Legal
Privacy Policy
Last updated August 14, 2026.
habits.chat is at the waitlist stage. Today this site collects one thing: the details you type into the early access form. This policy describes both that, and how habit data will be handled once accounts open, so you can decide now rather than after you've logged six months of it.
What we collect today
- Your email address, which is the only required field.
- The optional answers you give — the habit you're working on, whether you're building or breaking, what you use today, which AI assistant you use, and anything you write in the free-text box.
- Basic attribution: the page you signed up from, the referring URL, and any campaign parameters in the link you followed.
We do not use advertising trackers, and we do not set cookies to follow you around.
Page analytics
We use Tinylytics to count page views, so we know which pages are worth writing more of. It's a deliberately small, privacy-focused tool, and what it sends is limited to:
- the URL and path of the page you're on;
- the referring URL, if you arrived from another site.
It sets no cookies, assigns you no identifier, does not follow you
between sites, and does not build a profile of you. There is no
cross-site tracking to opt out of because there is none to begin with.
If you'd still rather not be counted, add ?analytics=off to
any URL on this site and this browser will stop being counted;
?analytics=on reverses it. That preference is remembered in
a cookie, which is the one cookie we set that isn't strictly required to
make a page work.
What we use it for
- Emailing you when early access opens, and occasional notes about progress.
- Deciding what to build first — the free-text answers and the assistant question genuinely drive the roadmap.
- Understanding which pages bring people in, so we know what to write more of.
We do not sell this information, share it with advertisers, or use it to build a profile of you anywhere else.
Habit data, once accounts open
Habit data is unusually personal. What someone is trying to quit, when they slip, how badly they slept — this is health-adjacent information, and it should be treated that way. Our commitments:
- It isn't used to train models. Not ours, and not a third party's. Your check-ins are yours.
- It isn't sold or shared with advertisers, data brokers or anyone else, and it isn't aggregated into a product.
- You can export all of it at any time, on every plan including the free one, in a format you can actually open.
- You can delete all of it, and deletion means deletion — removed from live systems immediately and from backups within 30 days.
Health-adjacent data
Some of what people track here — symptoms, reactions, medication changes, a child's diagnosis-adjacent behavior — is health information in everything but name, even though we are not a healthcare provider and this is not a medical record. We treat it as the most sensitive category of data on the service: it isn't used to train models, isn't sold, isn't shared, and is exportable and deletable on request like everything else.
It is not, however, held to any clinical record-keeping standard, and it is not covered by health-specific regimes such as HIPAA. If you need a record that meets a formal standard, this isn't it — keep the authoritative version wherever your clinician keeps theirs.
Tracking for someone else, including a child
A lot of people use a tracker like this to record what's happening for someone they care for — most often their own child. That means the record contains personal information about a person who isn't the account holder, and often about a child, so it's worth being explicit:
- The account, and the record in it, belongs to the adult who created it. There is no separate account for the person being tracked.
- It is not shared with a school, a clinician, a local authority or anyone else. Nothing leaves the account unless you export it and send it somewhere yourself.
- The same commitments apply as to any other habit data: not used to train models, not sold, exportable and deletable at any time.
- Only record what you'd be comfortable holding. This is a notebook, not a clinical record system, and it isn't built to meet any clinical record-keeping standard.
- Where the person being tracked is old enough to have a view about it, we'd encourage you to involve them. That's not a legal requirement we can enforce — it's just the right way round.
Autistic adults tracking their own patterns are covered by everything else in this policy; nothing in this section applies differently to you.
What the AI features send
When you use the chat, your message and the habit data relevant to it are sent to a third-party language model provider so the request can be answered. Some specifics worth stating plainly:
- Only what's needed for the request is sent — the habits and check-ins in scope for what you asked, not your entire history by default.
- Every reply shows which tools were called and with what arguments, so what was involved is visible rather than implied.
- Model providers are used under agreements that prohibit training on data sent through the API.
- The AI features are optional. The app is fully usable without ever opening the chat, and habit data is not sent to a model provider if you don't use it.
Connected assistants (MCP)
If you connect an assistant over MCP, that client can call the tools you've granted it, against the habits you've scoped it to. Data reaching that client is then subject to that vendor's terms, which is precisely why access is read-only by default, scoped per habit, expirable, and revocable at any time. Every call a connected client makes is logged and attributed.
Where it lives and who can see it
Data is stored on servers we control, encrypted in transit and at rest. Access by us is limited to what's needed to operate the service and support you — and we'd rather ask you before looking at anything than treat your habit history as ours to browse.
How long we keep it
Waitlist entries are kept until launch and for a reasonable period after, or until you ask us to remove yours. Account data is kept while the account is open and deleted on request or within 90 days of closure.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it — including removal from the waitlist — by emailing privacy@habits.chat. Every email we send has a one-click unsubscribe. Depending on where you live you may have additional rights under the GDPR, UK GDPR or CCPA; we'll honour them regardless of where you live.
Changes
If this policy changes materially, we'll email everyone on the list or with an account before it takes effect rather than quietly updating the date at the top.
Contact
Questions about any of this: privacy@habits.chat.