init.Habits
en
app store

privacy

what we collect

This policy covers three contexts: the inithabits.com marketing website, the init.Habits iOS app, and the init.Habits web app at app.inithabits.com. Where we say "the app" we mean the iOS app and the web app together, unless we single one out.

Website (inithabits.com)

When you sign up for the init.Habits beta or updates list, we collect your email address and whether you opted in to receive dev updates. Email addresses are stored on our server in the EU. Emails are sent via Resend, who deliver each message and track which links you open and click to help us understand engagement. That's the only personal data we collect on the marketing website.

Accounts and sign-in

To use Cloud Sync — which is required for the web app and optional on iOS — you create an init.Habits account. There are two ways:

Sign in with Apple (iOS and web): we receive a stable, Apple-provided identifier for you and, if you allow it, an email address (which may be an Apple private-relay address). We do not request or store your Apple name or any other Apple profile detail.

Email and password (web only): we store your email address and a securely hashed version of your password. We never see or store your password in plain text — authentication is handled by our self-hosted Appwrite backend on our server in the EU. We send you transactional emails to verify your address and to let you reset your password; these are delivered via Resend.

Your account is what ties your synced data together across your devices.

App — your habit data

All habit data you create (habits, routines, completions, streaks, day records, achievements, goal tags, custom themes, and app settings) is created and stored locally on your device or in your browser. Whether it leaves your device depends on what you turn on:

Cloud Sync stores the same data on our server in the EU so it can sync across your devices and power the web app. Cloud Sync is required to use the web app or to sync between web and iOS; on iOS it is optional. Sensitive free-text fields — habit names, notes, subtitles, routine names, custom theme names, and your display name if you set one — are encrypted at rest on our server. You can turn Cloud Sync off at any time, which deletes your data from our server, or fully delete your account from the app's $ sync & data settings page.

iCloud Backup (iOS only) syncs the same data through your personal iCloud account via Apple's CloudKit. We have no access to this. Cloud Sync and iCloud Backup used to be Pro features; they are now available to everyone.

App — HealthKit (iOS only)

If you use habits backed by Apple Health (such as steps or workouts), the app reads the relevant metrics from HealthKit on your device only, to mark those habits complete. HealthKit data is never transmitted to or stored on our servers. If such a habit is synced via Cloud Sync, only its completion state and value sync — the same as a manual habit — never your underlying Health records.

App — reminders and notifications

On iOS, reminders are scheduled as local notifications on your device. On the web, if you turn web reminders on, your browser creates a Web Push subscription (an endpoint and keys that identify that specific browser). We store this subscription on our server in the EU so our server can deliver the reminders you asked for. It is per-browser, and it is removed when you turn web reminders off in that browser or delete your account.

Comeback nudges (web): if you have web reminders enabled and then don't open the app for a while, we may send you a "comeback" re-engagement email, delivered via Resend, to the email on your account. Every such email carries an unsubscribe link, and you can turn comeback nudges off in the app's notification settings at any time.

Feedback messages

If you send a message or screenshot through the feedback feature — available in both the iOS app and the web app — that content is transmitted to and stored on our server in the EU. We use it solely to read and process your request, and to improve init.Habits. It is not shared with third parties or used for any other purpose.

Themes marketplace

If you choose to publish a custom theme to the themes marketplace, the theme itself (its name and colour values) and the username you enter when submitting it are stored on our server in the EU. This information is public by design: it is used solely to display your theme — together with the username you chose — in the marketplace inside init.Habits, so other users can browse and download it. The username is one you pick at submission time; it does not have to be your real name and is not linked to your email. Publishing is entirely optional — if you never publish a theme, none of this applies to you, and you can remove a theme you published (and the username attached to it) at any time, which deletes it from our server.

Analytics

We use analytics to understand how init.Habits is used, in three places:

Marketing website (inithabits.com): anonymous, cookieless page-view data via TelemetryDeck and Umami — the page you loaded, the approximate time, the referring site if any, and your approximate country. Your IP address is not stored.

Web app (app.inithabits.com): usage events (which screens and actions are used) sent to our self-hosted Aptabase instance on our server in the EU. For signed-in users, these events also carry a pseudonymous account reference and the platform, so we can understand how the same account uses the app across web and iOS. This reference is not your name or email, but it does link the events to your account, so it is pseudonymous rather than fully anonymous.

iOS app: the same usage events via TelemetryDeck and our self-hosted Aptabase, with the same pseudonymous account reference for signed-in users, plus a small number of anonymous count events (app launches, habits created, habits completed) sent to inithabits.com to display public usage statistics.

We use analytics to see how the product is used in aggregate, find crashes and issues, and prioritise improvements. We never sell this data or use it for advertising.

QR sign-in (pairing)

If you sign in to the web app by scanning a QR code with the iOS app, our server briefly processes the web browser's IP address, approximate location (city), and browser type — solely to show them to you on your phone so you can confirm the request is really yours before you approve it. This is used only for that security confirmation and is discarded after the short pairing window closes.


why we collect

Your email (website) is used solely to send you the TestFlight invite and — if you opted in — occasional development updates. Link-click data is used to send relevant follow-ups (for example, a reminder if you haven't joined TestFlight yet).

Account data is used to provide the account, sync, and web app you signed up for, and to send you account and security messages (verification, password reset).

