Updated: 19/08/2026
1. Who we are
England and Wales.
- Company number: 07858207
- Registered and trading address: Woodlands, 25 Caring Lane, Bearsted, Maidstone, Kent, ME14 4NJ
- VAT number: GB 328 0697 85
- ICO registration reference: ZA541988
We are the data controller for the personal data described in this policy, which means we decide why and how it is processed. This policy covers the Habits for Health mobile app.
If you have any questions about this policy or how we handle your data, contact our Data Protection Lead at data.protection@wellbeingpeople.com.
2. Who this policy is for
This policy applies to everyone who uses the App. You can access the App by taking out a paid individual subscription through the app store, or by redeeming a free or discounted code that an employer or organisation has provided, which you redeem through the app store. The App's global individual leaderboard is available to everyone. Separately, if your organisation is running a challenge, we compare the email address you gave us when you created your account against the list of people it has approved for that challenge, so we can show you its organisation leaderboard and include your results in it. This does not affect your access to the App, which comes from your subscription or a redeemed code. Section 4 of the Terms of Use explains these access routes in more detail.
The App is intended for users aged 18 and over. We ask for your age when you create your account; you cannot complete signup if you are under 18. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
3. The personal data we collect
Information you give us
- Account details: your first name, last name, email address and password (your password is handled securely by our authentication provider and is not visible to us).
- Display name: a name of your choosing that is shown to other users on leaderboards (see section 9).
- Profile details: your age, which you provide when you create your account, and your gender, which you can choose to provide or leave blank. We use these to personalise your experience in the App. Your age also confirms that you are aged 18 or over (see section 2).
- Organisation challenge membership: if your organisation is running a challenge, it gives us a list of the people it has approved to take part. We do not collect any extra information from you for this. We compare the email address you already gave us when you created your account (see Account details above) against that list, to see whether to show you its teams and organisation leaderboard.
- Communications: any messages you send us, for example support requests. When you use the Contact support form in the App, we receive the content of your message, your first and last name, your email address, an internal user identifier for your account, and the time you sent it. Your email address is used as the reply address so our support team can respond to you directly. Please include only the information that is relevant to your enquiry.
Information created as you use the App
- Activity and engagement data: the challenges you activate, your daily check-ins and streaks, points and medals earned, and your answers to in-app quizzes. This is self-reported activity data about your engagement with the App.
- Notification preferences: whether notifications are switched on, your preferred notification time, and a device token used to deliver push notifications.
Information collected automatically
- Usage and analytics data: information about how the App is used (for example, screens viewed, features used, approximate device and app version, and a pseudonymous app-instance identifier), collected through Google Firebase Analytics. We have configured analytics to anonymise IP addresses.
Subscription and payment information
If you take out an individual subscription, your payment is handled by the app store you bought it through (Apple's App Store or Google Play). We do not collect, see or store your card number, billing address or other payment card details. The app store acts as merchant of record and processes the payment.
To give you the access you have paid for, and to keep that access secure, we receive and store limited information about your subscription: its status (for example active or expired), the plan you chose (for example monthly, 3-month or annual), its expiry date, and a store transaction identifier that links the purchase to your account. We do not store any card or payment-card data.
A note on health data
We treat your habit and challenge activity as self-reported engagement data, not as health data. Whether you complete a habit on a given day does not, in our view, reveal information about your state of health. We do not ask for, and the App is not designed to collect, medical information, diagnoses, or other special category data.
