Unbottle privacy policy
Last updated 31 July 2026
Unbottle is made by Serhii Alpieiev. This page describes what the iPhone app stores, who else touches it, and how to get it back or destroy it. It covers Unbottle only — Vapexit, the quit-vaping app from the same developer, is a separate app with separate storage, a different set of fields and its own policy, published on its own site.
The short version
- No account. No email address, no name, no phone number, no password.
- What you log is filed under a random anonymous ID so it survives a new phone.
- Your body weight is stored, because the morning-after estimator cannot work without it. It never goes to analytics, and neither does any estimate it produces.
- Nothing is sold. Nothing goes to advertisers or data brokers.
- The app never asks to track you across other companies' apps and never reads the advertising identifier.
- Export everything or delete everything from Settings, free, whenever you want.
What is stored
What you enter and log
Kept under your anonymous ID in Google Firestore:
- Your setup: your goal, your quit date, when you started, what a drink costs you, how much you were drinking a day, and your reminder time.
- Your reasons for quitting — the chips you pick and anything you type. This is the most personal text in the app. It never goes to analytics, and a notification only ever says that you wrote something down, never what it says.
- Your AUDIT-C answers as a score — which instrument you were shown, the score, and whether it came from the first question alone.
- Withdrawal-risk flags, where setup identified any, plus the moment you acknowledged the medical-supervision warning. The flags are recorded, not the clinical history behind them.
- Your body weight, and the biological sex the estimator uses, if you have used the morning-after tool. Stored so you are not asked every time; used for nothing else. The clinical field that AUDIT-C's scoring threshold reads is kept separate and is never written from this tool.
- Every day you track: the number of standard drinks, the drinks themselves (kind, size, strength), which hours they fell in, your morning pledge, your evening check-in (a mood rating and a craving rating), how many slips, and your taper limit for that day if you are on one.
- Every slip and craving you log: when, which triggers you picked, how strong it was if you said, which tool you used, and how it ended.
All of this is health information about alcohol use, and the body-weight field makes it health and fitness data in Apple's own classification. It is scoped to your anonymous ID, and the security rules deny every other signed-in user access to it.
What the morning-after estimator does not store
The estimate itself is calculated and shown, and then it is gone. No blood-alcohol figure, no drink count, no stop time and no weight is recorded for it, and the analytics event says only which of the four possible readouts appeared — not a single number from the calculation. The one figure the feature exists to produce is the one figure that leaves no trace.
What the app measures about itself
Usage events go to Amplitude and to Google Analytics for Firebase: which screens you open, which onboarding pages you finish, that a drink was logged, that a craving tool ran, whether a paywall appeared. Some carry values from your history — a check-in sends the mood and craving ratings; onboarding sends your goal, the band your AUDIT-C score fell in and how many reasons you wrote. Never the reasons themselves, never the raw score, never your weight.
Crashes
Firebase Crashlytics receives crash traces, your device model and iOS version, tied to the anonymous ID, so a crash can be found and fixed.
Purchases
Subscription state is handled by RevenueCat on top of Apple's receipt. Apple takes the payment; card details never reach the app or the developer.
Identifiers
- A random anonymous account ID from Firebase Authentication, created on first launch. Everything above is filed under it, and it is the ID given to Amplitude, Google Analytics, Crashlytics and RevenueCat so their records line up.
- A Firebase app-instance ID and your device's vendor identifier, shared with RevenueCat so a purchase can be matched to an install.
- Apple's Search Ads attribution token, if you arrived from an ad. It is not the advertising identifier and does not identify you.
What is never collected
- Your name, email address, phone number or postal address.
- Your location, contacts, photos, microphone or camera.
- Anything from Apple Health — Unbottle does not request HealthKit access, and the weight you type here is never written back to it.
- The advertising identifier. There is no App Tracking Transparency prompt because there is nothing to ask for.
Who processes it
| Who | What they get | Why |
|---|---|---|
| Google (Firebase Authentication, Firestore, Crashlytics, Analytics) | The anonymous ID, everything you log including body weight, crash traces, usage events | Storing your history and keeping the app working |
| Amplitude | Usage events and the anonymous ID — no weight, no estimate | Understanding which parts of the app help |
| RevenueCat | The anonymous ID, the two install identifiers, purchase state | Knowing whether you have Pro |
| Apple | The purchase itself | Taking the payment, running the App Store |
They act as processors on the developer's behalf and may not use your data for their own purposes. Storage is on these providers' servers, which may sit outside your own country.
Your data, in your hands
Settings → Data → Export my data writes your profile, every day and every logged event to JSON or CSV and hands you the file. Free, unlimited, and your whole history rather than a recent window — a complete copy, produced immediately, without asking anyone's permission.
Settings → Data → Delete all my data destroys your profile, your days and your events, and tells you how many days that is before it does. It cannot be undone, so export first if you want a copy. Your anonymous ID and purchase record survive, so a subscription you paid for keeps working.
Deleting the app from your iPhone does not delete the stored copy, and reinstalling starts a fresh anonymous ID rather than reconnecting to the old one — so old records become unreachable rather than erased. Use Delete all my data first, or write to support@unbottle.mriy.io and we will do it.
Because there is no account, an emailed request cannot be tied to one person's records. That is a privacy property rather than an obstacle: the two buttons in the app do the same job instantly, from the only device that can prove the history is yours.
Children
Unbottle concerns alcohol, is not intended for anyone under 17, and is rated accordingly on the App Store. It is not knowingly used to collect information from children.
Changes
If what the app collects changes, this page changes with it and the date at the top moves. A change that materially affects what is stored — a new field, a new processor — will be described here rather than quietly folded in.