Privacy Policy - Rhabit
Choose an app to view its specific privacy policy, or read our general terms below.
Privacy Policy - Rhabit
Last updated: August 25, 2026
1. Information We Collect
In providing our services, the App collects the following information:
1.1 Account Information
- Email address and password (when registering for an account)
- Anonymous (guest) account identifier (when starting to use the app without account registration)
Passwords are securely managed by the authentication infrastructure (Firebase Authentication). In addition, for the purpose of generating a key to encrypt data on the device, passwords are stored exclusively within the device's secure storage. The password itself is never transmitted to our servers or any external services.
Even if you start as a guest account, you can transfer your existing data by registering an account (email address) later.
1.2 App Usage Data (Habits & Record Data)
We collect habit (routine) names, completion logs, consecutive streaks, diary/reflection (journal) entries, water intake logs, challenge progress, earned badges, video watching records, total XP (experience points), and related activity data.
In principle, these data are stored within the database on your device. For registered accounts (non-guest accounts), regardless of whether you are on a free or paid plan, data is automatically synchronized and saved to the cloud (Cloud Firestore) for purposes such as transferring data when changing devices. For guest accounts (prior to account registration), data is stored only on your device and is not transmitted to the cloud. Sensitive items such as diary entries, goals, and gratitude logs are encrypted on the device before being sent to the cloud.
1.3 Audio Data
When you use the voice input feature for diary entries or other features, we request permission to access your microphone and convert your voice to text through the speech recognition service provided by your operating system (Android/iOS). The processing of audio data follows the privacy policy of your device's OS vendor (Google or Apple).
1.4 Information Regarding AI Coaching Features
The App provides AI coaching and chat features. When you use these features, the following information is transmitted to the AI service provider (Anthropic, Google, OpenAI, or OpenRouter, depending on your settings):
- Chat messages entered by the user
- Habit names, recent completion status, and streak records
- Coach interaction settings (tone of voice, reply length, etc.)
- Summaries of past coaching sessions
Diary (journal) contents are included in the transmission to the AI service only if the user explicitly consents. Consent is explicitly obtained via a confirmation dialog within the app and can be turned off at any time in the settings.
The handling of transmitted data is governed by the privacy policy of the respective AI service provider. Please exercise caution when entering sensitive information.
For free plans, the App adopts a Bring Your Own Key (BYOK) model where users register their own API keys (Anthropic/Google/OpenAI). In this case, chat and related requests are sent directly from the user's device to the respective service. API keys are saved only on the device and excluded from cloud synchronization.
1.5 Inquiries and Feedback Information
Information submitted through the in-app feedback form (content text, optional email address), along with app version and OS type, is received by us via a form management service (Formspree).
1.6 Payment Information
Purchases of paid plans (subscriptions) are processed through App Store / Google Play in-app purchases and a purchase management service (RevenueCat). We do not directly collect payment information such as credit card numbers. RevenueCat receives transaction details such as purchase content and subscription status.
1.7 Usage and Device Information
To improve our service, we collect statistical information regarding feature usage (onboarding completion, habit additions, paid plan screen views, purchase completions, feedback submissions, etc.) using Firebase Analytics. In addition, to improve app quality, we collect error logs and device information at the time of crashes or errors using Firebase Crashlytics.
For residents in EU/EEA member states and the UK, the above collection will only commence if you select "Agree" on the consent dialog displayed at initial launch. If you do not consent, this collection will not occur. You can change your consent status at any time from "Privacy" in the settings screen. In other regions, collection for quality improvement will occur unless you opt out in the settings.
2. Purpose of Use
- To provide the features of the App (habit management, record synchronization, AI coaching, etc.)
- For user authentication and account management
- For providing paid plans and payment management
- To respond to inquiries and feedback
- For detecting and fixing bugs, and maintaining/improving service quality
- For feature improvements through analysis of usage status
3. Provision & Entrustment to Third Parties
Except as required by law, we will not provide personal information to third parties without your consent. However, in providing the App, we utilize the following external services, and data is transmitted to these providers to the extent necessary:
| Service | Purpose | Main Data Transmitted |
|---|---|---|
| Firebase Authentication(Google) | Authentication | Email address, account identifier |
| Cloud Firestore(Google) | Cloud synchronization (Registered users only; free & paid plans) | Habit data, encrypted diary data, etc. |
| Firebase Analytics(Google) | Usage analysis | Feature usage events, device info |
| Firebase Crashlytics(Google) | Crash analysis | Error logs, device info |
| RevenueCat | Billing & subscription management | Purchase & contract status |
| Anthropic / Google(Gemini)/ OpenAI / OpenRouter | AI coaching feature | Chat content, habit data, (if consented) diary content |
| Formspree | Inquiry form processing | Feedback text, email address (optional) |
4. Data Retention Period
- When an account deletion is performed, corresponding data on the cloud (Firestore data, authentication account) and data on the device are deleted.
- Raw chat logs (individual messages) of AI coaching are stored on the device for 30 days after session summaries are generated, after which they are automatically deleted.
- AI coaching session summaries, similar to diary records, remain stored on the device until deleted by the user or until the account is deleted (not subject to automatic deletion).
- Other record data (habits, diary entries, etc.) are retained until deleted by the user or until the account is deleted.
5. Information Security
When synchronizing sensitive data such as diaries to the cloud, data is encrypted on the device using a user-specific key before transmission. All communications take place over encrypted channels (HTTPS).
Session summaries of the AI coaching feature are encrypted on the device using a user-specific key and saved locally (not sent to the cloud). On the other hand, raw chat logs (individual messages) are temporarily stored unencrypted in the local database and automatically deleted 30 days after summary generation. For guest accounts or users logged in with a Google account where no user password exists as an encryption key, data on the device (including summaries) is not encrypted.
6. Use by Minors
The App does not feature age verification and is not intended for children under 13 years of age. If it is discovered that a child under 13 is using the App, we will endeavor to promptly delete related information. Minors aged 13 to 17 should use the App with parental consent. In regions with higher consent age standards (such as GDPR's 16 years), those standards take precedence.
7. User Rights
- Confirmation and correction of registered personal information
- Deletion of account and associated data
- Revocation of consent for diary sharing in AI coaching features
- Modification of notification settings
8. Cookies and Related Technologies
As a mobile application, the App does not use cookies, but measurement using device identifiers or similar data may be performed via Firebase Analytics and related services.
9. International Data Transfers & Governing Law
The App may be offered outside Japan, and data may be transferred to and stored in the United States or other countries via cloud provider servers. Depending on your region, additional rights under GDPR/UK GDPR or CCPA/CPRA may be granted (we do not sell personal information).
10. Disclaimer
- We do not guarantee against data loss or corruption caused by natural disasters, communication failures, cloud provider outages, etc.
- We assume no responsibility for data loss confined to the device due to device loss, damage, formatting, etc.
- Upon termination of the service, access to cloud data may become unavailable or deleted; while we strive to provide advance notice, users are advised to maintain their own backups.
- Except in cases of intentional misconduct or gross negligence, we are not liable for damages.
11. Changes to This Policy
This Policy may be updated as necessary. Important changes will be notified via in-app announcements or other appropriate means.