HabitPocket

Privacy Policy

App and website · Last updated: 28 September 2026 · Deutsche Fassung

This is a translation. If the versions differ, the German version prevails.

1. Controller

The controller for the HabitPocket app and the website habitpocket.com is Real Movement Analytics GmbH, Kleines Everstal 18d, 44388 Dortmund, Germany. Contact: info@rm-analytics.de.

2. Local first

HabitPocket works fully without an account. The app stores habits, schedules, reminders, entries, notes, settings and local backups in a database on your device. Without an account we receive none of this content.

The app contains no ads, no analytics or tracking SDKs and no crash reporting to third parties. We only see aggregated usage numbers from App Store Connect and the Google Play Console.

Local storage is required for the features you ask for (Section 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR). The data stays until you delete it in the app or uninstall the app. Your device's system backups (iCloud or Google) may contain copies depending on your device settings; Apple or Google manage these backups, not us.

You decide which habits you create. If you track habits related to health (e.g. "take medication"), they may allow conclusions about your health. We do not analyse content.

3. Update check

When the app starts or returns to the foreground, it asks our server – also without an account – whether your app version is still supported. It sends the platform (iOS/Android), app and API version and, for technical reasons, your IP address. No habit content or identifiers are sent. The purpose is to tell outdated versions in time that an update is needed (Art. 6(1)(f) GDPR). We do not store these requests in our database; for logging by Cloudflare see Section 10.

4. Reminders, widgets and app lock

Reminders are scheduled as local notifications on your device; for this the app asks for notification permission. Widgets read a local copy of today's habits. The app lock uses Face ID, Touch ID or your device's biometrics through the operating system – we never receive biometric data.

5. Apple Health and Health Connect

If you enable it for a habit, the app reads selected values from Apple Health or Health Connect: steps, distance, active minutes, workout minutes or sleep duration. This only happens while the app is open and only on your device. Individual measurements (raw data) are never sent to us. From them, the app stores one daily value as a habit entry (e.g. "8,000 steps on 28 Sep").

You grant read access through the operating system's permission prompt and can revoke it there at any time (Art. 6(1)(a), Art. 9(2)(a) GDPR).

Syncing these values: If you use sync (Section 7) and at least one habit is linked to Health, the app asks once whether the daily values taken over may be synced with your account and included in cloud backups. They only leave your device with this explicit consent (Art. 9(2)(a) GDPR); without it they stay local and everything else still syncs. You can withdraw consent at any time under Settings › Account › "Sync Health values". Use "Delete cloud data" (Section 8) to delete values already transferred.

Values from Apple Health or Health Connect are not used for advertising, not sold and not shared with third parties.

6. Purchases (Pro)

Apple (App Store) and Google (Google Play) handle purchases and subscriptions under their own privacy policies and are responsible for that processing. We never receive bank or card details.

If you are signed in, the app passes a pseudonymous account identifier to Apple or Google at purchase so the purchase can be linked to your HabitPocket account. Our server verifies the purchase: we process the store-signed transaction data or purchase token, transaction identifiers, the product ID, purchase and expiry time and the subscription status. Apple and Google notify our server about renewals, cancellations and refunds. Without an account, the purchase stays with your store account and is not stored by us. The legal basis is Art. 6(1)(b) GDPR and, for abuse prevention (e.g. one purchase not being linked to several accounts), Art. 6(1)(f) GDPR.

7. Account, sync and cloud backups (optional)

An account is optional and only needed for sync and cloud backups. You sign in with Apple or Google; there is no password. We process:

The legal basis is Art. 6(1)(b) GDPR (providing sync and backups) and Art. 6(1)(f) GDPR (secure operation, abuse prevention). Section 5 applies to Health daily values.

8. Retention and deletion

For technical reasons, the databases of our hosting provider Cloudflare keep a recovery history of up to 30 days; deleted data disappears from it after this period at the latest.

9. Deleting your account

You can delete your account in the app under Settings › Account › Delete account or at habitpocket.com/konto-loeschen. For requests via the web form we store the email address and time you provide to find your account and confirm the deletion; we delete both once the request is completed.

10. Hosting and website

The website and our server run on Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (Cloudflare Pages, Workers, D1, Durable Objects, R2). For every request to the website or our server, Cloudflare processes the IP address and technical request data (time, address, browser or app information, status) to deliver content and protect the service against disruption and abuse (Art. 6(1)(f) GDPR). For troubleshooting we keep logs of server requests at Cloudflare for at most 7 days.

The website sets no cookies and uses no analytics. Fonts and images are loaded from our own server. If you choose light or dark mode on the website, your browser stores this choice in local storage (key hp-theme) until you reset it or clear your browser data. This is required for the feature you asked for (Section 25(2) no. 2 TDDDG); nothing is sent to us.

11. Contact by email

If you write to us, we process your address and the content to answer your request (Art. 6(1)(b) or (f) GDPR). Emails are stored by Microsoft 365 (Section 12) on our behalf. The message is deleted once it is no longer needed for follow-up questions, legal defence or statutory retention duties. If you send diagnostic information from the app, you decide what it contains.

12. Recipients and transfers to third countries

You can request a copy of the safeguards via our contact address.

13. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and to withdraw consent with effect for the future. Where we process data based on legitimate interests, you can object on grounds relating to your particular situation. You can export your data yourself in the app at any time (JSON or CSV).

You can lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).

There is no automated decision-making or profiling. Providing data is not required by law; without an account, sync and cloud backups are not available.