← QuitDuo

Privacy Policy

Last updated: 5 October 2026 · Version 1.3

Data controller: Aiovent Solutions UG (haftungsbeschränkt), Scholppenäcker 4/1, 71642 Ludwigsburg, Germany. Managing Director: Himanshu Kalubhai Kevadiya. Amtsgericht Stuttgart, HRB 800332. Full provider details: Impressum.

Contact for privacy questions and data-subject requests: hello@aiovent.com


1. Who we are and what this covers

QuitDuo ("the app", "we", "us") is a smoking-cessation support app operated by Aiovent Solutions UG (haftungsbeschränkt). This policy explains what personal data we process when you use the app, why, on what legal basis, how long we keep it, and the rights you have. It applies to both user roles: Smoker and Observer — the one person a Smoker invites to support them (see §4).

2. Data we process

CategoryExamplesRole
Account dataEmail address, nickname (the name you choose when you sign up and can change in Settings — the only name the person you link with sees), chosen role, sign-up date, authentication identifiers, and the settings you choose, such as your quit-line country and notification preferencesBoth
Consent recordsTimestamps and version of the terms, privacy, and health-data consent you gave, and your age confirmation; if you invite an Observer, when you agreed to share with them (the time your invite code was created)Both
Health-behavior data (special category)Cigarette counts (including half-cigarettes), craving intensity 1–10, mood, requests for support, craving notes, journal entries, streaks, relapse events, daily confirmed totalsSmoker
Smoking-timing dataWhen each cigarette was smoked or scheduled, your usual first and last smoking times (learned from your logs, or entered by you), and how closely you followed your planSmoker
Plan & progress dataYour 90-day plan (including whether it is waiting for an Observer or paused without one), baseline cigarettes per day, pack price and cigarettes per pack, reward score, badgesSmoker
MessagesMotivational messages shown to you — from the app's built-in library or AI-generated (see §5), including the weekly progress message of a paid program; the pre-written messages you and your Observer send each other, stored as a reference to the chosen message, never as typed textBoth
Link dataYour Smoker↔Observer link: invite code, status, when it was created and when it was claimed, both account IDs, and — while the link is active — both nicknamesBoth
Alert dataCraving alerts raised for your linked Observer: the craving score that triggered each one, whether it was urgent or a request for support, when it was raised, and when your Observer acknowledged itBoth
Safety dataReports you send us (the reason you chose, what you reported — a message or the person — and which link it concerns) and the people you have blocked (their account ID and the date)Both
PurchasesWhether and when you bought the 90-day program, and the purchase confirmation from Apple or Google — never card or payment details (see §9)Smoker
Device / technical dataTime zone, app version, the IP address your phone connects from (which our servers and providers receive with each request), crash diagnostics (only with your consent, see §5), and — only if you are an Observer and allow notifications for craving alerts — a push notification tokenBoth

We do not process payment card data (see §9), we do not use advertising identifiers, and we do not serve ads. Your health data is never used for advertising and is never sold.

Special-category (health) data

Craving, mood, cigarette, timing, and relapse data reveal information about your health and are treated as special-category data under GDPR Article 9. We process it only with your explicit consent, which you give on the consent screen at registration and can withdraw at any time. Showing it to an Observer needs a second, separate explicit consent, which you give on the invite screen (see §4).

Signing in with Google or Apple

Instead of an email address and a password, you can sign in with Google (iOS and Android) or Apple (iOS only). Google or Apple confirms who you are and gives the app a sign-in token, from which Firebase Authentication (Google, see §5) creates your account. From Google or Apple we receive the following, which becomes part of your account data:

We never see your Google or Apple password and do not ask for your contacts or anything else in your Google or Apple account. No Google or Apple advertising or analytics feature is used, and signing in shares nothing with Google or Apple beyond what the sign-in requires (and, for Apple, the revocation described below). The sign-in itself is processed by Google or Apple under their own privacy policies (Google, Apple). The legal basis is the same as for an account created with email and password: contract (Art. 6(1)(b), see §3). How you sign in changes nothing about your health data: every account needs the same explicit consent, given on the consent screen described above.

