Privacy Policy - Quit Family Apps
Effective date: August 20, 2026
This policy covers Quit Nicotine Pouches, Quit Vaping, Quit Weed, Quit Soda, Quit Porn, Quit Paid Content, Quit Alcohol, Quit Shopping, Quit Phone, Quit Betting, Quit Binge Eating. It tells you what each app saves, what can leave your iPhone, who receives it, and where you can turn each optional service off.
1. Who is responsible for your data
Doved Studio controls the personal data described in this policy.
Email [email protected] with a privacy question or deletion request.
2. What the app saves on your iPhone
Your recovery record is saved on your iPhone. Depending on what you enter and which app you use, that record can include:
- Your name, age, quit target, quit date, goals, triggers, safety answers, use level, spending, previous attempts, and the answers you gave during setup.
- The exact product, platform, place, time, amount, or replacement you add after purchase.
- Your streak, pledges, check-ins, cravings, relapses, journal entries, action logs, timers, learned patterns, completed lessons, achievements, and coach conversations.
Each Quit Family app opens its own recovery database file. The apps still use one Apple App Group for widgets, Watch, Shortcuts, and notification actions. That shared area holds only the small values those surfaces need, such as the current app name, streak date, money saved, predicted hard time, privacy choices, or a pending action.
Doved Studio does not receive this local record unless you choose a feature that sends specific data off your iPhone, such as remote AI, optional analytics, a purchase, or ad attribution. Those cases are listed below. The current apps do not request Apple Health or HealthKit access.
3. Remote AI coach
The first time you try the coach, you choose between remote AI and a simpler on-device reply. Remote AI stays off until you allow it. If the age saved in the profile is under 18, remote AI stays off.
With Recovery Context off, the app sends only the message you just typed and general safety instructions. It does not send your quit target, name, profile, prior coach messages, or saved recovery history.
If you turn Recovery Context on, the request can also include up to 20 recent coach messages and a recovery summary containing your name, age, quit target, streak, goals, use level, spending, severity, triggers, safety answers, sleep, exercise, mental-health answers, previous attempts, recent cravings or relapses, mood and check-ins, achievements, tools used, predicted hard time, and recent app activity.
The app sends that request over HTTPS to Doved Studio's Cloudflare Worker. The Worker adds safety rules and forwards the request to DeepSeek, which generates the reply. The request does not attach your email address, RevenueCat ID, or advertising ID. It can still contain your name or other identifying details if you turned Recovery Context on or typed those details into your message.
The Worker uses no-store response headers and its application logs record operational events such as the model and response status, not coach-message text. Cloudflare processes the request to run the Worker, and DeepSeek handles the submitted text under its own retention and privacy terms. Remote AI is support, not medical care, diagnosis, crisis care, financial advice, or betting advice.
You can turn off remote AI or Recovery Context at any time in Privacy Center. Turning either one off does not delete data already processed by a provider; email us if you want help requesting deletion from an off-device provider.
4. Optional PostHog analytics
PostHog analytics is off by default. If you turn on Send limited app-use events in Privacy Center, PostHog can receive these events: paywall viewed or closed; purchase started, completed, cancelled, failed, or abandoned; restore tapped or completed; trial started or converted; onboarding completed; and notification permission granted.
Those events can include only a short allowlist of purchase details: source, plan tier, price, currency, offering, purchase type, free-trial status, prior-subscription status, and plan. The app strips the quit target and any other property before it sends an allowed event.
PostHog does not receive your journal text, coach messages, exact product or platform, triggers, cravings, relapses, mood, safety answers, streak, or RevenueCat customer ID from this analytics path. Automatic screen capture, lifecycle capture, and session replay are disabled. Turning analytics off resets PostHog's local anonymous identifier and does not change your paid access.
5. Purchases and subscriptions
Apple bills your plan. RevenueCat receives an anonymous customer ID, product and transaction identifiers, purchase dates, trial or renewal status, and subscription status so the app can unlock paid access, show your plan, and restore purchases. Doved Studio and RevenueCat do not receive your payment-card number from the app.
