Legal · Habit Novice

Privacy Policy

Last updated: 13 September 2026

The short version. Habit Novice keeps your habits and check-ins in an account so they follow you between phones — a guest account if you never sign in, or one tied to Google, Apple or an email. The coach sends your habit names and recent check-ins to an AI model to write its replies, and nothing else. Health data is read on your phone and only the resulting check-in is stored. Voice is recognised on your device. We don't sell your data, we don't show ads, and you can delete your account and everything in it from inside the app.

This policy describes how Habit Novice, a mobile app published by Leafy Orb (“LeafyOrb”, “we”, “us”), handles information. It sits alongside the LeafyOrb Privacy Policy; where the two differ for this app, the page you are reading governs.

1. Your account

Habit Novice works from the first tap without asking who you are: “Try it without an account” creates an anonymous account — a random identifier with no name, email or password. You can later attach Google, Apple or an email address to it so your habits survive a new phone, and you can also sign in with those directly.

Depending on how you sign in, we hold: a random account identifier (always); your email address (email, Google and Apple sign-in — Apple may give us a private relay address); and your display name and profile photo where Google or Apple provide them. Sign-in is handled by Google Firebase Authentication. We never see your password (it is hashed by Firebase) and we never see your Google or Apple password at all.

2. What is stored in your account

The following is stored in our database (Google Cloud Firestore), tied to your account identifier, so it can sync between your devices and be read by the coach:

Only you can read this data: our database rules refuse every request that does not carry your own sign-in, with the single exception of the buddy summary described below. Deleting your account (section 12) removes all of it.

3. The AI coach

Several features are written by a large-language model (Google’s Gemini, run through Google Cloud Vertex AI in our own cloud project): the habit suggestions during onboarding, the goal decomposer, the chat coach, lapse-recovery messages, keystone-habit detection and the weekly report. Each request sends only what that feature needs — typically your habit names, their types and targets, recent check-in counts, your onboarding goals, the coaching tone you chose, and, for the chat coach, the last twenty messages of the current conversation. Requests carry your account identifier so we can apply daily limits; they do not carry your name or email.

Google processes these requests as our data processor. Under the Vertex AI terms, your prompts and the model’s replies are not used to train Google’s models and are not retained by Google beyond serving the request. The replies are stored in your account (section 2) so you can read them again.

The coach is limited per day (three chat messages on the free tier, a higher ceiling on Premium) and can be turned off entirely by not using it — no feature sends anything to the model unless you open it.

4. Health data — Apple Health and Health Connect

You can link a habit to a health metric so the day’s total fills it in for you. This is off until you switch it on for a specific habit, and the app then asks the operating system for read-only access to that one metric — steps, walking and running distance, active energy, exercise minutes, mindful minutes, sleep, or water.

5. Voice check-in and the microphone

“Say it” on the Today screen lets you check in by speaking. Speech is converted to text by your phone’s own recogniser (Apple Speech on iOS, Google’s speech service on Android), subject to those services’ own policies; Habit Novice does not record or store audio. The text is matched to your habits on the device. Only when the app cannot tell which habit a phrase refers to is that phrase sent, as text, to our server and on to the AI model (section 3) together with your habit names. You confirm what was understood before anything is written, and nothing is written otherwise. Microphone and speech-recognition permissions can be revoked in your device settings.

6. Buddy Mode

If you connect with a buddy by exchanging invite codes, that person can see your display name and a daily summary: how many habits you had scheduled, how many you completed, and the rate — never your habit names, amounts or notes. They can send you a nudge, which arrives as a push notification. Either of you can disconnect at any time, after which nothing further is shared. Invite codes can be resolved by anyone who has been given one, but cannot be listed or guessed.

7. Notifications

Reminders are scheduled on your device by the app. Buddy requests, nudges and lapse-recovery prompts may be delivered as push notifications through Expo’s push service and Apple or Google’s notification services, using the device token stored in your account. You can turn all of it off in the app’s reminder settings or your device settings.

