01Introduction
This policy explains what data Familiar (the "Service") collects, why, where it goes, and the controls you have over it. Familiar is provided by Familiar Habits, which is the data controller for the data described here.
The short version of our approach: your data is yours. Familiar stores it to run features you use, shows it back to you as your own history and insights, and keeps it out of everyone else's hands. We have tried to write this policy in plain language; if anything is unclear, please ask us.
02What Familiar collects
Here is what lives in your Familiar account, grouped by what it is for:
- Account. Your email address and password, used only to sign you in and managed by our authentication provider (Supabase), plus the name you choose to show in the app and your timezone. Optionally, a birthday month and day if you choose to share one so Familiar can mark the day — the year is never asked for or stored, and you can clear it at any time.
- Schedule and calendar. Calendar items you create, when your day starts and ends, and any time off you set — plus events imported from your Google Calendar, if you turn on sync (section 05).
- Habits. Which habits you have turned on, your habit logs (like water, food, movement, and sleep), and your streaks.
- Device health data (optional, off by default). If you connect your device's health service, Familiar reads your sleep sessions and daily step totals — to offer to prefill your sleep log, and to hold back movement reminders when you have already been moving. It is read only if you connect it, it stays in your account, and it is covered by the stricter health-data standard in section 03.
- Energy and mood. The energy and mood check-ins you log, kept as your own history so the app can meet you where you are.
- Journal. Your journal entries, any song link and song title/artist you attach, and how you interact with journal prompts (accept, skip, hide). Pasting a song link can ask its provider once for a title and artist. On the web, the embedded player itself loads only after you choose Play; while it plays, the provider can see your connection and may use cookies. Familiar never loads provider images.
- Captures. The quick notes you capture and what you decide to do with them.
- Settings and preferences. Notification, timer, appearance, and companion preferences — everything you shape the app with.
- Places you save. If you use travel-time features, the locations you save so Familiar can estimate when to leave.
- How you use features, so features can adapt. Familiar records some of your interactions with its own features in order to respond to you: which activity suggestions it showed you and how you responded (accepted, declined, or set them aside), so it can suggest less of what you ignore; which insight cards you have seen and opened, so it shows you fresh ones and less of what you ask to see less of; whether you responded to or dismissed wellness check-ins, which feeds one of your own insight cards; how you answer the small focus check-ins during a timer; and how you respond to habit reminder cards. This information changes your experience — it is feature data, not analytics — and it stays in your account like everything else.
- Notification subscriptions. If you turn on web notifications, we store a push subscription for each browser you enable so notifications can reach it. Mobile notifications are scheduled on your device.
- Summaries of your own data. Familiar computes recaps and day summaries from your data, for you. They are derived from nothing but your own account.
- Feedback you send us. If you use Settings → Help & feedback to report a problem or share an idea, we store the message you wrote and which kind you picked. Alongside it we store which app you were using, its version, and which screen you came from — the screen only, never which entry or item you had open. We keep it so we can act on what you told us; it is included in your data export and deleted with your account.
Familiar has no advertising identifiers and no third-party trackers, and it never tracks your location in the background. There is one optional, off-by-default location feature: if you turn on "use current location" for travel time, the app reads your device's position once, in the moment, to estimate travel time for an upcoming event. That position is used for the estimate and is not stored in your account.
03Medication and health-related data
Familiar is built for tracking things that can be sensitive: what you ate, how you slept, how you are feeling, and routines that may include medication. We hold this to a stricter standard than the rest of your data:
- It is used only to power your own view of your own life — your logs, streaks, recaps, and insights.
- It is never shared with or sold to anyone.
- It is never included in our internal product analytics (section 04).
- Beyond the storage and hosting in section 06, Familiar passes it on in two cases only, and both are ones you ask for. Your habit logs, your mood history, and your journal are never sent to the AI service that shapes captures. What is sent is the text of a capture, when you ask the AI to shape or split that capture, and the sentence you type into the natural-language bar, when you ask where it should go — which can be a sentence about to become a mood or journal entry (see section 06). Each time it is that one piece of text and nothing around it. Turn off AI text parsing in Settings and nothing is sent to the AI service at all — Familiar works with on-device parsing and manual entry only.
