Privacy
Privacy
WITHSTAND is built to hold as little about you as it can while still keeping sessions safe. This page describes what the app does today.
- Operator
- Aster Works
- Contact
- asterworks3322@gmail.com
- Effective
- August 13, 2026
What is collected
Account
- a sign-in identity, created when you sign in with Apple, Google, or an email address and password;
- your email address, or the relay address Apple gives us if you hide your own address;
- your confirmation that you are 18 or older;
- which version of these policies you accepted;
- the status of your account.
Anonymous identity
- an anonymous display name that is picked from a fixed list, not written by you;
- the appearance of your light;
- your language;
- the country you answer for, used only to show the right emergency resources. It is your answer to a question, never a location lookup.
Recovery data
- one Recovery Focus and its commitment phrase, chosen from constrained options;
- the times of day you marked as vulnerable;
- check-ins: an urge level, a trigger picked from a fixed list, and the safe action you chose;
- your Recovery Plan selections;
- private Journal entries, including an optional note and an optional note about what triggered the moment. These words are returned only to you and are not shown to a peer or sent to product analytics;
- day and completion events, and a restart if you record one.
Sessions
- when a request was made, matched, or went unmet;
- who took part, held internally and never shown to the other member;
- the fixed signals exchanged, the duration, and the outcome you selected;
- reports and blocks;
- what makes a previous peer familiar.
Personal Circle
- invitation metadata, including a protected form of the invite code, its status, and its expiration time. The plain invite code is returned once and is not stored;
- the Circle relationships you join, their status and dates, and the mute setting for structured requests;
- one display name each person chooses for that relationship. It is free text, is visible only inside the invited Circle relationship, and cannot be edited after the connection is created;
- structured Circle requests and the sessions they create.
Subscriptions
- the App Store product, transaction, subscription status, expiration, and eligibility information needed to offer, restore, and manage Plus or Supporter;
- a pseudonymous app user ID used by RevenueCat to verify purchases and return current entitlements;
- the current Plus and Supporter entitlement status and the time and source of its latest verification, stored by the WITHSTAND backend.
Device
- platform and app version;
- a push notification token, if you turn notifications on. It is stored encrypted and is never returned to the app, shown in a log, or included in an error;
- sign-in and session metadata needed to keep you signed in;
- counters used for rate limits and abuse prevention, such as how many requests an account has made today.
A copy of your Recovery Plan is kept in your device’s secure storage so it opens during an urge even with no network. Deleting your account from inside the app clears it, along with everything else the app has cached.
What is never collected
WITHSTAND does not ask for or verify a legal name. It does not collect a profile photo, GPS or exact location, postal address, contacts, microphone or camera recordings, voice, open-ended chat between members, a public social graph, biometrics, health records, diagnoses, medication, financial credentials, gambling transaction history, or any advertising identifier. Because a Personal Circle display name is written by you, do not put contact details or other identifying information in it.
WITHSTAND does not sell personal data, does not share it with data brokers, and runs no behavioral advertising. This mobile-app release ships no advertising SDK, no third-party analytics SDK, and no crash-reporting SDK. The optional analytics used on this public website is described separately below.
What a peer can see
In an anonymous peer session, the other person sees only your light, the fixed signals of the session in progress, the safe action chosen for it, whether you are a familiar peer once a session has started, and whether you are connected.
A peer cannot see your anonymous name, email address, any internal identifier, your country, your exact age, your gender, your location, your Focus, your history, your reports, your other familiar peers, whether you are online outside the current session, or anything about your device.
A person connected through Personal Circle can see the one display name you chose for that relationship and the state of a structured Circle request or session. They cannot see your email address, anonymous peer name, Focus, Plan, Journal, check-ins, other Circle relationships, or subscription status.
