Primal is a self-help app for adults who want support changing compulsive pornography-use habits. Information about sexual behaviour, urges, symptoms, and recovery can be highly sensitive. This Privacy Policy explains what we collect, how we use it, when it is shared, and the choices available to you.
1. Who we are and when this policy applies
Primal is operated by Syed Khizer, an individual, trading as Functional Apps (“Primal,” “Functional Apps,” “we,” “us,” or “our”). Syed Khizer is the controller of the personal information described in this policy, except where another company acts as an independent controller under its own terms.
Operator: Syed Khizer, an individual, trading as Functional Apps
Privacy and support email: admin@functionalapps.org
This policy applies to the Primal iOS app, our related backend services, and support communications. It does not apply to third-party services you visit independently.
Where required by applicable consumer-health privacy law, our separate Consumer Health Data Privacy Policy provides additional disclosures and rights concerning recovery, sexual-health, and other consumer health data. That notice supplements this policy, is presented as a separate document, and is also available in the app from Settings → Legal.
2. The short version
- We collect account, recovery, subscription, technical, and—if you choose to use them—community, AI-coach, and support information.
- Journal entries and saved AI-chat history are designed to remain on your device. They are not synced to Primal's servers. Your device or Apple backup settings may still back up local app data.
- The current app uses Sign in with Apple. Apple may give us an Apple-specific identifier, a relay or account email address, and a name if you choose to share it.
- We do not ask you to tick a consent box. The Privacy Policy and Terms are linked on the welcome, paywall, and account screens, and all three policies are available from Settings → Legal. By choosing to enter recovery details into Primal after being shown this policy, you consent to Primal storing them.
- Community posts and replies are visible to other signed-in users together with your generated handle, streak, and arena information.
- We do not sell personal information or use recovery information for advertising. Apart from the optional Meta ad measurement described next, we do not track you across other companies' apps or websites.
- Meta ad measurement is optional and, where it is available in your version of the app, stays off unless you allow it both in Primal and in Apple's tracking prompt. If you allow it, Meta learns that you opened Primal and whether you started a trial or subscribed, and at what price, together with device identifiers (such as your advertising identifier and IP address) and a one-way hashed (“coded”) form of your account identifier. Meta never receives your answers, recovery records, journal, Leo or community messages, name, or email. Primal works exactly the same either way, and you can turn it off at any time in Settings → Privacy & data.
- Apple processes payments. We do not receive your payment-card number.
- Leo AI and Product analytics are off until you switch them on in Settings → Privacy & data. Purchasing or renewing paid access does not turn them on.
- Crash reports are always on so we can fix crashes. They never contain journal text, chats, your name, or your email. You can object by emailing admin@functionalapps.org.
- You can export your data as a JSON file and delete your account from inside the app. Deleting your Primal account does not cancel an Apple subscription.
- Primal is for adults aged 18 or older. We do not verify identity or ask an in-app age question; by using Primal or creating an account you confirm that you are 18 or older.
3. Information we collect
3.1 Account and profile information
We collect or create:
- a Firebase user identifier and authentication-provider information;
- your Sign in with Apple identifier and, if Apple provides them, your email address (including a private relay address) and name;
- a generated community handle;
- the name or nickname you enter in Primal;
- gender, the age range you select for when you first encountered pornography, and any optional demographic fields you choose to enter;
- onboarding status, goals, notification preference, and feature settings;
- versioned consent records for the Leo AI and Product analytics choices and, where it is available, the Meta ad measurement choice, described in Sections 3.8 and 6; and
- device push-notification tokens when notifications are enabled.
3.2 Assessment and recovery information
Depending on how you use Primal, we collect:
- onboarding assessment answers, severity score, reported symptoms, reasons for quitting, frequency, duration, triggers, perceived control, and escalation;
- quit date, original quit date, target, streak, and progress information;
- daily check-ins, including whether you stayed on track, mood, urge intensity, and an optional note;
- urge logs, including intensity, outcome, trigger, mood, tools used, blocker source, whether you were alone or stressed, and optional tags that you enter manually;
- relapse records, including date, streak, trigger tags, optional notes, and optional location labels that you type yourself;
- pledges, their outcomes, and optional notes;
- focus-session information, such as timing, intention, minutes, cycles, and completion; and
- achievements, experience points, tasks, and related progress state.
The location labels above are user-entered descriptions; Primal does not request GPS location permission in the current version.
3.3 Community information
If you use community features, we collect the posts, replies, photos, polls, votes, groups, reactions, blocks, and reports you submit. A bug-report post may also include your app and operating-system versions. We associate community activity with your account so we can display it, prevent abuse, and moderate the service.
When content is reported for possible child exploitation, self-harm, threats, or other serious safety violations, we may preserve the report, relevant content, account identifiers, timestamps, and moderation actions for investigation, safety, legal compliance, and cooperation with valid legal process.