Deleting your account (see §10) removes an account created with Google or Apple like any other; your Google or Apple account itself is not affected. As such an account has no password, you confirm the deletion by signing in with Google or Apple once more. For an Apple account, the app also asks Apple to revoke QuitDuo's Sign in with Apple authorization before your data is erased; if that request fails, your account is deleted anyway. You can also remove QuitDuo from your Google Account or Apple Account settings at any time.

3. Why we process it, and our legal basis

PurposeLegal basis
Provide core features (logging, plan, schedule, rewards, messages, the Observer link)Contract (Art. 6(1)(b))
Process health data to build and adapt your personal plan and messages, including the AI-generated messages described in §5Explicit consent (Art. 9(2)(a))
Share your nickname, logs, progress, rewards and messages with the Observer you invite, and send them craving alerts (see §4)Your explicit consent, given on the invite screen when you tap "Agree & create my code" (Art. 6(1)(a), Art. 9(2)(a)). You withdraw it by ending the link.
Send push notifications you enabledConsent (Art. 6(1)(a))
Sell and provide the 90-day program, and confirm your purchase with Apple or Google (see §9)Contract (Art. 6(1)(b))
Review reports and enforce blocksLegitimate interests (Art. 6(1)(f)) in keeping the app safe for the people who use it
Improve the pacing algorithm using historical logs (see §8)Explicit consent (Art. 9(2)(a)) together with our legitimate interest in improving the service (Art. 6(1)(f))
Optional usage statistics, which include coarse health-related bands (see §5)Explicit consent, off by default (Art. 6(1)(a), Art. 9(2)(a))
Security and abuse prevention, including the IP address your phone connects from and our server logs (see §2 and §8)Legitimate interests (Art. 6(1)(f))
Crash and error diagnosticsConsent, off by default (Art. 6(1)(a)) — the same switch as usage statistics
Comply with legal obligations, such as keeping accounting recordsLegal obligation (Art. 6(1)(c))

You can withdraw consent at any time (see §10). Withdrawal does not affect processing already carried out before you withdrew.

4. The Observer (sharing you control)

A Smoker has one Observer at a time. The app asks you to invite one person you trust — a partner, friend or family member — within your first seven days. Without an Observer your step-down plan does not start, and if the link ends it pauses until a new Observer joins. Logging, the tools, the emergency button, the quit-line, getting a copy of your data and account deletion always work, with or without an Observer.

Nothing is shared without your consent. Before your invite code is created, the app lists what your Observer will and will never see, and you agree by tapping "Agree & create my code". The time your code is created is our record of that consent. Sharing begins only when your Observer enters the code, and you can withdraw your consent at any time by ending the link.

What your Observer can see while the link is active

What your Observer never sees: your email address; your real name, unless you use it as your nickname; your craving notes — a note you add to a craving is stored separately, where no other user can read it, and it is never used for machine learning; your journal; your plan itself and the settings in your profile; your consent record; your purchases, beyond the purchase time that a paid program's plan identifier carries (see above); your push token.

If you are an Observer, the person you support sees only your nickname, the messages you send each other, and whether an alert was sent to you. The link and alert records their account can read also hold your account ID, when you joined and when you acknowledged an alert; their app does not display these. Your email address, push token and settings stay in your own profile, which no other user can read.

Messages

Neither of you can type a message to the other. Your Observer taps one of 50 pre-written encouragements, and you can tap one of 50 pre-written updates back. Only a reference to the chosen message is stored, and each phone shows it in its own language. A new Observer never sees the messages you exchanged with an earlier one.

Craving alerts

Your Observer is alerted about a craving in these situations, and no others:

Cravings of 1 to 4 never generate an alert, although they still appear in the logs your Observer can see. Non-urgent alerts are limited to one every two hours, so your Observer is not flooded; urgent alerts and your own requests for support are not held back.

Alerts reach your Observer as push notifications (see §5). A notification names you only by your nickname and never contains your craving score; inside the app, your Observer sees the alert alongside your logs. An Observer can turn these notifications off at any time in Settings → Notifications ("Craving alerts"); the alert is then still recorded and shown in their app.

Ending, blocking and reporting

Either of you can end the link at any time in Settings → Support ("Remove Observer", or "Stop supporting" for an Observer). As soon as a link ends, our server cuts off the other person's access, removes both nicknames from the link and deletes that link's alerts; the messages you exchanged stay in the Smoker's account. You can also block the other person: this ends the link, and the two of you cannot link again unless the block is lifted. And you can report the other person to us — a Smoker can also report a single message from their Observer. A report tells us the reason you chose and what it concerns; we review reports, normally within 24 hours, and may suspend accounts that break our Terms of Service. Questions about a report or a block can go to hello@aiovent.com at any time.

