Legal

Privacy Policy

Effective date: July 23, 2026Last updated: July 23, 2026

QuitIt is a recovery tool. The information you put into it — urges, slips, journal entries, the shape of a habit you are trying to break — is among the most sensitive information a person can record. This policy explains exactly what we collect, what we do with it, and what we will never do with it.

We never sell your personal information.

We do not sell your data, we do not share it for cross-context behavioral advertising, and we do not disclose it to advertisers or data brokers. There is no advertising in QuitIt and no advertising or analytics SDK that profiles you. We have never done these things and this policy is our commitment not to start.

1. Who we are

QuitIt ("QuitIt", "we", "us", "our") provides the QuitIt mobile application for iOS (the "App") and this website. We are based in Ontario, Canada, and our handling of personal information is governed by Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"). For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), QuitIt is the data controller for personal data processed through the App.

You can reach us about anything in this policy — including to exercise your rights — at quititadmin@gmail.com.

This policy applies to the App and this website. It does not apply to Apple's own handling of your Apple Account, payment, and App Store data, which is governed by Apple's Privacy Policy.

2. Summary

3. Information we collect

3.1 Recovery data you create in the App

This is the information you enter yourself as you use QuitIt:

By default this data is stored only in the App's local database on your device. It is included in your device backups if you have iCloud Backup or encrypted local backups enabled — those backups are controlled by Apple and by you, not by us.

3.2 Account data (only if you choose to sign in)

Creating an account is optional. If you create one, we process:

3.3 Subscription data

Premium subscriptions are sold and billed by Apple through the App Store. We receive from Apple only what is needed to unlock your features: a subscription status, product identifier, purchase and expiration dates, and an opaque transaction identifier. We never receive or store your card number, bank details, billing address, or Apple Account password.

3.4 Diagnostic and technical data

We process limited technical information to keep the App working: crash reports, error logs, App version, device model, and operating system version. Where this is provided through Apple's App Analytics, it is aggregated by Apple and shared with us only if you have consented to share analytics with developers in your iOS settings. Diagnostic data is not used to build a profile of you and is not combined with your recovery data.

3.5 Support correspondence

If you email us, we process your email address, the content of your message, and any information you choose to include, in order to answer you.

3.6 What we do not collect

4. Sensitive data and consent

Information about sexual behavior and about health-related habits is "special category" data under Article 9 of the GDPR and "sensitive personal information" under California law. We treat all of your recovery data — urge logs, relapse logs, journal entries, and onboarding answers — as sensitive, regardless of where you live.

In the EEA and UK, we rely on your explicit consent (Article 9(2)(a) GDPR) to process this data. You give that consent by choosing to enter it into the App, and you can withdraw it at any time by deleting the relevant entries, deleting your account, or deleting the App. Withdrawal does not affect processing that already took place.

We use sensitive personal information only to provide the features you asked for. We do not use or disclose it to infer characteristics about you, and we do not use it for any purpose that would require offering a "Limit the Use of My Sensitive Personal Information" right under the CPRA.

5. How and why we use your information

What we useWhy
Recovery dataTo show your progress, generate your analytics and pattern insights, select coping content, and power reminders and the panic/urge tools.
Encrypted backup payloadsTo restore your data when you reinstall the App or sign in on another device.
Account identifiersTo authenticate you, secure your account, and respond to your privacy requests.
Subscription statusTo unlock premium features and to manage renewals, restores, and refund questions.
Diagnostic dataTo fix crashes, find bugs, and improve reliability and performance.
Support correspondenceTo answer your questions and keep a record of what we told you.

We do not use your data to train machine-learning or artificial-intelligence models. QuitIt's insights are produced by rule-based logic that runs on your device.

7. We never sell your data

We have never sold, rented, or traded personal information, and we will not. Specifically, in the preceding twelve months and going forward:

If this ever changed, we would update this policy, notify you in the App before the change took effect, and — where the law requires it — obtain your consent first.

8. Where your data lives

On your device. QuitIt is local-first. Your logs and journal entries are written to a database on your iPhone and are protected by iOS file-system encryption and your device passcode.

In the cloud, only if you sign in. If you enable an account, your recovery data is encrypted on your device using AES-GCM before it is uploaded. The encryption key is generated on your device and stored in your Apple Keychain. Our hosting provider stores only opaque ciphertext, and access is restricted at the database level so that no account can read another account's rows. Because we do not hold your key, we cannot read your backups, and neither can our provider.

What this means for you: end-to-end encryption is a strong protection, but it has a trade-off. If you lose access to your device Keychain — for example by erasing your device without a backup — we cannot recover your encrypted data for you, because we have no way to decrypt it.

9. Sharing and service providers

We disclose personal information only in the limited circumstances below. Every provider is bound by a contract that requires them to process data only on our instructions and prohibits them from using it for their own purposes.

ProviderPurposeWhat they receive
AppleApp distribution, in-app purchases and subscriptions, crash reporting, push notificationsPayment and Apple Account data (held by Apple, not shared with us), subscription status, aggregated analytics
SupabaseAuthentication and encrypted backup storageAccount identifiers, session metadata, encrypted (unreadable) backup payloads
GoogleOptional "Sign in with Google" authenticationYour Google account identity, only if you choose that sign-in method

We may also disclose information where we are legally required to do so — to comply with a valid legal process, to enforce our Terms of Service, or to protect the rights, safety, or property of our users or the public. We will challenge requests we believe to be overbroad or unlawful, and where we are permitted to notify you of a request affecting your data, we will.

