Gambling Guardian Privacy Policy
Effective Date: August 2, 2026
Gambling Guardian is a recovery-support app that helps people who are quitting gambling track their progress, understand triggers, and stay accountable to their own goals. It is not a gambling app, does not facilitate gambling in any way, and contains no gambling content. This Privacy Policy explains what recovery information the app stores, the specific, limited situations where information can leave your device, and the choices you have.
1. Summary
Gambling Guardian is local-first and account-free. Your recovery information — session history, check-ins, urges, spending and savings estimates, Guardian Mode and Lockdown settings, and personal notes — is stored only on your device. "Stored locally" does not mean this information can never leave the device: your device's own encrypted backup may include it, an explicit export or share action you choose to trigger will hand a copy to a destination you pick, and external support links open your browser. We have no developer backend, and none of this recovery information — including your Guardian Mode/Plan choices, Lockdown state, schedules, Risk Autopilot suggestions, barrier confirmations, or PIN — is ever sent to RevenueCat, our subscription provider, which only ever receives the limited purchase information described in Section 6. Each of these situations is described below.
2. Information Stored on Your Device
Gambling Guardian does not require an account, sign-up, login, or email address. Depending on how you use the app, it stores the following locally, in a database on your device:
- Recovery session start and end times, how a session ended, and its relation to any reset — used to show your current, longest, and lifetime progress
- Spending amount, frequency, currency, and effective dates you provide — used only to estimate money avoided, without rewriting your history
- Your personal reason for quitting, shown back to you in the Today and Rescue screens
- Trigger and coping preferences you select for quick Rescue choices and local insight
- Daily check-in mood, urge intensity, and any optional note or time you add
- Urge event times, intensity, trigger, action taken, and exercise completion, used to build your Rescue history and local insight
- Reset time, trigger, reflection, and any optional amount, used for session transitions and comeback context
- Savings-goal titles, targets, and currency, plus the allocations you record toward them
- Daily mission date, key, and completion status
- The time-zone label and UTC offset stored beside your check-in, urge, and reset entries, so your local day and time groupings stay accurate
- Your Guardian Mode/Plan choice — the protection mode or plan you've selected within the app
- Your Lockdown state — whether Lockdown is currently active and its associated schedule
- Protection and payday schedules you configure, such as recurring windows of heightened protection
- Risk Autopilot suggestions — prompts generated on-device from your own local activity, used only to surface timely, relevant suggestions inside the app
- External barrier confirmations — a status flag recording that you've confirmed setting up an external gambling-blocking barrier outside the app
- Your Trusted Guardian cooling-off state — the status of a cooling-off period tied to a Trusted Guardian contact, used before certain protective settings such as Lockdown can be disabled
- A salted digest of your app PIN, if you set one for Lockdown or Guardian Mode changes — see Section 4 for how this is handled
- An accountability contact's name, contact detail, and preferred method, if you choose to add one — this is a manual reference only; the app never contacts this person automatically and does not use your device's Contacts
- A watermark of the last milestone you were celebrated for, so the same milestone isn't celebrated twice
- A cached copy of your last known Premium status, used only so the app still recognizes your entitlement if it's briefly unable to reach RevenueCat
- Your App Lock preference (whether Face ID, Touch ID, or a passcode is required to open the app)
- Debt name, amount, monthly payment, currency, and created/closed dates, if you use the Guardian Plan debt-recovery planning feature
- Your reminder enabled/time preference
- Theme, Reduce Motion, and app-switcher cover preferences
This information is never transmitted to us. We do not operate a server for this app and have no way to access what you've entered.
3. No Account Required
Gambling Guardian does not use accounts, sign-up, or login of any kind. There is no user profile on our side to create, and nothing to link your recovery data to your identity.
4. Guardian Mode, Lockdown, and Your PIN
Gambling Guardian includes protective features you can configure to add friction against relapse: Guardian Mode/Plan choices, a Lockdown state, protection and payday schedules, Risk Autopilot suggestions, external barrier confirmations, and a Trusted Guardian cooling-off period. All of these are computed and stored entirely on your device, exactly like the rest of your recovery data described in Section 2, and are never transmitted anywhere.
If you set a PIN to confirm actions such as exiting Lockdown or changing your Guardian Mode, the raw PIN is never stored, by the app or by us. Instead, the app stores a salted cryptographic digest of your PIN locally on your device. When you enter your PIN again, the app recomputes the digest and checks it against the stored one — the original PIN cannot be recovered from this digest, and it is never transmitted off your device.
5. When Information Can Leave Your Device
Your recovery data can leave your device only in the following situations, each of which is either entirely under your control or is standard operating-system behavior:
- Encrypted device backups. Because the app's database lives in a location iOS may include in your backups, your own device or iCloud backup settings may retain a copy of it. This is standard iOS behavior, governed by your own backup configuration; we have no access to your backups.
- Data export. If you choose to export your data, the app builds a JSON copy of the information above in memory and opens the system share sheet so you can send it to a destination you choose. The app keeps no copy of this export once the share sheet closes.
- Progress-card image. If you choose to share a progress card, the app creates a temporary image summarizing your current and lifetime days, estimated savings, and Guardian Strength. This image deliberately excludes your reasons, notes, triggers, accountability contact, Guardian Mode/Lockdown state, and reset details. It is held in a temporary cache only while the share flow is open and is deleted once it returns.
- External support links. Tapping a support link opens your device's browser to an external site. Beyond that request, the app keeps no history of the visit; the destination site's own privacy terms apply.
