Privacy Policy
Data controller: Aiovent Solutions UG (haftungsbeschränkt), Scholppenäcker 4/1, 71642 Ludwigsburg, Germany. Managing Director: Himanshu Kalubhai Kevadiya. Amtsgericht Stuttgart, HRB 800332. Full provider details: Impressum.
Contact for privacy questions and data-subject requests: hello@aiovent.com
1. Who we are and what this covers
QuitDuo ("the app", "we", "us") is a smoking-cessation support app operated by Aiovent Solutions UG (haftungsbeschränkt). This policy explains what personal data we process when you use the app, why, on what legal basis, how long we keep it, and the rights you have. It applies to both user roles: Smoker and Observer — the one person a Smoker invites to support them (see §4).
2. Data we process
| Category | Examples | Role |
|---|---|---|
| Account data | Email address, nickname (the name you choose when you sign up and can change in Settings — the only name the person you link with sees), chosen role, sign-up date, authentication identifiers, and the settings you choose, such as your quit-line country and notification preferences | Both |
| Consent records | Timestamps and version of the terms, privacy, and health-data consent you gave, and your age confirmation; if you invite an Observer, when you agreed to share with them (the time your invite code was created) | Both |
| Health-behavior data (special category) | Cigarette counts (including half-cigarettes), craving intensity 1–10, mood, requests for support, craving notes, journal entries, streaks, relapse events, daily confirmed totals | Smoker |
| Smoking-timing data | When each cigarette was smoked or scheduled, your usual first and last smoking times (learned from your logs, or entered by you), and how closely you followed your plan | Smoker |
| Plan & progress data | Your 90-day plan (including whether it is waiting for an Observer or paused without one), baseline cigarettes per day, pack price and cigarettes per pack, reward score, badges | Smoker |
| Messages | Motivational messages shown to you — from the app's built-in library or AI-generated (see §5), including the weekly progress message of a paid program; the pre-written messages you and your Observer send each other, stored as a reference to the chosen message, never as typed text | Both |
| Link data | Your Smoker↔Observer link: invite code, status, when it was created and when it was claimed, both account IDs, and — while the link is active — both nicknames | Both |
| Alert data | Craving alerts raised for your linked Observer: the craving score that triggered each one, whether it was urgent or a request for support, when it was raised, and when your Observer acknowledged it | Both |
| Safety data | Reports you send us (the reason you chose, what you reported — a message or the person — and which link it concerns) and the people you have blocked (their account ID and the date) | Both |
| Purchases | Whether and when you bought the 90-day program, and the purchase confirmation from Apple or Google — never card or payment details (see §9) | Smoker |
| Device / technical data | Time zone, app version, the IP address your phone connects from (which our servers and providers receive with each request), crash diagnostics (only with your consent, see §5), and — only if you are an Observer and allow notifications for craving alerts — a push notification token | Both |
We do not process payment card data (see §9), we do not use advertising identifiers, and we do not serve ads. Your health data is never used for advertising and is never sold.
Special-category (health) data
Craving, mood, cigarette, timing, and relapse data reveal information about your health and are treated as special-category data under GDPR Article 9. We process it only with your explicit consent, which you give on the consent screen at registration and can withdraw at any time. Showing it to an Observer needs a second, separate explicit consent, which you give on the invite screen (see §4).
Signing in with Google or Apple
Instead of an email address and a password, you can sign in with Google (iOS and Android) or Apple (iOS only). Google or Apple confirms who you are and gives the app a sign-in token, from which Firebase Authentication (Google, see §5) creates your account. From Google or Apple we receive the following, which becomes part of your account data:
- Your email address. With Apple you can choose Hide My Email: we
then receive only a private relay address ending in
@privaterelay.appleid.com, which Apple forwards to your own address, and Apple does not tell us your real address. - Your name, if your Google or Apple account shares it. Apple shares it only the very first time you sign in with Apple, and lets you edit it before sharing. Firebase Authentication may keep it with your sign-in details, but the app never shows it to anyone and never uses it as your nickname: you type your nickname yourself when you set up your account.
- An identifier for your Google or Apple account, so that your next sign-in opens the same account. Google also passes on a link to your Google profile picture, if you have one; it is stored with your sign-in details, but the app never uses or displays it.
