Habi | Privacy Policy

How Habi handles your account, tracking history and optional sharing.

Last updated: 2026-10-01

Who is responsible

Habi is operated under the name ByCracus. For privacy questions, rights requests or account deletion, contact polfm3@hotmail.com.

This notice covers the Habi app and its public legal pages. It describes current features, not permission for future advertising or unrelated uses.

Local use and verified accounts

You can track habits and workouts without an account. Guest tracking history is stored on your device. Signing in uses a separate account-specific local store; guest history is imported only after your confirmation.

Email/password registration creates an authentication account before verification. You must verify ownership of your email before cloud sync or social features work. Anonymous cloud accounts are not supported. Google sign-in uses the identity and email supplied by Google.

Signing out does not delete your account or its separate local history. Device backup and restore services may keep copies under your operating system settings, even for local-only use.

Information processed

Account information includes your email, authentication identifier, sign-in provider, username and friend code. Firebase Authentication processes passwords for email/password accounts and sign-in security information. Google sign-in may provide a display name; it does not give Habi access to your inbox or contacts.

Tracking content includes habits, completion logs, notes, break days, workouts, routines, exercises, sets, repetitions, weights, durations and preferences. If you use a verified account, this content and synchronization metadata are stored in the cloud to support cross-device use.

Optional social data includes friend requests, accepted connections and the habit summaries you choose to share. Support email contains whatever you send us; avoid passwords and unnecessary sensitive information.

Service providers may process IP addresses, device or installation identifiers, browser or app information, timestamps and security logs to deliver and protect their services. Habi currently has no advertising, dedicated analytics or remote crash-reporting SDK configured.

Purposes and legal grounds

We process account details, requested cloud synchronization and selected sharing to provide the service you ask for. Where the GDPR applies, this is necessary to perform our agreement with you. Support requests are handled to provide assistance and meet applicable obligations.

We use necessary security information to prevent abuse and protect accounts, relying on legitimate interests where applicable and subject to your rights. Processing required by law relies on legal obligations. Optional device permissions remain under your control and can be withdrawn in device settings.

What other users can see

Your username, friend code and account identifier can be looked up by verified users using an exact friend code or known account identifier. Your email is private and is not included in the public profile.

Only mutually accepted friends can read your shared habit summaries. Sharing is optional per habit and includes its name, icon, colour, type, frequency, target and streak. Private notes and detailed workout or completion history are not part of that summary. Turning sharing off or removing a friend stops subsequent authorized reads, but cannot erase screenshots or copies already received.

Providers and international processing

Google Firebase provides authentication and cloud storage. The Firestore database is hosted in Madrid, Spain (europe-southwest1); this does not mean that all authentication, support or provider processing stays in Spain or the EEA. International processing is subject to the relevant provider terms and applicable transfer safeguards, including standard contractual clauses where required.

GitHub Pages hosts these public legal pages and may process visitor IP addresses and technical logs. The pages add no advertising trackers or non-essential cookies. Google Play, Google sign-in and device backup providers also operate under their own privacy notices. Habi does not sell personal data or share it for targeted advertising. Data may be disclosed when legally required.

Device features and sensitive content

Reminders use notification permissions; workout timers may use a foreground service. Notifications and home-screen widgets may show habit or workout information to anyone who can see your device. You can change notification visibility and remove widgets in device settings.

Habi does not request access to your contacts, microphone, camera, precise location or health-platform records. Information you type may nevertheless reveal health or other sensitive matters. Habi is not designed for medical records: avoid entering diagnoses or unnecessary sensitive details, and consider local-only tracking when you do not want content synchronized.

Security and your choices

Cloud access is authenticated and restricted by access rules, with verified email required for sync and social access. Service connections use encrypted transport. Habi does not provide end-to-end encryption or a separate encrypted vault for local history.

No system is completely secure or always available. Protect your device and credentials, keep the app updated, and use a screen lock. You can use guest mode, decline social sharing, change device permissions or request deletion.

Retention and deletion

Cloud account content is kept while the account exists until you delete content or request account deletion. In-app deletion removes the account's cloud profile, synced history and owned social records before removing the authentication account. Required cleanup failures are shown so you can retry; a failed operation must not be treated as completed deletion.

A minimal record containing the authentication identifier and a deletion flag is retained to prevent old devices from recreating deleted data. It contains no email, profile or tracking history and currently has no automatic expiry. Some legacy relationship identifiers may remain without granting access to deleted content. Contact us to review retained identifiers.

Local copies on other devices, operating-system backups and copies received by friends are not remotely erased by account deletion. Providers may retain security records or backups for their applicable retention periods. Support correspondence is retained as needed to resolve the request and meet applicable obligations, then deleted or minimized. Uninstalling or signing out is not a cloud account deletion request.

Your rights

Depending on applicable law, you may request access, correction, deletion, portability, restriction or object to processing, and withdraw consent where consent is the basis. Email polfm3@hotmail.com; we may ask for proportionate proof that the account is yours, never your password.

We respond within applicable statutory deadlines, normally one month for GDPR rights requests, and explain permitted extensions. You may complain to your local data protection authority, including Spain's AEPD. Habi does not make automated decisions producing legal or similarly significant effects about you.

Children

Habi is not directed to children under 13. You must also meet the applicable minimum age or parental-authorization requirements where you live. If you believe a child has provided data in breach of these requirements, contact us so it can be investigated and removed where appropriate.

Changes and contact

The date below identifies this notice's latest revision. Material changes to data use will be explained before they take effect where required; any required consent will be requested separately. Privacy and deletion contact: ByCracus, polfm3@hotmail.com.