1. Introduction
This Privacy Policy describes how Uatixsystems ("we," "us," or "our") collects, uses, stores, and discloses your information when you use our mobile application, HabitLoop - Daily Habits (the "Application" or "Service"), as well as our related web services and pages.
By downloading, accessing, or using HabitLoop - Daily Habits, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not download or use the Application.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us at:
- Operator / Company: Uatixsystems
- Address: Johar Town, Lahore, Pakistan
- Support Email: support@habitloop.uatixsystems.com
- Privacy Email: privacy@habitloop.uatixsystems.com
- Website: https://habitloop.uatixsystems.com
2. Information We Collect
We collect information directly from you when you provide it to us, automatically as you navigate through the Application, and from third-party services integrated into the Service.
Account Information
When you register an account in HabitLoop, we collect:
- Name / Display Name: The name you provide during sign-up or profile editing.
- Email Address: Your email address used for account registration, authentication, and communication.
- User Identifier: A unique internal UUID assigned to your account by our authentication provider (Supabase Auth).
- Profile Image URL: If you choose to sign in using Google Sign-In, we may receive your public Google profile picture URL.
- Authentication Provider Data: Information regarding your method of sign-in (Email/Password or Google Sign-In).
- Account Timestamps: The date and time your account was created and last updated.
Note on Passwords: We do not store or process your plaintext password. All password authentication is securely managed by Supabase Authentication.
User-Generated Data
To provide our core habit-tracking features, we process:
- Habits: Habit names, custom subtitles, selected icon codepoints, color values, difficulty levels (
easy,medium,hard), target values, and creation/archival dates. - Schedules: Frequency settings (
daily,weekly,custom), selected active weekdays, and reminder wall-clock times (HH:mm). - Completion Progress: Dated daily completion progress entries (
yyyy-MM-ddmapped to progress values from 0.0 to 1.0). - Statistics & Streaks: Calculated current streak days, best streak records, and total completion counts.
- Archived Items: Habits marked as archived, which remain stored to preserve historical completion statistics unless deleted.
- Preferences & Settings: Theme choices (system, light, dark), premium color palette choices, onboarding completion status, and diagnostics opt-in toggles.
Sensitive Information You Choose to Enter
HabitLoop does not require you to place medical records, financial account information, government identifiers, passwords, or other highly sensitive information in habit names, notes, or AI prompts. Because habit titles or prompts are user-generated, they could reveal sensitive information if you choose to enter it. Please avoid entering unnecessary sensitive or confidential information.
Device and Technical Information
When you access the Application, we may collect technical information about your device, including:
- Device Hardware & OS: Device model, operating system version (Android / iOS), and platform type.
- Application Metadata: HabitLoop version string (
1.0.0+2) and build number. - Locale & Timezone: System language preferences and device timezone setting (used to format reminder times and calendar completion dates accurately).
- Push Notification Token: Firebase Cloud Messaging (FCM) device registration token assigned to your installation when notification permissions are granted.
- Device Credential Hash: An internal cryptographic hash used to manage token registration and revocation securely.
- IP Address & Technical Logs: Standard server access logs and network request metadata generated during API requests.
Usage Information
If you leave Diagnostics & Analytics enabled in the Application settings, we process app event and interaction data via Firebase Analytics:
- Feature Usage: Screens opened, buttons tapped, habit creation events, and completion actions.
- Session Metrics: Session duration, app launches, and general engagement statistics.
- Performance Metrics: Application load performance and network response times.
You can disable analytics and diagnostics collection at any time in Settings > Diagnostics & analytics.
Advertising Information
HabitLoop incorporates the Google Mobile Ads SDK (AdMob) to display banner advertisements on supported Android builds. When banner ads are requested, Google Mobile Ads may process:
- Advertising Identifiers: Android Advertising ID (
AD_ID). - Location Data: Coarse, IP-derived general geographic location.
- Ad Interaction Data: Ad impressions, clicks, and engagement metrics.
- Device & Diagnostic Data: Device hardware parameters and SDK performance metrics.