Other signed-in users may see your generated handle, streak, arena, posts, replies, photos, polls, and other information you deliberately publish. Primal does not currently offer direct messages or friend relationships.
3.4 Purchases and subscriptions
The current iOS version offers paid access only through Apple's in-app purchase system. Before you confirm a purchase, Apple's purchase sheet displays the product, billing period, local price and currency, applicable trial or introductory offer, and renewal terms. Apple processes the payment and controls billing, renewal, cancellation, price-change notices, and refund requests. We do not receive your full payment-card number, security code, or Apple Account payment credentials.
Apple and our subscription-management provider, RevenueCat, provide us with subscription and entitlement information such as a Primal app-user identifier, product identifier, purchase, renewal, cancellation and expiration status, transaction identifiers, price and currency metadata, and refund or revocation status. RevenueCat helps us validate purchases, restore paid access, keep entitlement state consistent across supported devices, prevent purchase abuse, and troubleshoot billing-access problems. If you allow Meta ad measurement, RevenueCat also sends your trial and subscription events to Meta on our instruction, as described in Section 3.8.
We do not use purchase or subscription information to infer recovery status or to personalise recovery content, and purchasing does not opt you into optional analytics, AI processing, or Meta ad measurement. If you cancel an auto-renewing subscription, paid access normally continues until the end of the paid billing period, unless Apple applies a refund, revocation, billing failure, or another App Store entitlement change. Your Primal account and recovery information remain until you delete them under the controls described below.
Deleting Primal or your Primal account does not cancel an Apple subscription. You must manage or cancel the subscription separately through your Apple Account. The commercial subscription terms, including trials, renewals, cancellations, refunds, price changes, and lifetime access if offered, are described in the Primal Terms and Conditions.
3.5 AI-coach information
Leo, Primal's AI coach, is off until you enable the Leo AI toggle in Settings → Privacy & data. You must enable Leo AI in Settings → Privacy & data before the first message can be sent; until then the app refuses to send anything to an AI provider. Leaving Leo AI off disables Leo's off-device AI replies but does not prevent you from using unrelated Primal features.
When you send Leo a message, the message you type, up to the last eight turns of that conversation, and a short recovery context (such as your current streak length) are sent to our Firebase Function and then to OpenRouter. OpenRouter routes the request to an eligible third-party inference host running OpenAI GPT-OSS-120B, an open-weight model developed by OpenAI, to generate the response. OpenAI is the model developer and licensor. Under this OpenRouter deployment, we do not represent that OpenAI receives message content unless the configured inference host changes to an OpenAI-operated service. Your name, email address, account identifier, and journal entries are never included in a Leo request.
Your saved Leo conversation history is stored locally on your device and is not synced to Primal's database. Our backend records operational metadata for each request—a request identifier, timestamp, token counts, and your account identifier—in Google Cloud Logging for 30 days, but is designed not to log message text or reasoning traces. Primal requests OpenRouter routes that require parameter support, Zero Data Retention, and no provider data collection. OpenRouter and the eligible inference host nevertheless process message text under their applicable contractual terms. Do not include information in an AI prompt that you do not want those processors to receive.
Leo can be inaccurate and is not a therapist, clinician, or emergency service.
3.6 Blocking and DNS-filter information
Primal's Screen Time blocker uses Apple's Family Controls framework. Apple provides the app with opaque selection tokens. Primal cannot read the names of the apps or websites represented by those tokens, and the tokens stay on your device.
When protection is enabled, Primal automatically applies Apple's adult website filter and any custom websites you add. You can also choose apps and app categories to shield. The adult website filter is part of protection by default and is not a separate setting. No blocker can identify or prevent all unwanted content.
The DNS filter feature currently runs in a limited mode that does not route your queries to any external DNS vendor. We store the filter's enablement state and a credential in the iOS Keychain needed to operate the feature. If an external DNS provider is enabled in a future version, we will name it in this policy first. We do not use DNS information for advertising.
3.7 Device, usage, and diagnostic information
We and our service providers collect technical information needed to operate and secure Primal, such as:
- app version, operating-system version, device model, locale, and time zone;
- Firebase and app-installation identifiers, authentication and App Check tokens, IP address, request time, and security signals;
- your device's advertising identifier (IDFA), its vendor identifier (IDFV), and Meta's anonymous install identifier, only if you allow Meta ad measurement (Section 3.8);
- product interaction and feature-usage events, only if you enable product analytics;
- crash reports, stack traces, performance information, and diagnostic state; and
- push-token and notification-delivery information.
Crash reports. Primal uses Firebase Crashlytics for crash diagnostics. Crash reports are always on so we can find and fix crashes; there is no in-app switch for them. A crash report contains the crash stack trace, device model, operating-system and app version, and a Crashlytics installation identifier. It never contains journal text, chats, your name, or your email address, and it is not linked to your name or email. We rely on our legitimate interest in keeping the app working (see Section 6). If you object to crash reporting, email admin@functionalapps.org.
