Habit of Living is a wellness platform and is not an emergency service. If you are in immediate danger or considering self-harm, call your local emergency number (e.g., 911 in the U.S.) or contact the 988 Suicide & Crisis Lifeline (call/text 988 in the U.S.).
This Privacy Policy explains how Habit of Living (also referred to as "Camus," "we," "us," or "our") collects, uses, discloses, and protects information when you access or use our websites, mobile applications, and related services (collectively, the "Service"). This Privacy Policy is incorporated into our Terms of Use.
1. Key Points (Plain-English Summary)
We collect information you provide (e.g., account details, journal entries) and information collected automatically (e.g., device and usage data).
Wellness entries, mood data, manager messages, and similar information may be sensitive information or consumer health data under some laws. Unless we sign a separate written agreement, the Service is not HIPAA-covered.
We use information to operate the Service, personalize experiences, support safety, prevent fraud, and improve the Service.
We share information with service providers (e.g., hosting, analytics, AI vendors) and as required by law or to protect safety.
We do not knowingly sell personal information or consumer health data. Depending on how you use the Service and what integrations are enabled, some data sharing may be considered "sharing" for targeted advertising under certain laws.
We do not knowingly use consumer health data for targeted advertising. If a future feature requires consent or written authorization for consumer health data sharing or sale, we will request it first.
You may have privacy rights depending on where you live (e.g., access, deletion, correction, opt-out of targeted advertising).
2. Information We Collect
2.1 Information You Provide
Account information: name, email address, username, password (hashed), and related identifiers.
Profile and preferences: goals, settings, reminders, wellness preferences, and communication preferences.
Content you submit: journal entries, mood check-ins, habit data, messages, feedback, reviews, and other content you provide.
Manager, program, and intake data: information you submit through assessments, onboarding flows, managed care or manager features, program signups, check-ins, and related support workflows.
Payment and transactional data: subscription status, transaction metadata, billing history, and (if applicable) shipping information for rewards. Payment processing is generally handled by third-party processors (e.g., Apple/Google app stores and/or payment vendors), who may collect payment card details directly.
Information about others: any personal information you choose to submit about another person, such as names, relationships, messages, or context you include in journal entries, prompts, or support requests.
Support communications: messages you send to us, including support tickets, emails, and in-app communications.
2.2 Information Collected Automatically
Device and connection data: IP address, device identifiers, operating system, browser type, app version, language, and network information.
Location-related data: approximate location inferred from IP address or device/network data, and precise location only if a feature requests it and you allow it.
Usage data: pages/screens viewed, features used, clicks, timestamps, session duration, crash logs, and diagnostic data.
Cookies and similar technologies: cookies, pixels, SDKs, local storage, and similar tools to operate the Service, remember settings, understand performance, and (where enabled) measure campaigns.
2.3 Sensitive Information
Because the Service involves wellness and self-reflection, information you provide may be considered "sensitive" in some jurisdictions (for example, health or mental health-related information). You control what you choose to submit. Please avoid submitting highly sensitive information you do not want processed as described here.
2.4 Not HIPAA-Covered
Unless we expressly agree otherwise in a written contract, Habit of Living is not a "covered entity" or "business associate" under HIPAA. This means information you submit to the Service is generally not treated as protected health information (PHI) under HIPAA.
2.5 Consumer Health Data and Sensitive Personal Information
Depending on where you live and how you use the Service, information related to wellness, mental health, habits, symptoms, treatment, medication, social or behavioral interventions, or attempts to obtain health-related services may be considered "consumer health data," "sensitive personal information," or a similar regulated category.
Categories: mood check-ins, journal content, goals, symptoms or conditions you voluntarily share, medication or treatment references, manager or support messages, program/intake responses, reminders, inferences generated from your use of the Service, and precise location if you enable a health-related feature that requires it.
Sources: you, your device, your interactions with the Service, connected services you choose to enable, staff or contractors supporting requested features, and service providers acting on our behalf.
