiers in your device settings, including resetting or limiting the Android Advertising ID where supported by your device.
10. Push Notifications
If you allow push notifications, we may send reminders, challenge updates, progress messages, service notifications, promotional messages, or other app-related notifications. We may process push notification tokens and related delivery information.
You can disable push notifications at any time in your device settings.
11. When We Share Information
We may share personal data with the following categories of recipients where necessary for the purposes described in this Privacy Policy:
11.1 Cloud, Database, Storage, and Backend Providers
We use providers such as Firebase, Google Cloud, Firebase Cloud Functions, Firestore, Firebase Realtime Database, Firebase Storage, Supabase, and related infrastructure to authenticate users, store data, store uploaded media, run backend logic, deliver app functionality, secure the Service, and process logs.
11.2 Analytics, Crash Reporting, and Remote Configuration Providers
We use services such as Firebase Analytics, Google Analytics for Firebase, Firebase Crashlytics, Firebase Remote Config, App Store Connect analytics, Google Play Console analytics, and related tools to understand app performance, diagnose crashes, improve features, and manage app configuration.
11.3 Payment and Subscription Providers
We use Apple App Store, Google Play Billing, RevenueCat, and Stripe to process individual and company subscriptions, collect recurring payments, verify purchases, manage entitlements, detect fraud, provide subscription support, issue or record refunds where applicable, and maintain billing, tax, and accounting records. Stripe processes information under its own privacy policy, available at https://stripe.com/privacy.
11.4 Maps, Links, WebView, Video, and External Content Providers
Features such as maps, webviews, link previews, YouTube content, external websites, and browser links may involve third-party services. When you interact with these services, they may process information under their own privacy policies.
11.5 Affiliate, Referral, and Attribution Partners
We may share limited attribution and purchase conversion information with affiliate, referral, creator, marketing, or campaign partners to measure referrals, attribute purchases, prevent fraud, and calculate commissions. We aim to share only the data reasonably necessary for these purposes.
11.6 Legal, Safety, and Business Purposes
We may disclose information if we believe it is necessary to:
comply with law, regulation, legal process, or government request;
enforce our terms, policies, or rights;
protect the safety, rights, property, or security of users, Double Shot OÜ, or others;
detect, investigate, or prevent fraud, abuse, security incidents, or unlawful activity;
support a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction.
12. AI Processing
ChallengeMe does not currently use artificial intelligence providers to generate, analyze, or moderate user content. If we introduce AI-based features in the future, such as challenge generation, content analysis, recommendations, or moderation, we will update this Privacy Policy as needed and explain what data is sent to AI providers.
13. Third-Party Services and SDKs
ChallengeMe may use or integrate with third-party services, SDKs, frameworks, and platforms, including but not limited to:
Firebase Core, Firebase Auth, Firebase Analytics, Firebase Crashlytics, Firebase Remote Config, Firebase Cloud Functions, Firestore, Firebase Realtime Database, and Firebase Storage;
Google Cloud and Google Analytics for Firebase;
Supabase;
RevenueCat;
Apple In-App Purchase and Google Play Billing;
Stripe Billing, Stripe Checkout, Stripe-hosted subscription management or customer portal features where enabled, and related Stripe payment services;
Apple App Store and Google Play Console analytics;
Google Maps;
device permission, media picker, video player, audio player, PDF viewer, webview, link preview, URL launcher, deep-linking, sharing, and file handling libraries;
YouTube player and external web content;
affiliate, referral, or attribution tools;
push notification infrastructure.
These third-party providers may process personal data according to their own terms and privacy policies. We encourage you to review the privacy policies of any third-party services you interact with.
14. Data Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
In general:
account data is retained until you delete your account or request deletion, subject to legal, security, and backup retention;
user-created challenges, tasks, comments, reactions, and progress are retained until you delete them, delete your account, or they are removed under our policies;
uploaded photos, videos, audio files, and documents are retained until deleted by you, removed by us, or deleted with your account, subject to backup and technical retention;
purchase, Stripe billing, invoice, payment, company subscription, and entitlement records are retained as long as needed for subscription management, employee eligibility, support, fraud prevention, legal, accounting, tax, and payment-provider obligations;
work email, company domain, and company-sponsored access records are retained while needed to provide access and for a reasonable period afterward for security, support, audit, dispute, and legal purposes;
analytics and crash logs are generally retained according to the default retention settings of our service providers unless we configure a shorter or longer period;
support communications may be retained as long as necessary for support, legal protection, security, and recordkeeping;
reports, moderation records, and abuse-prevention records may be retained as needed to protect users and enforce our policies;
backup copies may remain for a limited period before they are deleted or overwritten.