Product analytics. If you enable the Product analytics toggle in
Settings → Privacy & data, we use PostHog (EU-hosted) for a small allow-listed
set of product-funnel events: app launch, neutral numbered onboarding-step views,
onboarding completion, paywall view, purchase start and completion, restore
completion, and account sign-in. Onboarding-step events include only the flow
version, neutral step code, step number, and total number of steps—not the screen
topic or your response. Primal does not send PostHog your Firebase user ID, name,
email, recovery activity, notes, AI conversations, community content, or any free
text. PostHog screen capture, session replay, screen/element autocapture, surveys,
push capture, person profiles, and error capture are disabled. The PostHog
identifier is random, is not linked to a Primal account identifier, and is rotated
when you sign out. Every accepted event includes the mandatory qp_environment
value development, beta, or production, so the shared EU project can keep test
and production insights separated. We do not use this analytics data for
third-party advertising or cross-company tracking.
Advertising measurement. The app includes Meta's software development kit (SDK), which is used only for the optional Meta ad measurement described in Section 3.8. Unless that measurement is available in your version of the app and you allow it, the SDK is not started and Primal shares nothing with Meta.
3.8 Advertising measurement (Meta), optional
Meta ad measurement helps us understand which of our ads on services run by Meta Platforms (“Meta”) lead people to install Primal, start a trial, or subscribe. It is optional, it is off unless you allow it, and it exists only where it is available in your version of the app. In a version where it is not available, Primal does not start Meta's SDK, does not show the onboarding screen, Apple's tracking prompt, or the settings switch described below, and shares nothing with Meta. Declining or withdrawing never affects your access to Primal, your paid subscription, or any feature.
When Primal shares anything with Meta. Primal shares nothing with Meta unless all three of the following are true, and sharing stops as soon as any of them stops being true:
- Meta ad measurement is available in your version of the app;
- you have allowed Meta ad measurement in Primal, which we store as a consent record
for this purpose (notice version
2026-09-24); and - Apple's App Tracking Transparency (ATT) permission for Primal is set to Allow.
How we ask. Where Meta ad measurement is available, an optional screen headed HOW DID YOU FIND US? appears once during onboarding, immediately before the paywall, but only if iOS has never shown Primal's tracking prompt and you have not already made a choice. It lists what Meta learns if you allow it (“That you opened Primal”; “Whether you start a trial or subscribe, and the price”; “Device identifiers (like your advertising ID and IP address) and a coded account ID”) and what is never shared (“Your answers, symptoms and reasons”; “Streaks, urges, relapses and journal”; “Leo and community messages, your name and email”). It says that Primal works exactly the same either way and that you can change your choice in Settings → Privacy & data. Its only button, Continue, shows Apple's tracking prompt, which reads: “If an ad brought you here, this lets Meta tell Primal which one. Meta learns that you use Primal and whether you start a trial or subscribe. Your answers, streaks, urges, journal and messages are never shared.” Choosing Allow records your consent; choosing Ask App Not to Track records that you declined. You can change your choice at any time with the Meta ad measurement switch in Settings → Privacy & data (see Section 10).
Your choice is stored on your device and, when you are signed in, recorded on our server with the purpose, your decision, the notice version, and a server timestamp. A choice you make before creating an account carries over to the new account.
What Meta receives from the app. Only while all three conditions are met, Primal starts Meta's Facebook Core SDK on your device. The SDK then sends Meta:
- an app-activation (“app opened”) event each time you open Primal or bring it to the foreground;
- Meta's anonymous install identifier;
- your device's advertising identifier (IDFA); the SDK's collection of it is switched on only while all three conditions are met; and
- the limited technical device, app, and network information that Meta's SDK attaches to such requests, such as device model, operating-system and app version, and IP address.
The SDK's automatic App Events and automatic purchase logging are switched off in the app, Meta's codeless event setup is not enabled for Primal, and Primal does not log purchase, onboarding, recovery, or any other custom events to Meta. While it is running, Meta's SDK may also update Apple's SKAdNetwork measurement values and use Meta's Aggregated Event Measurement.
What Meta receives through RevenueCat. Only while all three conditions are met, the app also gives RevenueCat, our subscription-management provider, four identifiers: your device's advertising identifier, its vendor identifier (IDFV), your IP address, and Meta's anonymous install identifier. On our instruction, RevenueCat then sends Meta your subscription events directly from its servers: trial started (“StartTrial”); trial converted, first purchase, and renewal (“Subscribe”); and non-renewing purchase (“fb_mobile_purchase”). These events can be sent while the app is closed—for example, when a subscription renews months later. According to RevenueCat's published field mapping, each event carries, where available: the advertising identifier; Meta's anonymous install identifier; a one-way hashed form of your RevenueCat app-user identifier, which in Primal is our internal account identifier (before you create an account, RevenueCat uses a random identifier instead); your IP address; the transaction amount in US dollars; an order identifier; the product identifier; the event time; and app and device information, such as the vendor identifier. We do not give RevenueCat your email address, phone number, or name for this purpose and do not use Meta's “Advanced Matching”, so none of them is sent to Meta.