Configuration Notice: In our Application Manifest, Firebase Analytics collection of the Advertising ID (google_analytics_adid_collection_enabled) and default ad-personalization signals (google_analytics_default_allow_ad_personalization_signals) are explicitly set to false. AdMob independently processes technical device identifiers for ad serving, measurement, and fraud prevention as detailed in Section 3.
3. Google AdMob / Advertising
HabitLoop uses Google Mobile Ads (AdMob) to display banner advertisements on supported Android builds.
Information Used for Advertising
When an ad request is made, Google and participating advertising technology providers may process information such as:
- Device and application information.
- IP address and coarse location inferred from IP address.
- Advertising or device identifiers where available and permitted by the operating system, app configuration, user choices, and applicable law.
- Ad impressions, clicks, interactions, and fraud-prevention signals.
- Consent and privacy-choice signals.
This information may be used to deliver ads, measure performance, limit repeated ads, detect invalid traffic or fraud, and comply with legal and platform requirements.
Personalized, Non-Personalized, and Limited Ads
Depending on your location, consent status, device settings, age-related settings, and AdMob configuration, Google may serve:
- Personalized ads, which may use information about interests or activity to tailor advertising.
- Non-personalized ads, which are selected primarily using contextual information. Non-personalized ads can still require technical processing such as IP address, device information, consent signals, frequency capping, and fraud prevention.
- Limited ads, where Google restricts the use of certain identifiers or other data for advertising purposes.
HabitLoop does not intentionally store your Android Advertising ID in its own application database. However, the Google Mobile Ads SDK may access or process advertising/device identifiers where available and permitted.
Our Firebase Analytics configuration is intended to keep Firebase Analytics advertising-ID collection and default ad-personalization signals disabled where those configuration flags are present. This does not mean that AdMob itself performs no advertising-related data processing.
Google's handling of advertising data is governed by its own policies and privacy disclosures, including the Google Privacy Policy and Google advertising technologies disclosures.
4. Consent Management / CMP
Advertising and analytics consent requirements vary by region.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, Google requires AdMob publishers serving personalized ads to use a Google-certified Consent Management Platform (CMP) that integrates with the IAB Transparency and Consent Framework (TCF). Where consent is legally required, advertising or analytics processing that depends on consent should occur only after an appropriate consent choice has been obtained.
HabitLoop may use Google User Messaging Platform (UMP) or another Google-certified CMP to present privacy choices where required. The exact consent flow must match the version of the Application distributed to users.
Where available, users may be given choices regarding:
- Personalized advertising.
- Non-personalized or limited advertising.
- Advertising storage and related consent signals.
- Analytics collection.
- Withdrawal or modification of previously provided consent.
Where personalized advertising requires consent, HabitLoop will rely on the consent status made available through the applicable Google-certified consent flow or other legally compliant mechanism. If consent is not available or is declined, advertising may be limited or non-personalized depending on region, device settings, and Google configuration.
Where a privacy-choices page is provided, it should be linked here:
Privacy Choices: Contact privacy@habitloop.uatixsystems.com
5. AI Features
HabitLoop includes an AI Habit Coach designed to provide general organizational, motivational, and productivity guidance.
How AI Processing Works
- Prompt Submission: When you submit a prompt, the text is sent to a protected Supabase Edge Function over HTTPS/TLS.
- Authentication and Entitlement Checks: The backend may verify your authenticated session and check usage limits or premium entitlement.
- Third-Party AI Processing: The backend forwards the prompt to Groq for AI inference. HabitLoop's provider credentials are stored on the backend and are not intentionally exposed in the mobile application.
- HabitLoop-Side Temporary Processing: The raw prompt is not intentionally stored in the primary habit database. A request hash and generated response may be retained for up to 24 hours for idempotency, retry handling, and prevention of duplicate quota consumption.
- Groq Processing: Groq states that inference customer data is not retained by default, but inputs and outputs may be temporarily logged for platform reliability or abuse investigation for up to 30 days unless applicable data controls, such as Zero Data Retention, are enabled. Groq also states that it does not use customer inputs or outputs to train or fine-tune models unless the customer gives permission or instruction.
