Privacy Policy

Last Updated: May 15, 2026

Introduction

This Privacy Policy describes how Galbit ("we," "our," or "us") collects, uses, and protects personal information when you use (1) our habit-tracking mobile application (the "App"), which features Puff—your in-app AI habit coach—and (2) our public marketing website at galbit.app and related pages (the "Website"). We are committed to protecting your privacy and ensuring transparency about our data practices.

By using the App or the Website, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App or the Website.

Information We Collect

1. Account Information

When you create an account, we collect:

  • Email address: Required for account creation (optional for Apple Sign-In users as a privacy feature)
  • Username: Required, unique identifier
  • Password: Stored securely using industry-standard encryption. Apple Sign-In users do not need to set a password
  • Full name: Optional
  • Phone number and country code: Optional
  • Identity statement: Optional (user-defined text describing the person you strive to be)
  • Apple User ID: If you sign in with Apple, we collect your Apple User ID to link your account

2. Habit Tracking Data

To provide our core habit tracking functionality, we collect:

  • Habit information: Titles, descriptions, categories, tracking types, measures/units, priority levels, colors, emojis, and whether the habit is positive or negative (quit habit)
  • Habit entries: Daily performance data, dates, completion amounts/times, associated notes, references to habits, targets, goals, and users, and optional photos or image references you attach to entries (e.g., Photo Log)
  • Target data: Habit targets, timeframes (daily, weekly, custom intervals), schedules, date ranges, and completion status
  • Goals and milestones: Goal titles, descriptions, targets, completion status, associated milestones, and linked habits
  • Streak information: Current and longest streaks for each habit
  • Achievement data: Achievement history, unlocked levels, achievement dates, and associated habit information
  • Archived habits: Habits that have been archived but not deleted

3. Onboarding Information

During the onboarding process, we collect:

  • User preferences: Answers to onboarding questions (multiple choice selections and free text responses)
  • Selected options: Your choices during the onboarding flow
  • AI-generated habit suggestions: When you complete onboarding, we may send your answers and profile information to our AI provider (OpenAI) to generate personalized habit suggestions. You can still build habits manually if you prefer not to rely on those suggestions.

4. Notification Preferences

We collect your notification settings including:

  • Global notification preferences: Enabled/disabled status
  • Quiet hours: Start and end times
  • Notification types: Sound, vibration, badge count preferences
  • Reminder settings: Streak reminders, weekly summaries, achievement notifications, motivational messages, and reminder if missed
  • Per-habit notification preferences: Custom notification times and settings for individual habits

5. Usage and Performance Data

We automatically collect:

  • Experience points: Gamification points earned through habit completion
  • Level information: User level, current level XP, next level XP, and progression data
  • Statistics: Performance metrics, completion rates, daily scores, longest streaks by habit, and time-based analytics
  • Habit sort order: Your preferred sorting method for habits

6. Authentication Data

  • Authentication tokens: Stored securely on your device using encrypted storage for authentication purposes
  • Apple identity tokens: Used for Apple Sign-In authentication and verification
  • Google tokens: If Google Sign-In is enabled (currently disabled in the app)

7. Device and Technical Information

  • Device identifiers: Through Adapty (subscription management service), though we have configured Adapty to disable IP address collection and Apple IDFA collection where possible
  • App version: For compatibility and support purposes

8. Guest Account Data

If you use the App as a guest:

  • Temporary username: Auto-generated temporary identifier
  • Temporary email: Auto-generated temporary email address
  • Onboarding data: Your onboarding responses and suggested habits
  • Habit data: Any habits created during guest usage

Guest accounts can be converted to permanent accounts through email verification or with Apple Sign In.

9. Website usage (galbit.app)

When you visit our Website, we and our analytics vendors may collect information automatically through cookies and similar technologies, including:

  • Google Tag Manager: Loads and coordinates marketing and analytics tags (container ID GTM-NXWQN48F)
  • Google Analytics: Usage data such as pages viewed, approximate location (region), device type, browser, and referral information (measurement ID G-WBHSTDPYN9)

This Website data is generally not linked to your App account unless you are signed in on a page that explicitly ties them together (the marketing site does not require an App login). For more on how Google uses data, see Google's policies. You can control cookies through your browser settings where available.

