Privacy Policy
Last Updated: February 1, 2026
Introduction
This Privacy Policy describes how Galbit ("we," "our," or "us") collects, uses, and protects your personal information when you use our habit tracking mobile application (the "App"). We are committed to protecting your privacy and ensuring transparency about our data practices.
By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree with this Privacy Policy, please do not use the App.
Information We Collect
1. Account Information
When you create an account, we collect:
- Email address: Required for account creation (optional for Apple Sign-In users as a privacy feature)
- Username: Required, unique identifier
- Password: Stored securely using industry-standard encryption. Apple Sign-In users do not need to set a password
- Full name: Optional
- Phone number and country code: Optional
- Identity statement: Optional (user-defined text describing the person you strive to be)
- Apple User ID: If you sign in with Apple, we collect your Apple User ID to link your account
2. Habit Tracking Data
To provide our core habit tracking functionality, we collect:
- Habit information: Titles, descriptions, categories, tracking types, measures/units, priority levels, colors, emojis, and whether the habit is positive or negative (quit habit)
- Habit entries: Daily performance data, dates, completion amounts/times, associated notes, and references to habits, targets, goals, and users
- Target data: Habit targets, timeframes (daily, weekly, custom intervals), schedules, date ranges, and completion status
- Goals and milestones: Goal titles, descriptions, targets, completion status, associated milestones, and linked habits
- Streak information: Current and longest streaks for each habit
- Achievement data: Achievement history, unlocked levels, achievement dates, and associated habit information
- Archived habits: Habits that have been archived but not deleted
3. Onboarding Information
During the onboarding process, we collect:
- User preferences: Answers to onboarding questions (multiple choice selections and free text responses)
- Selected options: Your choices during the onboarding flow
- AI-generated suggestions: Based on your onboarding responses, we use AI technology to generate personalized habit suggestions. Your onboarding answers and profile information are sent to our AI service provider for this purpose.
4. Notification Preferences
We collect your notification settings including:
- Global notification preferences: Enabled/disabled status
- Quiet hours: Start and end times
- Notification types: Sound, vibration, badge count preferences
- Reminder settings: Streak reminders, weekly summaries, achievement notifications, motivational messages, and reminder if missed
- Per-habit notification preferences: Custom notification times and settings for individual habits
5. Usage and Performance Data
We automatically collect:
- Experience points: Gamification points earned through habit completion
- Level information: User level, current level XP, next level XP, and progression data
- Statistics: Performance metrics, completion rates, daily scores, longest streaks by habit, and time-based analytics
- Habit sort order: Your preferred sorting method for habits
6. Authentication Data
- Authentication tokens: Stored securely on your device using encrypted storage for authentication purposes
- Apple identity tokens: Used for Apple Sign-In authentication and verification
- Google tokens: If Google Sign-In is enabled (currently disabled in the app)
7. Device and Technical Information
- Device identifiers: Through Adapty (subscription management service), though we have configured Adapty to disable IP address collection and Apple IDFA collection where possible
- App version: For compatibility and support purposes
8. Guest Account Data
If you use the App as a guest:
- Temporary username: Auto-generated temporary identifier
- Temporary email: Auto-generated temporary email address
- Onboarding data: Your onboarding responses and suggested habits
- Habit data: Any habits created during guest usage
Guest accounts can be converted to permanent accounts through email verification or with Apple Sign In.
