Full privacy notice
1. Who operates Hab-it
Hab-it is operated by To be confirmed: operator's legal name, To be confirmed: operator's address, referred to as “we”, “us” or “our”. This entity is responsible for the personal information described in this notice.
Privacy contact: To be confirmed: privacy contact email.
Version: To be confirmed: version, set on approval. Effective date: To be confirmed: effective date, set on approval.
This notice covers the Hab-it pilot in Israel.
2. What information is involved
The information depends on the features you use:
Account/profile: your email, chosen display name, sign-in information (see Technical information below), language, timezone and Hebrew form of address; profile photo if you add one.
Challenge setup: age eligibility answer, chosen challenge, Level, duration, start date, routine, motivation, Identity Statement, Coach style and support choice.
Safety: answers concerning participation requirements, such as pregnancy/breastfeeding, glucose-related conditions, professional support, prescribed diets or distress around food rules. These answers can reveal sensitive health information.
Food preferences: diet choices, food inclusions/exclusions and allergies/intolerances you enter.
Progress: missions, Check-ins, mood/craving/energy answers, reflections, pauses, SOS and slip-recovery notes, history and Stars/Keys/Grace transactions.
Coach: the text messages you send (the Coach is text-only), plus the context described in section 6.
Future Self: text, audio or video you choose to save.
Community: circle membership, posts/messages, encouragement, support requests and replies, blocks and reports.
Steps: manually submitted totals; or step-count information from an authorised health connection where supported. The pilot requests read access to step count only, not heart rate, sleep, calories or medical records. Specifically: daily step totals for the last 7 days, read only where a supported Hab-it phone app with Apple Health or Health Connect is in use, when its connect or sync screen is opened (there are no background reads; a browser cannot read them). Each saved total records the date, its source (Apple Health, Health Connect or entered by you) and when it was saved.
Scanner: ingredient text and product-label images you submit, and the generated result.
Technical information: sign-in records (a protected password hash if you use email and password, or your Google or Apple account ID and email if you sign in with them, and sign-in sessions); your device timezone and app language; and, if you allow reminders, this device's notification address. The app contains no analytics, advertising or crash-reporting tools. Request logs kept by the hosting provider: To be confirmed: hosting log retention.
Reviewer note: Do not list an inactive feature as a data source. Final wording must match the deployed pilot.
3. Why we use it
We use the information necessary for account access, challenge eligibility/routing, personalised food guidance, Coach responses, progress/reward accounting, features you request, notifications you enable, and operation/support/security of the service.
Safety answers are used to apply the approved participation restrictions; they are not a diagnosis. Hab-it is a wellbeing service and does not replace advice from a qualified healthcare professional.
Additional analytics, marketing, research or product-improvement uses: none at present.
Reviewer note: Any additional use must be described here specifically. Do not treat “improvement” as blanket permission for sensitive-data use.
4. Your choices and what happens if you decline
There is no legal duty to provide information to Hab-it merely because you use this voluntary service. Some information is needed for particular features.
Account details, your display name, the required Safety answers and an allergy answer (which can be “none”) are necessary to create the account, determine whether the selected challenge can be offered and personalise its food guidance. Declining a required field may prevent that feature or participation from proceeding; the screen explains the consequence.
Optional reflections, photos and Future Self messages can be skipped where offered.
Health connection is optional; a clearly labelled manual step-entry route is available where supported.
You can decline optional device permissions; the feature requiring them may be unavailable, while the challenge continues where its rules allow. Withdrawing a device permission stops the corresponding future access; it does not itself erase previously stored information.
Safety consent, health permission and any promotional-email consent are never combined into one checkbox.
5. What other participants see
Within community features, members of your circle or Hab-it Group see your display name, your profile photo if you add one, and the messages, encouragement and support requests you post there, with your name and the time. Encouragement sent to one member is visible only to that member and you. Members do not see your Level, Check-ins, reflections, Coach conversation, scans, food preferences, individual step counts or Stars, Keys and Grace. If you switch on “Show my journey day to my circle” in Settings (off by default), they also see your current challenge day. A Hab-it Group is matched automatically, so its members may be people you don't know.
