Privacy Policy
Last Updated: July 21, 2026
Welcome to Habit
Welcome to Habit, a guided journaling application designed to provide personalized reflection experiences. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully to understand our practices regarding your data.
By using Habit, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (required for account creation and communication)
- Display name (optional, provided by you)
- Password (encrypted and stored securely by Firebase Authentication)
- Email verification status
- Account creation and last login timestamps
1.2 Journal Entry Data
When you use our guided journaling features, we collect and store:
- Questions presented to you during check-ins
- Your selected answers to questions
- AI-generated insights based on your responses
- Emotional tags and categories assigned to your entries
- Entry timestamps and dates
- Entry type and metadata (e.g., "wordless" journal entries)
- User ratings and feedback on entries
This data is essential for providing personalized journaling experiences and generating insights tailored to you.
1.3 Payment Information
When you make a purchase:
- Payment processing is handled by Stripe, a third-party payment processor
- We store your Stripe customer ID to manage your purchases
- We do not store your full credit card information on our servers
- Stripe collects and processes payment information according to their privacy policy
1.4 Contact and Feedback Information
When you contact us or submit feedback, we collect:
- Name (if provided)
- Email address
- Subject and message content
- Feedback type and CSAT scores (if applicable)
- User ID (if you are logged in)
- Submission timestamp
1.5 Automatically Collected Information
We automatically collect certain information when you use our Service:
- Device information (browser type, operating system)
- Usage data (pages visited, features used, time spent)
- IP address (for security and analytics purposes)
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Provision: To provide, maintain, and improve our journaling services, including generating personalized questions and insights
- Account Management: To create and manage your account, authenticate your identity, and communicate with you about your account
- Personalization: To adapt questions and insights to your emotional state and responses
- Payment Processing: To process payments and manage your purchased check-in packs
- Communication: To respond to your inquiries, provide customer support, and send important service updates
- Analytics and Improvement: To analyze usage patterns, identify technical issues, and improve our Service
- Security: To detect, prevent, and address technical issues, fraud, and security threats
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
3. AI Processing and Data Usage
Habit uses artificial intelligence to generate personalized questions and insights based on your journal entries. This processing involves:
- Analyzing your responses to generate follow-up questions
- Creating personalized insights that reflect your patterns and needs
- Categorizing your entries by themes (Resilience, Gratitude, Purpose, Connection, Wellness, Creativity, Growth)
- Identifying emotional patterns and trends in your journaling history
Your journal content is processed to provide these personalized features. This processing occurs on secure servers, and your data is not used to train general AI models or shared with third parties for AI training purposes.
4. Third-Party Services and Data Sharing
We use the following third-party services to operate our Service. Each service has its own privacy policy:
4.1 Firebase (Google)
We use Firebase for:
- Authentication: User account creation and login
- Firestore Database: Storage of your journal entries, account settings, and app data
- Firebase Analytics: Aggregated usage analytics (page views, feature usage)
Your journal content is stored in Firebase Firestore. Firebase Analytics collects aggregated, anonymized usage data. Your personal journal entries are NOT shared with Firebase Analytics.
Firebase Privacy Policy: https://firebase.google.com/support/privacy
4.2 Google Analytics
We use Google Analytics to understand how users interact with our Service. Google Analytics collects:
- Page views and navigation patterns
- Feature usage statistics
- Device and browser information
- Aggregated, anonymized user behavior data
Important: Your personal journal entries, answers, and insights are NOT shared with Google Analytics. Only aggregated, anonymized usage statistics are collected.
Google Analytics Privacy Policy: https://policies.google.com/privacy
4.3 Stripe
We use Stripe to process payments. Stripe collects and processes:
- Payment card information (encrypted and stored by Stripe, not by us)
- Billing address and contact information
- Transaction history
We only receive confirmation of successful payments and your Stripe customer ID. We do not have access to your full payment card details.
Stripe Privacy Policy: https://stripe.com/privacy
4.5 Postmark
We use Postmark to send transactional emails (account verification, password resets, contact form submissions). Postmark processes email addresses and message content solely for the purpose of delivering emails.
Postmark Privacy Policy: https://postmarkapp.com/privacy-policy
Data Sharing: We do not sell, rent, or trade your personal information to third parties. We only share data with the third-party services listed above as necessary to provide our Service. These services are contractually obligated to protect your data and use it only for the purposes we specify.
