Back to home
Legal Framework

Rules of the Game

Terms of Service · Privacy Policy · Consumer Health Data

§
Terms of Service
Effective & Updated: July 21, 2026

01 Acceptance of Terms

You accept these Terms by affirmatively indicating your agreement during onboarding — for example, by checking the "I accept the Terms and Privacy Policy" box — before you use the Quitory mobile application (the "App"). If you do not agree, do not use the App. You represent and warrant that you are at least 18 years of age. Quitory is operated by Quitory LLC, a limited liability company organized in California, United States, and is intended for users in the United States.

! Medical & Wellness Disclaimer

THE APP IS PROVIDED ON AN "AS IS" BASIS FOR INFORMATIONAL, SELF-HELP, AND ENTERTAINMENT PURPOSES ONLY. QUITORY IS NOT A MEDICAL DEVICE, A DIAGNOSTIC INSTRUMENT, OR A TREATMENT SYSTEM. IT DOES NOT PROVIDE MEDICAL ADVICE, DIAGNOSIS, OR PRESCRIPTIONS.

  • "A.R.I.A." is a fictional, scripted character within the App's science-fiction narrative. Its messages are pre-written by us and are not generated by artificial intelligence and not provided by a medical professional. It does not give medical advice, diagnosis, triage, or therapy.
  • Health metrics, timelines, and recovery stats are averaged, educational models based on public sources (such as WHO benchmarks). They are informational only and do not reflect your individual medical condition.
  • ALWAYS CONSULT A QUALIFIED HEALTHCARE PROFESSIONAL BEFORE MAKING SIGNIFICANT CHANGES TO YOUR NICOTINE OR CHEMICAL DEPENDENCY STATUS, OR IF YOU EXPERIENCE WITHDRAWAL OR HEALTH PROBLEMS.

03 User Content ("Beacon" Module)

The Beacon feature lets users submit short public text messages.

  • Content Rules: Offensive, discriminatory, threatening, sexual, unlawful, or infringing content (including third-party copyrighted text such as song lyrics or book excerpts) is prohibited.
  • Human Pre-Moderation: All Beacon submissions are reviewed and moderated by us before they appear, and are added to the App with an update.
  • Report & Block: you can report any signal via the "⋮" menu on the message, and hide an author so their signals no longer reach you and their messages disappear from your history. We review reports within 24 hours and remove content that breaks these rules. You can also write to support@quitory.app.
  • Enforcement: Repeat violations may result in a permanent block of your Beacon access.
  • Copyright: If you believe content in the App infringes your copyright, email support@quitory.app and include: identification of the copyrighted work; identification of the content and where it appears in the App; your contact details; and a statement that you have a good-faith belief the use is not authorized by the copyright owner, its agent, or the law. We review such notices promptly, remove infringing content, and terminate repeat infringers. All Beacon submissions are reviewed by us before they appear.

04 Intellectual Property

All functional architecture, source code, interface designs, narrative content, the A.R.I.A. character, and brand marks are the exclusive property of Quitory LLC (California, US) and are protected under United States and international copyright law.

05 Subscriptions & Auto-Renewal

  • A 7-day free trial may be offered on the annual plan to eligible new subscribers (as determined by the App Store and Google Play; typically users who have not previously used a trial or subscription for this app). Eligibility, availability and the price and period after any trial are shown on the purchase screen before you confirm. After the trial, access to premium features requires a paid subscription.
  • Auto-renewal: Subscriptions renew automatically. The price and billing period are shown on the purchase screen before you buy. Payment is charged at the start of each period. The "Lifetime" purchase incurs no recurring charges.
  • Cancel anytime: You can cancel at any time in your app store settings, or in one tap via Settings → "Manage Subscription" in the App. Cancelling stops the next renewal — you are not charged again. Your premium access continues until the end of the period you have already paid for; it is not revoked immediately. No reason, call or email is required.
  • Purchases and billing are processed by the Apple App Store and Google Play. Card and banking data are handled by Apple, Google, and their payment processors under PCI-DSS; we never receive, log, or store your card or banking information.
  • Refunds are governed by the policies of the relevant store (Apple App Store / Google Play).
  • Slip Protection: If you relapse, your premium access and unlocked content remain intact. A setback is data, not a penalty.

06 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, QUITORY LLC DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. QUITORY LLC PROVIDES NO GUARANTEE OF CESSATION SUCCESS.

  • The App is provided on an "As-Is" and "As-Available" basis.
  • IN NO EVENT SHALL QUITORY LLC BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF YOUR USE OF THE APP.
  • Your journal and logs are stored on your device. We are not liable for loss of on-device data if the App is uninstalled or the device is changed without exporting a backup.

