Philiabit
Legal hub Privacy Terms Community
Get the app
Legal hub/Privacy Policy
Privacy

🔒 Privacy Policy

How Philiabit collects, uses, shares, and protects your information when you use our app and website.

Effective 2026-07-20 Last updated 2026-07-20 Version 1.0 Applies to iOS & Android
Before publishing: Confirm the legal entity name and registered address in the Contact section, the data-hosting region(s), and whether a Data Protection Officer must be named for GDPR purposes before this document goes live.

At a glance

  • We collect the account, profile, and habit/challenge activity data needed to run Philiabit — plus any photos or videos you submit as challenge proof.
  • Proof photos/videos are used to verify challenge completion and are visible to the people you choose (peers, group, or public, depending on your Privacy Settings).
  • We use Firebase (Google) for push notifications and product analytics. We do not sell your personal data or use it for third-party advertising.
  • Camera, photo library, contacts, notifications, and location permissions are all optional and only requested when you use the related feature — see Data & Permissions.
  • You can download a copy of your data or delete your account at any time from Settings, or by request — see Account & Data Deletion.
  • Philiabit is not directed at children under 13, and we do not knowingly collect data from them.
1. Overview & scope2. Information we collect3. How we use your information4. How we share information5. AI-assisted features6. How we protect your data7. How long we keep your data8. Your privacy choices9. Children's privacy10. International users & GDPR11. California privacy rights (CCPA/CPRA)12. Data portability & export13. Changes to this policy14. Contact us
1 Overview & scope

This Privacy Policy explains how Philiabit ("Philiabit", "we", "us") collects, uses, discloses, and safeguards information when you use the Philiabit mobile application (iOS and Android) and the philiabit.com website (together, the "Service").

By creating an account or otherwise using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service. This Policy should be read alongside our Terms & Conditions and Community Guidelines.

2 Information we collect

We collect information in three ways: information you give us directly, information created automatically as you use the app, and information from your device (with your permission).

Account & profile information

  • Email address, username, and password (stored as a salted hash — we never store your plaintext password).
  • Display name, profile photo/avatar, bio, and optional profile details you choose to add.
  • Language preference (English / Arabic) and basic device/locale settings.

Habit & challenge activity

  • Challenges you create, join, or are invited to, including category, tracking type (threshold, survivor, or relay), targets, and schedule.
  • Daily check-ins, tracked progress (counts, timers, checklist items, boolean completions), streak history, and challenge outcomes.
  • XP, coins, levels, badges, and leaderboard standing earned through in-app activity.

Proof, stories & social content

  • Photos and videos submitted as proof of habit or challenge completion, and the peer-approval decisions (approve/reject) made on that proof.
  • 24-hour proof stories, and metadata about who viewed them.
  • Posts, comments, reactions, and direct or group chat messages you send through the Service.
  • Your friends list, group/team memberships, and social connections (including contacts you choose to invite from your device address book).

Device, usage & diagnostic information

  • Device model, OS version, app version, and general usage/interaction events (e.g., screens viewed, challenge joined, level up) collected via Firebase Analytics.
  • Push notification tokens (Firebase Cloud Messaging) so we can deliver reminders and social notifications.
  • Crash and performance diagnostics, and security signals such as jailbreak/root-detection status and TLS certificate validation results, used to protect accounts from compromised devices.
  • Approximate location (only if you grant permission) captured at the moment you submit a proof photo, used solely to attach an optional location tag to that proof — see Data & Permissions.
3 How we use your information

We use the information described above to:

  • Create and secure your account, authenticate you, and keep you signed in across sessions.
  • Operate core features: challenge tracking, streaks, proof review, XP/coins/leveling, leaderboards, and the social feed.
  • Deliver real-time updates (challenge progress, milestones, level-ups, chat, presence) and push/local notifications you've enabled.
  • Personalize your experience — for example, showing relevant challenge categories or friend suggestions.
  • Detect and prevent fraud, cheating on proof submissions, account takeover, and abuse of the reward system.
  • Understand product usage in aggregate so we can fix bugs and improve features, via Firebase Analytics.
  • Communicate with you about your account, security notices, and (where you've opted in) product updates or marketing.
  • Comply with legal obligations and enforce our Terms & Conditions and Community Guidelines.
4 How we share information

We do not sell your personal information. We share information only in the following circumstances:

With other users, based on your settings

Your profile, habits, challenges, streaks, proof stories, and leaderboard position are visible to other users according to the visibility level you choose in Privacy Settings (Public, Friends Only, or Private). Proof submitted for a group or team challenge is always visible to that group for verification purposes.

With service providers ("subprocessors")

These providers are contractually restricted to using your data only to provide services to Philiabit.

  • Firebase / Google Cloud — push notifications (Cloud Messaging), product analytics, and app infrastructure.
  • Cloud storage and hosting providers — storing uploaded photos/videos and application data (backed by our PostgreSQL database).
  • Certificate/security tooling used to validate connections between the app and our servers (certificate pinning) and to detect rooted/jailbroken devices.

