Privacy Policy for HabitPocket
This is a translation. If the versions differ, the German version prevails.
1. Controller
The controller for the HabitPocket app and the website habitpocket.com is Real Movement Analytics GmbH, Kleines Everstal 18d, 44388 Dortmund, Germany. Contact: [email protected].
2. Local first
HabitPocket works fully without an account. The app stores habits, schedules, reminders, entries, notes, settings and local backups in a database on your device. Without an account we receive none of this content.
The app contains no ads, no analytics or tracking SDKs and no crash reporting to third parties. We only see aggregated usage numbers from App Store Connect and the Google Play Console.
Local storage is required for the features you ask for (Section 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR). The data stays until you delete it in the app or uninstall the app. Your device's system backups (iCloud or Google) may contain copies depending on your device settings; Apple or Google manage these backups, not us.
You decide which habits you create. If you track habits related to health (e.g. "take medication"), they may allow conclusions about your health. We do not analyse content. Section 7 explains how we handle such content when you sync.
3. Update check
When the app starts or returns to the foreground, it asks our server, also without an account, whether your app version is still supported. It sends the platform (iOS/Android), app and API version and, for technical reasons, your IP address. No habit content or identifiers are sent. The purpose is to tell outdated versions in time that an update is needed (Art. 6(1)(f) GDPR). We do not store these requests in our database; for logging by Cloudflare see Section 10.
4. Reminders, widgets and app lock
Reminders are scheduled as local notifications on your device; for this the app asks for notification permission. Widgets read a local copy of today's habits. The app lock uses Face ID, Touch ID or your device's biometrics through the operating system. We never receive biometric data.
5. Apple Health and Health Connect
If you enable it for a habit, the app reads selected values from Apple Health or Health Connect: steps, distance, active minutes, workout minutes or sleep duration. This only happens while the app is open and only on your device. Individual measurements (raw data) are never sent to us. From them, the app stores one daily value as a habit entry (e.g. "8,000 steps on 28 Sep").
You grant read access through the operating system's permission prompt and can revoke it there at any time (Art. 6(1)(a), Art. 9(2)(a) GDPR).
Sync and cloud backups of these values: If you use sync (Section 7) and at least one habit on a device is linked to Health, the app asks on that device whether the daily values taken over may leave it. Your consent covers two things: syncing the values with your account and including them in cloud backups (Art. 9(2)(a) GDPR). Without consent the values stay on the device. Everything else still syncs, and cloud backups from that device then leave the Health values out. Consent applies per device; if you sign out there and back in, the app asks again.
Withdrawal: You can withdraw consent at any time under Settings › Account › "Sync Health values". The device then stops uploading Health values, and we delete your account's Health values from the sync data and from the cloud backups, including values uploaded by other devices. This covers all daily values of habits linked to Health. If the device is offline, the app completes the deletion at the next sync; you can only sign out once it is done. The values on your devices stay. If another device still has consent, it uploads Health values from there again until you withdraw there as well.
Values from Apple Health or Health Connect are not used for advertising and not sold. Cloudflare stores synced values on our behalf as our processor (Section 12). Beyond that, we do not share them with third parties.
6. Purchases (Pro)
Apple (App Store) and Google (Google Play) handle purchases and subscriptions under their own privacy policies and are responsible for that processing. We never receive bank or card details.
If you are signed in, the app passes a pseudonymous account identifier to Apple or Google at purchase so the purchase can be linked to your HabitPocket account. Our server verifies the purchase: we process the store-signed transaction data or purchase token, transaction identifiers, the product ID, purchase and expiry time and the subscription status. Apple and Google notify our server about renewals, cancellations and refunds. Without an account, the purchase stays with your store account and is not stored by us. The legal basis is Art. 6(1)(b) GDPR and, for abuse prevention (e.g. one purchase not being linked to several accounts), Art. 6(1)(f) GDPR.
7. Account, sync and cloud backups (optional)
An account is optional and only needed for sync and cloud backups. You sign in with Apple or Google; there is no password. We process:
- Account data: a pseudonymous identifier from Apple or Google and, if provided, your email address (with Apple possibly an anonymous relay address).
- Device data: device name, platform, app version, time of last activity and last sync.
- Sessions: one access key per device, stored only as a cryptographic hash, with creation and last-use time.
- Sync content: habits (name, icon, colour, description, schedule, reminder times, pauses), entries, notes and week notes; Health daily values only with consent (Section 5). Settings, app lock, widget configuration and Health links are not synced.
- Cloud backups: backups of your habits, schedules, entries and notes (without settings and Health links) that you create yourself.
- Sign in with Apple: if you sign in with Apple, we also store the refresh token issued by Apple in our database (Cloudflare D1). We use it for one purpose only: when you delete your account, we use it to revoke the link between "Sign in with Apple" and HabitPocket at Apple. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 17 GDPR (complete erasure) and Art. 6(1)(f) GDPR. Our legitimate interest is to end the sign-in link cleanly when the account is deleted, as Apple requires.
- Audit log: a log of account and purchase actions (e.g. sign-in, device removed, purchase confirmed) without habit content.
- Connection data: the IP address is processed for abuse prevention (rate limiting). We do not store it in our database; for processing by Cloudflare see Section 10.
