Restep AI Privacy Policy
Effective date: August 1, 2026
Developer: Oleksandr Cherbadzhy
Contact: restepsupport@gmail.com
Country: Ukraine
Restep AI is a wellness and recovery-support application. It helps you record habits, check-ins, reflections, reminders, and progress. It is not a medical service and does not provide medical diagnosis, treatment, or emergency services.
This Privacy Policy explains how Restep AI handles information when you use the app. It applies to the Restep AI mobile application with bundle identifier com.sashacherbadzhy.restep.
Information We Collect
Information you enter and information generated from it
Restep AI can process the information you choose to enter, including:
- an optional preferred name;
- habit names, categories, start dates, reasons, and optional spending and time estimates;
- daily check-ins, moods, urge or craving intensity, triggers, coping actions, emotions, contexts, and optional alcohol-involvement indicators;
- journal entries and other private notes;
- relapse or slip records, including optional trigger and note fields;
- Support Session information and optional outcomes, such as intensity before and after a session, selected coping action, and whether an action helped;
- article-reading progress, achievement progress, reminder preferences, notification-message history, appearance and tutorial preferences; and
- Recovery Coach conversations and messages.
The app also derives local results from this information, such as streaks, personal bests, estimated savings and reclaimed time, Recovery Journey milestones, Weekly Recovery Reports, Trigger Analytics, achievements, and local Premium-preview information.
Information Stored on Your Device
Most Restep AI information is stored locally in the app's device storage. This includes your habits, check-ins, journal entries, private notes, support-session history, reminders, local analytics and reports, article progress, achievement history, AI-analysis cache, and Coach conversations.
Restep AI does not provide an account system or cloud synchronization for these records. The app does not send your complete local database, unrelated habits, raw journal history, or recovery records to a cloud database as part of normal tracking.
Local storage is governed by your device and operating-system settings. Do not treat device-local storage as a guarantee of encryption, anonymity, or immunity from device backup, device compromise, or access by someone who can use your unlocked device.
Information Processed by Optional Online/AI Features
AI Recovery Analysis and AI Recovery Coach are optional Premium online features. They require an internet connection and are initiated when you choose to use them.
AI Recovery Analysis
When you request an analysis, the app sends a bounded, selected-habit summary to the Restep AI recovery-analysis service. It may include the selected recovery category, analysis-window length, streak and recovery-day counts, check-in and support-session counts, slip count, aggregate urge trend and intensity, aggregate trigger and coping-action counts, weekly focus, bounded local journal-signal categories and counts, local evidence labels and counts, language, and an allow-list of local article identifiers.
The app is designed not to send raw journal-note text, your preferred name, habit name, raw local timestamps, unrelated-habit records, the entire local database, device identifiers, or API credentials in an Analysis request.
AI Recovery Coach
When you use Coach, the app sends selected-habit structured context similar to the Analysis summary, along with the selected recovery category/profile, recovery start date, current streak, aggregate trigger and coping-action summaries, weekly focus, allowed article and evidence identifiers, your chosen Coach mode, and language.
Coach also sends the message you choose to submit and up to four recent conversation turns, with each recent turn capped by the app. Do not enter information you do not want processed by the online AI feature. Coach conversations are otherwise stored locally, per habit, and are not a long-term cloud memory feature.
Online AI processing
The Restep AI backend receives these requests and uses Google Gemini to generate structured responses. The backend validates request and response formats and is designed to reject malformed or oversized requests. Application logs are designed to exclude request bodies, prompts, journal text, private notes, and API keys; they may include operational metadata such as a generated request ID, endpoint, status, duration, request mode, bounded counts, and token-usage metrics.
Online AI processing currently uses a server-side direct Gemini Developer API integration through Google Cloud Run, rather than a Vertex AI integration. The code does not use Gemini grounding, file storage, model tuning, explicit context caching, or stateful conversation APIs. The Gemini API key used for this service is confirmed to use Google's Paid 1 service tier. Under Google's current paid-service terms, Google does not use prompts or responses to improve Google products. Google may log prompts and responses for a limited period solely to detect and prevent policy violations and maintain safety and security; Google does not publish an exact duration in those terms. Google also documents default implicit in-memory caching for Gemini models with a 24-hour time-to-live; the backend does not configure explicit caching, and the applicability of implicit caching to the selected model must be confirmed with Google. Restep AI does not represent this service as Zero Data Retention.
The currently deployed Cloud Run service is in the europe-west1 region. Cloud Run automatically produces request, container, and system logs in Google Cloud Logging. Restep AI's backend application logs are designed to exclude request bodies, prompts, journal text, Coach messages, AI responses, and API keys. However, automatic request logs can include operational HTTP metadata such as request method, URL/path, status, size, user agent, latency, and client IP address. The current Google Cloud project has the default _Default log bucket with 30-day retention and the mandatory _Required audit bucket with 400-day retention; no additional project-level log sinks were found during this audit.
Subscriptions and Purchases
Restep AI offers optional Premium subscriptions. Purchases are processed by Apple through StoreKit and App Store Connect. Restep AI uses RevenueCat to obtain subscription offerings, localized product information, and the active premium entitlement, and to support purchase restoration. The app does not create an account or provide a custom RevenueCat App User ID; RevenueCat generates an anonymous App User ID for the subscription integration. The audited app code does not set RevenueCat customer attributes or advertising/attribution identifiers.