You can view or cancel your plan through Apple's subscription settings. Deleting local app data does not cancel the subscription or erase Apple's purchase record.
6. Ad attribution and Apple's tracking prompt
The app can use Apple AdServices to tell whether an Apple Search Ads campaign led to an install. RevenueCat can receive that attribution with the purchase record.
Builds configured for paid-ad attribution can also use AppsFlyer, Meta, and TikTok. The app waits for you to answer Apple's App Tracking Transparency prompt before those SDKs start. They can process app, device, session, and campaign-attribution data. They receive the IDFA only when you allow tracking. If the build has no provider keys, those SDKs do not start and the app does not show the tracking prompt.
You can change tracking permission in iOS Settings. Denying tracking stops access to the IDFA; it does not stop Apple from processing purchases or permitted first-party and privacy-preserving attribution.
7. Notifications, widgets, Watch, and Shortcuts
Notifications and widgets use neutral wording by default. In Privacy Center, you can separately allow them to show your quit target, streak, or predicted hard time. Quit Porn and Quit Paid Content widgets stay neutral even if you turn those controls on.
These surfaces can appear while your iPhone or Watch is locked, where someone nearby may see them. Keep the controls off if you do not want those details on a lock screen. Apple handles delivery of local notifications and widget, Watch, and Shortcut features.
8. Exporting and deleting your data
Export: The app can create a JSON file containing your current app's local recovery record. iOS file protection covers the temporary file while it stays in the app's temporary folder, and the app deletes that copy after the share sheet closes. Once you share or save the file elsewhere, you control that copy. It is readable JSON, so store it somewhere private.
Delete data from this iPhone: This button erases the current app's local recovery database, coach history, preferences, pending and delivered notifications, optional-analytics choice and identifier, temporary exports, and the current app's widget payload. It does not erase a sibling Quit Family app's database.
Local deletion does not cancel your Apple subscription or automatically delete records held by Apple, RevenueCat, Cloudflare, DeepSeek, PostHog, AppsFlyer, Meta, or TikTok. UseRequest deletion of off-device data in the app to email Doved Studio with the RevenueCat customer ID for that install, or email [email protected] yourself.
9. Providers that can process data
- Apple — app delivery, purchases, subscriptions, AdServices, notifications, widgets, Watch, and Shortcuts.
- RevenueCat — subscription access, purchase history, restore, and purchase attribution.
- Cloudflare — Doved Studio's remote-AI proxy and its operational metadata.
- DeepSeek — remote-AI request processing and reply generation.
- PostHog — limited product analytics, only after you turn it on.
- AppsFlyer, Meta, and TikTok — paid-ad attribution when those providers are configured; IDFA access only after you allow tracking.
These providers may process data in countries outside your own. Their policies explain where they process it, how long they keep it, and the transfer safeguards they use.
10. Retention and your choices
Your local record stays on the device until you delete it. Because the apps use an Apple App Group, uninstalling one Quit Family app may not remove shared widget data while another Quit Family app remains installed. Use the in-app deletion button when you want the current app's local record cleared.
Apple, RevenueCat, DeepSeek, Cloudflare, PostHog, and attribution providers keep data under their own retention rules. Doved Studio keeps the remote-AI Worker's operational logs for service reliability and security; the Worker code does not write coach-message text to those application logs.
Privacy Center lets you turn remote AI, Recovery Context, optional analytics, quit-target details, streak details, and hard-time details on or off. You can also export your local record or delete it. Email [email protected] to ask what off-device data is linked to your install, request a copy or correction, object to or restrict processing, withdraw consent, or request deletion. We will verify and handle the request as the law requires.
11. Children and safety
Quit Family is not directed to children under 13. Doved Studio does not knowingly collect personal data from children under 13. When a saved profile says the person is under 18, the app keeps remote AI and Recovery Context off.
12. Policy changes
We will update this page when the apps, providers, or data flows change, and we will change the effective date at the top. If a change needs a new permission, the app will ask before using that data in the new way.