Quitty is a health and wellness app that helps users manage smoking cessation with built-in health tracking features.
Quick Verdict
Best for: Tracking habits with minimal privacy trade-offs
What It Means For You
Usage patterns and in-app behavior are collected by analytics services including PostHog and Amplitude. Purchases are handled through RevenueCat, and push notifications are managed by OneSignal. Users have limited control over what data is collected, but nothing is shared with advertising networks.
Quick Verdict
Best for: Tracking habits with minimal privacy trade-offs
What It Means For You
Usage patterns and in-app behavior are collected by analytics services including PostHog and Amplitude. Purchases are handled through RevenueCat, and push notifications are managed by OneSignal. Users have limited control over what data is collected, but nothing is shared with advertising networks.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
1 totalPrivacy
4 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
victor.dev.quittyapp
Version
1.20.0 (Build 72)
Analysis Date
Mar 28, 2026
Classes Analyzed
78,287
Feedback helps us improve our analysis
Data Security - 1 finding (1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 4 findings (3 medium, 1 low)
In-app behavior, session patterns, and habit tracking activity are collected by PostHog and Amplitude for analytics purposes. Purchase history and subscription status are processed through RevenueCat to manage the user's account. Push notification interactions are tracked through OneSignal. Feature requests and feedback submitted by users may be collected through WishKit.
Behavioral and usage data is shared with PostHog and Amplitude. Subscription and purchase data is shared with RevenueCat. Notification interaction data is shared with OneSignal. Data sharing is limited to these functional service providers, with no advertising or marketing networks receiving user data.
| Category | Score |
|---|---|
| Security | 98/100 |
| Privacy | 72/100 |
| Data Security | 93/100 |
| Network Security | 100/100 |
| Code Safety | 100/100 |
| Data Collection | 82/100 |
| Data Sharing | 85/100 |
| User Control | 40/100 |
This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the app's technical implementation as of the scan date.
Developer not yet contacted