We never see your Google or Apple password and do not ask for your contacts or anything else in your Google or Apple account. No Google or Apple advertising or analytics feature is used, and signing in shares nothing with Google or Apple beyond what the sign-in requires (and, for Apple, the revocation described below). The sign-in itself is processed by Google or Apple under their own privacy policies (Google, Apple). The legal basis is the same as for an account created with email and password: contract (Art. 6(1)(b), see §3). How you sign in changes nothing about your health data: every account needs the same explicit consent, given on the consent screen described above.
Deleting your account (see §10) removes an account created with Google or Apple like any other; your Google or Apple account itself is not affected. As such an account has no password, you confirm the deletion by signing in with Google or Apple once more. For an Apple account, the app also asks Apple to revoke QuitDuo's Sign in with Apple authorization before your data is erased; if that request fails, your account is deleted anyway. You can also remove QuitDuo from your Google Account or Apple Account settings at any time.
3. Why we process it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Provide core features (logging, plan, schedule, rewards, messages, the Observer link) | Contract (Art. 6(1)(b)) |
| Process health data to build and adapt your personal plan and messages, including the AI-generated messages described in §5 | Explicit consent (Art. 9(2)(a)) |
| Share your nickname, logs, progress, rewards and messages with the Observer you invite, and send them craving alerts (see §4) | Your explicit consent, given on the invite screen when you tap "Agree & create my code" (Art. 6(1)(a), Art. 9(2)(a)). You withdraw it by ending the link. |
| Send push notifications you enabled | Consent (Art. 6(1)(a)) |
| Sell and provide the 90-day program, and confirm your purchase with Apple or Google (see §9) | Contract (Art. 6(1)(b)) |
| Review reports and enforce blocks | Legitimate interests (Art. 6(1)(f)) in keeping the app safe for the people who use it |
| Improve the pacing algorithm using historical logs (see §8) | Explicit consent (Art. 9(2)(a)) together with our legitimate interest in improving the service (Art. 6(1)(f)) |
| Optional usage statistics, which include coarse health-related bands (see §5) | Explicit consent, off by default (Art. 6(1)(a), Art. 9(2)(a)) |
| Security and abuse prevention, including the IP address your phone connects from and our server logs (see §2 and §8) | Legitimate interests (Art. 6(1)(f)) |
| Crash and error diagnostics | Consent, off by default (Art. 6(1)(a)) — the same switch as usage statistics |
| Comply with legal obligations, such as keeping accounting records | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent at any time (see §10). Withdrawal does not affect processing already carried out before you withdrew.
4. The Observer (sharing you control)
A Smoker has one Observer at a time. The app asks you to invite one person you trust — a partner, friend or family member — within your first seven days. Without an Observer your step-down plan does not start, and if the link ends it pauses until a new Observer joins. Logging, the tools, the emergency button, the quit-line, getting a copy of your data and account deletion always work, with or without an Observer.
Nothing is shared without your consent. Before your invite code is created, the app lists what your Observer will and will never see, and you agree by tapping "Agree & create my code". The time your code is created is our record of that consent. Sharing begins only when your Observer enters the code, and you can withdraw your consent at any time by ending the link.
What your Observer can see while the link is active
- Your nickname.
- Your logs — cravings with their level, cigarettes and daily check-ins, and the optional mood — with the date and time of each, including entries from before they joined. Each entry also carries the technical details the app stores with it: the time zone it was logged in; the identifier of the plan that was active, which during a paid 90-day program contains the date and time you bought it; and, for a cigarette logged against your schedule, its scheduled time, that day's target and the first and last smoking times your schedule is built on. Your Observer's app does not display these details, but they are part of the entries it can read.
- Your progress, streaks, reward meter and badges.
- The pre-written messages you send each other.
- An alert when a craving runs high or when you ask for support (see below).
What your Observer never sees: your email address; your real name, unless you use it as your nickname; your craving notes — a note you add to a craving is stored separately, where no other user can read it, and it is never used for machine learning; your journal; your plan itself and the settings in your profile; your consent record; your purchases, beyond the purchase time that a paid program's plan identifier carries (see above); your push token.
If you are an Observer, the person you support sees only your nickname, the messages you send each other, and whether an alert was sent to you. The link and alert records their account can read also hold your account ID, when you joined and when you acknowledged an alert; their app does not display these. Your email address, push token and settings stay in your own profile, which no other user can read.
Messages
Neither of you can type a message to the other. Your Observer taps one of 50 pre-written encouragements, and you can tap one of 50 pre-written updates back. Only a reference to the chosen message is stored, and each phone shows it in its own language. A new Observer never sees the messages you exchanged with an earlier one.
