Privacy Policy
Effective date: July 28, 2026 · Controller: Pleasant Park LLC · Contact: tryclearpuff@gmail.com
Prefer plain language? The summary page says the same things shorter. This document is the precise version.
1. What we collect, and why
- Account data — email address, password (hashed by our authentication provider; we never see it), first and last name, optional phone number. Purpose: sign-in, account recovery, receipts.
- Health-related data — your assessment answers (product, usage, strength, spend, triggers, symptoms, lifestyle, prior attempts), quit date and approach, daily check-ins (mood, craving level, whether you vaped, optional notes), and craving logs. Purpose: operating your plan and showing you your own progress. Collected only after your explicit, standalone consent during onboarding.
- Billing data — subscription status, plan, and billing period, plus identifiers from our payment processor. We never see or store your card number.
We do not collect advertising identifiers, run third-party analytics trackers, or embed social pixels. We do not sell personal data, and we do not share it with advertisers or data brokers.
2. Lawful basis
Health-related data: your consent, given separately during onboarding and withdrawable at any time by deleting your data. Account and billing data: performance of the contract. Where GDPR applies, those are the Article 6 bases; consent is also the Article 9 basis for health-related data.
3. Service providers (processors)
Running the Service necessarily involves infrastructure providers acting on our instructions:
- Stripe — payment processing. Your card details go directly to Stripe; we receive only subscription status and identifiers.
- Supabase — database and authentication hosting. Your profile, check-ins and craving logs live here, protected by row-level security.
- Vercel — application hosting and delivery.
- Resend — transactional email delivery (verification codes, password resets, and reminder emails if you leave them on).
These providers process data to provide their service to us, not for their own marketing. No provider on this list is an advertising or analytics company.
4. Retention
- Health-related data: kept until you delete it. Deletion is immediate and permanent — no archive, no soft delete.
- Account data: kept until account deletion.
- Billing records: our processor and we retain transaction records as required for tax and accounting law, typically 7 years. These contain payment facts, not your health-related data.
5. Your rights
Regardless of where you live, you can: see what we hold about you (your plan, logs and check-ins are all visible in the app; ask us for an export), correct it (editable in the app), and delete it permanently (Settings → Delete my account, which also cancels billing). We honour the rights granted by the Washington My Health My Data Act and Nevada SB 370 for all users, not just residents of those states. Where GDPR applies, the same mechanisms exercise your rights of access and erasure; you also have the right to lodge a complaint with your supervisory authority.
6. Children
The Service is not directed at children under 13, and the onboarding age question stops the flow before any data is collected. Users aged 13–17 are directed to free, age-appropriate quitting resources rather than a paid subscription.
7. Security
Data in transit is encrypted (TLS). Database access is scoped per-user with row-level security. Payments never touch our servers. No system is perfectly secure; if a breach affects your data we will notify you as the law requires.
8. Changes
Material changes will be announced by email before they take effect, with the new effective date at the top of this page.