How We Use Your Information
We use the collected information to:
- Provide Core Services: Enable habit tracking and goal management; calculate streaks, achievements, and statistics; deliver personalized notifications and reminders based on your preferences; sync your data across devices; provide AI-powered habit suggestions during onboarding
- Improve User Experience: Customize the App based on your preferences and settings; provide personalized recommendations and insights; enhance app functionality and features; generate statistics and performance analytics
- Account Management: Authenticate your identity using secure methods; manage your account and preferences; process subscription transactions via Adapty (third-party subscription management service); handle account upgrades from guest to permanent accounts
- Communication: Send you notifications and reminders as requested and configured; send email verification codes via Brevo email service (for guest account conversion); respond to your inquiries and support requests
- AI-Powered Features: Generate personalized habit suggestions using AI technology based on your onboarding responses and profile information
Data Storage and Security
Local Storage
- Secure Storage: Authentication tokens are stored using encrypted storage on your device
- Local Preferences: Notification preferences and habit sort order are stored locally on your device for quick access
Cloud Storage
Your data is stored on secure servers:
- Database: MongoDB Atlas (cloud database service)
- Backend API: Hosted on Render.com
- Data Transmission: All data transmission uses HTTPS encryption
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption: Data in transit is encrypted using industry-standard encryption protocols
- Password Security: Passwords are encrypted and never stored in plain text
- Authentication: Secure authentication mechanisms with token expiration
- Access Controls: Our systems require authentication for access to user data
- Secure Storage: Sensitive data is stored using encrypted storage
Data Retention
- Active Accounts: We retain your personal information for as long as your account is active and you use our services
- Deleted Accounts: When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal or legitimate business purposes (e.g., transaction records)
- Guest Accounts: Guest account data may be deleted if not converted to a permanent account within a reasonable period
Third-Party Services
We use the following third-party services to provide and improve our App:
1. Adapty (Subscription Management)
- Purpose: Manages in-app subscriptions and purchases
- Data Collected: Purchase transaction data, subscription status, user identification (user ID)
- Privacy Settings: We have configured Adapty to disable IP address collection and Apple IDFA collection where possible
- Privacy Policy: https://adapty.io/privacy/
- Note: Adapty is only activated on mobile platforms (iOS/Android), not on web
2. Apple Sign-In
- Purpose: Authentication service allowing you to sign in with your Apple ID
- Data Collected: Apple User ID, email (optional - you can choose to hide your email), full name (if provided)
- Privacy Features: Email address is optional and can be hidden for privacy. If you sign in with Apple, your email cannot be changed through the App (managed by Apple)
- Privacy Policy: https://www.apple.com/privacy/
3. OpenAI (AI-Powered Habit Suggestions)
- Purpose: Generates personalized habit suggestions based on your onboarding responses
- Data Sent: Your profile information (name, identity statement, goals) and onboarding question answers
- Data Received: Personalized habit suggestions
- Privacy Policy: https://openai.com/policies/privacy-policy
- User Control: You can choose not to use AI-generated suggestions during onboarding
4. Brevo (Email Delivery Service)
- Purpose: Sends email verification codes for guest account conversion
- Data Processed: Your email address and verification codes
- Service Provider: Brevo (formerly Sendinblue)
- Privacy Policy: https://www.brevo.com/legal/privacypolicy/
- Data Usage: Email addresses are used solely for sending verification codes and are not used for marketing purposes
5. MongoDB Atlas (Database Hosting)
- Purpose: Cloud database service that stores your account and habit data
- Data Stored: All user account information, habits, entries, goals, achievements, and preferences
- Privacy Policy: https://www.mongodb.com/legal/privacy-policy
- Security: MongoDB Atlas provides enterprise-grade security and encryption
6. Render.com (Backend Hosting)
- Purpose: Hosts our backend API that processes your data
- Data Processed: All API requests and responses
- Privacy Policy: https://render.com/privacy
- Security: Render.com provides secure cloud hosting infrastructure
Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Service Providers: With trusted third-party service providers who assist us in operating the App (e.g., Adapty for subscription management, Brevo for email delivery, OpenAI for AI suggestions, MongoDB Atlas for database hosting, Render.com for backend hosting), subject to confidentiality agreements and only for the purposes described in this Privacy Policy
- Legal Requirements: When required by law, court order, or governmental authority, or to comply with legal processes
- Protection of Rights: To protect our rights, property, or safety, or that of our users or others, including to prevent fraud or abuse
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to users and subject to the same privacy protections
- With Your Consent: We may share your information with your explicit consent for specific purposes
Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request access to your personal data stored in our systems
- Correction: Update or correct inaccurate information through the App settings or by contacting us
- Deletion: Request deletion of your account and associated data through the App ("Delete Account" feature) or by contacting us
- Data Portability: Request a copy of your data in a portable format
- Opt-Out: Disable notifications through App settings; adjust notification preferences at any time; disable specific data collection features where available
- Account Management: Update your profile information, preferences, and settings through the App
How to Exercise Your Rights
To exercise any of these rights, please contact us at support@galbit.app. We will respond to your request within a reasonable timeframe and in accordance with applicable data protection laws.
For account deletion, you can use the "Delete Account" feature in the App's Edit Profile section, or contact our support team.