When we no longer need personal data, we will delete it, anonymize it, or retain it only where legally permitted.
15. Account Deletion and Data Deletion
You can request deletion of your account and personal data:
inside the ChallengeMe app, where account deletion is available; or
by contacting us at sergey@doubleshot.digital.
We aim to process deletion requests within 30 days, unless a longer period is required or permitted by law.
Deleting your account may delete or disable access to your profile, private data, uploaded content, progress, and account-related information. Some information may remain where necessary for:
legal, accounting, tax, app store, Stripe, or other payment obligations;
fraud prevention, security, and abuse prevention;
resolving disputes;
protecting other users;
backup and disaster recovery systems;
content that other users have copied, shared, commented on, or interacted with;
public content where retention is legally permitted or technically necessary.
If you only want to delete specific content, you may be able to delete that content directly in the app.
Deleting an employee's ChallengeMe account does not cancel the company's Stripe subscription or affect other eligible employees. It ends that user's company-sponsored access and is handled as an individual account deletion request. A company subscription must be cancelled separately by the company customer or another authorised representative using the available subscription-management method or by contacting us.
16. Your Privacy Rights
Depending on where you live, you may have rights to:
access personal data we hold about you;
request correction of inaccurate personal data;
request deletion of personal data;
request restriction of processing;
object to certain processing;
withdraw consent where processing is based on consent;
request data portability;
opt out of certain advertising, targeted advertising, sale, sharing, or profiling practices where applicable;
lodge a complaint with a data protection authority.
To exercise your rights, contact us at sergey@doubleshot.digital. We may ask you to verify your identity before responding to a request.
If you are located in the European Economic Area, you may also contact your local data protection authority. Because Double Shot OÜ is established in Estonia, the Estonian Data Protection Inspectorate may be relevant for certain matters.
17. U.S. State Privacy Notice
If you are a resident of a U.S. state with applicable privacy laws, you may have additional rights, such as the right to know, access, correct, delete, obtain a copy of, or opt out of certain uses or disclosures of personal information.
We do not sell personal information for money. However, certain referral, affiliate, advertising, analytics, or attribution activities may be considered a "sale", "sharing", or "targeted advertising" under some U.S. state privacy laws.
You may contact us at sergey@doubleshot.digital to request access, deletion, correction, or opt-out rights where applicable.
18. Children’s Privacy
ChallengeMe is not directed to children under 13. We do not knowingly collect personal data from children under 13 without appropriate parental consent.
If you are a parent or guardian and believe that a child under 13 has provided personal data to us, contact us at sergey@doubleshot.digital. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will take reasonable steps to delete that information.
Users under the age of digital consent in their country or region should use the Service only with permission and supervision from a parent or legal guardian.
19. Security
We use reasonable technical and organizational measures designed to protect personal data. These may include HTTPS, authentication controls, cloud provider security features, access controls, monitoring, encryption in transit, encryption at rest where provided by our infrastructure providers, and security practices for backend systems.
However, no method of transmission, storage, or electronic processing is completely secure. We cannot guarantee absolute security.
You are responsible for keeping your account credentials secure and for using caution when sharing content publicly or with other users.
20. International Data Transfers
Double Shot OÜ is based in Estonia. We may process and store personal data in the European Economic Area and other countries where our service providers, infrastructure, app stores, analytics providers, payment providers, support tools, or partners operate.
When personal data is transferred internationally, we rely on appropriate safeguards where required by applicable law, such as contractual protections, Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms.
21. Local Device Storage and Cached Data
ChallengeMe may store certain information locally on your device, such as app settings, cached images, downloaded media, temporary files, login/session information, local database entries, preferences, or progress-related data.
You may be able to delete local data by using in-app controls, deleting downloaded content, signing out, clearing app storage, or uninstalling the app. Some locally stored information may not be accessible to us because it remains only on your device.
22. Communications and Marketing
We may send service-related messages, app updates, challenge reminders, push notifications, and support communications. We may also show in-app promotions or partner offers.
Where required by law, we will request your consent before sending marketing communications or tracking notifications. You can opt out of push notifications through your device settings and unsubscribe from marketing emails if such emails are offered.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may notify you through the app, website, app store listing, email, or another appropriate method.
The "Last updated" date at the top of this Privacy Policy indicates when it was last revised. After changes become effective, we will process information according to the updated Privacy Policy.
24. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our privacy practices, contact us at:
Double Shot OÜ
Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
Company registration number: 17485987
Email: sergey@doubleshot.digital
Website: https://doubleshot.digital