Purposes: providing requested features, personalization, reminders, account support, safety and security, fraud prevention, compliance, troubleshooting, analytics, and improving the Service as described in this Privacy Policy.
Sharing: service providers and processors, AI vendors, assigned managers or support personnel where a requested feature involves human support, legal or safety recipients where permitted or required, parties involved in a business transfer subject to applicable law, and third parties you direct us to share with.
We do not sell consumer health data. We do not knowingly share consumer health data for cross-context behavioral advertising. Where applicable law requires separate consent or written authorization to collect, use, share, or sell consumer health data, we will seek it before that processing.
3. How We Use Information
We may use information for the following purposes:
Provide and operate the Service: create accounts, authenticate users, deliver features, process subscriptions, and fulfill rewards (if offered).
Personalization: tailor prompts, reminders, and content suggestions, including via AI-assisted features where enabled.
Customer support: respond to your requests, troubleshoot, and provide service communications.
Safety and security: prevent fraud, abuse, and unauthorized access; enforce our Terms; and protect users and the public.
Sensitive-data controls: process sensitive information and consumer health data as reasonably necessary for the Service, with additional consent where required by applicable law.
Research and improvement: analyze usage trends and improve features, including using de-identified or aggregated data.
Marketing and communications: send service-related messages; and, where permitted, send promotional communications you can opt out of.
Legal compliance: comply with law, respond to legal requests, and protect rights and safety.
4. AI Features and Processing
The Service may include AI-assisted features (such as prompts, summaries, or suggestions). To provide these features, your inputs (and limited related context) may be processed by AI vendors and related service providers under contract.
Vendor processing: AI vendors and related service providers may process, transmit, and log inputs, outputs, and related metadata as needed to provide, secure, debug, and support the feature, subject to contractual and technical safeguards we use for service providers.
Human review: Certain features (e.g., a manager-supervised experience) may involve review by trained staff or contractors to deliver the feature, provide support, and maintain quality and safety.
Model improvement: We may use de-identified, aggregated, or otherwise non-identifying information to improve our Service and related AI systems. If we use identifiable content for model improvement, we will do so only where permitted by law and (where required) with your consent, and you may request an opt-out by emailing contact@habitofliving.com.
Information about others: Please do not submit information about another person unless you have all rights and permissions needed for us and our service providers to process it as described here.
5. How We Share Information
We may share information in the following ways:
Service providers: vendors who help us operate the Service (e.g., hosting, analytics, customer support, email delivery, AI vendors). They are authorized to process information only on our instructions and subject to contractual obligations.
Legal and safety: to comply with law, respond to lawful requests, enforce our Terms, investigate fraud, and protect safety and rights.
Business transfers: in connection with a merger, acquisition, financing, or sale of assets (subject to confidentiality and applicable law).
With your direction: when you choose to connect third-party services or otherwise direct us to share information.
De-identified / aggregated data: we may share information that cannot reasonably be used to identify you.
5.1 Consumer Health Data Sharing Limits
For consumer health data, we share only as described in this Privacy Policy, such as with service providers and processors, AI vendors, assigned managers or support personnel for requested features, legal or safety recipients where permitted or required, parties involved in a business transfer subject to applicable law, and third parties you direct us to share with. We do not sell consumer health data or knowingly disclose it for targeted advertising, and we will seek any additional consent or authorization required by applicable law.
5.2 Advertising, Analytics, and "Do Not Sell or Share"
We may use analytics tools and, where enabled, advertising/attribution tools that collect information via cookies, SDKs, pixels, or similar technologies. Under some privacy laws, certain disclosures of information for cross-context behavioral advertising may be considered "sharing" (even if no money changes hands).
Do Not Sell or Share: We do not knowingly sell personal information. You may opt out of "sharing" for targeted advertising by emailing contact@habitofliving.com and (where available) using in-app privacy controls.
