This policy describes what we collect, what stays on your device, and what we do not collect. It is written to match the app as built. The in-app Privacy screen is a plain-language summary; this document is the full policy App Store and Play review require.
| Your slips, cravings, notes, plans, moods, debriefs, quiz answers, habit names, and anything you type | Stay on this device. Optional backup uses your iCloud, not our servers. We cannot read that data. |
| Account, email, name, phone, advertising ID | We do not create accounts and we do not ask for these. |
| Subscription | Charged by Apple or Google to your store account, not to an account with us. |
| Optional anonymous usage events | Sent to us only if you leave “Anonymous usage data” on. They never include what you are quitting or anything you typed. |
| Purchase confirmation | Our servers receive a store purchase token so we can confirm you paid. They do not receive your log. |
If this policy and the app ever disagree, the narrower description here wins — we will not collect a category this policy says we do not collect.
Ninth Minute is a habit tracker and urge timer. It is not a medical device, not treatment, not counselling, and not an emergency service. See the Terms of Use.
You must be 18 or older (or the age of majority where you live, if higher) to use the app.
Processed on device for the features you use. We do not receive it.
iCloud: If “Back up to your own iCloud” is on, Apple stores an encrypted copy in your iCloud account (iCloud.com.ninthminute.app). That is Apple’s service under Apple’s terms. We do not operate that container as a product database we can query. Turn backup off and the data stays on that phone. There is then no cross-device sync. That is deliberate.
Export / import: You may export an encrypted file protected by a passphrase you choose. We do not store that passphrase.
Delete everything: Removes habits, slips, plans, and settings from this phone and, if backup is on, from that iCloud backup. It cannot be undone. It does not cancel a store subscription (cancel in the App Store or Play Store).
Hosted in India (ap-south-1). We do not run user accounts.
On first launch the app creates a random install ID (UUID) on the device and sends it as X-Install-Id. It is not your name. We use it to remember coarse app version, platform, and store-locale region (two letters — not GPS); honour your telemetry opt-out; and bind a confirmed subscription to at most three installs (device replacement, not sharing).
X-App-Version, X-Platform, and a request ID for errors. We do not persist IP addresses.
When you buy or restore, the app sends the store’s purchase token and product ID so we can verify with Apple or Google. We store a hash of the token and subscription state in order to issue a short-lived entitlement token the app can check offline. We never receive your card number. Apple or Google is the merchant of record.
The app downloads public content bundles (question definitions, blocklists, crisis-resource listings, feature flags, paywall variant weights). These are not your personal log.
If “Anonymous usage data” is on, the app may send allow-listed events such as: onboarding screen ID (not answers); paywall variant and purchase started/completed/declined; that a question ID was shown or skipped — never the answer; that the blocker was enabled for a habit category (not a custom name); content bundle version; feature-flag exposure.
Timestamps are truncated to the minute. If you opt out, we discard events for that install on the server as well. We intend to keep raw events about 90 days.
We do not collect email, phone, name, government ID, precise location, contacts, photos, advertising identifiers, payment card data, or the contents of your habit log. We do not sell personal data. We do not use your log for advertising.
Legal bases (where a law requires one): performance of the contract (subscription), legitimate interests in running a secure anonymous service, and consent for optional telemetry.
We share server-side data only with Apple / Google (purchase verify), infrastructure processors in India, and authorities if legally required. We do not share your on-device log, because we do not have it. Crisis listings are third-party public resources.
All optional. The app works without them.
| Permission | Why | Sent to us? |
|---|---|---|
| HealthKit (sleep, read-only) | Slip debrief / on-device model | No (except your iCloud if backup is on) |
| Calendars (free/busy) | Empty-evening risk window | No |
| Notifications | Local reminders | No |
| Family Controls / Screen Time | Block apps/sites you picked | No |
| Face ID | Optional app lock | No |
| iCloud | Optional backup | Apple, not us |
Uninstalling does not cancel auto-renewal. Cancel in Apple Settings → Subscriptions or Google Play → Subscriptions.
The app is not directed at children. Do not use it if you are under 18 (or the higher age of majority where you live).
Servers are in India. Server-side fields in section 4 are processed in India.
We will post an updated date on this page. Material changes that expand collection will be reflected in the app and in store privacy labels.
Elixent Technologies Private Limited
privacy@ninthminute.app
support@ninthminute.app
This policy applies to the Ninth Minute iOS and Android applications and to api.ninthminute.app / cdn.ninthminute.app.