How Meta uses it. Meta uses this information to measure and optimise our advertising on Meta's services—for example, to show which ads led to installs, trials, and subscriptions. Meta also applies its own terms and data policy to the information it receives. Separately, Apple's privacy-preserving SKAdNetwork system may report aggregated, anonymised campaign results to Meta; those reports come from Apple, not from Primal, and do not identify you.
Why we treat this as sensitive. Primal is a recovery app for compulsive pornography use, so the mere fact that you use Primal, start a trial, or subscribe can reveal information about your health or sex life. We treat it that way: as consumer health data under our Consumer Health Data Privacy Policy and, for UK and EEA users, as potentially special-category data. We share it with Meta only with your consent (for UK and EEA users, your consent and explicit consent; see Section 6). Your recovery information—answers, symptoms, reasons, streaks, urges, relapses, journal, Leo conversations, and community content—is never used for advertising and never sent to Meta.
Withdrawing. Turn off Settings → Privacy & data → Meta ad measurement, or turn off tracking for Primal in iOS Settings → Privacy & Security → Tracking; Primal detects the iOS change the next time you open it or bring it to the foreground. When you withdraw, the app stops the SDK's access to your advertising identifier, stops sending activation events, and asks RevenueCat to delete the four identifiers it holds for you. RevenueCat does not send your events to Meta while Apple's tracking permission for Primal is anything other than Allow, so turning off tracking in iOS Settings is the most complete way to stop future events. If you turn the switch off in Primal while iOS still allows tracking, Primal tells you this and links to iOS Settings. Withdrawing does not delete information Meta has already received (see Section 11).
3.9 Support, feedback, and legal communications
When you contact admin@functionalapps.org or submit a bug report, we collect your email address, message, attachments, and any app or device details you include. We use that information to respond, troubleshoot, protect the service, and keep appropriate business records.
3.10 Information designed to remain on your device
Journal entries, saved AI-chat history, Screen Time selection tokens, local app preferences, and some local activity records are designed to stay on your device and are not uploaded to Primal's servers. The live camera mirror used by a grounding feature is not recorded, stored, or uploaded by Primal. There is no Home Screen widget in the current build.
Local information can still be included in an encrypted or unencrypted device backup depending on your iOS and Apple backup settings. Deleting the app normally removes its local data from that device, but it does not necessarily remove an existing device backup.
The current storage design is:
| Data | Primary location |
|---|---|
| Raw onboarding audit row, journals, saved Leo history, Screen Time tokens, preferences | Device |
| Profile, onboarding answers/symptoms/severity/reasons, check-ins, urges, relapses, pledges, focus, achievements, blocking state | Device and Firebase |
| Authentication, community content, reports, votes, push tokens, consent records, subscription state | Firebase |
| Community photos | Firebase Storage |
| Leo request and up to eight recent turns | Firebase Function → OpenRouter → eligible inference provider (only when Leo AI is on) |
| Crash reports | Firebase Crashlytics (always on) |
| Optional product analytics | PostHog EU (only when Product analytics is on) |
| Optional Meta ad measurement: app-opened events, trial and subscription events, and device identifiers | Device → Meta, and RevenueCat → Meta (only where available and only while you allow it; see Section 3.8) |
3.11 Sensitive recovery information
Much of the information in Sections 3.2, 3.3, and 3.5 reveals sexual behaviour or health-adjacent recovery information and is treated as sensitive. We collect it only to provide the recovery service you ask for. Sensitive recovery information is never sold, never used for advertising or profiling, and never shared with data brokers.
The fact that you use Primal, and whether you start a trial or subscribe, can itself reveal that you are seeking support for compulsive pornography use. We treat that information as sensitive too and share it with Meta only if you allow Meta ad measurement (Section 3.8).
4. How we obtain information
We obtain information:
- directly from you when you register, complete onboarding, track progress, post, use Leo, or contact support;
- automatically from the app and device when you use Primal;
- from Apple for authentication, purchases, subscription status, and push delivery;
- from RevenueCat for subscription management; and
- from other users when they interact with or report community content.
We do not obtain information about you from Meta or other advertising networks. If Meta ad measurement is in use, we see only aggregated reports about how our advertising performed, not information about you.