Your Safety answers, private Coach conversation and private Future Self message are not displayed to your circle/community.
On the Steps screen, your circle sees one combined step total for the day and how many members contributed, not each person's count. In a very small circle, one member's count may be worked out from the total. It does not expose another participant's private raw health records.
Information you intentionally post or send to participants is visible to its selected audience; recipients may retain copies outside Hab-it.
6. AI and automated features
Where the AI Coach or the label Scanner's text reading is enabled, submitted content and necessary context are processed by OpenAI (GPT) to provide the requested response.
Coach data sent: your message and the last 20 messages of your Coach conversation; your display name, form of address and app language; your challenge day and duration, Level, Check-in Streak and Coach style; and what you shared during setup about your reasons, your Identity Statement, harder times and available time. Food answers saved in the conversation can mention a food you said you avoid or are allergic to. When you use “Ask Coach” from a Scanner result, that scan’s product name, type, reviewed ingredients and Scanner result are sent too. Not sent: your Safety answers, step data, Check-in answers, reflections, Future Self message, email address or account ID.
Scanner data sent: for a photo or upload, only the label image and a fixed request to read its ingredients; no name, account ID, Level or food preferences. Checking the ingredients against your Level happens on Hab-it's own server. Typed ingredients are not sent to OpenAI.
Community translation, on request: community messages are shown as written. When you ask to translate a specific message, only that message's text and the target language are sent to the same provider. Before the first translation you see an explanation and a choice, which you can change in Settings. No message is sent for translation just because a page was opened or a message was sent. A translation is stored with its message, shown only when someone asks for it, and deleted with the message.
Provider retention, model-training use and relevant controls: To be confirmed: provider retention and training terms.
Content that is not public in the community may still be processed by a service provider.
AI responses can be inaccurate. Participation restrictions and food rules remain governed by the approved product rules; the Coach does not change those rules.
7. Service providers and other disclosures
We use these providers to run the service:
| Provider | Service | Information received | Location, retention and contract |
|---|---|---|---|
| Railway | Hosting the app | All information the app processes | To be confirmed: location, retention and contract |
| To be confirmed: database and storage provider | Database and media storage | All app data, including photos, recordings and label images | To be confirmed: location, retention and contract |
| OpenAI | AI Coach, label reading, community translation on request | As described in section 6 | To be confirmed: provider retention and training terms |
| Resend | Password-reset email | Your email address and the reset link | To be confirmed: location, retention and contract |
| Sign in with Google; Android notifications | Google account ID and email; device token and reminder text | To be confirmed: location, retention and contract | |
| Apple | Sign in with Apple; iPhone notifications | Apple account ID and email (may be a relay address); device token and reminder text | To be confirmed: location, retention and contract |
| Your browser's push service | Web reminders | An encrypted reminder for this device | To be confirmed: location, retention and contract |
Reviewer note: Include only actual authentication, hosting/database/media, AI/OCR, messaging/push, logging/analytics and support providers. Confirm from the production configuration which of these are switched on.
Staff access: inside Hab-it's management system, access to personal information is limited to Hab-it's two owners, for administration and technical operation; any future team member gets only the access their role needs. Access through hosting and service-provider accounts: To be confirmed: hosting and provider account access.
Other disclosures, including legally required disclosures: To be confirmed: other disclosures (legal review).
Sale, advertising and third-party tracking: the app contains no advertising, analytics or third-party tracking tools. To be confirmed: owner-approved “no sale, no sharing for advertising” — awaiting provider verification.
8. Storage and international processing
Data is stored and processed in To be confirmed: storage and processing locations. Where a provider processes data outside your country, the arrangements and protections are: To be confirmed: transfer arrangements (legal review).
Reviewer note: Do not infer data location from the provider's headquarters or from a public app URL.
