Privacy Policy
Cirrus is a quit-vaping app. This policy describes exactly what it stores, who else can see it, and how to make it all go away. It describes what the app actually does, not what we might do later.
The short version
- We do not sell your data, and we never will.
- There are no advertising SDKs and no third-party ad trackers in the app. Not "we don't use them much" — they are not in the build.
- The community is anonymous to other users: your posts carry an alias you choose, never your account or email.
- You can delete your account and everything in it from inside the app, in two taps, without asking us.
What we store
Your account
An account is created through Firebase Authentication when you sign in with email, Google, or Apple. If you start without signing in, an anonymous account is created for you so your plan has somewhere to live. We store the identifier that service gives us, and the email address if you used one.
Your quit journey
This is the app's main record and it stays under your account:
- Your answers to the onboarding questions: age band, gender, how often you vape, how soon after waking, previous attempts, why you are quitting and what you are worried about.
- Your plan: baseline puffs per day, nicotine strength, weekly spend, method and pace.
- Every day you log: puff counts and the hours they happened, cravings you got through, mood check-ins, any note you wrote, and any trigger you selected after a slip.
- Savings goals you set, and badges you earn.
Your conversations with Ember
Ember is the in-app coach. Messages you send and its replies are stored under your account so the conversation continues between sessions.
Ember also keeps a short list of things you have told it that are worth remembering later — a person you mentioned, something you are working toward. You can read that entire list, and delete any item from it permanently, in Settings → What Ember remembers. We built that screen because a coach that quietly accumulates personal disclosures with no way to look is not something anyone should be asked to trust.
Device and app data
Your timezone and language, so reminders and reports arrive at the right local time; a notification token if you allow notifications; and, if you subscribe, your subscription status. We also collect crash reports and anonymous usage events (which screens are reached, whether onboarding was completed) to find bugs and dead ends.
Who else sees it
We use a small number of service providers. They process data for us and are not permitted to use it for their own purposes.
- Google Firebase — authentication, database, hosting, crash reporting and analytics. Data is stored in Google Cloud in the United States.
- Google Gemini — the model behind Ember. The message you send, plus a summary of your own quit data, is sent to it to generate a reply.
- RevenueCat — subscription status, if and when in-app subscriptions are available.
That is the complete list. We do not share your data with advertisers, data brokers, or anyone else.
The community
Posts and replies are stored without your account identifier attached to them. Other people see the alias and emoji you chose, the day number of your quit, and what you wrote — nothing else. We keep the link between you and your posts separately and privately, so that deleting your account can actually remove them.
Reactions work the same way: the totals are public, who left them is not.
Posts are screened automatically before they appear, and anything flagged is reviewed by a person. You can report or block from any post.
Deleting everything
Settings → Delete account. This removes your quit journey, your conversations with Ember and everything it remembered, your craving history, your weekly reports, your subscription record and your login. Community posts you wrote are kept but permanently detached from you and re-attributed to "a departed quitter", so a conversation other people are part of does not disappear from under them.
Deletion is immediate and cannot be undone. You do not need to email us or wait for us to action it.
How long we keep things
Until you delete your account. Ember's memory list is capped and drops the least-used entries on its own. Crash and analytics data is retained on Firebase's standard schedule.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your data, and to object to some processing. The delete control above covers deletion. For anything else, write to us at the address below and we will respond.
Age
Cirrus is for adults 18 and over. We ask your birth year during setup and do not let under-18s continue; we point to age-appropriate quit services instead. We do not knowingly keep data from anyone under 18. If you believe we have, contact us and we will delete it.
Not medical advice
Cirrus is a support tool, not medical treatment, and Ember is not a doctor. Nothing in the app is a diagnosis or a prescription. If you are considering nicotine replacement or medication, speak to a pharmacist or a doctor.
Changes
If this policy changes in a way that affects what we do with your data, we will say so in the app before it takes effect.
Contact
Questions, requests, or anything that looks wrong: khakontas33@gmail.com.