HabitHabit← Back to myhabit.ai

Habit — Privacy Policy

Effective date: 11 June 2026 Last updated: 26 June 2026

[Legal entity name] (“Habit”, “we”, “us”, “our”) operates the Habit private AI concierge service available at myhabit.ai and through connected channels (the “Service”). This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, where it is stored, how long we keep it, and the rights you have over it.

We treat the personal information of the people we serve as confidential. This policy is written to align with the Protection of Personal Information Act, 2013 (POPIA) and, where applicable, the EU/UK General Data Protection Regulation (GDPR).

If you have questions or wish to exercise your rights, contact our Information Officer at benjamin@myhabit.ai (see Contact below).


1. Who this policy covers, and the people in it

Habit operates on an operator–principal model. It helps to define the roles up front:

  • Principal — the client the Service works for (typically a founder or executive). The principal is the primary user and the person whose Google account, calendar, mailbox, schedule, relationships and preferences the Service draws on. If you are a principal, this policy is about your information.
  • Operator — Habit personnel who set up, personalise and onboard a principal’s account, and who maintain operator-only configuration. The operator never signs in as the principal and never enters the principal’s third-party logins; the principal authorises any connected account directly with the provider.
  • Concierge — the AI system that does the day-to-day work of the Service on the principal’s behalf, within the principal’s own dashboard and channels.
  • Third parties whose information may appear — people the principal interacts with (for example, names in a calendar invite, a meeting participant, or the sender of an email). We process this information only as a consequence of, and to the extent needed to provide, the Service to the principal. See section 11.

This policy applies to principals, to prospective principals who go through onboarding, and to operators and website visitors where noted.


2. The information we collect

We practise data minimisation: we capture only what the Service needs to function, and sensitive values are held in a secured per-client vault rather than in general storage.

2.1 Account and identity

Created when you are invited and you sign in. Authentication is handled by our provider Clerk using a passwordless email code — we do not operate or store a password for you. We collect your email address and basic account identifiers.

2.2 Onboarding intake

During onboarding you (or an operator, with your consent) provide the context the concierge needs: your preferences, the relationships that matter to you, your boundaries and do-not-contact rules, and similar concierge instructions. Some of this can be sensitive (for example, the people in your life and how you want them handled). We collect it to personalise the Service, and we process it only after you have given data-processing consent.

2.3 Connected accounts (connectors)

With your authorisation, the Service connects to third-party accounts you choose. Today these can include:

  • Google Calendar — read access to display your schedule and assemble your daily brief, and — only when you explicitly confirm a proposed change — access to create, update or cancel events on your behalf.
  • Gmail — read access to identify unread messages that need your attention and to surface them with sender and subject context, and to draft replies in your style. Where you enable it, and only after you explicitly approve each message, Habit can send that reply on your behalf from your mailbox. (Sending is offered where enabled for your account.)
  • Google Contacts — read-only access to enrich the people in your relationships view and to suggest contacts you may want to add. (Offered where enabled for your account.)
  • Google Drive — access to find and read the files relevant to your work, so the concierge can gather documents and context for your brief, and — only when you explicitly confirm an action — to create, edit, organise or share files on your behalf. (Offered where enabled for your account.)
  • Meeting notes (Fireflies) — meeting summaries/notes, where you connect it.
  • Documents (Craft) — the document surface where finished briefs are delivered.

You grant these permissions directly with the provider through their consent screen; the operator never enters your login. You can disconnect any connector at any time.

Google user data — Limited Use. Habit’s access to, use of, storage of, and sharing of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar, Gmail, Contacts and Drive data only to provide the user-facing features described above — your dashboard schedule, daily brief, email triage, relationship suggestions and document gathering, together with the calendar, email and file actions you explicitly approve. We do not use Google user data for advertising; we do not sell or transfer it, except as set out in section 5; and we do not use it to develop, improve or train generalised AI models (see section 4). Human access is restricted as described in section 5.

2.4 Communications

The Service operates across channels:

  • WhatsApp (delivered through Twilio) — the primary conversational channel. We process the messages you exchange with the concierge.
  • Web dashboard — your interactions within the app.
  • Voice (delivered through Vapi) — voice interactions. Where the concierge places an outbound call on your behalf, it discloses that the caller is an AI agent and handles recording consent before any recording is made; the disclosure and consent are recorded in the call record.

