C
Loading…
Skip to main content

Privacy policy — ClearMind Quit: Stop Smoking & Vaping

Last updated: 1 August 2026

1. In short

  • You can use the app without an account. In that mode everything stays in your browser and reaches us only when you use an AI feature.
  • What you write — journal entries, chat messages, craving notes, your reason for quitting — is never sent to product analytics, and never sent to error monitoring.
  • Optional analytics can be switched off, and AI features can be switched off.
  • You can export your data, delete it locally, delete it from your account, or delete the account.

2. Who we are

  • Data controller: ClearMind Quit
  • Address: Kilkenny, Ireland
  • Contact: welcome@clearmindquit.com

[LEGAL REVIEW] Confirm the registered entity name and whether a Data Protection Officer is required before publishing.

3. Guest mode: what stays on your device

If you use ClearMind Quit without creating an account, the following are stored in your browser’s local storage on your device and are not transmitted to us:

  • Your onboarding answers, including pathway, stage, usage, triggers and your reason for quitting
  • Your quit date and chosen pathway
  • Daily check-ins and slip records, including any note you add to a slip
  • Craving-rescue records: urge ratings, trigger category, strategy used, and any free-text note
  • Your if–then plans
  • Journal entries and unsaved drafts
  • Your preferences, including whether AI features and optional analytics are enabled

Clearing your browser data deletes all of it. We have no copy and cannot recover it. The Privacy & data screen in the app shows exactly what is currently stored.

4. Account data: what is stored in Supabase

If you create an account, we use Supabase (authentication and database) to store:

  • Your profile: email address, authentication credentials managed by Supabase, display name if you gave one, quit date, pathway, and stated usage.
  • Your payment status: whether premium access is active, and an expiry timestamp when access came from a promotional code.
  • Your synced progress (when signed in): onboarding answers, check-ins, slips, craving-rescue records, if–then plans, programme position and preferences. This exists so your progress survives a lost phone and follows you between devices.

Journal entries are not synced by default. They only leave your device if you explicitly turn on journal sync in Privacy & data. You can turn it off again, and you can delete the synced copy without deleting your account.

5. AI processing

When you use an AI feature, the text you send is transmitted to our server and forwarded to Google (Gemini) to generate a response. This includes chat messages and any context you type into an AI-assisted tool.

  • We do not store your AI conversations in our database. They exist for the duration of the request and in your browser session.
  • Because AI messages can contain health-related information, we ask for your explicit consent before the first time free text is sent to the AI provider, and you can withdraw it at any time.
  • You can disable AI features entirely and keep using the programme, the check-in, Craving Rescue, the coping tools and the support directory.
  • Google may retain transient logs for its own abuse and safety monitoring for a limited period, independently of our settings. [LEGAL REVIEW] Confirm current retention terms and the correct transfer mechanism with the provider’s data processing addendum.

6. Voice processing

Voice support streams audio from your microphone to Google’s live AI service for the duration of a session, using a short-lived token issued by our server. We do not record, store or transcribe the audio. Sessions end automatically after a period of inactivity. Your microphone is only accessed while a session is running, and only after you grant browser permission.

7. Payments

Payments are processed by Stripe. Card details are entered on Stripe’s systems and never reach our servers. We receive confirmation that a payment succeeded, along with the associated email address and our own account identifier, and we store the resulting access status against your profile.

8. Technical and security data

  • Rate-limit records: we count requests per IP address in a short rolling window, and count AI requests per account per day, to prevent abuse and control cost. These counters expire automatically and are not linked to anything you write.
  • Server logs: our hosting provider records standard request logs, including IP address and timestamps.
  • Error monitoring (optional, off by default): if enabled, we send an error name, a redacted message and a redacted stack trace. Request bodies and user data are redacted by default, and any error string touching journal, craving or onboarding storage is discarded entirely rather than transmitted.

9. Analytics

Product analytics are optional, disabled unless configured, and can be switched off by you at any time in Privacy & data.

When enabled, we record high-level product events only. We never send:

  • Journal content
  • Chat messages
  • Free-text trigger or slip notes
  • Medication or NRT details
  • Your name or email address

Event properties are restricted to a fixed allowlist: pathway, onboarding stage, day number, trigger category from a controlled list, feature name, guest or registered, free or premium, device class, and country where lawfully available. Anything else is dropped before it leaves your device. The full event catalogue is documented in our repository.

10. Special category (health) data

Some of what you enter is health-related and is special category data under the GDPR: your smoking or vaping status, cravings, withdrawal experiences, slips, and anything you mention about medication or your health in a journal entry or AI conversation.

Where we process this, we rely on your explicit consent, which we ask for before the relevant feature is used and which you can withdraw. Withdrawing consent disables that feature; it does not delete data you have already saved, which you can delete separately.

[LEGAL REVIEW] Confirm the lawful bases below and the Article 9 condition relied on for each processing activity, and complete a DPIA before launch.

11. Legal bases

  • Contract: providing the account, saved progress and paid features you asked for.
  • Consent: AI features, journal sync, optional analytics, and processing of special category health data.
  • Legitimate interests: security, abuse prevention, rate limiting and keeping the service running.

12. Who else processes your data

  • Supabase — authentication, database and account storage
  • Google (Gemini) — AI text and voice generation, only when you use those features
  • Stripe — payment processing
  • Vercel — hosting and serverless functions
  • Upstash — rate-limit and quota counters
  • An analytics provider and an error-monitoring provider, only if configured

We do not sell personal data, and we do not use it for advertising.

13. International transfers

Some of these providers process data outside the EEA. Where that happens we rely on recognised safeguards such as adequacy decisions or Standard Contractual Clauses. [LEGAL REVIEW] Confirm the current transfer mechanism and hosting region for each processor and record them here.

14. Retention

  • Local data: kept on your device until you delete it or clear your browser.
  • Account and synced progress: kept until you delete your account or delete your saved progress.
  • AI conversations: not stored in our database.
  • Rate-limit counters: expire automatically within 24 hours.
  • Payment records: retained by Stripe and by us as required for financial record-keeping. [LEGAL REVIEW] Confirm the statutory retention period.

15. Your controls and rights

From Privacy & data inside the app you can, at any time:

  • See what is stored locally versus in your account
  • Export your structured progress as a file
  • Delete all local data on this device
  • Delete your saved progress from your account
  • Delete your account
  • Turn optional analytics off
  • Turn AI features off and keep using the programme
  • Withdraw consent for journal sync and AI processing

You also have rights of access, rectification, erasure, restriction, objection and portability. Email welcome@clearmindquit.com — we may need to verify your identity first.

16. Complaints

Please contact us first. You also have the right to complain to a supervisory authority — in Ireland the Data Protection Commission, in the UK the Information Commissioner’s Office.

17. Children

ClearMind Quit is intended for adults. If you tell the AI coach that you are under 18, it stops and directs you to age-appropriate support. Please do not use the service or provide personal data if you are under 18.

18. Not medical advice

ClearMind Quit provides information and behavioural support. It does not diagnose or provide individual medical treatment. Decisions about nicotine replacement or stop-smoking medication should be discussed with a pharmacist, GP, stop-smoking adviser or other appropriately qualified professional.

19. Changes

We will post any updated version on this page and change the date at the top. If a change is material we will tell you in the app.