Short version: nothing leaves your device unless you ask it to. Everything you enter — the addictions you track, your quit dates, your check-ins, your moods — stays on your phone. There is no analytics and no tracking, and you never need an account. Two features are optional and do send something, only once you switch them on: backup, which saves your progress to a private record only your own account can read (section 4), and Fener, the AI companion, whose messages are processed to generate a reply and are not stored (section 8).
Stop & Heal ("the app") is an addiction-recovery tracking app. This policy explains what happens to your information when you use it. If you have questions, write to help@stopandheal.com.
Almost none, and none of it by default. The app has no analytics SDK, no advertising SDK, no crash-reporting SDK, and no tracking of any kind. Every feature works without an account, and unless you connect one we do not know who you are and cannot see what you do inside the app. Two optional features send something off your device, each only after you switch it on: backup (section 4) and Fener, the AI companion on the panic screen (section 8).
To work at all, the app keeps the following in your phone's local storage, in the app's own private sandbox:
The journeys you have chosen (for example nicotine, alcohol, gambling), the date and time you quit each one, your daily check-ins and mood entries, your streaks and any relapses you record, your in-app "Light" balance and the cosmetics you own, your language and theme preferences, and your notification settings.
Unless you switch on backup (section 4), this data never leaves your device and we hold no copy of it: if you delete the app it goes with the app, and we cannot restore it for you. Depending on your own settings, your operating system's backup (iCloud Backup or Google Backup) may include the app's data; that backup is controlled by Apple or Google under their own policies, not by us.
Everything in section 3 stays on your device unless you switch on backup. Backup is off until you turn it on, and turning it on means connecting a Google or Apple account. If you never connect one, nothing in this section happens and nothing about your recovery ever reaches our servers.
When you do connect an account, the app copies your saved state to a private record keyed to that account: the journeys you track, your quit dates, your streaks and any relapses, your check-ins and moods, your vow, your gratitude notes, your Light balance and cosmetics, the name you entered if you entered one, and the e-mail address you gave for the sapling if you gave one. The record is held for us on Google's Firebase (Cloud Firestore). Only your account can read it. We do not analyse it, profile you with it, sell it or share it, and no advertiser or third party ever receives it.
It exists for one reason: a new phone should not cost you your streak. You can turn backup off, sign out, or erase the whole thing whenever you like — Settings > Account & Backup > Delete account removes the account and the stored copy together, permanently (step-by-step).
Milestone and streak reminders are scheduled locally on your device by the operating system. No notification passes through a server of ours, and no push token is sent anywhere. If you enable "discreet notifications," the addiction name and milestone title are hidden from the lock screen.
Fener (the paid tier) is sold through the Apple App Store and Google Play. When you buy or restore a purchase, the transaction is handled entirely by Apple or Google. We never see your name, your card, your billing address, or your email. We receive only a signed receipt from the store confirming that a purchase exists, and that receipt is verified on your device. Apple's and Google's own privacy policies govern the payment itself.
There is one exception, and it happens only if you ask for it. When you request your real sapling, the app sends your store transaction ID — and nothing else — to our verification endpoint so that we can confirm the purchase with Apple or Google. Your name, your e-mail address and your device identifiers are not included in that request. The transaction ID is not stored: it is used to answer that single request and then discarded. No other part of the app sends purchase information anywhere.
What you track in this app — addiction, relapse, mood — is sensitive. Data the app reads from Apple Health is used on your device only: it is never sent to our servers and is never part of a backup. Your own entries, such as a mood check-in, are also saved inside the app, so if you have switched on backup they are included in it (section 4).
Only with your permission, and only on your device, the app can exchange the following with Apple Health:
Reading (to show your recovery): your resting heart rate and sleep, so the app can show your physical recovery since quitting — for example, the drop in your resting heart rate — using your own real data. Writing (your own entries, kept in Health too): your daily mood check-ins are written to Apple Health's State of Mind, and your breathing / calming sessions are written as Mindful Minutes.
This access is entirely optional: iOS asks the first time, and you can revoke it at any time in Settings > Privacy & Security > Health. If you decline, the app keeps working normally. Your health data stays on your device and in Apple Health; it is never sent to our servers, never used for advertising or marketing, and never shared with third parties. The app does not exchange anything with Google Fit, and does not request access to your contacts, photos, microphone, camera, or location.
The panic screen includes Fener, an optional AI companion. When you choose to talk to it, the messages you type — together with the journey context that makes a reply make sense: the addiction you selected, your day count, the stage you are on, milestone titles, your vow, and the mood or trigger you picked if you picked one — are sent over an encrypted connection to our relay server (Cloudflare Workers) and passed to Google's Gemini API, which generates the reply. Your journal and your relapse log are never included. It runs only when you actively use it.
We do not store these conversations: our relay keeps no record of message content, and the exchange is processed transiently to produce the answer. Under the Gemini API terms that apply to our usage, Google does not use this content to train its models. Requests carry a random, anonymous identifier — not your name, not an email, not an advertising ID — used only to enforce per-device rate limits. Messages that look like a mental-health crisis receive fixed safety guidance; when such a message is recognized on your device, it is not sent at all.
If you are offline, or simply prefer not to use Fener, the panic screen's breathing exercise runs entirely on your device and nothing is sent anywhere.
Stop & Heal is not directed at children and is not intended for use by anyone under 13 (or the minimum age of digital consent in your country, where that is higher). We do not knowingly hold data about a child. If you believe a child has used the app with backup switched on, write to us and we will erase the stored copy.
Regulations such as the GDPR and the KVKK give you rights over personal data held about you — access, correction, deletion, portability. If you have never switched on backup, we hold no personal data about you at all: there is nothing for us to hand over or erase, your data lives on your device, and deleting the app deletes it. If you have switched on backup, that stored copy is yours — you can read it back onto any device, change it by using the app, and erase it completely with Settings > Account & Backup > Delete account, which removes the account and the backup together (step-by-step). If you would rather we did it, write to help@stopandheal.com.
If this policy changes, the new version will be posted at this address with a new "last updated" date. If what the app collects or sends ever changes, we will say so here plainly, and in the app, before it happens.