HabitTracker — Privacy Policy
Last updated: July 2026
HabitTracker is a personal health and habit dashboard, operated by Ace Apps. This policy explains what data the app handles and how.
What data we use
With your explicit permission, HabitTracker imports your own health data from connected services you choose to link:
- Garmin — your daily step counts, sleep summaries, and workout/activity sessions.
- Google Drive — used only to store a single private backup file of your own data.
-
Google Calendar — read to show your schedule alongside your day inside the app, and (at your request)
to create or remove events, such as adding a preparation task for an upcoming meeting. Event deletion is limited to
events that were created inside the app: HabitTracker never modifies or deletes calendar events that originate anywhere
else (Google Calendar itself, other apps, or invitations from other people).
It also stores the information you enter yourself, such as food, weight, tasks, and habit check-ins.
How we use it
Your data is used for a single purpose: to display your own activity, sleep, workouts, and habits back to you inside the app so you
can review your personal trends. For example, a completed Garmin workout can automatically mark a "worked out" day, and exercise
can be correlated with recovery metrics like sleep. That's it.
What we do not do
We do not sell your data. We do not share it with any third party. We do not use it for advertising. Your data is not aggregated
with other users' data.
Google user data — Limited Use
HabitTracker's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. Specifically, data obtained from Google Drive and Google Calendar is used only to provide and
improve the app's features for you (backing up your data and showing/managing your own calendar events). We do not transfer this data
to others except as necessary to provide those features, and we do not use it for advertising, sell it, or allow humans to read it
except with your explicit consent, for security purposes, or to comply with applicable law.
Where your data is stored
Your tracker data is stored privately on your own device and, if you enable backup, in a single private file in your own Google
Drive. Garmin and Google access is authorized by you and can be revoked at any time — by disconnecting inside the app, or from
your Garmin Connect and Google account settings.
If you create an account (optional — used to sync your data between your devices), a copy of your tracker data
is also stored in our sync database, hosted on Supabase. Each user's data is isolated by row-level security: it is accessible
only to your authenticated account, is never shared with other users or third parties, and is used solely to sync your own data
to your own devices. The only account information we store is the email address (or Google/Apple identity) you sign in with.
Signing out stops syncing; deleting your account (below) removes the synced copy entirely.
How we protect your data
HabitTracker is designed so that sensitive data is protected by default:
-
Encryption in transit. All communication between the app, our servers, and Google/Garmin APIs takes place
exclusively over HTTPS (TLS).
-
Encrypted credentials. The OAuth tokens that grant access to your Google and Garmin accounts are encrypted with
AES-256-GCM using a server-held secret key, and are stored only in secure, HTTP-only cookies on your own device. They are never
stored in plain text and never written to a server-side database.
-
No server-side storage of Google user data. Our serverless functions process Google Calendar and Drive data
transiently, in memory, only for the moment needed to serve your request, and then discard it — none of it is written to a
database. The optional sync database (see above) holds only the tracker data you entered yourself, isolated per account by
row-level security.
-
Minimum access. The app requests only the narrowest scopes needed for its features (for Drive, the
drive.file scope, which can only see files the app itself created), and access is limited to the app's automated
functionality — no humans read your data.
Data retention and deletion
-
Google Calendar data is fetched on demand to display your schedule and is cached only on your own device. It is
not retained on our servers.
-
Google Drive data consists of a single backup file that the app creates in your own Drive. You can delete it at
any time directly from Google Drive; we keep no copy.
-
Access tokens are retained only until you disconnect. Disconnecting Google or Garmin inside the app immediately
deletes the stored token from your device. You can also revoke the app's access at any time from your
Google account permissions page, which
invalidates its access instantly.
-
Account sync data is retained only while your account exists. Deleting your account from inside the app
(Settings → Account → Delete account) permanently removes your synced data and your sign-in identity from our database,
immediately and irreversibly. The copy on your own device remains yours and is untouched.
-
Everything else (your habits, food log, notes) lives on your own device. You can erase it at any time by
clearing the app's site data or removing the app, and delete the Drive backup file for a complete removal. Because we retain no
Google user data server-side, no further deletion request to us is required — though you can always contact us at the address
below and we will assist.
Contact
Questions about this policy: aceex7@gmail.com