Tracking a private habit without exposing your private life
Tracking a habit like porn use means putting some of the most sensitive data about you into an app. Before you hand that over, it's worth knowing exactly what you're trusting it with — because "health app" and "data broker" aren't mutually exclusive as often as people assume.
Why this category is different
A step counter leaking data is annoying. A relapse-tracking log tied to porn use leaking data is a different order of problem — it can touch relationships, employment, or just the basic discomfort of a deeply private struggle becoming someone else's dataset. Several widely used health and wellness apps have been caught sharing behavioral data with advertising and analytics partners, often disclosed only in fine print. Mental-health and recovery apps are not exempt — some of the more scrutinized privacy failures in the wellness app category have involved exactly this kind of data.
What to actually check before trusting an app
- Does it require an account? An account tied to an email or phone number is a re-identification point by default. Apps that work fully offline or pseudonymously remove that link entirely — no server-side profile to breach, subpoena, or sell.
- Where does the data live? Local, on-device storage is a fundamentally different risk profile than data mirrored to a company's servers. If it's server-side, ask what's encrypted at rest and who — including the company itself — can read it.
- Is there a business model that depends on your data? Free apps monetized by advertising have a structural incentive to use behavioral data, even indirectly through analytics SDKs. A clear answer to "how does this app make money" tells you more than the privacy policy does.
- Can you read the actual policy, not just the summary? Look specifically for the words "third parties," "partners," and "analytics" — that's where resale and sharing clauses tend to hide, even in apps that market themselves as private.
- Is deletion actually complete? A real delete should remove data from backups and any connected analytics pipeline, not just hide it from the app's interface.
What "good" looks like
The bar isn't complicated: local storage by default, no account requirement, no advertising SDKs, and a business model — subscription or one-time purchase — that doesn't need your behavioral data to make money. Encryption in transit and at rest for anything that does leave the device. A privacy policy short enough to actually read.
Qwit is built to that standard for exactly this reason: no account is required to use it, no user data is sold or shared with advertisers, and tracking data stays private to you rather than existing as an asset the company could monetize or leak.
The takeaway
For a habit this personal, the app itself is part of the recovery decision, not just a neutral tool. Before trusting one with this data, check whether it needs an account, where the data actually lives, and whether its business model depends on your behavior being visible to anyone but you.
Sources: Mozilla Foundation "Privacy Not Included" reports on health and wellness apps; FTC enforcement actions on health-app data sharing (BetterHelp, GoodRx); Grundy et al., BMJ, on data sharing practices in top health apps.