Privacy Policy
Effective and last updated: July 15, 2026
Important Notice
Habit of Living is a wellness platform and is not an emergency service. If you are in immediate danger or considering self-harm, call your local emergency number (e.g., 911 in the U.S.) or contact the 988 Suicide & Crisis Lifeline (call/text 988 in the U.S.).
This Privacy Policy explains how Camus LLC, doing business as Habit of Living (also referred to as "Camus," "we," "us," or "our"), collects, uses, discloses, retains, and protects information when you access or use our websites, mobile applications, and related services (collectively, the "Service"). This policy is incorporated into our Terms of Use. Our separate, prominently posted Consumer Health Data Privacy Policy supplements this policy for consumer health data regulated by applicable state law.
1. Key Points (Plain-English Summary)
- We collect information you provide (e.g., account details, journal entries) and information collected automatically (e.g., device and usage data).
- Wellness entries, mood data, manager messages, and similar information may be sensitive information or consumer health data under some laws. Unless we sign a separate written agreement, the Service is not HIPAA-covered.
- We use information to operate the Service, personalize experiences, support safety, prevent fraud, and improve the Service.
- We share information with service providers (e.g., hosting, analytics, AI vendors) and as required by law or to protect safety.
- We do not sell personal information or consumer health data. Depending on how you use the Service and what integrations are enabled, some data sharing may be considered "sharing" for targeted advertising under certain laws.
- We do not knowingly use consumer health data for targeted advertising. If a future feature requires consent or written authorization for consumer health data sharing or sale, we will request it first.
- See our Consumer Health Data Privacy Policy for categories, sources, purposes, recipient categories, consent withdrawal, deletion, recipient lists, and appeals.
- You may have privacy rights depending on where you live (e.g., access, deletion, correction, opt-out of targeted advertising).
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, username, password (hashed), and related identifiers.
- Authentication and quick-access data: security settings, login or remember-me tokens, and whether device biometric quick access is enabled. The Service receives an authentication token after device-level biometric verification; it is not designed to receive or store your fingerprint, face geometry, or biometric template.
- Profile and preferences: goals, settings, reminders, wellness preferences, and communication preferences.
- Content you submit: journal entries, mood check-ins, habit data, messages, feedback, reviews, and other content you provide.
- Manager, program, and intake data: information you submit through assessments, onboarding flows, managed care or manager features, program signups, check-ins, and related support workflows.
- Payment and transactional data: subscription status, transaction metadata, billing history, and (if applicable) shipping information for rewards. Payment processing is generally handled by third-party processors (e.g., Apple/Google app stores and/or payment vendors), who may collect payment card details directly.
- Information about others: any personal information you choose to submit about another person, such as names, relationships, messages, or context you include in journal entries, prompts, or support requests.
- Support communications: messages you send to us, including support tickets, emails, and in-app communications.
2.2 Information Collected Automatically
- Device and connection data: IP address, device identifiers, operating system, browser type, app version, language, and network information.
- Location-related data: approximate location inferred from IP address or device/network data, and precise location only if a feature requests it and you allow it.
- Usage data: pages/screens viewed, features used, clicks, timestamps, session duration, crash logs, and diagnostic data.
- Cookies and similar technologies: cookies, pixels, SDKs, local storage, and similar tools to operate the Service, remember settings, understand performance, and (where enabled) measure campaigns.
2.3 Sensitive Information
Because the Service involves wellness and self-reflection, information you provide may be considered "sensitive" in some jurisdictions (for example, health or mental health-related information). You control what you choose to submit. Please avoid submitting highly sensitive information you do not want processed as described here.
2.4 Not HIPAA-Covered
Unless we expressly agree otherwise in a written contract, Habit of Living is not a "covered entity" or "business associate" under HIPAA. This means information you submit to the Service is generally not treated as protected health information (PHI) under HIPAA.
2.5 Consumer Health Data and Sensitive Personal Information
Depending on where you live and how you use the Service, information related to wellness, mental health, habits, symptoms, treatment, medication, social or behavioral interventions, or attempts to obtain health-related services may be considered "consumer health data," "sensitive personal information," or a similar regulated category.
- Categories: mood check-ins, journal content, goals, symptoms or conditions you voluntarily share, medication or treatment references, manager or support messages, program/intake responses, reminders, inferences generated from your use of the Service, and precise location if you enable a health-related feature that requires it.
- Sources: you, your device, your interactions with the Service, connected services you choose to enable, staff or contractors supporting requested features, and service providers acting on our behalf.
- Purposes: providing requested features, personalization, reminders, account support, safety and security, fraud prevention, compliance, troubleshooting, analytics, and improving the Service as described in this Privacy Policy.
- Sharing: service providers and processors, AI vendors, assigned managers or support personnel where a requested feature involves human support, legal or safety recipients where permitted or required, parties involved in a business transfer subject to applicable law, and third parties you direct us to share with.
We do not sell consumer health data. We do not knowingly share consumer health data for cross-context behavioral advertising. Where applicable law requires separate consent or written authorization to collect, use, share, or sell consumer health data, we will seek it before that processing.
3. How We Use Information
We may use information for the following purposes:
- Provide and operate the Service: create accounts, authenticate users, deliver features, process subscriptions, and fulfill rewards (if offered).
- Personalization: tailor prompts, reminders, and content suggestions, including via AI-assisted features where enabled.
- Customer support: respond to your requests, troubleshoot, and provide service communications.
- Safety and security: prevent fraud, abuse, and unauthorized access; enforce our Terms; and protect users and the public.
- Sensitive-data controls: process sensitive information and consumer health data as reasonably necessary for the Service, with additional consent where required by applicable law.