The legal basis is Art. 6(1)(b) GDPR (providing sync and backups) and Art. 6(1)(f) GDPR (secure operation, abuse prevention). Section 5 applies to Health daily values.
8. Retention and deletion
- Signing out: If you sign out on your last signed-in device, we immediately delete all sync content and cloud backups on our server. If other devices are still signed in, the cloud data stays for them; the app tells you beforehand which case applies. Data on your device always stays. If the app cannot reach our server when you sign out, the cloud data stays there. You can remove it at any time by deleting your account.
- Delete cloud data: Under Settings › Account you can delete all sync content and cloud backups at any time. All devices are signed out; your account and Pro status stay, and data on your devices stays.
- Deleted habits: We remove their entries and notes from the sync history within 24 hours. The habit's deletion marker (only its ID, no content) is kept for 365 days so devices that were offline for a long time also apply the deletion.
- Cloud backups: At most the latest 30 are kept; older ones are deleted automatically. You can delete single backups yourself at any time.
- Sessions and devices: signed-out or removed devices and their sessions are deleted 30 days after sign-out.
- Audit log: entries are deleted after 180 days.
- Account data and purchase link: until the account is deleted.
- Deleting your account: We immediately remove the account, sign-in data, devices, sync content, cloud backups, purchase link and audit log. We only keep a note without personal data that a deletion took place.
- Apple refresh token: deleted together with the account after we have revoked it at Apple. If revocation fails, we keep only the token for up to 7 days to retry and then delete it in any case.
- Deletion requests via the web: we delete completed requests no later than 30 days after completion.
For technical reasons, the databases of our hosting provider Cloudflare keep a recovery history of up to 30 days; deleted data disappears from it after this period at the latest.
9. Deleting your account
You can delete your account in the app under Settings › Account › Delete account or at habitpocket.com/en/delete-account.
If you delete without the app, you sign in with Apple or Google on api.habitpocket.com. We process the identifier from that sign-in to find your account, plus the time and status of the request. For requests via the email form or by email we store the email address you provide and the time, to match your account and confirm the deletion to you. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 17 GDPR. We delete completed requests no later than 30 days after completion.
Cookie for deletion on the web: when you open the deletion page on api.habitpocket.com, our server sets the cookie __Host-hp_delete. It holds a random value that binds the Apple or Google sign-in to exactly this browser. This way nobody can use a sign-in issued elsewhere to delete an account. The cookie expires after 15 minutes and is removed right after the deletion. It is strictly necessary for the deletion you asked for (Section 25(2) no. 2 TDDDG; Art. 6(1)(c) GDPR in conjunction with Art. 17 GDPR).
10. Hosting and website
The website and our server run on Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (Cloudflare Pages, Workers, D1, Durable Objects, R2). For every request to the website or our server, Cloudflare processes the IP address and technical request data (time, address, browser or app information, status) to deliver content and protect the service against disruption and abuse (Art. 6(1)(f) GDPR). For troubleshooting we keep logs of server requests at Cloudflare for at most 7 days.
The website habitpocket.com sets no cookies and uses no analytics. Only the deletion page on api.habitpocket.com uses a strictly necessary cookie (Section 9). Fonts and images are loaded from our own server. If you choose light or dark mode on the website, your browser stores this choice in local storage (key hp-theme) until you reset it or clear your browser data. This is required for the feature you asked for (Section 25(2) no. 2 TDDDG); nothing is sent to us.
11. Contact by email
If you email us, for example at [email protected], it arrives in our company mailbox at Microsoft 365 (Microsoft Ireland Operations Ltd., Ireland). For some addresses, Cloudflare first receives the message through its Email Routing service and forwards it there; Cloudflare processes the sender, recipient and time and does not store the content permanently. Microsoft stores the email including its content and attachments as a processor under a data processing agreement (Art. 28 GDPR), generally in data centres in the EU. Microsoft relies on the EU-US Data Privacy Framework and EU Standard Contractual Clauses for transfers to Microsoft Corporation in the USA, for example for support or security.
We process your address, the content and any information you provide voluntarily to answer your request. The legal basis is Art. 6(1)(b) GDPR for contract-related requests and otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering requests. The message is deleted once it is no longer needed for follow-up questions, legal defence or statutory retention duties. If you send diagnostic information from the app, you decide what it contains.
12. Recipients and transfers to third countries
- Cloudflare, Inc. (USA): hosting of website, server, databases and backups and forwarding of emails (Email Routing) as a processor under a data processing agreement (Art. 28 GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; EU Standard Contractual Clauses apply in addition.
- Apple and Google: independently responsible for sign-in, app stores, purchases and Apple Health or Health Connect (for users in the EU: Apple Distribution International Ltd., Ireland; Google Ireland Ltd., Ireland). Their privacy policies apply.
- Microsoft Ireland Operations Ltd. (Ireland): Microsoft 365, our email mailbox, as a processor under a data processing agreement (Art. 28 GDPR). Data is generally stored in the EU; transfers to Microsoft Corporation (USA) rely on the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
You can request a copy of the safeguards via our contact address.
13. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and to withdraw consent with effect for the future. Where we process data based on legitimate interests, you can object on grounds relating to your particular situation. You can export your data yourself in the app at any time (JSON or CSV).
You can lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
There is no automated decision-making or profiling. Providing data is not required by law; without an account, sync and cloud backups are not available.