Craving alerts
Your Observer is alerted about a craving in these situations, and no others:
- Automatically, when your craving is 7 or higher — at 9 or 10 the alert is marked urgent.
- When your craving is 5 or 6 and you explicitly tap "Yes, let them know" when the app asks whether you want your supporter to know. If you do not answer, nothing is sent.
- When you tap "Tell my supporter" on the emergency screen, which is saved as a craving of 10.
Cravings of 1 to 4 never generate an alert, although they still appear in the logs your Observer can see. Non-urgent alerts are limited to one every two hours, so your Observer is not flooded; urgent alerts and your own requests for support are not held back.
Alerts reach your Observer as push notifications (see §5). A notification names you only by your nickname and never contains your craving score; inside the app, your Observer sees the alert alongside your logs. An Observer can turn these notifications off at any time in Settings → Notifications ("Craving alerts"); the alert is then still recorded and shown in their app.
Ending, blocking and reporting
Either of you can end the link at any time in Settings → Support ("Remove Observer", or "Stop supporting" for an Observer). As soon as a link ends, our server cuts off the other person's access, removes both nicknames from the link and deletes that link's alerts; the messages you exchanged stay in the Smoker's account. You can also block the other person: this ends the link, and the two of you cannot link again unless the block is lifted. And you can report the other person to us — a Smoker can also report a single message from their Observer. A report tells us the reason you chose and what it concerns; we review reports, normally within 24 hours, and may suspend accounts that break our Terms of Service. Questions about a report or a block can go to hello@aiovent.com at any time.
5. Who else processes your data (sub-processors)
We use the following providers under data-processing agreements. PostHog and Sentry receive data only if you agree:
- Google Firebase / Google Cloud — authentication (including password-reset
emails), the Firestore database, server functions, and Firebase Hosting, which serves this website
and the small file the app reads to check whether a newer version exists (that request carries no
account information). Everything in our database — your profile, logs, notes, plans, journal,
messages, links, alerts, reports and blocks — is stored in the European Union
(Firestore,
eur3), and our server functions run in the EU (regioneurope-west1). Your sign-in record — email address, name or nickname, account ID, and either a hashed password or the Google or Apple details listed in §2 — is handled by Firebase Authentication, which Google runs only in the United States; Google LLC is certified under the EU–U.S. Data Privacy Framework, and Google's data processing terms include the EU Standard Contractual Clauses. - Our backend server — our server, hosted in the European Union by a hosting provider under a data-processing agreement. It checks each craving you log for an alert to your Observer and requests the AI-generated messages described below. For each craving, the app sends it the entry you logged — never the note you added to it — together with your account ID, nickname, time zone and link ID. It reads from our database what these tasks need and writes alerts and AI messages back to it.
- Expo (push delivery) — delivers push notifications to Observers who allow notifications for craving alerts: the craving alerts themselves and, from a daily check, reminders to get in touch. Expo receives the Observer's push token, the notification's title and text — which name the Smoker only by nickname and never contain a craving score — and a few technical fields (the type of notification, internal identifiers and whether it is urgent), and passes the notification to Apple's or Google's push service for delivery to the phone. A Smoker's reminders are scheduled on the phone itself and do not pass through Expo or any other server.
- Anthropic — writes the personal AI messages. After you log a craving during your free week or a paid 90-day program, our server asks Anthropic's Claude AI for a short encouragement. Outside those periods, beyond a daily limit, or when our server cannot be reached, nothing about your craving is sent to Anthropic and your message comes from the app's built-in library, which also steps in whenever an AI message cannot be used. Requests are minimized and pseudonymized: they contain no name, no email, no account identifier, and none of your craving notes or journal entries — only a coarse time of day, your craving score and mood word, a one-line summary of where you are in your plan (such as how many cigarettes today's plan allows), and the type, craving score and mood of up to five recent log entries. For the program's weekly progress message, its day-90 message (which can also be written in the 30 days after the program) and the note the app can show when you ask to restart your program, Anthropic receives only a few numbers — such as the day of your program, smoke-free days, cravings you rode out, cigarettes this week and money kept — and the language to write in. Anthropic does not use this data to train its models.
