This Consumer Health Data Privacy Policy describes how Syed Khizer, an individual, trading as Functional Apps (“Primal,” “we,” “us,” or “our”), collects, uses, shares, and protects consumer health data through the Primal app and related services.
This notice is separate from and supplements the general Primal Privacy Policy. It is intended to provide the specific disclosures required by consumer-health privacy laws, including the Washington My Health My Data Act where applicable. It is published at https://quitpal-13e20.web.app/consumer-health-privacy and is also available in the app from Settings → Legal.
1. Consumer health data we collect
Depending on the features you choose, Primal may collect the following categories of consumer health data:
- information about pornography use, compulsive sexual behaviour, sexual wellbeing, perceived arousal, frequency, duration, escalation, and perceived control;
- onboarding assessment answers, calculated severity or reflection scores, reported symptoms, and inferences drawn from those answers;
- recovery goals, quit dates, streaks, progress, pledges, wins, setbacks, and relapse records;
- urge intensity, triggers, mood, stress, loneliness, sleep-related information, coping tools, blocker state, and outcomes;
- check-ins, optional notes, user-entered location labels, focus-session activity, and recovery-related achievements;
- messages and limited recent context that you choose to send to Leo, our AI coach, when those messages reveal health, sexual-behaviour, or recovery information;
- community content or safety reports that you choose to submit when they reveal health, sexual-behaviour, or recovery information;
- information inferred from the above categories for the purpose of providing your requested recovery features and personalising the app; and
- only if you allow Meta ad measurement where it is available in your version of the app, information showing that you use Primal—“app opened” events and whether you started a trial or subscribed, with the price—linked to your device's advertising identifier and other identifiers. Because Primal is a recovery app for compulsive pornography use, the fact that you use it, start a trial, or subscribe can reveal information about your health or sex life, so we treat this as consumer health data.
Primal does not currently collect information from Apple HealthKit, Health Connect, medical records, fitness trackers, GPS, or precise-location services. User-entered location labels are text you provide and are not device location readings.
2. Sources of consumer health data
We collect consumer health data:
- directly from you when you complete onboarding, record progress, complete a check-in, log an urge or relapse, make a pledge, write a note, use Leo, participate in the community, or contact support;
- automatically from your interactions with recovery features, such as calculated streaks, assessment results, task completion, and feature state;
- only if you allow Meta ad measurement, automatically from your device when you open Primal and, through Apple and RevenueCat, when you start a trial or subscription; and
- from another user only when they interact with or report content that you chose to publish in the community.
We do not purchase consumer health data from data brokers or obtain it from advertising networks, including Meta.
3. Why we collect and use consumer health data
We collect and use consumer health data only as reasonably necessary to:
- provide the self-help, tracking, progress, check-in, urge, relapse, pledge, blocking, community, and other recovery features you request;
- calculate and display your assessment results, streaks, progress, and insights;
- personalise requested recovery content and feature suggestions;
- generate a Leo response when you have enabled Leo AI in Settings → Privacy & data and send Leo a message;
- sync requested account and recovery information across supported devices;
- maintain safety, investigate reports, prevent fraud and abuse, and secure Primal;
- respond to your requests and provide support; and
- comply with law and establish, exercise, or defend legal claims.
With your separate consent, and only where the feature is available in your version of the app, we also use information showing that you use Primal, and whether you started a trial or subscribed, for Meta ad measurement: we share it with Meta to measure and optimise our advertising, such as which ads lead to installs, trials, and subscriptions. This is the only advertising-related use. Some US state privacy laws may treat it as “sharing” for cross-context behavioural advertising or as “targeted advertising”; you can opt out at any time (Section 5). We do not otherwise use consumer health data for advertising or cross-context behavioural advertising, and we do not use it for data-broker activity, employment, credit, housing, insurance, or other eligibility decisions. We do not sell consumer health data. Sensitive recovery information—your answers, symptoms, reasons, streaks, urges, relapses, journal, Leo conversations, and community content—is never sold, never used for advertising or profiling, never sent to Meta, and never shared with data brokers.
4. Consumer health data we share
“Share” may have a specific meaning under applicable consumer-health privacy laws. Depending on the feature, we may share the following categories:
- Account and synced recovery data: Firebase and Google Cloud (United States) process account, assessment, progress, check-in, urge, relapse, and feature-state information to provide authentication, storage, sync, server functions, security, and diagnostics.