Your habit data is stored on our server, when you enable Cloud Sync, so it can sync across your devices and run in the web app.

Reminders and push subscriptions are used only to deliver the reminders and nudges you turned on.

Feedback messages are used to read and process your request and improve init.Habits. They are not shared with third parties.

Themes you publish to the marketplace, and the username you submit with them, are used only to display those themes to other users browsing the marketplace inside init.Habits.

Analytics are used to understand how the app and site are being used, identify crashes and issues, and prioritise improvements.


legal basis

We rely on the following legal bases under the GDPR:

Contract (Art. 6(1)(b)): providing your account, Cloud Sync, the web app, and any paid subscription — this processing is necessary to deliver the service you signed up or paid for.

Consent (Art. 6(1)(a)): the website email/updates list; publishing a theme to the marketplace; sending us feedback; and turning on web push reminders and comeback emails. You can withdraw consent at any time.

Legitimate interest (Art. 6(1)(f)): anonymous and pseudonymous analytics, and keeping the service secure and working.

We are based in the Netherlands. This policy is written to meet GDPR requirements.


international transfers

Your habit data, account data, feedback, published themes, and website email are stored on our own server in the EU.

Some of the service providers we rely on are based outside the European Economic Area — for example Apple, RevenueCat, and Sentry in the United States, and Paddle in the UK/EU/US. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and/or the providers' participation in the EU–US Data Privacy Framework.


payments

On iOS, subscriptions are processed by Apple through the App Store. We never receive your card or payment details.

On the web, subscriptions are processed by Paddle, acting as our merchant of record. Paddle is an independent data controller for your billing and tax data, and collects information such as your name, billing address, payment method, and country (for VAT). We do not receive or store your card details; through RevenueCat we receive only your subscription status and a pseudonymous customer identifier, which links your purchase to your account so we can unlock Pro for you.


data details

habit data stored on your device or in your browser * in your own iCloud account if iCloud Backup is enabled, iOS (we cannot access it) * on our server in the EU if Cloud Sync is enabled, required for the web app (sensitive fields encrypted at rest)
account data stored a server in the EU (email and a securely hashed password for email accounts * an Apple-provided identifier for Sign in with Apple)
feedback stored a server in the EU
published themes stored a server in the EU (public — theme name, colours, and the username you chose at submission)
website email stored a server in the EU
web push subscription stored a server in the EU (one row per browser you enable reminders on)
payment data Apple, iOS * Paddle as merchant of record, web — we do not store your card details
retained until you unsubscribe or request deletion (website email) * you delete the app, turn off Cloud Sync, or delete your account (habit and account data) * you remove init.Habits data from iCloud (iCloud copy) * you unpublish it (marketplace themes) * you turn off web reminders or delete your account (push subscription) * handled per their own retention policy (third-party services)
shared with Resend (email delivery and open/click tracking — privacy), TelemetryDeck (anonymous analytics — privacy), Umami (anonymous website analytics — privacy), RevenueCat (subscription and entitlement management — privacy), Paddle (web payments, merchant of record — privacy), Sentry (iOS crash reporting — privacy), Apple CloudKit (iCloud Backup — privacy), Apple (Sign in with Apple and the App Store — privacy)
self-hosted (not shared) our Appwrite backend and our Aptabase analytics both run on our own server in the EU — this data does not leave our infrastructure
sold to anyone never
used for ads never

security

Data sent between your device and our servers is encrypted in transit (HTTPS/TLS). Sensitive free-text fields in Cloud Sync are encrypted at rest on our server, and account passwords are stored only as secure hashes — we never hold them in plain text. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.


your rights

Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your data, and the right to data portability. You can also withdraw consent at any time.

Portability: you can export your full habit data at any time using the in-app backup export.

To unsubscribe from all emails, use the unsubscribe link in any email we've sent you, or email us directly. To request full deletion of your data, email us and we'll remove your record within 30 days.

To delete your habit data: delete the app to remove the local copy; remove the init.Habits data from your iCloud account in iOS Settings to clear the iCloud copy; and turn off Cloud Sync in the app's $ sync & data settings, or use $ delete-account, to remove the copy on our server along with your account.

To remove a custom theme you published to the marketplace — along with the username attached to it — unpublish it from the themes marketplace in the app, which deletes it from our server.

Complaints: you have the right to lodge a complaint with your local data protection authority. In the Netherlands, that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Automated decisions: we do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

Contact: hello@inithabits.com


children

init.Habits is not directed at children. You must be at least 16 years old to use the app, the web app, or the website, and to create an account. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.


data controller

The data controller responsible for your personal data is Vladyslav Glogus, an individual operating init.Habits from the Netherlands. For any privacy question or request, contact hello@inithabits.com.


changes

We may update this policy from time to time. When we do, we will update the date at the top of this page. We encourage you to check back occasionally. Continued use of the app or website after changes are posted constitutes your acceptance of the updated policy.


cookies

The marketing website (inithabits.com) uses no cookies — our website analytics are cookieless. Your theme preference and visit state are stored locally in your browser and never sent to our servers.

The web app (app.inithabits.com) uses one strictly-necessary sign-in token, stored in your browser, to keep you logged in. We use no tracking, advertising, or third-party cookies anywhere.