How We Use Your Information

We use the collected information to:

  1. Provide Core Services: Enable habit tracking and goal management; calculate streaks, achievements, and statistics; store photos or image references you attach to entries; deliver personalized notifications and reminders based on your preferences; sync your data across devices; deliver AI-powered coaching features described below when you choose to use them
  2. Improve User Experience: Customize the App based on your preferences and settings; provide personalized recommendations and insights (including through Puff); enhance app functionality and features; generate statistics and performance analytics
  3. Account Management: Authenticate your identity using secure methods; manage your account and preferences; process subscription transactions via Adapty (third-party subscription management service); enforce monthly limits on certain AI-powered actions based on your subscription tier; handle account upgrades from guest to permanent accounts
  4. Communication: Send you notifications and reminders as requested and configured; send email verification codes via Brevo email service (for guest account conversion); respond to your inquiries and support requests
  5. AI-Powered Coaching (Puff): When you invoke these features, we send the minimum data needed to OpenAI to: generate onboarding habit suggestions; build a suggested set of habits from a goal you provide; produce weekly summaries from habit statistics you submit; power the Excuse Killer conversational coach (your messages and selected habit context); and analyze a photo you choose to upload to suggest which of your existing habits the image may represent (Photo Log). AI output is informational and coaching-oriented—not medical, mental-health, or other professional advice.
  6. Website analytics: Understand how visitors use galbit.app and improve our marketing pages

Data Storage and Security

Local Storage

  • Secure Storage: Authentication tokens are stored using encrypted storage on your device
  • Local Preferences: Notification preferences and habit sort order are stored locally on your device for quick access

Cloud Storage

Your data is stored on secure servers:

  • Database: MongoDB Atlas (cloud database service)
  • Backend API: Hosted on Render.com
  • Data Transmission: All data transmission uses HTTPS encryption

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption: Data in transit is encrypted using industry-standard encryption protocols
  • Password Security: Passwords are encrypted and never stored in plain text
  • Authentication: Secure authentication mechanisms with token expiration
  • Access Controls: Our systems require authentication for access to user data
  • Secure Storage: Sensitive data is stored using encrypted storage

Data Retention

  • Active Accounts: We retain your personal information for as long as your account is active and you use our services
  • Deleted Accounts: When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal or legitimate business purposes (e.g., transaction records)
  • Guest Accounts: Guest account data may be deleted if not converted to a permanent account within a reasonable period

Third-Party Services

We use the following third-party services to provide and improve our App and Website:

1. Adapty (Subscription Management)

  • Purpose: Manages in-app subscriptions and purchases
  • Data Collected: Purchase transaction data, subscription status, user identification (user ID)
  • Privacy Settings: We have configured Adapty to disable IP address collection and Apple IDFA collection where possible
  • Privacy Policy: https://adapty.io/privacy/
  • Note: Adapty is only activated on mobile platforms (iOS/Android), not on web

2. Apple Sign-In

  • Purpose: Authentication service allowing you to sign in with your Apple ID
  • Data Collected: Apple User ID, email (optional - you can choose to hide your email), full name (if provided)
  • Privacy Features: Email address is optional and can be hidden for privacy. If you sign in with Apple, your email cannot be changed through the App (managed by Apple)
  • Privacy Policy: https://www.apple.com/privacy/

