Privacy Policy
Plain-English version first, formal version second. Both apply. If they ever disagree, email us and we'll fix the document.
Last updated: July 22, 2026
The plain-English version
- You can use most of Quitora anonymously. Signing in with Apple is optional and only used to preserve your data across reinstalls.
- We don't sell or rent your data. Ever. To anyone. Period.
- We don't run third-party advertising inside the app. No ad SDKs, no behavioral profiling, no cookies following you across the web.
- AI features send your data to OpenAI to generate responses. We don't allow OpenAI to train their models on your data. See the "AI processing" section below for the detail.
- The community is optional and can be anonymous. You can post and comment without showing your name, and report or block anyone. Treat anything you post as public.
- The app blocker uses Apple Screen Time with your permission. We can't see which apps or sites you choose to block — that stays on your device.
- Delete everything from Settings → Deactivate Sanctuary. Your account, check-ins, chats, summaries, and attached identifiers are purged within 7 days.
1. Who we are
Quitora ("we", "us", "our") is an independent publisher of a mobile porn-addiction recovery app, also called Quitora. You can reach us at support@quitora.app.
2. What data we collect
You give us, directly
- Account identifiers — when you sign in with Apple, we receive a stable Apple user identifier and your chosen display name. We do not receive your real Apple ID email unless you explicitly share it.
- Recovery data — your recovery start date, streak goal, personal urge triggers, and the contents of your daily check-ins (mood, urge intensity, sleep quality, optional journal, and whether you stayed on track).
- Optional profile data — name, birthday, gender, weight, weight unit, emergency contact details. Every field is optional and editable.
- AI coach conversations — the messages you send to the in-app coach and the responses you receive.
- Wisdom Scroll interactions — likes and comments you post, and comments you report.
- Community content — the posts and comments you publish, and the likes, shares, reports, and blocks you make. Posts and comments are visible to other members. You can choose to post anonymously, which hides your display name from others.
Automatically, minimally
- App-quality telemetry — anonymized crash reports, performance metrics, and aggregate event counts used to fix bugs and improve reliability. No individual behavior profile is built from this.
- Subscription state— whether you hold an active premium subscription, provided to us by Apple's App Store. We never receive your Apple payment details.
3. What we do NOT collect
- Advertising identifiers (IDFA) — not used.
- Contact list, photo library, or location — not requested.
- Third-party cross-site tracking — none. No Meta Pixel, no Google advertising cookies, no fingerprinting.
- Your Apple ID real email, unless you explicitly choose to share it at sign-in.
- Which specific apps or websites you block with Screen Time — Apple hands the app privacy-preserving tokens that stay on your device; we never see your selections.
4. Why we collect it
- To run the app: showing your streak, check-in history, milestones, impact stats, and pattern insights all require reading back what you entered.
- To generate personalized AI responses: coach replies, daily quotes, and weekly therapy summaries use your recent check-ins and chats as context.
- To keep your data safe across devices: signing in with Apple lets us restore your progress if you reinstall or switch phones.
- To keep the community safe: we filter posts and comments for links and objectionable language, rate-limit posting, let members report or block others, automatically hide reported content, and can remove or ban accounts that break the rules.
5. AI processing
When you use an AI feature (coach chat, wisdom quotes, therapy summary, craving toolkit), the relevant portion of your recent data is sent to OpenAI to produce a response. We use OpenAI's API in a mode that contractually prohibits them from training their models on your submissions and that retains data for only abuse-monitoring purposes, per OpenAI's API data usage policy.
The inputs sent are limited to what the specific feature needs — for example, the coach receives your recent conversation history and structured check-in signals, not your full account.
6. Community & user content
The community is an optional, post-only space. Anything you post — posts, comments, likes, and shares — is stored on our backend and is visible to other members. You can post and comment anonymously, which hides your display name from other users; we still keep an internal identifier with your content so we can enforce ownership and moderation. Treat anything you share as public, and don't post personal or identifying information.
To keep it safe we filter submissions for links and objectionable language, rate-limit posting, and let members report or block others. Reported content is hidden automatically, and accounts that break the rules can be removed or banned.
If you delete your account, your community posts and comments are anonymised and disassociated from you rather than removed, so conversations other members took part in stay intact. Everything else tied to your account is deleted as described below.
7. Screen Time & content blocking
The optional app & website blocker uses Apple's Screen Time (Family Controls) with your explicit permission. When you choose which apps or categories to block, iOS gives the app privacy-preserving tokens — Quitora cannot see which specific apps or sites you selected, and that information never leaves your device.
The optional website filter routes your device's DNS lookups through a filtering resolver (Cloudflare for Families) to block adult sites. Those DNS queries are handled by that resolver under its own privacy policy; Quitora does not log or store your browsing history.
8. Where data is stored
Your data is stored on Supabase-managed infrastructure hosted in secure cloud data centers. Access is limited to authorized Quitora operators for support, debugging, and account-deletion requests. All data is encrypted in transit (TLS) and at rest (AES-256).
9. How long we keep it
- Active accounts: while your account is active plus 30 days after you request deletion (to allow cancellation of accidental delete requests).
- Anonymized quality telemetry: up to 13 months for trend analysis, then deleted.
- Stored therapy summaries: the most recent 4 summaries, automatically pruned.
- Community posts & comments: anonymised (not deleted) when you delete your account, so threads other members joined stay readable.
- Backups: rolling encrypted backups retained for up to 30 days, after which deleted data is unrecoverable.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, restrict certain processing, or object to processing. You can exercise most of these directly from Settings inside the app. For anything you can't do in-app, email support@quitora.app.
If you are in the EU or UK, our lawful bases for processing under GDPR are (a) performance of a contract — delivering the service you signed up for — and (b) legitimate interest for minimal service-quality telemetry.
11. Children
Quitora is not directed to children under 13 (or under 16 in the EU/UK). We do not knowingly collect data from children under this age. If you believe we have, email us and we will delete it.
12. Changes
If we materially change this policy, we'll update the "Last updated" date at the top and notify active users in the app. The latest version always lives at this URL.
13. Contact
Privacy questions, data requests, complaints: support@quitora.app.