Privacy and data

Privacy Policy

A clear account of what Habpic stores on your device, what may be sent to our service providers, and the choices you control.

Last updated: August 11, 2026

Scope and our role

This policy covers the Habpic mobile app and habpic.app. Habpic is the controller of personal data described here. Some features work locally without an account, while sign-in, cloud sync, subscriptions, analytics, and Proof Pacts use the providers listed below.

Information we process

The information depends on the features you choose to use:

  • Account and profile data, such as your Firebase user ID, email, display name, sign-in provider, profile photo, and a Habpic account identifier.
  • Habit content, including habit names, schedules, reminders, completion logs, streaks, focus-session records, reflections, settings, and linked-habit information.
  • Photo proofs and related metadata, such as the linked habit, creation time, notes, storage path, and sharing choice. The current store build blocks microphone, audio-library, and video-library permissions.
  • Proof Pact content, including membership, invitations, linked habits, completion status, shared photos or private-image placeholders, reactions, reports, and moderation status.
  • Usage, diagnostics, subscription status, app version, platform, and device or app identifiers used for analytics, crash diagnosis, security, sync, and entitlement delivery.

Local storage and cloud sync

Habpic is local-first. Guest habits, proofs, settings, and focus data are stored in app-owned storage on your device. Signed-in users may use Firebase Authentication, Cloud Firestore, Cloud Storage, and Cloud Functions for identity, supported backup and sync, profile photos, and Proof Pacts. Automatic personal backup is controlled by the app's sync settings and plan eligibility. Habpic does not use Google Drive for app backup.

Proof Pacts and photo sharing

Proofs are private by default. When you link a habit to a Proof Pact, each eligible completion is prepared for that Pact. You can withhold the image for an individual completion while still sharing that you completed it. Images you choose to share are visible to eligible Pact members and are processed by Google Cloud Vision SafeSearch before approval. A flagged or unreviewed image is not made available to other members. Members can report a proof or account and can block another member. A block separates the two accounts across shared Pacts. Report details are restricted to moderation access.

Analytics and error diagnostics

When enabled, Habpic uses PostHog to measure onboarding, feature use, proof and Proof Pact activity, subscription lifecycle events, retention, and technical failures. Events use a pseudonymous Habpic identifier. After non-anonymous sign-in, activity may be associated with your Firebase user ID. We do not send habit names, proof media, notes, report text, or email addresses to PostHog. You can turn Usage analytics off in Profile, Data. We do not sell this data or use it for third-party advertising.

Website and waitlist data

On habpic.app, we record page paths, referring pages, browser user-agent strings, and App Store or Google Play button clicks to measure site performance and conversion. Vercel Analytics and Speed Insights provide aggregate traffic and performance data. If you join a waitlist, we store your email address, selected device platform, and signup time so we can contact you about Habpic.

Device permissions

Habpic asks for camera access when you choose to capture a proof, photo-library access when you choose an existing image, and notification permission when you opt into reminders. Notifications are scheduled locally on the device. Habpic does not request contacts or location, and its current Android release configuration blocks microphone, audio-library, video-library, and broad legacy storage access.

Service providers

We use processors only to operate, secure, measure, and sell Habpic:

  • Firebase / Google Cloud: authentication, database, media storage, server functions, app attestation, and SafeSearch moderation through Google Cloud.
  • PostHog: product analytics and error diagnostics.
  • RevenueCat: subscription status, purchase history, customer identifiers, and entitlement management.
  • Apple and Google process sign-in and store purchases under their own terms. Vercel hosts and measures the website; MongoDB stores website analytics and waitlist records; the email provider delivers waitlist messages.

International processing

Our providers may process data in the United States and other countries where they operate. Where applicable law requires it, we rely on provider data-processing terms and recognized transfer safeguards. Privacy protections and government-access rules can differ from those in your country.

Retention

Local data remains until you delete it, clear the app's data, or remove the app, subject to your device backups. Cloud account data remains while your account is active or until you delete the relevant content. Under current Proof Pact controls, shared full-size images may be removed after 90 days and thumbnails after up to 365 days. Account deletion removes live Habpic account data and contributed Pact media; limited security, billing, legal, and provider-backup records may remain only as required or for the provider's documented deletion cycle. Firebase states that some deleted authentication data can take up to 180 days to leave backup systems. Evidence copied for a safety report is scheduled for deletion after 30 days. Report records are normally retained for 365 days; an unresolved report may be retained longer while review remains necessary. Block records remain until unblocked or the related account is deleted.

Your choices and rights

You can use core local features without linking Google or Apple, decide whether to enable cloud sync, control reminders in Habpic or system settings, withhold individual Pact photos, leave Pacts, and delete your account from Profile, Account & Support, Delete Account. You may request access, correction, or deletion by emailing us. Rights vary by location, and we will verify requests before disclosing or deleting account data. You can report Pact content, block accounts, and manage your blocked-account list in the app. Unblocking permits future interaction but does not restore former Pact membership or content.

Children

Habpic is not directed to children under 13, or a higher minimum age where local law requires it. If you believe a child has provided personal data without appropriate consent, contact us so we can investigate and remove it.

Security

We use authenticated access controls, Firebase security rules, App Check attestation for protected Pact operations, HTTPS in transit, provider encryption at rest, and restricted storage paths. No system is completely secure, so please use a protected device and promptly report suspected account misuse.

Contact and policy changes

We may update this policy as Habpic or its providers change and will post the revised date here. For privacy requests or questions, contact habpic.app@gmail.com.