3. OpenAI (Puff — AI coaching in the App)

  • Purpose: Powers Puff's AI coaching in the App, including personalized habit suggestions after onboarding; habit "system" ideas from a goal you type; weekly written summaries derived from statistics you send from the App; Excuse Killer chat support (your messages and the habits you are struggling with); and Photo Log image analysis to rank which of your habits a photo may represent
  • Data sent (varies by feature): Onboarding answers and profile fields; goal text; aggregated stats strings (e.g., recent scores, completion rates, streak summaries); chat messages and habit titles/IDs for Excuse Killer; photos you upload for Photo Log plus titles/descriptions of your active habits so the model can match contextually
  • AI credits: Many AI actions consume monthly credits tracked on your account; limits are higher for eligible paid subscribers than for free users. Credits reset monthly as described in the App
  • Privacy Policy: https://openai.com/policies/privacy-policy
  • Your choices: You decide when to open Excuse Killer, run the weekly summary, use Photo Log matching, or request goal-based habit ideas. You can build and log habits without using these AI features; onboarding suggestions can be ignored or edited

4. Brevo (Email Delivery Service)

  • Purpose: Sends email verification codes for guest account conversion
  • Data Processed: Your email address and verification codes
  • Service Provider: Brevo (formerly Sendinblue)
  • Privacy Policy: https://www.brevo.com/legal/privacypolicy/
  • Data Usage: Email addresses are used solely for sending verification codes and are not used for marketing purposes

5. MongoDB Atlas (Database Hosting)

  • Purpose: Cloud database service that stores your account and habit data
  • Data Stored: All user account information, habits, entries, goals, achievements, and preferences
  • Privacy Policy: https://www.mongodb.com/legal/privacy-policy
  • Security: MongoDB Atlas provides enterprise-grade security and encryption

7. Google Tag Manager & Google Analytics (Website)

  • Purpose: Measure traffic and campaign performance on galbit.app
  • Data: Device, browser, pages viewed, and related usage data collected per Google's policies
  • Google Tag Manager: Google Privacy Policy
  • Google Analytics: Google Privacy Policy; you may use browser or OS controls to limit cookies where available

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  1. Service Providers: With trusted third parties who assist us (e.g., Adapty; Brevo; OpenAI for Puff AI coaching in the App; MongoDB Atlas; Render.com; Google Tag Manager and Google Analytics on the Website), subject to confidentiality agreements and only for the purposes described in this Privacy Policy
  2. Legal Requirements: When required by law, court order, or governmental authority, or to comply with legal processes
  3. Protection of Rights: To protect our rights, property, or safety, or that of our users or others, including to prevent fraud or abuse
  4. Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to users and subject to the same privacy protections
  5. With Your Consent: We may share your information with your explicit consent for specific purposes

Your Rights and Choices

You have the following rights regarding your personal information:

  1. Access: Request access to your personal data stored in our systems
  2. Correction: Update or correct inaccurate information through the App settings or by contacting us
  3. Deletion: Request deletion of your account and associated data through the App ("Delete Account" feature) or by contacting us
  4. Data Portability: Request a copy of your data in a portable format
  5. Opt-Out: Disable notifications through App settings; adjust notification preferences at any time; disable specific data collection features where available
  6. Account Management: Update your profile information, preferences, and settings through the App

How to Exercise Your Rights

To exercise any of these rights, please contact us at support@galbit.app. We will respond to your request within a reasonable timeframe and in accordance with applicable data protection laws.

For account deletion, you can use the "Delete Account" feature in the App's Edit Profile section, or contact our support team.

Guest Accounts

The App supports guest accounts that allow you to use basic features without creating a permanent account.

  • Temporary Storage: Guest account data is stored temporarily with auto-generated usernames and emails
  • Conversion: Guest accounts can be converted to permanent accounts through email verification
  • Data Retention: Guest account data may be deleted if not converted to a permanent account within a reasonable period
  • Data Preservation: When converting from guest to permanent account, your existing data (userName, suggested habits, onboarding data) is preserved

Permissions

Notifications

  • Purpose: To send you local notifications for habit reminders, streak reminders, weekly summaries, achievement notifications, and motivational messages based on your preferences
  • User control: You can enable or disable notifications at any time through App settings. You can also configure quiet hours, notification types (sound, vibration, badge), and per-habit notification preferences
  • Permission screen: The App includes a dedicated screen requesting notification permissions with clear explanation

Photos and camera (App)