07 Dispute Resolution & Waiver

ANY DISPUTE, CLAIM, OR CONTROVERSY ARISING OUT OF OR RELATING TO THESE TERMS OR THE APP SHALL BE RESOLVED THROUGH BINDING, INDIVIDUAL ARBITRATION IN THE STATE OF CALIFORNIA, USA, AND NOT IN A COURT OF LAW. YOU WAIVE ANY RIGHT TO PARTICIPATE AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS ACTION OR REPRESENTATIVE PROCEEDING AGAINST QUITORY LLC.

These Terms are governed by the laws of the State of California, United States, without regard to conflict-of-law principles. We may update these Terms; for material changes we will provide notice in the App and, where required, ask for your renewed agreement.

Privacy Policy
Effective & Updated: July 21, 2026

01 Our Privacy Approach

Quitory is built to be privacy-protective. Your journal, notes and letters are stored on your device and never sent to us.

Two different things happen with the rest: (1) REQUIRED — a small amount of technical data is always processed so the App can run and stay stable: crash diagnostics and app configuration. You cannot turn this off while using the App. Required crash diagnostics do not independently collect your journal or quit-journey data; if you separately opt in to usage analytics, recent quit-journey events may be included in crash reports as breadcrumbs (see below). (2) OPTIONAL — usage analytics, including quit-journey events, are processed ONLY if you opt in. This is off by default, the App works fully without it, and you can turn it off at any time.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. This Policy also covers our website (quitory.app) and our support email: our site is static, our hosting/CDN provider processes standard server logs (IP, browser, requested page, timestamp) to deliver it and for security, and we use no advertising cookies or advertising analytics (our hosting provider Framer provides cookie-free, privacy-oriented aggregate website analytics using short-lived, non-persistent measurements); the delete-data page collects only what you type into it; and if you email support@quitory.app we receive your address and whatever you include (if you describe your quit journey there, you may be sending health information voluntarily — we use it only to reply, via our email provider as processor). This Policy applies to users in the United States. The App is intended for users 18 and older.

02 Information We Process

  • On-device data: Your journal entries, craving logs, relapse history, "Letters to the Future," SOS notes, milestones, and achievements are stored locally on your device. If you delete the App or switch devices without exporting, this data is permanently lost.
  • Crash diagnostics (always on) & usage analytics (optional): We use Google Firebase Crashlytics to detect and fix crashes — it collects a pseudonymous installation identifier, device model, OS version and crash stack traces. This is necessary to keep the App stable and cannot be turned off; The crash report itself does not contain your journal, notes or letters, and does not independently gather quit-journey data. However, if you have opted in to usage analytics, some of your recent quit-journey events may be attached to a crash report as "breadcrumbs" — these are covered by your analytics opt-in. If you have not opted in, no such events exist and none are attached. Crash reports linked to your device are retained for only about 90 days, after which they are automatically deleted (see the Consumer Health Data Policy). Separately, we use Google Firebase Analytics (a pseudonymous app-instance ID, approximate country/region-level location derived from IP, device and OS information, and in-app events). Some events relate to your quit journey (for example, that a craving or relapse was logged, its intensity and trigger, the nicotine product type, or dose-reduction progress) and are used to understand how the App is used, to improve it, and to develop future features, including a predictive craving-support model. This collection is OFF by default and starts only if you opt in during onboarding; you can turn it off at any time in Settings → "Your Privacy Choices". See our separate Consumer Health Data Privacy Policy for how we handle this.
  • App configuration: We use Google Firebase Remote Config to roll out features and settings. It uses a pseudonymous Firebase installation identifier to decide which configuration your device receives. It does not collect your journal or health data.
  • Purchases: Handled by the Apple App Store and Google Play under PCI-DSS. We never receive or store your card or banking information. We use RevenueCat, Inc. as our processor to manage subscriptions; it receives a pseudonymous app user ID and subscription information from the stores — product identifiers, purchase and renewal dates, trial/introductory status, expiration and transaction identifiers. It does not receive your journal, cravings, relapse details or tapering parameters. Whether purchase or subscription information is itself "consumer health data" can depend on context; we treat it conservatively and never use it for advertising.
  • Beacon: A message you post is linked to a pseudonymous in-app identifier generated on your device (used for spam prevention, moderation and the block feature). It is not your name, email, or a hardware identifier, and we hold no account for you — but because it is persistent, several messages by the same author can be linked together. An optional nickname, if added, is shown publicly. Messages are reviewed by us before they appear. Anything you publish is public: do not include information you would not want others to see, including details about your health.
  • Motion / steps (Premium): If enabled, step data is read via CoreMotion and remains on your device; it is not transmitted to us.