5. How we use information
We use personal information to:
- create and secure your account;
- sync your progress across supported devices;
- provide check-ins, insights, streaks, goals, blocking tools, AI replies, community features, and notifications;
- process purchases, restore access, and manage entitlements;
- personalize the experience based on the information you provide;
- operate, test, troubleshoot, and improve Primal;
- if you allow Meta ad measurement where it is available, measure and optimise our advertising on Meta's services, such as which ads lead to installs, trials, and subscriptions (Section 3.8);
- detect abuse, moderate content, enforce our Terms, and protect users;
- respond to support, privacy, and legal requests;
- comply with law and establish, exercise, or defend legal claims; and
- send important service or policy notices.
We do not use your recovery information to determine eligibility for employment, housing, credit, insurance, or similar decisions.
5.1 Automated insights
Streak counts, insights, arena levels, achievements, and reminder timing are calculated automatically from the information you enter. This logic is simple rule-based processing that runs to show you your own progress. It is not a medical evaluation, does not diagnose anything, and does not produce decisions that have legal or similarly significant effects on you.
6. Legal bases for UK and EEA users
Where UK or EEA data-protection law applies, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Creating an account, syncing progress, providing requested features, and managing purchases | Performance of our contract with you |
| Storing and syncing information about sexual behaviour or health-adjacent recovery information to provide the assessment and recovery features you request | Your explicit consent (GDPR / UK GDPR Article 9), given by choosing to enter that information into the app after being shown this policy, and performance of our contract with you |
| Sending Leo messages to AI providers | Your consent, given by enabling Leo AI in Settings → Privacy & data, and performance of the feature you request |
| Optional notifications and similar choices | Consent where required |
| Crash reports and essential service diagnostics | Our legitimate interests in keeping the app working, balanced against your rights; you may object by emailing admin@functionalapps.org |
| Security and fraud prevention | Our legitimate interests, balanced against your rights |
| Optional PostHog product analytics | Your consent, given by enabling Product analytics in Settings → Privacy & data |
| Optional Meta ad measurement, where available (Section 3.8) | Your consent and, because the fact that you use or subscribe to Primal can reveal information about your health or sex life, your explicit consent (GDPR / UK GDPR Article 9), given by choosing Allow in Apple's tracking prompt after our explanation, or by turning on Meta ad measurement in Settings → Privacy & data and allowing tracking |
| Moderation, safety, and legal requests | Legitimate interests and/or legal obligation |
| Tax, accounting, and regulatory records | Legal obligation |
How consent works in Primal. We do not ask you to tick a consent box. The Privacy Policy and Terms are linked on the welcome, paywall, and account screens, and all three policies are available from Settings → Legal. Your explicit consent to our storing health-related recovery information is given by choosing to enter that information into the app after being shown this policy. You can withdraw it at any time by deleting the relevant entries or by deleting your account.
Leo AI and Product analytics are separate opt-in toggles in Settings →
Privacy & data and are off by default. Meta ad measurement, where available,
is also off unless you allow it, and it needs both your choice in Primal and Apple's
tracking permission (Section 3.8). Each choice is stored as a versioned consent
record that notes the version of the notice for that choice: currently 2026-09-05
for Leo AI and Product analytics and 2026-09-24 for Meta ad measurement. If the
notice for a choice changes materially, your earlier choice stops counting and that
processing stays off until you choose again. Crash reports are always on and are
not a toggle; you may object by emailing admin@functionalapps.org. None of these
choices is bundled with a purchase. You may withdraw an optional consent for future
processing at any time without affecting processing already performed or your paid
access.
7. How we disclose information
We do not sell personal information or disclose recovery information for advertising. If you allow Meta ad measurement where it is available, we disclose the limited information described in Section 3.8 to Meta for advertising measurement. Some US state privacy laws may treat that as “sharing” for cross-context behavioural advertising or as “targeted advertising”; you can opt out at any time as described in Section 10. We disclose information only to the recipients below, and only for the stated purposes.
- Google Firebase / Google Cloud (Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging, App Check, Cloud Logging). Receives your account identifiers, all synced records described in Section 3, community photos, push tokens, and device attestation signals. Hosted in the United States. Google acts as our processor.
- Firebase Crashlytics. Receives crash stack traces, device model, operating-system and app version, and an installation identifier. Never receives journal text, chats, your name, or your email. Always on; you may object by emailing admin@functionalapps.org.
- PostHog (EU). Receives only allow-listed funnel events with a random identifier, never recovery content or free text, and only while the Product analytics toggle is on.
- OpenRouter → OpenAI GPT-OSS-120B on a zero-data-retention-eligible inference host. Receives the Leo message you type plus up to the last eight turns of that conversation and a short recovery context such as streak length. Never receives your name, email, account ID, or journal entries. Only while the Leo AI toggle is on. OpenAI is the model developer and licensor and is not represented as receiving prompts under the current third-party hosted route.
- RevenueCat. Receives App Store transaction identifiers and entitlement status keyed by your account ID. Only if you allow Meta ad measurement, it also receives your device's advertising identifier, vendor identifier, IP address, and Meta's anonymous install identifier, and on our instruction sends your trial and subscription events to Meta (Section 3.8). Never receives recovery content.
