01Introduction
This policy explains what data Familiar (the "Service") collects, why, where it goes, and the controls you have over it. Familiar is provided by Familiar Habits, which is the data controller for the data described here.
The short version of our approach: your data is yours. Familiar stores it to run features you use, shows it back to you as your own history and insights, and keeps it out of everyone else's hands. We have tried to write this policy in plain language; if anything is unclear, please ask us.
02What Familiar collects
Here is what lives in your Familiar account, grouped by what it is for:
- Account. Your email address and password, used only to sign you in and managed by our authentication provider (Supabase), plus the name you choose to show in the app and your timezone. Optionally, a birthday month and day if you choose to share one so Familiar can mark the day — the year is never asked for or stored, and you can clear it at any time.
- Schedule and calendar. Calendar items you create, when your day starts and ends, and any time off you set.
- Habits. Which habits you have turned on, your habit logs (like water, food, movement, and sleep), and your streaks.
- Device health data (optional, off by default). If you connect your device's health service, Familiar reads your sleep sessions and daily step totals — to offer to prefill your sleep log, and to hold back movement reminders when you have already been moving. It is read only if you connect it, it stays in your account, and it is covered by the stricter health-data standard in section 03.
- Energy and mood. The energy and mood check-ins you log, kept as your own history so the app can meet you where you are.
- Journal. Your journal entries and how you interact with journal prompts (accept, skip, hide).
- Captures. The quick notes you capture and what you decide to do with them.
- Settings and preferences. Notification, timer, appearance, and companion preferences — everything you shape the app with.
- Places you save. If you use travel-time features, the locations you save so Familiar can estimate when to leave.
- How you use features, so features can adapt. Familiar records some of your interactions with its own features in order to respond to you: which activity suggestions it showed you and how you responded (accepted, declined, or set them aside), so it can suggest less of what you ignore; which insight cards you have seen and opened, so it shows you fresh ones and less of what you ask to see less of; whether you responded to or dismissed wellness check-ins, which feeds one of your own insight cards; how you answer the small focus check-ins during a timer; and how you respond to habit reminder cards. This information changes your experience — it is feature data, not analytics — and it stays in your account like everything else.
- Notification subscriptions. If you turn on web notifications, we store a push subscription for each browser you enable so notifications can reach it. Mobile notifications are scheduled on your device.
- Summaries of your own data. Familiar computes recaps and day summaries from your data, for you. They are derived from nothing but your own account.
Familiar has no advertising identifiers and no third-party trackers, and it never tracks your location in the background. There is one optional, off-by-default location feature: if you turn on "use current location" for travel time, the app reads your device's position once, in the moment, to estimate travel time for an upcoming event. That position is used for the estimate and is not stored in your account.
03Medication and health-related data
Familiar is built for tracking things that can be sensitive: what you ate, how you slept, how you are feeling, and routines that may include medication. We hold this to a stricter standard than the rest of your data:
- It is used only to power your own view of your own life — your logs, streaks, recaps, and insights.
- It is never shared with or sold to anyone.
- It is never included in our internal product analytics (section 04).
- It is never sent to any third-party service: your habit logs, mood history, and journal are never sent to the AI service that shapes captures, or anywhere else. (When you explicitly ask for a capture to be shaped, the text of that one capture is sent — see section 06 — so a capture is only ever shared at your request, and only that capture.)
- It is excluded from our own server logs.
- If you set up medication reminders, we store only the times you choose and an optional nickname you write — never a medicine name, dose, or count. You can mark any reminder “discreet” so its notification shows a generic message instead of your nickname on your lock screen.
Like all your data, it is covered by your export and deleted with your account.
04Internal product analytics
To improve Familiar, we need to understand how it is used — and we built that fully in-house rather than handing usage data to an analytics company. The app has no third-party analytics processor and no analytics SDK, and none of this usage data leaves our own infrastructure. Because of that, there are also no tracking cookies and no cross-site tracking — which is why you will not see a cookie banner.
As Familiar's internal product analytics roll out, they are limited to:
- Screen presence. Which screens of the app you opened on a given day, with a per-day count, tagged with the platform (web or mobile). No timestamps and no sequence — it records "the calendar was opened on Tuesday," not when or in what order.
- Capture shaping outcomes. When the dialog that shapes a capture into an event or habit is opened, whether it ends in a confirm or a cancel — so we can tell whether the flow is working.
