Qwit Vaping — Privacy Policy
Last updated: 27 July 2026
Qwit Vaping supports people changing their relationship with vaping and nicotine. This policy describes the personal data handled by the app and website. Addiction and recovery information can be sensitive health-related data.
1. Controller and scope
Norulab controls personal data for Qwit Vaping. Contact: contact@norulab.com. This policy covers the mobile app, related cloud services, optional AI features, community features and qwit.app pages. Store operators process purchases under their own policies.
2. Data categories
- Account and identity: internal user ID, sign-in provider, email when supplied by the provider, display name, profile image and account status.
- Addiction and recovery: selected addiction, quit lifecycle and dates, consumption/quantity and cost baselines, urges, triggers, relapse/check-ins, goals, motivations, journal notes, program answers, progress and milestones.
- Community and social: public profile fields, ally/friend code, posts, comments, direct messages, reactions, reports and blocks.
- Purchases: product and entitlement status, Store transaction reference and purchase/restore result. Full payment-card data is not received.
- Device, usage and diagnostics: app version, operating system, language, time zone, push token, feature events, crash reports, performance traces and limited device metadata supplied by Firebase SDKs.
- AI interactions: messages and the declared profile context needed for optional coach, craving, advice and program features; moderation result, request status and quota counters.
3. Purposes and legal bases
- Provide, synchronize, secure and support requested app/account features: performance of the service contract.
- Process addiction/recovery data and optional AI context: explicit consent where required for sensitive data and AI processing. Consent can be withdrawn in Settings.
- Prevent abuse, moderate content, diagnose crashes and protect service integrity: legitimate interests, balanced against user rights, or legal obligation where applicable.
- Validate purchases and keep required transaction records: contract and legal obligations.
- Send optional notifications: device permission and configured app choices.
Qwit does not sell personal data, serve third-party ads or use addiction data for cross-app advertising.
4. AI transparency and safety
The optional coach and generated guidance are powered by artificial intelligence. They can make mistakes and provide behavioral support only; they do not diagnose, treat or replace a doctor or emergency service. If your health is at risk or you are in crisis, seek qualified medical help.
After explicit in-app consent, Qwit sends only the context declared above through an authenticated Firebase proxy to OpenAI. The OpenAI key is not stored in the app. API content is not opted into model training. Standard abuse-monitoring retention can be up to 30 days. Withdrawing consent stops new optional AI requests.
5. Recipients, processors and transfers
- Google Firebase/Google Cloud: authentication, database, storage, functions, push, analytics, crash and performance services.
- OpenAI: optional AI generation and moderation after consent.
- Google Play and Apple: distribution, purchases and entitlement processing under the selected Store account.
- Service providers and authorities: only when needed to operate the service, enforce rights, investigate abuse or comply with law.
Providers may process data outside the EEA. Norulab must use applicable transfer safeguards, such as adequacy decisions or standard contractual clauses, and records them in its processor inventory.
6. Visibility and security
Qwit uses account-based Firestore access controls; release checks verify that private user documents are owner-only. Public-profile fields and content intentionally posted to community surfaces can be visible to other users. Direct messages are visible to their participants and may be processed for safety/report handling. Data is encrypted in transit. No system can guarantee absolute security; suspected incidents should be reported to the contact above.
7. Retention
- Account, recovery and private app data: while the account exists, then deleted within 30 days of a valid account-deletion request unless law requires longer.
- Community content: until deleted, moderated or the associated account is deleted; limited abuse records may be retained when necessary to protect users or comply with law.
- AI API abuse-monitoring content: up to 30 days under the standard OpenAI endpoint policy; Qwit keeps only operational metadata needed for quota/security unless a feature explicitly saves content to the user's account.
- Purchase references: for entitlement support and any legally required accounting period.
- Crash, performance and analytics data: according to documented Firebase project retention settings and then deleted or aggregated.
8. Access, export, correction and deletion
Users can change many fields in the app, withdraw AI consent, reset local progress and use the account-deletion action in Settings. They may request access, portable export, correction, restriction, objection or deletion by emailing contact@norulab.com. Identity verification may be required. Users may complain to their competent data-protection authority.
9. Children
Qwit Vaping is not intended for children under 16. Community and age-restricted features are also subject to current Store rules and local law.
10. Changes
Material changes are dated here and, when required, announced in the app. New purposes that require consent will not be activated silently.