QuitCo — Legal

QuitCo Privacy Policy

Last updated: July 23, 2026

Effective date: July 23, 2026

QuitCo (“QuitCo”, “the app”, “we”, “us”, “our”) is a caffeine-reduction (taper) app for iPhone. This Privacy Policy explains what information the app handles, where it is stored, who (if anyone) it is shared with, and the rights you have over it.

The short version, and the design principle behind the whole app:

Your personal and health information stays on your device. QuitCo has no user accounts and runs no server of its own. Your name, quiz answers, caffeine logs, check-ins, and taper plan are stored locally on your iPhone and are never uploaded to us.

Please read the full policy below for the details, including the limited third parties involved in purchases and (optionally) analytics.

1. Who we are (Data Controller)

The party responsible for the app and this policy — the “data controller” under the GDPR and the “veri sorumlusu” under Turkey's KVKK — is:

  • Controller: FGY Limited Şirketi (trading as “FGY Software”)
  • Address: Söğütözü Mah. Söğütözü Cad. No: 2C/17 Çankaya/Ankara, Türkiye
  • Contact for privacy matters: hasan@fgysoftware.com
  • App bundle identifier: com.fgysoftware.quitco
  • EU/UK representative (Art. 27 GDPR): We have not appointed an EU/UK representative at this time.

If you have any question about this policy or wish to exercise your rights, contact us at the email above.

2. Our privacy model in one picture

CategoryWhere it livesLeaves your device?
Name, quiz answers, taper plan, caffeine logs, check-insOn your iPhone (local database)No — never sent to us
Apple Health data (resting heart rate, sleep)Read on-device onlyNo — never sent to us or any third party
Purchases / subscriptionsApple App Store + RevenueCatYes — to those processors only
Analytics only (Firebase/GA4, if enabled)Third-party SDKOnly if enabled; no cross-app tracking, no ATT prompt
Marketing attribution / IDFA tracking (optional, see §6)Third-party SDKsOnly if enabled and you allow it via Apple's ATT prompt
NotificationsScheduled locally on your deviceNo — we run no push server

3. Information the app handles and where it is stored

3.1 Data that stays on your device (we never receive it)

QuitCo does not have accounts and does not operate its own backend server. The following information is created and stored locally on your iPhone in the app's on-device database (Apple's SwiftData/Core Data). We — FGY Limited Şirketi — do not receive, see, or store any of it:

  • Your name (or nickname), as entered during onboarding.
  • Onboarding quiz answers — your responses about caffeine habits, goals, and symptoms.
  • Your taper plan — the daily caffeine-reduction schedule generated for you.
  • Caffeine logs — the drinks/amounts you record.
  • Check-ins — cravings, mood, and daily status entries.
  • Progress and in-app rewards (e.g. streaks, garden/milestone state).
  • App preferences and settings.

To show your progress on the home-screen widget and Lock Screen Live Activity, the app writes a small summary snapshot into a shared app group on the same device; this stays on your device and is not transmitted off it.

This data may be included in your encrypted device backup (iCloud or a computer backup) that you control through Apple. That backup mechanism belongs to Apple and is governed by Apple's terms and privacy policy; it is not a transfer of data to us.

You can erase all of this data at any time by deleting the app from your device.

3.2 Apple Health (HealthKit) data — read-only, on-device only

If — and only if — you explicitly grant permission, QuitCo reads two signals from Apple Health to show you two optional insight cards (heart rate and sleep trends during your taper):

  • Resting heart rate
  • Sleep analysis (including deep sleep)

How we handle it:

  • Access is read-only. QuitCo never writes to Apple Health.
  • The data is processed entirely on your device to compute the two trend numbers shown in the app.
  • We never transmit HealthKit data off your device — not to us, and never to any third party, advertising network, or analytics/attribution service. This is both an Apple platform requirement and our own commitment.
  • You can grant or revoke this permission at any time in iOS Settings → Privacy & Security → Health → QuitCo, or within Apple Health. If you deny it, the app simply shows a “Connect Apple Health” prompt instead of the numbers; nothing else changes.

Apple Health data is special-category / sensitive data (see §8). Because it never leaves your device, there is no transfer of this sensitive data to us or to anyone else.