Global Privacy Control (GPC): If we detect a valid GPC signal in a browser context where the Service is accessed, we will treat it as an opt-out request for applicable jurisdictions.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
6. Cookies and Similar Technologies
We and our partners may use cookies, pixels, SDKs, and similar technologies to operate the Service, remember preferences, measure performance, and detect fraud. You can control cookies through browser settings. Note that disabling cookies may affect functionality.
7. Data Retention
We retain personal information for as long as reasonably necessary to provide the Service and for legitimate business purposes such as security, fraud prevention, recordkeeping, and legal compliance. Retention periods vary based on the type of information, how it is used, and legal requirements.
If you delete your account, we will delete or de-identify personal information from active systems within a reasonable period, subject to backups, security logs, records needed to prevent fraud or abuse, unresolved disputes, payment/tax records, and legal obligations.
We may retain de-identified or aggregated information for longer periods. Where we de-identify information, we maintain and use it in de-identified form and do not attempt to re-identify it except to test safeguards, investigate security issues, or as otherwise permitted by law.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your login credentials, devices, and communications with us. Contact us promptly if you believe your account or information has been accessed without authorization.
Encryption in Transit
Access Controls
Regular Audits
Data Monitoring
9. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps.
Users between 13 and 17 may use the Service only with permission from a parent or legal guardian. We may delete or restrict accounts where we believe the age or consent requirements are not met.
10. International Transfers
We may process and store information in the United States and other countries. Laws in those locations may differ from the laws where you live. By using the Service, you consent to these transfers where permitted.
11. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information; to opt out of targeted advertising; and to limit certain processing. You may exercise rights by emailing contact@habitofliving.com. We may need to verify your identity before fulfilling certain requests.
Where consumer health data laws apply, you may also have rights to confirm whether we collect, share, or sell consumer health data; access or delete consumer health data; withdraw consent for certain processing; and request a list of categories of third parties or affiliates with whom consumer health data has been shared or sold.
11.1 California (CCPA/CPRA) Notice
Categories collected: identifiers, internet/network activity, device data, inferences, and user-submitted content (which may be sensitive).
Purposes: operate the Service, personalize, security, analytics, marketing, legal compliance.
Rights: know/access, delete, correct, opt out of sale/share, limit use of sensitive personal information (where applicable), and non-discrimination.
Do Not Sell or Share: you may submit an opt-out request by emailing us; we also honor GPC where applicable.
11.2 Other U.S. State Privacy Rights
Many U.S. states provide similar rights (access, deletion, correction, portability, opt-out of targeted advertising). Some states also provide an appeal process if a request is denied. If we deny a request, you may appeal by replying to our response email and requesting an appeal.
11.3 Verification, Authorized Agents, and Appeals
We may ask for information reasonably necessary to verify your identity and authority to make a request. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and may ask you to verify your identity directly. If we deny a request and applicable law provides an appeal right, you may appeal by replying to our response or emailing us with "Privacy Appeal" in the subject line.
11.4 Rewards and Financial Incentives
If we offer points, rewards, discounts, or similar benefits, participation is voluntary. These programs may be considered a financial incentive or loyalty program under some privacy laws because they may involve collecting, retaining, or using personal information. The value of the benefit is reasonably related to the value of the information, engagement, and relationship associated with the program. You may opt out by not participating or by contacting us, but deleting required information may affect eligibility for pending rewards.
11.5 Marketing Communications
You can opt out of promotional emails by using the unsubscribe link (where present) or by contacting us. Service-related messages (e.g., receipts, security alerts) are not promotional and may still be sent.
12. Data Breach Notification
If we become aware of a security incident affecting personal information, we will evaluate it and provide notices as required by applicable law. If an incident involves unsecured, individually identifiable health information or consumer health data, we will evaluate obligations under the FTC Health Breach Notification Rule, state consumer health privacy laws, and state data breach notification laws, including notices to affected users, regulators, and media where required.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above. If changes are material, we may provide additional notice (for example, via in-app notice or email) as required by law.