Privacy Policy
Effective date: September 5, 2026
1. Introduction
This Privacy Policy explains how HabitGrip ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use the HabitGrip mobile application (the "App").
HabitGrip is designed as a local-first application — your habits, tasks and activity history are stored on your device and never leave it unless you opt in to cloud sync. The exceptions are the diagnostic data described in Section 3, which you can switch off at any time. We are committed to protecting your privacy and complying with applicable data protection laws, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Data Controller
The data controller responsible for your personal data is:
HabitGrip LLC
United States
Email: [email protected]
3. Data We Collect
Account Data
An account is optional — the App is fully usable offline without one. If you choose to create an account, we collect your email address and, optionally, a display name. Accounts are managed by our own backend service; passwords for email/password accounts are stored only as salted, hashed values and are never kept in plain text. If instead you sign in with Google or Apple, we receive your email address and basic profile information (your name, and where you provide one, a profile picture) from that provider — we never receive your Google or Apple password. The address the provider gives us is stored alongside the one on your account; where they differ, both are kept so that signing in either way finds the same account.
Habit and Activity Data
Your habits, tasks, activity logs, goals, tags, and related data are stored locally on your device using SQLite. If you opt in to cloud sync (Ultra plan), this data is also stored on our servers so it can be synchronized across your devices. Our backend is hosted on Railway and our database is provided by Neon, both located in the United States.
Usage Analytics (Optional)
We collect usage analytics via Firebase Analytics, including screen views and feature usage. This data does not include your personal habit information and is used solely to improve the app experience. Where the GDPR or the Swiss nFADP applies, we ask for your consent before collecting any of it. Elsewhere it is on by default. Either way, you can switch it off at any time in Settings > Tracking Preferences.
Crash Reports & Error Diagnostics (Optional)
We collect crash reports and error logs via Firebase Crashlytics to identify and fix technical issues. This data includes device type, operating system version, and stack traces. No personal habit data is included in crash reports. As with analytics, we ask for your consent first where the GDPR or the Swiss nFADP applies, and elsewhere it is on by default — and you can switch it off at any time in Settings > Tracking Preferences.
When a critical error occurs in the app (for example, a sync or sign-in failure), the app also sends a short diagnostic event to our servers: the error's name and coarse technical context such as counts and status codes. These diagnostic events never include your habits, notes, or any content you have entered.
Subscription Data
If you subscribe to a paid plan, subscription management is handled by RevenueCat. We receive information about your subscription status, plan type, and transaction identifiers. We do not receive or store your payment card details — those are handled directly by the Apple App Store or Google Play Store.
Device Information
We collect basic device information including operating system, app version, and device model for compatibility and debugging purposes.
Session and Security Data
When you sign in, we create a session record so that you stay signed in and can see and end your sessions later. Each record holds the device's name, model and operating-system type, an identifier generated by the app for that installation, the network address the request came from, and the browser or app identification string your device sends. We use this only to keep you signed in, to let you recognise and revoke a session you do not recognise, and to detect abuse of the sign-in system. It is not used to build a profile of you, and it is not shared with anyone.
These records are kept while a session is active and for up to 30 days after it ends, so that we can investigate suspicious sign-ins. They are deleted when you delete your account.
Tracking Technologies
Firebase Analytics uses mobile advertising identifiers (IDFA on iOS, GAID on Android) solely for usage analytics, and only while usage analytics is switched on. You can reset or disable these identifiers in your device settings (iOS: Settings > Privacy > Tracking; Android: Settings > Google > Ads). We do not use cookies, web beacons, or pixels as the App is not web-based.
4. Information We Do Not Collect
We do not collect contacts, photos, health data, financial information, or browsing history.
We do not collect your location. The app does not ask for location permission and contains no location feature — on Android it requests only the permissions needed to schedule reminders. The network address recorded with a sign-in session (see Session and Security Data above) is used for account security, not to determine where you are.
We do not use device fingerprinting or cross-app tracking. The device details we store are attached to a sign-in session on your own account, so that you can recognise and end that session. They are not combined to identify you across other apps or websites, and they are not shared with advertisers or data brokers.
Android Device Backups
If you use an Android device with the system "Backup" feature enabled (Settings > System > Backup), the Android operating system may automatically back up app data — including your local database — to your Google account. This backup is controlled by your device settings, not by HabitGrip. To prevent this, you can disable backup for this app or turn off device backup entirely in your Android settings.
5. How We Use Your Data
We use your personal data for the following purposes:
- To provide and operate the App and its features
- To create and manage your user account
- To sync your data across devices (if enabled)
- To process and manage subscriptions
- To send you notifications and reminders (if enabled)
- To analyze app usage and improve our services (only while usage analytics is switched on)
- To diagnose and fix technical issues
- To respond to your support requests
We do not sell your personal information. We do not use your data for advertising or behavioral profiling.
We do not use automated decision-making or profiling as defined under GDPR Article 22.
