Last updated February 18, 2026

Privacy Policy

How HabitHelm handles account data, integrations, and security controls.

Overview

HabitHelm is designed with privacy-first defaults. This policy explains what data is processed, why it is processed, and which controls are available to users.

Data categories

HabitHelm may process:

  • account identifiers (for example user ID and sign-in provider)
  • profile and settings data (such as birthday, height, weight, and preferences)
  • diary entries and recipe records you create
  • integration metadata from connected providers (for example Strava or Withings)

Why data is processed

Data is used to:

  • deliver core app functionality
  • calculate user-visible features such as BMR/TDEE estimates
  • keep integrations synchronized
  • improve reliability and security monitoring

Security controls

HabitHelm uses defense-in-depth patterns including:

  • authentication and scoped authorization checks
  • server-side validation for API inputs
  • least-privilege defaults in backend access layers

Data sharing

HabitHelm does not sell personal data. Data may be processed by infrastructure and integration providers required to operate the service.

Data retention and deletion

Data is retained as needed to provide the service and meet legal obligations. Users can request deletion of account data through support channels.

Contact

Privacy questions can be sent to privacy@habithelm.me.

Medical disclaimer

HabitHelm provides informational guidance and is not medical advice. Consult qualified professionals for medical or dietary concerns.