Recovrr App Privacy Policy

The short version

You need only a small amount of information to create a Recovrr account. An email address is required, but most profile information is optional.

Only approved members who are signed in can access member information. The app does not display a member’s geographic coordinates or map position. Optional In Person discovery can show nearby members your presence and approximate device-to-device distance. Geographic member discovery and Nearby Discovery have separate controls, and both are off by default.

Only members who have a mutual connection with you can see your phone number or meeting attendance. Your connection list is private. Blocking hides each member from the other.

Recovrr does not sell member information, use it for advertising, or give it to data brokers.

This policy applies to the Recovrr app and the Recovrr application server that the app uses.

Recovrr helps Narcotics Anonymous members, and people with a legitimate interest in NA, find meetings and connect privately with other Recovrr members.

Recovrr.org Inc. is independent of Narcotics Anonymous, Narcotics Anonymous World Services Inc., and na.org.

Your Account

You need an approved Recovrr account to use member features in the app.

Your account requires a valid email address. We use it to identify and manage your account, sign you in, help with password resets, and send Recovrr messages that need to reach you.

The Recovrr service stores your email address, but other Recovrr members cannot see it.

Accounts must be approved. An authorized Recovrr administrator may review an account request before activating it.

The server returns member information only to an authenticated account. An app or direct API request without a valid login bearer token receives no member information.

Passwords and Login Information

Recovrr does not store your password on the server as readable plain text.

The server stores authentication information that lets it check your password. It does not store a copy that can be read or retrieved.

If you forget your password, it is reset. An administrator cannot recover and show you the old password.

The app may save login credentials or related authentication information in Apple’s keychain on your device. This keeps you from having to enter the information every time you use the app.

Apple’s keychain is part of the operating system. Depending on your Apple settings and configuration, keychain items may remain after you reinstall the app or may be available through Apple’s device or account features.

Recovrr provides a way to erase saved login information from the device when needed.

Your Profile

Your Recovrr profile contains information that identifies you to other members of the service.

Depending on what you choose to provide, your profile may include:

  • a display name;
  • a profile image;
  • a tagline;
  • a clean date;
  • an optional location used for member discovery;
  • a phone number;
  • meeting attendance information; and
  • information needed for connections, requests, blocking, and notification choices.

Most profile information is optional.

Your display name does not have to be your legal name.

When the app displays profile information, it shows only the fields allowed by Recovrr’s visibility rules. Geographic coordinates and map positions are not displayed in member Profiles or lists. In Person may show a nearby member’s approximate distance, as described below.

Profile Image

You may add a profile image.

If you do not add one, the app may use a placeholder.

A saved profile image is part of your Recovrr profile. Other members may see it wherever the app displays your profile information.

Do not use an image unless you are comfortable sharing it with members who can view your profile.

Tagline and Clean Date

Your tagline and clean date are optional.

If you provide them, they become part of your profile. Other Recovrr members who may view your profile can see them.

Phone Number

A phone number is optional.

Your phone number has stricter limits than ordinary profile information. Only members who have a completed mutual connection with you can see it.

If your number supports text messages, the app may let connected members call or text it through normal device features.

Location

Location is optional account information. Recovrr may use it to decide which members appear in location-based discovery lists.

Location-based member discovery is turned off for new accounts.

If you turn it on, your location may help place you in “Local Members” in the Map tab or in “Suggested” results under Find Others in the Network tab.

In Local Members and Suggested, the app does not display your geographic location, coordinates, map position, or a distance calculated from that location. Your Profile may be included in those lists based on location. In Person is a separate, optional proximity feature.

A signed-in person using the API directly may receive a latitude and longitude pair for a member. Before returning that pair, the server replaces the precise location with a randomized location within about a five-kilometer radius. The access check and location obfuscation are enforced on the server, not only in the app interface.

You can turn off location-based member discovery in Recovrr’s Settings. Other members can still find you using Search under Find Others in the Network tab, subject to Recovrr’s visibility and blocking rules. The Nearby Discovery setting is separate: turning off geographic member discovery does not turn off In Person discoverability.

When location-based member discovery is turned off:

  • you do not appear in Local Members in the Map tab; and
  • you do not appear in Suggested under Find Others in the Network tab.

