Privacy Policy
Last updated: [DATE] · Applies to the myHab.Fit Android app (com.aura.auraai4) and this website
In short
- You must be 18 or older to use myHab.Fit.
- We collect what the app needs to build your workout plan and track your progress. Nothing more.
- Menstrual-cycle and symptom data never leaves your phone. We cannot see it.
- Camera images never leave your phone. No photo or video frame is ever stored or sent anywhere.
- Your account data is stored in India (Mumbai). Some supporting services run on Google's global infrastructure.
- We do not sell your data. We do not use it for advertising. We do not collect an advertising identifier.
- You can delete your account and all of it from inside the app, at any time.
myHab.Fit is currently available only in India.
1. Who is responsible for your data
myHab.Fit is operated by [FULL LEGAL NAME], an individual based in Hyderabad, Telangana, India.
Under the Digital Personal Data Protection Act, 2023 ("the DPDP Act"), that person is the Data Fiduciary for your personal data — meaning they decide what data is collected and why, and are answerable for it.
Contact for any question or complaint about your data — Grievance Officer:
Email: contactus@myhab.fit
Postal: S-404, Poojitha Estates, Model Colony, Sundernagar, Hyderabad, Telangana, India – 500038
We will respond to any request about your data within 90 days, and usually much sooner.
2. Age requirement
myHab.Fit is for adults. You must be 18 or over to create an account or use the app.
The app asks for your date of birth during setup and will not let you continue if you are under 18 on that date. That check applies wherever the date can be changed, not only at sign-up. It relies on what you tell us — we do not verify it, and we would rather say so than imply a check we do not perform.
We do not knowingly collect data from anyone under 18. Under Indian law, anyone under 18 is a child, and processing a child's data requires verifiable parental consent, which this app is not designed to obtain. If we learn that an account belongs to someone under 18, we will delete it.
If you believe a child is using the app, contact us at contactus@myhab.fit.
3. What we collect, and why
We collect only what a named feature actually uses. Every field below feeds something specific.
3.1 Your account
Your email address, display name, profile photo link and an internal account ID, provided by Google when you sign in. They identify your account and let your data follow you to a new phone.
Sign-in is through your Google account. We never see or store a password. There is no guest mode — an account is required.
3.2 What you tell us when you set up
| What | Why |
|---|---|
| First name | To greet you. Nothing else. |
| Gender | Chooses which exercise-demonstration video is shown, the default coaching voice, and whether the optional cycle feature is offered. |
| Date of birth | The exact date is used for one purpose only — the 18 check in §2. Everywhere else only your age in years is used: as one input to the formula that estimates calories burned, and to show the typical resting heart-rate range for your age group. |
| Height and weight | The same calorie formula. Weight also starts your body-weight trend chart. |
| Goal, fitness level, sessions per week, preferred time of day | Builds your workout plan and sets your weekly target. |
| Equipment you have | Limits which exercises can appear in your plan. |
| Theme preference | Appearance only. |
3.3 What the app records as you use it
Workouts you complete (exercises, sets, repetitions, weights, duration, estimated calories), personal bests, your streak and consistency record, per-exercise progression, any injuries you flag, recovery scores calculated from your health data, movement breaks, and walks.
3.4 Health data from Health Connect (optional, and separately permitted)
If you connect Health Connect and grant permission, we read: steps · sleep sessions and stages · heart rate · heart-rate variability · resting heart rate · active calories · body weight · workouts recorded by other fitness apps (including the name of the app that recorded them).
This is used to estimate how recovered you are, to adjust the intensity of your sessions, and to show your health trends in the app.
We also write two things back to Health Connect: the workouts you complete in myHab.Fit, and the calories for them, so your other health apps can see them.
You can grant or revoke each of these permissions at any time in Android's Health Connect settings.
3.5 Menstrual cycle (optional, off by default)
If you turn this on, you can log period days with a flow level, and symptoms from a fixed list, with a severity. There is no free-text box.
It is used to gently reduce workout intensity on days you report certain symptoms, to leave jumping exercises out on days you log a period, and to show cycle predictions.