6. Legal Basis for Processing (GDPR)
Under the GDPR, we process your personal data on the following legal bases:
- Consent (Article 6(1)(a)): For usage analytics, crash reporting, and marketing communications. You can withdraw consent at any time through the app settings.
- Contract Performance (Article 6(1)(b)): To provide the App's core features, manage your account, and process subscriptions.
- Legitimate Interests (Article 6(1)(f)): For security and fraud prevention: keeping you signed in, letting you review and end your own sessions, and detecting abuse of the sign-in system. Our interest in protecting accounts is balanced against the limited data this involves — details of the device you signed in on, held on your own account and used for nothing else. Where we rely on legitimate interests, you have the right to object under Article 21.
Crash reporting and usage analytics are processed based on your consent (Article 6(1)(a)). You can enable or disable these at any time in Settings > Tracking Preferences.
7. Third-Party Services
We use the following third-party services to operate the App. Each acts as a data processor on our behalf:
- Neon — Cloud database hosting (stores your account and, if you enable sync, your synced data). Privacy Policy.
- Railway — Application and backend hosting. Privacy Policy.
- Cloudflare — Content delivery, DNS, and security/DDoS protection. Privacy Policy.
- Resend — Transactional email delivery, such as email verification and password resets. Privacy Policy.
- Firebase (Google) — Analytics and crash reporting. Privacy Policy.
- RevenueCat — Subscription management. Privacy Policy.
We maintain Data Processing Agreements (DPAs) with each provider as required by the GDPR.
8. International Data Transfers
Our infrastructure and service providers are located in the United States. If you use the App from the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States:
- Neon — Account and synced data are hosted in the United States (AWS US East).
- Railway — Our backend application runs in the United States.
- Resend — Transactional email is processed in the United States.
- Firebase (Google Cloud) — Analytics and crash report data are processed in the United States. Google operates under the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs).
- RevenueCat — Subscription data is processed in the United States under Standard Contractual Clauses (SCCs).
- Cloudflare — Operates a global edge network; requests are routed through the location nearest to you.
For all transfers outside the EEA, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework, to ensure an adequate level of data protection.
9. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
- Account data: Until you delete your account
- Habit data (local): Stored on your device until you uninstall the app or delete the data
- Habit data (cloud): Until you delete your account or request erasure
- Session and security data: Up to 30 days after a session ends, and deleted immediately when you delete your account
- Diagnostic logs sent from the app: Up to 90 days, and deleted immediately when you delete your account
- Analytics data: Retained by Firebase for up to 14 months
- Crash reports: Retained by Firebase for up to 90 days
When you delete your account, your personal data is removed from our servers immediately — the deletion runs as a single operation, with nothing queued for later. Anonymized analytics data may be retained. Database backups containing your data are overwritten within 30 days.
10. Your Rights
Under the GDPR and other applicable data protection laws, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data
- Right to Rectification (Article 16): Correct inaccurate personal data
- Right to Erasure (Article 17): Request deletion of your data. You can delete your account at any time in Settings
- Right to Data Portability (Article 20): Export your habits, tasks and settings in a structured, machine-readable format using the Backup feature in Settings. For a copy of the data held on our servers — your account details, subscription, and sign-in history — contact us using the address below.
- Right to Object (Article 21): Object to data processing based on legitimate interests
- Right to Restrict Processing (Article 18): Request restriction of processing in certain circumstances
- Right to Withdraw Consent: Withdraw consent for analytics at any time in Settings > Tracking Preferences. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
- Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days, as required by applicable law. The Backup feature covers the habit data stored on your device; anything held on our servers is available on request at the same address.
11. Your California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information. You can delete your account at any time in Settings, or contact us at [email protected].
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. As such, there is no need to opt out of any sale.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. All app features remain available regardless of your privacy choices.
You can manage your analytics and crash reporting preferences at any time in Settings > Tracking Preferences. To submit a verifiable consumer request, contact us at [email protected].
12. Disclaimer
The App is intended for general informational and productivity purposes only. It is not a substitute for professional medical, psychological, financial, or other expert advice.
If you have questions or concerns about your health, mental well-being, or any other professional matter, you should consult a qualified professional. Do not disregard professional advice or delay seeking it because of information or habits tracked in the App.
We make no guarantees regarding specific results or outcomes from using the App.
13. Children's Privacy
The App is intended for adults and is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe a minor has provided us with personal data, please contact us so we can delete it.
14. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Data transmitted between your device and our servers is encrypted using TLS/SSL. Your local data is stored on your device and protected by your device's operating-system security (app sandboxing and device-level encryption).
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The Effective Date at the top of this page shows when it last changed, and the current version is always available at this address.
Where a change affects processing that relies on your consent — usage analytics or crash reporting, as described in Section 3 — we will ask for your consent again in the App before that change takes effect. This applies wherever you are, not only in the European Economic Area, the United Kingdom or Switzerland. For changes that do not require your consent, we will tell you in the App and you can review or withdraw your consent at any time in Settings > Tracking Preferences.
16. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
HabitGrip LLC
United States