  • Purpose: To let you attach images to habit entries and use Photo Log features (including AI-assisted habit matching when you choose it)
  • User control: The operating system may prompt for photo library or camera access; you can change permissions in device settings

Apple Sign-In Specific Information

If you choose to sign in with Apple:

  • Email Privacy: Your email address is optional when signing in with Apple. You can choose to hide your email, and Apple will provide a private relay email address
  • Email Changes: If you sign in with Apple, your email address cannot be changed through the App (it is managed by Apple)
  • Account Linking: Your Apple User ID is linked to your account for authentication purposes
  • Guest Upgrade: If you were using a guest account, signing in with Apple will upgrade your guest account to a permanent account, preserving your existing data (userName, suggested habits, onboarding data)

AI-Powered Coaching (Puff)

Galbit includes Puff, an in-app AI habit coach. When you use AI features, relevant content is processed by OpenAI as described in the "OpenAI" section above. In summary:

  • Onboarding suggestions: After you answer onboarding questions, we may send those answers and profile details to generate suggested habits
  • Goal → habits: If you submit a goal, we may send that text to propose a small set of aligned habits
  • Weekly summary: If you request it, we send summarized statistics from the App (e.g., recent scores, completion rates, streaks) to generate a short written report
  • Excuse Killer: If you start a session, we send your chat messages and the habits you mark as "struggling" so the model can coach you in context
  • Photo Log matching: If you upload a photo for matching, we send the image and metadata about your active habits (titles, descriptions, IDs) so the model can suggest which habit fits; you can always pick the habit yourself
  • Credits and plans: Many AI calls require available monthly credits; paid subscribers typically receive higher monthly allowances than free accounts
  • Not professional advice: Outputs are informational and motivational, not medical or mental-health advice; contact a qualified professional for health concerns

For OpenAI's own practices, see https://openai.com/policies/privacy-policy.

Children's Privacy

The App and Website are not intended for children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@galbit.app, and we will delete such information from our systems.

If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. Specifically:

  • Database Storage: MongoDB Atlas servers may be located in various regions
  • Backend Hosting: Render.com servers may be located in various regions
  • Third-Party Services: Data may be processed by service providers in different countries (e.g., OpenAI, Adapty, Brevo, MongoDB Atlas, Render.com, Google)

We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy, including:

  • Using standard contractual clauses approved by data protection authorities
  • Ensuring service providers comply with applicable data protection laws
  • Implementing appropriate security measures

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:

  • Posting the updated Privacy Policy in the App
  • Updating the "Last Updated" date at the top of this policy
  • Sending you a notification through the App (if significant changes occur)

Your continued use of the App after such changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.

Regional Privacy Rights

European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to Access: You have the right to request access to your personal data
  • Right to Rectification: You have the right to request correction of inaccurate or incomplete data
  • Right to Erasure: You have the right to request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: You have the right to request restriction of processing of your personal data
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format
  • Right to Object: You have the right to object to processing of your personal data
  • Right to Withdraw Consent: You have the right to withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at support@galbit.app. We will respond within one month of receiving your request.

California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You have the right to know what personal information is collected, used, shared, or sold
  • Right to Delete: You have the right to request deletion of your personal information
  • Right to Opt-Out: You have the right to opt-out of the sale of personal information (we do not sell personal information)
  • Right to Non-Discrimination: You have the right to non-discrimination for exercising your privacy rights

To exercise any of these rights, please contact us at support@galbit.app. We do not sell your personal information to third parties.

Other Jurisdictions

We strive to comply with applicable data protection laws in all jurisdictions where we operate. If you have questions about your privacy rights in your jurisdiction, please contact us at support@galbit.app.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: support@galbit.app

We will respond to your inquiry within a reasonable timeframe, typically within 30 days, and in accordance with applicable data protection laws.

Note: This Privacy Policy is designed to comply with applicable privacy laws including GDPR, CCPA, and Apple App Store requirements. However, you should review this policy with a legal professional to ensure compliance with all applicable laws and regulations in your specific jurisdiction.