Privacy Policy
Effective date: June 3, 2026
This Privacy Policy applies to Quitly: AI Addiction Coach, also referred to as "Quitly" or the "Application", and related services operated by Hisham Kherbouch, referred to in this Policy as the "Service Provider".
Quitly is an iOS mobile app that helps users quit or reduce nicotine vaping. The Application provides quit planning, craving support, slip recovery, daily check-ins, progress tracking, notifications, feedback tools, and AI-generated coaching.
This Privacy Policy explains what information the Application collects, how it is used, and the choices available to users.
Information We Collect
The Application may collect the following categories of information:
- Account information, such as your email address, user ID, authentication data, and account status.
- Health and quit-support information, such as quit-vaping goals, quit plans, nicotine or vaping usage, craving logs, slip logs, daily check-ins, progress data, trigger categories, intervention outcomes, rationalization logs, notification preferences, and coach messages.
- Product interaction data, such as onboarding completion, craving flow completion, slip recovery usage, coach usage, notification taps, subscription events, data export events, and deletion requests.
- Feedback content, if you choose to send feedback through the Application.
- Waitlist information, such as your email address, optional first name, and consent to receive Quitly launch updates if you join the pre-release waitlist.
- Technical information processed by the Application or service providers, such as device operating system, request metadata, IP address, timestamps, and usage events needed to operate, secure, and improve the Application.
The Application does not ask for your first and last name, phone number, postal address, contacts, camera, or GPS location.
How We Use Information
The Service Provider uses information to:
- Provide and personalize quit-support features.
- Create and manage accounts.
- Sync and back up selected data across devices when you sign in.
- Generate AI coaching responses.
- Send service-related notices and transactional communications.
- Process subscription purchase and restore flows through Apple.
- Improve reliability, safety, and user experience.
- Respond to support requests and feedback.
- Export or delete data at your request.
- Comply with legal obligations and protect the Application from abuse.
The Service Provider does not sell your personal information and does not use your information for advertising tracking or remarketing.
Analytics
Quitly uses limited first-party product analytics to understand whether the Application is working well and to improve core features. Analytics events may include event names and categorical properties, such as whether onboarding was completed or whether a craving support flow was finished.
Analytics events are designed not to include raw coach messages, personal notes, rationalizations, detailed medical information, or free-form health text.
AI Coaching
Quitly uses artificial intelligence to provide coaching and support responses. AI coaching may process the minimum context reasonably needed to generate a relevant response, such as recent coach messages or quit-support context.
AI processing is routed through app-controlled backend services. The Application does not place raw AI provider API keys in the mobile app.
AI-generated responses may be incomplete, inaccurate, or inappropriate for your situation. AI coaching is not medical advice, therapy, diagnosis, treatment, emergency care, or a substitute for a qualified healthcare professional.
If you are in immediate danger, may harm yourself or someone else, or are experiencing a medical emergency, call emergency services. In the United States, you can call or text 988 for the Suicide & Crisis Lifeline.
Third-Party Service Providers
The Service Provider may share information with service providers that help operate the Application. These providers are used only as needed to provide, secure, maintain, or improve the Application.
Current service providers may include:
- Supabase, for authentication, database storage, sync, backend functions, account deletion, and related infrastructure.
- Google Gemini API, for AI-generated coach responses routed through backend functions.
- Apple StoreKit and the App Store, for subscriptions, in-app purchases, purchase restoration, and related payment processing.
These service providers may process information according to their own terms and privacy practices. The Service Provider does not authorize these providers to use Quitly user information for advertising tracking by the Service Provider.
Payments and Subscriptions
Subscriptions and in-app purchases are processed by Apple through StoreKit and the App Store. The Service Provider does not receive your full payment card details from Apple.
Subscription pricing, renewal terms, trial terms, and cancellation options are shown before purchase. You can manage or cancel subscriptions through your Apple account settings.
Cookies and Tracking Technologies
The Application itself does not use advertising cookies, pixels, or remarketing technologies. Service providers may process technical information such as request metadata, device information, and logs as needed to operate and secure the Application.
Where applicable law requires consent for non-essential tracking technologies, the Service Provider will request that consent before using them.
Data Retention
The Service Provider retains personal information for as long as reasonably necessary to provide the Application, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, and protect the Application.
User-provided quit-support data is generally retained while your account is active or until you delete it or request deletion, subject to legal or security-related retention requirements. Product analytics may be retained for a limited period to understand usage trends and improve the Application. Aggregated or de-identified information that no longer identifies you may be retained for longer.
Your Choices and Rights
You may be able to:
- Export local app data from Settings.
- Delete local data from Settings.
- Request deletion of synced account data from Settings.
- Request access to, correction of, or deletion of personal information held by the Service Provider.
- Withdraw consent where processing is based on consent.
- Stop further local collection by uninstalling the Application.
Uninstalling the Application stops collection from your device, but it does not automatically delete information that has already been synced, transmitted, or processed. To request deletion or exercise privacy rights, contact the Service Provider at support@hfoster-labs.dev.
California Privacy Rights
If you are a California resident, you may have rights under California privacy laws, including the right to know what personal information is collected, the right to request deletion or correction, the right to opt out of the sale or sharing of personal information, and the right not to be discriminated against for exercising privacy rights.
Quitly does not sell personal information and does not share personal information for cross-context behavioral advertising.
To exercise California privacy rights, contact the Service Provider at support@hfoster-labs.dev.
Children
The Application is not intended for users under 18. You may not use the Application if you are under 18.
The Service Provider does not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the Application, contact support@hfoster-labs.dev so the Service Provider can take appropriate action.
Security
The Service Provider uses reasonable administrative, technical, and organizational safeguards to protect information processed and maintained by the Application. No method of transmission or storage is completely secure, and the Service Provider cannot guarantee absolute security.
International Transfers
Information may be processed in countries other than your country of residence, including the United States. Data protection laws in those countries may differ from the laws where you live. Where required by applicable law, the Service Provider will use appropriate safeguards for international transfers.
Legal Disclosures
The Service Provider may disclose information when required by law or when the Service Provider believes in good faith that disclosure is necessary to comply with legal process, protect rights and safety, investigate fraud or abuse, enforce terms, or respond to a government request.
Changes to This Policy
The Service Provider may update this Privacy Policy from time to time. Material changes will be posted with an updated effective date. Where required by law, the Service Provider will seek consent before material changes take effect.
Previous versions may be made available upon request by contacting support@hfoster-labs.dev.
Contact
If you have questions about this Privacy Policy or the Application's privacy practices, contact: