Privacy Policy
Quitting porn is private. Turnoff is built around that: the blocklist is evaluated locally on your device, we do not log your browsing history, and we use no advertising networks. This policy explains exactly what we do process, why, and your rights.
1. Who is responsible
The controller for the processing described here is Follow Your Instincts UG (haftungsbeschränkt), Birkenstr. 14, 67067 Ludwigshafen am Rhein, Germany (“we”, “us”) — Imprint. Contact: support@turnoff.now.
2. What we never do
- We do not log the pages you visit. The blocklist is matched on your device: inside your browser by the extension (Chrome’s declarativeNetRequest), or on your phone by our Android app (section 4). Your browsing history never reaches our servers, and neither the extension nor our apps read the content of the pages you view.
- No advertising or cross-site tracking. No ad networks, no advertising cookies, no cross-site tracking, no sharing of usage data with ad platforms. We do measure how the product itself is used (section 3), but that data stays with us and our processors.
- We do not sell or share your personal data for advertising or any similar purpose.
3. What we process
Account data
Your email address, a user ID, and authentication data, processed through Firebase Authentication. If you sign in with Google or Apple, that provider shares your name and email address (and, for Google, your profile picture) with us as part of the sign-in; Apple lets you hide your email behind a relay address. When you start the onboarding, we create a pseudonymous user ID for you (an anonymous sign-in) so that your answers and any purchase can be linked together before you create an account.
Subscription status
Whether your subscription is active and its timestamps (started, renewed, cancelled, period end), together with payment references: Stripe customer and subscription IDs for purchases on the website, or App Store or Google Play transaction data for purchases made in our apps. Your full payment details (card number etc.) never reach our systems.
Payment data (processed by Stripe)
Payments on the website are handled by Stripe as merchant of record. Stripe processes your payment and billing data under its own responsibility; see the Stripe Privacy Policy. We receive only the subscription status and reference IDs described above.
App purchases (processed by Apple or Google, and RevenueCat)
If you subscribe inside our iPhone app, the purchase is an in-app purchase processed by Apple under Apple’s own terms and privacy policy. If you subscribe inside our Android app, it is processed by Google Play under Google’s own terms and privacy policy. We use RevenueCat to validate these purchases and keep your subscription status in sync across devices; RevenueCat receives your user ID and store transaction data for that purpose. We never receive your payment details.
Your progress stats
When you make a choice on the interrupt screen (“I’m turned off” or “Open anyway”), use the panic button, or report a slip yourself, we store the outcome, what triggered it (the domain, or the fact that it was a panic or manual entry — including the reason you pick when reporting a slip), and a timestamp in your account, together with your streak and counters. This is what powers your dashboard. It exists only for you; you can delete it at any time by deleting your account.
Your custom blocklist
Domains you choose to block in addition to the default list, stored in your account so all your browsers can use them.
Your onboarding answers
During onboarding we ask multiple-choice questions about you and your habits (for example your gender, how often and when it happens, symptoms you notice, and your goals), and optionally your first name and age. Your selections are saved as you answer, under the pseudonymous user ID described above, so your plan can be built and your progress is not lost; when you create an account they become part of it. We use them to tailor the Service to you and handle them under the sensitive-data rules in section 5. They are deleted with your account.
Extension link token and connected devices
A random token that connects your installed extension to your account. It is stored in the extension’s storage in your browser and used to fetch your blocklist and subscription status and to record interrupt outcomes. Web pages cannot read it. For each connected extension we also store a coarse device label (for example “Safari · iPhone”) and when it last checked in, so your dashboard can show which browsers are connected. Our apps, and iPhone Safari while you are signed in there, likewise leave a last-used stamp on your account, so the app can tell you whether Safari is still signed in.
Push notifications (apps)
If you enable notifications in our apps, we store a device push token in your account to deliver them (via Firebase Cloud Messaging). It is removed when you sign out or delete your account.
Waitlist email
If you ask to be notified when the Service (or a version for your browser) becomes available, we store the email address you enter, together with your browser type and, where applicable, the plan you picked, solely to send you that notification.
