Habiness ← Back to home

Habiness — Privacy Policy

Effective date: July 31, 2026 Last updated: August 21, 2026 Version: 2.1


1. Introduction and Who We Are

Habiness is a personal wellness and habit-tracking application developed and operated by Sylvain Pierre Paul Lacroix, an individual operating Habiness as a sole proprietor ("we", "us", "our"). We are committed to protecting your personal data and being transparent about how we collect, use, store, and share it.

This Privacy Policy explains our data practices in full. It applies to all users of the Habiness mobile application ("App"), available on iOS and Android, and any related services we provide.

Contact details:

  • Operator: Sylvain Pierre Paul Lacroix (sole proprietor)
  • Email: support@habiness.com
  • Website: https://habiness.com
  • App identifier: com.habiness.app

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at support@habiness.com. We will respond within 30 days.


2. Data We Collect and Why

We collect only the data necessary to provide the Habiness service. We do not run advertising. We do not sell your data to any third party. Below is a complete inventory of everything we collect.

2.1 Account Data

Data Why we collect it Legal basis
Email address Account creation, authentication, account recovery, service communications Performance of contract
First name Personalisation (in-app greetings and messaging) Consent
Onboarding "pain points" (up to 2 selections from a fixed list, e.g. sleep issues, stress or anxiety, feeling overwhelmed) To personalise onboarding content and messaging relevance Consent

We do not collect your date of birth, phone number, gender, or any other identity information beyond what is listed above, unless you choose to include it in content you create (e.g. a journal or gratitude entry).

2.2 App Content You Create

All content you actively create in the App is stored in your account and belongs to you.

Data Why we collect it Legal basis
Habits (goals): name, pillar, icon, frequency, active days, duration, reminder settings, pause status, renewal history To provide the core habit-tracking service Performance of contract
Habit logs: date, completion status (done / partial / missed) To show your progress history and weekly dashboard Performance of contract
Journal entries: date, text content, prompt used To provide the journaling tool and history Performance of contract
Gratitude entries: date, text content, prompt used To provide the gratitude tool and history Performance of contract
Breathing sessions: date, session count, duration To provide the breathing tool and history Performance of contract
Me Time sessions: date, duration To provide the Me Time tool and history Performance of contract
Mood logs: date, mood values recorded To provide the mood tracking tool and history Performance of contract

2.3 Usage Analytics

We collect anonymised in-app usage events to understand how the App is used and to improve it. These events are linked to your internal account identifier, not to your email address or real-world identity.

Data Examples Legal basis
Feature interactions "opened journal", "opened gratitude", "completed breathing session", "tapped Inspo article" Legitimate interest
Screen navigation Screens visited, time spent Legitimate interest
Feature adoption Which tools are used, which habits are most common Legitimate interest

Analytics events are not used for advertising, are not shared with advertisers, and are not used to build profiles sold to third parties.

2.4 Push Notification Token

If you enable habit reminders, we store a device-level push notification token to deliver reminders at the times you set. This token is tied to your device, not your identity, and is used exclusively to route notifications. We do not send marketing push notifications.

2.5 Subscription Status

If you subscribe, we store your subscription tier (free trial / monthly / annual / lifetime) and its validity dates. We do not process, receive, or store your payment card details — all payment processing is handled by Apple (App Store) or Google (Google Play) under their own privacy policies.

2.6 Technical Data

We may collect limited technical data to operate and secure the service:

Data Why we collect it
Device operating system and version To ensure compatibility and diagnose platform-specific issues
App version To provide version-appropriate features and support
Error logs and crash reports To identify and fix bugs

We do not collect your device's advertising identifier (IDFA / GAID), precise GPS location, camera or microphone access, contacts, or any data from Apple Health or Google Fit.


3. How We Use Your Data

In addition to the specific purposes listed in Section 2, we use your data to:

  • Provide and sync the service across devices linked to your account
  • Deliver habit reminders at times you have configured
  • Respond to support requests you send us
  • Improve the App based on anonymised usage patterns
  • Detect and prevent fraud or abuse of the service
  • Comply with legal obligations when required

We do not use your data for automated individual decision-making or profiling that produces legal or similarly significant effects.