If QuitIt is ever involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We would notify you in the App and by email before your information became subject to a materially different privacy policy, and you would be able to delete your account first.

10. Community features

If QuitIt offers community features and you choose to use them, the content you post — messages, group posts, and your chosen display name — is shared with the other users you send it to or post it for. Please do not post information you would not want another person to see. Community content is not end-to-end encrypted in the same way as your private recovery data, because it must be delivered to other people and moderated for safety. You can report abusive content and block other users from within the App; we review reports and may remove content or suspend accounts under our Terms of Service.

11. Third-party content

QuitIt's motivational feed may embed videos hosted by third parties such as YouTube. When a video loads, the host may set cookies and receive your IP address and technical information about your device under its own privacy policy. We do not send your recovery data to video hosts, and we do not receive information about you from them. External links on this site and in the App are governed by the privacy policies of the sites they lead to.

12. How long we keep data

13. Your privacy rights

The sections that follow set out the extra rights that apply in Canada, the EEA and UK, and California. Regardless of where you live, you can:

We will never discriminate against you for exercising a privacy right. We will not deny you service, charge you a different price, or give you a lower quality of service because you asked us to delete your data.

To verify a request made by email, we will ask you to send it from the email address associated with your account, and we may ask for one additional piece of information that matches our records. We do not ask for government identification. An authorized agent may submit a request on your behalf with written proof of authorization.

14. Additional rights in Canada

We are a Canadian organization and PIPEDA applies to everything we do with your personal information. Under PIPEDA and the ten fair information principles in its Schedule 1, you have the right to:

We respond to PIPEDA access requests within 30 days, and at no cost to you. If we need an extension permitted by the Act, we will tell you within the first 30 days, explain why, and tell you about your right to complain to the Commissioner.

Accountability. Our privacy officer can be reached at quititadmin@gmail.com. We remain accountable under PIPEDA for personal information transferred to a service provider for processing, and we use contractual means to give it a comparable level of protection while it is in their hands.

Processing outside Canada. Our service providers store and process information in the United States and other countries, which means that information may be accessible to the courts, law enforcement, and national security authorities of those countries under their laws. This is why your recovery data is encrypted on your device before it leaves it — see section 8.

Breach reporting. Where a breach of security safeguards creates a real risk of significant harm, we will report it to the Privacy Commissioner and notify affected individuals as soon as feasible, and keep records of breaches as PIPEDA requires.

Quebec residents have additional rights under Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, including the right to data portability and the right to be informed when information is used to render a decision based exclusively on automated processing. QuitIt makes no such decisions.

Marketing email. We do not send marketing email. If we ever do, it will comply with Canada's Anti-Spam Legislation ("CASL"): we will obtain your consent first, identify ourselves, and include a working unsubscribe link in every message. Service messages about your account, security, or a purchase are not marketing and will continue regardless.

15. Additional rights in the EEA and UK

If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to:

We respond to rights requests within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

16. Additional rights in California

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have the right to know, delete, correct, and opt out of sale or sharing, and the right to limit the use of sensitive personal information.

We do not sell or share personal information, so there is nothing to opt out of. We use sensitive personal information only for the purposes permitted under CCPA §7027(m) — providing the service you requested — so the right to limit does not apply. We offer the "Do Not Sell or Share My Personal Information" position as our default and permanent practice rather than as a setting you must find.

Categories of personal information we have collected in the preceding twelve months, using the CCPA's categories: identifiers (email address, user ID); commercial information (subscription status); internet or network activity (diagnostic and error data); and sensitive personal information (data concerning sex life or sexual orientation, and health-related information, in the form of your recovery logs). We collected each category from you directly, or from Apple and our authentication provider as described above. We disclosed identifiers, commercial information, and encrypted payloads to the service providers listed in section 9 for business purposes only. We disclosed no category to any third party for money or other valuable consideration.

We respond to California requests within 45 days, extendable once by a further 45 days with notice.

17. International transfers

We are based in Canada, and we and our service providers may process your information in Canada, the United States, and other countries whose data-protection laws differ from those where you live.

Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable). The EEA benefits from the European Commission's adequacy decision for Canada in respect of organizations subject to PIPEDA. In every case these legal mechanisms sit on top of a technical one that matters more: your recovery data is encrypted on your device before transfer, and is unreadable in transit and at rest by anyone without your key.

18. Children

QuitIt is rated 17+ on the App Store and is intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 17. If you believe a child has provided us with personal information, email quititadmin@gmail.com and we will delete it promptly. Parents and guardians can use Apple's Screen Time and Ask to Buy controls to manage what is downloaded and purchased on a child's device.

19. Security

We protect your information with measures appropriate to its sensitivity, including end-to-end encryption of recovery data using AES-GCM with keys held only on your device, TLS for all data in transit, row-level access rules that isolate each account's data at the database layer, least-privilege access for the small number of people who administer our systems, and no plaintext storage of recovery data on our servers at any point.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

20. Changes to this policy

We may update this policy to reflect changes to the App or the law. When we do, we will revise the "Last updated" date above. For material changes — a new purpose for your data, a new category of recipient, or anything that reduces your protections — we will give you notice in the App before the change takes effect, and we will obtain your consent where the law requires it. Previous versions are available on request.

21. Contact us

Privacy contact

Email: quititadmin@gmail.com

Please include "Privacy Request" in the subject line so we can route it quickly. We aim to acknowledge every privacy request within 5 business days and to resolve it within the statutory deadline that applies to you.