Important AI Limitations
- AI outputs may be inaccurate, incomplete, inappropriate, or misleading.
- AI outputs are not medical, psychological, mental-health, legal, financial, or other professional advice.
- Do not submit unnecessary sensitive personal information, government identifiers, payment-card information, health records, passwords, confidential business information, or other information you do not want processed by an AI provider.
- You are responsible for reviewing AI-generated content before relying on or acting on it.
- AI providers, models, and technical configurations may change over time. If a material change affects how personal information is processed, we will update this Privacy Policy as appropriate.
6. Payments and Subscriptions
HabitLoop may offer optional premium features, including expanded AI Habit Coach access, through in-app subscriptions.
Payment Processing
On Android, purchases and subscriptions are processed through Google Play Billing. If HabitLoop later offers purchases through another platform's authorized in-app purchase system, that platform's payment terms and privacy practices will apply.
HabitLoop does not intentionally receive or store your full payment-card number, bank account number, CVV/security code, or other full payment credentials. Those details are handled by the applicable app-store or payment platform.
Transaction Information Received by HabitLoop
To validate purchases and provide premium access, HabitLoop may receive and process transaction-related metadata such as:
- Subscription or product identifier.
- Purchase token or transaction identifier.
- Cryptographic hash associated with a purchase token and user account.
- Purchase or entitlement status.
- Subscription expiration or renewal-related status made available by the platform.
- Technical verification results.
Our backend validates Google Play purchases using Supabase Edge Functions and stores only the transaction/entitlement information needed to maintain premium access, prevent fraud, and support account functionality.
The app-store provider may retain additional billing records independently under its own legal obligations and privacy policy.
7. Firebase Services
We use select Google Firebase services to maintain app reliability, deliver notifications, and understand app usage. HabitLoop does not use Firebase Authentication, Cloud Firestore, Firebase Storage, or Firebase Realtime Database.
Firebase Cloud Messaging (FCM)
- Purpose: Delivers push notifications and habit reminders to your device.
- Data Processed: FCM device registration tokens, message delivery statuses, and notification payload titles/bodies.
- Storage: Push notification history and device tokens associated with authenticated users are stored in our Supabase PostgreSQL database.
Firebase Crashlytics
- Purpose: Identifies application crashes, memory errors, and technical instability to help us improve app performance.
- Data Processed: Stack traces, app state at the time of crash, device model, operating system version, and system diagnostic logs.
- Activation: Crash reporting runs only in release builds and only when Diagnostics & analytics is enabled in app settings.
Firebase Analytics
- Purpose: Helps us understand how users interact with the app so we can improve features and UX.
- Data Processed: App launch events, screen views, feature interactions, and performance metrics.
- Privacy Controls: Android Advertising ID collection (
google_analytics_adid_collection_enabled) and ad personalization signals are disabled for Firebase Analytics in our manifest. Analytics collection can be toggled off at any time under Settings > Diagnostics & analytics.
8. Supabase Backend Services
Our primary cloud backend and database infrastructure is hosted by Supabase.
Backend Features Utilized
- Authentication: Manages user accounts, email/password credentials, and Google OAuth sessions.
- PostgreSQL Database: Synchronizes habit definitions, schedules, daily completion progress (
yyyy-MM-dd), archived items, notification records, and subscription entitlements. - Row Level Security (RLS): Enforces strict database policies ensuring that authenticated users can only view, modify, or delete their own data rows.
- Edge Functions: Serverless TypeScript functions (
generate-ai-response,verify-google-play-purchase,play-billing-webhook,delete-account) that process business logic, AI requests, purchase validation, and account deletion securely.
All communications between the Application and Supabase infrastructure are encrypted in transit using HTTPS/TLS.
9. Authentication & Guest Mode
HabitLoop supports two usage modes: Signed-In Account Mode and Local Guest Mode.