This is low-sensitivity metadata: it never includes what you wrote, logged, or journaled, and never anything health-related. We review it only in aggregate — patterns across usage, not a view into any one person's day. It is never shared or sold, and once collected, this metadata is included in your data export and removed with your account.
05Sign-in and connected services
Familiar accounts currently use email and password. We plan to offer sign-in with Google and sign-in with Apple as well:
- If you sign in with Google, Google shares your email address with us to create and identify your account. We also ask, at sign-in, for read-only access to your Google Calendar so that a planned calendar view can work without a second permission request later. Familiar does not currently read, import, or store anything from your Google Calendar. Before any calendar data is used, we will update this policy to say exactly what is stored and why.
- If you sign in with Apple, Apple shares your email address with us — or, if you choose Apple's private relay option, a forwarding address instead.
06Service providers
Familiar runs on a deliberately short list of service providers. Each one receives only what its job requires:
- Supabase — our database, authentication, and backend. Your account data described in section 02 is stored here, hosted on Amazon Web Services in the United States (us-west-2 region). Every account's data is isolated by database-level row security, so it is only ever readable by your own signed-in account.
- Vercel — hosts and serves the Familiar web app and this website.
- Anthropic — when you ask Familiar to shape a capture into a calendar event or a habit, the text of that one capture (plus your timezone, and any date your device already detected in it) is sent to Anthropic's AI service to draft the result you then review. It is sent without your name, email, or account identifier. This happens only when you explicitly ask for a capture to be shaped — nothing else you write in Familiar is ever sent to it.
- Mapbox — powers travel-time features: the place names you type when searching for a location, and the coordinates of places you choose (or, if you turned on the optional "use current location" setting, your device's one-time position), are sent to Mapbox to suggest addresses and estimate travel time. These requests go through our server, not directly from your device.
- Your browser's push service — if you turn on web notifications, they are delivered through the push service built into your browser (operated by your browser's maker). Mobile notifications are scheduled locally on your device rather than pushed through a third party.
That is the whole list. There is no advertising network and no data broker, the app contains no third-party analytics, and we never sell your data to anyone.
08The legal bases we rely on
Where data-protection law (such as the GDPR) asks us to name a legal basis:
- Providing the Service (performance of a contract) — for everything in section 02: the app stores your data because that is what the app is.
- Legitimate interest — for the minimal internal product analytics in section 04, kept deliberately narrow so it never outweighs your privacy.
- Consent — for optional extras you choose to share, like your birthday month and day. You can withdraw these at any time by clearing them.
09Your rights and controls
You do not have to ask us for your data; the controls are in the app:
- Export. In Settings → Privacy & Account → Your Data, you can download a readable copy of your history and a complete machine-readable copy of your account data — your profile, settings, schedule, habits, logs, journal, captures, summaries, and — once collected — the analytics metadata described in section 04. (A small amount of purely technical state is not part of the export: notification delivery endpoints, regenerable view caches, and passively recorded interaction telemetry that only tunes features — like which insight cards you have already seen. All of it is still deleted with your account.)
- Delete. In Settings → Privacy & Account, you can delete your account. This removes your account and all of its data (section 10).
- Edit. Your data is editable in place — entries, logs, items, and settings can be changed or removed as you go.
Depending on where you live, you may also have legal rights to access, correction, deletion, portability, and objection. The controls above cover the common cases; for anything else, contact us (section 13) and we will help.
10How long we keep your data
Your data is kept for as long as your account exists, so your history and insights keep working. When you delete your account, your account record and all the data attached to it — logs, journal entries, calendar items, captures, settings, and any analytics metadata collected — are deleted from the database together. Expired notification subscriptions are also removed automatically when a browser reports them gone, and the internal analytics metadata in section 04 is capped on its own clock: entries older than 400 days are removed automatically even while your account is open.
11Age requirement
Familiar is for people aged 16 and over. When you create an account, we ask for your date of birth once, only to check that you meet the minimum age. The check happens in the moment: the date itself is never stored anywhere — the only thing we keep is a yes/no record that your account passed the check.
12Changes to this policy
If we change what Familiar collects or how it is used, we will update this policy first, update the "Last updated" date, and provide notice where required. We will not quietly expand data collection behind an old policy.
13Contact
Questions, concerns, or requests about your data can be sent to hello@familiarhabits.com. Our Terms of Service are published alongside this policy.