3.3 Purchases and subscriptions

QuitCo offers optional premium subscriptions. Purchases are handled by Apple's App Store and processed through RevenueCat, Inc., which acts as our payments/subscription infrastructure processor. In connection with a purchase or restore:

  • Apple processes your payment. We never receive your full payment card details.
  • RevenueCat receives a pseudonymous app user identifier (not your name or email) and your purchase/subscription history and status, so the app can unlock and validate premium features and restore purchases across your devices.

We use this information only to provide and manage subscriptions. See §6/§7 for the processor list.

3.4 Notifications

QuitCo uses local notifications only (reminders and check-in nudges scheduled on your device). We do not operate a push-notification server and do not collect a device push token for our own servers. You can turn notifications off in iOS Settings at any time.

3.5 Analytics and attribution (optional — see §6)

When enabled for a public release, QuitCo may use third-party analytics and marketing-attribution SDKs to understand aggregate usage of certain flows (for example, how many people reach the paywall, purchase, or continue on the free plan). This is described in detail in §6, including the fact that advertising identifier (IDFA)-based tracking happens only if you allow it through Apple's App Tracking Transparency prompt.

4. Why we process data and the legal basis (GDPR Art. 6)

Under the EU/UK GDPR we must have a lawful basis for each purpose. Because most data never reaches us, the table below focuses on the limited processing that actually involves us or our processors.

PurposeData involvedLegal basis (GDPR Art. 6)
Run the app's core features (plan, logs, check-ins, insights) locally on your deviceOn-device data (§3.1); optionally Health data (§3.2)Processing occurs on your device under your control; to the extent it involves us, performance of the app you requested (Art. 6(1)(b)). Health-data access relies on your explicit consent (Art. 9(2)(a)) — see §8.
Sell and manage subscriptions; restore purchasesPseudonymous app user id, purchase history (§3.3)Performance of a contract (Art. 6(1)(b))
Prevent fraud, ensure app security and integrityPurchase validation dataLegitimate interests (Art. 6(1)(f))
Product analytics — understand aggregate usage and improve the appUsage/interaction events, app-instance identifier (§6)Consent (Art. 6(1)(a)) where the analytics SDK requires it; otherwise legitimate interests (Art. 6(1)(f)) for non-tracking, aggregate analytics
Marketing attribution & advertising measurement (IDFA-based)Advertising identifier (IDFA), attribution/event data (§6)Consent (Art. 6(1)(a)), given via Apple's App Tracking Transparency prompt. No IDFA-based tracking occurs without it.
Send local reminders/notificationsOn-device schedule onlyPerformance of the app you requested (Art. 6(1)(b)) and your device-level notification permission
Comply with legal obligationsAs requiredLegal obligation (Art. 6(1)(c))

Where we rely on consent, you may withdraw it at any time (see §9 and §11) without affecting the lawfulness of processing before withdrawal.

5. No automated decision-making

QuitCo does not carry out automated decision-making that produces legal or similarly significant effects about you within the meaning of Art. 22 GDPR. Your taper plan is generated algorithmically on your device from the answers you provide, to help you follow a reduction schedule; it does not make decisions that legally or significantly affect you, and there is no profiling for such purposes.

6. Third-party SDKs, processors and recipients

We keep third parties to the minimum. No third party ever receives your Apple Health data.

6.1 Platform and purchases

RecipientRoleWhat it receivesPurpose
Apple (App Store, iOS, HealthKit backup)Platform / paymentPayment and subscription transaction data; device backups you controlApp distribution, payments, OS services
RevenueCat, Inc.Processor (subscriptions) — active once purchases go livePseudonymous app user id; purchase/subscription history & statusUnlock, validate, and restore subscriptions

RevenueCat is configuration-gated: until in-app purchases are switched on for a public release, no data is sent to it and purchases run through Apple's on-device StoreKit only.

6.2 Analytics & attribution — active only when configured for a public release, and (for tracking) only with your ATT consent

For a public release we may enable the following SDKs to measure aggregate funnel events and marketing effectiveness. Each is independently switchable; when a given integration is not configured, it collects nothing.

