HabiTrack Privacy Policy
Effective date: Jul 30 2026
Last updated: Jul 30 2026
HabiTrack is a habit tracker published by Roman Medvid (“I”, “me”). This policy describes what the app collects, what it does not, and how to get your data out or have it deleted.
Contact for any question or request in this policy: support@habitrack.live
The short version
- The app works entirely offline, and that is the default. If you never turn on sync and never turn on crash reports, HabiTrack sends nothing anywhere. Your habits stay in a database file on your own device.
- I do not collect your habit data. Turning on sync copies it to your account so your own devices can share it. Nobody else can read it.
- There are no analytics SDKs and no advertising SDKs in the app. I do not track your usage, I do not build a profile of you, and I sell nothing to anyone.
- Nothing requires an account. Signing in is an explicit choice you make in Settings, never a condition of using the app.
What the app stores on your device
Everything you create lives in a local database on your device:
- Habits — name, optional description, icon, colour, category, goal settings, and the order you arranged them in.
- Completions — which habit, which date, an optional amount, and when you recorded it.
- Categories — the twelve built-in ones, plus any you add.
- App settings — which day your week starts on, your chosen view, your appearance preference, and your answers to the sync and crash-report choices.
- Your purchase entitlement, if you have bought a subscription or the lifetime option.
This data is not transmitted anywhere unless you turn on sync. Deleting the app deletes this database.
Optional: sync
Sync is off until you turn it on in Settings. Turning it on requires signing in, using one of:
- Sign in with Apple
- Sign in with Google
- Email and password
What is received when you sign in. Firebase Authentication (a Google service — see “Service providers” below) creates an account for you and gives the app a user id. Depending on the method you chose, it also holds your email address — which may be Apple’s private relay address if you chose to hide yours. Your password is handled by Firebase and never reaches me in readable form.
What syncs. Your habits, completions and categories — the
same fields listed above — are copied to Cloud Firestore under a path
belonging to your account alone (/users/{your user id}/...).
Security rules on the server reject any attempt by one account to read or
write another account’s data.
What does not sync. Your app settings and your crash-reporting choice stay on the device.
Turning sync off signs you out and stops the copying. Your data stays on your device and continues to work. It also remains in your account until you delete it — see “Your rights”.
Optional: crash reports
Crash reporting is off until you agree to it. The app asks once, on first launch, and you can change the answer at any time in Settings › Privacy.
If you turn it on, Firebase Crashlytics sends a technical report when the app crashes: the error and its stack trace, your device model, operating system version, and app version. Habit names, descriptions, completion history and your email address are not included in these reports. They are used only to find and fix crashes.
Crashlytics has no web implementation, so the web version of HabiTrack collects no crash data at all.
Purchases
Subscriptions and the lifetime option are sold and processed by Apple (App Store) or Google (Google Play) under their own terms and privacy policies. I never see your card details.
The app receives only a confirmation from the store that a purchase was made, and keeps it on your device so it knows to unlock the paid features. That confirmation is not sent to any server of mine — there is no purchase-related data leaving your device at all.
Sharing
The share feature turns a habit’s progress into an image on your device and hands it to your operating system’s share sheet. Where it goes from there is your choice, and is governed by whatever app you send it to. Nothing is uploaded to me.
Service providers
I use the following, and no others:
| Provider | What it does | What it holds |
|---|---|---|
| Google — Firebase Authentication | Signs you in, if you choose to sync | Your user id, and your email address (or Apple’s relay address) |
| Google — Cloud Firestore | Stores your synced habit data | Habits, completions and categories, under your account only |
| Google — Firebase Crashlytics | Crash diagnostics, only with your consent | Crash reports, device model, OS and app version |
| Apple / Google | Process purchases | Handled entirely by them; the app receives only a confirmation, which stays on your device |
Firebase is operated by Google. Their handling of this data is covered by Google’s Privacy Policy and the Firebase data-processing terms.
Where synced data is stored. The Firestore database is in
Google’s nam5 multi-region, which is in the
United States. If you are in the UK or EU and turn sync on,
your habit data is transferred to and stored in the US under Google’s
standard contractual clauses. Leaving sync off means no transfer happens at
all.
How long things are kept
- Data on your device: until you delete it in the app, or delete the app.
- Synced data: until you delete it — either by deleting the habit, or by deleting your account.
- Crash reports: retained by Crashlytics for up to 90 days.
Your rights and how to exercise them
Get a copy of your data. Settings › Export produces a complete file of your habits and completions, on device, free, with no account needed.
Delete your synced data and your account. Settings › Delete account removes your data from the server and then deletes your sign-in account. The app keeps working on your device afterwards, offline.
Delete everything. Delete the account as above, then delete the app.
Stop crash reports. Settings › Privacy › Send crash reports.
If you are in the UK, EU or another region with data-protection law giving you rights of access, correction, erasure, portability or objection, the controls above are the fastest route. For anything they do not cover, write to support@habitrack.live and I will respond within 30 days.
The lawful basis, where one is required, is your consent — for sync and for crash reports, both of which are off until you turn them on — and performance of a contract for processing a purchase you have made.
Children
HabiTrack is not directed at children under 13 (or under 16 where local law sets that age), and I do not knowingly collect their data. If you believe a child has created an account, write to me and I will delete it.
Changes to this policy
If this policy changes, the “Last updated” date above will change with it, and for any change affecting what is collected you will be told in the app before it takes effect.
Contact
Roman Medvid
support@habitrack.live
PO Box 02, Kyiv, 02094 Ukraine