Skip to content

Privacy Policy

What Quit Vaping Slowly collects, why, how long it is kept, and the controls you have over it.

Last updated:

This policy explains what Quit Vaping Slowly collects, why, and what you can do about it. It is written to be read, not to be skimmed past.

The short version: we collect the tracking data you enter so the app can show it back to you, plus the minimum needed to run an account. We do not sell it, we do not use it for advertising, and you can export or delete all of it from inside the app.

Who we are

Quit Vaping Slowly operates the Quit Vaping Slowly mobile app and this website. For privacy questions, contact privacy@quitvapingslowly.app.

What we collect

We collect three categories of data, and nothing else.

  • Data you enter. Puff logs (time, count, and optionally a trigger, mood and note), reflections, journal entries, goals, reduction plans, reminders, and your onboarding answers such as your typical daily average, how long you have vaped, device type and nicotine strength.
  • Account data. If you create an account: your email address, a securely hashed password, an optional display name and date of birth, your timezone and language. Guest accounts have none of this — only a random identifier.
  • Technical data needed to operate the service. IP address and user agent at sign-in, kept in a security log so we can detect account takeover.

How reminders work

Reminders are scheduled and delivered entirely on your own device. The app does not send your reminders to a server, and we do not operate a push-notification service, so there is no push token or device identifier associated with them.

This is also why reminders keep working with no internet connection. If you turn notifications off, nothing is scheduled and nothing changes on our side.

What we do not collect

  • We do not collect your contacts, photos, precise location, microphone or camera data. The app does not request these permissions, and they are explicitly blocked in the Android manifest.
  • We do not use advertising identifiers, and there are no third-party advertising or analytics SDKs in the app.
  • We do not build profiles for marketing, and we never sell or rent personal data to anyone.
  • We do not operate a push-notification service, so we hold no push tokens. Reminders are scheduled locally on your device.

Why we process it, and our legal basis

Under the GDPR, we rely on the following bases. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

  • Performance of a contract. Storing your logs and syncing them across your devices is the service you signed up for.
  • Consent. Push notifications, and optional anonymous usage statistics, are off unless you turn them on.
  • Legitimate interests. Keeping a limited security log of sign-ins to detect account takeover, and keeping the service running and secure.

Health-related data

Information about nicotine use may be considered health data, and in the EEA and UK it is treated as a special category requiring extra protection. We treat all of your tracking data that way regardless of where you live.

Concretely: this data is never used for advertising, never shared with third parties for their own purposes, is excluded from our application logs, and is encrypted in transit and at rest. Where processing is based on consent, that consent is explicit and separate.

How it is stored and protected

  • All traffic between the app and our servers uses TLS. Data is encrypted at rest by our hosting provider.
  • Passwords are hashed with Argon2id. We never store them, and we cannot recover them.
  • Session tokens are stored in the iOS Keychain or Android Keystore, never in ordinary app storage, and are marked device-only so a restored backup on a new phone does not carry a live session.
  • Refresh tokens are stored only as SHA-256 digests, so a database compromise cannot be replayed into working sessions. Reusing an old token revokes the entire session family immediately.
  • Access to production data is limited to what is required to operate the service, and every access path requires authentication.

How long we keep it

  • Tracking data is kept until you delete it or delete your account.
  • Deleted entries are retained briefly as tombstones so the deletion can reach your other devices, then removed.
  • Security logs (sign-in events) are kept for up to 12 months.
  • Expired and revoked session tokens are purged automatically within 30 days.
  • Data exports you generate expire and are deleted after 24 hours.
  • When you request account deletion there is a 14 day grace period during which you can cancel. After that, your data is permanently erased.

Your rights

Depending on where you live you may have some or all of the following rights. We honour all of them for every user, regardless of location.

  • Access and portability. Export everything you have entered as JSON or CSV from Settings, at any time, without asking us.
  • Rectification. Edit or delete any individual entry directly in the app.
  • Erasure. Delete your account from Settings. After a 14 day grace period everything is permanently removed.
  • Objection and restriction. Turn off notifications and optional analytics in Settings, or contact us.
  • Withdrawal of consent. Any consent-based processing can be switched off in Settings.
  • Complaint. You may lodge a complaint with your local data protection authority. We would appreciate the chance to resolve it first at privacy@quitvapingslowly.app.

California privacy rights (CCPA/CPRA)

California residents have the right to know what personal information is collected, to delete it, to correct it, and to opt out of sale or sharing.

We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes beyond providing the service. Exercising these rights will never result in worse service or different pricing.

Children

This app is intended only for adults who already use nicotine. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

Service providers

We use a small number of providers to run the service. Each processes data only on our instructions and under a data processing agreement.

  • Railway — application and database hosting.

International transfers

Our infrastructure may process data in regions outside your own. Where data leaves the EEA or UK, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.

Changes to this policy

If we make a material change we will update the date at the top of this page and notify you in the app before the change takes effect. Continued use after that constitutes acceptance.