What counts as consumer health data here
Under these laws, information that identifies your past, present or future physical or mental health status is consumer health data. In a recovery app that would include what you are recovering from, when you lapsed, what you wrote about it, and any of it linked to you.
What we collect: none of it
| Category | Collected by OB DATA LLC |
|---|---|
| What you are working on (gambling, alcohol, other) | No. On iPhone, stored on your device and in your own iCloud account. On Android, stored on your device. |
| Journal entries — including evening reviews, inner-work answers and the letter for the worst hour — lapse notes, urge notes, mood, symptoms | No. Local-only. No cloud mirror exists for these records. |
| Your reasons; your people, with the names and phone numbers you type in, the message you write ahead of time, and when you called or texted them from the app | No. Local-only. The app never reads your contacts, and calls and texts happen in your phone’s own apps. |
| Meetings you keep or log as attended, notes about them, reminder choices, your 90-in-90 count | No. Local-only. |
| If-then trigger plans | No. Local-only. |
| Financial disclosure list | No. Local-only. |
| The hours of day your pattern covers | No. Local-only. |
| Dates you mark — an anniversary, a birthday, a day you dread — and what you call them | No. Local-only. |
| Counter, run history, milestone dates | No. On iPhone, your own iCloud account, which we cannot read. On Android, your device. |
| Precise or approximate location | No. Read on device, compared locally, discarded. Never transmitted. |
| Biometric identifiers | No. The optional app lock uses the phone’s own system authentication, Apple’s on iPhone and Android’s on Android; we never see a biometric. |
How that is enforced
Not by policy. On iPhone, free-text records are registered in a database configuration that has no cloud container attached, so there is no destination for them to be uploaded to. This was verified on real hardware, not by reading the code: a marker string written into four free-text fields appeared in the local store and in none of the cloud-synced tables. The record types added in versions 1.1 and 1.2 are registered in the same local-only configuration.
If you back up your iPhone to iCloud or to a computer, the backup includes these records, like the rest of your phone. It is held in your Apple account or on your computer, not by us, and we cannot open it. Apple holds the keys to an iCloud backup unless you turn on Advanced Data Protection. You can leave Limiter out of iCloud Backup in Settings; the privacy policy says how.
On Android, the app keeps every record in its own database on the phone, and has no sync. From version 1.2, Android’s own backup can carry a copy of that database and three small settings files to your Google account, but only when the phone can encrypt it end to end: Android 9 or later, with a screen lock set. The copy is encrypted with your PIN, pattern or password; Google cannot read it, and neither can we. With no screen lock, or on Android 8, nothing is backed up. The app names each file that may go, and everything else stays on the phone. Android’s device-to-device transfer, which you start yourself when you move to a new phone, copies the same files and nothing more directly to the new phone; from a phone on Android 8, it copies nothing. We are not part of the backup or the transfer.
The one thing that leaves the device toward us
On iPhone, when you reach a milestone, the app increments a shared counter of how many people reached that milestone in that week and reads the total back. The record contains a count and nothing else. Two different people reaching the same milestone in the same week produce a byte-identical record. Totals under fifty are never displayed.
We consider this not to be consumer health data because it is not linked and not reasonably linkable to you: there is no identifier in the record, no field to put one in, and no other data of ours to join it against. We describe it here anyway rather than leaving you to discover it.
The Android app does not take part in this counter. Nothing leaves an Android phone toward us.
This website and email
getlimiter.com sets no cookies and runs no analytics. Vercel, which hosts it, receives your IP address and browser details with each request in order to deliver the page, and uses that traffic data under its own privacy notice to run and secure its service. We do not treat a page request as consumer health data: we never link it to a person, never use it to infer anything about anyone’s health, and never export or keep it.
If you email us, we receive your address and what you write, which may include health information you choose to tell us. Mail to getlimiter.com is forwarded by our domain registrar, Namecheap, to our email provider. We use it only to reply, share it with no one else, and delete it 90 days after the last message.
Sharing and selling
We do not sell consumer health data. We never have and there is no mechanism in this product to do so. We do not share it with advertisers, data brokers, analytics providers or anyone else. There are no third-party SDKs in either app beyond the platform’s own: Apple’s frameworks on iPhone; on Android, Android’s and the Kotlin language’s own libraries, and Google Play’s In-App Review library (com., with the three Google libraries it brings: com., com. and com.), which shows the Play Store’s own rating card. It adds no permission and no internet access, and the app passes it nothing but the request to show the card.
No employee or contractor of OB DATA LLC can access your health data, because it is not in any system we operate.
Your rights
Washington, Nevada and Connecticut residents have the right to know what consumer health data is collected, to access it, to withdraw consent, and to have it deleted. Because we hold none:
- Access — everything the app holds can be exported from inside it, free, at any time, without asking us.
- Deletion — “Delete everything” in the app removes the local database, the synced records and your iCloud zone; on Android, every record and setting the app keeps on the phone. Google’s encrypted copy, if the phone keeps one, is replaced at the phone’s next backup; uninstall and reinstall before then, and the old copy can come back. We cannot delete on your behalf because we have no copy.
- Withdraw consent — deleting the app ends everything. The milestone counter cannot be traced back to you, so there is nothing of yours left in it to withdraw.
- Appeal — if we decline a request, you may appeal to the address below, and you may contact the Washington Attorney General.
To exercise any of these, or if a request is refused: privacy@getlimiter.com.
Retention
The app sends us no consumer health data, so there is nothing of it to retain. Email you send us is deleted 90 days after the last message. Data on your device stays until you delete it or delete the app.
27 September 2026: updated for version 1.1 and for the Android app. The records version 1.1 adds are listed above and are all local-only; the Android app’s storage is described under How that is enforced.
28 September 2026: said what an iPhone backup holds and who holds its keys; added this website and email.
28 September 2026, for version 1.2: on Android, the phone’s own backup can now carry the app’s records to your Google account, only when the phone can encrypt them end to end. Said what it and a device-to-device transfer carry, and what Delete everything cannot reach in a backup. Named Google Play’s In-App Review library in the Android app. Added the dates you mark, which are local-only, and the app lock on Android.
Contact
OB DATA LLC — privacy@getlimiter.com