Privacy Policy

This privacy policy is applicable to the Habit Counter app for mobile devices, together with any related services operated by SENZU STUDIO SOFTWARE LTD (collectively, the “Application”). SENZU STUDIO SOFTWARE LTD is hereinafter referred to as the “Service Provider”.

Data Controller Information

SENZU STUDIO SOFTWARE LTD acts as the Data Controller responsible for the processing of your personal data.

  • Name: SENZU STUDIO SOFTWARE LTD
  • Address: 128 City Road, London, United Kingdom, EC1V 2NX
  • Email: [email protected]

For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.

What information does the Application obtain and how is it used?

The Application collects information that you provide when you create and use an account.

Account information: When you create an account, the Application collects your email address and authentication information through Firebase Authentication. Your email address is used to create and authenticate your account and to provide account-related functionality.

User identifier: The Application uses a unique user identifier (UID) associated with your Firebase Authentication account. This identifier is used to associate your account with your data stored in the Application’s database.

The Application does not collect location information, display advertising, or use your personal information for marketing purposes.

Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:

  • Contract performance: processing necessary to provide the Application or fulfil a contract with you.
  • Consent: where you have given explicit consent to processing, including for marketing, analytics, or optional features. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
  • Legitimate interests: where processing is necessary for the Service Provider’s specific legitimate interests, such as maintaining network and information security, preventing fraud and abuse, or improving the Application’s core functionality through analytics, provided those interests are not overridden by your data protection rights or fundamental freedoms.
  • Legal obligation: to comply with laws or government requests.

Cookies and Similar Technologies

The Application does not use cookies or advertising pixels. Some third-party services used by the Application may use technical mechanisms necessary to provide their services, such as authentication, security, or application updates.

Automated decision-making and profiling

The Application does not use automated decision-making or profiling that produces legal or similarly significant effects on users.

What information does the Application collect automatically?

The Application and the third-party services it uses may process certain technical information automatically when you use the Application. This may include information necessary to authenticate users, maintain security, prevent abuse, and provide application updates.

For example, Firebase Authentication may process technical information such as IP addresses and user-agent information for security and authentication purposes. Expo EAS Update may process technical information associated with update requests, such as the device operating system, application project identifier, and a randomized installation token.

Does the Application collect precise real time location information of the device?

This Application does not gather precise information about the location of your mobile device.

Does the Application use Artificial Intelligence (AI) technologies?

The Application does not use Artificial Intelligence (AI) technologies to process your data or provide features.

Do third parties see and/or have access to information obtained by the Application?

The Application uses third-party service providers to provide authentication, database storage, and other services necessary to operate the Application. These providers process information on our behalf as described in this Privacy Policy.

International Data Transfers

The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V.

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other safeguards or derogations recognized under GDPR Chapter V, including consent where legally permitted

Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.

Please note that the Application utilizes third-party services that have their own Privacy Policy about handling data. Below are the links to the Privacy Policy of the third-party service providers used by the Application:

The Service Provider may disclose User Provided and Automatically Collected Information:

  • as required by law, such as to comply with a subpoena, or similar legal process;
  • when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
  • with their trusted services providers who work on their behalf, do not have an independent use of the information the Service Provider discloses to them, and have agreed to adhere to the rules set forth in this privacy statement.

Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR. These DPAs impose the same data protection obligations on those service providers as described in this Privacy Policy.

Your Choices and Data Deletion

You can stop the Application from accessing information on your device by uninstalling the Application. However, uninstalling the Application does not automatically delete your account or information already stored by our service providers.

You can request deletion of your account and associated personal data by contacting us at [email protected] or in the app.

What is the data retention policy and how can you manage your information?

We retain your personal data for as long as your account remains active and as necessary to provide the Application’s services.

When you delete your account, we delete your account information and associated data from our systems, except where we are required to retain information to comply with a legal obligation or for other lawful purposes.

Data Deletion

You can request deletion of your personal data or account by contacting the Service Provider at [email protected]. The Service Provider will process your request within 30 days.

Upon verification of your identity, the Service Provider will delete your personal data (including account credentials, saved habits, and motivational quotes) from its systems, except where retention is required for legal compliance or legitimate business purposes.

In the app in addition to full account deletion, you can delete individual habits and motivational quotes without deleting your account.

How does the Application address children’s privacy?

The Application is not intended for children under 13 years of age, or where a higher age of digital consent is established under applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them.

Where parental or guardian consent is required under applicable law, the Application is not intended for use without that consent. The Service Provider does not knowingly collect personally identifiable information from children under 13 years of age, or where a higher age of digital consent is established by applicable law, in violation of applicable law. In the event the Service Provider discovers that a child has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided the Service Provider with personal information, please contact the Service Provider ([email protected]) so that they will be able to take the necessary actions.

How is your information kept secure?

The Service Provider is committed to safeguarding the confidentiality of your information. The Service Provider implements physical, electronic, and procedural safeguards to protect information it processes and maintains. For example, access is limited to authorized employees and contractors who need to know that information to operate, develop, or improve the Application. However, no security system can prevent all potential security breaches.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, the Service Provider will notify the ICO where legally required, without undue delay and, where feasible, within 72 hours as required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, the Service Provider will also notify you without undue delay, providing information about the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach.

How will you be informed of changes to this Privacy Policy?

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.

Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at [email protected].

This privacy policy is effective as of 2026-08-25

What are your GDPR data protection rights?

Under the GDPR, you have the following rights:

  • Right of Access: You can request access to your personal data.
  • Right to Rectification: You can request correction of inaccurate data.
  • Right to Erasure: You can request deletion of your personal data (the “right to be forgotten”).
  • Right to Restrict Processing: You can request that the Data Controller limits how they use your data.
  • Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to Object: You can object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.
  • Right to Withdraw Consent: Where processing is based on your consent, you can withdraw it at any time. Withdrawal is as simple as contacting the Data Controller.
  • Rights Regarding Automated Decision-Making: You have rights related to automated decisions that affect you.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country’s Data Protection Authority can be found at: https://edpb.ec.europa.eu/about-edpb/members_en

If you are located in the United Kingdom, you may contact the Information Commissioner’s Office at https://ico.org.uk

Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases, including contract performance, legitimate interests, or legal obligations, is carried out as described above.

How can you contact the Data Controller?

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at [email protected].

To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.