Privacy Policy
How OptimusX Group (Pty) Ltd collects, uses and protects your information when you use Overcome.
Effective date: 21 August 2026 · Last updated: 21 August 2026
Who we are and what this policy covers
Overcome is a recovery support application published by OptimusX Group (Pty) Ltd, a company registered in the Republic of South Africa under registration number 2026/657042/07 ("OptimusX", "we", "us", "our"). We are the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA), and the data controller where the GDPR applies.
This policy applies to the Overcome mobile and web applications, our coach tools, and any related services that link to it. It explains what we collect, why, who it goes to, how long we keep it, and the choices you have. It does not apply to a third-party website or service you reach from a link inside the app, which will have its own policy.
Overcome is built for people working on recovery. Much of what you record here is information about your health, and we treat all of it as sensitive whether or not the law where you live classifies it that way.
Overcome is a recovery-support and journalling tool. It is not a medical service, it does not diagnose, treat or prevent any condition, and it does not create a clinical or therapeutic relationship between you and us.
Information we collect
Information you give us
- Account details: your email address, your password (stored only as a cryptographic hash, never in a readable form), and optionally your first and last name, phone number, country and time zone. If you sign in with Google or Apple we receive your email address and name from that provider instead, and you have no password with us at all.
- Community identity: the alias and cartoon avatar you choose. These exist so you can take part in the community without using your real name. There are no photo uploads.
- Recovery information you enter: your recovery start date, the focus areas you are tracking and any custom counters you create, your daily check-ins (mood, anxiety, stress, cravings, sleep, energy and confidence), your one-off starting assessment, journal and workbook entries, free writing, goals and habits, daily pledges, urge logs including how strong the urge was and what set it off, coping techniques you used, resets you record, and milestones you reach.
- What you say to the companion: the messages you send to the in-app companion, and the facts it remembers about you between conversations. You can see, edit and delete what it remembers, and turn the memory off entirely.
- Trusted contact details: the name and contact details of a person you nominate for support. We store these for you to reach; we do not contact them ourselves. You are responsible for having their permission before you enter them.
- Dictation: if you use the microphone button to speak instead of type, your speech is turned into text by your device’s own speech service — see the third-party section below. We store the text, never the audio.
- Support correspondence: messages you send us, and what you exchange with a coach through the app.
Information we collect automatically
This list is short, and it is complete. Overcome contains no analytics SDK, no crash-reporting SDK, no advertising identifier and no third-party tracker of any kind.
- Sign-in security information: when you sign in, we record the IP address and browser or device description of that session against the sign-in itself, so a stolen session can be detected and ended. We do not use it to work out where you are, and we do not build a location or profile from it.
- Reminder delivery information: if you turn on reminders in the installed web app, we store the push subscription your browser issues, whether the device is a phone, tablet or desktop, and your time zone, so a daily reminder arrives at the right local hour.
- Device storage: the app keeps your session, your theme and your app-lock settings on your own device.
We do not collect your location. We do not track which screens you open. We do not collect crash or diagnostic reports from inside the app. We do not use advertising identifiers, and there is no third-party advertising anywhere in Overcome.
Separately from the app, Apple and Google may collect crash reports from your device at the operating-system level if you have allowed them to. That is their collection under their own policies, not ours, and we receive only aggregate crash counts from the stores.
Information from others
- From a coach: if you connect to a coach, that coach may record notes and session records about you and assign you tasks within the app.
- From our payment provider: if you buy a subscription, we receive confirmation of the transaction, the plan and its status, and a reusable token that stands in for your card. We never receive or store your card number.
How we use your information
- To provide the service: to create and maintain your account, keep your counters and streaks accurate, save your entries, and sync your data across your devices.
- To show you your own progress: to calculate your recovery score, trends, milestones and weekly reflections. These are self-tracking numbers derived from what you recorded — they are not a clinical measurement of anything.
- To connect you to a coach, where you have chosen to, and to share with that coach only the categories you have agreed to share.
- To produce written summaries, supportive prompts and reflections using a third-party AI service, as described in the AI section below.
- To keep the service safe and working: to detect and prevent fraud and abuse, to moderate reported community content, and to enforce our terms.
- To communicate with you: reminders you have turned on, security notices, and replies to your support requests.
- To take payment, where you are on a paid plan.
