“Stop Drinking Alcohol: Freedom”

Privacy Policy

Privacy Policy — “Stop Drinking Alcohol: Freedom” Last updated: 5 October 2026 Who we are SK LABS SP Z O O is the controller of personal information for the “Stop Drinking Alcohol: Freedom” app, also shown as “Freedom” or a translated name on your device. ul. Juliusza Słowackiego 24/105, 35-060 Rzeszów, Poland KRS 0000616904 · NIP 5170375109 · REGON 364391903 [email protected] · +48 796 508 231 This policy covers the app, its connected account services and our related support. The service is intended for adults. It provides self-help and wellbeing tools, not medical or emergency care. What stays on your device The app stores your full onboarding answer set, written programme-exercise answers and notes, unfinished drafts and Support exercise-completion counters locally. It also keeps local copies of account information, health/progress records, settings and pending changes, plus sign-in credentials and temporary audio files. Selected onboarding information does reach our server when you activate and use your account: your goal, starting/last-alcohol time, time zone and drinking quantities used for spending calculations. The complete questionnaire is not uploaded as one record. What our services store • Account: email, optional name, Apple/Google sign-in identifiers and verification information, language, login/session records, IP address and approximate country. Apple may provide a relay email address. We do not ask you to create a password for the “Stop Drinking Alcohol: Freedom” app. • Alcohol, health and progress: dated drinking/alcohol-free entries, spending information, goals, programme and lesson completion, wellbeing observations, PHQ-4 answers/results and their dates/version/language, savings goals, mission plans/notes/outcomes and achievements. • Features you choose: community activity, mentor text/audio, scheduled letters, purchases, support correspondence and notification preferences, as explained below. Alcohol and wellbeing answers can be sensitive health information even without a diagnosis. We do not obtain data from HealthKit or Health Connect, use GPS, or read your contacts. Recovery timelines and savings are calculations, not medical measurements. Required account information enables sign-in and paid access; optional entries enable the corresponding feature. Withholding them may limit that feature. Community, country and anonymity Community stores your nickname, avatar, optional bio, posts/replies, reactions, saved/hidden threads, blocks, reports, appeals, moderation and rule-acceptance records. Other members can see your contributions, a broad stage of your alcohol-related journey and, where enabled, your profile and achievements. Achievement visibility starts enabled on new profiles and can be turned off. An anonymous contribution remains linked to your account for SK LABS and moderation. Your broad stage may still appear, and you may be recognisable within a thread or from what you write. Members may copy or capture what they see. Do not include another person's private details. Cloudflare derives approximate country from your connection IP. We use country for regional content, reference drink prices, community discovery and service records. You can choose a community country. Country filtering does not restrict who can access a contribution; historical posts keep their original country. Language selection is separate from country and store prices. Mentors and voice messages Mentor chat is a private, account-linked conversation accessible to authorised support staff, not an anonymous service or an AI chatbot. We store sent messages/recordings and sending/read times. Your voice and message contents can identify you. Before first sending under a version of the chat terms, the app records your acceptance, the displayed terms, version and language. The option to attach programme/goal/completion context starts selected and can be cleared. Separately, the staff conversation view can show your recorded last-alcohol time. Microphone permission allows recording. You can preview or discard audio before sending. Sent recordings are converted and stored on our server for playback, without AI transcription in the current service. Deleting your own message removes its text, attachment and stored audio; a record that the message existed may remain. It cannot undo previous reading or listening. Letters and contact A letter to your future self stays local until scheduled. Scheduling sends its title, text, verified account email, delivery time/time zone and delivery status to our server. Delivery passes the contents through email providers. Cancelling delivery and deleting a letter are separate actions; an already delivered email cannot be recalled by deleting it in the app. Contact us sends your message, category, language, account identifier and verified email to our support mailbox. The app database keeps delivery/status information to prevent duplicates, not a separate message-body copy. Correspondence remains in email. Direct email or telephone contact gives us the information you provide through that channel. Payments and notifications Apple or Google processes subscription payments. We receive purchase/transaction identifiers, verification data, products/plans, status and relevant dates to verify access, restore purchases, manage refunds and prevent fraud. We do not receive your full payment-card number. Enabled notifications use Google Firebase Cloud Messaging and Apple Push Notification service on iOS. We keep delivery tokens, an app-generated device identifier, platform, language, permission status, reminder times/time zone and any reminder text you enter. Providers receive routing information and the notification payload. Your reminder text or alcohol-free day count may appear on a lock screen. Change preferences in the app or revoke permission in device settings. Activity measurement When analytics is enabled, the app sends our API screen/action events, times, random installation/session/event identifiers, app/OS versions, phone language and content/offer identifiers; offer events can include price, currency and trial details. The server records IP and approximate country. Events exclude questionnaire answers, health scores, selected drinking status, message contents, recordings and free-text notes. These records are pseudonymous: login can link an installation's activity to your account. Events can also reveal use of a health-related feature. Analytics is enabled by default. You can turn it off in My account → Analytics and app improvement. This choice is saved on your device and remains in effect after restarting the app or signing out. Turning analytics off stops new analytics collection and requests and discards unsent events; it does not delete data already sent, which follows the retention rules below. Requests needed for account access, purchases and other app features continue. It uses no advertising SDK, Firebase Analytics or Crashlytics for this measurement. We do not sell your information or use health entries for targeted advertising. Purposes and legal grounds We use ordinary account/service/purchase information to provide requested features and perform our agreement (Article 6(1)(b) GDPR); relevant records to meet legal duties (Article 6(1)(c)); and necessary information for account security, fraud prevention, moderation, enquiries, troubleshooting and service evaluation in our legitimate interests (Article 6(1)(f)). You may