- Meta Platforms, only if you allow Meta ad measurement where it is available. Receives from the app an “app opened” event each time you open Primal, Meta's anonymous install identifier, your device's advertising identifier, and limited technical device, app, and network information such as IP address; and receives from RevenueCat your trial and subscription events with the transaction amount, those identifiers, your device's vendor identifier, and a one-way hashed form of your account identifier (Section 3.8). Never receives recovery information, your name, email address, or phone number. Meta uses this information to measure and optimise our advertising and applies its own terms and data policy to it.
- Apple. App Store purchases and refunds, Sign in with Apple, push-notification delivery, and Screen Time / Family Controls, which stays on your device. Apple acts as an independent controller under its own privacy terms.
- DNS-filter provider. The DNS filter feature currently runs in a limited mode that does not route your queries to any external DNS vendor. If an external provider is enabled, we will name it here first.
- Other community members. Your handle, arena level, streak days, and what you post are visible to other signed-in users.
- Professional advisers and authorities. Information reasonably necessary for legal, audit, compliance, safety, or claims purposes.
- Transaction participants. Information necessary for a business transfer as described in Section 17.
We require service providers acting on our behalf to process information only for authorised purposes and to provide the same or an equivalent level of protection as described in this policy and required by Apple's App Review Guidelines. Some recipients, such as Apple and Meta, may also act as independent controllers under their own terms and privacy notices.
8. International transfers
Primal's Firebase backend currently runs in the United States, including the
us-central1 region. Other providers may process information in the United States or
other countries. Where required, we use recognised transfer mechanisms such as the
European Commission's Standard Contractual Clauses, the UK International Data
Transfer Addendum, or an adequacy decision. You may contact us for information about
the safeguards relevant to your data.
If you allow Meta ad measurement, the information described in Section 3.8 is sent to Meta Platforms, Inc. and its affiliates, which process it in the United States and other countries. Where required, those transfers rely on the mechanisms described above and on Meta's own transfer mechanisms.
9. Retention
We keep personal information only for as long as reasonably necessary for the purposes described above, including security, legal, tax, accounting, and dispute requirements.
| Information | Retention |
|---|---|
| Private recovery records (profile, assessment, check-ins, urges, relapses, pledges, focus sessions, tasks, achievements, blocking state, settings) | For as long as your account exists; deleted when you delete your account |
| Consent records for the Leo AI and Product analytics toggles and, where available, the Meta ad measurement choice | With your account; deleted when you delete your account |
| Community posts, replies, photos, polls, votes, reactions, and groups you authored | Until you delete the content or your account |
| Abuse reports and moderation-queue records | Anonymised when the reporter's or subject's account is deleted (see Section 11), then kept for up to 24 months after anonymisation |
| Crashlytics crash reports | Up to 90 days (Google's default); not linked to your name or email |
| PostHog product analytics, only if you enabled it | Up to 12 months; not linked to a Primal account identifier |
| Leo AI request operational metadata (request id, timestamp, token counts, account ID) in Google Cloud Logging | 30 days |
| App Store / RevenueCat webhook idempotency records | 90 days |
| Meta ad-measurement identifiers held by RevenueCat (advertising identifier, vendor identifier, IP address, Meta anonymous install identifier), only if you allowed Meta ad measurement | Until you withdraw, when the app deletes them, or until you delete your account |
| Information Meta has received through Meta ad measurement | Kept by Meta under its own terms and policies; Primal cannot delete it (see Section 11) |
Legacy public-chat archive from a removed feature (chatRooms) |
Inaccessible in the app; will be permanently deleted no later than 31 December 2026 |
| Support and legal communications | For the time needed to resolve the matter and maintain reasonable business/legal records |
| Purchase, tax, and transaction records | For the period required by applicable law and platform requirements |
| iOS Keychain items (session and DNS-filter credentials) | Until you delete your account or uninstall the app |
| Local-only information and device backups | Until you delete it or the app; backups are under Apple's and your device's control |
Deleting the app normally removes its ordinary sandbox data, including SwiftData, local JSON files, saved Leo history, journals, Screen Time tokens, and preferences. Uninstalling does not submit an account-deletion request and does not delete Firebase, community, subscription-provider, or other cloud records. iOS Keychain credentials may survive uninstall. Use the in-app deletion path in Section 11 to delete cloud and provider records as well. Uninstalling also does not withdraw Meta ad measurement: if you allowed it, RevenueCat keeps the identifiers described in Section 3.8 and can continue to send renewal events to Meta while your subscription renews, until you withdraw in the app or delete your account.
When deletion cannot happen immediately because information remains in encrypted backups, we isolate it from ordinary use and delete or overwrite it on the backup cycle, unless law requires preservation.