- To meet legal obligations: to keep the financial records the law requires us to keep, and to respond to lawful requests.
We do not use your recovery information to build advertising profiles, we do not sell it, and we do not show you third-party advertising.
Our lawful basis — consent
Everything sensitive in Overcome is here because you chose to put it here. Our lawful basis for processing your personal information, and in particular your health-related information, is your consent.
- Consent to the service: you consent when you create an account and accept these documents. Recording a check-in, writing a journal entry or starting a counter is you choosing to give us that information.
- Consent for special personal information: information about your health, including substance use, cravings, mood, anxiety and what you write in your journal, is special personal information under POPIA section 26 and special category data under GDPR Article 9. We process it only with your consent, given under section 27(1)(a) of POPIA and Article 9(2)(a) of the GDPR.
- Consent to share with a coach: connecting to a coach, and each of the seven sharing categories, is separately yours to switch on and off at any time.
- Consent to the AI features: the summaries and reflections described below rely on sending content to a third-party AI provider. Where a feature does that, it is described as such and you can choose not to use it.
- Withdrawing consent: you can withdraw any of it at any time — turn a sharing category off, turn the companion’s memory off, leave the community, or delete your account. Withdrawing does not affect processing that already, lawfully, took place.
- Where we must keep something anyway: after you delete your account we keep a small set of financial records because tax and company law require it, not because you consented. Those records are listed by name in the retention section.
A coach on Overcome is a recovery coach, not a registered health practitioner, and coaching through this app is not medical or psychological treatment. Nothing you record here becomes a clinical record.
Third parties your information is sent to
These are the only services outside Overcome that receive your information, and exactly what reaches each one. Where content leaves our systems we say so plainly, because "we collect" and "we send it somewhere" are different promises.
Google (Gemini) — our AI provider
Overcome uses Google’s Gemini API to write summaries, supportive prompts and reflections. This is a genuine transfer of your content to a third party, not processing that stays inside our systems.
- Journal and workbook entries: the full text of an entry is sent to Google every time you save it and every time you edit it, so a summary can be written and stored alongside it.
- Companion messages: the message you type, together with recent messages in that conversation.
- Your context, sent with companion messages: your first name or the name you asked to be called, what you are working on, how long you have been at it, your recovery score, your check-in streak, your most recent mood and craving scores, a plain-language summary of your recent trend, your stated goal and reasons, coping strategies that have worked for you, milestones you have reached, recurring themes from your journal, and the patterns we have measured in your own data.
- Coach briefings: when a briefing is prepared for a coach you are connected to, your full name is sent, along with up to 200 characters from each of your recent journal entries — but only if you have journal sharing switched on. With it off, no journal text is sent and the briefing says only how many entries you wrote.
- Weekly reflections: your own weekly statistics, so the reflection can be written in words rather than numbers.
We use the paid Gemini API rather than a consumer product, and we rely on Google’s terms for that API, under which content sent to it is not used to train their models. If we change AI provider we will name the new one here before the change takes effect. A second provider, Anthropic, is configured as a fallback and receives the same content on the same terms if it is ever used.
If you would rather nothing you write reached an AI provider, do not use the companion, and turn journal sharing off so no journal text is included in a coach briefing. Your entries are still saved, summarised only by the parts of the app that never leave our systems.
Apple and Google — speech recognition
The microphone button uses the speech recognition built into your phone or browser. When you dictate, your speech is handled by Apple’s speech service on an Apple device and Google’s on an Android device or in Chrome, which may process it on their servers rather than on the device. That handling is governed by their privacy policies, not ours. We never receive the audio — only the text it produced, which then becomes an ordinary journal entry or note. Do not use dictation if you would rather your voice did not reach them; typing does exactly the same thing.
Paystack — payments
If you are on a paid plan, our payment provider Paystack receives your email address, your first and last name, the amount, and an internal reference identifying the account or invoice. You enter your card on Paystack’s own page — it never passes through Overcome, and we hold only a token that lets us charge the same card again.
Neon and Render — hosting
Neon hosts the database in which everything described above is stored. Render hosts the application and the interface you use, and therefore handles all traffic between your device and us. Both are engaged under terms requiring appropriate security, confidentiality, and use of the data only to provide their service to us.
Email delivery
An email delivery provider sends account emails such as verification and password reset messages, and receives your email address in order to do so.
