Privacy Policy
Last updated: July 11, 2026
The short version: PHALANX is built for private recovery. Journal entries, reflections, Fortify logs, and sensitive app records are stored locally by default. Basic progress, account, subscription, notification, and app setup data may sync securely so the product works across sessions and devices. When you use AI Centurion, your message and limited recent context may be sent through our secure proxy to a third-party AI provider for processing. We do not sell your data or use in-app discipline records for advertising profiles. PHALANX may use limited device identifiers and coarse app events for attribution, analytics, subscription, and paywall measurement.
I. Our Philosophy
PHALANX was built with a single, uncompromising principle: your recovery is your business and nobody else's. We believe sensitive self-improvement data deserves clear boundaries and plain disclosure.
II. Data We Collect
Authentication
When you sign in with Apple or Google, we receive:
- A unique user ID (for account recovery)
- An email address - Apple hides your real email through their Private Relay system; Google Sign-In may provide your actual email address
We never see your Apple or Google password. This data is stored in Firebase Authentication and is used solely for account recovery and optional service communications.
Optional Setup and Personalization
During onboarding and app use, you may choose to provide information that helps PHALANX tailor your plan, Fortify flow, notifications, and progress view. This may include your warrior name, warrior likeness preference, quit goal, danger windows, reasons for quitting, preferred reminder times, Fortify preferences, and optional personal anchors you choose to enter.
Do not enter information that you do not want processed or stored by the app. Personalization data is used to make PHALANX more useful to you. It is not sold and is not used to build advertising profiles.
What We Do NOT Collect
- We do not build advertising profiles around your in-app recovery behavior
- We do not send journal entries, questionnaire answers, AI coach messages, relapse records, Fortify logs, personal anchors, or discipline records to advertising networks. Limited device identifiers and coarse app events may be used for app-install attribution and advertising measurement.
- We do not collect precise location data
- We do not collect browsing history, search terms, adult-content details, or a list of blocked pages from content-blocking features
- Authentication, payments, subscription, paywall, attribution, AI processing, analytics, and hosting providers may process limited technical data needed to provide those services
- We never sell or monetize your data
III. Data Storage
Data Stored Locally on Your Device
The following sensitive data is stored locally on your device using encrypted local storage (MMKV) by default:
- Journal entries and private reflections
- Self-tracking questionnaire scores (PPCS-6, PHQ-9, GAD-7)
- AI Centurion chat history saved on your device
- Fortify logs, reset notes, daily task completions, and urge or pattern logs
- Optional personal anchors and reasons for quitting, when you choose to save them
Data Synced for Account Recovery
The following limited account and product data may be synced when you sign in, so PHALANX can recover your account, confirm your access, and keep basic preferences working:
- Warrior profile (name, appearance preferences)
- Streak data (start date, current streak, highest streak)
- Cosmetic preferences and equipped items
- App settings and notification preferences
- Subscription entitlement status and product access state
- Coarse onboarding progress and feature state needed to run the app
This data is kept separate from private reflections and user-written journal content. If you uninstall the app, local-only records are deleted from that device.
IV. Fortify, Notifications, and Content Blocking
Fortify: Fortify is an urgent-use flow for moments when you want help staying in control. Fortify may use your app setup answers, saved preferences, previous Fortify outcomes, and optional personal anchors to suggest a next action. Fortify is not therapy, medical care, or an emergency service.
Notifications: PHALANX may schedule reminders, check-ins, and recovery prompts based on your preferences, onboarding answers, app state, and local device settings. Notification timing can be changed or disabled in the app or device settings.
Content blocking: If you use a blocker or restriction feature, PHALANX does not record your browsing history, search terms, adult-content details, blocked URLs, or blocked domains. We may record limited setup or status events, such as whether a blocking feature is enabled, so the app can function and improve reliability.
Community: PHALANX does not include a public social feed in v1. If future formation, ally, or community features are added, they will be covered by this policy before release.
If you choose to use future community features, please note:
- Posts display your warrior name (the in-app name you choose) and your warrior rank - no real names, profile pictures, or other identifiable information is required
- You control your warrior name and can set it to anything - we recommend not using your real name
- We do not track which device submitted which post
V. Self-Tracking Questionnaires
PHALANX includes optional self-report questionnaires (PHQ-9, GAD-7, PPCS-6). Your questionnaire results are:
- Stored only on your device
- Not shared with healthcare providers, researchers, or third parties for diagnosis or research
- Not used for diagnostic purposes; consult a qualified healthcare professional for clinical evaluation
VI. Third-Party Services
- Sign in with Apple / Google: Used only for authentication. We receive a relay email and user ID - never your password.
