Quenched (the "App") is built by Swift Fox Software LLC, a North Carolina limited liability company ("we", "us"). We designed Quenched to be private by default: your hydration history belongs to you and stays under your control. This policy explains exactly what the App handles, what leaves your device, and who processes it.
1. The short version
- Your water log, your goal, and the body details used to calculate it are stored on your device and, on iPhone and Apple Watch, in your own private iCloud account if you enable it. We cannot read either one. The Android app has no cloud sync at all — its data stays on your device.
- There is no Quenched account. We never ask for your name, and an email address is optional and only used if you write to support.
- The App sends product analytics — which screens you open, which features you use, and when you log a drink — to our analytics providers, tied only to a random ID generated on your device.
- We never sell or rent your information, never share it for advertising, and never try to work out who you are. The App shows no ads and contains no advertising SDK. On iPhone and Apple Watch it never asks for tracking permission, so it has no access to your advertising identifier; on Android, our attribution provider does read the Google advertising ID to match your install to an ad campaign, and you can reset or delete that ID at any time in Android Settings.
2. Information stored on your device
To do its job, Quenched stores the information you enter, including:
- Water and drink entries (amounts, drink type, and timestamps).
- Your daily goal and the inputs you optionally provide to calculate it — body profile, weight, activity level, and climate.
- App preferences such as units (oz or mL), reminder schedule and sounds, quick-add amounts, custom drinks, and caffeine settings.
This information lives in an on-device database and in the App's local settings. Your goal inputs — including weight and body profile — never leave your device. They are not sent to us and not sent to any third party.
3. iCloud sync (iPhone and Apple Watch)
The Android app does not sync to any cloud service — everything it stores stays in its on-device database. The rest of this section applies only on Apple devices.
If you are signed in to iCloud and have iCloud enabled for Quenched, your entries sync through Apple's CloudKit so they stay consistent across your iPhone and Apple Watch. That data resides in your private iCloud database, is governed by Apple's Privacy Policy, and is not accessible to us. You can turn iCloud off for Quenched at any time in iOS Settings.
4. Apple Health (iPhone and Apple Watch)
If you grant permission, Quenched can read your existing water and caffeine data from Apple Health and write what you log back to Health. This exchange happens directly between the App and HealthKit on your device, under your control.
Health data is never transmitted to us, never shared with any third party, and never used for advertising or marketing. It is used only to provide the syncing features you turn on. You can revoke access at any time in the Health app or in iOS Settings, and you can turn Health sync off inside Quenched.
5. Health Connect (Android)
On Android, Quenched can sync with Health Connect, the on-device health store built into the system. Syncing is off until you turn it on inside Quenched and grant the permissions in Health Connect's own permission screen.
With your permission, Quenched uses exactly four Health Connect permissions and nothing else:
- Read hydration — so drinks you logged in another app count toward your daily goal.
- Write hydration — so drinks you log in Quenched appear in your other health apps.
- Read nutrition — used only to read the caffeine field, so caffeine logged elsewhere is reflected in Quenched.
- Write nutrition — used only to write the caffeine field for drinks you log in Quenched.
Quenched also updates or removes its own Health Connect records when you edit or delete the matching entry in the App, so the two stay consistent. It never modifies or deletes records written by another app.
Health Connect data is read and written entirely on your device. It is never transmitted to us, never sent to any of the third parties listed in this policy, never used for advertising or marketing, and never used to train any model. It is used only to provide the syncing features you turn on, and we do not retain it — Quenched holds no copy of your Health Connect history on any server, because it has no server to hold it on.
You are in control of this at all times. You can turn Health sync off inside Quenched, which stops all reading and writing while leaving your existing records untouched, and you can revoke any or all of the four permissions in Settings → Security & privacy → Health Connect (or in the Health Connect app). Quenched continues to work normally with these permissions denied. Uninstalling the App stops all access and removes its local database; records Quenched previously wrote to Health Connect stay in Health Connect until you delete them there.
Our use of Health Connect complies with the Google Play Health Apps policy, including its restrictions on how health data may be used and shared.
6. Reminders and notifications
If you enable reminders, the App schedules local notifications on your device based on the times, days, and sounds you choose. Reminders are generated entirely on-device — we do not operate a push server and receive nothing from your notifications.
7. Product analytics
To understand how Quenched is actually used and where it frustrates people, the iPhone and Android apps send usage events to PostHog and Amplitude. The Apple Watch app, the widgets, and the complications send no analytics at all.
How you are identified
On first launch the App generates a random identifier (a UUID) and stores it on your device. Analytics events are attached to that random ID and nothing else — not your name, not your email, not your Apple or Google account, and not your advertising identifier. Deleting the App discards the ID; reinstalling generates a brand-new one with no link to the old one.
What the events contain
- App lifecycle: installs, updates, launches, and backgrounding.
- Screens and navigation: onboarding steps you complete or skip, which tab you view, and which settings screens you open.
- Feature use: opening the add-water sheet, choosing a reminder sound, turning Health sync on or off, opening support, and being shown a review prompt.
- Paywall activity: when a paywall is shown, where it was opened from, and whether you tapped to purchase, cancelled, skipped, or hit an error.
- Drinks you log: the amount, the hydration-equivalent amount, the drink name, whether it counts as plain water, and which part of the App you logged it from.
