Privacy Policy

Steadied · Last updated 24 August 2026

The short version. Steadied has no accounts and no server. Everything you log — cravings, check-ins, notes, your reasons for quitting, your streak history and your quit plan — is stored in a database on your own phone and is never transmitted anywhere.

Three services receive limited technical information: PostHog (anonymous usage analytics), Sentry (crash reports) and RevenueCat (subscription management). None of them ever receives anything you typed or logged.

You can switch analytics off, export everything as a file, and permanently delete everything — all from inside the app.

This policy explains what information Steadied handles and what happens to it. It is written to match what the app actually does; if you find anything here that does not match your experience of the app, please contact us at the address at the bottom.

1. Information stored only on your device

Steadied stores the following in a database on your phone. There is no account, no server, and no sync. This information is never transmitted to us or to anyone else.

WhatIncludes
ProfileA randomly generated identifier created on your device, the date you started, what you are quitting (vape, pouches or both), your timezone and your currency
Quit planYour chosen method, the products you described and what you told us they cost, your reasons for quitting (free text), taper length, and your start and quit dates
Streak historyStarts, slips and restarts, with timestamps and any note you added (free text)
CravingsTimestamp, intensity, mood, location, trigger tag, whether the SOS exercise resolved it, and any note you added (free text)
Daily check-insDate, mood, craving intensity and any note you added (free text)
Subscription stateAn anonymous identifier generated by RevenueCat, your subscription status, plan and trial end date
PreferencesAppearance, notification settings, your analytics choice, sound settings and similar app settings

The identifier created on your device is not linked to your name, email address, phone number or any other identity, because Steadied never asks for those.

Backups

You can save a backup of your data as a file from Settings. Backup files are created on your device and shared using your phone's own sharing features, so they go wherever you choose to send them. Steadied never uploads a backup. Once a backup file leaves the app, it is subject to the privacy practices of wherever you put it.

2. Information that leaves your device

Five third parties are involved in running Steadied. What each one receives is listed below.

PostHog — anonymous usage analytics

PostHog helps us understand how the app is used, so we can improve it. It is off unless you turn it on. We ask once, when you first set the app up, and nothing is sent unless you agree. Saying no costs you nothing — every feature works exactly the same either way.

PostHog receives a fixed, limited list of events, together with the option chosen on the relevant screen:

PostHog never receives: your cravings, trigger tags, reasons for quitting, moods, notes, puff or pouch counts, money figures, streak lengths or quit dates. Nothing you type, and nothing calculated from it, is sent.

These events carry an anonymous device identifier only. We never link them to an identity, automatic event capture is switched off, and session recording is not installed. Your IP address is discarded rather than stored alongside your events, and location lookup from IP address is disabled.

You can change your mind at any time in Settings. The app checks your choice before the analytics client is created, so switching it off means nothing further is sent. It does not retrieve or undo events already sent before you changed the setting — to have those removed, contact us using the details in section 14.

Sentry — crash reports

Sentry tells us when the app crashes so we can fix it. It only sends anything when an error occurs; nothing about ordinary use is transmitted.

A crash report contains the technical stack trace, your operating system version, the app version and your device model. Personally identifying information is switched off, so no IP address, device identifier or user record is attached. Breadcrumbs (console output, network logs and touch history) are disabled entirely, and performance tracing is switched off. As a further safeguard, any report containing a field known to hold text you wrote is discarded before it is sent.

RevenueCat — subscription management

RevenueCat manages subscriptions and free trials. It receives an anonymous identifier that RevenueCat itself generates, your App Store transaction receipt, the product identifiers, your subscription status, and standard technical information their software collects such as country, platform and app version.

We never link a purchase to a person, because there is no account to link it to.

Apple — payment

Apple is the merchant of record for every subscription. Your payment details never reach Steadied; the purchase happens entirely within Apple's own payment sheet. Apple's handling of that transaction is covered by Apple's privacy policy, not this one.

Expo — app updates

When the app launches it asks Expo's servers whether a newer version of the app's code is available. Expo's servers see the request's IP address, your platform and the app's runtime version. This is infrastructure for delivering updates, not analytics.

3. Our legal basis for using information

Under UK and EU data protection law we have to tell you why we are allowed to use each piece of information. Nothing you record in the app appears below, because it never reaches us.

WhatWhy we may use it
Usage analytics (PostHog)Your consent. You can give or withdraw it at any time in Settings, and withdrawing takes effect immediately.
Crash reports (Sentry)Our legitimate interests in keeping the app working and fixing faults. Crash reports carry no identifier and no content you wrote.
Subscription information (RevenueCat, Apple)Performance of a contract — providing the subscription you paid for, and honouring free trials, renewals and restores.
App updates (Expo)Our legitimate interests in delivering fixes and improvements to the app you installed.

Where we rely on legitimate interests, we have considered whether that is fair to you: both cases involve technical information only, carry no identity, and are limited to keeping the app working. You can object to processing based on legitimate interests — see section 10.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. The patterns the app shows you — your trigger heatmap, your craving trends, the timing of reminders — are calculated on your own device from your own entries, and are suggestions for you to act on rather than decisions taken about you.