- It is excluded from our own server logs.
- If you set up a medication, we store only what you choose: the days it repeats on, the times of day, and an optional nickname you write — never a medicine name, dose, or count. You can mark any medication “discreet” so its notification shows a generic message instead of your nickname on your lock screen.
Like all your data, it is covered by your export and deleted with your account.
04Internal product analytics
To improve Familiar, we need to understand how it is used — and we built that fully in-house rather than handing usage data to an analytics company. The app has no third-party analytics processor and no analytics SDK, and none of this usage data leaves our own infrastructure. Because of that, there are also no tracking cookies and no cross-site tracking — which is why you will not see a cookie banner.
As Familiar's internal product analytics roll out, they are limited to:
- Screen presence. Which screens of the app you opened on a given day, with a per-day count, tagged with the platform (web or mobile). No timestamps and no sequence — it records "the calendar was opened on Tuesday," not when or in what order.
- Capture shaping outcomes. When the dialog that shapes a capture into an event or habit is opened, whether it ends in a confirm or a cancel — so we can tell whether the flow is working.
This is low-sensitivity metadata: it never includes what you wrote, logged, or journaled, and never anything health-related. We review it only in aggregate — patterns across usage, not a view into any one person's day. It is never shared or sold, and once collected, this metadata is included in your data export and removed with your account.
05Sign-in and connected services
Familiar accounts use email and password, or sign-in with Google. We plan to offer sign-in with Apple as well:
- If you sign in with Google, Google shares your email address with us to create and identify your account. We also ask, at sign-in, for read-only access to your Google Calendar, so that turning on calendar sync later doesn’t need a second permission request. We store that token from Google on our server from the moment you sign in, so it is ready if you turn sync on. Nothing is read from your calendar until you turn on sync yourself, in Familiar’s calendar screen. Once sync is on, we read your primary Google Calendar and store a copy of each event’s title, when it starts and ends, its location, its description as plain text, and its meeting link if it has one, covering about the last week and the next two months. We do not store event guests, and we never write anything back to your calendar. Events you delete in Google disappear from Familiar on the next sync. Disconnecting deletes that token and every event we imported, and asks Google to revoke it. You can also remove the stored token at any time from the calendar screen, whether or not you ever turned sync on.
- If you sign in with Apple, Apple shares your email address with us — or, if you choose Apple's private relay option, a forwarding address instead.
06Service providers
Familiar runs on a deliberately short list of service providers. Each one receives only what its job requires:
- Supabase — our database, authentication, and backend. Your account data described in section 02 is stored here, hosted on Amazon Web Services in the United States (us-west-2 region). Every account's data is isolated by database-level row security, so it is only ever readable by your own signed-in account.
- Vercel — hosts and serves the Familiar web app and this website.
- Anthropic — Familiar sends text to Anthropic's AI service in two situations, and only ever the text you are working on right then. First, when you ask Familiar to shape a capture into a calendar event or a habit, or to suggest where a long capture could be split: the text of that one capture is sent. Second, when you type a sentence into the natural-language bar and ask Familiar what to do with it: that sentence is sent so the AI can suggest where it belongs — a calendar item, a habit, a mood, a journal entry, or a plain capture — for you to confirm or change. That second one means a sentence you are about to save as a journal or mood entry is sent before it becomes one. Your timezone travels with the text; shaping a calendar item also sends a date your device already read in it, and a natural-language request also sends your device's current clock time. A split suggestion sends the text on its own. Never your name, email, or account identifier, and nothing else you have saved in Familiar — not your habits, your moods, your journal, or any of your history. These requests go through our server, not directly from your device. Turn off AI text parsing in Settings and nothing is sent to Anthropic at all — Familiar works with on-device parsing and manual entry only.
- Mapbox — powers travel-time features: the place names you type when searching for a location, and the coordinates of places you choose (or, if you turned on the optional "use current location" setting, your device's one-time position), are sent to Mapbox to suggest addresses and estimate travel time. These requests go through our server, not directly from your device.