4. Legal Bases for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal data under the following legal bases under the GDPR:

Processing activity Legal basis
Providing the App, storing your content, managing your account Article 6(1)(b) — Performance of a contract
Delivering habit reminders Article 6(1)(b) — Performance of a contract; Article 6(1)(a) — Consent (for push notification permission)
Anonymised usage analytics Article 6(1)(f) — Legitimate interests (improving the service; does not override your rights)
Responding to support requests Article 6(1)(f) — Legitimate interests
Compliance with legal obligations Article 6(1)(c) — Legal obligation

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, given the limited and non-sensitive nature of the data processed and the genuine benefit to service quality.

You may withdraw consent or object to processing based on legitimate interest at any time — see Section 9 (Your Rights).


5. Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We share data only with the following service providers, each acting as a data processor under our instructions and bound by data processing agreements.

5.1 Supabase

Role: Primary data storage and authentication provider. Data shared: All app data (account, habits, logs, journal entries, gratitude entries, sessions, moods, analytics events). Location: Supabase infrastructure runs on Amazon Web Services (AWS). Your data is stored in the Ireland (eu-west-1) AWS region. GDPR transfer mechanism: Standard Contractual Clauses (SCCs) — Module 2 (Controller to Processor), as set out in Supabase's Data Processing Agreement, available at https://supabase.com/privacy. Supabase Privacy Policy: https://supabase.com/privacy

5.2 Apple Inc.

Role: App distribution (App Store), in-app payment processing, push notification delivery (APNs). Data shared: App Store handles your payment; APNs routes notifications using your device token. We do not share your email or app content with Apple beyond what Apple collects through standard App Store usage. Apple Privacy Policy: https://www.apple.com/legal/privacy/

5.3 Google LLC

Role: App distribution (Google Play), in-app payment processing, push notification delivery (FCM). Data shared: Google Play handles your payment; FCM routes notifications using your device token. Google Privacy Policy: https://policies.google.com/privacy

5.4 RevenueCat (active when subscriptions are live)

Role: Cross-platform subscription state management. Data shared: Your app user ID and subscription events (purchase, renewal, cancellation). RevenueCat does not receive your email address, journal entries, gratitude entries, habits, or any other app content. Location: United States. Transfer mechanism: Standard Contractual Clauses. RevenueCat Privacy Policy: https://www.revenuecat.com/privacy

5.5 Expo

Role: Push notification infrastructure (Expo Push Notification Service). Data shared: Push notification tokens and notification payloads (which contain only your habit name, not journal or gratitude content, or mood data). Expo Privacy Policy: https://expo.dev/privacy

5.6 Sentry

Role: Crash and error reporting, to help us detect and fix bugs. Data shared: Crash reports, error messages, and technical diagnostic data (device operating system and version, app version). Sentry does not receive your email address, journal entries, gratitude entries, habits, mood logs, or any other app content — error reports are not linked to your identity. Location: United States. Transfer mechanism: Standard Contractual Clauses. Sentry Privacy Policy: https://sentry.io/privacy/

5.7 Legal and Safety Disclosures

We may disclose your data to law enforcement or other authorities if required by applicable law, court order, or to protect the rights, property, or safety of Sylvain Pierre Paul Lacroix, our users, or the public. We will notify you of such disclosures where permitted by law.

We do not share your data with any other third parties.


6. International Data Transfers

Sylvain Pierre Paul Lacroix is based in Portugal. Your data may be transferred to and processed in countries outside your country of residence, including the United States (via Supabase/AWS and RevenueCat).

For transfers from the EEA or UK to third countries, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) — approved by the European Commission under Decision 2021/914 — with each relevant processor (Supabase, RevenueCat).
  • Where applicable, we supplement SCCs with a Transfer Impact Assessment to assess the risk level of the destination country.

You may request a copy of the applicable SCCs by contacting us at support@habiness.com.


7. Data Retention

We retain your data only for as long as necessary for the purposes described in this Policy.

Data type Retention period
Account data (email) Until account deletion, then deleted within 30 days
Habits, logs, journal entries, gratitude entries, sessions, moods Until account deletion, then deleted within 30 days
Analytics events 24 months from collection, then deleted
Push notification tokens Until you disable reminders or delete your account
Subscription status Until account deletion, then deleted within 30 days
Error logs and crash reports 90 days from collection
Support correspondence 3 years from last contact, then deleted

When you delete your account (via Settings → Data & Privacy → Delete account), we initiate permanent deletion of all your personal data from our systems. This process completes within 30 days. Backup copies may persist for up to an additional 30 days before being purged from all backup systems.


