Last updated 2026-07-31.
To run WouldYouTho, we store: your email address; the dares you create and the pledges you make (amounts, timestamps, and which dare they belong to); and the customer and payment-method identifiers our payment processor gives us so it can charge or void a saved card later. We do not store your card number, expiry date, or CVC. That data goes directly to our payment processor and never touches our servers or database — we only ever hold their reference to it.
Our database is hosted by Supabase in an EU region. Card data is held by our payment processor under its own security and compliance program, not by us. Transactional emails — pledge receipts, status updates, review outcomes — are sent through Resend.
We don't run tracking cookies, third-party ad trackers, or cross-site analytics pixels on WouldYouTho. We don't sell your data, and we don't use it for anything beyond running the dare you created or backed: showing progress, sending the emails described above, processing the charge or the payout, and keeping the event log that lets us resolve disputes fairly.
We keep account and pledge records for as long as your account is active and for a reasonable period afterward to satisfy accounting, tax, and dispute-resolution obligations. The event log for a dare is kept indefinitely as the historical record of what happened, even after the dare itself is completed, cancelled, or expired.
To request deletion or a copy of what we hold about you, email xavier@xavierhaas.com. We will respond and act on legitimate requests as quickly as we can, subject to records we are required to keep for legal, tax, or dispute-resolution reasons.
See also our Terms of Service and our Imprint.