5. Data Storage and International Transfers
Your data is stored on servers operated by our third-party service providers, primarily:
- Firebase/Firestore (Google Cloud Platform) - may store data in various regions
- Stripe - processes payments globally
If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those in your country.
We take appropriate measures to ensure that your data receives an adequate level of protection, including:
- Using service providers that comply with applicable data protection laws
- Implementing appropriate contractual safeguards
- Following industry-standard security practices
6. Data Retention
We retain your information for as long as necessary to provide our Service and fulfill the purposes described in this policy:
- Account Data: Retained while your account is active and for a reasonable period after account deletion to comply with legal obligations
- Journal Entries: Retained until you delete them or request account deletion
- Payment Information: Transaction records are retained as required by law (typically 7 years for tax and accounting purposes)
- Contact/Feedback Data: Retained for up to 2 years or until you request deletion
- Analytics Data: Aggregated analytics data may be retained indefinitely in anonymized form
When you delete your account, we will delete your personal information within 30 days, except where we are required to retain it for legal, tax, or regulatory purposes.
7. Your Rights Under GDPR and Other Privacy Laws
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with similar privacy laws, you have the following rights regarding your personal data:
7.1 Right of Access
You have the right to request access to your personal data and receive a copy of the data we hold about you.
7.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
7.3 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data. You can delete your account and data by:
- Using the account deletion feature in the Service (if available)
- Emailing us at contact@habit.am with your deletion request
We will process your deletion request within 30 days, subject to legal retention requirements.
7.4 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances.
7.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another service provider.
7.6 Right to Object
You have the right to object to processing of your personal data for certain purposes, such as direct marketing or where processing is based on legitimate interests.
7.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
7.8 Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.
To exercise any of these rights, please contact us at contact@habit.am. We will respond to your request within 30 days.
8. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise your California privacy rights, please contact us at contact@habit.am.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest
- Secure authentication and access controls
- Regular security assessments and updates
- Firebase security rules to restrict unauthorized database access
- Secure password storage using industry-standard hashing algorithms
- Regular monitoring for security vulnerabilities and threats
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
10. Data Breach Notification
In the event of a data breach that may compromise your personal information, we will:
- Investigate the breach immediately and take steps to contain it
- Notify affected users within 72 hours of becoming aware of the breach (as required by GDPR)
- Notify relevant data protection authorities within 72 hours (as required by GDPR)
- Provide information about the nature of the breach, data affected, and steps we are taking to address it
- Recommend steps you can take to protect yourself
Notifications will be sent to the email address associated with your account.
11. Cookies and Tracking Technologies
We use the following types of cookies and tracking technologies:
11.1 Essential Cookies
These cookies are necessary for the Service to function and cannot be switched off. They include:
- Authentication cookies (to keep you logged in)
- Security cookies (to protect against fraud and security threats)
- Session cookies (to maintain your session while using the Service)
11.2 Analytics Cookies
We use analytics cookies to understand how users interact with our Service:
- Firebase Analytics cookies (for usage analytics)
- Google Analytics cookies (for website analytics)
These cookies collect aggregated, anonymized data and do not include your personal journal content.
11.3 Cookie Management
You can control cookies through your browser settings. However, disabling essential cookies may affect the functionality of the Service.
12. Children's Privacy
Our Service is intended for users who are 16 years of age or older. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child under 16 has provided us with personal information, please contact us immediately at contact@habit.am, and we will delete such information.
If you are between 16 and 18 (or the age of majority in your jurisdiction), you represent that you have your parent's or guardian's permission to use the Service.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to the address associated with your account (for significant changes)
- Displaying a notice on the Service (for major changes)
Your continued use of the Service after changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using the Service and delete your account.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: contact@habit.am
Subject Line: Privacy Policy Inquiry
We will respond to your inquiry within 30 days.
15. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal bases:
- Contractual Necessity: To provide the Service you have requested (e.g., creating an account, processing payments, generating journal insights)
- Legitimate Interests: To improve our Service, ensure security, prevent fraud, and analyze usage patterns
- Consent: Where you have provided consent for specific processing activities (e.g., analytics cookies)
- Legal Obligations: To comply with applicable laws and regulations (e.g., tax and accounting requirements)
16. Data Controller Information
Habit is the data controller for your personal information. For GDPR purposes, if you are located in the EEA, our representative can be contacted at contact@habit.am.
17. Acknowledgment
By using Habit, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. If you do not agree with this policy, please do not use our Service.
Free Resources
For Professionals
© 2026 Habit. All rights reserved.
Build version: v2.18.6