This data is stored only on your phone. It is never uploaded to us, never backed up to our servers, and never sent to anyone else. We cannot see it. Because of that, it does not transfer to a new phone, and uninstalling the app removes it.
Two indirect signals, which we would rather state than have you discover. Although the cycle data itself never leaves your phone: (a) exercise-demonstration videos are streamed from a delivery network, and the file requested differs by gender — so that network's logs can imply your gender; and (b) if you train less during your period, your synchronised workout history reflects that, as any change in your training would. Neither transmits your cycle log, but both are signals we can see the shape of, and we would rather say so.
You can delete all cycle data at any time from Settings, separately from the rest of your account.
3.6 Camera (optional, off by default, marked Beta)
If you turn the camera on, it is used to count your repetitions during a set.
No image, video frame, or body-position recording is ever saved or sent anywhere. The analysis runs entirely on your phone, using a model bundled inside the app. Nothing is uploaded for processing. The only thing kept is a small set of numbers describing your joint angles, stored on your phone, which you can reset in Settings.
3.7 Usage analytics
- Standard analytics (on by default). Which screens you reach, whether onboarding completed, whether a workout started and finished, subscription outcomes, feature usage. These carry a random per-installation identifier generated by Google. Your name, email and account ID are never included.
- Detailed repetition data (off by default — we ask, and you can say no). If you opt in, we additionally record repetition counts and any corrections you make to an automatic count, so we can improve the counter's accuracy. You can turn this off at any time in Settings.
No free-text and no identifying field ever appears in analytics.
3.8 Crash reports
If the app crashes, a technical report is sent to Google Crashlytics: the error trace plus your device model and Android version. We attach no account identifier and no custom information of our own.
3.9 Exercise videos
Exercise-demonstration videos are streamed on demand rather than bundled into the app. Each request necessarily includes your device's IP address and which exercise you are viewing. No cookies, account identifier or account data are sent.
4. Where your data is stored
On your phone only — never sent to us: cycle and symptom logs, injury flags, equipment, exercise progression, recovery scores, movement-break logs, walk state, camera calibration, the cached list of other apps' workouts, your achievements record, and all your settings and preferences.
In our cloud storage (Google Cloud Firestore, Mumbai region, India): your account record, workout history, lifetime totals and personal bests, streak state, monthly training summaries, your body-weight log, excluded exercises and any custom workout you built.
Access is restricted so that only your own signed-in account can read or write your own records. Everything else is refused by default.
Data leaving India. Your account records are held in India. However, sign-in, analytics and crash reporting are operated by Google on its global infrastructure, so some data is processed outside India. The DPDP Act permits such transfers subject to conditions set by the Government of India, and we will comply with any conditions applicable to us.
5. Who else receives data
| Who | What they receive |
|---|---|
| Google (Firebase Authentication) | Your sign-in and account record |
| Google (Cloud Firestore, Mumbai) | Exactly the cloud data listed in §4 |
| Google (Firebase Analytics) | The usage events in §3.7 |
| Google (Firebase Crashlytics) | Crash reports as in §3.8 |
| Cloudflare | Video requests: your IP address and which exercise video you asked for |
| Google Play | Your subscription purchase and status |
We do not share your data with anyone else. We do not sell it, and we do not give or license it to advertisers, data brokers, or any other third party for their own purposes.
Google processes the data it receives under its own terms and its own privacy policy, at policies.google.com/privacy. We do not control what Google does with data under those terms, and we do not claim to.
6. Advertising
We do not use your data for advertising. myHab.Fit shows no ads and runs no advertising campaigns using your data.
We also do not collect an advertising identifier — the device-level ID that advertising networks use to recognise you across apps. The permissions that would allow it have been removed from the app, and Google's own collection setting is switched off.
We state this about what we collect and what we do. As above, data that Google receives is governed by Google's own terms.
7. How long we keep it
On your phone, older records are automatically removed:
| Data | Kept for |
|---|---|
| Workout history | 372 days |
| Individual set records | 183 days |
| Cycle and symptom logs | 372 days |
| Other apps' cached workouts | 372 days |
| Movement-break logs | 372 days |
| Recovery scores | Approximately the last 60 |
| All-time personal bests | Kept indefinitely |
In our cloud storage, your data is kept for as long as your account exists. It is removed when you delete your account (§8).