object to processing based on legitimate interests. Before you create an account or sign in, we ask you to actively select an initially unticked checkbox accepting the Terms of Use and Privacy Policy and explicitly consenting to the processing of your health and alcohol-use data for statistics and account synchronisation. The sign-in buttons remain disabled until you select it. After successful sign-in, we record the statement, its version and language, and the acceptance time. For the health-data processing described in that statement, we request explicit consent under Article 9(2)(a) GDPR. You can withdraw consent by contacting [email protected]; withdrawal does not affect earlier lawful processing. Where consent is a valid basis, you may withdraw it without affecting earlier lawful processing. Information strictly necessary for legal claims may be processed under Article 6(1)(f) and, where applicable, Article 9(2)(f); this is not a basis for keeping every health record indefinitely. Personalisation uses rules/calculations, not solely automated decisions with legal or similarly significant effects. Who can receive data and where SK LABS administers the service. Authorised people handling support, moderation and operations may access information needed for their work. Community members receive what you make visible; email recipients and their providers receive delivered messages. Competent authorities may receive information where legally required. Our application server/database is in the EU. Implemented providers include OVH hosting, Cloudflare network/proxy services, Amazon Simple Email Service for outgoing email (Frankfurt endpoint), Google Firebase messaging, Google Cloud Pub/Sub for purchase-status notifications, and Apple/Google sign-in, stores and Apple push delivery. Their consumer accounts and stores are also covered by their own privacy policies. Mentor messages are not sent to an AI provider in the current implementation. These providers and their subprocessors may process personal data outside the European Economic Area, including in the United States. Cloudflare's Data Processing Addendum, Firebase's Data Processing and Security Terms, Google Cloud's Cloud Data Processing Addendum and AWS's data-processing terms govern the corresponding services we use. Transfers to US recipients covered by the EU–US Data Privacy Framework rely on the European Commission's adequacy decision for that framework. Where that framework or another adequacy decision does not cover a transfer, the applicable provider terms provide for European Commission Standard Contractual Clauses (SCCs), together with the technical and organisational safeguards described in those terms. Apple and Google also process certain sign-in and app-store data as independent controllers under their own privacy policies. Apple states that international transfers of personal data collected in the EEA are governed by SCCs. Contact [email protected] for information about the recipients, processing locations and safeguards relevant to your data, including how to obtain a copy of the applicable safeguards. Retention and deletion Account and feature history is kept for the corresponding account service until you delete the information or request account deletion, subject to the process and limited exceptions below. Telemetry events and technical session records, including their recorded IP addresses, are automatically deleted by a daily scheduled task once they are older than 12 calendar months from server receipt. Deletion takes place at the first daily run after that threshold; related records may be deleted earlier. Installation identifiers are deleted after 12 calendar months without analytics contact. Turning analytics off stops new collection; existing records follow these deletion rules. Routine access, error and application logs on servers we operate are automatically removed within 30 days. These technical logs may contain IP addresses and are not described as anonymous. This limit does not apply to the separate telemetry or account-security records described here. Cloudflare maintains separate traffic and security records under its own service- and dataset-specific retention rules; its dashboard query range is not a maximum storage period. For account security, we record the IP address of the latest successful sign-in and each sign-in session. Session records are removed when they expire or are deleted; the latest sign-in IP is removed with the account. We do not keep a permanent account-creation IP archive. Any limited security or transaction evidence retained for a specific legal obligation, fraud investigation or claim must have a documented reason and review or expiry date. Resolved moderation evidence/cases and reply-notification records have scheduled cleanup; unresolved cases remain for review. Support correspondence is retained for handling the request and any necessary related claim, with retention limited to that purpose. Account-deletion review separately records the handling of providers, backups and justified retained evidence, including the applicable review or expiry date. A backup is not a reason to restore erased information to active use. In-app deletion immediately disables access, revokes sessions/notification registrations, removes visible community content and cancels pending letters. Remaining data is covered by our daily manual deletion review after verification. This includes health/alcohol history, assessments, programme/progress, mentor messages/audio, letters and identifiable account-linked activity. Only justified minimum transaction/security evidence may be retained for a legal or fraud-prevention reason; we explain any exception and its applicable retention to you. Signing out leaves some local information. Account deletion cannot remotely erase every offline device, secure-storage item, operating-system backup or email already received by someone else. Provider records, correspondence, logs and backups have separate lifecycles. Deleting the app/account does not cancel a store subscription; cancel it separately through Apple or Google. Subscription cancellation is not required to request data deletion. Your rights Under GDPR conditions, you may request access/copies, correction, erasure, restriction, portability, object to legitimate-interest processing and withdraw consent where used. Email [email protected] for all or selected data, including without access to the app: https://apps-api.central-1.pl/stop-drinking/delete-account We verify ownership; contact us for another method if you cannot use your account email or use an Apple relay address. Do not send passwords or sign-in codes. We normally respond within one month; a justified extension of up to two further months will be explained within the first month. You may complain to the President of Poland's Personal Data Protection Office (Prezes UODO), https://uodo.gov.pl, or the competent authority where you live, work or believe an infringement occurred. You need not contact us first. Protection and updates Production connections use HTTPS; authenticated access separates private account services from public content, and mentor audio uses private server storage. This is not a promise of end-to-end encryption or that authorised staff cannot access records. Protect your device and email access. We update this policy when processing changes and show the update date. Publishing a new policy does not replace a separate notice or consent where required.