Privacy Policy

Last updated: 2 September 2026 · Version 2026-09-02-r3

1. Controller

The controller responsible for processing personal data in connection with Don't Break Two is Tim Gabel, trading as HowtoHabit, Lerchenauer Straße 28, 80809 München, Germany. Email: howtohabit.service@gmail.com.

2. Local-first habit data

Core habit data is designed to remain local to the user's device. This can include habit definitions, schedules, completion history, protected-time entries, daily tasks, reminder preferences, Premium habit-plan data, execution levels, sparse friction labels, target-contribution check-ins and locally computed progress or trajectory information. This local data is not automatically uploaded merely because a user creates or signs into an account.

3. Account and authentication data

A user may use the free local habit tracker without an account. An account is required for server-backed Premium and Coach functionality. When an account is created or used, Supabase processes information required for authentication, such as email address, user identifier, authentication state and related security metadata.

Purpose: account creation, authentication, security and provision of account-bound services. Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR) and, where applicable, legitimate interests in account and service security (Art. 6(1)(f) GDPR).

4. Premium purchases and entitlements

For paid products, Don't Break Two processes product identifiers, store source, entitlement status, purchase-verification references, purchase/expiry timestamps where supplied and limited verification metadata needed to confirm access. Payment-card details are handled by Apple or Google and are not processed by the Don't Break Two backend.

5. AI Coach

When AI Coach is used, the user's prompt and a structured subset of relevant habit context and computed analytics are sent to the Don't Break Two backend and then to the configured AI provider to generate a response. The AI-provider API key is held server-side and is not embedded in the mobile app. Coach usage information such as model identifier and token usage may be stored for quota, abuse-prevention and cost-control purposes.

Users should not submit unnecessary sensitive personal data to Coach. Coach is not intended for medical diagnosis, treatment decisions or emergency support.

6. Aggregate trajectory learning

Premium can compute trajectory signals locally from the user's execution history. To improve a shared machine-learning model, the app may derive a small bounded numerical feature vector from an older local time window and a later numerical outcome label.

The learning payload does not contain habit names, target names or text, prompts, notes, friction free text, account ID, habit ID, email address, exact completion dates, raw completion history, location or device advertising identifiers. The backend may validate that the request comes from an authenticated account for security and abuse prevention, but account identity is not supplied to the learning function as a feature and is not written to the trajectory model.

The server does not retain individual trajectory-training examples. Each accepted sample is used to update shared aggregate model parameters and a total sample counter; the individual sample is then discarded.

7. Feedback and bug reports

Feature requests and bug reports submitted inside the app are stored through Supabase together with the submitted text and limited technical context such as app/platform version where available.

8. Notifications and widgets

Notification preferences, reminder schedules and home-screen widget state are primarily processed locally and by the user's operating system to provide those functions. Platform notification infrastructure may process technical delivery data according to the platform provider's terms and privacy information.

9. Legal acceptance records

The app stores the accepted Terms and Privacy Policy versions and the acceptance timestamp locally. For signed-in users, those acceptance records may also be synchronized to the account so that the currently accepted legal version can be demonstrated.

10. Service providers and recipients

Depending on the feature used, data may be processed by Supabase for authentication, database and backend infrastructure; OpenAI or another explicitly configured AI provider for AI Coach generation; Apple App Store and Google Play for purchases, subscriptions and store account functionality; and operating-system providers for notifications and widgets where applicable.

Only data required for the relevant function should be transmitted. If additional analytics, advertising, crash-reporting or marketing services are introduced later, this Privacy Policy must be updated before those services are used in production where required.

11. International data transfers

Some service providers may process data outside Germany or the European Economic Area. Where the GDPR requires safeguards for such transfers, the applicable provider arrangements are to rely on an adequacy decision, Standard Contractual Clauses or another legally recognized transfer mechanism as applicable.

12. Retention

Local habit data remains on the device until it is deleted by the user, cleared by the operating system or removed with the app, subject to platform behavior. Account and entitlement data is retained for as long as the account or relevant service relationship exists and thereafter only where required for legal obligations, security, fraud prevention or purchase records. Individual trajectory-learning samples are not retained as a training dataset; only shared aggregate model parameters and aggregate sample counts are stored by the learning system.

13. Account deletion

Registered users can request/delete their server account through the app where the function is available. Deleting a server account does not automatically delete local habit data from the device and does not cancel an App Store or Google Play subscription. Store subscriptions must be managed through the respective store account. See the account deletion page for the external deletion procedure.

14. Your GDPR rights

Where the GDPR applies, you may have rights to access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, consent may be withdrawn for the future. You also have the right to lodge a complaint with a competent data-protection supervisory authority.

15. Changes to this policy

This policy may be updated when the app, legal requirements or production service providers change. The app records a policy version and may require renewed acceptance when a material update is introduced.