Push delivery
If you turn reminders on in the installed web app, the reminder is delivered through your browser’s push service — operated by Google, Mozilla or Apple depending on your browser. The message is encrypted to your device before it leaves us.
Artificial intelligence and automated processing
- What it is: a text generator. It produces supportive and reflective language from what you have recorded, as set out in the section above.
- What it is not: it is not a clinician. It does not diagnose, it does not assess you, it does not treat anything, and it makes no decision about you, your care or your access to the service.
- No decisions with legal or significant effects: we do not use automated processing to make decisions that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 of the GDPR and section 71 of POPIA.
- Accuracy: generated text can be wrong or clumsy. It is a prompt for your own reflection, never a statement of fact about you, and never a substitute for professional advice.
- Not used for training: we use the Gemini API under terms that do not permit your content to be used to train their models.
- Your choice: every feature that relies on it is described as such, and you can decline all of them and still use Overcome.
How we share your information
We do not sell your personal information, and we have never sold it. We do not share it for cross-context behavioural advertising.
Beyond the providers named above, we share only:
- With your coach, if you connect to one: a coach you are linked to can see the categories you have chosen to share, your progress, and any sessions or tasks recorded. A coach can only ever see clients assigned to them. You can disconnect at any time, and you can turn any category off without disconnecting.
- With other members, in the community: only what you post, and only under your alias — never your real name or email address. You can report a post or comment for us to review, delete your own posts, and leave the community entirely at any time.
- For legal reasons: where required by law, court order or a valid request from a public authority, or where necessary to establish, exercise or defend legal claims.
- To protect people: where we believe in good faith that disclosure is necessary to prevent or address a serious risk to anyone’s life or safety.
- In a business transfer: if OptimusX is involved in a merger, acquisition or sale of assets. We will tell you before your information becomes subject to a different privacy policy, and you will be able to delete your account first.
- With your direct permission: any other sharing you ask for.
Taking your data with you
You can ask us for a copy of everything you have put into Overcome, at any time, by writing to overcome@optimusx.co.za from the address on your account. We send it as a JSON file, which any computer can read, within 30 days and usually much sooner. There is no charge.
- What is in it: your account and profile, your recovery profile, counters, goals and history, every check-in, mood log, pledge, urge log and coping-tool use, your journal and workbook entries, your habits and lesson completions, your companion conversations and the facts it remembers, your weekly reflections, tasks assigned to you, your community profile, posts, comments and reactions, your settings and sharing choices, your notifications, and your subscription plan and dates.
- What is not, and why: a coach’s own notes and session records about you are that coach’s professional observations, written under their own obligations — tell us if you need them and we will deal with that request individually. Other members’ community content is not yours to export. Passwords, session tokens and card tokens are never included, because handing over a credential would turn a privacy feature into a way to steal one.
Ask for your copy before you delete, if you want to keep any of it. Deletion cannot be undone and we cannot recover an account afterwards.
Deleting your account
You can delete your account yourself, at any time, from Settings → Delete account. There is no form to fill in and no waiting period.
- How it is confirmed: you re-enter your password, tick an acknowledgement and confirm once more. It is your own deliberate act, on top of already being signed in.
- If you signed in with Google or Apple: you have no password with us, so the in-app route cannot confirm it is you. Write to overcome@optimusx.co.za from the address on your account and we will delete it for you within 30 days, and usually within a few days. We are building the in-app route for these accounts and will update this policy when it is live.
- What it does: it deletes your account and everything attached to it — your profile, recovery profile, counters, goals, check-ins, journal and workbook entries, urge logs, habits, lessons, companion conversations and remembered facts, community profile, posts, comments and reactions, notifications, reminder subscriptions, trusted contacts, your coach connection, and the notes and tasks recorded against you.
- It is immediate and permanent: it happens when you confirm it, not after a waiting period, and it cannot be undone.
- A coach cannot prevent it: if you are connected to a coach, deleting your account deletes your records regardless of any retention the coach would prefer. Your decision about your own data is the one that counts.
What survives deletion, and why
Four kinds of financial record outlive the account, because South African tax and company law require us to keep books that add up. None of them contains health information, anything you wrote, or your name — they are amounts, dates and an internal reference:
- Roster events: a dated record that an account joined or left a coach’s roster, which is what makes an invoice explainable afterwards.