10. Your choices and rights
Depending on where you live, you may have rights to:
- know whether we process your personal information and access a copy;
- correct inaccurate information;
- delete information;
- obtain a portable copy of information you provided;
- restrict or object to certain processing;
- withdraw consent for future processing;
- opt out of the sale of personal information, of “sharing” for cross-context behavioural advertising, or of targeted advertising (we do not sell personal information; Meta ad measurement, if you allow it, may count as sharing or targeted advertising under some US state laws, and you opt out by turning it off as described below); and
- appeal a decision or complain to your local data-protection authority.
In the app. Export and deletion are available without contacting us:
- Export my data: Settings → Privacy & data → Export my data produces a JSON file containing all of your local records and your server records. The stored Apple credential is redacted from the export.
- Delete my account: Settings → ACCOUNT → Delete my account opens the Privacy & data screen; tap Delete my account there and choose Delete now or Delete after 24 hours (which can be cancelled). See Section 11.
- Privacy toggles: Settings → Privacy & data lets you turn Leo AI and Product analytics on or off at any time. Turning a toggle off stops new collection and does not remove paid access. Crash reports have no toggle; to object, email admin@functionalapps.org.
- Meta ad measurement: where it is available, the Meta ad measurement switch in Settings → Privacy & data shows whether measurement is actually active: it is on only when you have allowed it in Primal and iOS tracking permission for Primal is Allow. Turning it on shows Apple's tracking prompt if iOS has not asked before; if you previously declined tracking, it opens iOS Settings instead, because only iOS can grant tracking permission. Turning it off records that you withdrew. You can also turn off tracking for Primal in iOS Settings → Privacy & Security → Tracking; Primal detects this the next time you open it or bring it to the foreground. Either way, sharing stops as described in Section 3.8, and this is how you opt out of any “sharing” or targeted advertising. If you can no longer use the app (for example, after uninstalling it), you can also withdraw by emailing admin@functionalapps.org: we will ask RevenueCat to delete the identifiers it holds for your account, or, if you prefer, delete your account, which deletes your RevenueCat record and stops any further events. If you have a Meta account, Meta's own privacy tools, such as Your activity off Meta technologies in your Meta account settings, let you review and manage activity that businesses share with Meta.
You can also change certain profile and notification settings in the app, disable notifications in iOS Settings, and delete individual community content where the feature allows.
By email. Correction, restriction, objection, and portability requests, and requests to delete previously collected analytics data where applicable, are handled by emailing admin@functionalapps.org. We may need to verify your identity before completing a request. We will respond within the period required by applicable law.
Complaints. If you are in the UK, you may complain to the Information Commissioner's Office (ico.org.uk). If you are in the EEA, you may complain to the supervisory authority where you live or work. You may also contact us first so we can try to resolve the issue.
11. Account deletion
How to delete. Go to Settings → ACCOUNT → Delete my account, which opens the Privacy & data screen. Tap Delete my account and choose Delete now or Delete after 24 hours. If you choose the 24-hour option you can cancel the request from the same screen before the deadline. Deletion then runs on our servers immediately, or after the grace period through an hourly scheduler.
What is deleted on our servers. The deletion process:
- revokes your Sign in with Apple token;
- deletes your RevenueCat subscriber record, including any identifiers stored there for Meta ad measurement;
- releases the DNS-filter vendor profile, if one was created;
- deletes all private records under your account: check-ins, pledges, relapses, urge logs, activity, focus sessions, tasks, achievements, coach conversations, push tokens, settings, blocking state, experience points, subscription mirror, groups, poll votes, blocks, and consent records;
- deletes the community posts and replies you authored, including their photos in Cloud Storage, reactions, poll votes, and impressions;
- removes the strength votes, poll votes, and impressions you made on other people's content, and repairs the affected counts;
- releases your public handle and deletes your public profile;
- deletes purchase-claim records; and
- finally deletes your Firebase Authentication account.
If a provider step (Apple, RevenueCat, or the DNS vendor) keeps failing, deletion retries hourly for up to 24 attempts and then completes anyway. In that case we keep an internal failure record so we can follow up with the provider manually.
Information already received by Meta. If you allowed Meta ad measurement, deleting your account removes the identifiers RevenueCat held for it and clears your consent record, but Primal cannot delete information that Meta has already received; Meta holds it under its own terms and policies. If you have a Meta account, you can use Meta's own privacy tools, such as Your activity off Meta technologies in your Meta account settings.
What is anonymised rather than deleted. Abuse reports and moderation-queue records that reference your account—whether you were the reporter or the subject—are not deleted. They are anonymised: user identifiers are replaced with “deleted”, any content fields are removed, and only the reason, status, outcome, and timestamps are kept. We retain these anonymised records for safety, enforcement, and dispute resolution for up to 24 months. Their internal record identifiers may still contain the former opaque account ID, which no longer maps to any account after deletion.