Guest Accounts
The App supports guest accounts that allow you to use basic features without creating a permanent account.
- Temporary Storage: Guest account data is stored temporarily with auto-generated usernames and emails
- Conversion: Guest accounts can be converted to permanent accounts through email verification
- Data Retention: Guest account data may be deleted if not converted to a permanent account within a reasonable period
- Data Preservation: When converting from guest to permanent account, your existing data (userName, suggested habits, onboarding data) is preserved
Permissions
Notifications
- Purpose: To send you local notifications for habit reminders, streak reminders, weekly summaries, achievement notifications, and motivational messages based on your preferences
- User Control: You can enable or disable notifications at any time through App settings. You can also configure quiet hours, notification types (sound, vibration, badge), and per-habit notification preferences
- Permission Screen: The App includes a dedicated screen requesting notification permissions with clear explanation
Apple Sign-In Specific Information
If you choose to sign in with Apple:
- Email Privacy: Your email address is optional when signing in with Apple. You can choose to hide your email, and Apple will provide a private relay email address
- Email Changes: If you sign in with Apple, your email address cannot be changed through the App (it is managed by Apple)
- Account Linking: Your Apple User ID is linked to your account for authentication purposes
- Guest Upgrade: If you were using a guest account, signing in with Apple will upgrade your guest account to a permanent account, preserving your existing data (userName, suggested habits, onboarding data)
AI-Powered Features
The App uses AI technology to generate personalized habit suggestions:
- When Used: During the onboarding process, after you complete onboarding questions
- Data Sent: Your profile information (name, identity statement, goals) and your onboarding question answers
- Purpose: To provide you with personalized habit suggestions tailored to your responses
- User Control: You can choose not to use AI-generated suggestions or ignore them if provided
- Third-Party Processing: Your onboarding data is sent to our AI service provider (OpenAI) for processing. Please review OpenAI's privacy policy: https://openai.com/policies/privacy-policy
Children's Privacy
The App is not intended for children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@galbit.app, and we will delete such information from our systems.
If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. Specifically:
- Database Storage: MongoDB Atlas servers may be located in various regions
- Backend Hosting: Render.com servers may be located in various regions
- Third-Party Services: Data may be processed by service providers located in different countries (e.g., OpenAI, Adapty, Brevo)
We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy, including:
- Using standard contractual clauses approved by data protection authorities
- Ensuring service providers comply with applicable data protection laws
- Implementing appropriate security measures
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated Privacy Policy in the App
- Updating the "Last Updated" date at the top of this policy
- Sending you a notification through the App (if significant changes occur)
Your continued use of the App after such changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
Regional Privacy Rights
European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Access: You have the right to request access to your personal data
- Right to Rectification: You have the right to request correction of inaccurate or incomplete data
- Right to Erasure: You have the right to request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: You have the right to request restriction of processing of your personal data
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format
- Right to Object: You have the right to object to processing of your personal data
- Right to Withdraw Consent: You have the right to withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us at support@galbit.app. We will respond within one month of receiving your request.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You have the right to know what personal information is collected, used, shared, or sold
- Right to Delete: You have the right to request deletion of your personal information
- Right to Opt-Out: You have the right to opt-out of the sale of personal information (we do not sell personal information)
- Right to Non-Discrimination: You have the right to non-discrimination for exercising your privacy rights
To exercise any of these rights, please contact us at support@galbit.app. We do not sell your personal information to third parties.
Other Jurisdictions
We strive to comply with applicable data protection laws in all jurisdictions where we operate. If you have questions about your privacy rights in your jurisdiction, please contact us at support@galbit.app.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: support@galbit.app
We will respond to your inquiry within a reasonable timeframe, typically within 30 days, and in accordance with applicable data protection laws.
Consent
By using the App, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.
You may withdraw your consent at any time by:
- Deleting your account through the App
- Contacting us at support@galbit.app to request account deletion
- Disabling specific features (e.g., notifications) through App settings
Please note that withdrawing consent may affect your ability to use certain features of the App.
Note: This Privacy Policy is designed to comply with applicable privacy laws including GDPR, CCPA, and Apple App Store requirements. However, you should review this policy with a legal professional to ensure compliance with all applicable laws and regulations in your specific jurisdiction.