GDPR Compliant

Privacy Policy

Last updated: January 2, 2026

This Privacy Policy describes how Cold Turkey ("we", "our", or "us") collects, uses, and protects your personal information when you use our addiction recovery and sobriety tracking app and related services (the "Service"). We are committed to protecting your privacy and ensuring transparent data practices in accordance with Danish and European Union data protection laws.

1. Data Controller Information

Data Controller

Cold Turkey

Location

Denmark, European Union

2. Interpretation and Definitions

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for you to access our Service.
Application refers to Cold Turkey, the software program provided by the Company.
Company (referred to as "the Company", "we", "us" or "our") refers to Cold Turkey, located in Denmark.
Country refers to Denmark.
Device means any device that can access the Service such as a computer, smartphone, or tablet.
GDPR refers to the General Data Protection Regulation (EU) 2016/679.
Personal Data is any information that relates to an identified or identifiable natural person.
Service refers to the Cold Turkey Application.
You refers to the individual accessing or using the Service.

3. Types of Data We Collect

Personal Data

While using our Service, we may ask you to provide certain personally identifiable information, including but not limited to:

Email address
First name and last name
Profile picture (optional)
Age and gender (optional)
Recovery journey data
Sobriety start date

Usage Data & Analytics

We collect extensive usage data automatically, including:

IP address and device information
App usage patterns and interactions
Feature usage and preferences
Session duration and frequency
Crash reports and error logs
Search queries and results interaction

Recovery & Journal Data

Sensitive Recovery Information: Your recovery journey data includes:

  • Streak and milestone tracking - your sobriety progress and achievements
  • Journal entries - your personal thoughts and reflections
  • Relapse tracking - only used to support your recovery journey
  • Community posts and comments - shared with other users when you participate
  • Can be deleted - by you at any time through your account settings

Third-Party Analytics & Advertising Data

We use extensive tracking through the following services:

RevenueCat

For subscription and purchase analytics:

Purchase behavior and patternsSubscription status and renewalsRevenue attributionCohort analysisChurn predictionLifetime value calculations

Meta (Facebook/Instagram) Ads

For advertising optimization and targeting:

Ad performance trackingConversion trackingCustom audience creationLookalike audience generationRetargeting campaignsAttribution modeling

TikTok Ads

For TikTok advertising and analytics:

Campaign performance trackingUser behavior analysisConversion optimizationAudience insightsAttribution trackingCustom event tracking

4. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

Consent

When you provide explicit consent for advertising tracking, analytics, and marketing communications

Contract

To perform our contract with you and provide the Cold Turkey Service

Legitimate Interest

For improving our Service, security, business operations, and fraud prevention

Legal Obligation

To comply with applicable laws and regulations

5. How We Use Your Personal Data

Service Provision

  • Track your sobriety streaks and milestones
  • Manage your account and recovery preferences
  • Process subscriptions and purchases
  • Provide customer support

Analytics & Optimization

  • Analyze app usage and performance
  • Improve recovery support features
  • Optimize user experience
  • Measure subscription performance

Marketing & Advertising

  • Deliver personalized advertisements
  • Measure ad effectiveness
  • Create custom audiences
  • Send promotional communications

Security & Compliance

  • Ensure platform security
  • Prevent fraud and abuse
  • Comply with legal obligations
  • Resolve disputes

6. Data Sharing and Disclosure

⚠️ Important: We do not sell your personal data to third parties.

We may share your personal information in the following situations:

Third-Party Analytics Providers

RevenueCat, Meta, TikTok for analytics and advertising purposes (with your consent)

Service Providers

Cloud hosting, payment processing, customer support, and other operational services

Legal Compliance

When required by law, court order, or legal process

Business Transfers

In case of merger, acquisition, or sale of assets (with prior notice)

7. Data Retention

Account Data

Until account deletion + 30 days

Usage & Analytics Data

2-3 years for business analytics

Images

Until you delete them or close your account

Legal Compliance Data

As required by Danish/EU law

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Access & Portability

  • Request access to your data
  • Receive data in structured format
  • Transfer data to another service

Control & Correction

  • Correct inaccurate data
  • Restrict processing
  • Object to processing

Deletion & Consent

  • Request data deletion
  • Withdraw consent anytime
  • Opt-out of tracking

Legal Recourse

  • File complaints with authorities
  • Seek legal remedies
  • Contact our DPO

9. Cookies and Tracking

We use extensive tracking technologies including:

Essential Cookies

Session management, authentication, preferences

Analytics Cookies

Usage patterns, performance metrics, A/B testing

Advertising Cookies

Ad targeting, conversion tracking, retargeting

You can control cookies through your browser settings, but some functionality may be limited.

10. International Data Transfers

Your data may be transferred outside the EEA to:

United States: Meta, RevenueCat, TikTok (with adequate safeguards)
Safeguards: Standard Contractual Clauses, adequacy decisions, certification schemes

11. Children's Privacy

Age Requirement: 16+

Our Service is not intended for anyone under the age of 16. We do not knowingly collect personal data from children under 16.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately and we will take steps to remove such information.

12. Data Security

We implement comprehensive security measures to protect your personal data:

Technical Safeguards

  • Encryption in transit and at rest
  • Secure API communications
  • Regular security audits
  • Access logging and monitoring

Organizational Measures

  • Staff training on data protection
  • Access controls and authentication
  • Incident response procedures
  • Regular policy updates

Note: While we implement industry-standard security measures, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

Posting the new Privacy Policy in the app
Sending you an email notification
Push notification (if enabled)
Updating the "Last updated" date

Important: For significant changes affecting your rights, we will obtain your consent where required by law.

14. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

General Inquiries

Email: simon@coldturkey.io

GDPR Requests

Email: simon@coldturkey.io

For data access, deletion, or portability requests

Response Time

We will respond to your inquiry within 30 days as required by GDPR

Danish Data Protection Agency

If you wish to file a complaint about our data processing, you can contact the Danish Data Protection Agency (Datatilsynet):

Website: www.datatilsynet.dk

Email: dt@datatilsynet.dk

Thank you for trusting Cold Turkey with your recovery journey

We're committed to protecting your privacy while supporting you on your path to recovery