9. How long information is kept
Today, Hab-it has no automatic deletion schedule: information is kept until you delete it or delete your account. Periods or criteria for each category: To be confirmed: retention periods or criteria.
| Information | Kept today |
|---|---|
| Account, profile and sign-in records | Until account deletion |
| Safety answers (each submission) | Until account deletion |
| Challenge history, Stars, Keys and Grace | Until account deletion |
| Coach conversation | Until you delete Coach memory or your account |
| Future Self message | Until you replace or clear it, or delete your account |
| Scans and label photos | With a completed scan, until account deletion. A photo whose scan is cancelled, fails or is replaced by a new upload is deleted |
| Reports other people made about you | Kept as a safety record after account deletion; period still to be set |
| Records of actions taken in Hab-it's management system (who did what; no answers or media) | Kept as an audit trail; period still to be set |
| Community messages you posted | Until account deletion |
| Steps | Until account deletion |
We retain information only for the documented purposes and applicable retention requirements; this is not permission for indefinite retention.
Deleting an account has different consequences from deleting Coach memory or removing a photo: deleting your account (type DELETE to confirm) immediately removes your account, profile, Safety answers, challenges, rewards, Coach conversation, Future Self, scans, steps and the messages you posted, in one step: if it fails, nothing is removed and you can try again. In other members' in-app updates, anything you sent them (your name and words) is replaced with “A message from a deleted account was removed”; their own messages are not deleted. Your stored photos and recordings are removed too; the confirmation says so only once removal is verified, and otherwise a failed removal is recorded and retried. Kept: reports other people made about you (a safety record whose retention is still to be set) and a technical record of the file removal, without content. Deleting Coach memory removes the Coach conversation at once, but your setup answers stay and are still used as Coach context. Removing your photo deletes it. Clearing or replacing your Future Self message deletes it with no copy left elsewhere. Backups and copies held by service providers: To be confirmed: backup and provider-copy deletion.
10. Security
Measures in place: passwords are stored only as a salted scrypt hash; sign-in sessions use a random token in a secure, HTTP-only cookie and only its hash is stored; password-reset links are single-use and expire after 60 minutes; Google and Apple sign-ins are verified with the provider; the database connection requires TLS; photos, recordings and Future Self messages are served only to people allowed to see them. Storage encryption, backups and console access controls: To be confirmed: encryption, backup and access settings.
No service can promise absolute protection.
11. Device permissions, cookies and local storage
Microphone access is requested for audio recording; camera or photo-library access for a photo you choose to take or upload; contacts only if you choose to invite someone from your contacts (the chosen contact stays on your device); notifications for reminders; step-read permission for a supported health connection. The permission request explains its purpose when needed.
Hab-it uses only first-party cookies and storage needed for the service. There are no analytics or advertising cookies.
| Name | Purpose | Duration |
|---|---|---|
| habit_session (cookie) | Keeps you signed in | 30 days |
| habit_locale (cookie) | Remembers your app language | 1 year |
| habit_oauth_*, habit_apple_* (cookies) | Protect Google and Apple sign-in | 10 minutes |
| Safety draft (session storage) | Keeps unsubmitted Safety answers on this device | Until you submit or close the tab |
| Service worker and push subscription | Installs the web app and delivers reminders you allow | Until removed |
12. Access, correction and deletion requests
You may request access to personal information held about you and request correction in accordance with applicable law, including correction of information that is incomplete, inaccurate, unclear or out of date.
Contact To be confirmed: privacy contact email. We may need reasonable identity verification before responding.
Account deletion: Me → Settings → Delete my account; before setup is finished, the “Delete my account” link under each setup step, or “Delete my registration” if setup stopped. If you can no longer sign in, contact To be confirmed: privacy contact email. The deletion scope, exceptions, backups and provider timing are described in section 9.
Additional rights in the confirmed pilot markets: To be confirmed: rights and request process (legal review).
Reviewer note: Do not promise an unconditional global deletion right, instant erasure, data export or a response deadline that has not been confirmed.
13. Age eligibility
The pilot is intended for adults aged 18 or older, subject to its Safety participation requirements.
If the age answer is under 18, setup stops at that question: no further Safety questions are asked, only that age answer is stored, and no challenge is offered. The registration can be deleted straight away from that screen. To be confirmed: automatic deletion of a blocked under-18 registration — pending legal check
14. Updates and contact
The version and date above identify this notice. We will communicate material changes through a notice in the app and an email, with the new version and effective date shown here, and request a new consent where required.
For questions or privacy requests, contact To be confirmed: privacy contact email.