QuitForecast

Privacy policy

Effective September 14, 2026. First version July 31, 2026. QuitForecast is an iOS app made by Allamanda LLC, the data controller for everything this policy describes. For any question about your data, write to info@quitforecast.com and a person will answer.

The short version

Your recovery data lives on your phone. Nothing leaves it unless you choose one of six things. The six: an iCloud backup. A post to the community board, a move or a feature request. A vote on somebody else's post. A report flagging a post for review. A feedback message. A support conversation. We run no analytics, no ads, no tracking, and no third-party SDKs.

What stays on your device

Everything the app is about stays here: your habits and quit dates, your craving log, your slip history, the savings tin, challenge progress, and settings. Anything read from Apple Health stays too. Health data is read-only, displayed to you, and never transmitted anywhere.

What leaves your device, only if you choose it

iCloud backup (off by default). If you turn it on, a copy of your app data is stored in your private iCloud database, which Apple secures under your Apple Account. The copy is encrypted on your phone before it is stored, with keys that belong to your account, so neither we nor Apple can read it. Turning the toggle back off stops new copies being made, but it does not remove copies already stored; Settings > Delete all data is what removes them, and it deletes every copy the app has made.

Community board posts. If you post to the board, a move or a feature request, its text is stored in Apple's public CloudKit database, the board's host. It carries an anonymous member identifier: a scrambled stand-in derived from your iCloud account that cannot be run backwards, never your name or email. Apple also stamps every record in its public database with an Apple-assigned account id for this app, which travels with each board record; the app never asks Apple to make your account discoverable, so that id resolves to no name or email. Posts are reviewed by a person before appearing. A post that is not approved is never published. It stays in the same public database, marked as unpublished, and the app never shows it; it is deleted when you delete your data. To remove what you posted, use Settings > Delete all data: it erases every post and vote you made on the board.

Votes. If you back somebody's post, your vote is stored against that post under the same anonymous member identifier, which is what lets you take the vote back. Nothing else about you is attached to it.

Reports. If you flag a post for review, the report is stored with the reason you picked and the same anonymous identifier, so a person can act on it. Blocking a member is different: that stays on your device and is never sent anywhere.

Feedback. If you send feedback from the app, the message carries exactly two things you wrote: the category you picked and the words you typed. The app adds one fixed technical token, the same for every copy of the app, which keeps strangers off the pipe and says nothing about you. No name, no device identifier, no habit data, nothing that would let us find the message again or connect it to you. It is stored on our feedback service, hosted by Cloudflare, where a person reads it. Every message is automatically deleted within twelve months of arriving. Sending it uses the internet, so the service sees your IP address the way any server does. That address is used only to limit repeat submissions, lives in that counter for about two minutes, and is never stored with your message.

Support conversations. If you open Get help and write to us, your messages and our replies are stored on the same feedback service, hosted by Cloudflare, under a random thread ID your phone invents. The ID is never your name, your email, or anything about your device. Nothing else travels with your words. The conversation lives on your phone, and deleting the app's data closes it there. The stored copy deletes itself within twelve months, or sooner if you ask us to remove it while the thread is still open on your phone.

Reading the board sends nothing and needs no account. Opening a board surface, or running a backup, does ask iCloud who you are. That check is Apple answering the app directly, and it writes nothing. If you never post, vote or report, nothing about you is written to the board.

What we never do

No advertising. No analytics SDKs. No tracking across apps or websites. No sale or sharing of data. No accounts, and no passwords.

This website

These pages set no cookies and load no fonts, scripts or trackers from any other host. We add no measurement of our own, and there is no form to fill in. The host that serves the pages sees requests the way every web host does; none of that reaches us.

Deleting your data

Settings > Delete all data erases three stores at once: everything on the device, your iCloud backup, and everything you sent to the board. The board part means your posts, your votes and your reports. Export your data first from the same screen if you want a copy. One stamp stays on the phone: the date your free week began, kept so the week cannot be restarted by erasing.

Feedback is the one exception. Messages carry no identifier, so Delete all data cannot find yours to delete them. They delete themselves within twelve months. If you want one gone sooner, write to us and quote it. A support conversation sits in between: Delete all data closes it on your phone, our copy deletes itself within twelve months, and asking us inside the thread deletes it sooner.

Children

QuitForecast is intended for adults.

Your rights

The app holds no accounts, and your data lives on your own device. So there is nothing for us to look up, correct or hand over. You already hold all of it. You can export it from Settings, and delete it from the same screen. If you have posted to the community board and want a post removed without erasing everything, write to info@quitforecast.com. A feedback message works the same way: quote it to us and we will delete it. Because no message carries an identifier, what it said is the only way to find it.

The same address handles the rest of your rights: if something we hold is wrong you can ask us to correct it, you can ask us to stop or limit what we do with it, and you can object to any of it. You can also complain to the data protection authority where you live, at any time, without asking us first.

The legal footing

Every send above happens only because you choose it. That choice is the legal basis for all six. For everything else there is nothing to justify, because nothing is processed.

The feedback and support service runs on Cloudflare's network, so a message can be handled outside your own country. Cloudflare's standard data protection terms cover that transfer, and they carry the EU's standard contractual clauses. Write to us for a copy of those clauses. The twelve-month deletion applies wherever the message lands.

You can take any of these choices back at any time. Stop sending, or use the deletion routes above; nothing keeps processing after.

Changes

If this policy changes, the updated version is posted at this address with a new effective date.