Privacy Policy
Version 1.2 · Effective July 7, 2026 · Updated August 6, 2026
UrgeLock is built privacy-first. Recovery is deeply personal, and the data behind it, including urges, relapses, moods, goals, and private reflections, can be highly sensitive. We designed UrgeLock to keep your core recovery data on your device by default, to work without requiring a personal account, and to share the minimum amount of data needed to provide optional features.
This Privacy Policy explains what information we handle, what stays on your device, what may leave your device, how we use third-party services, and what choices and rights you have.
In this policy, "UrgeLock," "we," "us," and "our" refer to A.A Group, the operator of the UrgeLock app and website. You can contact us at support@urgelock.app.
What stays on your device on device
The heart of your recovery data never leaves your device. Your journal, your voice notes, your urge log, your relapse history, your mood check-ins, and your date of birth are not sent anywhere. We do not receive them, we cannot read them, and there is no copy of them on our servers. The sensitive parts are also encrypted on the device itself, which is explained under "How we protect your data" below.
This data is stored using your operating system's standard app storage. If you delete the app, it is removed with it, unless your device or operating system separately backs up app data.
This may include:
- Your streak start date, current streak, best streak, daily pledges, and relapse history;
- Your urge log and any triggers you tag;
- Mood check-ins and notes you write;
- Your recovery goals, symptoms you recognize in yourself, and lesson progress;
- Your profile details, such as name or nickname, age or date of birth, and selected avatar;
- Your conversation history with the AI guide, unless you choose to send a message to the AI service;
- Music listening time, content-blocker settings, personal block list, and notification preferences;
- Voice notes you record in the journal, saved as audio files in the app's own storage;
- A record of the consents you gave, covering this policy, the terms, and the clinical disclaimer.
There is one exception on this list, and we want to name it plainly rather than hide it. If you choose to chat with the AI guide, your first name or nickname and a few numbers, such as your current streak and today's mood, are sent along with your message so the reply makes sense. The "AI guide" section below lists exactly what those are. Nothing else on this list is ever sent, whether you use the AI guide or not.
What may leave your device off device
Some features cannot work without sending limited information to outside services. When data leaves your device, we explain what is sent, why it is sent, and which third-party service is involved.
Most of these flows only happen if you choose to use the feature: the AI guide, the community, and the content blocker.
A few run automatically when the app starts, before you do anything:
- Anonymous sign-in: the app signs in to Google Firebase using an anonymous account so the community, the AI guide, and deletion requests can work. No email address, phone number, or password is involved, and the account is not tied to your identity;
- Device attestation: the app asks Apple or Google to confirm that this really is a genuine, unmodified copy of UrgeLock, so our servers can turn away abuse and automated attacks;
- Subscription check: RevenueCat is started up so the app knows whether you have an active subscription;
- Error reporting: see "Crash diagnostics and error reporting" below.
None of these send your recovery data. They send technical and account-level information only.
AI guide
If you choose to chat with the in-app AI guide, your message is sent to OpenAI's API so it can generate a response.
To make replies more relevant, we may include limited context, such as:
- Your first name or nickname, if you set one;
- Your current streak day;
- Your best streak;
- Today's mood;
- How long it has been since your last urge or relapse;
- A short summary of your current recovery context.
Using the AI guide is optional. The rest of UrgeLock works without it, including the streak and daily pledge, the panic button, breathing, urge and relapse logging, the journal, music, insights, achievements, and the content blocker. If you never open a chat, nothing from a chat is sent to OpenAI.
There is no separate approval step at the moment you send your first message. You accept this Privacy Policy during onboarding, before the app opens, and this section is how we tell you that anything you type into the AI guide, plus the limited context listed above, is transmitted to OpenAI to generate a reply.
Your message and the reply are both checked by OpenAI's automated safety screening before you see the reply. That screening runs at OpenAI, on the same account, and it is part of the same flow described here.
AI messages are processed by OpenAI according to the OpenAI API terms, data-processing rules, and retention settings that apply to our account. We ask OpenAI not to keep the conversation, and OpenAI states that data sent through its API is not used to train its models unless an account chooses to share it, which we have not. OpenAI may still keep prompts and replies for a limited period so it can monitor for misuse, currently up to 30 days. We do not use your AI chats for advertising, we do not sell them, and we do not use them to build a marketing profile about you.
Please avoid sharing information in the AI chat that you would not want processed by a third-party AI provider.
Community
The community is optional, and it has two parts: a wall you post reflections to, and a live chat room. Both send what you write to our community backend, hosted through Google Firebase, so that other members can read it.
The community is pseudonymous, not fully anonymous. We do not require your real name, email address, or phone number. You pick a handle and an avatar, and those are shown next to everything you post. Your content also carries a token derived from your anonymous account ID. That token cannot be turned back into the account it came from. It is what lets the app recognize your own posts and lets us moderate content and honour deletion requests.