The app does not process or store your full payment-card information. Apple and RevenueCat may process purchase, subscription-status, product, transaction, Apple receipt or StoreKit information, anonymous app-user, device/app, and network technical information needed to provide purchases, entitlement verification, fraud prevention, and restoration. Their processing is governed by their respective policies and terms.
Notifications
Notifications are optional. The app asks for notification permission only after you explicitly enable notifications. The app schedules local on-device reminders and can store reminder settings and a small local history of message-template identifiers to reduce repetition.
Private notification mode is the default and is designed not to include a habit name or recovery-specific details in notification text. Detailed mode may include a habit name or progress-related text. Notification data can contain an internal route and habit identifier so that a notification tap can open the relevant screen. Restep AI does not obtain an Expo push token or send remote push notifications in the current implementation.
Sharing
Sharing is optional and happens only when you explicitly choose a share action. The app previews the selected progress summary or progress card before opening the device share sheet. The selected information is then handled by the destination you choose. The sharing flow is designed not to include journal entries, triggers, relapse details, personal reasons, or other private recovery notes.
Third-Party Services
Restep AI currently uses these services for the functions described below:
- Apple / StoreKit / App Store Connect: app distribution, subscription purchase, payment processing, subscription restoration, and Apple-delivered notification capability.
- RevenueCat: subscription offering retrieval, localized StoreKit product metadata, purchase handling, restoration, and Premium-entitlement status.
- Google Cloud Run / Cloud Logging: hosts the optional Restep AI online Analysis and Coach service and processes service/request operational metadata.
- Google Gemini Developer API: generates structured responses for the optional online Analysis and Coach features under the applicable Google Gemini terms.
- NHS website: if you choose to open the source link shown for the smoking recovery timeline, your browser connects to the NHS website. That is a user-initiated external link.
The app includes Expo and React Native technology. The audited application code does not send app analytics, crash reports, advertising identifiers, or recovery records to Expo as an application feature. Platform, hosting, App Store, device, network, and third-party SDK providers may independently collect technical information under their own terms.
Analytics and Tracking
Restep AI does not include an advertising SDK, cross-app tracking SDK, product-analytics SDK, or crash-reporting SDK in the audited application dependency list or source code. The app does not use data for targeted advertising or cross-app tracking.
Local features called Trigger Analytics, Weekly Recovery Report, Recovery Journey, and other progress features are calculations performed from your local recovery records. They are not third-party behavioral analytics services.
The optional online AI service produces operational logs as described above. These logs are not used for advertising or cross-app tracking.
Data Retention
Local records remain on your device until you delete them, delete the applicable habit or conversation, use the explicit full local reset, clear app data, or remove the app, subject to your device's backup and operating-system behavior.
The app limits certain local records: AI Analysis cache entries are capped, Coach conversations are capped per habit, and Coach messages are capped per conversation. The exact retention of data processed by Apple and RevenueCat is determined by their services and the developer's service configuration. Cloud Run's current project-level _Default log retention is 30 days and its required audit-log retention is 400 days; the backend application logs are designed not to contain raw user content. Under the verified Gemini paid-service tier, Google may retain prompts and responses for a limited, undocumented period for safety and abuse prevention and may apply documented implicit in-memory caching where applicable.
Data Deletion
You can delete journal entries and individual habits in the app. Deleting a habit is designed to remove that habit's local history, journal entries, reminders, support data, associated AI Analysis cache, Coach conversations for that habit, and achievement history. You can also delete individual Coach conversations using the Coach controls.
When you explicitly choose the app's complete local data deletion/reset action, Restep AI cancels its scheduled local notifications and removes the app-owned local records listed in this policy, including separate AI Analysis, Coach-conversation, achievement, tutorial, notification-template-history, and automatic-paywall state. It does not and cannot delete purchase records or subscription history held by Apple or RevenueCat. You may also remove the app and app data through your device settings, subject to device backup and operating-system behavior.
Deleting local app information does not retroactively remove information already processed by Apple, RevenueCat, Google Cloud Run, or Google Gemini. Requests concerning information held by those services should be directed to restepsupport@gmail.com and handled according to applicable agreements and law.
Security
Restep AI uses device-local storage for core records and HTTPS for the configured online AI service and subscription services. The backend is designed to keep the Gemini API key outside the mobile app and to validate structured AI inputs and outputs. No system is completely secure; do not rely on Restep AI to protect information against every possible loss, misuse, or unauthorized access.
Children's Privacy
Restep AI is not directed to people under 18. If you believe a person under 18 has provided personal information in violation of applicable law, contact restepsupport@gmail.com.
International Processing
If you use optional online AI features or subscriptions, information may be processed in countries other than the one where you live, including where Apple, RevenueCat, Google Cloud Run, or Google Gemini operate. The current Cloud Run service is deployed in europe-west1; Google's Gemini terms state that certain paid-service safety/abuse logs may be stored transiently or cached in countries where Google or its agents operate. Oleksandr Cherbadzhy will maintain applicable international-transfer safeguards as required by law.
Your Rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or information about personal data processed by or on behalf of Oleksandr Cherbadzhy. You can manage most recovery records directly on your device. For other requests, contact restepsupport@gmail.com.
Changes to This Privacy Policy
We may update this Privacy Policy when Restep AI or applicable legal requirements change. We will post the updated version in the app, on the applicable privacy-policy webpage, or both, with a revised effective date.
Contact
For privacy questions or requests, contact:
Oleksandr Cherbadzhy
restepsupport@gmail.com
Ukraine