Measurement
Product measurement is a server-side switch, and it is off by default. When it is on, an event records a pseudonymous key that is separate from anything a peer can see, the hour it happened in rather than the exact time, the platform and app version, the focus category, and coarse buckets for waiting time and duration. There is no free-text field an event could carry, and no event carries your email address, your anonymous name, your commitment phrase, a report note, a device token, or an identifier for a pair of members. Deleting your account rotates that key, so past events can no longer be connected to you.
Website analytics
The public WITHSTAND website uses Google Analytics only after you select “Allow analytics.” Before you consent, the Google tag is not loaded and no analytics request is sent to Google.
After consent, Google Analytics may receive the pages visited, session statistics, approximate location derived from network information, and browser and device information. It may set the first-party cookies _ga and _ga_* to distinguish a browser and its sessions; Google documents a default lifetime of up to two years. WITHSTAND does not set a Google Analytics user ID or send an account email, Recovery Focus, Journal, Plan, form content, peer activity, or other app data. Advertising storage, Google Signals, and ad personalization remain disabled.
Your choice is stored only in this browser’s local storage. Use the “Analytics settings” button to change or withdraw it. Withdrawal stops future collection and clears the Google Analytics cookies this website can access, but it does not erase data Google already received.
Notifications
Notifications are off until you turn them on, and the app explains why it is asking before the system prompt appears. The default text on a locked screen says nothing about your focus category, your urge level, a lapse, a familiar peer, or the details of a request.
How long data is kept
- Detailed session and connection events: removed after 90 days. A session that a report concerns is the exception — its events are held as evidence until that report is dismissed, and nothing else releases them.
- Queue entries, match offers, the counters behind rate limits, and requests that never became a session: removed after 30 days.
- The session records themselves — who took part, when, how it ended — and the request that produced each one: kept. They are the record a report is read against, and they are the other member’s history as much as yours. A deleted account’s side of them keeps the shape and loses the light.
- Security and audit records: removed after 12 months.
- Active Personal Circle invitations and relationships: kept while they are active. Expired, revoked, redeemed, or ended Circle records are removed after 90 days. Circle invitations and memberships involving you, including the display names, are deleted when you delete your account, together with every Personal Circle mute record that names your account, in both directions.
- Your profile, Focus, Plan, check-ins, Journal, and current entitlement snapshot: kept until you delete your account.
- App Store and RevenueCat transaction records follow Apple’s and RevenueCat’s retention obligations and are not erased by deleting the WITHSTAND account.
- Reports, blocks, and safety actions: kept while they are needed for abuse prevention, and they survive the deletion of the account they concern. The deletion page explains why, and lists everything else that outlives an account.
Your controls
- turn notifications on or off, per device;
- see the lights you have blocked and remove a block, without seeing anything about the member behind it. Removing a block does not withdraw a report;
- mute Personal Circle requests, end a Circle relationship, or block its member;
- manage or cancel an App Store subscription through Apple’s subscription settings;
- delete your account from inside the app, at any time, without contacting anyone and without cancelling anything first.
Who processes data
WITHSTAND uses service providers for its hosted backend and authentication, Apple and Google sign-in, Apple push notifications and App Store purchases, and RevenueCat subscription verification. They receive only the information needed to provide those functions and process it under their own terms and privacy policies.
Production vendors: Supabase provides the app backend, authentication, Edge Functions, and encrypted secret storage; Apple provides Sign in with Apple, push-notification delivery, and App Store purchase processing; Google provides Google sign-in; RevenueCat verifies App Store purchases and manages subscription entitlements using a pseudonymous app user ID; Vercel hosts this public website. The mobile app does not use advertising networks, third-party analytics SDKs, or crash-reporting SDKs in this release.
People under 18
WITHSTAND is for adults. It is not directed at children, and an account credibly belonging to a minor is suspended pending review. If you believe a minor has created an account, write to asterworks3322@gmail.com.
Changes
When this page changes in a way that affects you, the app asks you to accept the new version, and it records which version you accepted. This page is a description of the product, not legal advice.