03 Google's Role (Data Processor)

Google acts as our data processor, under Google's data-processing terms and not for its own advertising, for: (i) analytics and crash diagnostics (Firebase Analytics, Crashlytics); (ii) storage and human moderation of Beacon messages you submit, held in Google Cloud Firestore before publication — if a message contains health information, Google processes it as our processor for this purpose; and (iii) app configuration (Remote Config) purposes. We have disabled Google's advertising features, ad personalization, and Google Signals for this project, and we do not use advertising SDKs. Because Google acts as our processor, these disclosures are not sales or "shares" of your personal information.

04 We Do Not Sell or "Share" Your Data

We do not sell your personal information and do not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar state laws. Who is who:

  • Google (Firebase Analytics, Crashlytics, Remote Config, Cloud Firestore) and RevenueCat, Inc., together with Zoho (email) and Framer (website hosting), act as our processors / service providers — they process data on our behalf, under contract, and not for their own purposes. Disclosures to them are not sales or "shares".
  • The Apple App Store and Google Play, when they process your purchase and operate your store account, act under their OWN terms and for their own purposes — not as our processors. What they collect is governed by Apple's and Google's privacy policies, not by this one. From the stores we receive your purchase and subscription information (such as whether a subscription is active, its product, dates and renewal status) as needed to provide premium access.

05 Your Privacy Choices & Rights

Depending on your state, you may have the right to access, delete, or correct your personal information, to opt out of analytics processing, and to limit the use of sensitive (health-related) data. To exercise your choices:

  • In the App: open Settings → "Your Privacy Choices" to turn usage analytics on or off at any time. It is off unless you opt in. Turning it off does not delete your on-device data.
  • Delete your data: use the in-app deletion option, or our data deletion request page at quitory.app/delete-data.
  • Requests & questions: email support@quitory.app. We will not discriminate against you for exercising these rights, and we verify requests as required by law.

06 Data Retention

  • On-device data: kept on your device until you delete it or remove the App.
  • Analytics & diagnostic data: usage analytics (Google Analytics) is retained for up to 14 months, then deleted or aggregated. Crash reports and their identifiers are retained by Google for approximately 90 days. The Firebase installation identifier (used by Crashlytics and Remote Config) is retained until a deletion request is made; removal from live and backup systems can take up to 180 days.
  • Beacon moderation data: retained only as long as needed for spam prevention and moderation.
  • Other processors: Beacon submissions (Cloud Firestore) are kept until you delete your data or ask us to remove a message; support emails (Zoho) and website form submissions (Framer) are kept only as long as needed to handle your request, then deleted; RevenueCat records are kept where required for subscription management and legal or accounting obligations; website server logs are kept by our hosting provider for a short period for security.

07 Security, Children & Breach Notice

  • Security: we use reasonable technical and organizational measures. No method of transmission or storage is completely secure.
  • Children: the App is for users 18 and older and is not directed to children. Consistent with COPPA, we do not knowingly collect data from children under 13; if we learn we have, we delete it.
  • Breach notification: if a breach of security affecting your data occurs, we will notify affected users and regulators as required by the FTC Health Breach Notification Rule (without unreasonable delay and no later than 60 days) and applicable state breach-notification laws.
Consumer Health Data Privacy Policy
Effective & Updated: July 21, 2026

01 Scope

This policy describes how Quitory LLC collects, uses, and shares consumer health data, as required by the Washington My Health My Data Act (MHMDA), Nevada SB 370, Connecticut law, and similar U.S. state privacy laws. It supplements our general Privacy Policy.

02 What Consumer Health Data We Collect

This distinction matters: much of what you enter never reaches us at all.

(a) Stays on your device — we do not receive it, cannot read it, and hold no copy: your journal and withdrawal notes; "Letters to the Future"; SOS session notes; the detailed history of your cravings and relapses; achievements and progress.

(b) We receive only if you opt in to usage analytics — as events, through our processor:

  • that a craving was logged: intensity, trigger, whether you overcame it, which tool you used;
  • that a relapse was logged: product type, trigger, days since your quit date;
  • dose-reduction (tapering) progress: current, baseline and target dose, phase, plan compliance;
  • your product type, quit stage, cessation method and subscription status.

If you do not opt in, none of this is sent.

