Legal · Habit Novice
Privacy Policy
Last updated: 13 September 2026
This policy describes how Habit Novice, a mobile app published by Leafy Orb (“LeafyOrb”, “we”, “us”), handles information. It sits alongside the LeafyOrb Privacy Policy; where the two differ for this app, the page you are reading governs.
1. Your account
Habit Novice works from the first tap without asking who you are: “Try it without an account” creates an anonymous account — a random identifier with no name, email or password. You can later attach Google, Apple or an email address to it so your habits survive a new phone, and you can also sign in with those directly.
Depending on how you sign in, we hold: a random account identifier (always); your email address (email, Google and Apple sign-in — Apple may give us a private relay address); and your display name and profile photo where Google or Apple provide them. Sign-in is handled by Google Firebase Authentication. We never see your password (it is hashed by Firebase) and we never see your Google or Apple password at all.
2. What is stored in your account
The following is stored in our database (Google Cloud Firestore), tied to your account identifier, so it can sync between your devices and be read by the coach:
- Your habits — names, icons, colours, schedules, targets, reminder times, and the optional plan B, identity statement, cues and rewards you write for them
- Your check-ins — the date, whether a habit was done, any amount logged, and any note you add (typed or spoken)
- Your onboarding answers (goals, schedule preference, experience) and settings, including Novice/Builder mode, ADHD-friendly mode, reminder budget and coaching tone
- Coach conversations and the weekly reports written for you
- Your Buddy Mode invite code, connections, and the daily summary shared with a buddy (see section 6)
- Your Premium status, as reported by RevenueCat (section 9)
- A push-notification token for the device, so a buddy request can reach you
Only you can read this data: our database rules refuse every request that does not carry your own sign-in, with the single exception of the buddy summary described below. Deleting your account (section 12) removes all of it.
3. The AI coach
Several features are written by a large-language model (Google’s Gemini, run through Google Cloud Vertex AI in our own cloud project): the habit suggestions during onboarding, the goal decomposer, the chat coach, lapse-recovery messages, keystone-habit detection and the weekly report. Each request sends only what that feature needs — typically your habit names, their types and targets, recent check-in counts, your onboarding goals, the coaching tone you chose, and, for the chat coach, the last twenty messages of the current conversation. Requests carry your account identifier so we can apply daily limits; they do not carry your name or email.
Google processes these requests as our data processor. Under the Vertex AI terms, your prompts and the model’s replies are not used to train Google’s models and are not retained by Google beyond serving the request. The replies are stored in your account (section 2) so you can read them again.
The coach is limited per day (three chat messages on the free tier, a higher ceiling on Premium) and can be turned off entirely by not using it — no feature sends anything to the model unless you open it.
4. Health data — Apple Health and Health Connect
You can link a habit to a health metric so the day’s total fills it in for you. This is off until you switch it on for a specific habit, and the app then asks the operating system for read-only access to that one metric — steps, walking and running distance, active energy, exercise minutes, mindful minutes, sleep, or water.
- The app reads only today’s totals (and last night’s sleep) for the metrics you linked, only while it is open, and never in the background.
- Health readings are used on your phone to work out a check-in value — “6 of 8 glasses”, or “done” once a threshold is reached. Only that check-in value is stored in your account, marked as having come from Health. The underlying health records are never uploaded, never stored by us, and never shown to the coach beyond the check-in itself.
- We never write to Apple Health or Health Connect.
- Health data is never used for advertising, never sold, never shared with third parties, and never used for any purpose other than filling in the habit you linked it to. This applies equally to data obtained through Health Connect, in line with Google’s Health Connect permissions policy.
- Switch it off on the habit, in Profile, or by revoking the permission in Apple Health / Health Connect. Anything already logged stays as an ordinary check-in.
5. Voice check-in and the microphone
“Say it” on the Today screen lets you check in by speaking. Speech is converted to text by your phone’s own recogniser (Apple Speech on iOS, Google’s speech service on Android), subject to those services’ own policies; Habit Novice does not record or store audio. The text is matched to your habits on the device. Only when the app cannot tell which habit a phrase refers to is that phrase sent, as text, to our server and on to the AI model (section 3) together with your habit names. You confirm what was understood before anything is written, and nothing is written otherwise. Microphone and speech-recognition permissions can be revoked in your device settings.
6. Buddy Mode
If you connect with a buddy by exchanging invite codes, that person can see your display name and a daily summary: how many habits you had scheduled, how many you completed, and the rate — never your habit names, amounts or notes. They can send you a nudge, which arrives as a push notification. Either of you can disconnect at any time, after which nothing further is shared. Invite codes can be resolved by anyone who has been given one, but cannot be listed or guessed.
