Privacy Policy
Effective: September 25, 2026
This Privacy Policy describes how Rebuild ("we," "us," or "our") handles information when you use the Rebuild mobile application ("App") and https://getrebuild.app ("Website"). Rebuild is an alcohol-recovery support tool. The short version: your log is stored on your phone, and there are no accounts, no login and no cloud sync. The App does send some details to Google (Firebase) and to RevenueCat, under a random ID rather than your name — including the type and number of drinks you log and your mood ratings. Section 3 lists every item. By using the App you agree to this policy.
1. No account, no server-side profile
Rebuild has no sign-up, no login, and no user accounts. We do not ask for your name, email address, or phone number, and we do not create a profile for you on any server. There is no password to manage because there is nothing to log in to.
Because there is no account, nothing the App sends carries your name, email address or phone number.
2. Your log is stored on your device
Everything you track is stored in a private database (SQLite) on your phone. Rebuild has no cloud sync and no backup server of its own. The log includes:
- Drink sessions you log (count, drink type, time, optional notes)
- Sober days and streaks
- Recovery milestones unlocked
- Daily commitments ("morning pledge")
- Evening check-ins ("stayed strong" / "had a drink")
- Journal entries you write (date, text, and an optional mood tag)
- Craving SOS sessions (which technique you used, an optional trigger tag, and how the craving intensity changed)
- Your settings (goal, baseline drinking pattern, your "why", savings targets, notification preferences)
Your journal text, drink notes, craving SOS sessions, morning pledges, baseline drinking pattern and savings targets never leave your phone. A few details of what you log do: the App sends the type and number of drinks, your mood ratings, your evening check-in answers, your sober-day count and your goal with its analytics. Section 3 lists each one.
On Android, the App opts out of Google's automatic backup, so the log is not copied to your Google account. On iPhone, your phone's own iCloud or computer backup includes the App's data, as it does for most apps; Rebuild never reads that backup. If you delete the App or use "Erase all data," the log is gone from your device. Analytics already sent are not deleted (see section 3).
3. What the App sends, and to whom
Rebuild works offline. When your phone has a connection, the App sends the items below. None of them carries your name, email address or phone number, because the App never asks for them.
Google Firebase Analytics — how the App is used
Firebase is a Google service. The App sends it:
- Two IDs — a random ID the App makes the first time you open it, and the ID Firebase gives each install. Everything below is sent with them, so Google can tell that events came from the same phone, but not who you are.
- What Firebase collects from any app — that the App was opened and for how long, the App version, your phone model, operating system and language, and a rough location (country and region) worked out from your network address. On Android this includes your phone's advertising ID. On iPhone it does not, because the App never asks for permission to track you.
- Drinks you log — the drink type (for example beer or wine), the number of drinks, and the estimated peak blood alcohol the App worked out.
- Mood — each mood rating you give (1 to 5) and which screen you gave it on.
- Evening check-ins — your answer: "stayed strong" or "had a drink".
- Your sober streak — the day count each time a sober day is recorded; each milestone you reach and its day; the day count and milestone when you open the "tonight's cost" sheet; and your streak as a range (for example 7–29 days) with your current milestone.
- Your goal and reasons — your goal (drink less, take a break, quit, or just track), and at the end of setup the reasons you ticked (for example "sleep" or "money") and how many.
- Setup and tenure — which setup screen you reached, and how long you have had the App, as a range (for example 7–13 days).
- Pro and purchases — when the Pro screen opens (with your goal and sober-day count), which plan you tap, a completed purchase with its price and currency, a restore and its result, whether you are on free, subscription or lifetime, and that a promo code was used (not the code).
- Smaller things — when the "what's new" note appears, when the App asks the store for a rating (with your streak day when a milestone prompted it), a tap on the store's rating page, and taps on "More apps by me" and the app you choose there.
Google Firebase Crashlytics — crash reports
When the App crashes or hits an error, it sends Google a report: the error and where in the code it happened, your phone model, operating system and App version, and the phone's state at that moment (for example free memory). Each report carries the same random ID, your exact sober-day count, your goal, how many days you have had the App, and whether you have Pro.
RevenueCat — purchases
RevenueCat runs Rebuild Pro subscriptions. It receives a random ID made on your phone (on iPhone, one kept in the phone's keychain so a purchase survives a reinstall), the Firebase install ID from above, so a purchase can be matched to that install's analytics, and what you buy or restore: the product, price, currency, dates and the store's receipt. Apple or Google take the payment; we never see your card details.
The "More apps by me" list
The App downloads a list of our other apps from gainaura.app. The request carries no ID and nothing you log; like any web request, it shows that server your network address.
Promo codes
If you redeem a promo code, this website checks it, and receives only the code. The App then turns on Pro without contacting any server.