2.5 Ambient context capture — optional, separately consented

Habit offers an optional desktop companion (the context agent) that observes your screen to help the concierge stay current with what you are working on. It is off unless you separately and explicitly enable it, with granular per-category consent. It is engineered to be privacy-protective by construction:

  • Raw stays on your device. Screen pixels and raw recognised text are held in memory and discarded immediately. They are never written to disk and never leave your machine.
  • Redaction happens before anything is sent. A deterministic on-device filter removes sensitive content (for example payment card numbers, credentials, API keys, one-time passcodes, identity and banking details, and special-category data) before anything is transmitted. If a sensitive surface or token is detected, the whole snippet is dropped; ambiguous cases default to drop.
  • Only minimal, redacted text snippets leave the device. The source is recorded as an application or site class, never the raw address/URL.
  • Server-side processing is ephemeral. A redacted snippet is interpreted into a typed “observation” and the snippet is then purged on a short timer — only the observation is retained, in your per-client vault. The device runs no AI model.
  • You stay in control. A visible capture indicator, a one-tap global pause, and an inspectable “what I sent” log you can review and redact from. Password managers, banking apps and private-browsing windows are excluded from capture.

Pending legal sign-off (context agent). Because redacted text (not only derived conclusions) is processed server-side, our data-processing agreement and our documented position on third-party information that may appear on screen are being finalised with counsel. This section will be updated to reflect that position before the feature is offered to any principal.

2.6 Derived memory (observations)

From the inputs above, the concierge derives and stores minimised, structured items (preferences, relationship facts, observations) in your per-client memory vault to do its job over time. We store derived items needed for your brief and dashboard — not raw mailboxes or raw screen content.

2.7 Billing

Subscriptions are handled through Clerk Billing, backed by Stripe. Payments are processed by Stripe; we do not collect or store your full card number on our systems. We receive billing status and limited transaction metadata needed to manage your subscription.

2.8 Technical and log data

We keep operational logs for security and reliability. Our logs record identifiers and event types, not message content or other personal payloads.


3. How and why we use your information, and our lawful basis

PurposeExamplesLawful basis (POPIA / GDPR)
Provide the concierge ServiceDisplay your schedule, assemble your daily brief, triage email, run conversations across WhatsApp/voice/dashboardYour consent; performance of our agreement with you
Personalise to youApply your preferences, relationships and boundariesYour consent
Take actions you approvePrepare proposed bookings, purchases, messages or calls for your confirmationYour consent; performance of our agreement
Security and integrityPer-client isolation, abuse/fraud investigation, auditOur legitimate interests; legal obligation
Billing and administrationManage your subscriptionPerformance of our agreement; legal obligation
Service improvementDiagnose issues, improve reliability (using non-content identifiers and aggregates)Legitimate interests

Consent-first. We do not process your personal information to operate the Service before you have given data-processing consent. You can withdraw consent (see section 9); withdrawal does not affect processing already carried out.

No surprise uses. Our use of your information is limited to the purposes disclosed here.


4. AI processing of your information

The concierge’s reasoning is performed using the Anthropic Claude API. To generate your brief, triage, and responses, relevant information is sent to that API for processing and a result is returned. We contract our AI processing on terms intended to protect your information, and:

  • We do not use your personal information, or information from your connected accounts, to train AI models, and we contract our processors not to use it to train their models on our behalf.
  • Where screen-derived content is processed (context agent), we process it against a region-appropriate configuration and the processing client does not log the content payload.

5. How we share information

We do not sell your personal information, and we do not use it for advertising, ad targeting, profiling for ads, or credit/lending decisions.