- Firebase Authentication: Stores your sign-in credentials securely. Subject to Google's Privacy Policy.
- Cloudflare: Routes AI coach requests through a secure proxy and protects service endpoints. The proxy prevents AI provider keys from being exposed in the mobile app.
- AI Centurion Coach: When you use the AI coach, your message, warrior status, and limited recent context may be sent to OpenAI for processing via our Cloudflare proxy. Messages are not stored in PHALANX databases. AI coach transcripts are retained by OpenAI for up to 30 days for trust and safety, then destroyed. PHALANX has opted out of OpenAI model training.
- RevenueCat: Subscription entitlement and receipt verification. RevenueCat helps us confirm whether your subscription, trial, or purchase is active. We do not send journal entries, Fortify logs, AI messages, or user-written recovery content to RevenueCat.
- Superwall: Paywall presentation, offer testing, and paywall conversion measurement. Superwall may process limited device, app, product, and paywall event data. We do not send journal entries, Fortify logs, AI messages, or user-written recovery content to Superwall.
- AppsFlyer: App-install attribution, deep-link handling, and advertising measurement. AppsFlyer may receive limited device identifiers, campaign/source data, and coarse app events such as install, onboarding completion, paywall view, trial start, and purchase completion. We do not send journal entries, questionnaire answers, AI coach messages, relapse records, Fortify logs, trigger labels, adult-content details, email addresses, names, or user-written content to AppsFlyer.
- PostHog: Limited product analytics, including feature usage, onboarding, paywall, and app reliability events. PHALANX does not send names, emails, Firebase user IDs, journal text, assessment answers, Centurion messages, or user-written Fortify or recovery text to PostHog, and does not use PostHog for advertising profiles.
- Meta App Events: Used for app-install attribution and coarse advertising measurement. Meta may receive limited device identifiers and event names such as app activation, onboarding completion, paywall view, purchase started, and purchase completed. PHALANX does not send journal entries, questionnaire answers, AI coach messages, relapse records, trigger labels, adult-content details, email addresses, names, or user-written content to Meta.
- Marketing website measurement: On PHALANX marketing pages, we may use Google Tag Manager, Google Analytics, Meta Pixel, Microsoft Clarity, and Cloudflare Web Analytics to measure landing-page views, traffic sources, page performance, App Store button clicks, and public-page interaction patterns. We do not send journal entries, questionnaire answers, AI coach messages, relapse records, or discipline records to these advertising or website analytics tools. We do not use session-recording tools on sensitive PHALANX flows.
- Sentry: Crash reporting and error monitoring to improve reliability.
- Beta Feedback: If you submit feedback through the in-app "Report to Command" feature, your message, feedback category, warrior name, rank, streak days, device platform, and OS version are stored in our Firebase database to help us improve the app.
Purchase Processing: If you choose a PHALANX subscription or Lifetime purchase, Apple processes the transaction. We never see or store your payment card information.
VI-B. Communications
We may send account, service, subscription, lifecycle, support, or marketing emails to your sign-in or relay email address where permitted. We do not include private journal content, adult-content details, or AI chat content in these emails. You can opt out of marketing emails at any time by using the unsubscribe link or by contacting us. Certain account, receipt, legal, and security messages may still be sent when needed to operate the service.
VII. Children's Privacy
PHALANX is not intended for children under 13. We do not knowingly collect personal data from children under 13.
VIII. Your Rights & Account Deletion
You have the right to:
- Delete your data: Use "Reset All Data" in Settings to permanently erase all local data from your device.
- Delete your account: Use "Delete Account" in Settings to permanently remove your Firebase authentication record and all associated server-side data.
- Request data export: Contact us at support@phalanxapp.com to request a copy of any data we hold about you.
Since most sensitive records are stored locally on your device, uninstalling the app will permanently delete the majority of your information. Server-side account and recovery metadata can be deleted through the in-app account deletion flow.
IX. Changes to This Policy
If we change this privacy policy, we will update this page and the "Last updated" date above. We aim to keep data collection limited to what is needed to run, improve, protect, and measure PHALANX.
X. Contact
If you have questions about this privacy policy, contact us at: support@phalanxapp.com