1. Overview
Habuild ("we", "our", "the extension") is a Chrome extension that helps you build and track daily habits. We collect only the data necessary to provide the service. We do not sell, rent, or share your personal data with third-party advertisers.
2. What We Collect
| Data | Why | Where stored |
|---|---|---|
| Name, email address, profile picture | Identify your account via Google Sign-In | Habuild backend (MongoDB) |
| Habit names and completion history | Track streaks and display your progress | Habuild backend (MongoDB) |
| Water intake count | Power the hydration reminder feature | Device only (chrome.storage.local) |
| Reminder preferences & quiet hours | Schedule wellness notifications per your settings | Device only (chrome.storage.local) |
| JWT access & refresh tokens | Authenticate API requests without re-login | Device only (chrome.storage.local) |
| Focus session durations and break logs | Track productivity and wellness patterns | Habuild backend (MongoDB) |
3. What We Do Not Collect
- Browsing history or the URLs of pages you visit
- Page content from any website you browse
- Keystrokes, form inputs, or clipboard contents
- Any data from third-party websites
The content script injected into web pages by the extension currently performs no actions and collects no data.
4. How We Use Your Data
- Authenticate you and maintain your session
- Store and retrieve your habits, streaks, and completion history
- Deliver wellness reminders (hydration, stretch, screen breaks)
- Calculate streak ranks and send rank-up notifications
- Send smart nudges (streak danger alerts, weekly digest)
- Process referral rewards when a friend signs up using your code
5. Chrome Permissions Explained
| Permission | Why it is needed |
|---|---|
| storage | Save auth tokens, preferences, and daily water count on your device |
| alarms | Schedule recurring wellness and habit reminders in the background |
| notifications | Show reminder and nudge notifications when alarms fire |
| identity | Enable "Sign in with Google" via Chrome's OAuth flow |
| scripting | Required for side panel and popup functionality |
| sidePanel | Render the Habuild UI as a Chrome side panel |
| https://*/* | Make authenticated API requests to the Habuild backend |
6. Data Retention
Account data is retained for as long as your account is active. You may request deletion of your account and all associated data by contacting us at the email below. Device-local data (chrome.storage.local) is cleared when you uninstall the extension or log out.
7. Third-Party Services
- Google Sign-In — we receive your name, email, and profile picture from Google during authentication. Google's privacy policy applies: policies.google.com/privacy
We do not use any advertising, analytics, or tracking SDKs.
8. Security
All communication between the extension and the Habuild backend is encrypted via HTTPS. Tokens are stored only in chrome.storage.local and are never exposed to web page scripts.
9. Children's Privacy
Habuild is not directed at children under 13. We do not knowingly collect personal information from children under 13.
10. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the extension after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or data deletion requests, contact us at:
mantosh.kumar@habuild.in