top of page

Rebooter: Quit Porn Forever
App Privacy Policy

Last updated: April 29, 2026

1. Introduction

This Privacy Policy explains how Hivaa Saitsuo LLC (“Company”, “we”, “us”, “our”), located in New Mexico, USA, collects, uses, and protects your personal data when you use the Rebooter mobile application (“App”).

This Policy applies to users worldwide and is designed to comply with applicable laws including the US Children’s Online Privacy Protection Act (COPPA), the California Consumer Privacy Act (CCPA/CPRA), the EU General Data Protection Regulation (GDPR), and the privacy requirements of the Apple App Store and Google Play Store.

By using the App you agree to this Policy. If you do not agree, please do not use the App.

2. Data Controller

Hivaa Saitsuo LLC
New Mexico, USA
Email: contact@hivaasaitsuo.com
Website: https://www.hivaasaitsuo.com/

For EU users, Hivaa Saitsuo LLC acts as the data controller within the meaning of Article 4(7) GDPR.

3. Data We Collect

We collect the following categories of personal data:

  • •Account data: email address; a unique account identifier (UUID); display name and profile picture URL received from your identity provider when you sign in via Google or Apple; sign-in activity timestamps (account creation, email confirmation, and last sign-in); and the name of the identity provider used (e.g. "google").

  • Usage data: streak counts, rewire counts, relapse events, personal reflections, goal settings, and rewiring habits you configure within the App. This data is associated with your account.

  • Analytics data: app usage events collected via Mixpanel to understand how users interact with the App and improve its features. This includes onboarding funnel events (e.g. which screens were viewed and at which step the funnel was completed), a randomised Mixpanel-assigned identifier, and technical metadata such as platform, operating system, and timestamps. After you create an account your Mixpanel identifier is linked to your app user ID. On web, Mixpanel may additionally auto-capture page interactions and record sessions (100 % session recording is enabled on web). On mobile only explicitly tracked events are collected — no automatic behaviour capture occurs.

  • Feedback: if you submit feedback through the App, we collect the text of your feedback. Feedback is stored without a direct link to your account to keep it anonymous.

  • Technical data: device type, operating system version, and app version collected automatically to ensure compatibility and diagnose issues.

  •  Authentication data: session tokens and hashed passwords (when you set a password) managed via our authentication provider (Supabase).

  • We do not collect precise geolocation, contacts, camera access, microphone, or financial information. Profile pictures are stored as URLs pointing to your identity provider\'s servers; we do not upload or store the image files themselves.

4. How We Use Your Data

We use your data for the following purposes and, for EU users, on the following legal bases under GDPR:

• To create and manage your account — performance of contract (Art. 6(1)(b)).

• To provide App features (streak tracking, rewiring habits, goals) — performance of contract (Art. 6(1)(b)).

• To store and display your progress across sessions — performance of contract (Art. 6(1)(b)).

• To receive and review anonymous feedback to improve the App — legitimate interest (Art. 6(1)(f)).

• To ensure security, prevent fraud, and debug technical issues — legitimate interest (Art. 6(1)(f)).

• To comply with legal obligations — legal obligation (Art. 6(1)(c)).

• Analytics and product improvement: we may analyse aggregated, anonymised usage patterns to improve the App — legitimate interest (Art. 6(1)(f)).

• Future AI features: we reserve the right to introduce AI-powered features. If we do, we will update this Policy and obtain any required consent before processing your data for this purpose.

5. Third-Party Service Providers

We share data with the following third-party service providers (subprocessors) who act on our behalf:

  • Supabase, Inc. — database hosting, user authentication, and backend services. Supabase may store data on servers in the United States and/or European Economic Area. See their privacy practices at https://supabase.com/privacy.

  • Mixpanel, Inc. — analytics platform used to collect and analyse app usage events and onboarding funnel data. Mixpanel processes data on servers in the United States. On web, Mixpanel may record user sessions and auto-capture page interactions. You can review Mixpanel's privacy practices at https://mixpanel.com/legal/privacy-policy and opt out of Mixpanel tracking at https://mixpanel.com/optout.

