Privacy Policy
Last updated: 10 August 2026. Canonical version of this notice; it replaces the Notion-hosted copy linked from older builds of the app.
Silex is built on one principle: your recovery is nobody's dataset.
We run no servers, hold no accounts, and have no way to read anything you write in this app. This page explains exactly what that means — including the few places where data does leave your phone, because a privacy policy that only lists the reassuring parts is not a privacy policy.
This notice is written to meet the EU General Data Protection Regulation (GDPR) and the UK GDPR. If you are in the EEA or the UK, the sections on legal bases, transfers and your rights apply to you in full.
1. What you enter stays on your device
Everything you record — quiz answers, check-ins, journal reflections, program answers, urge logs, lapse entries, streak dates, money figures, your signature and your collection — is stored in two places, both of which belong to you:
- On your iPhone, in the app's local database.
- In your private iCloud, via Apple CloudKit's private database, so your history survives a lost or replaced device.
Your private iCloud database is accessible only to your Apple ID. We are not a party to it and cannot read it. If iCloud is unavailable or disabled, the app stores data only on your device.
We never receive this content. There is no API call that sends it, no backup on our side, and no key that would let us decrypt it. Because we have no access to it and no ability to use it, we do not consider ourselves the controller of what you write in the app — you are. We describe it here for transparency, not because we process it.
2. What actually reaches anyone else
Four narrow cases, all optional or technically unavoidable.
Purchases — Apple, and RevenueCat
Subscriptions are processed by Apple. We use RevenueCat to verify and manage subscription status. It acts as our processor and receives:
- device type and operating system,
- last-seen time, and Apple receipt files,
- optionally, a user identifier and attribution metadata.
It never receives your journal, answers, streak or any recovery content. See Apple's privacy policy and RevenueCat's privacy policy.
The DNS shield — only if you turn it on
This installs an encrypted-DNS (DoH) configuration so gambling domains fail to resolve across your apps and browsers. While it is on, your device's DNS lookups are answered by Mullvad's public resolver under their no-logging policy. Advanced users may point it at their own NextDNS configuration instead. Mullvad or NextDNS act as independent controllers for those lookups under their own policies — we are not in that path and never see your browsing. Turning the shield off in iOS Settings ends this immediately.
Blocklist updates
The app periodically downloads public gambling-domain lists from jsDelivr and GitHub. As with any file download, those servers can see the request and your IP address. The request carries no identifier and nothing about you or your recovery.
Usage counts — which reach no one
The app keeps a first-party tally of how the app is used (for example, how many times a screen was opened on a given day), stored as counts by day in a single file in the app's own storage. It contains no identifiers and no content you wrote, and is never transmitted anywhere. Deleting the app deletes it.
Nothing else. The app makes no other network requests. There are no advertising identifiers, no third-party analytics SDKs, no cross-app tracking, and no profiling or automated decision-making that produces legal or similarly significant effects.
3. Legal bases (GDPR Art. 6 and Art. 9)
| What | Purpose | Legal basis |
|---|---|---|
| Purchase & subscription status (via Apple / RevenueCat) | Provide and restore the subscription you bought; prevent fraudulent entitlement | Art. 6(1)(b) — performance of a contract with you |
| IP address visible to the blocklist CDN when the app downloads a list | Deliver the blocking feature the app exists to provide | Art. 6(1)(f) — legitimate interests (keeping protection lists current). Our assessment: minimal data, no profiling, no linkage to you |
| DNS lookups, while the shield is enabled | Block gambling domains device-wide | Art. 6(1)(a) — your consent, given by enabling the shield and approving the iOS dialog; withdrawable at any time by turning it off |
| What you write in the app | Deliver the recovery programme to you on your own device | We do not receive it, so we carry out no processing to justify. To the extent it is processed at all, it is on your device under your control |
Special-category (health) data. What you record here reveals information about health and about a possible behavioural addiction, which is special-category data under Art. 9. That is exactly why the app is designed the way it is: that data never reaches us, so we never rely on an Art. 9 condition for it. Nothing in §2 reaching a third party is special-category data — a subscription receipt does not reveal a health condition beyond the fact that you bought an app.
4. International transfers
RevenueCat is a US company (Brandon, Florida) storing data on Amazon Web Services in the United States. Transfers are covered by its data processing agreement, which incorporates the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two — controller to processor. For the UK it additionally applies the ICO's International Data Transfer Addendum of 21 March 2022, and for Switzerland the SCCs adapted to the Swiss FADP. RevenueCat is not certified under the EU–US Data Privacy Framework; the SCCs are the mechanism. Verified against RevenueCat's published DPA on 6 August 2026.
Apple — see Apple's privacy policy for its own transfer safeguards. Your private iCloud data is governed by Apple's terms and is not transferred by us, because we never hold it.
Us. We are established in Ukraine, which is outside the EEA and has no European Commission adequacy decision. Where you give data to us directly, that is a direct collection rather than a Chapter V transfer (per EDPB Guidelines 05/2021 on the interplay of Art. 3 and Chapter V). In practice there is almost nothing to collect: there is no account, and the only personal data we can see is the pseudonymous subscription record in RevenueCat's dashboard.
5. How long anything is kept
- On your device and in your private iCloud: until you delete it. We cannot delete it for you, and we cannot stop you deleting it.
- On our systems: nothing, because we operate none.
- Purchase records: retained by Apple and RevenueCat under their own retention schedules, and as required by tax and accounting law.
- Usage counts: on your device only, removed when the app is deleted.
6. Who is responsible
Controller: Kyrylo Lozovyi
Address: Vidpochinku 12, Kyiv, Ukraine
Privacy contact:
support@trysilex.com
(also reachable at
stopgamblesupport@gmail.com, the
address shown inside current builds of the app)
We have not appointed a Data Protection Officer; we are not required to, because we carry out no large-scale monitoring and hold no special-category data on our systems (see §3).
7. Your rights
If you are in the EEA or UK you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent at any time where consent is the basis (the DNS shield — withdraw by turning it off; this does not affect processing already carried out).
An honest limitation. For almost everything this app touches, we hold no identifiable data about you and no account that could link a request to a person. Under GDPR Art. 11 we are not required to obtain extra information purely to identify you, and we will not ask you for identity documents to service a request we have no data to answer. In practice:
- Content you wrote — exercise these rights directly: it is on your device and in your iCloud, and deleting the app (plus the iCloud copy) erases it completely.
- Purchase data — contact Apple, or contact us and we will pass the request to RevenueCat, which acts as our processor.
Write to support@trysilex.com and we will respond within one month, as required by Art. 12(3).
Right to complain. You may lodge a complaint with your national data protection authority. The list is at edpb.europa.eu; in the UK it is the ICO. You do not have to contact us first, though we would rather you did.
8. Deleting everything
- Delete the app from your iPhone.
- Remove the iCloud copy: Settings → your name → iCloud → Manage Account Storage → Silex.
- Cancel a subscription: Settings → your name → Subscriptions, or the Manage Subscription link in the app.
9. Sensitive information, and why the design is the policy
What you record here concerns your health and your finances, and we treat it that way. No accounts to breach, no servers to subpoena, no analytics vendor holding a copy. The strongest protection we can offer is not holding your data at all — and that is a structural decision, not a promise we could quietly reverse.
10. Children
Silex is intended for adults and is not directed at children. We do not knowingly collect information from anyone under 18. The App Store listing is rated accordingly.
11. Changes
If this policy changes, the date at the top changes and the current version is always published at this address. Material changes will be surfaced in the app.