Cairn — Legal

Privacy policy and legal pages for the Cairn sober streak tracker app (iOS and Android).

View the Project on GitHub mike43-ai/cairn-legal

Privacy Policy

Effective date: June 18, 2026 Last updated: June 26, 2026

Cairn (“we”, “us”, “our”) operates the Cairn sober streak tracker applications for iOS and Android (the “App”). Cairn is a personal sobriety tracking and reflection app. It is a support tool for your own journey — not medical care, and not a substitute for professional help. This Privacy Policy explains what information the App handles and the choices you have.

1. Your data stays on your device

Your sobriety start date, daily check-ins, streak, stats, milestones, and journal entries are stored locally on your phone. We do not sell or share your personal data, and this content is not uploaded to our servers in normal use.

2. Anonymous account

The App uses an anonymous sign-in so that optional reflection requests can be authenticated. No name, email address, or phone number is required to use Cairn. The anonymous account identifier is not linked to your real identity.

3. Reflection (optional, Pro)

When you ask for an AI reflection, the journal entries you choose are sent securely for processing by third-party AI providers — OpenRouter and Google (Gemini) — to generate gentle, non-clinical observations, which are then returned to you. We send only your chosen reflection entries and minimal context — never your identity beyond an anonymous account id.

Your entries are processed only to generate your reflection and are not stored on our servers afterward. We do not sell your entries, use them for advertising, or use them to train AI models. The AI providers process the text on our behalf under their own data-use terms (OpenRouter: https://openrouter.ai/privacy).

4. Subscriptions

Optional subscriptions (Cairn Pro) are handled by the App Store / Google Play and RevenueCat. We do not receive or store your payment method, billing address, or full account details — the store confirms only whether your subscription is active.

5. Third-Party Services

Service Purpose Data received
Firebase Authentication (anonymous) Authenticate reflection requests Anonymous account identifier only
Cairn Reflection API (Cloudflare Workers) Server-side AI gateway The reflection entries you submit, plus your anonymous account id
OpenRouter + Google Gemini Generate reflection observations Reflection text relayed by our gateway (only when you trigger a reflection)
RevenueCat Subscription management App User ID (anonymous), purchase receipts
Apple App Store / Google Play In-app purchases Purchase receipt

Each provider stores data on its own infrastructure under its respective privacy policy.

6. Crisis resources

If you are in crisis, please use the crisis resources in the App or contact a local helpline. Cairn cannot provide emergency help.

7. Data Retention

8. Your Rights

Because Cairn stores your personal content locally and requires no identifying account, you control your data directly: uninstalling the App or clearing its data removes it. For any privacy question or request, contact us at the email below; we respond within 30 days.

9. Children

Cairn is not directed to children and references alcohol; it is intended for adults.

10. Security

We use industry-standard measures: TLS for all data in transit, a server-side AI gateway that authenticates every request with your anonymous account identity (so AI provider keys are never embedded in the App), and encrypted storage on Apple- and Google-managed infrastructure. No system is perfectly secure.

11. International Transfers

We are based in Vietnam. When you use the optional reflection feature, your text may be processed in the United States or other countries where our providers (Google, Cloudflare, OpenRouter, RevenueCat) operate. By using that feature you consent to such transfers.

12. Changes to This Policy

We may update this policy from time to time. We will post the new version at this URL and update the “Last updated” date. Continued use of the App after a change takes effect constitutes acceptance of the updated policy.

13. Contact

For privacy questions or data requests:

Email: support.gravita@gmail.com

We aim to respond within 5 business days.