(c) You publish voluntarily — Beacon: if you write something about your health in a public message (for example "I relapsed today"), you are voluntarily submitting consumer health data and we do receive it: it is transmitted to our servers, read by a human moderator before it can appear, stored, and if approved published to other users with a later update. This does NOT depend on your analytics opt-in. Please do not include health details you would not want to be public. To remove a message you sent, email support@quitory.app — we remove it from moderation and from pending content bundles; if already published, it stops being distributed from the next update onward.

03 How & Why We Collect It

We receive the information described in sections (b) and (c) above directly from you; the information in section (a) remains solely on your device, and we neither receive nor can read it. If — and only if — you opt in, limited quit-journey events (for example, that a craving or relapse was logged, its intensity and trigger, the nicotine product type, and dose-reduction progress) are processed through our analytics provider, acting as our processor, to understand how the App is used, to improve it, and to develop future features, including a predictive craving-support model. We do not use consumer health data for advertising, and we do not sell it.

04 Consent

We collect consumer health data for the purposes above — including to develop future features such as a predictive craving-support model — only with your separate, affirmative opt-in consent, requested during onboarding as a distinct choice from our Terms of Service and other acknowledgments. This consent is entirely OPTIONAL: if you decline, the App remains fully functional and no consumer health data is sent to our analytics provider. You may grant or withdraw consent at any time via Settings → "Your Privacy Choices". Withdrawal stops future collection.

05 Who We Share It With

We share consumer health data only with service providers/processors acting on our behalf under contract:

  • Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043) — for analytics and crash diagnostics, and for storage, human pre-publication moderation, and deletion/content management of Beacon messages held in Google Cloud Firestore. If a Beacon message you submit contains health information, Google processes it as our processor for this purpose. Configured without advertising features.
  • RevenueCat, Inc. (San Francisco, CA) — for subscription management. It does NOT receive your journal, cravings, relapse details or tapering parameters. It receives pseudonymous purchase and subscription information (product identifiers, purchase, renewal and expiration dates, trial status, transaction identifiers), which we treat as sensitive in the context of a nicotine-cessation app and never use for advertising.
  • Zoho Corporation — our email provider. If you email support@quitory.app and describe your quit journey, any health information you include is processed by Zoho as our processor solely so we can respond to you.
  • Framer B.V. — our website hosting provider, which also serves our data-deletion request page. Any health information you type into that page is processed by Framer as our processor solely to transmit your request to us.
  • We do not sell consumer health data, and we do not share it with third parties for their own purposes.
  • We do not use geofencing around any health care facility, and we do not collect location to infer health-facility visits.

06 Your Rights & How to Exercise Them

You have the right to access the consumer health data we have, request its deletion, and withdraw consent.

When you delete your data in the App we: (a) delete everything stored on your device; and (b) reset your analytics identifier and delete your Firebase installation identifier, which stops further events being linked to the previous ones. Resetting the identifier does not, by itself, erase events already received by our analytics provider.

To have those earlier events erased as well, the App offers to send us a deletion request containing your previous analytics identifier (you can also email it to support@quitory.app). On receiving it we submit a server-side deletion request to our analytics provider. If you do not send the request, the events remain in pseudonymous form and are automatically deleted or aggregated after 14 months.

Crash reports are pseudonymous and are retained by our crash provider for only about 90 days, after which they are automatically deleted. When you delete your data, we reset your identifier so that future crash reports are not linked to previous ones. Beacon messages you submitted are deleted from our storage when you delete your data in the App, and you can ask us to remove a specific message at any time. Purchase records held by Apple, Google and RevenueCat are retained where required for subscription management and legal or accounting obligations. If you contacted us by email or used our deletion page and included health information, on your deletion request we also delete that support correspondence held by our email provider (Zoho) and any form submission held by our hosting provider (Framer), and instruct these processors to delete it, subject only to short retention required by law or for security/backup purposes.

To exercise these rights:

  • In the App: Settings → "Your Privacy Choices" (opt out / withdraw consent) and the in-app deletion option;
  • Online: our deletion request page at quitory.app/delete-data;
  • Email: support@quitory.app.

We respond to requests within 45 days. Where reasonably necessary we may extend this period by a further 45 days and will tell you why.

Appeal. If we deny your request, we will tell you why and how to appeal. To appeal, reply to our decision or email support@quitory.app with "Appeal" in the subject line. We will respond to an appeal within 45 days. If we deny the appeal, you may submit a complaint to the Washington State Attorney General (www.atg.wa.gov/file-complaint) or to the attorney general of your state.

Privacy & Corporate Inquiries
Quitory LLC
support@quitory.app