Using Location on the Device

The app may ask iOS for permission to use your device location. It may use location to find nearby meetings, position a map, or update the optional location used for member discovery.

iOS controls whether the app may access protected location information.

You can deny or remove location permission in your device’s privacy settings.

The app may use a precise device location to complete a task you request. The app does not display that member location to anyone.

Meeting Locations Are Different

Recovrr treats private member-location information differently from a meeting location.

Meeting information comes from meeting-list services. It may include an exact street address or other precise location because members need that information to find an in-person meeting.

The rule that the app does not display a member’s location does not apply to the public or published location of a meeting.

Nearby Meetings

The Nearby Meetings feature provides a useful local list. It does not promise to include every possible meeting.

The search distance may change. A dense area may use a smaller search radius than a rural area.

Nearby Discovery (In Person)

On supported iPhones and iPads, Network → Find Others → In Person uses direct device-to-device communication and Apple’s Nearby Interaction technology to find members within about 5 meters (16 feet). Both people should have Recovrr running. This is separate from geographic member discovery and does not share your geographic coordinates.

Nearby discoverability is Off by default. The setting is stored on your device, not on the Recovrr server. In Settings, Always Allow Nearby Discovery makes you discoverable while Recovrr is open in the foreground. In My Profile, Allow Nearby Discovery Once enables discovery for one connection interaction and is hidden when Always is enabled. One-Time turns off when the interaction is accepted, rejected, blocked, deferred with Later, or interrupted. You can turn discoverability off at any time.

When you allow discovery, nearby members may see your display name, profile image if provided, existing relationship, and approximate distance. Opening your Profile or receiving your connection request may also show other permitted profile information, including your clean date if provided. Phone numbers and meeting attendance remain restricted to mutual connections. Enabling discovery reveals that you are a nearby Recovrr member.

Devices exchange a Recovrr member identifier, temporary session information, and connection-interaction messages over an encrypted local link. Nearby discovery does not send profile fields, email addresses, passwords, login tokens, or geographic coordinates over that link. Profile information comes from Recovrr’s ordinary authenticated member service or its local cache. The server is still used to load Profiles and save or check requests, connections, and blocks.

Nearby distance measurements are processed on the devices and are not sent to the Recovrr server or saved as a distance history. The app remembers discovered member identifiers locally across restarts for the same account, and clears that list on sign-out. This list does not store encounter times or geographic locations. Remembering a member does not keep them visible after they stop being discoverable, except while a connection interaction is being resolved.

You can look for nearby members while your own discoverability is Off. Using connection controls with a nearby member identifies you to that member and may show them your approximate distance. Finding a member does not create a mutual connection: the recipient must accept. Reject or Later ends the immediate invitation but leaves the request pending. Blocking sends no block notification to the other member and prevents the members from being shown to each other.

Nearby discovery requires supported hardware and the relevant device permissions, including Nearby Interaction and Local Network access. You can manage these permissions in your device’s privacy settings. Moving Recovrr to the background stops nearby discovery and ranging. Turning off Nearby Discovery does not cancel existing requests or connections or erase information another member has already seen.

Meeting Attendance

You may tell Recovrr that you attend a meeting regularly or plan to attend a certain meeting occurrence.

Meeting attendance is optional member information.

Attendance information is restricted. Only members who have the required completed connection with you can see it. It is not part of your general public profile.

Connections

Recovrr members start without connections to one another.

A connection is mutual.

One member may send a connection request. The connection is complete only when the other member accepts it.

A completed connection may give the two members added information or features, including phone-number visibility and meeting-attendance information.

Your Relationship List Is Private

Recovrr must store relationship information to provide connection requests, mutual connections, blocking, and related features.

The Recovrr member app and RecovrrServer API allow a signed-in member to retrieve only their own relationship list or graph. The server prevents access to another member’s graph. This restriction also applies to administrators using the member system.

Authorized administrators can view member relationship graphs only through the completely separate administrative app, API, and server, for the permitted administrative purposes described below. This access is never available through the RecovrrServer API.

Blocking

You may block another member.

Blocking affects visibility in both directions.

While a block is active, the blocked member cannot see you through Recovrr, and you cannot see that member through Recovrr.

The service must keep the relationship information needed to enforce the block.

Email Between Members

Recovrr lets members contact one another without showing their private email addresses.