- AI-coach data: only while the Leo AI toggle is on, the message you type, up to eight recent turns of that conversation, and a short recovery context (such as streak length) pass through Primal's Firebase Function to OpenRouter, which routes OpenAI GPT-OSS-120B to an eligible zero-data-retention inference host. Your name, email, account ID, and journal entries are never included. OpenAI is the model developer/licensor and is not represented as receiving prompts under the current third-party hosted route.
- DNS-filter information: the DNS filter feature currently runs in a limited mode that does not route your queries to any external DNS vendor. If an external provider is enabled we will name it here first.
- Advertising-measurement information (Meta): only with your consent, where Meta ad measurement is available in your version of the app. Meta Platforms, Inc. and its affiliates (United States) receive an “app opened” event each time you open Primal and your trial-started, trial-converted, purchase, and renewal events with the transaction amount, linked to your device's advertising and vendor identifiers, Meta's anonymous install identifier, your IP address, a one-way hashed form of your account identifier, and limited device and app information. The app sends the “app opened” events; RevenueCat, our subscription processor, sends the trial and subscription events on our instruction, including renewals while the app is closed. Meta uses this information to measure and optimise our advertising and applies its own terms and data policy to it. Meta never receives your answers, symptoms, streaks, urges, relapses, journal, Leo or community content, name, email, or phone number. Details are in Section 3.8 of the Primal Privacy Policy.
- Community information: other signed-in users receive the recovery-related information you deliberately publish with your generated handle, arena level, and streak days.
- Safety and legal information: professional advisers, child-safety organisations, law enforcement, courts, regulators, or other authorities may receive information reasonably necessary for a valid legal, safety, or claims purpose.
- Business transactions: a successor involved in a merger, financing, reorganisation, acquisition, bankruptcy, or asset transfer may receive information subject to applicable safeguards and consumer-health privacy obligations.
Firebase Crashlytics receives crash stack traces and device/app version information only, never journal text, chats, your name, or your email; crash reporting is always on and you may object by emailing admin@functionalapps.org. PostHog (EU) receives only allow-listed product-funnel events with a random identifier, and only while the Product analytics toggle is on; Primal does not send PostHog recovery answers, symptoms, urges, relapse information, notes, AI messages, community content, or any free text. RevenueCat receives App Store transaction identifiers and entitlement status and, only if you allow Meta ad measurement, the device identifiers it needs to send your trial and subscription events to Meta. Primal's app includes Meta's software development kit, but the kit is not started, and nothing is sent to Meta, unless you allow Meta ad measurement.
We have no affiliates.
5. Consent and withdrawal
Primal is for adults aged 18 or older. We do not verify identity or ask an in-app age question; by using Primal or creating an account you confirm that you are 18 or older. We do not ask you to tick a consent box. This notice and the Primal Privacy Policy are linked on the welcome, paywall, and account screens, and all three policies are available from Settings → Legal. Your consent to the collection and storage of your consumer health data is given by choosing to enter that information into the app after being shown this policy; we also process it to perform our contract with you by delivering the features you request. Sharing with AI providers requires a separate choice: the Leo AI toggle in Settings → Privacy & data, which is off by default. Product analytics is likewise a separate opt-in toggle and never receives consumer health data.
Sharing with Meta for ad measurement is a further separate choice, offered only where the feature is available in your version of the app. If iOS has not asked before, an optional onboarding screen shown once immediately before the paywall explains what Meta would learn and what is never shared, and its Continue button shows Apple's tracking prompt. We share with Meta only if you choose Allow in that prompt (or later turn on Meta ad measurement in Settings → Privacy & data with tracking allowed), and only while Apple's tracking permission for Primal remains Allow. Choosing Ask App Not to Track records that you declined. Declining never affects your access, your subscription, or any feature.
Each choice is stored as a versioned consent record (notice version 2026-09-05
for Leo AI and Product analytics, and 2026-09-24 for Meta ad measurement).