4. We do not sell or share your information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There are no advertising networks, no data brokers, no advertising identifiers and no tracking pixels in Steadied.

5. Consumer health data

Some of what you record in Steadied — cravings, moods, nicotine use, check-ins — relates to your health. Several jurisdictions, including Washington, Nevada and Connecticut, give this kind of information particular protection. This section describes how Steadied handles it.

If you have questions about health information in Steadied, or want to exercise any right relating to it, contact us at the address in section 14. Because we hold no such data and there is no account to identify you by, in most cases the fastest route is the backup and delete controls in the app itself.

Steadied is not a healthcare provider, health plan or clearinghouse, and is not acting on behalf of one. It is a consumer self-help app, so it is not covered by HIPAA, and using it does not create a provider–patient relationship.

6. Permissions

PermissionWhy
NotificationsDaily check-in reminders and nudges before your high-risk moments. These are scheduled and delivered entirely on your device — no push tokens are requested, so no notification data reaches any server.
FilesSaving and loading a backup, only when you explicitly choose to.

Steadied does not request access to your camera, location, contacts, microphone, photo library, advertising identifier or health data.

7. How long information is kept

WhatKept for
Everything you record in the appUntil you delete it. It lives on your device and we have no copy, so it is kept for exactly as long as you choose to keep it. Deleting the app also removes it.
Usage analytics (PostHog)One year on our current plan. After that PostHog may move it to archival storage or delete it permanently.
Crash reports (Sentry)Up to 90 days, then automatically deleted by Sentry. Our current plan is shorter than this, but 90 days is the maximum any crash report is held.
Subscription records (RevenueCat)For as long as the subscription is active, and afterwards for as long as we need to handle renewals, restores, refunds and our own tax and accounting obligations.
Update requests (Expo)Held in Expo's server logs under their own retention schedule. We do not receive or store these logs.

8. Deleting and saving your data

Deletion is immediate and total. Choosing to delete your data in Settings erases the database on your phone. Because there is no server copy, there is nothing left anywhere for you to request the deletion of afterwards. This cannot be undone, so save a backup first if you want to keep anything.

Saving a backup is available at any time from Settings, as a file containing everything Steadied holds about you.

Deleting the app from your phone also removes its local database.

9. Where information goes

Everything you record stays on your own device, wherever you are, and is not transferred anywhere.

The limited technical information described in section 2 is processed where each provider stores it:

ProviderProcessed in
Usage analytics (PostHog)European Union
Crash reports (Sentry)European Union
Subscription information (RevenueCat)United States
App update requests (Expo)United States

Transfers from the United Kingdom to the European Economic Area are covered by the UK's adequacy regulations, so no additional safeguard is needed for the first two.

For the providers that process in the United States, we rely on the transfer safeguards they offer — the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or their certification under the UK Extension to the EU–US Data Privacy Framework, as applicable to each. You can ask which mechanism applies to a given provider using the contact details in section 14.

10. Your rights and choices

Wherever you live

Three controls are built into the app and available to everyone, immediately, without contacting us:

For everything you record, you already hold and control that data directly — it is on your device. We could not access, produce or delete it on your behalf even if you asked us to, because we never receive it.

United Kingdom and European Union

Under UK and EU data protection law you have rights to access, correct, delete and port your personal data, to object to or restrict its processing, and to withdraw consent at any time where we rely on it.

If you are in the UK you also have the right to complain to the Information Commissioner's Office (ico.org.uk). If you are in the EU, you may complain to your local supervisory authority.

United States

Depending on your state, you may have rights to know what personal information is collected about you, to access or delete it, to correct it, to obtain a portable copy, and to opt out of its sale or of targeted advertising. We will not discriminate against you for exercising any of them.

Two points specific to how Steadied works:

Information about health specifically is covered in section 5.

To make a request or ask a question, contact us at the address in section 14. We may need to ask for information to verify a request, and we will not use anything you provide for that purpose for anything else. You may use an authorised agent where your state's law allows it.

11. Children

Steadied is rated 18+ and is not directed at anyone under 18. We do not knowingly collect information from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided information to us, contact us and we will act on it.

12. This website

These pages are hosted on GitHub Pages. GitHub records standard server information about visits, including your IP address, as part of serving and protecting the site. That is GitHub's processing under their own privacy statement, and we do not receive those logs or use them for anything.

This site sets no cookies and runs no analytics, advertising or tracking scripts of any kind.

13. Changes to this policy

If this policy changes, the updated version will be posted at this address with a new "last updated" date. Significant changes will also be noted in the app.

14. Who we are, and contact

Steadied is operated by Daniel Dewdath, 18 Waybrook Crescent, Reading, RG1 5RG, United Kingdom. We are the data controller for the limited information described in section 2.

Questions about this policy or about privacy in Steadied: steadiedapp@gmail.com