- PostHog (EU) — optional product analytics, off unless you switch it on. It uses a random identifier stored on your phone, which is not linked to your account, your name or your email — so the statistics are pseudonymous, not anonymous. Geolocation is disabled, and PostHog is set not to store your IP address. Health-related information is included only as coarse bands and yes/no answers: how strong a craving was (low, medium or high), whether you added a mood to it (never which mood) and whether it came while your next cigarette was still locked, your usual daily amount (under 10, 10–19, or 20 or more cigarettes), whether a day was smoke-free or under, on or over its target, whether a cigarette was early, on time or late against your schedule, which stage of your plan you are in, that you started your plan again before it ended (with its stage and roughly how far in it was), and smoke-free milestones (whether you are smoke-free and on plan when you reach days 30, 60 and 90). Each event also carries the time it happened, such as when you logged a craving or a cigarette. It never receives notes, messages, journal entries, your email or your account ID.
- Sentry — crash reports and error diagnostics, to help us fix faults. Like usage statistics, this is off unless you switch it on: nothing is sent to Sentry until you grant the diagnostics consent, and switching it off stops it. Crash reports are not linked to your account, and Sentry is set not to store your IP address. Crashes that happen before you answer the consent screen are not reported at all.
Alerts are never sent by WhatsApp, SMS or email: we do not use Twilio or any other messaging service, and the app does not ask for your phone number.
We do not sell your personal data, and we share it with no one other than the person you link with (as described in §4), the providers listed above, and — only as far as needed — Google or Apple when you sign in with them (see §2) or buy the program through their store (see §9).
6. International transfers
Everything in our database is stored in the European Union, and our server functions and our backend server run there too; your sign-in record is processed by Google in the United States, as described in §5. Some other providers listed in §5 are established outside the EEA or may process data outside it: Expo, Anthropic and Sentry are based in the United States, and PostHog, whose EU cloud stores the statistics in the EU, is a US company; push notifications are delivered through Apple's and Google's push services. Where that happens we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses and, where a provider is certified, the EU–U.S. Data Privacy Framework, together with additional technical measures — most importantly the minimization and pseudonymization described in §5.
7. Security
Data is encrypted in transit (HTTPS/TLS) and at rest. Access to the database is controlled by deny-by-default security rules: an Observer can read a Smoker's logs, progress, alerts and the messages of their own link only while that link is active; once it ends, the two of them can still read only the bare record of their link (see §8). No other user can ever read your profile, plan, journal or craving notes. Server endpoints require a verified authentication token. Deleting your account requires both re-entering your password — or, for an account that signs in with Google or Apple instead (see §2), signing in with it once more — and typing a confirmation word.
8. Retention
In short: the design is that your logs stay visible in the app for 90 days and then move into a separate, access-restricted archive we use to improve the pacing algorithm — never with your craving notes. That move is not yet in operation. Today your logs simply stay in the app database until you delete your account; there is no archive holding anything about you. You can ask us to erase archived logs at any time, and deleting your account erases them too.
- Logs in the app (cravings, cigarettes, mood, check-ins): 90 days, once archiving runs. The intended behaviour is that after 90 days each log is moved out of the app database into a separate archive and deleted from the app database. The scheduled task that does this is not in operation, so at present logs older than 90 days remain in the app database with the rest of your data, and nothing has been archived. We will update this policy and notify you in the app before that changes.
- Craving notes: kept in your account until you delete your account. They are never archived and never used for machine learning.
- The archive (planned, and currently empty). Archived logs are stored under your account identifier — they are pseudonymous, not anonymous — and never include your craving notes. We use them to train and improve the algorithm that paces your plan. The archive has no automatic expiry. You can have it erased at any time, independently of the rest of your data, by writing to hello@aiovent.com, and we erase it automatically if your account no longer exists.
- Plans, journal entries, messages and rewards: kept while your account exists.
- Links: the record of a link — its invite code, status, dates and both account IDs — is kept until either of you deletes your account; the nicknames are removed from it as soon as the link ends.
- Alerts: kept while the link is active, and deleted as soon as it ends or either of you deletes your account.
- Reports: kept until the account of the person who sent the report, or of the person it names, is deleted; they do not expire automatically.
- Blocks: kept until the person who blocked lifts the block or deletes their account.
- Purchases: what we record about a purchase (see §2) is kept while your account exists.
- Push token: kept on an Observer's profile until a new token replaces it or the account is deleted.
- Account and consent records: kept while your account exists, and deleted with it.
- Unfinished sign-ups: if you start creating an account — with Google, with Apple, or with an email address and password — but stop before accepting the consent screen, a sign-in record with the email address and the name or nickname that you or your provider gave (with Google, also the profile-picture link) remains in Firebase Authentication. Apart from its account ID, when it was created and last used and, for an email sign-up, the hashed password, it holds nothing else, and no other data about you is stored. We do not delete such records automatically; write to us and we will delete it.
