Privacy Policy
Effective 14 September 2026
This policy describes what HabitX collects, why, where it goes and how to remove it. HabitX is published by CineX LLC Confirm: legal publisher entity, part of Alpheraz. It is written to match what the app actually does; where a statement depends on a configuration we have not yet confirmed, it is marked.
The short version
- HabitX has no ads and does not sell your data.
- You sign in with Apple or Google. We receive an account identifier, and an email address only if you choose to share it.
- What you track — habits, routines, goals, completions, mood check-ins, gratitude entries and journal entries — is stored in your account so it syncs and survives a new phone or reinstall.
- Journal entries are private reflection: they sync encrypted with your account, are not used by Q, are not sold, and are not browsed by HabitX staff for product features. Operators may access production data only to run the service, fulfill a support request you initiate, or meet a legal obligation.
- When you ask Q a question, the question and the relevant non-journal records from your account are sent to our servers to produce an answer, and Q shows you which records it read.
- Payments are handled entirely by Apple. We never see your card.
- You can delete your account and its data from inside the app.
What we collect and why
| Data | Why | Where it lives |
|---|---|---|
| Apple sign-in identifier; email address if you share it; name if you share it | To create and secure your account and restore it on a new device | Our authentication provider (Supabase) |
| Habits, schedules, subtasks, completions, routines, goals, milestones | The product — this is what you are tracking | Your account on our database (Supabase) |
| Mood check-ins and gratitude entries | Context for Day Score and Q | Your account on our database (Supabase) |
| Journal entries (free text) | Private reflection that survives device changes; never used by Q | Your account on our database (Supabase), encrypted in transit and at rest; not included in Q requests |
| Questions you ask Q, and the records Q reads to answer | To generate the answer | Sent to our servers over HTTPS for processing; see Q below |
| Subscription status | To unlock Pro features | Apple provides an entitlement; we store the status, not payment details |
What we do not collect
- Location. HabitX does not request or use your location.
- Health data. HabitX does not read from or write to Apple Health. Confirm: no HealthKit entitlement in the release build
- Contacts, photos, microphone recordings stored server-side. Voice input to Q is transcribed on device by iOS; the audio is not sent to us. Confirm: Q voice input uses on-device iOS speech recognition
- Advertising identifiers. There are no ad networks in HabitX.
- Third-party analytics. HabitX does not currently include third-party analytics or crash-reporting SDKs. Confirm: no analytics/crash SDK in the release build
Q
Q is HabitX’s intelligence feature. When you ask a question, HabitX sends the question and the specific records needed to answer it — for example a habit’s recent completions, mood check-ins and Day Scores over a period — to HabitX’s servers, authenticated with your account’s session token. Q shows you what it read before it answers. Q never reads journal entries; journals are excluded from Q evidence and from any Anthropic Claude requests.
Q runs on HabitX servers. Structured evidence and scoring stay on HabitX infrastructure. When generative answers are produced, HabitX uses Anthropic Claude; those requests leave HabitX infrastructure and are processed by Anthropic under their terms (including retention and no-training for API traffic under Anthropic’s commercial API terms). HabitX does not use Q requests to train HabitX models.
Q describes associations it finds in your data. An association is not proof that one thing caused another, and Q is not medical, psychological or financial advice.
Day Score
Day Score is computed from your own completions, targets, consistency and mood check-ins, and compared with your own history. It is not a health or medical measure and is not shared with anyone.
Payments
HabitX Pro is sold through the App Store. Apple processes the payment and holds your payment details; HabitX receives a transaction record confirming your subscription status. Manage or cancel in Settings → Apple ID → Subscriptions. Refunds are handled by Apple.
Where data is stored and who can see it
Account data is stored with Supabase, our database and authentication provider, in Confirm: Supabase project region, e.g. us-east-1. Data is encrypted in transit (HTTPS) and at rest by the provider. Access to production data is limited to the people who operate HabitX and is used only to run the service, respond to support requests and investigate problems. We do not sell personal data and we do not share it with advertisers.
Providers who process data on our behalf: Apple (sign-in, payments), Supabase (database and authentication), and Anthropic (Claude, for generative Q answers when that path is used). Each acts under its own terms and only to provide the service.
Retention and deletion
Your data is kept for as long as your account exists. You can delete your account at any time from Settings → Account → Delete account Confirm: in-app deletion path exists in the release build — required by App Store guideline 5.1.1(v). Deletion removes your account and all associated records from our database, including journal entries. If you cannot access the app, email support@habitx.ai from the address on the account and we will delete it within 30 days. See Delete your account.
Children
HabitX is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your data, or to object to certain processing. Most of these you can do yourself in the app. For anything else, email support@habitx.ai. Confirm: if EU/UK users are in scope, add GDPR lawful basis and supervisory-authority contact; if California, add CCPA notice
Changes
If this policy changes in a way that matters, we will note it in the app and update the date at the top of this page.
Contact
CineX LLC, Alpheraz. support@habitx.ai. Confirm: add a postal address if required in your jurisdiction