Usage events (product analytics)
To understand whether the product works — in particular where people abandon the onboarding — we record a small, fixed set of events (for example “landing page viewed” or “checkout opened”) with a pseudonymous device identifier stored in your browser. Alongside the screen name, these events also carry how long you spent on a screen, whether you moved forward or back, and — for the onboarding — the multiple-choice answers you selected, so we can tell which answers go with which drop-off point. Your browsing history and the sites you block are never part of them. Because the onboarding answers are sensitive data, we handle these events under the sensitive-data rules in section 5. They are processed for us by PostHog on servers in the EU (see section 7). Until you create an account or purchase, events are not linked to any account; after that, they are linked to yours so we can understand the product journey. Our apps record the same kind of events. Section 9 describes how long events are kept.
Support communication
If you contact us, we process your message and email address to answer you.
Technical logs
Our infrastructure (Vercel for the website, Google Cloud / Firebase for backend services) produces short-lived technical logs (such as request metadata and IP addresses) for security, abuse prevention, and troubleshooting.
4. The browser extension in detail
The extension asks for permission to act on websites so that it can match your blocklist against the sites you open — this matching happens entirely on your device. The only data the extension sends to our servers is: periodic fetches of your blocklist and subscription status (authenticated with your link token), and — when you make a choice on the interrupt screen — the outcome described under “progress stats” above. Nothing else about your browsing leaves your browser.
The same applies to our apps for iPhone and Mac (distributed via Apple’s App Store, including TestFlight): they host the Safari version of the extension and behave the same way. The iPhone app’s optional “Beyond Safari” feature uses Apple’s Screen Time framework to filter adult sites in other browsers and to pause apps you pick — that filtering and your app selection stay entirely on your device; we never receive them. If you sign in inside the app, the same account data described above applies, and subscriptions bought in the app are processed as described under “App purchases” in section 3. The apps also record the usage events described in section 3 and send crash reports (Firebase Crashlytics) so we can fix bugs — technical device and error information, not tied to your browsing.
Our Android app (distributed via Google Play) blocks in a different way, because Android browsers have no extensions: when you turn protection on, it sets up a local VPN on your phone. Android then routes only your phone’s domain lookups (the question “which address belongs to this site?”) through the app. The app compares each name with your blocklist on your device, refuses the blocked ones, and passes every other lookup unchanged to your network’s own DNS resolver. No traffic goes through a server of ours, the lookups are not logged, and nothing about your browsing leaves your phone. The only thing that reaches us is the outcome you choose on the interrupt screen, as described under “progress stats” above. Android asks for your permission before the VPN starts and shows a notification while it runs, and you can turn it off in the app at any time. The Android app also records the usage events described in section 3 and sends crash reports, like our other apps, and subscriptions bought in it are processed as described under “App purchases” in section 3.
5. Sensitive data
Using a tool made for quitting porn can itself reveal information about your sex life — data that is specially protected under Art. 9 GDPR. We treat everything connected to your use of Turnoff that way: we process it only to provide the service you explicitly asked for and to understand where people abandon it, based on your explicit consent — given when you create your account and, for the onboarding questions, by choosing to answer them. We never use it for advertising, never sell it, and never share it beyond the processors listed below. You can withdraw consent and erase this data at any time by deleting your account.
6. Purposes and legal bases (GDPR)
- Providing the Service (account, blocking, interrupt, stats, custom blocklist, billing status): performance of a contract, Art. 6(1)(b) GDPR; for the sensitive aspects described in section 5, your explicit consent, Art. 9(2)(a) GDPR.
- Payments and tax: handled by Stripe as merchant of record under Stripe’s own legal obligations.
- Security, abuse prevention, troubleshooting: legitimate interests, Art. 6(1)(f) GDPR.
- Product measurement (the usage events in section 3): legitimate interests, Art. 6(1)(f) GDPR; for the onboarding events that carry your multiple-choice answers, your explicit consent, Art. 9(2)(a) GDPR — the same consent as in section 5. Your browsing history is never measured.
- Waitlist notifications: your consent, Art. 6(1)(a) GDPR — withdraw at any time by emailing us.
7. Who receives data (processors and partners)
- Google Ireland Ltd. / Google LLC — Firebase (authentication, database, hosting, cloud functions, push notifications, and crash reporting in the mobile/desktop apps), and Google Play distribution and in-app purchases in our Android app (independent controller for payments made through Google Play). Our database and functions run in EU regions; some Firebase services operate globally.