For legal & safety reasons

We may disclose information if required by law, subpoena, or legal process, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Philiabit, our users, or the public — including enforcing our Community Guidelines after an in-app report.

In a business transfer

If Philiabit is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We'll notify you before your data becomes subject to a different privacy policy.

5 AI-assisted features

Philiabit does not currently include an AI coach or AI-generated recommendations. If we introduce AI-assisted features in the future (such as personalized habit suggestions), this Policy and our dedicated AI Features Disclaimer will be updated before launch to explain what data powers those features, whether an AI provider processes your data, and how to opt out.

6 How we protect your data

We apply industry-standard technical and organizational safeguards, including:

  • Encryption in transit (TLS) for all traffic between the app and our servers, reinforced with certificate pinning to block man-in-the-middle attacks.
  • Secure, encrypted on-device storage of authentication tokens (never plaintext credentials) using the platform Keychain (iOS) / Keystore (Android).
  • Jailbreak/root detection and screen-capture protection on sensitive screens to reduce the risk of compromised devices exposing your data.
  • Access controls limiting employee access to personal data to what's needed to operate and support the Service.
  • Regular security review of authentication, session handling, and data-transfer flows.

No method is 100% secure

No system of data storage or transmission can be guaranteed completely secure. If we become aware of a breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.

7 How long we keep your data

We keep information only as long as needed for the purposes described in this Policy:

  • Account & profile data — retained while your account is active.
  • Proof stories — automatically expire and are removed from general visibility 24 hours after posting; the underlying media may be retained briefly afterward for moderation/appeals before deletion.
  • Challenge history, streaks, XP/coins, and badges — retained as your permanent in-app history unless you delete your account.
  • Chat messages — retained to preserve conversation history for you and the other participant(s) until either deletes them or the account is deleted.
  • Diagnostic/security logs — typically retained for up to 90 days for fraud and abuse investigation, then deleted or anonymized.
  • Upon account deletion, we delete or irreversibly anonymize your personal data within 30 days, except where we must retain limited records to comply with law, resolve disputes, or enforce our agreements — see Account & Data Deletion.
8 Your privacy choices

You control most of this directly in the app under Settings → Privacy (see our companion Privacy Settings guide), including:

  • Profile visibility (Public / Friends Only / Private) and discoverability in search.
  • Who can view your habits, challenges, and streaks, and who can invite, message, or friend-request you.
  • Story visibility, leaderboard visibility, activity status, and last-active visibility.
  • Push, email, and (where offered) SMS notification preferences.
  • Analytics sharing and marketing email opt-in/opt-out.
  • Camera, photo library, contacts, and location permissions — revocable anytime in your device's OS settings.
9 Children's privacy

Philiabit is not directed at, and is not intended for use by, children under 13 years old (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal information from children under this age.

If you believe a child has provided us with personal information, please contact us at [email protected] and we will investigate and delete the data as appropriate.

10 International users & GDPR

If you're located in the European Economic Area, the UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including the right to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing.

Our legal bases for processing include: performance of our contract with you (running your account and the Service), our legitimate interests (security, fraud prevention, product improvement), your consent (e.g., marketing emails, optional AI personalization, location tagging), and legal obligation.

Where we transfer personal data outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. To exercise a GDPR right, contact [email protected]; you also have the right to lodge a complaint with your local data protection authority.

11 California privacy rights (CCPA/CPRA)

If you're a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information.

Philiabit does not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. You can submit a verifiable request to know, delete, or correct your data by emailing [email protected] or using the in-app data export/delete tools. We will not discriminate against you for exercising these rights.

12 Data portability & export

You can request a machine-readable export of your account data (profile, challenge history, streaks, XP/coins, and content you've posted) from Settings → Privacy → Export My Data, or by emailing [email protected]. We aim to fulfill export requests within 30 days.

13 Changes to this policy

We may update this Policy as Philiabit evolves. If we make material changes, we'll notify you in-app or by email before they take effect and update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

14 Contact us

Questions, requests, or concerns about this Policy or your data can be sent to [email protected]. For security reports, see [email protected].

Data controller: [Philiabit Legal Entity Name], [Registered Address — to be confirmed].

Have a question about your data?

Our privacy team responds to access, deletion, and correction requests within 30 days.

Email [email protected]

Related documents

Privacy Settings Every visibility and sharing control, explained. Data & Permissions Why we ask for camera, location, and more. Account & Data Deletion How to delete your account and data.
Philiabit

Turn habits into adventures. Build streaks, join challenges, and move forward — together.

Product
ChallengesStreaksRewardsThe app
Company
AboutCareersBlogPress
Legal
Privacy PolicyTerms & ConditionsCommunity GuidelinesAll legal documents
Support
Data & PermissionsDelete my accountContact
© 2026 Philiabit. All rights reserved.