Privacy Policy
Effective Date: December 7, 2025
This privacy policy applies to the ByteSabre app (hereby referred to as "Application") for mobile devices that was created by Sabyasachi Pandey (hereby referred to as "Service Provider") as a Free service. This service is intended for use "AS IS".
Information Collection and Use
The Application collects information when you download and use it. This information is necessary to provide our recovery tracking services and ensure your data is securely stored and accessible across your devices.
Personal Information We Collect
When you use the Application, we collect the following personally identifiable information:
Account Information:
- Email address (required for authentication)
- User ID (automatically generated unique identifier)
- Name and profile picture (only if you choose to sign in with Google or Apple)
Health and Behavioral Data:
- Journal entries including daily recovery logs, relapse tracking, and planned activities
- Free-text notes (personal reflections you choose to add to journal entries)
- Mood ratings (great, good, okay, bad, terrible)
- Activity counts (busts count associated with journal entries and plans)
- Recovery/relapse statistics and trends (calculated from your journal data)
- Planned activities with free-text descriptions and dates
Technical Data:
- Session tokens and authentication credentials (stored locally on your device)
- Account creation and update timestamps
- Timezone (automatically synced from your device for accurate date tracking)
- Notification preferences (your push notification settings)
Device Permissions Data:
- Profile photos (only if you choose to upload a profile picture from your camera or photo library)
- Location data (approximate location used only for delivering relevant notifications; not stored on our servers)
Health Data Sensitivity
IMPORTANT: The journal entries and mood data you provide may contain highly sensitive health information related to addiction recovery. This information is protected with industry-standard security measures. However, you should be aware that you are entrusting us with sensitive personal health data.
What We Do NOT Collect
The Application does NOT collect:
- Your device's precise GPS location (we only use approximate location for notification targeting)
- Device identifiers or advertising IDs
- Payment information
- Contacts from your device
- Photos from your device (except profile pictures you explicitly choose to upload)
- Analytics or tracking data for advertising purposes
Note: Your IP address may be collected by our error tracking service (Sentry) for debugging purposes only. It is not used for advertising or user tracking.
How We Use Your Information
We use the collected information for the following purposes:
- Authentication: To create and manage your account using email OTP or OAuth providers
- Data Storage & Sync: To store your journal entries, plans, and recovery data securely in the cloud
- Recovery Tracking: To calculate statistics, trends, and insights about your recovery journey
- Service Communication: To send you one-time passwords (OTP) for account verification
- Account Management: To maintain your session and provide access to your data across devices
- Push Notifications: To send you helpful reminders and encouragement for your recovery journey (you can disable these at any time)
- Profile Personalization: To display your profile picture if you choose to upload one
- Error Tracking & Debugging: To identify, diagnose, and fix bugs, crashes, and performance issues through error reports and session replay recordings
We do NOT:
- Sell your personal data to third parties
- Use your health data for advertising
- Share your recovery data with anyone without your consent
- Send marketing emails or promotional content
Third-Party Services
The Application utilizes the following third-party services to provide our core functionality. Your data is subject to these services' privacy practices:
Backend Infrastructure
Supabase
- Purpose: Stores your account information, journal entries, plans, mood data, and all user-generated content. Handles user authentication and database operations.
- Privacy Policy: https://supabase.com/privacy
- Terms of Service: https://supabase.com/terms
- Data Shared: Email address, User ID, all journal entries, mood ratings, plans, and recovery statistics
Authentication Providers (Optional)
If you choose to sign in with Google or Apple instead of email OTP, your authentication is handled by these providers:
Google OAuth (Optional Sign-In Method)
- Purpose: Allows you to sign in using your Google account
- Privacy Policy: https://policies.google.com/privacy
- Terms of Service: https://policies.google.com/terms
- Data Shared: We receive your name, email address, and profile picture from Google only if you authorize it. We do NOT receive your Google password.
Apple Sign-In (Optional Sign-In Method)
- Purpose: Allows you to sign in using your Apple ID
- Privacy Policy: https://www.apple.com/legal/privacy/
- Terms of Service: https://www.apple.com/legal/internet-services/itunes/
- Data Shared: We receive your name, email address (or private relay email), and profile information only if you authorize it. We do NOT receive your Apple password.
Push Notification Service
OneSignal
- Purpose: Delivers push notifications for recovery reminders and encouragement
- Privacy Policy: https://onesignal.com/privacy_policy
- Terms of Service: https://onesignal.com/tos
- Data Shared: Device push token, approximate location (if enabled), notification preferences, and notification interaction data. We do NOT share your health data, journal entries, or personal recovery information with OneSignal.
Error Tracking and Crash Reporting
Sentry
- Purpose: Monitors application crashes, errors, and performance issues to improve app stability and user experience
- Privacy Policy: https://sentry.io/privacy/
- Terms of Service: https://sentry.io/terms/
- Data Shared: Error stack traces, IP address, session metadata, user identifier, email address, device information, and application context
- Session Replay: To help us identify and fix bugs, the Application records visual session replays (screen recordings of app interactions). Approximately 10% of normal user sessions and 100% of sessions where errors occur are recorded. These recordings capture your interactions with the app interface but do NOT capture keyboard input, passwords, or content you type in text fields.
- Note: Session replay data is used solely for debugging and improving the Application. It is not used for advertising or marketing purposes.