- Purchases. As described in Section 6, RevenueCat processes information needed to manage your subscription. This purchase information never includes any recovery data — it does not include your Guardian Mode/Plan choices, Lockdown state, schedules, Risk Autopilot suggestions, barrier confirmations, PIN digest, or any other information listed in Section 2.
Outside of these five situations, your recovery information does not leave your device. In particular, it is never sent to RevenueCat or to any developer backend — we don't operate one.
6. Purchases and RevenueCat
Optional Guardian Plan subscriptions are managed through RevenueCat, a subscription-management service, together with Apple's App Store. RevenueCat receives an anonymous App User ID, receipt data, purchased products, entitlement status, and request metadata needed to process purchases, restores, and entitlement checks. This information is handled under RevenueCat's and Apple's own retention terms; you can review RevenueCat's privacy policy at revenuecat.com/privacy. We never receive your card number or billing details directly — Apple handles all payment processing.
Your recovery data is never sent to RevenueCat. RevenueCat only ever receives the limited purchase-related information described above.
Purchase and entitlement records are not affected by Delete All Data (Section 13); your purchases remain restorable even after a local data reset.
7. Generic Notifications
If you enable reminders, the app schedules a local notification through iOS. Scheduling is handled entirely by the operating system, and notification copy is always generic — it never contains session details, streak counts, personal notes, Guardian Mode or Lockdown status, or any other recovery information, so nothing sensitive is exposed on your lock screen.
8. App Lock (Face ID, Touch ID, Passcode)
If you enable App Lock, the app asks iOS to verify your identity using Face ID, Touch ID, or your device passcode before it opens. This verification is performed entirely by iOS; the app never receives, stores, or has access to any biometric data itself — only a yes/no confirmation that verification succeeded. This is separate from the optional in-app PIN described in Section 4, which uses a salted digest rather than device biometrics.
9. Sensitive Information
We recognize that recovery information — including gambling-recovery history, spending and debt details, Guardian Mode/Lockdown settings, and personal notes about triggers and coping — is sensitive. This information stays on your device except in the specific situations described in Section 5. We do not access, sell, share, or use it for advertising of any kind.
Gambling Guardian is a self-directed recovery-support tool. It does not provide medical, psychological, or financial advice, diagnosis, or treatment, and it is not a substitute for professional support. If you are in crisis or need help with gambling addiction, please contact a qualified professional or a dedicated support service in your country.
10. What We Do Not Do
- We do not require or collect accounts, sign-ups, or email addresses
- The app includes no analytics, advertising, attribution, session-replay, or crash-reporting SDKs
- The app does not use any social SDKs
- Your recovery data — including Guardian Mode/Plan choices, Lockdown state, protection and payday schedules, Risk Autopilot suggestions, external barrier confirmations, Trusted Guardian cooling-off state, and your PIN digest — is never stored on a remote server operated by us, and is never sent to RevenueCat
- We do not store your raw PIN — only a salted digest, as described in Section 4
- The app does not use your device's Contacts; any accountability contact you add is typed in manually and is never contacted automatically
- We do not sell or share your data, and we do not use it for advertising
11. App-Switcher Privacy
By default, Gambling Guardian covers its recovery screens in the iOS app switcher while the app is backgrounded, so a snapshot of your progress, Lockdown state, or check-ins isn't visible to anyone glancing at your open apps. You can review this behavior under the app's appearance and privacy preferences.
12. Data Sharing
The only third party that receives any information from the app is RevenueCat (and, through it, Apple), for the purchase-related information described in Section 6. Beyond that, information only leaves your device when you personally trigger an export, a progress-card share, or a support link, as described in Section 5. We do not sell, rent, or otherwise share your recovery data with anyone.
13. Data Retention and Deletion
Your data remains on your device until you remove it. Delete All Data, available in the app, removes your profile and preferences, sessions, spending rates, check-ins, urges, resets, savings goals and allocations, missions, Rescue choices, accountability contact, debts, Guardian Mode/Plan choice, Lockdown state, protection and payday schedules, Risk Autopilot suggestions, external barrier confirmations, Trusted Guardian cooling-off state, and your PIN digest; cancels any pending reminder notifications; and returns the app to onboarding.
Delete All Data does not cancel a subscription and does not remove your Apple or RevenueCat transaction history — subscriptions are managed separately through your Apple ID, purchase and entitlement records are kept by Apple and RevenueCat under their own terms, and your purchases remain restorable afterward. Deleting the app removes its local data too, but because iOS device or iCloud backups may retain a prior copy under your own backup settings, we recommend also checking your backup settings if you want a complete removal.
14. Children's Privacy
Gambling Guardian is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided personal information through the app, please contact us so we can review the matter.
15. International Users (GDPR, UK GDPR, CCPA)
Because your recovery data is stored only on your device, you retain direct control over it and can erase it at any time using Delete All Data — there is no remote copy for us to access or delete on your behalf, beyond the purchase information RevenueCat and Apple hold under their own terms.
The limited processing that does occur beyond your device — purchase and entitlement data handled by RevenueCat and Apple — relies on the necessity of processing your purchase and our legitimate interest in providing subscription functionality. To exercise any privacy rights available to you under GDPR, UK GDPR, CCPA, or similar laws, you can use the on-device deletion tools above or contact us with any questions.
16. Terms of Use
Use of Gambling Guardian is also governed by Apple's Standard End User License Agreement:
https://www.apple.com/legal/internet-services/itunes/dev/stdeula
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a new effective date. Your continued use of the app after changes are posted means you accept the updated Privacy Policy.
18. Contact
For questions about this Privacy Policy or the app, please use our contact page.
Questions about this policy? Contact us.