We share information only with sub-processors who help us run the Service, each under contract and only for that purpose:

Sub-processorRole
ClerkAuthentication and billing administration
SupabaseDatabase and memory store (EU, Paris region)
InfisicalPer-client secrets vault
InngestScheduling of background jobs
TwilioWhatsApp messaging
VapiVoice calls
FirefliesMeeting notes (where you connect it)
CraftDocument delivery surface
GoogleCalendar, Gmail, Contacts and Drive connectors (your authorised access — reading your data, plus the calendar, email-send and file actions you approve)
Voyage AIEmbeddings for the memory store
AnthropicAI reasoning (Claude API)
StripePayment processing

We may also disclose information for security purposes (for example investigating abuse), to comply with applicable law or lawful requests, or as part of a merger, acquisition or sale of assets, in which case we will seek your consent where required and continue to protect your information under this policy. A current list of sub-processors is available on request.

Human access to your data is restricted. People do not read your connected-account content except where you have given affirmative agreement to view specific items, where necessary for security, or where required by law.


6. Where your information is stored, and international transfers

Your information is stored in the European Union (Supabase, Paris region) with per-client isolation. Habit is operated from South Africa. This means your information may be transferred across borders between South Africa and the EU in the course of providing the Service.

Pending legal sign-off (cross-border basis). The cross-border transfer basis under POPIA (section 72) — relying on adequacy of the receiving jurisdiction, our processor agreements, and your consent — is being finalised with counsel and documented. This section will state the confirmed basis before any principal’s real data is processed. No principal will be onboarded on a basis that misstates where data is stored.


7. How we protect your information

  • Per-client isolation. Each principal’s data is logically isolated; one principal’s data paths cannot read another’s. Database access is enforced with row-level security.
  • Secrets vault. Your connected-account tokens are held in a per-client encrypted vault namespace, never in general application storage and never in logs.
  • Confirm-before-act. The concierge does not book, buy, send or call without your explicit, logged confirmation.
  • On-device redaction for the optional context agent (section 2.5).
  • Minimised logging. Logs hold identifiers and event types, not your content.
  • Access governance and review over any change that touches credentials, the action layer, or voice.

No method of storage or transmission is perfectly secure, but we maintain safeguards appropriate to the sensitivity of the information.


8. How long we keep your information

DataRetention
Account and identityFor the life of your account; removed after deletion (see below)
Onboarding intake and derived memory (observations)While your account is active and the item remains relevant; subject to decay/minimisation over time
Connected-account tokensUntil you disconnect the connector or close your account
Raw screen pixels / raw OCR text (context agent)Never stored — discarded in-memory on device
Redacted snippet (context agent)Ephemeral — purged on a short timer after interpretation; only the derived observation persists
Messages and call recordsAs needed to provide and evidence the Service, then minimised
LogsA limited operational period
Billing recordsAs required by law and for legitimate business records

When you close your account, we delete or de-identify your personal information within a reasonable period, except where we must retain certain records to comply with law.


9. Your rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you;
  • Correct information that is inaccurate or out of date;
  • Delete your information (“right to be forgotten”) — for accounts, deletion severs your sign-in and removes your principal data;
  • Object to or restrict certain processing, and withdraw consent at any time;
  • Pause processing — the Service supports a per-principal pause and delete;
  • Data portability where applicable;
  • Lodge a complaint with a supervisory authority (in South Africa, the Information Regulator; in the EU/UK, your local authority).

To exercise any right, contact our Information Officer at benjamin@myhabit.ai. We will respond within the timeframe required by law. You can also disconnect connectors and pause the context agent yourself at any time from within the Service.


10. Children

The Service is for adults (18+) and is not directed to children. We do not knowingly collect personal information from anyone under 18.


11. Information about other people

In doing its job, the concierge may process information about people other than you (for example, a meeting participant or an email sender). We process such information only as needed to provide the Service to you, do not build independent profiles of those people for our own purposes, and do not covertly monitor third parties’ communications. By providing relationship and contact information, you confirm you are entitled to share it for this purpose.


12. Changes to this policy

We may update this policy as the Service evolves. We will post the updated version with a new “Last updated” date and, for material changes, give you appropriate notice. Continued use after an update means you accept the revised policy.


13. Contact

Information Officer: Benjamin Lazarus Email: benjamin@myhabit.ai Entity: [Legal entity name], [registration number] Address: [registered address], South Africa

For privacy questions, requests, or complaints, contact us using the details above.

Effective 11 June 2026