RecipientRoleTypical dataTracking (IDFA)?
Google (Firebase / Google Analytics 4)AnalyticsApp-instance identifier, in-app event names, basic diagnosticsDoes not require IDFA; no cross-app tracking by us
Meta Platforms, Inc.Attribution / analyticsApp events, advertising identifier (if permitted)Yes — only with ATT consent
Adjust GmbHAttributionInstall/session and selected events, advertising identifier (if permitted)Yes — only with ATT consent
TikTok / ByteDanceAttribution / analyticsApp events, advertising identifier (if permitted)Yes — only with ATT consent

App Tracking Transparency (ATT). The advertising identifier (IDFA) and any cross-app/website tracking are used only if you tap “Allow” on Apple's tracking prompt. The prompt appears only when an IDFA-based adapter (Meta, Adjust, or TikTok) is active. If you choose “Ask App Not to Track” (or never allow it), no IDFA-based tracking takes place. You can change this at any time in iOS Settings → Privacy & Security → Tracking, and turning it off withdraws consent for that tracking going forward.

Non-tracking analytics (Firebase / GA4). If only Firebase/GA4 is enabled, no ATT prompt is shown because this analytics does not use the IDFA and does not track you across other apps or websites. We rely on our legitimate interest (Art. 6(1)(f)) in understanding aggregate usage to improve the app. This processing does not currently have a separate in-app opt-out toggle; you can object to it under Art. 21 (see §9) by contacting us, and you can prevent all analytics by not installing or by deleting the app. We use only privacy-preserving, aggregate event data here — never your Health data, caffeine logs, or check-ins.

The analytics events are about aggregate usage of app flows (e.g. paywall viewed, purchase started/completed, continued on free plan). They do not include your Health data, and they do not include your caffeine logs, check-ins, or the contents of your plan.

We may also share this Policy and disclose data where required by law, to enforce our terms, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will require the recipient to honour this Policy.

7. International data transfers

We are established in Türkiye. Some processors above (e.g. Apple, RevenueCat, Google, Meta, Adjust, TikTok) are based in, or process data in, the United States and other countries outside the EEA/UK/Turkey.

Where personal data is transferred outside the EEA/UK, we rely on an appropriate safeguard under GDPR Chapter V, namely:

  • the EU-US Data Privacy Framework (and the UK Extension / Swiss-US DPF) where the recipient is certified; and/or
  • the European Commission's Standard Contractual Clauses (SCCs) (and the UK IDTA/Addendum), with supplementary measures where appropriate.

For transfers from Turkey, see §12 (KVKK Art. 9). You may request a copy of the relevant safeguard by contacting us.

Reminder: your Apple Health data and your on-device app data (name, logs, check-ins, plan) are not transferred internationally by us, because they never leave your device.

8. Sensitive / special-category data

Some information the app works with — Apple Health signals (resting heart rate, sleep) and information related to caffeine consumption and wellbeing — may qualify as special-category (health) data under GDPR Art. 9 and special-nature personal data under KVKK Art. 6.

  • Health data from Apple Health is processed only on your device, only with your explicit consent (GDPR Art. 9(2)(a) / KVKK Art. 6), and is never transferred to us or to any third party. Because there is no transfer, there is no onward sharing of this sensitive data.
  • Your on-device caffeine logs and check-ins likewise stay on your device and are not transmitted to us.

You can withdraw Health consent at any time in iOS Settings (see §3.2).

9. Your rights (GDPR Art. 15–21)

Subject to the conditions in applicable law, you have the right to:

  • Access — obtain confirmation of, and a copy of, personal data we process about you (Art. 15).
  • Rectification — have inaccurate data corrected (Art. 16).
  • Erasure (“right to be forgotten”) — have data deleted (Art. 17).
  • Restriction — limit our processing in certain cases (Art. 18).
  • Data portability — receive certain data in a portable format (Art. 20).
  • Object — object to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
  • Withdraw consent — where processing is based on consent (e.g. Health access, tracking), withdraw it at any time, without affecting prior processing.