Signed-In Accounts
You can register or log in using:
- Email and Password: Managed via Supabase Auth. Passwords are hashed and stored securely by Supabase.
- Google Sign-In: Authenticated via Google OAuth. We receive your email address, display name, user ID, and optional profile image URL.
Authentication tokens (access and refresh tokens) are stored on your device using platform-backed secure storage (FlutterSecureStorage utilizing Android Keystore or iOS Keychain).
Guest Mode
If you choose to use HabitLoop without creating an account:
- All habits, completion history, notification records, and settings remain stored locally on your device inside private app storage (
Hive). - A random, locally generated guest scope identifier (e.g.,
guest_...) isolates local guest data. This scope identifier is strictly internal to your device and is not linked to any user identity or advertising system. - If you later decide to create an account or sign in, you may choose to merge your local guest habits into your new authenticated account.
10. Notifications
HabitLoop provides habit reminder notifications to help you stay on track.
Types of Notifications
- Local Notifications: Scheduled directly on your device using
flutter_local_notifications. They execute locally based on your configured reminder times without sending data to external servers. - Push Notifications: Sent via Firebase Cloud Messaging (FCM) for system updates or cloud-based notification delivery.
Managing Notifications
You can enable or disable notification permissions at any time through:
- App settings: Settings > Notifications.
- System settings: Your device's system settings under Apps > HabitLoop > Notifications.
11. Local Storage and Cookies
The mobile Application does not use traditional web cookies. Instead, we use secure on-device local storage mechanisms:
- FlutterSecureStorage (Android Keystore / iOS Keychain): Holds encrypted session tokens to keep you logged in securely.
- Hive Database: Stores application-private caches for habits, schedules, completion history, notification history, and app preferences.
- SharedPreferences: Used for basic platform preferences and legacy session migration metadata.
Local sandbox data is protected by operating system application isolation rules. Device backup (allowBackup="false") is explicitly disabled in our Android configuration to prevent unauthorized copying of local app data.
12. How We Use Information
We use the information we collect for the following specific purposes:
- Core Service Delivery: To create, display, calculate, and synchronize your habits, schedules, streaks, and completion rates.
- User Authentication: To verify your identity, secure your account, and maintain your active session across launches.
- Cloud Synchronization: To back up and synchronize your habit data across devices when logged into a Supabase account.
- Notification Delivery: To schedule and display local habit reminders and push notifications.
- AI Assistance: To process your prompts and generate supportive habit-coaching responses.
- Subscription Management: To verify in-app purchases, maintain premium access, and fulfill digital features.
- Advertising: To serve banner advertisements on supported builds and support app maintenance.
- Diagnostics & App Improvement: To detect crashes, diagnose bugs, measure feature usage, and enhance user experience (when enabled).
- Customer Support & Communication: To respond to your support requests, account inquiries, or deletion requests.
- Security & Legal Compliance: To prevent fraud, enforce our Terms and Conditions, protect system integrity, and comply with applicable laws.
We do not use your habit history or personal content for marketing or sell it to third parties.
13. Legal Bases for Processing (GDPR / UK GDPR)
If the GDPR or UK GDPR applies to our processing of your personal data, we rely on one or more lawful bases depending on the purpose and circumstances:
- Performance of a Contract: Where processing is necessary to create and manage your account, provide cloud synchronization, deliver requested app functionality, process subscription entitlements, or otherwise perform our Terms and Conditions.
- Consent: Where consent is required, including for certain analytics, advertising, device-storage, or similar processing. You may withdraw consent at any time, although withdrawal does not affect processing that was lawful before withdrawal.
- Legitimate Interests: Where necessary for proportionate interests such as securing the Service, preventing fraud and abuse, maintaining reliability, responding to support requests, and improving the Service, provided those interests are not overridden by your rights and interests.
- Legal Obligation: Where processing is necessary to comply with applicable law, lawful requests, tax/accounting obligations, or regulatory requirements.
- Vital Interests or Other Lawful Bases: In limited circumstances, another lawful basis recognized by applicable law may apply.
