Privacy Policy
Overview
HabitFlow is a privacy-first habit tracker. We are designed to keep your personal data on your device. This policy explains exactly what we collect, why, where it lives, and what choices you have. If anything here is unclear, reach out and we will explain in plain language.
Data we store on your device
The following information is stored locally in an encrypted Hive database on your phone and never leaves your device by default:
- Habits you create, edit, and complete (names, icons, streaks, reminder times)
- Mood entries (rating, optional note, tags, date)
- Sleep logs (bedtime, wake time, quality rating)
- Water intake counters
- Workout / gym logs (sets, reps, weight, notes)
- Meditation / breathing session history
- Favorited exercises and app preferences (theme, onboarding state)
- Step counts read from your phone's pedometer sensor
Data we store in the cloud
If you choose to sign in with email or Google, we store the following profile information in Firebase (Google Cloud) so it can be associated with your account:
- Your name and email address
- Your profile photo URL (if signing in with Google)
- Account creation date and last sign-in timestamp
We do not currently sync your habits, moods, or workouts to the cloud. Signing out removes your local session but does not delete the account profile in Firebase — use "Delete Account" in Settings (or contact us) to remove it.
Permissions we ask for
- Notifications — to send habit reminders you have scheduled.
- Activity Recognition — to count your daily steps via the pedometer.
- Microphone — used only by the in-app voice assistant when you tap the mic button. Audio is processed by your device's built-in speech recognizer and is not sent to or stored by HabitFlow.
- Bluetooth — used only by Android's text-to-speech engine to route voice replies to wireless headphones / speakers when paired.
Voice assistant
The voice assistant uses your phone's built-in speech-to-text and text-to-speech engines (Google on Android, Apple on iOS). Your spoken commands are converted to text on-device or by your phone's OS provider under their respective privacy policies. HabitFlow does not record, store, or transmit your voice.
Third-party services
We use the following services strictly to provide the features above:
- Firebase Authentication & Firestore (Google LLC) — for account sign-in and profile storage. Subject to Google's privacy policy.
- Google Sign-In (Google LLC) — optional, only if you tap "Sign in with Google".
- Device speech-to-text / text-to-speech — handled by Android / iOS, subject to your device manufacturer's policy.
We do not use third-party advertising, analytics SDKs, or trackers.
Children's privacy
HabitFlow is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us information, contact us and we will delete it.
Your rights & choices
- Local data — you can wipe everything by uninstalling the app or using "Clear All Data" in Settings.
- Cloud profile — you can sign out from Settings, and request account deletion by emailing us.
- Permissions — every permission above can be revoked in your phone's system Settings at any time.
Changes to this policy
If we make material changes, we will update the "Last updated" date and surface a notice in the app. Continuing to use HabitFlow after a change means you accept the updated policy.
Contact
Questions or requests? Email us at afroz.w9199@gmail.com.