Analytics data is retained for 14 months, then deleted by Google.
8. Deleting your account and your data
In the app: open Settings → Delete account. This removes:
- your entire cloud record — account, workout history, personal bests, streak, training summaries, and everything you authored;
- your Google sign-in link to this app;
- every piece of personal data stored on that phone, including your cycle logs.
It cannot be undone.
Please read this before you delete — some things are outside our reach:
- Workouts we wrote into Health Connect stay there. The workouts and calories we recorded into your phone's Health Connect store are yours and remain in it. They may already have been read by other apps. You can remove them yourself in the Health Connect app. We deliberately do not delete them, because they are part of your own health record and other apps may depend on them.
- Your subscription is not cancelled. Deleting your account does not cancel a Google Play subscription. Cancel it in Google Play.
- Another phone is not wiped remotely. If you are signed in on a second device, its local data remains until you next open the app there — at which point it will be erased because the account has changed — or until you uninstall.
- Analytics and crash reports already sent are not recalled. They carry a random per-installation identifier, not your account.
If you have already uninstalled the app, or cannot sign in, use the account deletion request page or email contactus@myhab.fit. We will verify that the request is yours and complete it within 90 days.
Deleting only some things. You can delete your cycle data alone, and reset your camera calibration alone, from Settings. Other categories can only be removed by deleting the account, or by asking us.
9. Your rights
Under the DPDP Act you have the right to:
- Know what personal data of yours we hold and what we do with it — this policy sets it out; ask us for anything more.
- Correct or complete it. Most of it is editable in the app under Settings → Profile; ask us for the rest.
- Have it erased, as in §8.
- Withdraw consent at any time. Turn off the analytics setting in Settings; turn off cycle tracking in Settings; revoke camera or Health Connect permission in Android settings; or delete your account to withdraw entirely. Withdrawing consent does not undo processing already carried out lawfully.
- Nominate another person to exercise these rights on your behalf if you die or become unable to. Contact us to do so.
- Complain. Write to our Grievance Officer at contactus@myhab.fit. If we do not resolve it, you may complain to the Data Protection Board of India.
Exercising any of these rights costs nothing and will never restrict your use of the app, except where the right you exercise necessarily does (deleting your account ends it).
10. Security
Your cloud records are held in Google Cloud Firestore with access rules that permit only your own signed-in account to read or write them. Sign-in is handled by Google; we never hold a password. Data in transit is encrypted.
If a data breach affects your personal data, we will inform you and the Data Protection Board of India without delay, and report the details to the Board as the law requires.
No system is perfectly secure, and we do not claim otherwise.
11. Permissions the app asks for
| Permission | What it is for | Optional? |
|---|---|---|
| Health Connect (individually per data type) | Reading your health data and writing your workouts back | Yes |
| Camera | On-device repetition counting | Yes — off by default |
| Physical activity | Counting steps for walks and movement breaks | Yes |
| Notifications | Reminders you have asked for | Yes |
Every one can be refused or revoked in Android settings, and the app continues to work without them, with the related features unavailable.
One thing this table does not show. The above is what myHab.Fit itself asks for. An Android app's installed package also lists permissions added by the software libraries it is built with — in our case Google's — which we never ask for and do not use. Google Play shows you that fuller list.
12. This website
This website is a small set of pages describing the app. It has no account, no sign-in, and no analytics or tracking of any kind. It sets no cookies.
If you write to us from it, we hold your message and your email address for as long as it takes to answer you.
13. Changes to this policy
If we change this policy we will update the date at the top and, where the change is significant, tell you in the app before it takes effect.
14. Availability in other languages
This policy is published in English. On request we will provide it in any of the languages listed in the Eighth Schedule to the Constitution of India. Write to contactus@myhab.fit.
15. Contact
Grievance Officer — contactus@myhab.fit
S-404, Poojitha Estates, Model Colony, Sundernagar, Hyderabad, Telangana, India – 500038