Habits

Privacy & AI controls

See what AI can access. Switch it off when you do not want it.

Habits keeps core tracking available without AI.

If you choose to use optional AI, you can control access by category and review recorded AI data-access events.

Privacy should be something you can inspect—not just a promise in small print.

Optional AI · 9 category controls · Access history · Export · Account deletion

Habits Overview screen showing AI health insights and weekly and monthly reports
Actual Habits app screen

What control do you have over AI and your Habits data?

The current Habits product includes:

  • an AI consent choice;
  • a master AI on/off switch;
  • separate AI controls for nine data categories;
  • an AI access history;
  • PII masking for supported AI processing;
  • Face ID or Touch ID app locking on supported devices;
  • health-data export in JSON or CSV;
  • re-authenticated account deletion.

You can use the core Habits trackers without enabling AI.

Habits currently uses OpenAI models for optional AI features.

Declining AI does not remove the core trackers.

Habits requires an AI consent choice before optional AI processing is enabled.

If you decline or later switch AI off, you can still use core features such as:

  • Medication tracking;
  • Hydration;
  • manual Food logging;
  • Exercise tracking and programmes;
  • Mood;
  • Weight;
  • Sleep;
  • Progress Photos;
  • Measurements.

You can return to the AI Privacy Dashboard later if you want to change your AI setting.

Turning AI off controls optional AI processing going forward; this page does not claim that the switch by itself deletes previously stored chat history or every historical processor record.

Turn optional AI processing off from one place.

The AI Privacy Dashboard includes a master AI on/off control.

When AI is disabled, the core tracking system remains available.

Choose which categories AI may access.

Habits has separate AI controls for:

  1. Medication
  2. Hydration
  3. Food
  4. Exercise
  5. Mood
  6. Weight
  7. Sleep
  8. Photos
  9. Measurements

That gives you a more specific choice than a single all-or-nothing AI setting.

For example, you may choose to allow one category while keeping another category unavailable to AI.

See a record of when AI accessed a category.

Habits includes an AI access history.

Each recorded event can show:

  • the time;
  • the data category;
  • the Habits feature that accessed it.

The current plan structure shows:

  • the last 5 recorded events in Free;
  • the last 20 recorded events in Pro.

The access history can also be cleared.

Habits filters certain direct identifiers before supported AI requests.

The current product applies PII masking to filter identifiers such as:

  • names;
  • phone numbers;
  • health IDs.

The product reference specifically applies that masking to supported AI processing including:

  • chat;
  • insights;
  • reports;
  • Daily Plan generation.

PII masking is not the same as full anonymisation.

Relevant health and tracking context may still be processed to provide an AI feature you enabled.

Know which third-party AI provider is involved.

Habits currently uses OpenAI models for optional AI features.

That means relevant information used to provide an enabled AI feature may be processed by OpenAI under the configuration and agreements used by Habits.

The final Habits Privacy Policy should explain the approved current processor/data-flow details.

Previous AI conversations can remain available in your account.

The current Habits product stores AI chat history server-side so previous conversations can remain available in the AI chat experience.

Because chat can contain sensitive information, the final Privacy Policy should explain:

  • how long chat history is retained;
  • what happens when an account is deleted;
  • any applicable third-party processor retention.

Add a device-level lock to Habits.

On supported devices, Habits includes Face ID or Touch ID app locking.

This can add another access barrier before someone opens the app on your device.

It does not control what iOS shows in notification previews outside the app.

Keep a portable copy of your Habits data.

Habits supports health-data export in:

  • JSON
  • CSV

This gives you a portable copy of supported logged data.

The website does not claim that these exports contain every original file or media asset, such as Progress Photo image files, unless the production export is verified to include them.

Account deletion requires you to confirm your identity again.

Habits includes permanent account deletion with re-authentication.

Depending on how you signed in, the current product supports identity confirmation through:

  • password re-entry;
  • Apple re-authentication;
  • Google re-authentication.

The deletion flow also invalidates active Habits sessions.

The final Privacy Policy should explain deletion timing for the Habits system, backups and third-party processors.

Body photographs are sensitive data.

Habits includes optional Progress Photos.

Because photos can be especially sensitive, this website does not make detailed security promises about photo storage until the current production storage and access controls have completed security/privacy review.

You do not need to use Progress Photos to use Habits.

Apple Health access is permission-based.

Where connected-health access is available, Habits can read selected Apple Health metrics with your permission:

  • Steps;
  • Heart Rate;
  • HRV;
  • Blood Oxygen.

Connected health is rollout-controlled.

The feature is designed for supported Habits tracking and insight functionality—not for advertising use.

Calendar access does not need edit permission.

Habits Pro can connect Google Calendar using read-only access.

The current feature can:

  • view upcoming events for the next seven days;
  • use calendar commitments as Daily Plan context where Daily Plan is available.

You can disconnect the calendar connection.

Habits does not need permission to create, edit or delete events for this feature.

Share only what is needed when you contact Support.

Habits includes a Contact Support option that opens email.

A support message can contain personal or health information if you choose to include it.

Only include the information needed to explain the issue, and do not use support email as an emergency or medical-advice channel.

The legal Privacy Policy should explain how support communications are handled and retained.

Specific controls are more useful than absolute promises.