The wall. A reflection, comment, or reaction you post is stored on our community backend. Every reflection is checked automatically before it is stored. The text goes through our own server-side filters, and it is also sent to OpenAI's API to be classified for harmful content. A post that is flagged is hidden until a moderator reviews it. Comments and reactions go through the server-side filters only, and are not sent to OpenAI.
Live chat. Messages you send in the chat room leave your device and are stored on our community backend, so that everyone in the room can read them. A stored message holds the text you wrote, your handle, your avatar choice, the time, and the token described above. Messages are set to expire 72 hours after they are sent, and the app does not show a message older than that. Chat messages are not sent to OpenAI. They are checked by an automatic filter that runs on our own server, and a message that fails is refused on the spot and never stored.
Who is in the room. While the chat screen is open and the app is on screen, the app sends a short signal to our servers about every 30 seconds so other members can see who is present. It contains your handle, your avatar choice, and the time. It contains nothing you wrote. It expires shortly after you leave the room, close the app, or switch away from it.
Anything you write in the community can be read by other members, and a chat message is visible to the room as soon as it is sent. Please do not post anything there you would not want other people to see, and do not post contact details or anything that identifies you.
Community content may also be reviewed after it appears. Users may report content, block users, or contact us about safety concerns.
If you never use the community, none of your post or message content is stored on our servers.
Subscriptions and purchases
If you purchase a subscription, payment is processed by the Apple App Store or Google Play. Subscription status is verified through RevenueCat.
Apple, Google, and RevenueCat may receive purchase-related information, such as an anonymous app identifier, purchase status, product ID, renewal status, and subscription entitlement. Your payment card details are handled by Apple or Google and are never seen by us or RevenueCat.
Crash diagnostics and error reporting
The released app sends crash reports and error diagnostics to Sentry, an error-tracking service, so we can find and fix bugs. This runs automatically from the moment the app starts. It is not tied to a feature you choose to use.
A report contains technical information only: the error message and stack trace, the device model, the operating system version, the app version, and a short label saying which part of the code failed, for example "storage.setItem". We deliberately built it so that nothing you typed is included:
- We turned off the SDK setting that would otherwise attach personal information automatically;
- We never attach an identifier for you to a report, so reports are not linked to a person or a profile;
- No error report carries the content of a journal entry, an urge or relapse note, a check-in, an AI chat message, or a community post.
Crash reports already received cannot be recalled by deleting your data in the app, because they are not stored against a user record we can look up. They are deleted on the retention schedule of the service that holds them.
Content blocker
If you use the content blocker, the app may fetch public network-address lists, including lists from the Tor Project, to help keep blocking effective.
This is an ordinary web request. We do not send personal recovery data as part of this request. Like any web request, the receiving server may see your IP address at the time of the request.
Website
If you visit the UrgeLock website, basic technical information may be processed automatically by our website host, such as IP address, browser type, device type, pages visited, and time of access. This is used to operate, secure, and maintain the website.
We use Vercel Web Analytics to understand how the website is used, for example how many people read a page and which site they arrived from. It is built so that it cannot identify you: it stores no cookies and nothing else on your device, it uses no advertising identifiers, and it cannot follow you to other websites. To avoid counting the same visit twice it derives a temporary hash from the incoming request rather than storing an identifier, and that hash is rotated daily, so you are not recognisable from one day to the next. What we see is aggregate: page views, the referring site, country, browser, operating system, and device type.
If you contact us through email or a website form, we receive the information you choose to send, such as your email address and message. We use it only to respond to your request.
We do not use the website to sell personal information, build advertising profiles, or track users across other websites.
Sensitive information
Because UrgeLock is a recovery tool, some information you enter may reveal sensitive details about your sexual behavior, habits, mental well-being, or emotional state.
Under laws such as the EU/UK GDPR, this may be considered "special category" data. Under the California CPRA, it may be considered "sensitive personal information."
We treat this information carefully:
- We keep core recovery data on your device, encrypted at rest;
- The features that can send sensitive information off your device, the AI guide and the community, are optional, and what each one sends is described in this policy, which you accept during onboarding;
- We do not sell or rent your personal information;
- We do not share personal information for targeted advertising;
- We do not use sensitive recovery data to build marketing profiles.
Third-party services we use
We use a limited number of third-party services to operate UrgeLock:
- OpenAI API: generates AI guide replies from messages you choose to send, and classifies community reflections for automated moderation;
- Google Firebase: provides the anonymous sign-in used at app start, stores pseudonymous community content including wall posts and live chat messages, and supports community/account deletion;
- Sentry: receives crash reports and technical error diagnostics from the released app;
- RevenueCat: verifies subscription status and app-store entitlements;
- Apple App Store / Google Play: process purchases, payments, renewals, cancellations, and refunds, and confirm that the app copy is genuine;
- The Tor Project: provides public network-address lists used by the content blocker;
- Vercel: hosts the UrgeLock website and provides its cookieless website analytics.