4. How we use your data, and our lawful basis
What we do | why |
| |
|---|---|---|---|
Create and manage your account; let you log in | To provide the App you have signed up for | Performance of a contract (Art. 6(1)(b)) | |
Deliver challenges, track streaks, award points and medals, run quizzes | Core functionality of the App | Performance of a contract (Art. 6(1)(b)) | |
Show leaderboards using your display name | To provide the social features | Contract (Art. 6(1)(b)); and our legitimate interest in engaging features (Art. 6(1)(f)) | |
Use your profile details (age and gender) to personalise content and features | To tailor your experience in the App | Your consent, which you can withdraw at any time (Art. 6(1)(a)) | |
Confirm you are aged 18 or over at signup | To keep the App restricted to adults | Legitimate interests (Art. 6(1)(f)) | |
Compare the email you gave us at signup against a list of people your organisation has approved for its challenge, at signup and each login | To show you your organisation's leaderboard and include your results in it, and keep those results to the people it has approved | Legitimate interests of the organisation and you (Art. 6(1)(f)) | |
Manage your individual subscription and unlock the access you have paid for | To provide the paid App you have signed up for | Performance of a contract (Art. 6(1)(b)) | |
Send service and transactional messages | To operate the App and keep you informed | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) | |
Receive, respond to and manage the support enquiries you send us through the App | To answer your question or resolve the issue you have raised | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) | |
Send push notifications | To remind and encourage you | Your consent, via your device and the in-app toggle (Art. 6(1)(a)) | |
Analyse usage to understand and improve the App | To make the App better | Consent and/or legitimate interests, depending on the mechanism in place (Art. 6(1)(a)/(f)). See section 6 | |
Produce anonymised, aggregated reports for organisations | To give clients insight into overall engagement | Legitimate interest in providing our service (Art. 6(1)(f)); once anonymised, the reports are not personal data | |
Show the organisation that approved you for its challenge your display name and email address | So the organisation can manage its challenge and confirm only approved people are taking part | Legitimate interests of the employer or organisation and us (Art. 6(1)(f)) | |
Protect the App against fraud, abuse and security threats | To keep the App and users safe | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced our interests against your rights and have concluded our processing is proportionate. You can ask us for more detail, and you have the right to object (see section 10). We do not make any decisions about you that have legal or similarly significant effects using solely automated means.
5. Who we share your data with
We do not sell your personal data. We share it only as set out below.
- Service providers (processors) acting on our instructions: Google (Firebase) for authentication, database storage, push messaging and analytics, and for briefly holding your support message on our backend while it is being sent.
- Amazon Web Services (Amazon Simple Email Service, Amazon SES): used to deliver the email generated by the Contact support form to our own support inbox, so our team can respond to you. It is configured in the AWS Europe (London) region.
- App stores (distribution and payment): Apple (App Store) and Google (Google Play), in connection with downloading the App and, if you take out an individual subscription, processing your payment as merchant of record and confirming your subscription status to us.
- Employers and organisations running a challenge: if your organisation is running a challenge, an administrator at that organisation can see the display name and email address of the people it has approved for that challenge, so they can manage it and check that only approved people are taking part (see section 9). Any wider reporting we provide to the organisation is anonymised and aggregated, and does not identify you individually.
- Professional advisers and authorities: we may disclose data where required by law, regulation, court order, or to establish, exercise or defend legal claims.
- Business transfers: if our business is reorganised, sold or transferred, your data may be disclosed to a successor under the same protections.
Each processor is bound by a contract requiring it to protect your data and use it only as instructed.
6. Analytics and consent
The App uses Google Firebase Analytics to understand how features are used so we can improve the App. We do not use analytics to track you across other companies' apps or websites, and we do not use your data for third-party advertising. Where the law requires your consent for analytics, we will ask for it (or provide a clear opt-out), and you can change your choice at any time in the App's settings. We have enabled IP anonymisation and a defined analytics retention window (see section 8).
7. Storage and international transfers
Our primary database (Google Firestore) is hosted in the United Kingdom (London region). Some of the providers we use operate global infrastructure, so certain processing, for example authentication, push messaging, analytics and confirming app-store subscription status, may involve transfers of personal data to countries outside the UK, including the United States. Where that happens, the transfer is protected by appropriate safeguards. We rely on the providers' data processing agreements, which incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses and/or the UK Extension to the EU-US Data Privacy Framework. You can ask us for more information about these safeguards using the contact details in section 1.
Support enquiries do not involve a transfer outside the UK. Your message is held briefly on our backend and is then delivered to our support inbox by Amazon SES in the AWS Europe (London) region, so no personal data for this feature is processed outside the UK.