This page does not claim that:

  • all Habits data stays only on your device;
  • all health data is anonymous;
  • AI sees no health context;
  • no third-party processor handles data;
  • every file is end-to-end encrypted;
  • Progress Photos can only ever be seen by the account holder;
  • OpenAI retains data for zero days;
  • Habits is HIPAA compliant;
  • Habits is GDPR compliant;
  • every original image is included in data export;
  • account deletion instantly erases every processor backup;
  • biometric lock hides notification previews.

Those claims require system-specific and legal evidence.

Habits instead describes the controls that are actually verified and links to the current Privacy Policy for the full legal data-handling statement.

Questions about Habits privacy and AI data controls

Do I have to use AI?

No. Core Habits tracking remains available if optional AI processing is declined or disabled.

Can I switch AI off?

Yes. The AI Privacy Dashboard has a master AI on/off control.

Can I control individual categories?

Yes. Habits has separate AI permissions for Medication, Hydration, Food, Exercise, Mood, Weight, Sleep, Photos and Measurements.

Can I see when AI accessed my data?

Yes. Habits includes an AI access history showing recorded events by time, category and feature.

How many AI access-history entries can I see?

The current plan reference shows the last 5 recorded events in Free and the last 20 in Pro.

Can I clear the AI access history?

Yes. The current product reference says the AI access history can be permanently cleared.

Does clearing the AI access history delete my health data?

This website does not claim that. Clearing the access history and deleting underlying health records are different actions.

Does Habits remove personal information before AI processing?

For supported AI processing, Habits applies PII masking to filter identifiers such as names, phone numbers and health IDs. Relevant health/tracking context may still be processed.

Does PII masking make my data anonymous?

No. PII masking is not the same as full anonymisation.

Does Habits use OpenAI?

Yes. Habits currently uses OpenAI models for optional AI features.

Does OpenAI train on my Habits data?

OpenAI's current API/business default is not to use API inputs and outputs for training unless the organisation opts in.

How long does OpenAI keep Habits AI data?

This website does not state a single retention period because OpenAI API retention can depend on endpoint and account configuration. The approved Habits Privacy Policy should state the verified production arrangement.

Is AI chat history stored?

Yes. The current product stores persistent AI conversation history server-side.

Does turning AI off delete old chat history?

That deletion behaviour is not established in the current verified feature reference, so this website does not claim it.

Does Habits send Progress Photos to AI?

Habits has a separate Photos AI permission, but the current verified product reference does not establish an AI Progress Photo/body-analysis workflow. This website does not claim one.

Can I lock the app with Face ID or Touch ID?

Yes, on supported devices.

Does Face ID hide medication notifications on my lock screen?

No. App locking and iOS notification-preview settings are separate controls.

Can I export my data?

Yes. Habits supports JSON and CSV export of logged health data.

Can I delete my account?

Yes. Habits includes re-authenticated permanent account deletion.

Is Habits HIPAA compliant?

This website does not make a HIPAA-compliance claim.

Is Habits GDPR compliant?

This website does not make a blanket GDPR-compliance claim. The legal Privacy Policy should describe the rights and obligations applicable to the markets where Habits operates.

Does Habits sell health data?

The current product feature reference does not establish the company's complete commercial/data-sharing policy strongly enough for this page to make an absolute “never sold” claim. The approved Privacy Policy should state the definitive current position.

Does Habits use my health data for advertising?

Habits' website/product analytics implementation should not send sensitive health records to advertising platforms. Apple also restricts use/disclosure of health, fitness and medical data gathered in that context for advertising or marketing data-mining. The final Privacy Policy and analytics implementation must match this boundary.

Who is legally responsible for Habits data?

Can I ask Habits to access or correct personal information about me?

The legal Privacy Policy should explain the access/correction rights and request process that apply to you. JSON/CSV export is a product feature, but it is not a substitute for every statutory privacy request right.

What happens to Google Calendar data?

Habits Pro uses read-only Calendar access. The final Privacy Policy must explain the exact Calendar fields accessed, storage/retention and whether Calendar context is processed by AI for Daily Plan. Habits' use of Google user data must comply with Google's API User Data / Limited Use requirements.

Can I contact Habits about privacy?

Yes. The published Privacy Policy should include the current Privacy Officer/privacy contact details before this page goes live.

What should I include in a Support email?

Only include information needed to explain the issue. Support email is not an emergency or medical-advice channel.

Where can I download Habits?

Habits: GLP-1 Companion is available on the Apple App Store.

About this page

Last updated: 20 August 2026

This page explains current Habits product-level privacy and AI controls.

It is not the legal Privacy Policy and does not replace the detailed disclosure of:

  • the legal entity responsible for collecting/holding the data;
  • data collected;
  • purposes;
  • processors;
  • retention;
  • overseas processing;
  • legal rights and request processes;
  • privacy contact details.

Read the full Privacy Policy →

Use the trackers. Decide where AI fits.

Keep core tracking without AI if that is what you prefer.

If you enable AI, control categories separately and review the access history when you want to see how Habits used those permissions.

Habits: GLP-1 Companion is available now on the App Store.

Small print:
Privacy and processor configurations can change. The current Privacy Policy is the authoritative legal description of Habits data handling.