- Stripe — payment processing for website purchases as merchant of record (independent controller for payment data).
- Apple Inc. — App Store distribution and in-app purchases in our apps (independent controller for payments made through Apple), and Sign in with Apple if you use it.
- RevenueCat, Inc. — validation and management of app subscriptions (receives your user ID and store transaction data).
- PostHog — product analytics (the usage events in section 3), hosted on servers in the EU (Frankfurt). PostHog processes these events solely on our behalf.
- Vercel Inc. — hosting of the turnoff.now website (technical server logs).
- Namecheap, Inc. — email forwarding for our support address.
We use no advertising networks.
8. International transfers
Where data is transferred outside the EU/EEA (for example to the US-based providers listed in section 7), this happens under the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses, supplemented by technical safeguards such as encryption in transit.
9. How long we keep data
- Account data, stats, custom blocklists, and onboarding answers: until you delete your account (the dashboard has a “Delete account” button that removes them).
- Usage events: automatically deleted by our analytics provider after at most 12 months; you can ask us to delete events linked to your account earlier (section 10).
- Technical logs: short retention periods, then deleted.
- Payment and tax records: retained by Stripe (website purchases) or by Apple or Google (app purchases) under their statutory obligations.
- Waitlist emails: until the notification is sent or you ask us to remove you.
- Support emails: as long as needed to handle your request and any follow-ups.
10. Your rights (GDPR — EU/EEA)
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority — for us the competent authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, but you may complain to the authority of your own country as well. To exercise your rights, email support@turnoff.now or use the in-product tools (account deletion).
11. United Kingdom and Switzerland
If you are in the UK, the rights above apply under the UK GDPR, and you may complain to the Information Commissioner’s Office (ICO). If you are in Switzerland, equivalent rights apply under the Swiss Federal Act on Data Protection (FADP); the competent authority is the FDPIC.
12. California (CCPA/CPRA)
To the extent the California Consumer Privacy Act applies: in the last 12 months we have collected the categories described in section 3 (identifiers, commercial information, limited internet activity within our own Service). Some of it is “sensitive personal information”; we use it only to provide the Service you request and for the product measurement described in section 3. We do not sell personal information and do not “share” it for cross-context behavioural advertising, so there is nothing to opt out of. You have the rights to know, correct, delete, and to non-discrimination for exercising them. Exercise them via support@turnoff.now or the in-product account deletion.
13. Canada, Mexico, and other regions
Where local data protection law applies (for example PIPEDA in Canada or the LFPDPPP in Mexico), you can exercise your rights of access, correction, and deletion through the same contact. We apply the protections described in this policy to all users, regardless of location.
14. Cookies and local storage
We use no advertising cookies and no analytics cookies. Your browser stores what is strictly necessary for the Service to work (your login session and, briefly, an interrupt outcome awaiting sign-in) plus the pseudonymous analytics identifier from section 3, which lives in local storage — not in a cookie — and is never shared across sites. If you arrive through a campaign link, the campaign label from that link (never an advertising click ID) is stored locally too, so we can tell which campaigns work. When we test two versions of a page against each other, the version your browser was randomly shown (a short label such as “control”) is also stored locally and attached to the measurement events described in section 3, so we can tell which version works better; it identifies the page version, not you. While you are working through the onboarding questions, the answers you have given so far are also held in local storage, so that reloading the page does not lose your place; they are kept for at most 24 hours and cleared once you finish. Our apps do the same on your phone, so that closing the app does not lose your place either. Stripe’s hosted checkout and billing pages use their own cookies under Stripe’s policy.
15. Security
All traffic is encrypted in transit (TLS). Access to production data is restricted, and per-user data is protected by server-side security rules. No method of transmission or storage is 100% secure, but we design for data minimisation: the most sensitive information — the pages you visit — never leaves your browser or your phone in the first place.
16. Age
The Service is for adults (18+). We do not knowingly process data of anyone under 18; if you believe a minor has created an account, contact us and we will delete it.
17. Changes to this policy
When we change this policy, we will update the date above and, for material changes, notify you by email or in-product notice.