Each third party processes data according to its own terms and privacy policy.
Permissions we request
The app may ask for permission to send notifications. Notifications are optional and are used for reminders, encouragement, streak check-ins, and recovery prompts.
You can decline notifications, and you can turn them off at any time in your device settings.
The app also asks for microphone access, but only at the moment you tap record on a voice note in the journal. If you never record one, the permission is never requested. A voice note is saved as an audio file in the app's own storage on your device. It is not uploaded to us, it is not sent to any third party, and it is not transcribed. Deleting the note, or the app, removes the file.
UrgeLock does not request access to your photo library, camera, contacts, or precise location.
No ads, no tracking, no data sales
UrgeLock contains no advertising and no third-party advertising SDKs.
We do not use advertising identifiers, cross-app tracking, third-party advertising cookies, or behavioral advertising tools.
We do not sell or rent your personal information.
Children
UrgeLock is intended for adults and is restricted to users aged 18 and over.
We do not knowingly collect information from anyone under 18. If you believe a minor has provided information to us, please contact us at support@urgelock.app so we can review and delete the information where appropriate.
How we protect your data
Your intimate data does not just sit in ordinary app storage. Journal entries, urge and relapse logs, mood check-ins, AI chat history, your onboarding answers, and your profile details are encrypted on the device with AES-256-GCM, a modern authenticated encryption standard.
The key is generated on your device and held in the iOS Keychain or the Android Keystore, which are hardware-backed. It never leaves the device, we never see it, and it is not included in device backups. Without that key the stored data is unreadable, including to someone with physical access to the phone or a copy of its files. If a stored value has been tampered with, decryption fails and the app treats it as missing rather than trusting it.
Android auto-backup is turned off, so recovery data is not copied into a cloud backup.
Data sent to third-party services is transmitted over encrypted connections. No method of storage or transmission is completely secure, and we cannot guarantee absolute security, but we take reasonable measures to protect the limited data that leaves your device.
How long do we keep data
- On-device data stays on your device until you delete it, clear it inside the app, or uninstall the app.
- Community posts remain until you delete your community data or account, unless we need to retain limited records for safety, abuse prevention, legal compliance, or dispute resolution.
- Live chat messages are set to expire 72 hours after they are sent, and the app does not show a message older than that. You can also remove yours by deleting your account.
- The "who is in the room" signal expires within about a minute of your last one.
- Subscription records are retained by Apple, Google, and RevenueCat for as long as needed to manage subscriptions, restore purchases, prevent fraud, and meet legal obligations.
- AI messages are processed by OpenAI to generate replies and may be temporarily retained depending on the OpenAI API terms and settings that apply, currently up to 30 days for misuse monitoring. We do not store AI chats as a separate server-side record unless we clearly tell you otherwise and ask for consent.
Your choices and rights
You are always in control of your core recovery data.
Inside the app, you can:
- Clear your on-device recovery data;
- Delete your community data and pseudonymous community account;
- Stop using the AI guide at any time;
- Disable notifications in your device settings.
Deleting your account removes your community posts, comments, reactions, your live chat messages, the reports you filed, your reserved handle, and your anonymous sign-in account. Your entry in the "who is in the room" list is not deleted by hand because it expires on its own within about a minute of you leaving.
Some server-side operational records are kept and are not removed by that action: abuse counters and rate-limit records, and daily usage counters for the AI guide and for posting. These exist to stop abuse. They hold no recovery content and no message text. Crash reports and error diagnostics already received cannot be recalled, because they are not filed against a user record.
If you want those remaining records removed, contact us at support@urgelock.app and we will handle it manually.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information; restrict or object to certain processing; withdraw consent; or lodge a complaint with your local data-protection authority.
To exercise your rights, contact us at support@urgelock.app.
California privacy rights
If you are a California resident, the CCPA/CPRA may give you the right to know what personal information we collect, access it, delete it, correct it, and limit the use of sensitive personal information.
We do not sell or share your personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes beyond providing and improving the app's features, safety, and support.
You will not be discriminated against for exercising your rights.
Requests can be sent to support@urgelock.app.
International users and data transfers
UrgeLock may be used worldwide. Some third-party services listed above may process the limited data they receive on servers in other countries, including the United States.
Where data is transferred internationally, we rely on the safeguards and legal transfer mechanisms used by those providers.
Because your core recovery data is stored on your device by default, most of your recovery information is not transferred internationally by us.
Changes to this policy
We may update this Privacy Policy as UrgeLock evolves.
If we make a material change, such as adding a new data flow or enabling a new third-party service, we will update the version and effective date and surface the change in the app where appropriate.
Continuing to use UrgeLock after a policy update means you accept the updated policy.
Contact
Questions, requests, or concerns about privacy can be sent to: