Legal
Privacy Policy
Habitual is a social accountability network. Pairs and small pods share one ring, and that ring only closes when everyone due that day shows up. This policy explains what information that requires — and what it does not.
What this policy covers
This policy applies to habitual.site, the Habitual waitlist, the Habitual web app, and the Habitual iOS app (together, the “Services”). It also covers information we receive when you connect a third-party service such as Sign in with Apple, Apple Health, or Strava.
By using the Services, you agree to this policy. Our Terms of Service govern use of the product itself.
Information we collect
We collect only what we need to run accountability between people — identity, the commitment you lock, proof that you showed up, and the relationships those things sit inside.
You provide
- Waitlist: first name, email address, and optional notes about who you would invite and what you care about.
- Account: email address and first name. On iOS you may also use Sign in with Apple, which can share your Apple user identifier, name, and email if you choose to.
- Profile: last name, handle, city, bio, Season Home Timezone, profile photo, and visibility settings.
- Commitments and Chapters: titles, categories, cadence, proof method, and the partner or pod you form them with.
- Proof: photo check-ins, personal attested check-ins, and — on iOS — connected activity summaries you choose to submit.
- Communities: membership, organizer details, public community name, city, tagline, and challenges you create or join.
- Communications: invite messages, reactions, comments, and support mail you send us.
We collect automatically
- A session cookie on the web app (habitual_uid) so you stay signed in. It is httpOnly, scoped to our site, and lasts up to one year.
- Product analytics events when analytics are enabled — for example that you viewed a page, joined the waitlist, created a Chapter, or closed a ring. These events are named for product use, not advertising profiles.
- Technical logs from our hosts (currently Vercel and Supabase), which may include IP address, browser or device type, and timestamps needed to operate and secure the Services.
Device permissions (iOS, optional, asked in context)
- Camera and photo library — to add a profile photo or photo proof when you show up.
- Location while using the app — only to suggest the nearest US city from our catalog, so we can point you toward nearby communities. We do not store a live trail of your location.
- Contacts — to help you find people you already know to be accountable with. We do not use your address book for advertising.
- Apple Health — we read recent workouts to verify a commitment you asked us to verify. Habitual does not write to Health.
- Notifications — to remind you that someone is waiting on the ring.
Habitual does not track you across other companies’ apps. We do not use the App Tracking Transparency prompt to build a cross-app advertising identity.
Connected apps and health data
If you connect Strava or another activity provider, we receive the activity metadata you authorize — typically title, sport, start time, and duration — so you can attach that activity as proof. Tokens are used to fetch that proof. We do not post to those services on your behalf.
Health and workout data from Apple Health or a connected provider is used only to verify the commitment you locked. We do not sell it, use it for advertising, or give it to data brokers. Disconnect the provider in Settings to stop future reads. Proof you already submitted to a Chapter remains part of that Chapter’s history, because history on Habitual is not rewritten.
How we use information
We use the information above to:
- Create and authenticate your account and keep you signed in.
- Form pairs and pods, run Seasons and Chapters, evaluate the shared ring, and show Today, Feed, and Season.
- Show proof to the people who need it — your partner or pod, and anyone you have chosen via visibility settings.
- Operate communities, public community pages, and invites.
- Send transactional mail and, on iOS, local reminders you have allowed.
- Contact waitlist members about early access. Joining the waitlist does not subscribe you to unrelated marketing.
- Keep the Services reliable and safe: spam controls (including a hidden honeypot on the waitlist form), abuse, debugging, and security.
- Understand, in aggregate, whether the product is working — for example that a first ring closed — not to sell ads against your habits.
How long we keep information
Waitlist records are kept until we have offered you access or you ask us to delete them.
Account, Chapter, proof, and community records are kept while your account is open. Habitual is built around permanence — a missed day stays missed, and a closed ring stays closed — so history is not silently rewritten. If you delete your account, we remove your profile and personal identifiers. Aggregated ring history that other people still need (for example that a partner’s ring closed that day) may remain in de-identified or partner-visible form so their record stays honest.
Backups, security logs, and legal holds may last a short additional period. Connected-app tokens are deleted when you disconnect the app or delete your account.
Your choices and rights
You can:
- Decline any iOS permission. The rest of the app still works with attested or photo proof.
- Change your profile, timezone, and visibility in the app.
- Disconnect Strava or other connected apps in Settings.
- Sign out on web or iOS.
- Delete your account in iOS Settings. That permanently removes your profile and history from the product. Contact privacy@habitual.site if you use the web app and need the same deletion, or if a control in the product is not enough.
- Ask us for a copy of the personal information we hold about you, or to correct it.
If you are in the European Economic Area, United Kingdom, or a similar jurisdiction, you may also have rights to object to or restrict certain processing, and to lodge a complaint with your local supervisory authority. If you are a California resident, you have the right to know, delete, and correct personal information, and to opt out of sale or sharing — we do not sell or share as those terms are defined under the CCPA/CPRA.
We will not discriminate against you for exercising these rights. We may need to verify that the request comes from you.
Children
Habitual is for people 16 and older. We do not knowingly collect personal information from children under 16. If you believe we have, write to privacy@habitual.site and we will delete it.
Security and international transfers
We use HTTPS, access controls, and least-privilege keys (for example a server-only service role for waitlist inserts). No method of transmission or storage is perfectly secure. Photo proof and profile images are sensitive; treat who you invite as a real choice.
Our providers currently store data in the United States. If you use Habitual from another country, you understand that your information is processed in the US, which may have different data-protection rules than your home.
Changes
If we change this policy in a material way, we will update the date above and, when the change affects how we use personal information, we will provide a more prominent notice — in the app, on the site, or by email. Continued use after the effective date means you accept the updated policy.
Contact
Privacy questions, requests, and complaints: privacy@habitual.site. Legal questions: legal@habitual.site.
Habitual operates the Services from the United States. There is no separate data-protection officer; those mailboxes reach the people who run the product.