When you use Recovrr to email another member, the Recovrr server routes the message.

The sender does not need to receive the other member’s private email address.

In the same way, receiving a message through Recovrr does not mean that Recovrr has shown you the sender’s private account email address.

The email service must use the destination address internally to deliver the message.

Feedback and Reports

The app may let you contact Recovrr, send feedback, or report a member or problem.

Information you choose to include in feedback or a report is sent to Recovrr so that authorized people can review it.

Depending on the feature, feedback may identify you or may offer an anonymous option.

If you ask Recovrr to respond, we need enough contact information to reach you.

Information Stored on the Recovrr Server

Recovrr stores the information it needs to operate the member service.

Depending on how you use the app, this information may include:

  • your account identifier;
  • your email address;
  • authentication information;
  • your display name and other profile fields;
  • profile-image data;
  • optional geographic location information and your setting for location-based member discovery;
  • an optional clean date;
  • an optional phone number;
  • meeting-attendance information;
  • connection requests and completed connections;
  • blocked relationships;
  • notification preferences or related information; and
  • other application information needed for features you use.

The service uses this personal information to provide and operate Recovrr.

Why We Use This Information

We use account and profile information to:

  • sign you in;
  • maintain your account;
  • show your profile under Recovrr’s visibility rules;
  • include eligible members in location-based discovery lists when that feature is on;
  • create and enforce connections, requests, and blocks;
  • show information that is limited to connected members;
  • route communications;
  • manage the service;
  • provide support;
  • prevent or investigate abuse;
  • find software and server problems; and
  • protect the service’s security and reliability.

We do not use this information to build advertising profiles.

Meeting Service

The Recovrr app also communicates with a separate Recovrr meeting service.

That service gathers meeting information from BMLT sources maintained by independent Narcotics Anonymous service bodies and BMLT data maintainers. Recovrr uses this information for meeting search and display. Recovrr does not own, control, or edit the official meeting records.

Meeting information is different from Recovrr member profile information. Meeting records may contain public or published information, such as the meeting name, schedule, formats, online-meeting details, and physical address.

The official meeting records are maintained independently. To correct a record, contact the NA service body or BMLT data maintainer responsible for it. Recovrr can show the correction after the source data is updated.

Technical and Server Information

When an app connects to an Internet server, the server receives technical information needed for the connection.

Operational server records may include:

  • a network or IP address;
  • the date and time;
  • the requested endpoint or operation;
  • HTTP or server information;
  • errors and diagnostic information; and
  • security events.

We use operational information to run, diagnose, maintain, and protect the service.

We do not use it for advertising.

We do not publish a fixed retention period for ordinary operational logs. The period may vary based on hosting, diagnosis, backup, and security needs.

Administrators

Recovrr’s administrative system is separate from the member app and its server API. Administrators do not use the Recovrr app or the member API to perform administrative work or obtain administrative information.

Administrative work uses a separate app, a separate API, and a separate server. Access to that system requires passkey-based authentication. The Recovrr member app, member API, and member server expose no administrative screens, endpoints, privileges, or administrative information.

A limited number of authorized administrators may use the separate administrative system to:

  • review account requests;
  • manage accounts;
  • reset credentials;
  • respond to support requests;
  • investigate reports, abuse, or security problems;
  • lock or delete an account; and
  • maintain the service.

If an administrator signs in to the Recovrr member app, the administrator has exactly the same access as any other member. An ordinary Recovrr login or member bearer token cannot provide administrative access.

Information hidden from ordinary members may be available through the separate administrative system when an authorized administrator has a valid operational need. Recovrr limits this access to administration, operation, support, safety, and security—not advertising, profiling, or sale.

Third Parties and Infrastructure

Apple

Apple distributes the app and provides operating-system services that the app uses.

Apple’s own privacy practices apply to information Apple processes through the App Store, iOS permissions, device services, Apple accounts, keychain behavior, and similar Apple features.

Meeting Infrastructure

Recovrr’s meeting-search systems process meeting searches separately from the Recovrr member-account server.

The meeting information comes from independently maintained BMLT sources, as explained in the Meeting Service section.

Internet and Hosting Providers

Network, hosting, domain, email-delivery, security, and similar service providers may process technical information while providing those services.

