Privacy policy
Your record lives on your phone.
EFFECTIVE 2026-07-02 · OPERATOR: INQUIRING MINDS
- Habit data, check-ins, your writing
- On your device
- Account identity
- Random ID · no name required
- Cloud sync
- Pro · opt-in
- Your photo, if you use portraits
- Sent once per render · never stored
- Ads · analytics · trackers
- None
- Selling or sharing data for marketing
- Never
- Export and deletion
- Built in
Who operates AntiVision
AntiVision: Change Course (the app) and antivisionapp.com (this website) are operated by Inquiring Minds (“we”), based in Tennessee, United States. For anything in this policy, write to mtaylorezell@gmail.com.
What stays on your phone
The app is local-first. Everything it records is stored in a database inside the app’s own sandbox on your device:
- the habits you set up, and the numbers you enter about them
- daily check-ins, including relapse and SOS entries
- your anti-vision writing, verbatim
- settings, including your intensity level
- generated portrait images, if you use that feature
None of it leaves the device unless you turn on Pro sync or generate a portrait, as described below. The app works fully offline. Settings includes a JSON export of your complete record and an erase-everything control that deletes the local database and portrait files. Deleting the app deletes all local data with it.
The account is a random ID
When the app first reaches the network it creates an anonymous account: a randomly generated identifier with no name, email address, or phone number attached. It exists so purchases, sync, and portrait generation can work without a sign-up wall. Accounts live in our database provider (Supabase); every row is scoped to your account ID and the database enforces that one account cannot read another’s rows. If you later claim the account with an email or Apple sign-in, we store the email address you provide; until then there is nothing that names you.
If you turn on Pro sync
Pro sync copies your habits, inputs, check-ins, anti-vision entries, and settings to rows owned by your account ID, so a new phone can restore them. For portraits, sync stores metadata only — horizon, variant, model used, timestamps. The portrait image files themselves never leave your device, with one transient exception during generation, described next.
Portraits and your photo
Portraits are optional; the app is fully functional without them. If you provide a photo and request a render, the app sends that photo once, encrypted in transit, through our server function to the AI provider that produces the image (OpenAI or Google, depending on the configured model). Our function is stateless: it does not store your photo, does not store the generated images, and does not log image contents. The finished pair is returned to your phone and saved only there. Outputs from Google models carry an invisible SynthID watermark identifying them as AI-generated. Deleting portraits in Settings really deletes them — the image files and their records.
Purchases
Pro is purchased through Apple’s App Store; Apple processes the payment and we never see your payment details. Our subscription processor (RevenueCat) receives the purchase receipt tied to your account’s random ID — never your email or an advertising identifier — so the app can unlock Pro and restore it later.
Notifications
The daily flash and evening check-in reminders are scheduled on your device. There is no push server; notification content is generated locally and never transmitted.
What we don’t do
- No ads, and no ad networks in the app or on this site.
- No third-party analytics or tracking SDKs.
- No sale of personal information, and no sharing for marketing.
- No cross-app tracking and no advertising identifiers.
Deletion, stated plainly
The in-app erase deletes everything on your device. One gap, stated plainly rather than papered over: if you used Pro sync, rows already copied to the server are not yet deletable from inside the app. Email mtaylorezell@gmail.com from any address and name the request; we delete the synced rows and the account itself. We intend to replace this with an in-app control.
Security
Data in transit is encrypted (TLS). Server-side rows sit behind row-level security scoped to your account ID, and provider API keys are held in server secrets the app never contains. No storage is perfectly secure — which is one reason the record stays on your phone by default. We keep the smallest server-side footprint the features allow.
This website
antivisionapp.com sets no cookies and runs no analytics. If you join the waitlist, we store the email address you enter in order to write to you about availability — nothing else is collected with it, and an email to us removes it. Our hosting produces standard, short-lived server request logs (such as IP addresses) that we do not use to identify anyone.
Children
AntiVision is rated 17+ and is not directed at children. We do not knowingly collect personal information from children under 13; if you believe a child has provided some, contact us and we will delete it.
Your rights
Depending on where you live, you may have legal rights to access, correct, delete, or receive a copy of personal information. The in-app export and erase tools cover most of that directly; for anything server-side, or any question about this policy, email mtaylorezell@gmail.com.
Changes
When practices change, we update this page and its effective date. A material change to what the app sends off-device will also be stated in the app.