- Usage statistics and crash reports (only if you switched them on): they are not linked to your account, so deleting your account does not delete them. PostHog deletes usage statistics after 1 year, and Sentry deletes crash reports after 30 days.
- Server logs (which can contain your IP address and account ID): deleted after 30 days.
- On account deletion: everything in your account is deleted — profile, logs, craving notes, plans, messages, rewards, journal entries and blocks — together with your links, every alert that concerns you and every report you sent or that names you; your archive is erased, and finally your sign-in account is removed. Two things stay with the other person: a block that someone else placed on you remains in their account (it holds only your account ID and the date) until they lift it or delete their account, and pre-written messages you sent as an Observer remain in the Smoker's message history, without your name or account ID. Beyond that, deletion is subject only to usage statistics and crash reports (see above), server logs (up to 30 days) and copies in Google's own disaster-recovery systems until they expire — we keep no backups of our own and never restore deleted data — and to records we are legally required to keep, such as accounting records relating to a purchase.
9. Payments
QuitDuo is free to install, and Observers never pay. A Smoker's first seven days are free and include personal AI messages. The paid 90-day program is a one-time in-app purchase through the Apple App Store or Google Play, shown as €49.99 — the price the store shows you, in your currency, is the one that applies. It never renews, and its 90 days count from the day you buy it. The store is your contractual partner for that purchase, collects the price and any applicable VAT, and issues your receipt. We never receive or process your card or payment details.
To unlock the program, our server confirms the purchase with Apple or Google and records on your account when you bought it; the plan it starts is marked as paid. We receive from the store only what we need to confirm and manage your purchase — for example that it was made, when, and whether it was later refunded. Our server uses your purchase date, together with your sign-up date and time zone, to work out which days include personal AI messages.
10. Your rights
You have the right to access, rectification, erasure, restriction, portability, to object, and to withdraw consent. Deleting your account and switching off usage statistics work in the app, under Settings → Privacy & data, and so does ending sharing with your Observer, under Settings → Support. Every right is also an email away, so you can use all of them even if you have uninstalled the app:
- Get a copy of your data: there is no button for this in the app. Write to hello@aiovent.com from your account's email address — with Apple's Hide My Email, from any address (see Support) — and we will send you a copy of your data in a structured, machine-readable format within one month.
- Erase your archive: the historical archive described in §8 can be erased on its own, without deleting your account. There is no separate in-app control for this — ask us at hello@aiovent.com and we will erase it and confirm in writing. Deleting your account erases it as well.
- End sharing with your Observer: Settings → Support → "Remove Observer" (as an Observer: "Stop supporting"). This withdraws your consent to share (see §4).
- Delete your account and all associated data: "Delete my account", confirmed by typing DELETE and re-entering your password — or, for an account that signs in with Google or Apple instead (see §2), by signing in with it once more. If you have uninstalled the app you do not need to reinstall it: Delete your account describes the email route, and we erase everything within 30 days.
- Withdraw your health-data consent: the app cannot work without it, so you withdraw it by deleting your account, or by writing to hello@aiovent.com and we delete your account and data.
- Turn off analytics: the "Share usage statistics" toggle, which is off unless you turn it on; it switches off crash reports as well.
You can also exercise any of these rights by writing to hello@aiovent.com; we respond within one month.
You have the right to lodge a complaint with a supervisory authority. Ours is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany. You may also complain to the authority in your own country of residence.
11. Children
QuitDuo is for adults aged 18 and over. You confirm your age when you accept the consent screen, and we store only that confirmation and its date — never a date of birth. We do not knowingly collect data from anyone under 18. If you believe a minor has given us their data, contact us and we will delete it.
12. Not medical advice
QuitDuo provides motivational and behavioral support. It does not provide medical advice, is not a medical device, and is not a substitute for professional or clinical treatment. See the in-app medical disclaimer and the Terms of Service.
13. Changes to this policy
We may update this policy. Material changes will be notified in the app, and where the change affects processing that rests on your consent we will ask for your consent again. The "Last updated" date above always reflects the current version.
14. Contact
Aiovent Solutions UG (haftungsbeschränkt), Scholppenäcker 4/1, 71642 Ludwigsburg, Germany · hello@aiovent.com · Impressum