Recovrr does not give member information to third parties for advertising or data-broker purposes.

Advertising, Profiling, and Sale

Recovrr does not show third-party advertising in the app.

Recovrr does not sell member information.

Recovrr does not give member information to data brokers.

Recovrr does not use the member service to build commercial behavior profiles.

Security

Recovrr uses technical and administrative safeguards designed to protect member information.

The server does not store credentials as readable passwords.

The app uses encrypted HTTPS connections to its production services.

Member profiles and other member information require an authenticated account. The server does not return member information when an app or direct API request lacks a valid login bearer token.

Administrative access uses a separate app, API, and server protected by passkey-based authentication. The member app and member API provide no administrative information or capabilities. An administrator who signs in to the member app receives only ordinary member access.

The app uses Apple’s keychain for sensitive login information saved on the device.

The app does not display a member’s geographic coordinates or map position. If an authenticated API response includes member coordinates, the server returns only a location randomized within about a five-kilometer radius. The server enforces both authentication and location obfuscation.

Member-to-member email does not reveal private email addresses to ordinary members.

No Internet-connected service can promise that unauthorized access will never happen.

If Recovrr learns of a security incident involving personal information, we will respond based on the incident and the requirements that apply.

Account Deletion

You can delete your Recovrr account through the service’s account-management process.

Account deletion permanently removes the account’s application data from the Recovrr server.

Deleting your account may not erase information held outside the Recovrr account database or controlled by another system. Examples include:

  • an email already delivered to another person’s mailbox;
  • information kept independently by Apple;
  • ordinary server or security logs;
  • backups that have not yet reached the end of their backup cycle; or
  • records Recovrr must keep for a valid legal or security reason.

If these limited operational copies exist, Recovrr does not use them to rebuild an active deleted account.

Deleting Local Login Information

Deleting the Recovrr app and deleting a Recovrr account are different actions.

Login information may be stored in Apple’s keychain. For this reason, deleting the app from a device may not erase every keychain item that keeps you signed in.

Recovrr provides a device-side history and login eraser for members who want to remove this saved login information.

Your Choices and Control

Depending on the feature, you can control your information by:

  • choosing which optional profile fields to provide;
  • turning off geographic member discovery and separately controlling Nearby Discovery;
  • changing your profile information;
  • deciding whether to accept a connection;
  • removing or changing a relationship where the app allows it;
  • blocking another member;
  • deciding whether to provide a phone number;
  • deciding whether to record meeting attendance;
  • controlling iOS permissions on your device;
  • removing login information saved on your device; and
  • deleting your Recovrr account.

Some choices change whether a feature can work. For example, turning off location-based member discovery keeps you out of Local Members and Suggested. Other members can still find you using Search under Find Others in the Network tab, subject to Recovrr’s visibility and blocking rules. The Nearby Discovery setting is separate: turning off geographic member discovery does not turn off In Person discoverability.

Legal Requirements

Recovrr does not disclose member information just because someone asks for it.

We may preserve or disclose information when we reasonably believe valid legal process requires it. We may also do so when needed to protect the service’s security and integrity or to address an immediate threat where the law allows it.

If this happens, we will limit the disclosure to what the circumstances reasonably require.

Children

Recovrr is designed for people who take part in Narcotics Anonymous or have a legitimate interest in NA. It is not designed to collect information from children.

If we learn that an account includes a child’s personal information that should not have been collected, we will take reasonable steps to address the account and the information.

Changes to This Policy

We may update this policy when Recovrr’s features, systems, or privacy practices change.

We will update the policy if there is a meaningful change to the personal information Recovrr collects, who can see it, or how it is used.

The date at the end of this page shows when this version was last updated.

How Apple’s App Privacy Label Maps to Recovrr

Recovrr’s App Store label condenses several different app features into seven broad categories. The practical meaning is easier to understand by looking at the Recovrr capability that creates or uses each kind of data.

Recovrr is a signed-in, account-based service. Information stored for a feature is tied to the account that owns it or created it. This lets the server return the correct profile, enforce connections and blocks, apply visibility rules, and deliver the right notifications. That account association is why the categories appear under “Data Linked to You.”

Here is what each category means in Recovrr:

Health & Fitness

Account review, clean dates, meeting attendance, and anniversaries

An account requester may provide information about a legitimate interest in NA or recovery for review through the separate administrative system.

