# Privacy Policy for Rebooted
**Effective date:** August 3, 2026
**Last updated:** August 3, 2026
Rebooted ("the app") is developed by Branchout ("we", "us"). This policy explains what information the app handles, what stays on your phone, what leaves it, and what rights you have. If you have any questions, email us at **ibraindump@gmail.com**.
The short version: **your streaks, relapse logs, journal entries, and other recovery history are stored only on your device.** We also send selected onboarding answers and a derived intake recovery category to our analytics and subscription providers as described below. We do not sell your data and the app shows no ads.
---
## 1. Information We Collect
### Information stored on our servers
When you first open the app, an **anonymous account** is created for you automatically. You do not provide an email address, phone number, or password. Linked to that anonymous account, we store:
- **Your first name** (the name you enter during onboarding), so the app can greet you and restore it if you reinstall.
- **Account timestamps** (when the account was created and last used).
### Information sent to analytics and purchase services
- **Onboarding answers**: Firebase Analytics receives the option you select for gender, usage frequency and duration, viewing history, triggers, social platforms, feelings, escalation, past attempts, age range, goals, and a coarse last-use bucket. We use this to understand how people move through onboarding and improve it. We do not send your name or a precise last-use date to Firebase.
- **Intake recovery category**: Firebase Analytics and Adapty receive a category derived from your onboarding habit-history answers. We use it to understand aggregate audience cohorts and paywall performance. This category is not the dynamic level shown in the app.
- **Purchase and paywall activity**: which paywall was shown, which subscription product you selected, and whether a purchase, restore, or trial succeeded or failed. This goes to Firebase Analytics and Adapty.
- **Purchase receipts**: when you subscribe, Apple or Google processes the payment and Adapty validates the store receipt. **We never see or store your card details** — payment is handled entirely by the App Store or Google Play.
- **Crash reports**: if the app crashes, Firebase Crashlytics sends a technical report (stack trace, device model, OS version, app version) so we can fix bugs.
- **Automatic analytics data**: Firebase Analytics automatically collects device model, operating system version, coarse region (derived from IP address), session information, and a random app-instance identifier.
- **Identifiers**: your anonymous account ID and the Firebase app-instance identifier are shared with Adapty so your subscription status and analytics can be matched to the same anonymous profile.
### Information stored only on your device
The following is stored locally and is not uploaded to our servers or analytics and purchase providers:
- Your streaks and recovery cycles.
- Relapse logs, including triggers, context, and any journal text you write.
- Urge sessions, commitments, and breathing settings.
Your complete onboarding answers are also stored locally so the app can personalize your experience. Selected answers and the derived intake recovery category are sent to the providers described above. If you delete the app, local data is deleted with it.
### Information we do NOT collect
- No email address, phone number, or contacts (unless you email us yourself).
- No precise location.
- No photos or camera recordings — the "mirror" feature shows a live camera preview on your screen only; **nothing is recorded, saved, or transmitted**.
- No advertising identifiers for tracking; the app contains no ads and does not track you across other apps or websites.
## 2. How We Collect Information
- **Directly from you**: your name and quiz answers during onboarding, and content you enter in the app.
- **Automatically**: analytics events, crash reports, and device information via the Firebase and Adapty SDKs.
- **From the app stores**: purchase and subscription receipts from Apple App Store or Google Play.
## 3. How We Use Information
- **To provide the app**: keep your anonymous account, restore your name, and unlock premium features you've purchased.
- **To understand usage in aggregate**: analyze onboarding choices and progression, see how many people reach the paywall, complete purchases, or start trials, and improve the app.
- **To fix problems**: crash reports tell us when and where the app breaks.
- **To manage subscriptions**: validate purchases and restore them across reinstalls.
We do not use your data for advertising, and we do not sell or rent it to anyone.
## 4. Legal Basis for Processing (GDPR)
<!-- LEGAL REVIEW: confirm legal bases, especially legitimate interest vs. consent for analytics in the EU -->
If you are in the European Economic Area or the UK, we process your data on these bases:
- **Performance of a contract**: your anonymous account, name, and purchase data are needed to provide the app and your subscription.