What is never sent
Your journal text, drink notes, craving SOS sessions and triggers, morning pledges, baseline drinking pattern, savings targets and your full history stay on your phone.
For the Firebase analytics and crash reports (and the website analytics in section 7), our legal basis is our legitimate interest (GDPR Article 6(1)(f)) in keeping the App and site working and improving them. We do not use this data for advertising and we do not sell it. Google keeps analytics events for no longer than 14 months and crash reports for 90 days.
4. Health-related data
The recovery data you log (drinks, cravings, sober days, milestones) is sensitive health-related information. Most of it never leaves your phone. The parts listed in section 3 — drink type and count, estimated peak blood alcohol, mood ratings, check-in answers, sober-day counts and your goal — go to Google Firebase under a random ID, not your name. For all of it:
- It is never sold, rented, or traded.
- It is never used for advertising or marketing.
- It is never shared with insurers, employers, or data brokers.
- Your full log is protected by your device's own security (screen lock, device encryption).
5. Notifications
All of Rebuild's reminders are local notifications scheduled on your device (for example, an evening check-in or a milestone getting close). They are generated on the phone and never leave it. There is no server-sent push. You can disable notifications from your system settings, or turn off specific categories inside the App.
6. Analytics and your choices
The analytics and crash reports in section 3 are always on. The App has no switch to turn them off, and your phone's privacy settings do not turn them off either. On Android you can delete your advertising ID (Settings → Privacy → Ads, or Settings → Google → Ads), which stops that one ID being sent. The only way to stop the rest is to stop using the App and uninstall it.
7. This website (getrebuild.app)
Separately from the App, this website uses Google Analytics to understand in aggregate how visitors find and use these pages — for example, which articles are read or which links are followed — so we can improve the site. This applies only to the website. Google Analytics sets its own cookies in your browser to tell a new visit from a return one. Google uses your network address to work out a rough location and does not store the address. None of this is linked to your name, and we do not run advertising or ad-tracking here. Nothing you log in the App is sent to this website.
The tools, and their one event. Each tool page sends an event named tool_used the first time you touch the tool itself, and it carries one thing: the name of the tool, such as "sobriety-counter". A click through to the App Store or Google Play is counted the same way, as a store click, with the store and the spot on the page the button sat in. A click from an article to a tool is counted too, with the tool, the article and the page's language. None of these events carries a figure, date or answer from the page. Where a tool puts a reading in the web address so you can bookmark or share it — the sobriety counter's quit date, for example — that address is part of the page view like any other.
The embeddable counter. The sobriety counter can be dropped into somebody else's blog or forum post as an iframe pointing at /embed/sobriety-counter. That document is served on its own, outside the site's layout: it carries no Analytics tag, no fonts and no bundle, it sets no cookie of ours, and the day count is printed by our server before any script runs. Whoever embeds it needs that to write their own cookie notice, which is why it is written down here.
What the tools keep in your browser. Several tools save what you type to your own browser's local storage so a page reopens where you left it — the thirty-day grid on the Dry January tracker, the craving timer's count of urges outlasted, the sobriety counter's date. That is local to that browser and to that device; clearing your browser data clears it. It is not part of any event described above.
8. Exporting and erasing your data
Because your data lives on your device, you are always in control of it:
- Export — you can export your data to a backup file (JSON) from within the App and save or share it wherever you like.
- Erase — "Erase all data" in the Profile screen permanently wipes your recovery data from the device.
We cannot access, export, or delete your log on your behalf, because we never hold a copy of it.
9. Children's privacy
Rebuild is not intended for anyone under 18. We do not knowingly collect data from children, and in the ordinary use of the App we do not collect identifiable data from anyone.
10. Your privacy rights
Rebuild has no accounts. The analytics, crash reports and purchase records in section 3 sit with Google and RevenueCat under random IDs, not your name, so we usually cannot tell which records are yours. Where data-protection laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA/CPRA) apply, you nonetheless have the right to:
- Access — ask what personal data, if any, we hold about you.
- Rectification — ask us to correct inaccurate personal data.
- Erasure — ask us to delete personal data we hold.
- Portability — receive a copy of your data in a portable format (the in-App JSON export already provides this for everything you track).
- Objection / restriction — object to or restrict the analytics processing described in sections 3 and 7.
We do not sell or share your personal information, and we do not use it for cross-context behavioural advertising, so there is nothing to opt out of in that respect. To exercise any right, contact us using the details below. Because your log lives only on your device, you are in control of it — you can export or erase it yourself at any time.
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be announced inside the App or on this page. The effective date at the top reflects the current version.
12. Data controller and contact
The data controller responsible for this policy is Must Have Apps SIA, registered at Valguma iela 18-16, Rīga, LV-1048, Latvia.
Questions and privacy concerns: hello@musthaveappscorp.com.