You may withdraw consent for future collection or sharing by deleting the relevant entries, by turning the relevant toggle off in Settings → Privacy & data, by deleting your account, or by emailing admin@functionalapps.org. To stop Meta ad measurement, turn off Meta ad measurement in Settings → Privacy & data or turn off tracking for Primal in iOS Settings → Privacy & Security → Tracking; Primal detects the iOS change the next time you open it or bring it to the foreground. If you can no longer use the app, email admin@functionalapps.org and we will ask RevenueCat to delete the identifiers it holds for your account, or delete your account, which deletes your RevenueCat record. When you withdraw in the app, it stops sending “app opened” events and asks RevenueCat to delete your device identifiers. RevenueCat does not send your trial and subscription events to Meta while iOS tracking permission for Primal is anything other than Allow, so turning off tracking in iOS Settings is the most complete way to stop future events; if you turn the switch off in Primal while iOS still allows tracking, Primal tells you this and links to iOS Settings. Withdrawal does not affect processing already performed, and Primal cannot delete information Meta has already received (see Section 7). If data is necessary for a feature you requested, withdrawal may disable that feature, but it will not remove paid access to unrelated features.
6. Your consumer health data rights
Depending on where you live, you may have the right to:
- confirm whether we collect, share, or sell your consumer health data;
- access the consumer health data we maintain about you;
- obtain a list of third parties or affiliates with whom your consumer health data has been shared where applicable;
- withdraw consent from future collection or sharing;
- opt out of the use of your data for targeted advertising or its “sharing” for cross-context behavioural advertising;
- request deletion from our systems and, where required, from processors or other recipients;
- receive a portable copy of information you provided;
- appeal our refusal of a request; and
- exercise these rights without unlawful discrimination.
The third parties with which we may share consumer health data are listed in Section 4. Meta Platforms receives consumer health data only if you allow Meta ad measurement, and you can withdraw that consent in the app at any time (Section 5).
Access and portability are available in the app: Settings → Privacy & data → Export my data produces a JSON file of all your local and server records. Deletion is available in the app: Settings → ACCOUNT → Delete my account opens the Privacy & data screen, where you tap Delete my account and choose Delete now or Delete after 24 hours. For any other request, email admin@functionalapps.org. We may verify your identity proportionately before acting. If we deny a request, you may appeal by replying to our decision with the subject “Consumer Health Data Appeal.” You may also contact the appropriate regulator or attorney general.
7. Deletion
An in-app account-deletion request runs immediately, or after a cancellable 24-hour grace period if you choose it. We then delete the consumer health data associated with the account from our active systems—private recovery records, consent records, community content you authored, votes and reactions you made, your public profile and handle, push tokens, and your Firebase Authentication account—and direct relevant processors (Apple, RevenueCat, and the DNS-filter vendor profile) to delete their records. Abuse reports and moderation records that reference you are anonymised rather than deleted and are kept for up to 24 months for safety, enforcement, and dispute resolution. The app also clears the account's local database, caches, preferences, consent records, Screen Time shields, and Keychain credential on the device.
If you allowed Meta ad measurement, deleting the RevenueCat record also removes the device identifiers held there for it. Primal cannot delete information that Meta has already received; Meta holds it under its own terms and policies. If you have a Meta account, you can review and manage activity that businesses share with Meta using Meta's own privacy tools, such as Your activity off Meta technologies in your Meta account settings.
Deletion from backups may occur on the applicable backup cycle, during which the information is isolated from ordinary use. Deleting Primal or your Primal account does not cancel an Apple subscription.
8. Retention
We retain consumer health data only for the period reasonably necessary for the requested feature and the security, safety, legal, and accounting purposes described above. In summary: private recovery records and consent records are kept for as long as your account exists; community content until you delete it or your account; anonymised moderation records for up to 24 months after anonymisation; Leo request operational metadata (no message text) for 30 days; crash reports for up to 90 days; and product analytics, if enabled, for up to 12 months. If you allowed Meta ad measurement, the device identifiers RevenueCat holds for it are kept until you withdraw or delete your account, and Meta keeps what it has received under its own terms. The full schedule is in the general Privacy Policy. Local journal entries and saved Leo history are designed to remain on your device until you delete them, delete the app, or remove the relevant device backup.
9. Security
We use administrative, technical, and organisational safeguards appropriate to the sensitivity and volume of consumer health data, including access controls, TLS, platform authentication, server-side authorisation rules, Firebase App Check, and restricted provider access. No system can guarantee absolute security. If a security incident affects your consumer health data, we will investigate, mitigate, and notify you and the relevant authorities where the law requires.
10. Changes to this notice
We will update the date above and provide additional notice or obtain consent before collecting, using, or sharing new categories of consumer health data or using existing consumer health data for materially different purposes where required.
11. Contact
Syed Khizer, an individual, trading as Functional Apps
Email: admin@functionalapps.org