Privacy Policy
Our Core Privacy Commitment: At HoneyTrack, your privacy is fundamental to our design philosophy of Warm Minimalism. We believe personal wellness reflections and daily habit routines are private and sensitive. We do not sell your personal data. This document outlines how CrossTech Solutions collects, uses, and safeguards your information.
1. Introduction & Scope
Legal Operating Entity: This Privacy Policy ("Policy") governs the privacy practices of CrossTech Solutions ("Company", "we", "us"), operating the brand Conscious Living and its flagship product HoneyTrack ("HoneyTrack" or "Service").
Cross-Platform Scope: This Policy applies to all users accessing HoneyTrack via iOS, Android, Web platforms, or associated backend APIs. By registering or using the Service, you consent to the data collection and usage practices detailed herein.
2. Categories of Information We Collect
Account Credentials & Profile: When setting up an account or cloud sync, we collect your email address, display name, username handle (`@handle`), avatar image, and custom profile bio.
Habit, Routine & Reflection Data: Your daily Hero tasks, Routine checklists, inline notes, streak counters, protected streak freezes (6 monthly freezes), mood ratings (e.g., Happy, Peaceful, Fantastic, Tired), diary entries, and 365-day YTD activity grids.
Technical & Device Telemetry: Device hardware model, operating system version, browser type, installation UUIDs, theme selections (Sky Blue, Amber Gold, Blush Warm, Mono), light/dark mode state, and system crash diagnostics.
Application Permissions: Local storage access for offline caching, optional camera/gallery access for avatar uploads, and local notification permissions for routine reminders.
3. Purpose & Legal Basis for Data Processing
Core Service Delivery: Processing habit completions, calculating unbroken streaks, managing streak freeze quotas, and rendering performance analytics.
Intelligent Carry-Forward: Detecting unfinished Hero tasks from yesterday and offering smart carry-forward prompts for today's agenda.
AI Reflection Synthesis: Synthesizing unstructured diary entries into empathetic AI reflection letters ("AI Letters") via integrated AI models.
Cloud Synchronization & Security: Authenticating accounts via Firebase Auth, securing cloud database Firestore rules, and enforcing per-user data isolation.
Regulatory Compliance: Adhering to obligations under the Digital Personal Data Protection (DPDP) Act 2023 and Information Technology Act 2000.
4. Artificial Intelligence (AI) Data Handling & Safeguards
Ephemeral Groq API Processing: When you request an AI reflection letter, your diary entry text is transmitted via TLS 1.3 to Groq's high-speed inference engines for immediate text synthesis.
Strict Non-Training Guarantee: Your personal diary notes and habit data are processed strictly in memory. We never sell, share, or allow third-party AI vendors to retain or use your personal content to train public foundation models.
User Choice & Offline Option: You can manage your Groq API key settings or use HoneyTrack in a completely local, offline-first mode at any time.
5. Cookies, Storage & Tracking Technologies
Offline-First Storage: We use browser `LocalStorage` and `IndexedDB` on device to store your local habit database, streak counts, and diary drafts locally.
Authentication Session Tokens: Encrypted session tokens are managed via Firebase Authentication to keep you securely signed in.
Zero Ad Trackers: We do not employ third-party advertising pixels, behavioral tracking scripts, or ad network cookies.
6. Data Sharing & Third-Party Service Providers
No Data Monetization: We do not sell, rent, or trade your personal data under any circumstances.
Google Firebase (Cloud Partner): Cloud authentication, database storage, and backup hosting. Primary Data Center Region: India / Asia-South1.
Groq Inc. (AI Partner): Ephemeral execution of AI reflection models under zero data retention terms.
Legal Authorities: Disclosures made strictly in response to valid court orders or law enforcement requests mandated by Indian law.
7. Data Retention & Account Lifecycle
Active Accounts: Habit and reflection records remain available for as long as your account is active.
Instant Danger Zone Wiping: You can permanently purge all local data, erase cloud database entries, and delete your account profile at any time using the Danger Zone options in Settings.
Backup Expiration: Deleted data is purged immediately from active systems and completely wiped from encrypted system backups within 30 days.
8. Security Architecture & Safeguards
Data in Transit: Encrypted using industry-standard Transport Layer Security (TLS 1.3 / HTTPS).
Data at Rest: Encrypted using AES-256 bit encryption in Google Firebase Firestore.
Per-User Security Boundaries: Strict Firestore Security Rules ensure only authenticated owners can read or modify their data.
9. Your Rights & Data Control
Right to Access & Review: View all your personal details, streak logs, diary reflections, and analytics directly within the app.
Right to Correction & Update: Modify your display name, username handle, profile avatar, bio, and custom templates at any time.
Right to Erasure & Deletion: Permanently wipe your account and data via the Danger Zone setting or by contacting our Grievance Officer.
Right to Withdraw Consent: Revoke cloud sync or notification permissions at any time in device settings.
10. Children's Privacy
Age Restriction: HoneyTrack is intended for individuals aged 18 and above (or 13 and above with verifiable parental/legal guardian consent). We do not knowingly collect personal data from children under 13.
11. Third-Party Links & External Services
External References: HoneyTrack may contain links to external sites (such as `mindspace.consciousliving.app`). This Policy applies solely to HoneyTrack and CrossTech Solutions.
12. Policy Amendments & Updates
Revision Tracking: We may update this Privacy Policy to reflect app enhancements or legal changes. Updates will be published here with a revised Effective Date and Version number.
13. Grievance Redressal Mechanism & Contact Information
In compliance with the Information Technology Act 2000, Information Technology Rules 2021, and DPDP Act 2023, CrossTech Solutions has appointed a Grievance Redressal Officer for privacy concerns.