8. How long we keep your data
Data | Retention |
|---|---|
Account and identity data (name, display name, email, age, gender, login credentials, push token) | Kept while your account is active. On account deletion, removed within 30 days. |
Activity and engagement data (streaks, points, quiz answers, challenge history) | Kept while your account is active. On deletion, all identifiers are removed and only irreversibly anonymised, aggregated data is retained for product analytics and client reporting, with no fixed end date. |
Subscription records (status, plan, expiry date, store transaction identifier) | Kept while your account is active, and removed within 30 days of account deletion. We do not hold card or payment-card data; the app store retains payment records as merchant of record. |
Inactive accounts | If you do not log in for 24 months, we will email you a warning and then delete or anonymise the account after a further 30 days if you do not respond. |
Support correspondence (the content of your message, your name, email address, internal user identifier and the time of your enquiry) | 24 months from the last message in the thread. The temporary copy of the message held on our backend while the email is being sent is deleted shortly after sending. |
Analytics data | Retained for 14 months in Firebase Analytics. |
Backups | Personal data is purged from backups within the backup rotation cycle (up to 35 days). |
Organisation approved list (email addresses or domains a client organisation gives us so we can show its challenge leaderboard to the people it has approved) | Kept while our agreement with that organisation is in place and its challenge is running. Removed within 30 days of the arrangement ending. |
Anonymised means the data has been irreversibly stripped of anything that could identify you, directly or indirectly, so that you can no longer be singled out. Once data is genuinely anonymised it is no longer personal data and this policy's retention limits no longer apply to it.
9. Leaderboards, display names and organisation administrators
The App includes two kinds of leaderboard.
- A global individual leaderboard, available to everyone who uses the App. It ranks individual users and shows each user's display name and points total, not email addresses or other account details.
- An organisation leaderboard, shown only when your organisation is running a challenge. It is made up of the results of the people your organisation has approved for that challenge, and it is shown only to those approved people. You appear on it, and can see it, only if the email you gave us at signup is on that approved list.
Other users only ever see your display name, not your email address. An administrator at the organisation that approved you for its challenge can additionally see your email address, as described above. Engagement information visible to administrators is not used by us for any employment, performance, insurance or disciplinary purpose, and our agreements with client organisations restrict such use.
10. Your rights
Under UK data protection law you have the right to: be informed about how we use your data (this policy); access the personal data we hold about you; rectify inaccurate or incomplete data; erase your data (the right to be forgotten) in certain circumstances; restrict our processing in certain circumstances; data portability; object to processing based on our legitimate interests; and withdraw consent at any time where we rely on consent (for example, push notifications or analytics).
To exercise any of these rights, contact data.protection@wellbeingpeople.com. We will respond within one month, and there is normally no charge. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO). Website: https://ico.org.uk. Helpline: 0303 123 1113. We would, however, appreciate the chance to address your concerns first.
11. Deleting your account
You can delete your account at any time from within the App (Profile, then Delete account). When you delete your account, your account and identity data are removed within 30 days, your activity data is anonymised as described in section 8, and some records may be retained where we are legally required to keep them. If you have an individual subscription, deleting your account does not cancel it or stop future charges: you need to cancel the subscription separately through your App Store or Google Play account (see section 5 of the Terms of Use). If you joined through an employer or organisation, deleting your account removes your personal data from our systems but does not affect the anonymised, aggregated figures already included in past reports.
12. Security
We take appropriate technical and organisational measures to protect your data, including encryption of data in transit, access controls, hosting your database in the UK, and using reputable providers who maintain recognised security standards. No system can be guaranteed completely secure, but we work to protect your data and will notify you and the ICO where we are legally required to do so in the event of a personal data breach.
13. Third-party services
The App relies on services provided by Google and the app stores. Your use of those services may also be governed by their own privacy policies:
- Google / Firebase: https://firebase.google.com/support/privacy
- Apple: https://www.apple.com/legal/privacy/
- Google Play: https://policies.google.com/privacy
14. Changes to this policy
We may update this policy from time to time. If we make significant changes, we will notify you in the App or by email. The “last updated” date at the top shows when this policy was last revised.
15. Contact
Wellbeing People Ltd, Woodlands, 25 Caring Lane, Bearsted, Maidstone, Kent, ME14 4NJ. Data Protection Lead, data.protection@wellbeingpeople.com.