Where ePrivacy or similar rules require consent for storing or accessing information on a user's device, we rely on consent unless an applicable exemption permits the activity without consent.
14. How Information Is Shared
We do not sell your habit history or personal content for money. We disclose or make information available to third parties only as described in this Privacy Policy and as reasonably necessary to operate, secure, monetize, or comply with legal obligations relating to the Service.
Service Providers and Platforms
Depending on the features you use, information may be processed by:
- Supabase: Authentication, database storage, synchronization, and Edge Functions.
- Google Firebase: Push notification delivery, crash reporting, and analytics where enabled.
- Google AdMob: Advertising delivery, measurement, fraud prevention, and related advertising processing.
- Groq: Processing AI Habit Coach prompts and responses.
- Google Play: App distribution, billing, subscription management, and transaction verification.
These providers process information under their own terms, privacy notices, contractual arrangements, and applicable law.
Other Disclosure Circumstances
We may also disclose information:
- To comply with law, legal process, court orders, or lawful government requests.
- To investigate fraud, abuse, security incidents, or violations of our Terms.
- To protect the rights, safety, property, and security of users, the public, the Service, or our company.
- In connection with a merger, acquisition, financing, reorganization, asset sale, insolvency, or similar corporate transaction, subject to applicable law.
U.S. Advertising Terminology
We do not sell personal information for monetary consideration. However, depending on how advertising is configured and how a particular U.S. state law defines "sale," "sharing," or "targeted advertising," disclosure of certain identifiers or device information to advertising technology providers for cross-context or personalized advertising may be treated as a regulated sale, sharing, or targeted-advertising activity. Where applicable, we will honor legally required opt-out rights.
15. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, taking into account the nature of the information, operational requirements, security needs, legal obligations, dispute-resolution needs, and applicable limitation periods.
- Account and Habit Data: Generally retained while your account remains active and removed from our primary application database when your account is deleted, subject to the limited retention exceptions below.
- Archived Habits: Remain associated with your account to preserve history until deleted through available app functionality or until account deletion.
- Guest Data: Stored locally on your device until you clear the application's local data, remove the guest data through available controls, or uninstall the app, subject to operating-system behavior.
- AI Idempotency Data: Request hashes and generated responses may be retained for up to 24 hours for retry/idempotency purposes.
- Groq AI Data: Groq states that inference data is not retained by default, but temporary logs may be kept for up to 30 days for reliability or abuse investigation unless Zero Data Retention or another applicable control is enabled.
- Subscription and Transaction Records: Retained as necessary to maintain entitlement, prevent fraud, resolve billing disputes, and satisfy accounting, tax, or legal requirements. App stores may independently retain their own transaction records.
- Analytics Data: Retention depends on the configured Google Analytics/Firebase Analytics property settings. Google Analytics 4 provides configurable retention periods for certain user-level and event-level data; we do not promise a fixed period here unless our production configuration is verified.
- Crash and Technical Logs: Retained for a period reasonably necessary to diagnose reliability or security issues and according to the relevant provider's configured retention controls.
Retention After Account Deletion
Deletion of your HabitLoop account is intended to remove personal data controlled by HabitLoop that is associated with the account from active application systems. We may retain limited information where reasonably necessary and legally permitted for purposes such as:
- Fraud and abuse prevention.
- Security incident investigation.
- Compliance with tax, accounting, legal, or regulatory obligations.
- Establishing, exercising, or defending legal claims.
- Enforcing transaction, refund, or chargeback records.
- Backup or disaster-recovery systems for a limited period until normal backup rotation removes the data.
Where data must be retained, it will be limited to what is reasonably necessary for the applicable purpose and will not be kept longer than required.
16. Account Deletion
You may request permanent deletion of your HabitLoop account and the personal data associated with it.
In-App Account Deletion
You can delete your account in the app:
- Open HabitLoop and sign in.
- Navigate to Profile > Edit Profile.
- Select Delete Account.
- Complete any reasonable re-authentication or confirmation step required to protect the account from unauthorized deletion.