- **Legitimate interests**: aggregate analytics and crash reporting to maintain and improve the app.
- **Consent**: optional information you choose to provide, such as gender ("prefer not to say" is always available).
## 5. Data Sharing and Third-Party Services
We share data only with the service providers that make the app work:
| Service | Purpose | What it receives | Privacy policy |
|---|---|---|---|
| Supabase | Anonymous accounts and database | Anonymous account ID, first name, timestamps | [supabase.com/privacy](https://supabase.com/privacy) |
| Google Firebase (Analytics, Crashlytics) | Usage analytics and crash reporting | Selected onboarding-answer categories, derived intake recovery category, purchase events, device info, crash reports, app-instance ID | [firebase.google.com/support/privacy](https://firebase.google.com/support/privacy) |
| Adapty | Subscription management | Purchase receipts, paywall events, gender, derived intake recovery category, anonymous IDs | [adapty.io/privacy](https://adapty.io/privacy) |
| Apple App Store / Google Play | Payment processing | Payment details (handled entirely by them) | [apple.com/legal/privacy](https://www.apple.com/legal/privacy/) / [policies.google.com/privacy](https://policies.google.com/privacy) |
We may also disclose information if required by law, such as in response to a valid legal request.
## 6. International Data Transfers
<!-- LEGAL REVIEW: confirm transfer mechanisms (SCCs / Data Privacy Framework) for each processor and the Supabase project region -->
Our service providers may process data on servers located outside your country, including in the United States. Where required, these providers rely on safeguards such as Standard Contractual Clauses or equivalent mechanisms. Details are available in each provider's privacy policy linked above.
## 7. Data Retention
- **Account data (name, anonymous ID)**: kept while your account exists; deleted when your account is deleted.
- **Analytics data**: retained by Firebase Analytics for up to 14 months, then automatically deleted or aggregated.
- **Crash reports**: retained by Crashlytics for 90 days.
- **Purchase records**: retained as long as needed to manage your subscription and meet legal (e.g., tax and accounting) obligations.
- **On-device data**: stays on your phone until you uninstall the app. This includes complete onboarding answers; selected answer categories and a derived intake recovery category may also be retained by Firebase Analytics and Adapty as described above.
## 8. Your Rights
Depending on where you live, you have the right to:
- **Access** the data we hold about you.
- **Delete** your data ("right to be forgotten").
- **Correct** inaccurate data.
- **Restrict or object** to certain processing.
- **Data portability** — receive a copy of your data in a usable format.
- **Lodge a complaint** with your local data protection authority (EEA/UK).
**California residents (CCPA/CPRA)**: you have the rights to know, delete, and correct your personal information, and to opt out of the sale or sharing of personal information. **We do not sell or share your personal information** as defined by the CCPA, and we do not discriminate against you for exercising your rights.
To exercise any of these rights, email **ibraindump@gmail.com** from any address and include your request. Because accounts are anonymous, we may ask you for information from your device (shown in the app) to locate your account. We respond within 30 days.
To delete your account and all associated data, email us at **ibraindump@gmail.com** and we will remove your data from our servers and process erasure of analytics and subscription-profile data at our providers (Firebase, Adapty).
## 9. Security
- All data is transmitted over encrypted connections (HTTPS/TLS).
- Server data is protected by access rules so that only your own account can read your data.
- We keep recovery history, journal entries, and precise last-use dates on your device. Selected onboarding-answer categories and a derived intake recovery category are transmitted to the service providers identified above.
No system is 100% secure. We design the app to keep recovery history, journal entries, and precise last-use dates on the device, while the selected onboarding data described above is handled by our service providers.
## 10. Children's Privacy
Rebooted is intended for adults and is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has used the app and provided personal information, contact us at **ibraindump@gmail.com** and we will delete it.
## 11. Changes to This Policy
If we make material changes, we will update the "Last updated" date above and notify you in the app before the changes take effect. Continued use of the app after changes take effect means you accept the updated policy.
## 12. Contact
**Branchout**
Email: **ibraindump@gmail.com**
We aim to respond to all privacy inquiries within 30 days.