- Resend — if you join the waitlist or sign up for updates on this website, the email address you give us (and, if you picked one, which familiar appealed to you) is stored with Resend, who also deliver the emails we send you. This is separate from your Familiar account: nothing you do inside the app is sent to Resend, and if you never enter your email on this website, Resend never has it. Every update we send carries an unsubscribe link, and using it stops the emails. If your address is later entered into a form on this site again, it goes back on the list — but we email you first, so it cannot happen quietly, and if that email cannot be sent you stay off the list. If you would like your address deleted outright rather than just unsubscribed, contact us (section 13) and we will remove it.
- Resend, for the contact form — when you write to us using the contact form on this website, your message and your email address are sent through Resend to reach our inbox, so that we can read it and reply. Writing to us does not put you on any mailing list: your message is delivered and nothing about it is stored on this website or added to the list described above.
- Your browser's push service — if you turn on web notifications, they are delivered through the push service built into your browser (operated by your browser's maker). Mobile notifications are scheduled locally on your device rather than pushed through a third party.
- Your browser's speech-recognition service — if you use voice dictation on the web app, the audio you speak is sent to the speech-recognition service built into your browser (operated by your browser's maker, for example Google in Chrome) to produce a transcript. Familiar never receives or stores that audio — only the text the browser returns. On mobile, Familiar asks your device to transcribe on-device, so your audio normally stays on your phone. That is a request rather than a guarantee: if your device cannot honor it — for example, some Android phones need an offline language pack installed first, and some iPhones or some languages have no on-device model — it may fall back to its maker's own speech-recognition service instead, and Familiar never receives or stores that audio either.
That is the whole list. There is no advertising network and no data broker, the app contains no third-party analytics, and we never sell your data to anyone.
08The legal bases we rely on
Where data-protection law (such as the GDPR) asks us to name a legal basis:
- Providing the Service (performance of a contract) — for everything in section 02: the app stores your data because that is what the app is.
- Legitimate interest — for the minimal internal product analytics in section 04, kept deliberately narrow so it never outweighs your privacy.
- Consent — for optional extras you choose to share, like your birthday month and day. You can withdraw these at any time by clearing them.
09Your rights and controls
You do not have to ask us for your data; the controls are in the app:
- Export. In Settings → Privacy & Account → Your Data, you can download a readable copy of your history and a complete machine-readable copy of your account data — your profile, settings, schedule, habits, logs, journal, captures, summaries, any feedback you sent us, and — once collected — the analytics metadata described in section 04. (A small amount of purely technical state is not part of the export: notification delivery endpoints, the connection token for a calendar you have linked (we deliberately keep credentials out of the export file), regenerable view caches, and passively recorded interaction telemetry that only tunes features — like which insight cards you have already seen. All of it is still deleted with your account.)
- Delete. In Settings → Privacy & Account, you can delete your account. This removes your account and all of its data (section 10).
- Edit. Your data is editable in place — entries, logs, items, and settings can be changed or removed as you go.
- AI text parsing. In Settings → Privacy & Account, you can turn off the AI shaping described in sections 03 and 06. With it off, nothing is sent to the AI service — Familiar works with on-device parsing and manual entry only.
Depending on where you live, you may also have legal rights to access, correction, deletion, portability, and objection. The controls above cover the common cases; for anything else, contact us (section 13) and we will help.
10How long we keep your data
Your data is kept for as long as your account exists, so your history and insights keep working. When you delete your account, your account record and all the data attached to it — logs, journal entries, calendar items, captures, settings, and any analytics metadata collected — are deleted from the database together. Expired notification subscriptions are also removed automatically when a browser reports them gone, and the internal analytics metadata in section 04 is capped on its own clock: entries older than 400 days are removed automatically even while your account is open.
11Age requirement
Familiar is for people aged 16 and over. When you create an account, we ask for your date of birth once, only to check that you meet the minimum age. The check happens in the moment: the date itself is never stored anywhere — the only thing we keep is a yes/no record that your account passed the check.
12Changes to this policy
If we change what Familiar collects or how it is used, we will update this policy first, update the "Last updated" date, and provide notice where required. We will not quietly expand data collection behind an old policy.
13Contact
Questions, concerns, or requests about your data can be sent to hello@familiarhabits.com. Our Terms of Service are published alongside this policy.