The deletion workflow is intended to remove the Supabase Authentication account and associated application data controlled by HabitLoop, including habit data, schedules, completion records, notification/device-token records, and account-specific entitlement data, subject to the retention exceptions described in Section 15.
The application should also clear account-specific local session data and cancel locally scheduled reminders associated with the deleted account where technically applicable.
External Account Deletion
If you no longer have access to the app, you can initiate an account-deletion request through our external deletion resource:
- Account Deletion Page: https://habitloop.uatixsystems.com/delete-account.html">https://habitloop.uatixsystems.com/delete-account.html
- Support Email: support@habitloop.uatixsystems.com
The external deletion page must remain publicly accessible and clearly identify HabitLoop. We may take reasonable steps to verify that the requester controls the account before completing deletion.
If a manual verification process is required, we will process verified requests within the period required by applicable law and will inform you if additional time is reasonably necessary.
Subscription Reminder
Deleting your HabitLoop account or uninstalling the application does not necessarily cancel an active app-store subscription. If you have a paid subscription, cancel it through the applicable app-store subscription-management controls to avoid future renewal charges.
17. User Rights
Depending on your location and applicable law, you may have some or all of the following rights:
- Access: Request confirmation of whether we process your personal data and obtain access to applicable data.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of personal information, subject to lawful exceptions.
- Restriction: Request restriction of certain processing where provided by law.
- Objection: Object to certain processing, including processing based on legitimate interests where applicable.
- Portability: Receive certain personal data in a structured, commonly used, machine-readable format where the right applies.
- Withdraw Consent: Withdraw consent for consent-based processing.
- Advertising Opt-Out: Opt out of sale, sharing, or targeted advertising where applicable law provides such a right.
- Appeal: Appeal a privacy-rights decision where applicable U.S. state law provides an appeal right.
- Non-Discrimination: Exercise applicable privacy rights without unlawful discrimination or retaliation.
- Complaint: Lodge a complaint with an appropriate privacy or data-protection regulator.
To exercise a right, use available in-app privacy controls, contact privacy@habitloop.uatixsystems.com.
We may need to verify your identity before fulfilling certain requests. Rights are not absolute and may be subject to exceptions under applicable law.
18. EEA / UK Users
If you are located in the European Economic Area or the United Kingdom and applicable data-protection law applies:
- Controller: Uatixsystems is the controller of personal data processed for HabitLoop's own purposes.
- Lawful Bases: The lawful bases used for processing are described in Section 13.
- Consent: Where processing depends on consent, you may withdraw consent at any time.
- Supervisory Authority: You may lodge a complaint with the data-protection authority responsible for your country or region.
- International Transfers: Personal data may be processed outside the EEA/UK. Where a restricted transfer requires safeguards, we and/or our service providers may rely on lawful transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, or other mechanisms permitted by applicable law.
Nothing in this section limits any rights that cannot lawfully be waived.
19. California / U.S. State Privacy Rights
Residents of California and certain other U.S. states may have additional rights where the relevant privacy law applies to Uatixsystems.
Depending on the applicable law, these rights may include:
- The right to know or access categories and specific pieces of personal information.
- The right to correct inaccurate personal information.
- The right to request deletion, subject to statutory exceptions.
- The right to obtain a portable copy of certain information.
- The right to opt out of the sale of personal information.
- The right to opt out of "sharing" for cross-context behavioral advertising or targeted advertising.
- The right to limit certain uses or disclosures of sensitive personal information where applicable.
- The right to appeal certain decisions and to exercise rights without unlawful discrimination.
Sale, Sharing, and Targeted Advertising
HabitLoop does not sell your habit history or personal content for money. However, depending on the configuration of AdMob and the definition used by applicable state law, disclosure of device identifiers or advertising-related data for personalized or cross-context behavioral advertising may constitute "sharing," "sale," or "targeted advertising."
Where a legally required opt-out mechanism applies, use:
Privacy Choices / Opt-Out: Contact privacy@habitloop.uatixsystems.com
You may also contact privacy@habitloop.uatixsystems.com.
