← Back home

Privacy Notice

Last updated: June 27, 2026

1. Who we are

This Privacy Notice describes how Build Better Habit ("we", "us", "our") collects and uses personal data when you use the Build Better Habit application and website (the "Service"). Build Better Habit is the data controller for personal data processed in connection with the Service.

2. Data we collect

  • Account data — name, email address, password hash, profile preferences, authentication identifiers (e.g. Google sign-in).
  • Habit and journal content — habits, completions, streaks, mood entries, journal entries, AI Coach messages.
  • Usage and device data — pages viewed, features used, approximate location derived from IP address, browser, OS, and device identifiers, sent for security and product improvement.
  • Support data — messages and attachments you send when contacting support.
  • Payment data — handled by Paddle (see section 5). We receive subscription status, plan, and billing-period metadata; we do not store full card details.

3. How and why we use your data

  • Create and manage your account and provide the Service (legal basis: performance of contract).
  • Store, sync, and display your habits, streaks, journal entries, and AI Coach history (performance of contract).
  • Generate AI Coach responses using your selected context (performance of contract).
  • Send transactional emails such as sign-in, password reset, and important service notices (performance of contract / legal obligation).
  • Detect and prevent fraud, abuse, and security incidents (legitimate interests).
  • Measure usage, debug issues, and improve the product (legitimate interests).
  • Send marketing or product updates only where you have opted in (consent), which you can withdraw at any time.

4. Cookies and similar technologies

We use a small number of essential cookies and local-storage entries needed to keep you signed in, remember your theme, and operate core features. We may use privacy-friendly analytics to understand aggregated usage. The Service does not run advertising cookies. You can clear cookies and local storage in your browser settings at any time.

5. Who we share data with

  • Hosting and backend — our cloud infrastructure provider, which stores account, habit, and journal data on our behalf.
  • Authentication — Google, where you choose to sign in with Google.
  • AI processing — our AI model provider, which processes the prompts and context needed to generate AI Coach responses.
  • Payments — Merchant of Record — Paddle (Paddle.com Market Limited) is the seller of record for all paid plans and processes payments, taxes, invoicing, subscription management, and refunds. See Paddle's privacy notice.
  • Professional advisers — legal, accounting, and similar advisers where necessary.
  • Authorities — when required by law or to protect our rights and the safety of users.

We do not sell your personal data.

6. International transfers

Our service providers may process data outside your country of residence, including in the United States and the European Union. Where transfers occur from the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

7. Data retention

We retain account and habit data for as long as your account is active. If you delete your account, we delete or anonymise associated personal data within a reasonable period, except where we are required to retain certain records for legal, tax, or fraud-prevention purposes (for example billing records held by Paddle).

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. UK/EEA users also have the right to complain to their local supervisory authority. We aim to respond to verified requests within one month. To exercise these rights, contact us via the in-app support option.

9. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and row-level authorization on user data. No system is perfectly secure; please keep your account credentials confidential.

10. Children

The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children.

11. Changes to this notice

We may update this Privacy Notice as the Service evolves. Material changes will be communicated in-app or by email. The "Last updated" date above always reflects the current version.

12. Contact

Questions about privacy or your data? Contact Build Better Habit via the in-app support option. For billing-related data handled by our Merchant of Record, contact Paddle at paddle.net.