Skip to main content
SoberA HaleHearth app
  • Overview
  • Support
  • Privacy
  • Terms

Effective July 15, 2026 · Sober 2.0 and later

Your record stays yours.

Sober is designed so HaleHearth does not receive your recovery journal in the first place. This policy explains the app, the public website, and the separate choice to email support.

Short version: Sober 2.0 does not require or provide a new Sober account. Journey names, urges, slips, notes, pattern summaries, money inputs, and settings are stored locally. The app contains no analytics or advertising SDKs and does not send usage events or journal content to HaleHearth. If an update finds a Sober 1.x Sign in with Apple identity, it is retained only so you can safely erase that legacy identity.

1. Scope and version

This policy applies to Sober version 2.0 and later, identified by App Store ID 6772129200 and bundle ID com.lumenly.sober. If you use an older 1.x build, the disclosures associated with that installed version continue to apply until you update. Legacy network routes may remain available temporarily for those older binaries. Version 2.0 does not use them for ordinary app activity; its only legacy network action is the user-initiated erasure flow described below.

2. What the app collects

HaleHearth does not collect data from ordinary use of the Sober app. In particular:

  • Sober 2.0 does not create a Sober account, email login, profile, or journal server identity.
  • Sober has no analytics or advertising SDKs, tracking pixels, crash-reporting SDKs, or behavioral telemetry.
  • Sober does not use HealthKit and does not request location, camera, photo-library, microphone, contacts, or remote-push access.
  • Sober does not upload journal content to an app backend, cloud-sync service, model provider, or public community.
  • Sober does not create or sell advertising identifiers, user profiles, predictive ratings, or inferred health profiles.

Legacy deletion exception: if Sober 2.0 detects the Keychain identity left by a 1.x Sign in with Apple flow and you choose Delete all Sober data, Sober asks Apple for a fresh confirmation and sends that Apple identity token to https://sober.keenshift.ai/v1/legacy-account. The endpoint verifies the token only for bundle ID com.lumenly.sober, confirms erasure for that same legacy subject, and returns a subject-bound receipt. It does not receive journal content, purchase history, analytics, advertising identifiers, or device data, and it does not log or retain the token or subject. Cancellation, offline status, identity mismatch, authentication failure, service failure, or an invalid receipt leaves the legacy credential and local data in place so you can retry.

3. What stays on your device

Your journeys, start dates, urge entries, trigger tags, self-ratings, slips, notes, user-entered cost and frequency, pattern summaries, preferences, and entitlement state are stored locally in the app container. A minimal read-only snapshot may be stored in Sober’s private App Group so its widget can show information you selected. An updated device may also retain the four Sober 1.x Keychain fields identityToken, userId, email, and givenName until you complete deletion; Sober 2.0 does not use them for sign-in, sync, profiling, or routine operation.

Local notifications are scheduled by iOS on your device. If you enable Face ID or Touch ID protection, Apple’s Local Authentication framework reports only whether authentication succeeded; Sober does not receive or store biometric data.

4. Your controls

  • Edit and undo: correct entries, including an accidental slip.
  • Export: create a file and choose its destination through Apple’s system share sheet. The destination you choose then has its own privacy practices.
  • Delete all Sober data: use Sober’s in-app deletion control. On clean installs it deletes local app-owned data. When a legacy 1.x identity exists, it first requires the same Apple Account and a confirmed legacy erasure receipt, then clears the Keychain identity and local data. Deleting the app also normally removes its app container, but does not cancel a subscription or delete exports saved elsewhere.
  • Notifications: change notification permission in iOS Settings and reminder choices in Sober.

Sober 2.0 creates no account or server copy of your journal, so HaleHearth cannot inspect, recover, export, or remotely erase that local record. The narrow legacy endpoint can only authenticate and confirm erasure of the 1.x identity; it cannot see your on-device journal.

5. App Store purchases

Apple processes Sober Pro purchases. Sober checks signed transaction information on device to determine whether Pro is active. The app does not send purchase receipts or transaction history to HaleHearth. Apple may provide the seller with aggregate App Store sales, proceeds, refund, and subscription reporting under Apple’s own terms; those reports are not linked by Sober to your journal.

See Apple’s Privacy Policy for Apple’s processing.

6. This public website

The Sober website has no sign-in, forms, cookies, analytics, ad pixels, or browser JavaScript. Like every website, its hosting infrastructure necessarily receives standard network request information such as an IP address, request time, requested path, and browser user agent to deliver and secure the page. That network information is separate from Sober’s local journal, and the website has no mechanism to connect it to app content. The separate legacy-erasure route is reachable only through a user-initiated authenticated DELETE request and is not a website tracking surface.

7. Emailing support is optional

If you email nora@halehearth.com, HaleHearth receives the address, message, and attachments you choose to send. Email is outside the Sober app. Please do not include sensitive recovery or health details. Support correspondence is used to answer the request, protect the service, and meet applicable legal obligations, then retained only as long as needed for those purposes.

8. Children

Sober is designed for adults and is not directed to children. The app does not operate an account service or knowingly collect personal information from children.

9. Changes

If a future version adds collection, accounts, sync, analytics, or another network feature, the app and this policy must be updated before that feature ships. We will change the effective date and provide notice appropriate to the change. A future feature will not retroactively upload an existing local journal without clear user action and consent.

10. Contact

Sober is a HaleHearth app. Privacy questions: nora@halehearth.com.

Sober by HaleHearth

Privacy questions? Email Nora.

© 2026 HaleHearth. Sober is not a medical device or crisis service.

  • App Store
  • Support
  • Privacy
  • Terms