Skip to content
Habit Protector
How it worksGuidesCompare
English
English한국어日本語DeutschFrançais繁體中文
Get the app

Legal

Privacy Policy

This policy explains what Habit Protector processes, what stays on your device, and the choices available to you.

Effective: October 6, 2026

1. Who this policy covers

Habit Protector is a mindful app-blocking application for Android, Android TV, iPhone, iPad, and Mac, provided by the operator identified on your app-store listing (Vitality Trails on Google Play). This Privacy Policy applies to the Habit Protector app, its optional account-sync features, and this website.

Habit Protector is designed for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children.

2. Information processed on your device

You can use Habit Protector without creating an account. The app keeps the information needed for your local protection plan on your device, including:

  • the apps you select for protection;
  • rule schedules, limits, challenges, and challenge settings;
  • local progress and protected-app usage summaries; and
  • the identifier of the foreground app needed to enforce a rule.

Installed-app names and native package or application identifiers stay on the device. Optional account sync can send opaque selection references, rule settings, and aggregate usage and progress as described below; it does not upload your installed-app catalog.

Android Accessibility Service

Habit Protector uses Android's Accessibility Service only to identify when a protected app is in the foreground and to present the relevant protection challenge. It reads application identifiers from window events or window metadata for local rule matching, not messages, passwords, typed text, or page text. It does not record the screen or perform touch gestures on your behalf. On Android TV, the optional whole-screen protection mode can show a branded gate over apps, Home, and Settings, handle remote-control keys, return to Home, and send media-control commands to enforce the session you configured.

Usage Access measures protected-app time for your limits. Foreground services and ongoing notifications keep user-started protection, movement tracking, and habit timers running; optional audio guidance can continue while a habit is active. Exact alarms apply your scheduled protection boundaries. These accesses support the features you choose. Accessibility can be disabled in Android settings at any time. Optional Android TV guest credentials and guest-session state stay on that TV, and guest viewing is excluded from the owner's progress.

Apple Screen Time and Mac protection

On iPhone and iPad, Screen Time authorization lets the app apply your protection rules. Apple's private app-selection tokens remain in the local App Group shared with the protection extensions. Account sync uses selection references and counts, not a catalog of app names. On Mac, the app observes the foreground application to apply local rules while Habit Protector is running; it does not read window text.

Movement, Health Connect, and Apple Health

Movement habits use device motion or step activity to verify progress. When you choose the optional workout habit, the app requests read-only access to completed exercise sessions in Health Connect on Android or completed workouts in Apple Health on iPhone. On Android, it requests only the exercise-read permission, not heart rate, routes, workout write access, background health reads, or extended health history.

Exercise session identifiers, start and end times, and active duration are processed locally to check workouts within your current protection window and avoid double-counting. The Android check excludes manually entered sessions and pause or rest segments. Raw workout records are processed transiently on your device and are not uploaded to our cloud. Verified duration and habit completion are kept as habit progress. If you enable optional account sync, aggregated workout and movement progress can be sent to Firebase and associated with your account to coordinate the habits and protection you request across your devices.

Health and movement data are not used for advertising, sold, or shared with data brokers. You can decline workout access and use another habit, revoke exercise access in Health Connect on Android, or revoke Health and Motion & Fitness access in Apple settings. Revoking access stops future reads; it does not automatically delete previously synced progress. Use the account-deletion options below to request removal of account data. These features support general wellbeing and do not provide medical diagnosis or treatment.

3. Information collected when online features are used

Technical information and purchase-service identifiers may be processed even when you use the app without an account. Account sync is optional. Depending on the features you use, we may process:

  • Technical information: app version, operating-system information, device or installation identifiers, network metadata, country or region, language and time zone used by remote configuration, security attestation results, and limited diagnostic information. The app does not request GPS or precise-location access.
  • Crash reports: new app releases use Firebase Crashlytics by default, including when you use the app without an account. Reports include technical error types, stack traces, app version, operating system, device information and installation/session identifiers and technical foreground/background session timing generated by the SDK. Reports may include active Remote Config rollout metadata. We use these reports to find and fix failures. We do not attach your account ID, email, selected apps, rule names or habit answers, and we do not enable Analytics breadcrumbs. Dart error messages and context are filtered before reporting; native crash reports can contain exception details collected by the SDK.
  • Purchase information: product, entitlement, and subscription status supplied by Google Play, the Apple App Store, and RevenueCat. We do not receive your full payment-card number.
  • Optional account information: your email address, a profile name if supplied by your sign-in provider, Firebase user identifier, synced rules, device records, progress, messaging token, and supported usage summaries when you create an account and enable sync.
  • Support communications: information you choose to send when contacting the support channel shown on your app-store listing.
  • Website data: ordinary request data such as IP address, browser type, requested page, and security logs processed by Cloudflare to deliver and protect this website.
Habit Protector contains no advertising SDKs. Current Android, iPhone, iPad and Mac releases deactivate Firebase Analytics at the native SDK level. Earlier internal test versions, including build 110, may initialize Firebase Analytics and process app-instance identifiers, app interaction events, device details, and approximate location inferred from network information.

4. Why we process information

We use information only as reasonably necessary to:

  • provide protection rules, challenges, insights, and optional sync;
  • authenticate accounts and keep them secure;
  • validate purchases and manage Pro access;
  • understand subscription performance through RevenueCat purchase reporting;
  • understand app usage and technical performance in earlier test versions that initialize Firebase Analytics;
  • send service-related notifications you have enabled;
  • detect fraud, abuse, or technical failures;
  • respond to support and legal requests; and
  • operate and protect the public website.

Depending on where you live, these activities rely on performing our agreement with you, your consent, our legitimate interests in providing and securing the service, or compliance with legal obligations.

5. Service providers

We use service providers that process information for the purposes described above:

  • Google Firebase: Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, App Check, Installations, and Remote Config, Crashlytics for technical crash reporting, and Analytics in the earlier test versions described above.
  • Google Play: app distribution, purchases, subscriptions, and store support.
  • RevenueCat: purchase validation and subscription entitlement management using an anonymous or account-linked app user identifier.
  • Apple: App Store distribution and payments, Sign in with Apple, push notifications, and device/app attestation.
  • Cloudflare: hosting, delivery, and security for this website.

These providers may process information in countries other than your own under their own privacy terms and appropriate transfer safeguards. We do not sell or rent personal information.

6. Retention

Local information remains on your device until you remove it, clear app data, or uninstall Habit Protector. Synced information is kept while your account is active and for only as long afterward as necessary for backup, security, dispute, or legal purposes.

When you delete an account in the app, our authenticated deletion flow removes the Firebase account and associated synced Habit Protector data. A technical deletion receipt may remain for up to eight days so the operation can finish reliably and be audited. Apple, Google Play, and RevenueCat may retain transaction records as required for billing, fraud prevention, accounting, and law.

7. Your choices and rights

  • Use the app without an account.
  • Choose which apps and schedules are included in each local rule.
  • Disable Accessibility access or notifications in Android settings.
  • Revoke exercise access in Health Connect on Android.
  • Revoke Screen Time, Health, motion, or notification permissions in Apple settings.
  • Quit the Mac app or disable its optional Start at Login setting.
  • Turn off optional account sync and sign out.
  • Delete your account from Settings → Account sync → Delete account.

Depending on your location, you may also have rights to access, correct, delete, restrict, or receive a copy of personal information, and to object to or withdraw consent for certain processing. To make a request without access to the app, email vortrekdev@gmail.com or follow the account-deletion instructions. We may need to verify that you control the account before acting on a request.

8. Security

We use reasonable technical and organizational safeguards, including authenticated access controls and encrypted network transport. No system can be guaranteed completely secure, so protect your device, Apple or Google account, and sign-in credentials.

9. Changes to this policy

We may update this policy as Habit Protector or applicable requirements change. We will publish the updated version here and revise the effective date. If a change is material, we may provide an additional in-app or store notice when appropriate.

10. Contact

For privacy questions or requests, contact Habit Protector support at vortrekdev@gmail.com.

Habit Protector

A habit before another scroll. App blocking with breathing, movement, reflection, and time for what matters to you.

Find your deviceScreen-time guidesCompare app blockersAboutSupportPrivacy PolicyTerms of UseDelete an accountGoogle Play · Pre-register onApp Store · Coming soon on
© 2026 Habit Protector · Vitality TrailsMade for your habits, across your screens.