QuitForecast / The manual / Data, backup and privacy

Data, backup and privacy

No accounts, nothing to sign into, and your record is yours. This section is the manual for keeping it that way.

Where your data lives

On your phone, in one file the app owns. The optional iCloud backup carries exactly the fields written down in the app's own allowlist, and Health readings are never among them.

Everything the app knows lives in one store on your device: habits, log, slips, tin, badges, settings. There is no account and no server copy unless you turn the iCloud backup on. That backup goes to your own private iCloud database, which we cannot read.

The backup carries an explicit allowlist of fields, held by test, so a new feature cannot quietly start syncing something. Health readings are never in it. Turning the backup off stops new copies; Delete all data removes the stored ones too.

Export

One tap in Settings hands you everything the app knows as a readable file. Your data is yours; a copy should cost nothing.

The export is a readable JSON file of your whole record: habits, cravings with their times and cues, slips, savings, badges, settings. It goes wherever you send it, and nothing about exporting phones home.

Export stays available on every tier and in every state, including after the trial. Handing you your own data is not a feature, it is the floor.

Delete everything

The other one tap. It takes the habits, the log, the shelf, the backup flags, all of it, and it cannot be undone. Unsent feedback is discarded rather than delivered, because somebody erasing themselves does not want their last message posted afterwards.

Delete all data erases three stores at once: the device, your iCloud backup, and everything you sent to the community board. Posts, votes and reports alike. If the network is down mid-erase, the app retries the remote deletions until they land.

It asks once, plainly, and then it is done. There is no soft delete and no recovery window, which is why Export sits on the same screen. Feedback queued but unsent is discarded rather than delivered.

Feedback, help and requests

Send feedback is anonymous and read by a person. Get help is a private thread a person answers, usually within a day. Feature requests are the public door: approved requests are visible to everyone and votes steer what gets built. Three doors, and the private two never feed the public one.

Send feedback carries the category you picked and the words you wrote, nothing that identifies you. That also means we cannot reply: it is a one-way note a person reads. Get help is the two-way door: a private thread under a random ID your phone invents, answered by a person, usually within a day.

Feature requests travel the community board's reviewed pipeline and appear under Your posts once approved; votes steer what gets built next. The private doors never feed the public one: nothing you write in feedback or support can appear on the board.