Privacy Policy for Habit Oracle
Effective Date: August 7, 2026
Last Updated: August 7, 2026
Published by: VenX Technologies LLC ("VenX Technologies", "we", "us", or "our")
Privacy Email: privacy@habitoracle.com
1. Introduction & Core Commitment
VenX Technologies built Habit Oracle as a privacy-first RPG habit tracking and productivity application for users of all ages. We believe that tracking your habits, building discipline, and exploring gamified quests should never require sacrificing your privacy or personal information. We take child privacy with the utmost seriousness. Habit Oracle is designed to comply fully with the Children’s Online Privacy Protection Act (COPPA), the General Data Protection Regulation for Children (GDPR-K), Apple’s App Store Review Guidelines (Sections 1.3 and 5.1.1), and applicable international child data protection laws.
2. Age Classification & Protected Mode (COPPA Compliance)
When first launching Habit Oracle, every user completes an initial Age Gate. The user selects their birth month and year to determine their age category (Child: Under 13, Teen: 13–17, or Adult: 18+). Crucial Privacy Guarantee: The exact Date of Birth is NEVER stored, logged, or transmitted anywhere. It is used instantaneously on the device to derive the age category, and is immediately discarded.
A. Protected Mode for Children Under 13
If a user is classified as under 13 years of age, Habit Oracle automatically operates in Protected Mode: Zero Personal Data Collection: We do not collect, request, store, or transmit any personally identifiable information (PII) from children under 13 (including names, email addresses, phone numbers, real-world locations, or persistent device identifiers for tracking). 100% Local On-Device Sandbox: All habit entries, character stats, journal notes, and game progress are stored exclusively in a local sandbox database on the user's physical device. No Account Creation or Sign In: Children under 13 cannot create accounts, sign in with Apple, or submit email addresses. No Cloud Sync or Server Communication: Network requests and CloudKit synchronization are strictly blocked for child accounts. No Third-Party Analytics or Advertising: We do not include third-party advertising SDKs, tracking pixels, behavioral tracking frameworks, or analytics services in Habit Oracle. Parental Gate for External Links: Any attempt to access external links (such as privacy policy web pages or support emails) requires solving an interactive Parental Gate (a multi-step math problem) to ensure a parent or legal guardian is present.
3. Information We Collect for Users Aged 13 and Older
For users who are 13 years of age or older, Habit Oracle offers optional enhanced features, such as multi-device synchronization and Sign in with Apple.
A. Account & Authentication Information (Optional)
Sign in with Apple: If you choose to sign in with Apple, Apple provides a unique anonymous user identifier (e.g., 001234.a1b2c3...). If you grant permission, Apple may share your display name or email address (or a Relay email address provided by Apple’s "Hide My Email" service).
Sign in with Google: If you choose to sign in with Google, Google provides your basic account information (display name, email address, and unique Google account ID) to authenticate your account. We do not request access to your Google Drive, Contacts, Google Calendar, or private Google data.
Email Sign-in: If you choose to sign in with your email address, you provide your email address and an optional hero display name. This information is used solely to authenticate your session and personalize your profile. We never send promotional spam or share your email with third parties.
Session Credentials: Authentication tokens are stored locally on your device in secure iOS storage (Keychain/UserDefaults) to maintain your login session.
B. App Usage & Quest Data (Stored in Private CloudKit)
If you enable iCloud Sync (available to users 13+):
Your habit names, categories, streak history, RPG level, XP, inventory items, and mountain summit logs are stored in your personal, private Apple CloudKit container (iCloud.com.venxtechnologies.HabitOracle).
World Boss Raid Events: For users aged 13 and older, shared boss health pool updates during optional World Boss Raid events are synchronized anonymously via Apple's CloudKit Public Database. No personal profile information, real names, or user-to-user communications are transmitted or attached to these event updates.
VenX Technologies does NOT own, control, view, or sell your private CloudKit data. It remains encrypted within your personal Apple iCloud account.
4. How We Use Information
Any data stored by Habit Oracle is used solely to provide and maintain core application features: Calculating your habit completion streaks, avatar level progress, and XP. Rendering your active companion familiars, inventory items, and dungeon boss combat logs. Synchronizing progress across your personal devices via Apple CloudKit (for accounts 13+). Rendering local widgets on your iOS Home Screen and Lock Screen. We NEVER: Sell, rent, lease, or monetize your data to advertisers, data brokers, or third parties. Build advertising profiles or track your activity across third-party websites or applications. Access your location, camera roll, contacts, or microphone without explicit, single-use permission.
5. Third-Party Services & SDKs
Habit Oracle maintains an extremely minimal third-party footprint: Apple Frameworks Only: Habit Oracle is built natively using Apple frameworks (SwiftUI, SwiftData, WidgetKit, StoreKit, and CloudKit). No Advertising SDKs: We do not show third-party ads or include advertising SDKs (e.g., Google AdMob, Unity Ads, Meta Audience Network). No Third-Party Analytics Tracking: We do not use third-party analytics trackers (e.g., Firebase Analytics, Adjust, AppsFlyer, Mixpanel).
6. Data Storage, Security, and Retention
Local Storage: All app data for Protected Mode (Child) accounts is stored on the physical device using Apple's encrypted Application Support storage. Data remains on your device until you delete the app or use the in-app reset function. Data Security: We leverage iOS native sandboxing, Keychain encryption, and Apple's secure infrastructure to guard your data against unauthorized access. Export Rights: Users can export their complete data at any time in .json or .csv format directly from Settings > Data Backup & Export.
7. Account Deletion & Data Removal Rights
We respect your right to completely erase your data at any time:
A. In-App Deletion
You can permanently delete all app data at any time inside Habit Oracle:Open Settings (gear icon). Scroll to Legal & Privacy -> Tap Delete Account / Reset Profile. Confirm deletion. This immediately wipes all local SwiftData databases, resets the Age Gate, clears session Keychain keys, and restores the app to factory install state.
B. Cloud Data Removal (13+)
To remove CloudKit sync data:Open iOS Settings > tap your Apple ID > iCloud > Saved to iCloud / Manage Storage. Select Habit Oracle and tap Delete Data from iCloud.
C. Parental Rights (COPPA)
Parents or legal guardians of children under 13 have the right to: Review or delete any data stored locally on their child's device by selecting Reset Profile in Settings or uninstalling the app. Contact us at privacy@habitoracle.com with any questions regarding child data protection. Because child accounts do not collect PII or store data on remote servers, we do not hold identifiable child records on external databases.
8. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect new features or legal requirements. If we make material changes to how child data is handled, we will notify users through an in-app notice prior to the change taking effect. The "Effective Date" at the top of this policy will reflect the most recent revision.
9. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our child privacy protections, please contact us:
VenX Technologies LLC
Email: privacy@habitoracle.com
Website: https://habitoracle.com