Privacy Policy

Last updated: April 16, 2026

1. Introduction

Habit Runner ("we", "our", or "us") operates the Habit Runner habit tracker application available at habit-runner.freeddns.org. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

2. Data We Collect

2.1 Application Storage

The PWA may cache its application shell on your device so repeat visits can load quickly. Habit data and check-in history are stored on our servers for your signed-in account and require a network connection to read or change.

2.2 Google OAuth

When you sign in with Google, we receive your Google Account ID, email address, and display name. We use this to identify your account for authenticated API access. We do not access your Google Drive, Gmail, contacts, or any other Google service data.

2.3 Account Data

When you sign in, your habit records and check-in history are transmitted to and stored on our servers over HTTPS using JWT authentication so they can be loaded on your signed-in devices. No financial information is collected or stored.

2.4 Telegram Mini App

If you open Habit Runner in Telegram, we receive the Telegram user identifier and the public profile fields Telegram includes in Mini App initialization data. The server verifies Telegram's signed data before creating a session. If you link Telegram and email sign-in, these identifiers are associated with the same account so your habits and check-ins remain available from both entry points. We do not receive your Telegram chats, contacts, or messages.

2.5 Push Notifications

If you enable push notifications, we store a browser push subscription endpoint. This is used only to deliver habit reminders you configure. You can revoke this permission at any time from your browser settings.

3. How We Use Your Data

  • To provide the habit tracking and streak analytics service.
  • To sync your data across devices when you sign in.
  • To send push notification reminders you configure.
  • To maintain your session via JWT access and refresh tokens.

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as required to operate the service (e.g., our hosting provider).

4. Data Retention

Cached application assets persist on your device until you clear your browser data or uninstall the app. Account data on our servers is retained while your account is active. You may request deletion of your account and associated server-side data by contacting us.

5. Cookies and Tokens

Habit Runner uses browser localStorage to store authentication tokens (JWT access token and refresh token). We do not use third-party tracking cookies or advertising cookies.

6. Your Rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to processing or request restriction of processing.
  • Data portability.

To exercise any of these rights, contact us through our GitHub profile.

7. Security

We use HTTPS for all data transmission. Authentication uses short-lived JWT access tokens and longer-lived refresh tokens. We do not store plaintext passwords.

8. Changes to This Policy

We may update this Privacy Policy. Changes will be posted on this page with an updated date. Continued use of the service constitutes acceptance of the updated policy.

9. Contact

For privacy-related questions or requests, contact us through our GitHub profile.