Privacy Policy
Last updated: June 27, 2026
This policy describes how HabTrack collects, uses, and protects the personal information of its users. By using the app, you agree to the practices described here.
This policy complies with the GDPR and the requirements of the App Store (Apple) and Google Play.
We collect only the data necessary for the app to function:
• Account data: email and Google name (if signed in with Google), anonymous identifier (without account)
• Profile data: username, avatar, friend code
• Habit data: created habits, completion history, statistics, exempted days
• Social data: friends, groups, group messages, leaderboards
• Progression data: level, XP, unlocked items, Pro status
• Local technical data: display preferences (stored on device only)
We do not collect: geolocation data, phone contacts, banking data, biometric data, or health data.
Collected data is used exclusively to:
• Enable personal habit tracking
• Display profile, statistics, and progress
• Power social features (friends, groups, leaderboards, challenges)
• Send in-app notifications
• Display rewarded ads (see section 5)
• Maintain app security and integrity
We do not sell your data or share it for commercial purposes.
The app uses the following services:
• Firebase Authentication – user account management
• Cloud Firestore – data storage (habits, profile, social)
• Firebase App Check – protection against unauthorized access
• Google Sign-In – optional sign-in via Google account
• RevenueCat & Apple/Google billing – in-app purchase and subscription management (Pro version, consumables). They process purchase data (transaction identifiers, purchase status), never your banking details.
These services are subject to their respective privacy policies. Data is stored on Google's servers (generally in Europe for European users).
The app integrates Google AdMob to display rewarded video ads for non-Pro users. These ads allow users to unlock rewards for free.
AdMob may collect: the device's advertising identifier (IDFA on iOS, GAID on Android), device information, and ad interaction data.
On iOS, your explicit consent is requested via the ATT framework before any ad tracking. You can withdraw this consent in iPhone Settings → Privacy → Tracking.
Pro users see no ads.
We implement the following measures to protect your data:
• Firestore security rules: each user can only access their own data
• Authentication required for all reads and writes
• Firebase App Check: only the official app can communicate with our servers
• No sensitive data stored in plain text on device
• Encrypted communications via HTTPS/TLS
Under the GDPR, you have the following rights:
• Access – request a copy of your data
• Rectification – have inaccurate data corrected
• Erasure – request deletion of your account and all associated data
• Portability – receive your data in a readable format (export available in the app)
• Objection – object to certain types of processing
• Restriction – request restriction of processing in certain cases
You can delete your account directly from the app (Profile → Settings → Delete my account).
You also have the right to lodge a complaint with your local data protection authority (e.g. CNIL in France, ICO in the UK).
The app is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with their data, please contact us for immediate deletion.
Users aged 13 to 16 must have obtained parental consent before using the app.
We may update this policy periodically. In the event of a significant change, you will be notified via the app. The date of the last update is shown at the top of this page.
Continued use of the app after any changes constitutes acceptance of the updated policy.
For any questions regarding this policy or your personal data, please contact us via Settings → Support → Report a bug.
We are committed to responding within 30 days.