Privacy Policy

Last updated: August 19, 2026

1. Introduction

Welcome to HabitsTogether ("we", "our", "us"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

2. Information We Collect

Depending on which features you use, we may collect:

  • Account Data: email address and authentication identifiers (via Firebase Authentication).
  • Habit Data: habit blueprints, logs, and related in-app notes you create.
  • Future You Data: selfie input you provide for processing and the generated Future You image.
  • Subscription Data: if you purchase a HabitsTogether Plus subscription, our payment partners (currently RevenueCat and Stripe) process your payment details. We do not receive or store your full card details; we store your subscription status and plan so the app knows what you have access to.
  • Usage Data: limited analytics data such as browser/device data, high-level usage events (for example, which onboarding step or checkout screen was reached), and page-load and performance timings. Analytics events never include the content you write, such as your dream, habits, or coach messages.
  • Diagnostic Data: to find and fix crashes we use Sentry for error monitoring. Reporting an error runs whether or not you accept analytics, because it is how we keep the app working. When an error happens we receive the error itself, your device and browser, the screens you visited, the controls you used, and network and console activity from the moments beforehand. We remove the wording of on-screen labels, such as a habit name shown on a button, before that record leaves your browser. We cannot promise text you wrote never reaches us another way: it can appear inside the error message itself, and anything you type into the feedback form is sent as you wrote it. Also regardless of your choice, and for the same reason, we record for each page you open whether it ended in an error, along with your browser and the app version, so we can measure what share of visits are error-free. That record carries a one-off identifier that exists only in memory for that page and is never stored on your device, and it is linked to your account only if you accept analytics.
  • Diagnostic Data and your analytics choice: the parts of error monitoring that are not needed to find out the app is broken follow the choice you make in the cookie banner. Only after you accept do we attach your account identifier, the streak of your primary habit, and whether you are on a paid plan to a report; only then does Sentry record a replay of your visit, with all text, inputs, and images masked; and only then is a short-lived key (sentryReplaySession) stored in your browser so a replay can be matched to its error. That replay is held in your browser and discarded unless an error happens, and from the first error onwards the rest of that visit is recorded too. If you decline, no replay is recorded at all. If you later turn analytics off, recording stops immediately, the key is removed, and reports carry no account identifier, though what was already recorded before you turned it off may still be sent. You can ask us to delete diagnostic data using the contact details in section 10.
  • Safety Signals: we screen messages you send to the coach for language suggesting a crisis, such as self-harm or abuse, so we can show you support resources instead of an AI reply. When the screen matches, we save to your account records which categories matched and which entries from our fixed internal list of warning phrases were triggered, alongside your account identifier so that we can reach out. Some of those entries are short everyday phrases, so this can record a phrase you actually used, though never your full message. Separately, a count carrying the categories only, with no account identifier attached, goes to our error-monitoring provider so we can confirm this safeguard is still working.
  • Anonymous Usage Counting: to understand where people leave while getting started, we keep a simple running count of how many times each step of the landing and sign-up flow is reached (for example, how many people view the splash screen or reach the sign-in wall). These are aggregate totals only. They set no cookies, store nothing on your device, and contain no identifier, so they cannot be traced back to you or to any single visit. To prevent abuse of the counting endpoint, our server derives a hashed value from your IP address to use purely as a short-lived rate-limit key. The raw address is not stored, this value never leaves our server, and it is kept separate from the usage counts. It runs regardless of your cookie choice, and you can turn it off at any time under Cookie preferences (linked from the footer and your Account screen).
  • Acquisition Data: if your first visit arrives via a marketing link, we record how you found us: campaign tags from the link (utm parameters), advertising click identifiers (such as Google's gclid or Meta's fbclid), the referring site's address (site only, never the full page), and the page you landed on. This is held in your browser only after you accept analytics in the cookie banner, and saved to your account profile when you sign up so we can understand which channels bring people here. It is deleted with your account.

3. Future You Photo Processing (Current Implementation)

  • Your source selfie is sent to our configured AI image provider(s) only to generate your Future You visualization - a dream-scene portrait of the life you described. We do not create age-progressed images.
  • We do not use the selfie you provide for biometric identification.
  • In our current implementation, we do not intentionally store the original selfie in our Firestore database.
  • We store the generated Future You image in your user profile so it can appear in your Today, Future You, and My Habits screens.

4. How We Use Your Information

  • Provide the Product: account login, habit-building workflows, and Future You visualization.
  • Communicate: send confirmations and support responses.
  • Improve Reliability: monitor errors and usage trends to improve quality and performance.
  • Manage Subscriptions: keep your plan and trial status up to date if you subscribe to Plus.

5. Data Storage and Security

Core application data is stored in Google Firebase services. Our Firestore rules are configured so users can read and write only their own user documents and subcollections.

We also use service providers who process data on our behalf, including:

  • Google Firebase, for hosting, authentication, and the database.
  • Google's Gemini and Gemma AI models, to generate coach replies, habit suggestions, and your Future You image. This means the dream, habit, and coach chat text you write is sent to them, along with your selfie when you generate an image. Where we have configured an alternative image provider, your selfie may instead be sent to that provider.
  • Google Analytics, for analytics, and only if you accept it in the cookie banner.
  • Sentry, for error monitoring, and Telegram, which delivers error alerts to our operator.
  • RevenueCat and Stripe, for subscription payments.

We apply reasonable technical and organizational safeguards. No internet transmission or storage system can be guaranteed as absolutely secure.

6. Retention and Deletion

We retain data for as long as needed to operate the service or meet legal obligations. If you want your account data or Future You image deleted, contact us at hello@habitstogether.com.

You can delete your generated Future You image directly on the Today screen using the Delete Photo control. We also support deletion requests through support.

Crisis-safety screening records saved to your account (described in section 2) are kept for no more than 12 months and then deleted automatically. The separate anonymous category count sent to our error-monitoring provider carries no account identifier and follows that provider's retention, also described in section 2.

7. Cookies, Analytics, and Error Monitoring

We use cookies and similar technologies, including analytics tooling (Google Analytics), to understand product usage and improve the experience. Analytics runs only after you accept it in the cookie banner; if you decline, no analytics scripts load and no analytics identifiers are stored. Accepting also lets us keep the first-visit acquisition record described in section 2 in your browser's storage. You can change this choice at any time using Cookie preferences, linked from the footer and from your Account screen.

Separately from the cookie-based analytics above, we keep an anonymous, aggregate count of how many people reach each step of getting started, described under Anonymous Usage Counting in section 2. It is used only to measure and improve how the product is working. Because it sets no cookies and stores nothing on your device, it is carried out for statistical purposes and does not depend on your cookie choice. You can still turn it off at any time using Cookie preferences.

Error monitoring is only partly separate from that choice. Reporting a crash runs on every visit, including when you decline, and so does the error-free measurement described in section 2, because together they are how we find out the app is broken; for that we rely on our legitimate interest in keeping the service working. Session replay, performance timing, and linking a report to your account are covered by your analytics choice: they begin only when you accept, they stop the moment you turn analytics off, and the sentryReplaySession key is written to your browser's session storage only while they are running. Section 2 describes what a report contains, and section 8 covers your right to object.

8. Your Rights

Depending on your location, you may have rights to access, correct, delete, or restrict use of your personal data. To submit a request, contact us at hello@habitstogether.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post updates on this page with a revised "Last updated" date.

10. Contact Us

Questions about privacy or data handling can be sent to hello@habitstogether.com.