A member may add a clean date to a profile; Recovrr uses it to calculate clean time and anniversaries, and connections may receive anniversary notifications. A member may also record plans to attend a meeting next time or regularly.

Clean dates are visible to signed-in members when provided, while meeting attendance is limited to connections. This category reflects recovery-related information, not a workout-tracking feature.

Location

Meeting search and optional member discovery

The app may use device location to center a map or find nearby meetings. Separately, a member may allow a stored location to be used for inclusion in Local Members or the Suggested section of Find Others.

The app does not display a member’s geographic coordinates or map position. Optional In Person discovery can show nearby members your presence and approximate device-to-device distance. In Person proximity measurements are processed on the devices and are not sent to the Recovrr server.

A direct API request must have a valid login bearer token, and any member coordinate returned by the server is randomized within about a five-kilometer radius. Turning on Hide My Location keeps you out of Local Members and Suggested. Other members can still find you using Search under Find Others in the Network tab, subject to Recovrr’s visibility and blocking rules. The Nearby Discovery setting is separate: turning off geographic member discovery does not turn off In Person discoverability.

Contact Info

Account email and optional phone number

Recovrr uses the required email address for sign-in, password help, and messages that must reach the member. Authorized administrators may also use it for account approval and administration through the separate administrative system.

The member app does not show that address to other members; member-to-member email is relayed without exposing either private address.

A phone number is optional and is available only to mutual connections, who may use normal device functions to call or text it.

Contacts

Recovrr relationships, not the device address book

This category maps to Recovrr’s own member relationship graph: connection requests sent and received, accepted connections, and blocks. Recovrr needs this state to show the correct relationship controls, limit connection-only information, and enforce blocks in both directions.

It does not mean that Recovrr imports or uploads the contacts stored on the member’s iPhone or iPad. In the member app and RecovrrServer API, members can access only their own graph. Administrators can view another member’s graph only through the separate administrative app, API, and server.

User Content

Profiles, messages, feedback, and reports

This includes a display name, avatar, tagline, text supplied with an account request, member-to-member message content, and anything a member writes in feedback or a report.

Recovrr receives only the profile image the member chooses to take or select, not the member’s whole photo library. Profile content is shown only to signed-in members under the profile rules, and messages go to the chosen recipient.

Account-request text, feedback, and reports may be reviewed by authorized administrators only through the separate administrative system. Feedback may be sent anonymously when that option is available.

Identifiers

The Recovrr account and its authenticated requests

An internal account identifier ties together the member’s profile, settings, connections, blocks, meeting attendance, and notification state. Nearby Discovery also exchanges your member identifier directly with a nearby device when you allow discovery or use nearby connection controls. Discovered member identifiers may be remembered on that device as described above.

Authentication information and the login bearer token let the server determine which account is making a request. The server returns no member information when that proof of sign-in is missing or invalid.

These identifiers are used to operate the account, not to build an advertising profile.

Other Data

Feature state and service operations

This covers information that does not fit neatly into the other categories, such as location-discovery and notification settings, whether notifications are read, unread, or ignored, and other state needed to provide app features. The Nearby Discovery preference and remembered nearby-member list are stored on the device, rather than the Recovrr server.

Account-approval and administrative state is handled through the separate administrative system.

Other Data can also include ordinary server records, errors, diagnostic details, and security events used to maintain and protect the service.

Not every account contains every type of information in the label. An email address and account authentication are required. A clean date, phone number, avatar, tagline, meeting attendance, location-based member discovery, feedback, and most other profile content are choices the member makes.

The App Store categories also do not show Recovrr’s different access levels.

A person who is not signed in receives no member information. Signed-in members see only the permitted profile fields. Mutual connections may also see an optional phone number and chosen meeting attendance.

Authorized administrators may access information for account review, support, safety, and service operations only through the separate passkey-protected administrative app, API, and server. The member system exposes no administrative information, and an administrator using the member app has only ordinary member access.

The app does not display a member’s geographic coordinates or map position. Recovrr does not use any of this information for advertising, sell it, or give it to data brokers.

Questions

If you have questions about this policy, your Recovrr account, or information connected with your account, please contact Recovrr.org Inc. through this website.

Last updated: October 5, 2026