Last Updated: May 20, 2024
1. Introduction
HabitGrind ("we," "our," or "the app") is committed to protecting your privacy. This policy explains how we handle your data when you use the HabitGrind mobile application and our services.
2. Data Collection and Purpose
We request and collect data only to provide and improve our core functionality:
- Account Information: If you choose to use Cloud Sync, we collect your email address and basic profile info via Google Sign-In to uniquely identify your account and sync your data across devices.
- App Data: Your habits, todos, routines, and progress logs are stored locally on your device. If Cloud Sync is enabled, this data is stored in Google Firebase, where data is protected using encryption in transit (TLS) and encryption at rest.
- Analytics: We may collect anonymous usage statistics to identify bugs and improve app performance.
Google OAuth Scopes
HabitGrind’s use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements. We use your Google account information solely for the purpose of identifying your sync profile and protecting your habit data. OAuth access tokens are transmitted securely over TLS and are not shared with third parties except as required to provide the requested Google services.
3. Permissions and Their Use
- Notifications/Alarms: To send you habit reminders and scheduled nudges.
- Accessibility Service: Used only if you enable the "App Blocker" or "Website Blocker" features. This service is used to detect and block distracting apps/URLs during your focus sessions. We do not collect or transmit any data from this service.
- Biometrics: Used locally to secure the "App Lock" feature. We never access your actual biometric data.
4. Data Transparency & Control
- Ownership: You own your data. You can export your habits and routines to CSV or PDF at any time via the settings.
- Deletion: You can delete specific data within the app or use the "Delete Account" option in settings to permanently remove all your data from our cloud servers.
- No Third-Party Sharing: We do not sell, trade, or share your personal data with third-party advertisers.
5. Data Security & Protection
We take reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
- Encryption in Transit: All communication between the HabitGrind app and our servers is protected using HTTPS/TLS encryption.
- Encryption at Rest: Cloud Sync data stored in Google Firebase is encrypted at rest using Google's managed encryption infrastructure.
- Secure Authentication: User authentication is handled through Google Sign-In using OAuth 2.0. HabitGrind does not collect or store your Google account password.
- Restricted Access: Access to cloud data is restricted by authenticated user identity through Firebase Security Rules. Access to cloud infrastructure is limited to authorized personnel only.
- Minimal Data Collection: We collect only the information necessary to provide the features you choose to use, such as Cloud Sync.
- Local Protection: Habit data remains on your device unless you explicitly enable Cloud Sync. App Lock uses your device's biometric authentication locally and no biometric information is transmitted or stored by HabitGrind.
- Data Deletion: When you delete your account from within the app, your associated cloud data is permanently deleted from our servers within a reasonable period, subject to backup retention policies where applicable.
While no method of electronic storage or transmission over the Internet is completely secure, we continuously work to protect your information using industry-standard security practices.
6. Contact Us
For any privacy-related questions or to request data deletion, contact us at:
hello@habitgrind.space