Privacy

What your quit-porn app knows about you.

In March 2026, a recovery app with 1.5 million downloads was reported to have left its users’ most private answers sitting in an open database. Here is what happened, why the design made it possible, and how to interrogate any app in this category — including ours.

Adrian Smith·Writes from lived experience·

To use most porn-recovery apps properly, you have to tell them things you have not told anyone. How often. What triggers it. What you were feeling at 1am. Whether last night went badly. That is not incidental to the product — it is the product. The app is useless if you lie to it.

Which makes the obvious question — where does all that go? — the most important one in the category, and the one almost nobody asks before they start typing.

What happened in March 2026

On 10 March 2026, 404 Media reported that Quittr — a porn-recovery app which, per their reporting, claims more than 1.5 million downloads and roughly $500,000 a month in revenue — had exposed its users’ intimate data through a misconfigured database that an independent researcher was able to reach.

According to 404 Media’s investigation (as summarised by Techlicious and Cybernews), the exposed database held more than 600,000 user records — including roughly 100,000 belonging to people who identified as minors — containing ages, masturbation frequency, pornography “triggers”, relapse incidents, mood check-ins and personal journal entries.

The timeline is the part worth sitting with. A researcher reported the flaw to the app’s creator in September 2025 and was told it would be fixed quickly. Months later it was still accessible. 404 Media separately reported that multiple hackers had warned the company. The vulnerability was eventually fixed — that is precisely why 404 Media named the app publicly rather than earlier.

We are stating what was reported, not conducting our own investigation, and we link the original above so you can read it rather than take our word for it. The point of this page is not that one company made a mistake. Misconfigured databases are one of the most ordinary failures in software. The point is what was sitting in it.

Why the design made it possible

A leak is only as bad as what got collected. The reason this one is catastrophic rather than embarrassing is architectural: the app asked for the most stigmatised details of someone’s private life, uploaded them to a server, and kept them there, attached to an account.

Once that decision is made, everything else is a race you have to win forever — every config, every intern, every acquisition, every subpoena, every future owner of the company. You only have to lose once.

The only data that cannot leak is the data you never collected.

And in this category the stakes aren’t “someone sees your email address”. A list of names attached to masturbation frequency and porn preferences is a blackmail dataset. For the ~100,000 records reported to belong to minors, it is considerably worse than that.

How WithAnchor is built — and where we’re exposed too

This is where a page like this usually turns into an advert. So here is the honest version, including the part that isn’t flattering.

What’s true:

  • It works on your device, without an account. You can use WithAnchor without signing in at all. Your plan, your answers, your sessions — they live on your phone.
  • No ads, no trackers, no fingerprinting, no advertising SDKs. The app doesn’t ask for your camera, photos, microphone, location, contacts, calendar or health data. Not “we don’t use it” — it never asks.
  • Nothing is sold or shared with third parties, and your notes and reflections are never used to train AI — ours or anyone else’s.
  • Delete Account genuinely deletes. It cascades across every table and we keep no shadow copy.
  • The self-check on this site has no email field at all. It runs in your browser and sends nothing. You can check that one yourself — open your network tab.

And the part we’re not going to pretend away:

  • If you choose to sign in, there is data on a server. Sign-in is optional and exists so your progress survives a lost phone — but if you use it, your synced entries sit in a managed cloud database. It’s encrypted in transit, access is enforced server-side so only you can read your rows, and we’d rather say that plainly than claim an immunity we don’t have.
  • “Local-first” is a meaningful reduction in risk, not a magic word. The honest claim is that we collect less, ask for nothing we don’t need, and give you a real delete button — not that we are unhackable. Anyone telling you they’re unhackable is the person to worry about.

Our privacy policy spells out every vendor category and every field, in plain English.

How to interrogate any app in this category — including this one

Don’t take anyone’s word for it, ours included. Before you type anything real into a recovery app, ask:

  1. Does it work without an account? If it forces registration before you can use it, everything you enter is attached to an identity from the first tap. Ask why it needs one.
  2. What is the most damaging sentence in its database about me? Write that sentence out. Then decide whether you trust a startup’s server configuration with it, forever, including after the company is sold.
  3. Can I delete it — actually? Not “deactivate”. Look for a delete that cascades, and for a policy that says so in words.
  4. Who benefits from the data? If it’s free, or it has ads, or it reports to an “accountability partner”, your entries are doing a job for someone other than you.
  5. What does the privacy policy actually name? Vague policies are vague on purpose. It should name the categories, the retention, and the deletion path.
  6. Is there a way to verify any of it? Open the network tab on their web tools. Read the App Store privacy label. Claims are cheap; behaviour is checkable.

The thing underneath all this

People type the truth into these apps because they’re desperate and it’s 3am and there is nobody else to tell. That is an act of trust, offered at the worst moment of someone’s week, and it deserves to be treated as seriously as a medical record — by everyone in this category, us included.

The lesson of March 2026 isn’t “use a different app”. It’s that an industry built on people’s most private admissions has been treating those admissions as growth data. Ask harder questions. Of us too.

Sources

  1. 1.404 Media (10 March 2026): “Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users.” (Original investigation; paywalled.)
  2. 2.404 Media: “Multiple Hackers Warned Anti-Porn App Quittr About Security Issue for Months.”
  3. 3.Techlicious (10 March 2026): “Porn addiction app reportedly leaked what users say they watch” — summary of the 404 Media investigation, source of the 600,000 / ~100,000 figures.
  4. 4.Cybernews: “Quittr app leak exposed intimate data of 600K users.”

Adrian writes from lived experience, not clinical practice. Nothing on this site is medical advice. WithAnchor is a paid iPhone app made by Doffy Labs, so we have a commercial interest in you finding this useful. We cite primary sources so you can check the claims yourself.

The practice, in your pocket

WithAnchor puts these techniques one tap away.

No streaks. No scoreboards. Progress that a slip can’t wipe out.

Download on the App Store