8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption in transit: all data transmitted between the App and our servers uses TLS 1.2 or higher
  • Encryption at rest: data stored on Supabase/AWS is encrypted at rest using AES-256
  • Access controls: access to production data is restricted to authorised personnel only, on a need-to-know basis
  • Row-level security: Supabase Row Level Security (RLS) policies ensure each user can only access their own data
  • Authentication: account access is protected by secure token-based authentication

No security system is impenetrable. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay, as required by GDPR Article 33/34.


9. Your Rights

9.1 Rights Under GDPR (EEA and UK residents)

You have the following rights under the General Data Protection Regulation and UK GDPR:

Right of access (Article 15): You may request a copy of all personal data we hold about you, along with information about how it is processed.

Right to rectification (Article 16): You may request correction of inaccurate or incomplete personal data. Most of your data (habit names, journal entries, gratitude entries) can be edited directly in the App.

Right to erasure (Article 17): You may request deletion of your personal data. The simplest way is to use the in-app account deletion feature (Settings → Data & Privacy → Delete account). You may also contact us at support@habiness.com. You can also delete an individual habit, along with its logs and history, directly within the App without deleting your entire account.

Right to restriction of processing (Article 18): You may request that we restrict the processing of your data in certain circumstances (e.g. while you contest its accuracy).

Right to data portability (Article 20): You may request a machine-readable copy of the personal data you have provided to us. Contact us at support@habiness.com to make this request.

Right to object (Article 21): You may object at any time to processing based on legitimate interests (including analytics). We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests.

Right to withdraw consent: Where processing is based on your consent (e.g. push notification permission), you may withdraw consent at any time through your device's notification settings. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Right not to be subject to automated decision-making: We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

To exercise any of these rights, contact us at support@habiness.com. We will respond within 30 days. We may ask you to verify your identity before processing your request. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.

Right to lodge a complaint: If you believe we have not handled your data in accordance with applicable law, you have the right to lodge a complaint with your local supervisory authority. In the EU, this is your national data protection authority. In the UK, this is the Information Commissioner's Office (ICO): https://ico.org.uk.

9.2 Rights Under CCPA (California Residents)

California residents have the following rights under the California Consumer Privacy Act:

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we share it.
  • Right to delete: You may request deletion of your personal information (subject to certain exceptions).
  • Right to opt out of sale: We do not sell personal information. No opt-out is required.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact us at support@habiness.com. We will respond within 45 days.

Categories of personal information collected (CCPA categories):

  • Identifiers (email address)
  • Internet or other electronic network activity information (usage analytics)
  • Commercial information (subscription status)
  • Inferences drawn to create a profile (none — we do not build inferred profiles)

10. Children's Privacy

Habiness is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child under 16 has created an account or provided personal data to us, please contact us immediately at support@habiness.com. We will delete the account and all associated data promptly upon verification.

Users in the United States: we do not knowingly collect personal information from children under 13 in accordance with the Children's Online Privacy Protection Act (COPPA).


11. Push Notifications

If you grant permission for push notifications, we use them solely to deliver habit reminders at the times you configure. You can disable push notifications at any time through your device's Settings app. Disabling notifications does not affect your account or stored data.

We do not send promotional or marketing push notifications.


12. Links to Third-Party Services

The App may display links to third-party wellness articles, tools, or websites. These third parties have their own privacy policies, and we are not responsible for their data practices. We encourage you to review the privacy policies of any third-party services you access through the App.


13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the App's features, or applicable law. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you via an in-app notice or email at least 14 days before the changes take effect (for material changes)

Your continued use of the App after the effective date of an updated Policy constitutes acceptance of the changes. If you do not agree to the updated Policy, you may delete your account before the changes take effect.


14. Contact and Supervisory Authority

For any privacy-related questions, requests, or complaints:

Sylvain Pierre Paul Lacroix support@habiness.com https://habiness.com

If you are not satisfied with our response, you have the right to contact your local data protection supervisory authority. EEA residents may find their national authority at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

← Back to home