Because most of your data lives only on your device and is not accessible to us, you can exercise several of these rights directly: view and edit your entries in the app, revoke Health/tracking/notification permissions in iOS Settings, and delete all local data by deleting the app.

For data held by us or our processors (e.g. subscription records), contact us at hasan@fgysoftware.com. We will respond within the timeframe required by applicable law (generally one month under the GDPR).

Complaints. If you believe we have infringed your rights, you may lodge a complaint with your local supervisory authority. In the EU this is your national Data Protection Authority; in the UK, the Information Commissioner's Office (ICO); in Turkey, the Personal Data Protection Authority (KVKK — Kişisel Verileri Koruma Kurumu). We would appreciate the chance to address your concerns first.

10. Data retention

  • On-device data (name, quiz answers, plan, logs, check-ins) is retained on your device until you delete it or delete the app. We set no server-side retention because we never receive it.
  • Subscription data held by Apple/RevenueCat is retained per their policies and as needed to provide and account for the subscription, and to meet legal/tax obligations.
  • Analytics/attribution data (when enabled) is retained no longer than each provider's maximum documented retention, and we configure it to the minimum reasonably necessary. For reference, Google Analytics 4 event-level user data is capped at a maximum of 14 months (we select the shortest available setting); Meta, Adjust, and TikTok retain attribution/event data per the maximum periods stated in their own documentation. Aggregate, non-identifying reports may be kept longer.

11. Children's privacy

QuitCo is not directed at children. Because it concerns caffeine reduction and health-related content, it is intended for users aged 18 and over. We do not knowingly collect personal data from minors. If you believe a child has provided data through the app, contact us and we will address it.

12. Turkey — KVKK notice (Law No. 6698)

This section supplements the policy for users in Turkey and serves as the summary of the matters an “Aydınlatma Metni” must cover under Article 10 of the KVKK. A dedicated Turkish-language clarification text can be prepared from this section if and when required.

  • Data controller (veri sorumlusu): FGY Limited Şirketi — see §1.
  • Processing conditions (KVKK Art. 5/6): we process personal data based on the performance of a contract, our legitimate interests (including non-tracking Firebase/GA4 analytics), and — for Health data and for IDFA-based tracking/attribution — your explicit consent (açık rıza). Special-nature (health) data is processed only with explicit consent and, as described above, only on your device.
  • Cross-border transfer (KVKK Art. 9): transfers to processors abroad (§7) are made under the mechanisms in Art. 9 as amended (an adequacy decision where available; otherwise appropriate safeguards such as standard contracts or binding corporate rules). IDFA-based tracking additionally requires your explicit consent via ATT — without it, that tracking and its transfer do not occur. Non-tracking analytics does not depend on consent.
  • Your rights (KVKK Art. 11) and how to apply: see the Turkish clarification text for the full list and the formal application procedure to the data controller.

13. California — CCPA/CPRA notice

If you are a California resident:

  • We do not sell your personal information for money.
  • “Sharing” for cross-context behavioural advertising: the optional attribution/advertising SDKs described in §6 could be considered “sharing” under the CPRA. This only happens if you allow tracking via Apple's ATT prompt.
  • Your opt-out: to opt out of this “sharing”, choose “Ask App Not to Track” at the ATT prompt, or turn tracking off in iOS Settings → Privacy & Security → Tracking. You may also contact us at hasan@fgysoftware.com.
  • Your rights: California residents have rights to know, delete, correct, and to non-discrimination for exercising these rights. Contact us to exercise them.

We do not knowingly sell or share the personal information of consumers under 16.

14. Security

We rely on Apple's on-device protections (device encryption, app sandboxing, and the Health data protections) for data stored locally, and on our processors' security measures for the limited data they handle. No method of storage or transmission is completely secure, but because we minimise the data that ever leaves your device, we minimise the associated risk.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the “Effective date” above and, where appropriate, provide an in-app or App Store notice. Continued use of the app after an update constitutes acceptance of the revised policy where permitted by law.

16. Contact us

Questions, requests, or complaints:

  • FGY Limited Şirketi (FGY Software)
  • Söğütözü Mah. Söğütözü Cad. No: 2C/17 Çankaya/Ankara, Türkiye
  • hasan@fgysoftware.com