- Invoice lines: the amount charged for one client line on a coach’s invoice.
- Rate change notices: the record that notice of a price change was given before it took effect.
- Capacity events: the record that a coach’s roster changed size.
We also keep the raw records our payment provider sends us about transactions, which include the email address used at the time. We keep these for the period South African tax and company law require, and we use them for nothing else.
If you were an archived client of a coach
A coach may archive a client rather than disconnect them, which keeps that client’s case file available to the coach for 12 months by default. Archiving is not deletion and never overrides it: if you delete your account, the archived file goes with it.
How long we keep your information
- While your account is open: we keep your account and recovery data so the service works and your history stays intact.
- When you delete your account: your data is deleted at that moment, other than the financial records named in the section above.
- Backups: copies may persist in our hosting providers’ encrypted backups for up to 30 days after deletion, after which they are overwritten on the normal backup cycle.
- Sign-in security records: the IP address and device description attached to a session are removed when that session expires or is ended, and in any case when the account is deleted.
- Archived coach case files: 12 months by default, unless you delete your account first.
- Support correspondence: up to 24 months from the last message.
- Financial records: for the period required by South African tax and company law.
- Aggregated and de-identified information: information that can no longer be linked to you may be kept indefinitely for statistics and product improvement.
Your rights and how to exercise them
Subject to the law that applies to you, you have the following rights over your personal information.
- Access: to be told whether we hold information about you and to receive a copy. Most of it you can already see in the app; write to us for the full copy.
- Correction: to have inaccurate or incomplete information corrected. You can edit almost everything yourself.
- Deletion: to have your information deleted, subject only to the financial records named above. Settings → Delete account does this immediately.
- Portability: to receive your information in a structured, commonly used, machine-readable format. Ask us and we send it as JSON.
- Restriction: to ask us to limit how we use your information while a question about it is resolved.
- Objection: to object to processing, and to object to direct marketing at any time.
- Withdraw consent: to withdraw any consent you have given, including consent to share with a coach and consent to health-information processing.
- Complain: to your data protection authority, named in the regional sections below.
Correction, deletion and withdrawing consent you can do in the app. For access and portability, and for anything else, write to overcome@optimusx.co.za. We will respond within 30 days and will tell you if we need longer. We do not charge for these requests unless they are manifestly unfounded or excessive, and we will never treat you differently for making one.
If Overcome is discontinued
If we decide to shut the service down, we will give you at least 60 days’ notice by email and in the app before any data is deleted. During that period you may ask us for a copy of everything. At the end of it we will permanently delete or irreversibly anonymise all personal information we hold, other than records we are legally required to retain. We will not sell your personal information as part of a wind-down, and if the service is transferred to another operator we will tell you who they are and let you delete your account before the transfer takes effect.
How we protect your information
- Encryption in transit: all traffic between your device and our servers uses TLS, and so does the connection between our application and our database.
- Encryption at rest: the database and its backups are encrypted by our hosting provider.
- Password handling: passwords are stored only as salted Argon2 hashes and are never readable by us. Session tokens are stored as hashes too.
- Session security: sessions rotate, and a replayed session token invalidates the whole family of tokens it belongs to.
- Access control: coaches reach only their own assigned clients, organisations are isolated from one another, and staff access is limited to what is needed to run and support the service.
- Device lock: you can turn on an app lock — a PIN, and fingerprint or face unlock where your device supports it — so the app cannot be opened by someone holding your phone.
We do not encrypt individual entries with a key only you hold, which means your journal is readable to the small number of people who administer the database. We would rather say so than imply a protection that is not there. No service can promise perfect security; if a breach affects your personal information and creates a risk to you, we will notify you and the Information Regulator as POPIA requires, without undue delay.
International transfers
We are based in South Africa. Our database is hosted in the European Union, and our AI, payment, hosting and email providers may process information in the European Union, the United Kingdom, the United States or elsewhere. Your information may therefore be transferred outside the country where you live.
Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies. Where we transfer personal information out of South Africa, we do so in line with section 72 of POPIA. You may request a copy of the safeguards we use by writing to overcome@optimusx.co.za.
Children and young people
Overcome is for adults. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18.
If we learn that we hold information from someone under 18, we will delete it and close the account. If you believe a minor has given us information, contact us at overcome@optimusx.co.za and we will act promptly.