5. Who else processes your data (sub-processors)

We use the following providers under data-processing agreements. PostHog and Sentry receive data only if you agree:

Alerts are never sent by WhatsApp, SMS or email: we do not use Twilio or any other messaging service, and the app does not ask for your phone number.

We do not sell your personal data, and we share it with no one other than the person you link with (as described in §4), the providers listed above, and — only as far as needed — Google or Apple when you sign in with them (see §2) or buy the program through their store (see §9).

6. International transfers

Everything in our database is stored in the European Union, and our server functions and our backend server run there too; your sign-in record is processed by Google in the United States, as described in §5. Some other providers listed in §5 are established outside the EEA or may process data outside it: Expo, Anthropic and Sentry are based in the United States, and PostHog, whose EU cloud stores the statistics in the EU, is a US company; push notifications are delivered through Apple's and Google's push services. Where that happens we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses and, where a provider is certified, the EU–U.S. Data Privacy Framework, together with additional technical measures — most importantly the minimization and pseudonymization described in §5.

7. Security

Data is encrypted in transit (HTTPS/TLS) and at rest. Access to the database is controlled by deny-by-default security rules: an Observer can read a Smoker's logs, progress, alerts and the messages of their own link only while that link is active; once it ends, the two of them can still read only the bare record of their link (see §8). No other user can ever read your profile, plan, journal or craving notes. Server endpoints require a verified authentication token. Deleting your account requires both re-entering your password — or, for an account that signs in with Google or Apple instead (see §2), signing in with it once more — and typing a confirmation word.

8. Retention

In short: the design is that your logs stay visible in the app for 90 days and then move into a separate, access-restricted archive we use to improve the pacing algorithm — never with your craving notes. That move is not yet in operation. Today your logs simply stay in the app database until you delete your account; there is no archive holding anything about you. You can ask us to erase archived logs at any time, and deleting your account erases them too.

9. Payments

QuitDuo is free to install, and Observers never pay. A Smoker's first seven days are free and include personal AI messages. The paid 90-day program is a one-time in-app purchase through the Apple App Store or Google Play, shown as €49.99 — the price the store shows you, in your currency, is the one that applies. It never renews, and its 90 days count from the day you buy it. The store is your contractual partner for that purchase, collects the price and any applicable VAT, and issues your receipt. We never receive or process your card or payment details.

To unlock the program, our server confirms the purchase with Apple or Google and records on your account when you bought it; the plan it starts is marked as paid. We receive from the store only what we need to confirm and manage your purchase — for example that it was made, when, and whether it was later refunded. Our server uses your purchase date, together with your sign-up date and time zone, to work out which days include personal AI messages.

10. Your rights

You have the right to access, rectification, erasure, restriction, portability, to object, and to withdraw consent. Deleting your account and switching off usage statistics work in the app, under Settings → Privacy & data, and so does ending sharing with your Observer, under Settings → Support. Every right is also an email away, so you can use all of them even if you have uninstalled the app:

You can also exercise any of these rights by writing to hello@aiovent.com; we respond within one month.

You have the right to lodge a complaint with a supervisory authority. Ours is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany. You may also complain to the authority in your own country of residence.

11. Children

QuitDuo is for adults aged 18 and over. You confirm your age when you accept the consent screen, and we store only that confirmation and its date — never a date of birth. We do not knowingly collect data from anyone under 18. If you believe a minor has given us their data, contact us and we will delete it.

12. Not medical advice

QuitDuo provides motivational and behavioral support. It does not provide medical advice, is not a medical device, and is not a substitute for professional or clinical treatment. See the in-app medical disclaimer and the Terms of Service.

13. Changes to this policy

We may update this policy. Material changes will be notified in the app, and where the change affects processing that rests on your consent we will ask for your consent again. The "Last updated" date above always reflects the current version.

14. Contact

Aiovent Solutions UG (haftungsbeschränkt), Scholppenäcker 4/1, 71642 Ludwigsburg, Germany · hello@aiovent.com · Impressum