Because state privacy-law coverage depends on factors such as company size, revenue, data volumes, and jurisdiction, this section does not represent that every listed law necessarily applies to Uatixsystems.
20. International Data Transfers
HabitLoop uses service providers that may process information in countries different from the country where you live. For example, Supabase, Google/Firebase, Google AdMob, Google Play, and Groq may process data through infrastructure located in the United States or other regions.
When applicable law restricts international transfers of personal data, we and/or our service providers are responsible for using a lawful transfer mechanism and appropriate safeguards. Depending on the provider and transfer, those mechanisms may include adequacy decisions, contractual protections such as Standard Contractual Clauses, or another legally recognized mechanism.
We do not claim that every provider or transfer uses the same mechanism. Provider-specific transfer practices are governed by the relevant provider's contracts and privacy documentation.
21. Children's Privacy
HabitLoop is a general productivity and habit-tracking service and is not directed to children under 13.
We do not knowingly seek to collect personal information from children under 13 through an account intended for the general public. If local law requires parental consent for a minor above age 13 to use certain online services or for certain processing activities, the parent or legal guardian is responsible for providing any consent required by law.
If we learn that personal information has been collected from a child in circumstances where valid parental consent was required and was not obtained, we will take reasonable steps to delete the information as required by applicable law.
If you believe a child has provided personal data in violation of this section, contact privacy@habitloop.uatixsystems.com.
Our app-store audience settings and advertising configuration are intended to remain consistent with this children's privacy approach.
22. Security Safeguards
We use reasonable administrative and technical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. Safeguards include:
- HTTPS/TLS for network communications.
- Platform-backed secure storage for authentication/session tokens.
- Supabase Row Level Security (RLS) and account-scoped access controls.
- Operating-system application sandboxing for local data.
- Backend storage of provider credentials rather than intentional exposure of secret API keys in the client application.
- Security and access controls provided by our infrastructure providers.
Security protections can change as the Service evolves, and the effectiveness of any safeguard depends on correct implementation and configuration.
No method of electronic transmission, storage, or security control is completely secure. We therefore cannot guarantee absolute security.
23. Third-Party Services Summary
Our Application integrates the following verified third-party services:
| Provider | Service / SDK | Purpose | Privacy Policy |
|---|---|---|---|
| Supabase Inc. | Supabase Flutter SDK & Edge Functions | Authentication, PostgreSQL Database, Backend Logic | Supabase Privacy Policy |
| Google LLC | Firebase Cloud Messaging (FCM) | Push Notifications | Google Privacy Policy |
| Google LLC | Firebase Crashlytics | Stability & Crash Reporting | Firebase Privacy Terms |
| Google LLC | Firebase Analytics | App Usage Analytics | Google Analytics Terms |
| Google LLC | Google Mobile Ads (AdMob) | Banner Advertisements | Google Ads Privacy |
| Google LLC | Google Play Store / Billing | App Distribution & Purchases | Google Play Terms |
| Groq Inc. | Groq API | AI Language Model Processing | Groq Privacy Policy |
24. Links to External Websites
The Application or related web pages may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of external third-party sites. We encourage you to review the privacy policies of any third-party websites you visit.
25. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the Service, data practices, providers, legal requirements, or operational practices.
When we make changes:
- We will update the Last Updated date at the top of this policy.
- If a change materially affects how we process personal information, we will provide additional notice where required by applicable law, which may include an in-app notice, consent prompt, or other appropriate communication.
- Where applicable law requires new consent, we will seek that consent before relying on it for the relevant processing.
An updated Privacy Policy applies from its stated effective date. Your rights with respect to previously collected information remain subject to applicable law.
26. Contact Us
If you have questions, comments, or privacy requests concerning this Privacy Policy, please contact us:
- Uatixsystems
- Attn: Privacy Officer
- Address: Johar Town, Lahore, Pakistan
- Support Email: support@habitloop.uatixsystems.com
- Privacy Email: privacy@habitloop.uatixsystems.com
- Website: https://habitloop.uatixsystems.com