stosmok app icon, a small dragonstosmok
Privacy policy

Your quit is your business

stosmok was built with no backend on purpose. This page explains exactly what that means, in plain language, and what little network traffic the app does make. Last updated 26 September 2026.

Health data collected?

Yes, computed and stored on your device.

Linked to your identity?

No. There is no account and no user database.

Used for tracking?

No. There is no advertising or analytics SDK.

This mirrors the App Store privacy nutrition label stosmok publishes at listing time: health data is collected, not linked to you, and not used for tracking.

There is no backend

stosmok has no server, no user accounts, and no remote database. Every calculation the app makes, your streak, your money saved, your dragon's health score, your health milestones, happens entirely on your device using data stored in a local database. Nobody at stosmok can see it, because it never leaves your phone.

We built it this way deliberately. A backend would mean an account system, a company holding your smoking history on a server somewhere, and an ongoing obligation to keep that service running and secure forever. None of that was necessary to make the app work, so none of it exists.

What does leave your device

Exactly two things, and neither carries your health data.

Store purchases

In-app purchases (the one-time lifetime unlock, and optional cosmetic dragon skins and themes) are handled by RevenueCat, which talks to Apple and Google directly to verify what you've bought. stosmok uses a random, anonymous app user ID, not an account. RevenueCat receives that ID, your purchase receipts and basic device details such as the app version and store country, and never your journal entries, cravings or streak data. Payment details stay with Apple or Google.

Crash reports

Optional crash reporting through Sentry. It is shown to you during setup, switched on by default, and you can turn it off there or in Settings at any time. When it is off, the crash reporting SDK never even starts. When it's on, it runs with personal data collection switched off (sendDefaultPii = false): no name, no identifiers, no IP address. Journal text, motivation cards, notes and photo paths are all scrubbed from crash breadcrumbs before anything is sent.

Your data, your control

Settings has a “Delete all my data” action that genuinely wipes the local database, the iCloud snapshot, and anything held in secure storage. There's no soft delete on our end to undo, because there's no server-side copy to begin with.

You can also export a copy of your data at any time as a single .stosmok file, for your own backup or to move between an iPhone and an Android phone. See the guide for how that works.

stosmok does not sell data, because there is no data to sell beyond what sits on your own device. There is no advertising network, no analytics SDK beyond the crash reporter described above, and no third party with standing access to anything you write in the app.

Questions

If anything here is unclear, write to bubs@viveclub.com.au.