Privacy Policy - Rhabit
Choose an app to view its specific privacy policy, or read our general terms below.
Privacy Policy - Rhabit
Last updated: August 25, 2026
1. Information We Collect
In providing our services, the App collects the following information:
1.1 Account Information
- Email address and password (when registering for an account)
- Anonymous (guest) account identifier (when starting to use the app without account registration)
Passwords are securely managed by the authentication infrastructure (Firebase Authentication). In addition, for the purpose of generating a key to encrypt data on the device, passwords are stored exclusively within the device's secure storage. The password itself is never transmitted to our servers or any external services.
Even if you start as a guest account, you can transfer your existing data by registering an account (email address) later.
1.2 App Usage Data (Habits & Record Data)
We collect habit (routine) names, completion logs, consecutive streaks, diary/reflection (journal) entries, water intake logs, challenge progress, earned badges, video watching records, total XP (experience points), and related activity data.
In principle, these data are stored within the database on your device. For registered accounts (non-guest accounts), regardless of whether you are on a free or paid plan, data is automatically synchronized and saved to the cloud (Cloud Firestore) for purposes such as transferring data when changing devices. For guest accounts (prior to account registration), data is stored only on your device and is not transmitted to the cloud. Sensitive items such as diary entries, goals, and gratitude logs are encrypted on the device before being sent to the cloud.
1.3 Audio Data
When you use the voice input feature for diary entries or other features, we request permission to access your microphone and convert your voice to text through the speech recognition service provided by your operating system (Android/iOS). The processing of audio data follows the privacy policy of your device's OS vendor (Google or Apple).
1.4 Information Regarding AI Coaching Features
The App provides AI coaching and chat features. When you use these features, the following information is transmitted to the AI service provider (Anthropic, Google, OpenAI, or OpenRouter, depending on your settings):
- Chat messages entered by the user
- Habit names, recent completion status, and streak records
- Coach interaction settings (tone of voice, reply length, etc.)
- Summaries of past coaching sessions
Diary (journal) contents are included in the transmission to the AI service only if the user explicitly consents. Consent is explicitly obtained via a confirmation dialog within the app and can be turned off at any time in the settings.
The handling of transmitted data is governed by the privacy policy of the respective AI service provider. Please exercise caution when entering sensitive information.
For free plans, the App adopts a Bring Your Own Key (BYOK) model where users register their own API keys (Anthropic/Google/OpenAI). In this case, chat and related requests are sent directly from the user's device to the respective service. API keys are saved only on the device and excluded from cloud synchronization.
1.5 Inquiries and Feedback Information
Information submitted through the in-app feedback form (content text, optional email address), along with app version and OS type, is received by us via a form management service (Formspree).
1.6 Payment Information
Purchases of paid plans (subscriptions) are processed through App Store / Google Play in-app purchases and a purchase management service (RevenueCat). We do not directly collect payment information such as credit card numbers. RevenueCat receives transaction details such as purchase content and subscription status.
1.7 Usage and Device Information
To improve our service, we collect statistical information regarding feature usage (onboarding completion, habit additions, paid plan screen views, purchase completions, feedback submissions, etc.) using Firebase Analytics. In addition, to improve app quality, we collect error logs and device information at the time of crashes or errors using Firebase Crashlytics.
For residents in EU/EEA member states and the UK, the above collection will only commence if you select "Agree" on the consent dialog displayed at initial launch. If you do not consent, this collection will not occur. You can change your consent status at any time from "Privacy" in the settings screen. In other regions, collection for quality improvement will occur unless you opt out in the settings.
2. Purpose of Use
We use the collected information for the following purposes:
- To provide the features of the App (habit management, record synchronization, AI coaching, etc.)
- For user authentication and account management
- For providing paid plans and payment management
- To respond to inquiries and feedback
- For detecting and fixing bugs, and maintaining/improving service quality
- For feature improvements through analysis of usage status
3. Provision & Entrustment to Third Parties
Except as required by law, we will not provide personal information to third parties without your consent. However, in providing the App, we utilize the following external services, and data is transmitted to these providers to the extent necessary. Please also review each provider's privacy policy.
| Service | Purpose | Main Data Transmitted |
|---|---|---|
| Firebase Authentication(Google) | Authentication | Email address, account identifier |
| Cloud Firestore(Google) | Cloud synchronization (Registered users only; free & paid plans) | Habit data, encrypted diary data, etc. |
| Firebase Analytics(Google) | Usage analysis | Feature usage events, device info |
| Firebase Crashlytics(Google) | Crash analysis | Error logs, device info |
| RevenueCat | Billing & subscription management | Purchase & contract status |
| Anthropic / Google(Gemini)/ OpenAI / OpenRouter | AI coaching feature | Chat content, habit data, (if consented) diary content |
| Formspree | Inquiry form processing | Feedback text, email address (optional) |
4. Data Retention Period
- When an account deletion is performed, corresponding data on the cloud (Firestore data, authentication account) and data on the device are deleted.
- Raw chat logs (individual messages) of AI coaching are stored on the device for 30 days after session summaries are generated, after which they are automatically deleted.
- AI coaching session summaries, similar to diary records, remain stored on the device until deleted by the user or until the account is deleted (not subject to automatic deletion). They are displayed alongside diary entries on the calendar of the diary screen.