  • • Apple Inc. — if you use Sign in with Apple, Apple authenticates you and shares your name and email address with us under Apple's own Privacy Policy. Apple does not share your real email address if you choose to hide it.

  • Google LLC — if you use Sign in with Google, Google authenticates you and shares your name, email address, profile picture URL, and a unique Google identifier with us under Google's Privacy Policy. Google LLC also operates the Google Play Store, which may independently collect app diagnostics and crash data on Android devices.

  • We do not sell your personal data to third parties.

  • We do not share personal data with advertisers or data brokers. We may share data with third parties if required by law or to protect the rights and safety of our users.

6. Analytics & Advertising

We do not currently use third-party advertising networks or cross-app tracking identifiers (such as IDFA on iOS or Advertising ID on Android).

We reserve the right to introduce analytics or advertising services in the future. If we do, we will update this Policy and, where required by applicable law, obtain your consent before enabling such services.

7. Data Retention & Deletion

We retain your personal data for as long as your account is active or as needed to provide the App.

• Account and usage data: retained until you delete your account, then deleted within 30 days.

• Anonymous feedback: retained indefinitely in aggregated or anonymised form.

• Technical and diagnostic data: retained for up to 90 days.

• Legal records: retained as required by applicable law (e.g. financial records for 7 years).

You can delete your account at any time from the More screen inside the App. Account deletion permanently removes your profile and all associated data from our systems. This satisfies Google Play Store account deletion requirements.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted data transmission (TLS), secure authentication, and access controls on our backend systems.

No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we take reasonable steps to protect your information.

9. Children’s Privacy

The App is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child under 13 has provided personal data to us, please contact us at contact@rebooter.app and we will delete it promptly.

If you are located in the EU and are under 16, you must obtain verifiable parental consent before using the App. Upon learning that we have collected data from a child without the required consent, we will delete it without undue delay.

10. Your Rights (All Users)

Regardless of your location, you have the following rights:

• Access: request a copy of the personal data we hold about you.

• Correction: request that inaccurate data be corrected.

• Deletion: request deletion of your personal data. You can also delete your account directly in the App.

• Portability: request your data in a structured, machine-readable format.

• Withdrawal of consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at contact@rebooter.app. We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.

11. EU / EEA User Rights (GDPR)

If you are located in the EU or EEA, in addition to the rights above you also have:

• Right to restrict processing: request that we limit how we use your data in certain circumstances.

• Right to object: object to processing based on legitimate interest.

• Right to lodge a complaint: you have the right to file a complaint with your local data protection authority (DPA). A list of EU DPAs is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

For international data transfers outside the EEA (e.g. to our US-based service providers), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or other appropriate safeguards.

12. California User Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA/CPRA:

• Right to Know: the right to know what personal information we collect, use, disclose, and sell.

• Right to Delete: the right to request deletion of your personal information, subject to certain exceptions.

• Right to Correct: the right to correct inaccurate personal information.

• Right to Opt-Out of Sale or Sharing: we do not sell or share your personal information for cross-context behavioural advertising.

• Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, contact us at contact@rebooter.app. We will respond within 45 days. Requests may be submitted by an authorised agent with written permission.

In the preceding 12 months we have not sold personal information to third parties.

13. International Transfers

Your data may be transferred to and processed in the United States or other countries where our service providers operate. If you are located in the EU/EEA or another jurisdiction with data transfer restrictions, we rely on appropriate safeguards (such as Standard Contractual Clauses) to ensure your data is protected in accordance with applicable law.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notice or email at least 14 days before changes take effect. The updated Policy will always be available within the App.

Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.

15. Contact Us

For any privacy-related questions, requests, or complaints:

Hivaa Saitsuo LLC
New Mexico, USA


Email: contact@rebooter.app


Website: https://www.rebooter.app/

bottom of page