We want to be plain about the last item: because an event is sent each time you log, these records do reflect when and how much you logged while the App was installed. They are never linked to your identity, and your history from before you installed the App — including anything read from Apple Health — is never uploaded.
What the SDKs add automatically
PostHog and Amplitude attach standard technical context to each event: device model, operating system version, app version, language and region, and time zone. Like any network request, the connection also reveals your device's IP address, which PostHog uses to estimate a coarse location (roughly city or region level) and which we never use to identify you.
What is never sent
We do not send your name, contacts, photos, precise location, browsing activity, or the contents of Apple Health. The App does not record your screen, does not use session replay, and does not include any advertising SDK.
8. In-app support
If you write to us from the App's support screen, your message is delivered through PostHog Support. We receive the text you write, a random support session ID, your analytics ID, and — only if you choose to add it — the email address you enter so we can reply outside the App. Support conversations are kept while we resolve the issue and for a reasonable period afterward for context, then deleted.
9. Purchases
Quenched offers an optional annual subscription and a one-time lifetime unlock. Payments are processed entirely by the app store you bought from — Apple on the App Store, Google on Google Play; we never see or receive your card or payment details.
We use RevenueCat to validate purchases and keep your unlock working across your devices. RevenueCat receives your store transaction information, your purchase and subscription status, your country, and the same random app identifier described above. On iPhone and Apple Watch it also receives the vendor identifier (IDFV) Apple assigns to our apps on your device; because Quenched never asks for tracking permission there, your advertising identifier (IDFA) is not available to it. On Android it also receives the Google advertising ID, which it uses to keep purchase records consistent with the install attribution described in the next section.
10. Install attribution and advertising
We run ads for Quenched, and we use AppsFlyer to learn which campaign an install came from so we know where our budget is going. Quenched deliberately never shows the App Tracking Transparency prompt and never accesses your IDFA; on iOS, campaign measurement instead relies on Apple's SKAdNetwork, which reports conversions to Apple in an aggregated, privacy-preserving way.
On Android there is no equivalent of the tracking prompt, and attribution works differently: AppsFlyer matches your install using the Google advertising ID and the Google Play Install Referrer, which tells us which campaign sent you to the Play Store listing. The advertising ID is a resettable identifier you control — you can reset it or delete it entirely under Settings → Privacy → Ads, and Quenched keeps working either way.
On both platforms, AppsFlyer receives install and session signals such as device model, OS version, and IP address, together with the platform identifier described above, and returns the media source and campaign name for your install. We store that campaign name alongside your random analytics ID. We do not use it to build an advertising profile of you, we never combine it with your hydration or health data, and we do not target you with ads based on anything you do inside the App.
11. Service providers we use
These are the only third parties that receive any data from the App. Each acts as our processor, is bound to use the data only to provide its service, and is not permitted to sell it.
- Apple — App Store purchases, iCloud sync, and SKAdNetwork. Privacy Policy
- Google — Google Play purchases and the Play Install Referrer on Android. Health Connect is part of the Android system and stores your health data on your device, not on Google's servers. Privacy Policy
- PostHog — product analytics and in-app support, processed on PostHog's US cloud. Privacy Policy
- Amplitude — product analytics. Privacy Policy
- RevenueCat — purchase validation and subscription status. Privacy Policy
- AppsFlyer — install attribution. Privacy Policy
12. What we never do
- We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising. Under the California Consumer Privacy Act, we do not "sell" or "share" personal information.
- We do not attempt to identify you or link your usage to a real-world identity, and we do not combine our data with data bought from anyone else.
- We do not use your data to train anything, and we do not hand it to data brokers.
- We do not read your private iCloud database, your Apple Health data, or your Health Connect data. Health data never leaves your device, on either platform, and is never used for advertising, marketing, or model training.
13. Retention
Data on your device stays until you delete it or delete the App. Analytics and attribution records are held by the providers above under their standard retention schedules and are deleted when they are no longer useful to us. Support conversations are deleted once they are no longer needed.
14. Your choices and your rights
You are in control of the data on your device: delete individual entries in the App, turn off iCloud sync, revoke Apple Health or Health Connect access, turn off notifications, reset or delete your Google advertising ID on Android, or delete the App entirely — which removes its on-device data and its random identifier.
Depending on where you live (for example under the GDPR or the CCPA), you may have the right to access, correct, delete, or object to our processing of information about you, and to be free from discrimination for exercising those rights. Email support@quenchedapp.com and we will honour it. One practical note: because we hold no account for you, the only way we can locate your analytics records is by their random ID — sending your request as a message from inside the App is the easiest way for us to match it. Our Managing Your Data page walks through exactly how, and what gets deleted.
Where the GDPR applies, we process usage and attribution data under our legitimate interest in understanding and improving the App and in measuring our advertising; purchase data to perform our contract with you; and Health data and notifications only with the permission you grant.
15. International transfers
Swift Fox Software LLC and the providers listed above process data in the United States. If you use the App from outside the United States, your information will be transferred there, protected by the safeguards those providers offer — including standard contractual clauses where required for transfers from the EEA, the UK, or Switzerland.
16. Children's privacy
Quenched is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, email us and we will delete it.
17. Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected here with an updated date, and significant changes will be called out in the App.
18. Contact
Questions about privacy? Email us at support@quenchedapp.com, or write to us from the support screen in the App.