7. Notifications
Reminders are scheduled on your device by the app. Buddy requests, nudges and lapse-recovery prompts may be delivered as push notifications through Expo’s push service and Apple or Google’s notification services, using the device token stored in your account. You can turn all of it off in the app’s reminder settings or your device settings.
8. Diagnostics and configuration
Usage analytics — Google Firebase Analytics
The app records a short list of events so we can see which features are used: a habit created, completed or skipped (its type, never its name), onboarding steps, mode changes, the paywall being viewed, a purchase starting, voice check-in and account linking. Firebase also collects standard device and app information — model, operating system version, language, country derived from IP address, and a randomly generated app instance identifier — and we set your account identifier, mode and tier as properties so we can tell whether Novice and Builder users use features differently.
Analytics and crash reporting can be switched off at any time in Profile → Share usage data. Switching it off stops both immediately, and the app works exactly the same without them.
Crash diagnostics — Google Firebase Crashlytics
When the app crashes we receive a stack trace and technical device state, tagged with your account identifier so a report can be traced to the account that produced it. Crash reports contain no habit names, notes or messages.
Anti-abuse — Google Firebase App Check
Every request to our servers carries an integrity token from Google Play Integrity (Android) or Apple App Attest / DeviceCheck (iOS), confirming it comes from a genuine copy of the app. It attests the app and device, not you, and we use it to keep scripts away from the coach.
Configuration — Google Firebase Remote Config
The app periodically fetches feature flags and limits so we can adjust them without shipping an update. The request carries the app instance identifier and device information above.
9. Purchases — Apple, Google and RevenueCat
Premium is sold through the Apple App Store and Google Play. Payment is handled entirely by Apple or Google — we never see your card number or billing address. We use RevenueCat to know whether a purchase is active: it receives purchase and receipt information and your account identifier, and tells our server which tier you are on. It does not receive your name or contact details from us.
10. Exports, app lock and calendar
Export data (CSV) builds a file of your habits and check-ins on your device and hands it to your phone’s share sheet; where it goes from there is up to you. App lock uses your device’s Face ID, Touch ID or fingerprint through the operating system — we never receive biometric data. The app does not read your contacts, photos, calendar or precise location.
11. What we do not do
- We do not sell or rent your personal data, and we do not share it with data brokers.
- We do not show advertising, and the app contains no advertising SDK or advertising identifier.
- We do not track you across other companies’ apps or websites.
- We do not use your habits, notes, messages or health data to train any model.
- We do not read your health data for anything except the habit you linked it to.
12. Deleting your account and data
Profile → Delete account permanently removes your account and everything in it — habits, check-ins, notes, coach conversations, reports, buddy connections, invite code and push token — and signs you out. It cannot be undone. If your session is too old for the store to confirm it is you, the app will ask you to sign in again first.
Uninstalling the app on its own does not delete a Google, Apple or email account — sign in on any device and use Delete account. An anonymous guest account that was never linked to a sign-in is unreachable after uninstalling and is treated as abandoned.
To have us delete records our processors hold outside your account — anonymous analytics and crash reports, and the purchase record at RevenueCat — email support@leafyorb.com with the word deletion in the subject and the email address or account identifier you used. We will confirm within 30 days. Purchase records required for tax and accounting obligations are retained where the law requires it.
13. Children
Habit Novice is intended for a general adult audience and is not directed to children under 13, or the equivalent age in your region. We do not knowingly collect personal information from children.
14. Retention
Account data is kept until you delete your account. Analytics events are retained by Firebase according to our configured retention period and then deleted. Crash reports are retained while they remain useful for diagnosing a fault. AI requests are not retained by Google beyond serving them; the replies live in your account. Purchase records are kept for as long as needed to honour entitlements and to meet tax and accounting obligations.
15. Your rights and choices
You can read, change, export and delete your data in the app at any time. Depending on where you live — for example the EU or UK under GDPR, or California under CCPA/CPRA — you may also have rights to access, correct, delete or port data we hold, and to object to certain processing. Email support@leafyorb.com from the address on your account, or include your account identifier if you signed in anonymously.
16. Data location and transfers
Leafy Orb is based in India. Your account data and our servers are hosted by Google Cloud in the United States. Our processors — Google, Apple, RevenueCat and Expo — operate globally and may process the data described above in the United States and elsewhere, with the safeguards for international transfers required by applicable law.
17. Changes to this policy
We may update this policy as the app evolves. We will change the “last updated” date above and, for significant changes, give notice in the app or on this site.
18. Contact
Questions about privacy in Habit Novice? Email support@leafyorb.com, or write to Leafy Orb, 937/2, Maruthupandiar Street, Thasilthar Nagar, Madurai, Tamil Nadu 625020, India.