Cookies and device storage
The web version of Overcome uses browser storage for a small number of strictly necessary purposes, and for nothing else.
- Keeping you signed in, keeping your session secure, and remembering your device if you choose "remember me".
- Remembering settings such as your theme, whether you have seen the introduction, and your app-lock configuration.
We set no analytics cookies and no advertising cookies, and there are no third-party trackers on any Overcome page. There is nothing here to opt out of.
You can clear or block browser storage in your browser settings, though the app will not work properly without it. The mobile apps use device storage rather than cookies for the same purposes.
Sensitive and health-related information
Much of what you record in Overcome — substance use, cravings, mood, anxiety, stress, and what you write in your journal — is information about your health. We handle all of it as sensitive, wherever you live.
- We collect it only because you choose to record it, and only to give you the service.
- We process it on the basis of your consent, which you can withdraw at any time.
- We do not use it for advertising, and we do not sell or rent it.
- It is shared with a coach only where you have connected to one, and only in the categories you have agreed to.
- Your journal is not shown to a coach unless you switch journal sharing on, and journal text is only ever included in a coach briefing while that setting is on.
- It is sent to our AI provider in the circumstances described above, and nowhere else.
- Access within our team is restricted to the minimum necessary to operate and support the service.
Overcome is not a healthcare provider and is not a covered entity under the United States Health Insurance Portability and Accountability Act (HIPAA). Recording information here does not create a clinical record, and it does not create a therapeutic or medical relationship between you and us.
Changes to this policy
We may update this policy as the app changes or the law does. When we do, we will change the "last updated" date above. If a change materially affects your rights or how we use your information — in particular if we add a new third party that receives your content — we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
Contact us and how to complain
For any question about this policy, or to exercise any right in it, contact our information officer.
- Entity: OptimusX Group (Pty) Ltd, registration number 2026/657042/07
- Information officer and privacy contact: overcome@optimusx.co.za
- Postal address: 40 Intaba Terrace, Zululami Estate, Sheffield Beach, 4420, KwaZulu-Natal, South Africa
We aim to resolve every complaint ourselves. If you are not satisfied with our response, you may escalate it to the regulator for your region, named in the sections below.
South Africa — your rights under POPIA
If you are in South Africa, the Protection of Personal Information Act 4 of 2013 applies and OptimusX Group (Pty) Ltd is the responsible party.
- You have the right to be told that we hold your personal information and to request the record or a description of it, under sections 23 and 24.
- You have the right to have information corrected, destroyed or deleted where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, under section 24.
- You have the right to object to processing on reasonable grounds under section 11(3), and the right not to have your information processed for direct marketing by unsolicited electronic communication without your consent under section 69.
- Information about your health is special personal information under section 26. We process it under section 27(1)(a) — your consent — and for no other purpose than the ones described here.
- You may submit a request using Form 2 as prescribed under the Promotion of Access to Information Act, sent to overcome@optimusx.co.za.
You may complain to the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, or by email to the Regulator’s complaints address published at inforegulator.org.za.
European Union and United Kingdom — your rights under the GDPR
If you are in the European Economic Area, Switzerland or the United Kingdom, the GDPR or UK GDPR applies and OptimusX Group (Pty) Ltd is the controller of your personal information.
- You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time.
- Our lawful basis is your consent, and special category health data is processed under Article 9(2)(a) on the basis of your explicit consent.
- You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
- International transfers out of the EEA or UK are protected by Standard Contractual Clauses or the UK Addendum, as described above.
You may complain to the supervisory authority where you live or work. In the United Kingdom this is the Information Commissioner’s Office (ico.org.uk). We do not currently have an EU or UK representative appointed under Article 27; if that changes we will name them here.
California — your rights under the CCPA and CPRA
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the following rights.
- The right to know what personal information we collect, where it comes from, why, and who we disclose it to. The categories are set out above.
- The right to delete personal information we hold about you, subject to the financial records named in the retention section.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of.
- The right to limit the use of sensitive personal information. We use it only to provide the service you asked for, which is a permitted use that does not require a limitation option.
- The right not to be discriminated against for exercising any of these rights. We offer no financial incentives in exchange for personal information.
To make a request, use the delete tool in Settings, or email overcome@optimusx.co.za from the address on your account. We will verify your request against your account before acting on it. An authorised agent may make a request on your behalf with written permission that we can verify.