- Research and improvement: analyze usage trends and improve features, including using de-identified or aggregated data.
- Marketing and communications: send service-related messages; and, where permitted, send promotional communications you can opt out of.
- Legal compliance: comply with law, respond to legal requests, and protect rights and safety.
4. AI Features and Processing
The Service may include AI-assisted features (such as prompts, summaries, or suggestions). To provide these features, your inputs (and limited related context) may be processed by AI vendors and related service providers under contract.
- Vendor processing: AI vendors and related service providers may process, transmit, and log inputs, outputs, and related metadata as needed to provide, secure, debug, and support the feature, subject to contractual and technical safeguards we use for service providers.
- Human review: Certain features (e.g., a manager-supervised experience) may involve review by trained staff or contractors to deliver the feature, provide support, and maintain quality and safety.
- Model improvement: We do not use identifiable health, journal, or therapy content to train general-purpose AI models. We may use information that has been de-identified under an applicable documented standard, or aggregate operational information that does not identify an individual, to improve the Service.
- Information about others: Please do not submit information about another person unless you have all rights and permissions needed for us and our service providers to process it as described here.
7. Data Retention
We retain personal information for as long as reasonably necessary to provide the Service and for legitimate business purposes such as security, fraud prevention, recordkeeping, and legal compliance. Retention periods vary based on the type of information, how it is used, and legal requirements.
If you delete your account, we will delete or de-identify personal information from active systems within a reasonable period, subject to backups, security logs, records needed to prevent fraud or abuse, unresolved disputes, payment/tax records, and legal obligations.
We may retain de-identified or aggregated information for longer periods. Where we de-identify information, we maintain and use it in de-identified form and do not attempt to re-identify it except to test safeguards, investigate security issues, or as otherwise permitted by law.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your login credentials, devices, and communications with us. Contact us promptly if you believe your account or information has been accessed without authorization.
Depending on the system and feature, safeguards may include:
9. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps.
Users between 13 and 17 may use the Service only with permission from a parent or legal guardian. We may delete or restrict accounts where we believe the age or consent requirements are not met.
10. International Transfers
We may process and store information in the United States and other countries. Laws in those locations may differ from the laws where you live. Where applicable law requires a transfer mechanism or separate consent, we will use an appropriate contractual or legal safeguard or obtain that consent; use of the Service does not waive a nonwaivable transfer right.
11. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information; to opt out of targeted advertising; and to limit certain processing. You may exercise rights by emailing privacy@habitofliving.com. We may need to verify your identity before fulfilling certain requests.
Where consumer health data laws apply, you may also have rights to confirm whether we collect, share, or sell consumer health data; access or delete consumer health data; withdraw consent for certain processing; and request a list of third parties or affiliates, with available contact information, with whom consumer health data has been shared or sold. Instructions are in our Consumer Health Data Privacy Policy.
11.1 California (CCPA/CPRA) Notice
In the preceding 12 months, depending on use of the Service, we may have collected the categories described in this policy: identifiers and account records; customer records and payment/subscription information; internet, device, and network activity; approximate geolocation; audio, visual, and message content; professional or employment-related information for provider relationships; inferences; and sensitive personal information, including account credentials and health-related content a user chooses to provide. We obtain these categories from the sources described in Sections 2.1 and 2.2, use them for the purposes in Section 3, and may disclose them for business purposes to the recipient categories in Section 5. We retain each category under the criteria in Section 7.
- Rights: know/access, delete, correct, opt out of sale/share, limit use of sensitive personal information (where applicable), and non-discrimination.
- Sensitive information: we use sensitive personal information only for requested services and other purposes permitted without a right to limit, unless we first provide any legally required notice and control. We do not use it to infer characteristics for advertising.
- Do Not Sell or Share: we do not sell personal information. You may submit an opt-out request at privacy@habitofliving.com. Targeted-ad tools must remain disabled where GPC handling is legally required until that handling is implemented and verified.
11.2 Other U.S. State Privacy Rights
Many U.S. states provide similar rights (access, deletion, correction, portability, opt-out of targeted advertising). Some states also provide an appeal process if a request is denied. If we deny a request, you may appeal by replying to our response email and requesting an appeal.
11.3 Verification, Authorized Agents, and Appeals
We may ask for information reasonably necessary to verify your identity and authority to make a request. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and may ask you to verify your identity directly. If we deny a request and applicable law provides an appeal right, you may appeal by replying to our response or emailing us with "Privacy Appeal" in the subject line.
11.4 Rewards and Financial Incentives
Ordinary in-product points and rewards are not intended as payment for selling or sharing personal information. If we offer a program that qualifies as a financial incentive or price/service difference under California law, we will provide a separate notice describing its material terms, the categories implicated, how the benefit is reasonably related to the value of the data using a disclosed good-faith method, how to opt in, and how to withdraw before enrollment. Participation will be voluntary, and withdrawal will not affect an unrelated Service.
11.5 Marketing Communications
You can opt out of promotional emails by using the unsubscribe link (where present) or by contacting us. Service-related messages (e.g., receipts, security alerts) are not promotional and may still be sent.
12. Data Breach Notification
If we become aware of a security incident affecting personal information, we will evaluate it and provide notices as required by applicable law. If an incident involves unsecured, individually identifiable health information or consumer health data, we will evaluate obligations under the FTC Health Breach Notification Rule, state consumer health privacy laws, and state data breach notification laws, including notices to affected users, regulators, and media where required.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above. If changes are material, we may provide additional notice (for example, via in-app notice or email) as required by law.
14. Contact Us
For privacy questions or requests, contact us:
Camus LLC dba Habit of Living
1141 N. Martin Luther King Jr. Drive
Milwaukee, WI 53203, USA