- Other record data (habits, diary entries, etc.) are retained until deleted by the user or until the account is deleted.
5. Information Security
When synchronizing sensitive data such as diaries to the cloud, data is encrypted on the device using a user-specific key before transmission. All communications take place over encrypted channels (HTTPS). We take necessary and appropriate measures to prevent leakage, loss, or damage of collected information and to ensure safety management.
Session summaries of the AI coaching feature are encrypted on the device using a user-specific key and saved locally (not sent to the cloud). On the other hand, raw chat logs (individual messages) are temporarily stored unencrypted in the local database and automatically deleted 30 days after summary generation (stored within the scope of standard OS app sandbox protection). Please keep this in mind in the event of device loss or theft. For guest accounts or users logged in with a Google account where no user password exists as an encryption key, data on the device (including summaries) is not encrypted.
6. Use by Minors
The App does not feature age verification functions (such as age verification screens). The App is not intended for children under 13 years of age, and we do not intentionally collect personal information from children under 13. If it is discovered that a child under 13 is using the App, we will endeavor to promptly delete information associated with that account. Minors aged 13 to 17 should use the App with parental consent.
Where applicable local laws (such as GDPR's consent age under 16) establish higher age standards, those laws will apply preferentially.
7. Account and Data Deletion / User Rights
7.1 Account and Data Deletion
Users of Rhabit (operated by Unote) can request deletion of their account and associated data through the following steps:
Deletion Steps
- Open the app and tap the person icon (Profile) in the upper right corner of the home screen.
- Scroll to the bottom of the Profile screen and tap "Delete Account" under "Account Actions".
- Review the warning displayed. If registered with an email address, enter your password (not required for Google account or guest users).
- Type "Delete" into the confirmation field.
- Tap "Delete Permanently" to immediately execute the account deletion.
If you have difficulty operating the app, you can contact us at support@unote-app.com with your registered email address, and we will delete it on your behalf upon identity verification.
Data to be Deleted (Permanently deleted upon account deletion execution and cannot be restored)
- Firebase Authentication account info (email address, etc.)
- All record data synchronized to Cloud Firestore such as habits, diary entries, challenge progress, earned badges, XP, coaching summaries, etc.
- Local data stored on the device (habits, diary entries, water intake logs, AI coaching raw chat logs, session summaries, etc.)
Data That May Be Retained and Not Deleted
- Submissions sent via contact/feedback forms (may remain as records on Formspree service)
- Past purchase/transaction history recorded on RevenueCat (may be retained for a period of time under applicable laws as payment provider transaction records)
- Records subject to legal retention obligations (if applicable)
If you also wish to delete these retained data, please contact support@unote-app.com. We will accommodate your request to the extent possible.
7.2 Other Rights
Users can also perform the following through in-app settings or our contact desk:
- Confirmation and correction of registered personal information (email address, etc.)
- Revocation of consent for diary sharing in AI coaching features
- Modification of notification settings
8. Cookies and Related Technologies
As a mobile application, the App does not use cookies in web browsers, but measurement of usage status using device identifiers or similar data may be performed via Firebase Analytics and related services.
9. International Data Transfers & Governing Law
The App may be offered in regions outside Japan. Because user information is processed and stored through servers of cloud service providers used by us (Google Firebase / Google Cloud, RevenueCat, etc.), data may be transferred to and stored in countries or regions outside your residence (such as the United States). We strive to ensure that appropriate protection measures matching the level specified in this Policy are taken at the transfer destination.
Depending on your region of residence, additional rights such as the following may be granted in addition to the contents specified in this Policy:
- EU/EEA & UK (GDPR/UK GDPR): Specification of processing grounds, right to data portability, right to request restriction of processing, right to lodge a complaint with a supervisory authority, etc.
- California, USA (CCPA/CPRA): Right to request disclosure of collected personal information categories, right to opt out of sale/sharing of personal information (we do not sell personal information to third parties), right to request deletion, etc.
- Other Regions: Rights based on data protection laws of respective regions
If you wish to exercise these rights, please contact us at the address provided at the end of this Policy. We will respond within the scope prescribed by law upon identity verification.
10. Disclaimer
- Under no circumstances shall we guarantee against loss, corruption, or temporary unavailability of data stored in the cloud, including natural disasters, communication line failures, outages of cloud service providers (Google Firebase, etc.), or any other causes.
- We assume no responsibility for data recovery if data stored exclusively on the device (such as data excluded from cloud sync or guest account data) is lost due to device loss, failure, formatting, app uninstallation, OS updates, or any other reasons.
- We may terminate the provision of the App upon prior notice. Upon service termination, access to user data stored in the cloud may become unavailable, or data may be deleted. While we endeavor to provide reasonable advance notice where possible, users are advised to maintain their own separate backups of important data at their own responsibility.
- Under no circumstances shall we be liable for any damages arising from the use of the App.
11. Changes to This Policy
We may change the content of this Policy as necessary. When making important changes, we will notify users through appropriate methods such as in-app announcements. The revised Privacy Policy will take effect from the time it is posted on this page.
12. Contact Information
If you have any inquiries regarding this Policy, please contact us at:
Operator: Unote
Contact Email: support@unote-app.com