Legal

Privacy policy

Last updated: 1 September 2026 · Applies to the Ash iOS app and to this website.

In short

Ash asks for no name, no email and no password: an anonymous account is created automatically. The data you enter (cigarettes, cravings, mood) exists to make the app work and is never sold or passed to data brokers. Photo journal pictures stay on your phone. You can erase everything at any time.

  1. Who is responsible for your data
  2. The data Ash processes
  3. Why, and on what legal basis
  4. Who it is shared with
  5. How long it is kept
  6. Your rights, and how to use them
  7. Security
  8. Minors
  9. Changes
  10. Contact us

1. Who is responsible for your data

The data controller is Refacto Studio, the publisher of the Ash app.

  • Legal form: to be completed
  • Registered office: Bordeaux, France — address to be completed
  • Company number (SIRET): to be completed
  • Contact: contact@refacto.studio

2. The data Ash processes

2.1 Your anonymous account

On first launch, Ash creates an anonymous account for you: a random technical identifier (UUID), with no email, no password and no name. It exists to link your data across the app, the widgets and your subscription. That identifier alone does not tell us who you are.

2.2 What you enter in the app

This is the data that makes Ash work. It is stored on your device and synchronised with our database:

  • cigarettes logged, your daily limit and your quit date;
  • your cravings: intensity, time, trigger, outcome;
  • your daily journal: mood, energy, free-form notes;
  • your setup answers (smoking habits, pack price, goal);
  • your progress: missions, XP, badges, streaks;
  • your preferences: language, theme, reminders.

Some of this describes your tobacco use and your emotional state. It qualifies as health data under Article 9 GDPR. You enter it voluntarily and can erase it at any time.

2.3 Your photos

Two features use the camera or photo library, and they handle images differently:

  • Photo journal — the daily pictures you take are stored on your phone only. Ash neither uploads nor backs them up.
  • Future Mirror — to generate a projection of your face, the photo you pick is sent encrypted to our server, which relays it to the Google Gemini AI service for as long as it takes to produce the image. Neither Ash nor that service keeps the original photo afterwards. The feature is optional: without it, no photo ever leaves your phone.

2.4 Product analytics

To understand which screens help and which get in the way, Ash sends usage events (app opened, screen viewed, feature used, subscription screen shown) to PostHog, hosted in the European Union. These events are tied to your anonymous identifier. Session recording is disabled: we never replay what you do on screen.

2.5 Subscription

If you subscribe to Ash Premium, the purchase is handled by Apple. We receive its status (active, expired, trial), the product bought and a transaction identifier, through RevenueCat. We never see your payment method: it passes through neither Ash nor our servers.

2.6 Advertising measurement

Ash uses the TikTok Business SDK to tell whether an install came from one of our campaigns. On iOS this tracking is only enabled if you explicitly allow it in Apple’s App Tracking Transparency prompt. If you decline — or ignore it — no advertising identifier is sent, and measurement is limited to Apple’s aggregated, anonymous SKAdNetwork.

Ash shows no advertising and sells no data to advertisers.

2.7 Notifications

If you accept reminders, your device receives a notification token (issued by Apple via Expo) which we store in order to send them. Declining notifications blocks no other feature.

2.8 What Ash does not collect

  • No name, email, phone number or date of birth.
  • No contacts, no location, no microphone.
  • No Apple Health data.
  • No payment details.

3. Why, and on what legal basis

ProcessingPurposeLegal basis (GDPR)
Anonymous accountLet you use the app and find your data againPerformance of a contract (Art. 6(1)(b))
Tracking, journal, cravings, moodProvide tracking, statistics and the recovery timelineExplicit consent (Art. 9(2)(a)) — you enter this data voluntarily
Future MirrorGenerate the requested imageConsent (Art. 6(1)(a)) — optional feature, triggered by you
Product analyticsUnderstand usage and improve the appLegitimate interest (Art. 6(1)(f)) — aggregate measurement, no ad profiling
SubscriptionUnlock and manage Ash PremiumPerformance of a contract (Art. 6(1)(b))
Advertising measurementAttribute an install to a campaignConsent (Art. 6(1)(a)) — via App Tracking Transparency
NotificationsSend the reminders you switched onConsent (Art. 6(1)(a))

4. Who it is shared with

Ash sells, rents and trades no data. We rely on technical processors, each bound by a contract that forbids them from using your data for their own purposes:

ProcessorRoleData involved
SupabaseDatabase and application serversAnonymous account, tracking, journal, progress
PostHog (EU)Product analyticsUsage events, anonymous identifier
RevenueCatSubscription managementSubscription status, anonymous identifier
AppleDistribution, payment, notificationsPurchase, notification token
ExpoNotification deliveryNotification token
TikTokAdvertising measurement (if you allowed it)Device identifier, install or purchase event
GoogleFuture Mirror image generationThe photo sent, for the duration of processing

Some of these providers are established outside the European Union. Where that is the case, transfers rely on the European Commission’s standard contractual clauses or on an adequacy decision.

5. How long it is kept

  • Account and tracking data: for as long as you use Ash, then erased on request or when you reset the app.
  • Analytics events: 24 months at most.
  • Photo journal pictures: on your phone, for as long as you keep them. Uninstalling the app deletes them.
  • Future Mirror photo: for the duration of processing, then deleted.
  • Purchase records: for as long as accounting and tax obligations require.

6. Your rights, and how to use them

The GDPR gives you rights of access, rectification, erasure, restriction, objection and portability, plus the right to withdraw consent at any time.

Erase your data yourself, right now: in the app, open Settings and tap Sign out. This wipes all of your data on the device and returns Ash to its setup screen.

Erase the copy on our servers too: write to contact@refacto.studio. Because your account is anonymous, we will ask for a few details that identify it with certainty before deleting anything — that is what protects your data from someone else’s request. We reply within one month.

Withdraw consent to advertising measurement: iOS Settings → Privacy & Security → Tracking, then switch off the permission for Ash.

If our answer does not satisfy you, you may lodge a complaint with your national data protection authority — in France, the CNIL.

7. Security

Traffic between the app and our servers is encrypted in transit (TLS). Access to data is restricted by row-level security rules, so an account can only read its own rows. Third-party API keys stay server-side and are not bundled into the app.

8. Minors

Ash is not intended for people under 16 and does not knowingly collect their data. If you are the legal guardian of a minor using Ash, write to us and we will delete the account.

9. Changes

This policy may change along with the app. The last-updated date sits at the top of this page. A substantial change — a new purpose, a new recipient — will be flagged in the app before it takes effect.

10. Contact us

Any question about this policy or your data: contact@refacto.studio.