How Philiabit collects, uses, shares, and protects your information when you use our app and website.
This Privacy Policy explains how Philiabit ("Philiabit", "we", "us") collects, uses, discloses, and safeguards information when you use the Philiabit mobile application (iOS and Android) and the philiabit.com website (together, the "Service").
By creating an account or otherwise using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service. This Policy should be read alongside our Terms & Conditions and Community Guidelines.
We collect information in three ways: information you give us directly, information created automatically as you use the app, and information from your device (with your permission).
We use the information described above to:
Philiabit does not currently include an AI coach or AI-generated recommendations. If we introduce AI-assisted features in the future (such as personalized habit suggestions), this Policy and our dedicated AI Features Disclaimer will be updated before launch to explain what data powers those features, whether an AI provider processes your data, and how to opt out.
We apply industry-standard technical and organizational safeguards, including:
No system of data storage or transmission can be guaranteed completely secure. If we become aware of a breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.
We keep information only as long as needed for the purposes described in this Policy:
You control most of this directly in the app under Settings → Privacy (see our companion Privacy Settings guide), including:
Philiabit is not directed at, and is not intended for use by, children under 13 years old (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal information from children under this age.
If you believe a child has provided us with personal information, please contact us at [email protected] and we will investigate and delete the data as appropriate.
If you're located in the European Economic Area, the UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including the right to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing.
Our legal bases for processing include: performance of our contract with you (running your account and the Service), our legitimate interests (security, fraud prevention, product improvement), your consent (e.g., marketing emails, optional AI personalization, location tagging), and legal obligation.
Where we transfer personal data outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. To exercise a GDPR right, contact [email protected]; you also have the right to lodge a complaint with your local data protection authority.
If you're a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information.
Philiabit does not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. You can submit a verifiable request to know, delete, or correct your data by emailing [email protected] or using the in-app data export/delete tools. We will not discriminate against you for exercising these rights.
You can request a machine-readable export of your account data (profile, challenge history, streaks, XP/coins, and content you've posted) from Settings → Privacy → Export My Data, or by emailing [email protected]. We aim to fulfill export requests within 30 days.
We may update this Policy as Philiabit evolves. If we make material changes, we'll notify you in-app or by email before they take effect and update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
Questions, requests, or concerns about this Policy or your data can be sent to [email protected]. For security reports, see [email protected].
Data controller: [Philiabit Legal Entity Name], [Registered Address — to be confirmed].
Our privacy team responds to access, deletion, and correction requests within 30 days.