What is cleared on your device. When deletion completes, the app clears the account's local database, local JSON caches (blocking state, community drafts, and Leo history), account-scoped preferences and consent records, Screen Time shields, the DNS-filter credential in the Keychain, and the signed-out onboarding store. If you no longer have the app, delete its local data and relevant device backups through your Apple settings. Signing out (without deleting) keeps the local database on the device but removes Screen Time shields until you next sign in.
Deleting your Primal account or the app does not cancel an Apple subscription. Manage or cancel subscriptions in your Apple Account subscription settings.
12. Security
We use safeguards designed for the sensitivity of the information we process, including TLS in transit, platform authentication, access-control rules, server-side validation, Apple Keychain storage for session credentials, and Firebase App Check. Access is limited to people and providers who need it for authorised purposes.
No method of storage or transmission is completely secure. Please use a protected device and contact admin@functionalapps.org if you believe your account or data is at risk.
12.1 Security incidents
If we become aware of a security incident affecting your personal information, we will investigate it, take steps to contain and mitigate it, and notify you and the relevant authorities where applicable law requires. Depending on the situation we may notify you by email, by a notice in the app, or by a notice on our website.
13. Adults only
Primal is intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has used Primal, contact admin@functionalapps.org so we can investigate and delete the information where appropriate.
We do not verify identity, use age-assurance technology, or ask an in-app age question. By using Primal or creating an account you confirm that you are 18 or older; the 18+ restriction is a condition of using the Service, as stated in the Terms and Conditions, and your use is a representation that you meet it.
14. Child safety
Primal has zero tolerance for child sexual abuse material, child sexual exploitation, grooming, trafficking, or any content or conduct that sexualises, exploits, endangers, or harms a minor. Users can report content and accounts through the in-app tools or by emailing admin@functionalapps.org.
We may remove content, restrict or terminate accounts, preserve evidence where lawful, and make reports to competent authorities or child-safety organisations when required or permitted by law. We disclose only information reasonably necessary for the safety, investigation, or legal purpose. Primal does not promise continuous or real-time monitoring.
15. Health and emergency notice
Primal is a self-help tool, not a healthcare provider, medical device, therapist, or emergency service. We do not monitor the app for emergencies. If you may harm yourself or someone else, contact local emergency services or an appropriate crisis service immediately.
16. Emails we send
The only emails Primal sends are:
- transactional emails from Firebase Authentication, such as sign-in links, address verification, or password-reset messages where applicable to your sign-in method; and
- replies to support, privacy, or legal requests you send to admin@functionalapps.org.
We do not send marketing email and there is no mailing list to unsubscribe from.
17. Business transfers
If Primal is sold, merged, reorganised, financed, or its assets are transferred, your personal information may be transferred to the successor. Any successor will be bound by this policy for the information transferred, or we will give you notice of any material change in how your information is handled and, where required, ask for your consent.
18. Changes to this policy
We may update this policy as Primal, our providers, or the law changes. We will change the “Last updated” date and provide additional notice in the app when a change is material or consent is required. If we need personal information for a materially different purpose, we will provide notice and seek consent where required.
19. Contact us
Syed Khizer, an individual, trading as Functional Apps
Email: admin@functionalapps.org
20. Privacy summary
- Primal is run by Syed Khizer, an individual trading as Functional Apps; contact admin@functionalapps.org.
- Primal is for adults 18+. We do not verify identity or ask an in-app age question; by using Primal you confirm you are 18 or older.
- You consent to Primal storing your recovery details by choosing to enter them after being shown this policy (linked on the welcome, paywall, and account screens); withdraw by deleting entries or your account.
- Journal entries and Leo chat history stay on your device.
- Recovery records sync to Firebase (US) and are deleted when you delete your account.
- Leo AI and Product analytics are off until you turn them on in Settings → Privacy & data; Crash reports are always on and you can object by emailing admin@functionalapps.org.
- Leo requests carry your message, up to eight recent turns, and a short recovery context—never your name, email, account ID, or journal.
- Meta ad measurement is optional and, where available, off unless you allow it in Primal and in Apple's tracking prompt. If you allow it, Meta receives app-opened events and, through RevenueCat, your trial and subscription events, with device identifiers and a hashed account identifier—never recovery information. Turn it off in Settings → Privacy & data or in iOS Settings → Privacy & Security → Tracking.
- The DNS filter does not currently send your queries to any external DNS vendor.
- Recovery information is never sold, never used for advertising or profiling, and never shared with data brokers.
- Other community members can see your handle, arena level, streak days, and what you post.
- Export your data as JSON and delete your account in-app; deletion runs immediately or after a cancellable 24-hour grace period, and does not cancel an Apple subscription.
- After deletion, only anonymised moderation records remain with us, for up to 24 months. Primal cannot delete what Meta has already received through Meta ad measurement.
- The only emails we send are authentication emails and replies to your requests.