Last Updated: April 8, 2026
Effective Date: April 8, 2026
Privacy Policy — detoxify
Welcome to detoxify. This Privacy Policy explains how detoxify (“we”, “us”, or “our”) collects, uses, discloses, and protects information when you use our iOS mobile application (the “App”). detoxify is a health-focused addiction recovery and habit-tracking app designed to help users overcome harmful dependencies through data-driven insights and gamification.
Please read this policy carefully. By installing or using the App you consent to the collection and use of information as described in this policy.
1. Information We Collect
We collect information you provide directly and information collected automatically to deliver and improve the App.
Types of information we collect:
- Account & Profile Data
- Email address, username, profile preferences, and other account settings you provide.
- Health & Sensitive Recovery Data
- Addiction types being tracked, sobriety streaks, urge logs (triggers, intensity, timestamps), health timeline events, challenge progress, badge/level history, and any notes you create related to recovery. This data is sensitive health-related information.
- Financial & Subscription Information
- Subscription status, purchase receipts, purchase dates and plan type. Payment processing is handled by Apple through StoreKit; we do not collect or store your full payment card details.
- Biometric Data
- Biometric authentication usage (e.g., Face ID / Touch ID) is supported via Apple’s LocalAuthentication framework. Biometric data itself is not collected or sent to our servers—authentication is performed and secured by the device and iOS. We may store a flag indicating whether you enabled biometric unlock.
- Device & Usage Data
- Device model, operating system version, unique device identifiers (as permitted by Apple policies), crash logs, performance diagnostics, feature usage, timestamps, and IP address.
- Local Notifications
- We use UserNotifications to schedule and deliver local notifications. We may store preferences for notifications.
- Communications
- Support requests, feedback, and correspondence you send to us (via email or in-app).
Information we do NOT collect:
- We do not collect full payment card numbers or banking credentials. Apple’s App Store / StoreKit handles payment processing.
- We do not sell personal information.
2. How We Use Your Information
We use collected information to provide, maintain, and improve the App and for the purposes described below:
- Provide App Functionality
- To enable core features (urgent logging, dashboards, streak tracking, health timeline, daily challenges, badges, gamification, and biometric unlock).
- Account & Subscription Management
- To create and manage your account, process subscription status and free trial information (through StoreKit/Apple), and communicate billing or account issues.
- Personalization & Insights
- To generate personalized progress insights, recommendations, and goal suggestions based on your inputs and usage patterns.
- Notifications & Reminders
- To send reminders, progress notifications, and challenge prompts via local notifications (UserNotifications).
- Security & Authentication
- To authenticate users, secure accounts (including optional biometric unlock), and protect against abuse.
- Support & Communication
- To respond to support requests, provide customer service, and send administrative messages (e.g., policy updates).
- Analytics & App Improvement
- To analyze usage trends, diagnose technical issues, and improve features and performance.
- Legal & Safety
- To comply with legal obligations, enforce our Terms of Service, and protect the rights and safety of users and others.
Legal basis for processing (EU/EEA users):
- Performance of a contract (providing the App and subscription services).
- Consent, where required (e.g., optional analytics or personalized insights settings).
- Legitimate interests (improving services, security) where balanced against user privacy.
3. Data Sharing and Third Parties
We do not sell your personal information. We disclose information only as described below or with your consent.
- Service Providers and Contractors
- We may share information with service providers who perform services on our behalf (for example, cloud hosting, email, analytics, and technical support). These providers are authorized to use your information only as necessary to provide services to us.
- Apple and iOS Frameworks
- LocalAuthentication: Used for on-device biometric authentication. Biometric data remains on the device and is not accessible to us.
- UserNotifications: Used to schedule and manage local notifications on your device.
- StoreKit: Used for in-app purchases, free trials, and subscription management. Payment processing and billing are handled by Apple.
- Legal Requirements and Safety
- We may disclose information in response to lawful requests by public authorities (e.g., subpoenas), to comply with legal processes, or to protect rights, safety, or property.
- Business Transfers
- If we are involved in a merger, acquisition, reorganization, or sale of assets, user information may be transferred as part of that transaction. We will notify users and apply contractual protections where required.
- Aggregated or De-identified Data
- We may aggregate or de-identify information and use or share it for any purpose (such data cannot reasonably be used to identify you).
4. Data Retention
We retain personal information only for as long as necessary to provide the App, fulfill the purposes described in this policy, and comply with legal obligations.
Typical retention periods:
- Account & Profile Data: Retained while your account is active and for up to 2 years after account deletion or as required by law.
- Health & Recovery Data (urge logs, timelines, progress): Retained while your account is active and for up to 2 years after deletion to allow for recovery of accounts, backup, or legal obligations unless you request earlier deletion.
- Transaction Receipts & Subscription Records: Retained as required for tax, accounting, and recordkeeping (commonly up to 7 years, or as required by law).
- Crash logs and diagnostics: Retained for up to 2 years to diagnose and improve the App.
When you delete your account or request deletion, we will delete your personal data from active systems and cease using it, except to the extent we need to retain an archival copy to comply with legal obligations or legitimate internal needs (e.g., fraud prevention). Where deletion is technically infeasible (backups), we will isolate retained data and apply security measures.