Device Permissions
Camera and Photo Library Access
- Purpose: Allows you to take or select a profile picture
- Data Handling: Photos you select are uploaded to Supabase storage. We only access your camera or photo library when you explicitly choose to update your profile picture.
- Note: This is entirely optional. You can use the app without providing a profile picture.
Location Access
- Purpose: Used by OneSignal to deliver relevant notifications based on your general area
- Data Handling: Only approximate location is used. Your precise GPS coordinates are NOT stored on our servers.
- Note: You can deny location permission and still use all core app features.
Legal Disclosure
The Service Provider may disclose User Provided and Automatically Collected Information:
- As required by law, such as to comply with a subpoena or similar legal process
- When we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request
- With trusted service providers (Supabase) who work on our behalf, do not have independent use of the information we disclose to them, and have agreed to adhere to industry-standard security practices
Data Storage and Security
Where Your Data Is Stored
Your data is stored on Supabase's secure cloud infrastructure. Session tokens and authentication credentials are stored locally on your device using encrypted storage (AsyncStorage).
Security Measures
The Service Provider is committed to safeguarding the confidentiality of your information. We implement:
- Encryption in transit: All data transmitted between your device and our servers uses HTTPS/TLS encryption
- Secure authentication: Industry-standard OAuth 2.0 and email OTP verification
- Access controls: Your data is only accessible to you when authenticated
- Trusted infrastructure: We use Supabase, a reputable cloud provider with enterprise-grade security
However, please note: No method of electronic storage or transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
Data Retention and Deletion
How Long We Keep Your Data
The Service Provider will retain your data for as long as you use the Application and for a reasonable time thereafter to comply with legal obligations.
Your Right to Delete Data
You have the right to request deletion of your personal data at any time. To delete your data:
- Contact us at support@bytesabre.com with your deletion request
- We will respond within a reasonable time (typically 30 days)
- Upon verification of your identity, we will permanently delete:
- Your account information
- All journal entries and notes
- All mood ratings and statistics
- All plans and activity data
- Session tokens and authentication data
Note: After deletion, this data cannot be recovered. We recommend exporting your data before requesting deletion.
Your Privacy Rights
Depending on your location, you may have the following rights:
General Rights
- Right to Access: Request a copy of the personal data we hold about you
- Right to Correction: Request correction of inaccurate personal data
- Right to Deletion: Request deletion of your personal data (see above)
- Right to Data Portability: Request your data in a portable format (contact us at support@bytesabre.com)
- Right to Withdraw Consent: Uninstall the app to stop all data collection
GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to object to processing
- Right to restriction of processing
- Right to lodge a complaint with a supervisory authority
CCPA Rights (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to opt-out of the sale of personal information (Note: We do NOT sell your data)
- Right to deletion
- Right to non-discrimination for exercising your rights
To exercise any of these rights, please contact us at support@bytesabre.com.
Opt-Out and Uninstall
You can stop all collection of information by the Application at any time by uninstalling it. You may use the standard uninstall processes available on your mobile device or via the App Store/Google Play Store.
Upon uninstallation:
- Local data (session tokens) will be removed from your device
- Your cloud data will remain on our servers until you request deletion
- You can reinstall the app and sign in to access your data again
To permanently delete all data, you must contact us at support@bytesabre.com.
Children's Privacy
The Application is intended for users who are at least 13 years of age. Given the sensitive nature of addiction recovery content, we recommend users be 18 years or older.
The Service Provider does not knowingly collect personally identifiable information from children under 13 years of age. If we discover that a child under 13 has provided personal information, we will immediately delete this information from our servers.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@bytesabre.com so we can take necessary action.
Medical Disclaimer
IMPORTANT: This Application is NOT a medical device and is NOT intended to diagnose, treat, cure, or prevent any disease or medical condition.
- The Application is a personal tracking tool for addiction recovery
- It is NOT a substitute for professional medical advice, diagnosis, or treatment
- Always seek the advice of qualified health providers with questions about medical conditions
- Never disregard professional medical advice or delay seeking it because of information in this Application
- If you are in crisis or experiencing a medical emergency, call emergency services immediately
Crisis Resources:
- National Suicide Prevention Lifeline: 988
- SAMHSA National Helpline: 1-800-662-4357
- Crisis Text Line: Text HOME to 741741
International Data Transfers
Your information, including personal data, may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
By using the Application, you consent to the transfer of your information to Supabase's servers and the processing of that information in accordance with this Privacy Policy.
Changes to This Privacy Policy
This Privacy Policy may be updated from time to time for any reason. We will notify you of any changes by:
- Updating the "Effective Date" at the top of this Privacy Policy
- Posting the new Privacy Policy in the Application
- Sending you an email notification (for material changes)
You are advised to review this Privacy Policy periodically for any changes. Continued use of the Application after changes constitutes acceptance of those changes.
Your Consent
By using the Application, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by us.
Contact Us
If you have any questions regarding privacy while using the Application, or have questions about our practices, please contact the Service Provider:
Email: support@bytesabre.com
Data Protection Inquiries: For questions about your data, deletion requests, or to exercise your privacy rights, email us at support@bytesabre.com with the subject line "Privacy Request."
We will respond to all legitimate requests within 30 days.
This privacy policy is effective as of December 7, 2025