8. Diagnostics and configuration

Usage analytics — Google Firebase Analytics

The app records a short list of events so we can see which features are used: a habit created, completed or skipped (its type, never its name), onboarding steps, mode changes, the paywall being viewed, a purchase starting, voice check-in and account linking. Firebase also collects standard device and app information — model, operating system version, language, country derived from IP address, and a randomly generated app instance identifier — and we set your account identifier, mode and tier as properties so we can tell whether Novice and Builder users use features differently.

Analytics and crash reporting can be switched off at any time in Profile → Share usage data. Switching it off stops both immediately, and the app works exactly the same without them.

Crash diagnostics — Google Firebase Crashlytics

When the app crashes we receive a stack trace and technical device state, tagged with your account identifier so a report can be traced to the account that produced it. Crash reports contain no habit names, notes or messages.

Anti-abuse — Google Firebase App Check

Every request to our servers carries an integrity token from Google Play Integrity (Android) or Apple App Attest / DeviceCheck (iOS), confirming it comes from a genuine copy of the app. It attests the app and device, not you, and we use it to keep scripts away from the coach.

Configuration — Google Firebase Remote Config

The app periodically fetches feature flags and limits so we can adjust them without shipping an update. The request carries the app instance identifier and device information above.

9. Purchases — Apple, Google and RevenueCat

Premium is sold through the Apple App Store and Google Play. Payment is handled entirely by Apple or Google — we never see your card number or billing address. We use RevenueCat to know whether a purchase is active: it receives purchase and receipt information and your account identifier, and tells our server which tier you are on. It does not receive your name or contact details from us.

10. Exports, app lock and calendar

Export data (CSV) builds a file of your habits and check-ins on your device and hands it to your phone’s share sheet; where it goes from there is up to you. App lock uses your device’s Face ID, Touch ID or fingerprint through the operating system — we never receive biometric data. The app does not read your contacts, photos, calendar or precise location.

11. What we do not do

12. Deleting your account and data

Profile → Delete account permanently removes your account and everything in it — habits, check-ins, notes, coach conversations, reports, buddy connections, invite code and push token — and signs you out. It cannot be undone. If your session is too old for the store to confirm it is you, the app will ask you to sign in again first.

Uninstalling the app on its own does not delete a Google, Apple or email account — sign in on any device and use Delete account. An anonymous guest account that was never linked to a sign-in is unreachable after uninstalling and is treated as abandoned.

To have us delete records our processors hold outside your account — anonymous analytics and crash reports, and the purchase record at RevenueCat — email support@leafyorb.com with the word deletion in the subject and the email address or account identifier you used. We will confirm within 30 days. Purchase records required for tax and accounting obligations are retained where the law requires it.

13. Children

Habit Novice is intended for a general adult audience and is not directed to children under 13, or the equivalent age in your region. We do not knowingly collect personal information from children.

14. Retention

Account data is kept until you delete your account. Analytics events are retained by Firebase according to our configured retention period and then deleted. Crash reports are retained while they remain useful for diagnosing a fault. AI requests are not retained by Google beyond serving them; the replies live in your account. Purchase records are kept for as long as needed to honour entitlements and to meet tax and accounting obligations.

15. Your rights and choices

You can read, change, export and delete your data in the app at any time. Depending on where you live — for example the EU or UK under GDPR, or California under CCPA/CPRA — you may also have rights to access, correct, delete or port data we hold, and to object to certain processing. Email support@leafyorb.com from the address on your account, or include your account identifier if you signed in anonymously.

16. Data location and transfers

Leafy Orb is based in India. Your account data and our servers are hosted by Google Cloud in the United States. Our processors — Google, Apple, RevenueCat and Expo — operate globally and may process the data described above in the United States and elsewhere, with the safeguards for international transfers required by applicable law.

17. Changes to this policy

We may update this policy as the app evolves. We will change the “last updated” date above and, for significant changes, give notice in the app or on this site.

18. Contact

Questions about privacy in Habit Novice? Email support@leafyorb.com, or write to Leafy Orb, 937/2, Maruthupandiar Street, Thasilthar Nagar, Madurai, Tamil Nadu 625020, India.