5. Security Measures
We take reasonable administrative, technical, and physical measures to protect personal data from unauthorized access, disclosure, alteration, and destruction. Measures include:
- Encryption in transit (HTTPS/TLS) for data transmitted between the App and our servers.
- Encryption at rest for sensitive data stored on servers where applicable.
- Use of iOS secure storage mechanisms (Keychain) for tokens and local secrets.
- Biometric authentication via LocalAuthentication (biometric data never leaves the device).
- Access controls, role-based access, and least privilege for employees and contractors.
- Regular security assessments, patch management, and monitoring.
- Processes for incident response and breach notification.
No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Children's Privacy
detoxify is not intended for children under the age of 13. We do not knowingly collect information from children under 13.
- If you are under 13, do not use the App or provide any information.
- If we become aware that we have collected personal information from a child under 13 in a manner that violates applicable law, we will take steps to delete such information promptly.
- For users in jurisdictions with higher age thresholds (e.g., GDPR: 16 or as set by local law), parental consent requirements must be satisfied before processing account creation; we do not target or knowingly accept registrations from under-age users.
7. Your Rights (GDPR / CCPA compliant)
We provide the following rights to users, subject to verification and applicable law:
For users in the EU/EEA (GDPR rights):
- Right of Access: You can request a copy of your personal data.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your personal data (subject to legal exceptions).
- Right to Restrict Processing: You can request restriction of certain processing activities.
- Right to Data Portability: You can request a machine-readable copy of data you provided.
- Right to Object: You can object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
For California residents (CCPA/CPRA rights):
- Right to Know: You can request the categories and specific pieces of personal information we have collected about you, and the categories of sources, purposes, and recipients.
- Right to Delete: You can request deletion of personal information we collected from you.
- Right to Opt-Out of Sale: We do not sell personal information and therefore there is no sale opt-out. If this practice changes, we will provide a Do Not Sell My Personal Information link or instructions.
- Right to Non-Discrimination: You have the right not to be treated differently for exercising CCPA rights.
How to exercise your rights:
- Contact us at detoxify@forvibe.app with the subject line “Privacy Rights Request” and include:
- Your account email or user ID, the request type (access, deletion, portability, etc.), and any supporting information to verify your identity.
- We may request additional information to verify your identity (for example, verifying the email associated with your account or device identifiers) to process requests.
- Timeframes: We will acknowledge receipt within a reasonable period and respond to verifiable requests within applicable statutory timeframes (typically up to 30 days for GDPR; CCPA/CPRA allows up to 45 days with potential extension).
- Authorized agents: If you use an authorized agent, we may require written permission from you or verification of the agent’s authority.
Note: Some requests may be limited by legal obligations or technical constraints (e.g., logs retained for security reasons).
8. AI / Automated Processing Disclosure
We use automated processing and algorithmic techniques to generate personalized insights, recommendations, progress predictions, and gamified leveling based on the data you provide (e.g., urge logs, streaks, engagement patterns).
- Purpose: To tailor suggestions, recommend challenges, visualize progress, and provide motivational content.
- Impact: Automated processing helps create personalized experiences but does not make legal decisions or decisions with similarly significant effects about you.
- User Controls: You can disable or limit personalized insights in the App settings. If you would like human review of algorithmic outputs or explanations about automated recommendations, contact us at detoxify@forvibe.app and we will provide assistance.
- Data used: The algorithms rely on your in-app data (health logs, usage patterns) and aggregated anonymized data. We do not use third-party profiling data to make sensitive medical determinations.
9. In-App Purchases & Subscriptions
detoxify offers a freemium model with optional subscription tiers, free trials, and auto-renewing subscriptions via Apple’s App Store/StoreKit.
- Free Trial & Auto-Renewal
- Free trials (where offered) convert to paid subscriptions automatically at the end of the trial unless canceled before the trial ends.
- Subscriptions auto-renew unless cancelled. You are responsible for managing and canceling your subscription through your Apple ID account settings prior to renewal. Generally, cancellations must be made at least 24 hours before the end of the current period to avoid being charged for the next period; check Apple’s terms for specific timing.
- Billing & Refunds
- Payments and billing are handled by Apple. For billing issues, refund requests, and subscription management, please use Apple’s subscription management and support channels. We cannot cancel your subscription for you but can provide assistance or guidance.
- Information Shared
- We may receive basic subscription status, transaction receipts, and plan information from StoreKit/Apple to manage access to premium features.
- Trial Abuse & Refund Policies
- We reserve the right to limit or refuse access to promotional trials in cases of suspected abuse or fraud.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or App features.
- When we change this policy we will update “Last Updated” at the top and, where required by law, provide notice through the App or via email.
- Continued use of the App after changes constitutes acceptance of the updated policy.
Effective Date of this policy: April 8, 2026. Last Updated: April 8, 2026.
11. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our data practices, please contact:
detoxify
Email: detoxify@forvibe.app
Website: https://detoxify.forvibe.app
When contacting us about privacy requests, please include sufficient information to identify your account (e.g., account email) and the nature of your request. We will respond within applicable legal timeframes.
Thank you for trusting detoxify with your recovery journey. We are committed to protecting your privacy and using your information to provide a secure, helpful, and respectful experience.