Privacy Policy.
OfflineHabit is built so that most of the time we do not see your data. This page explains the parts where we do, the parts where we deliberately don't, and what you can make us do about it. It is written to be read, not to be survived — but it is also the formal notice required by Article 13 of the GDPR, so nothing here is decorative.
1. What lives on your phone
By default, every habit, every check-mark and every streak number stays in your phone's local storage. The app is fully functional offline: creating habits, checking them off, reminders, statistics and CSV/JSON export all work with no account and no network. Nothing about your tracking leaves the device unless you switch on optional sync.
2. Who we are
The controller for the processing described here is:
- DJUMP, MB
- Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania
- start@djump.io
We are a two-person company. We are below every threshold in Article 37 GDPR, so we have not appointed a Data Protection Officer; the address above reaches the people who actually make these decisions, which is the point of naming it.
3. What we collect, why, and the legal basis
Nothing in this list is collected from someone who simply installs the app and uses it. Each row names its own legal basis under Article 6(1) GDPR.
- Email address and display name — only if you create an account for sync. Basis: performance of a contract, Art. 6(1)(b). The app is fully usable without an account.
- Your habit log — transmitted to your own private account only while sync is on, protected by row-level security so that only your account can read your rows. Basis: performance of a contract, Art. 6(1)(b).
- Push notification token — only if you turn on reminders. Basis: consent, Art. 6(1)(a) — the operating system asks you first, and turning reminders off withdraws it.
- Anonymous product analytics (PostHog) — which screens are opened and which features are used, never the content of a habit. No account id and no email are ever attached, and we never call PostHog's
identify(). Basis: consent, Art. 6(1)(a). From app version 1.0.1 the analytics SDK is not started at all until you say yes. - Crash and error reports (Sentry) — the technical trace of a failure: app version, device model, operating system, and the code path that broke. Personal identifiers are stripped before sending, performance tracing is off, session replay is off, and the log lines and tap targets that could echo your habit text are dropped before they leave the device. Basis: legitimate interest, Art. 6(1)(f) — keeping the app from crashing on you. We consider this to pass the balancing test precisely because it is narrowed to crashes and carries nothing you wrote; you can object under Article 21 at any time.
- Subscription status (RevenueCat) — whether Premium is active, tied to a store-issued identifier, never to your email. Basis: performance of a contract, Art. 6(1)(b).
- Website page views (Vercel Web Analytics) — cookieless, first-party, aggregate. No cross-site tracking, no advertising identifiers, no profile. Basis: legitimate interest, Art. 6(1)(f).
- Messages you send us — the name, address and text you type into the contact form, so we can reply. Basis: legitimate interest, Art. 6(1)(f), or a contract if your message is about one.
4. What we never collect
- Payment or card details. Apple and Google take the payment; we are told only that a subscription is active.
- Location, contacts, photos, calendar, health data, or the device advertising identifier. The app declares no advertising ID, and there is no
AD_IDpermission in the Android build. - The text of your habits — not for analytics, not in crash reports, not anywhere off your device unless you switched sync on yourself.
- Anything at all, if you use the app without an account and decline analytics.
5. The services we use, and where your data goes
These are our processors. Where we have verified the hosting region ourselves, it is stated; where we have not, we say so rather than guess.
- PostHog — product analytics, on PostHog's EU infrastructure (
eu.i.posthog.com). Verified. - Sentry — crash reporting, on Sentry's German (EU) region (
ingest.de.sentry.io). Verified. - Supabase — database and authentication for accounts and sync.
- RevenueCat — subscription state.
- Resend — the transactional email we send you.
- Vercel — hosting and cookieless analytics for this website.
- Apple and Google — app distribution, sign-in, and payment.
Two of these are confirmed to keep your data inside the European Union. For the others, personal data may be processed outside the European Economic Area. Where that happens we rely on the European Commission's Standard Contractual Clauses or on an adequacy decision, and you may ask us at start@djump.io for the specifics that apply to you. None of these companies is permitted to use your data for their own purposes, and none of them is an advertising network.
6. Analytics consent — and taking it back
The first time you open OfflineHabit, it asks one question, before any analytics code has run. Declining is a button of exactly the same size and weight as accepting, because a choice that is visually rigged is not a choice. If you never answer, nothing is collected — silence is not consent.
You can change your mind at any time in Settings, and withdrawing is as easy as giving it was. This is how we meet § 25 TDDDG in Germany, the PECR consent rules and the UK Information Commissioner's 2025 guidance for apps, and the equivalent rules elsewhere: consent has to come before the SDK starts, not after. "It is anonymous" is not a substitute, which is why we gate it rather than merely mute it.
7. Your rights
Under the GDPR you have the following rights, and you exercise all of them by writing to start@djump.io. We answer within one month.
- Access (Art. 15) — a copy of what we hold. The app also exports your entire habit history to CSV or JSON on demand, with no account and no request to us.
- Rectification (Art. 16) — correct anything wrong.
- Erasure (Art. 17) — in-app, Settings → Delete account removes the server-side records permanently. You do not need to ask us.
- Restriction (Art. 18) and objection (Art. 21) — including objecting to the crash reporting described in section 3.
- Portability (Art. 20) — the CSV/JSON export is built for exactly this, and it is a free feature.
- Withdrawal of consent (Art. 7(3)) — at any time, in Settings, without affecting anything already lawfully processed before you withdrew.
8. Complaints
If you think we have handled your data badly, we would rather hear it first — but you do not have to come to us at all. You may complain directly to a supervisory authority: ours is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, vdai.lrv.lt). You may also complain to the authority in the country where you live or work.
9. Children
OfflineHabit is not intended for children under 13, and the store listings are rated accordingly. We do not knowingly collect data from anyone under that age. If you believe a child has given us data, write to us and we will delete it.
10. How long we keep things
- Account and synced habits — until you delete the account, which erases them immediately.
- Analytics events — kept in our PostHog project in the EU for as long as that project exists. PostHog Cloud offers no retention window we could set and no scheduled deletion of old events, so we will not print a deadline here that we cannot enforce. What limits this is the shape of the data rather than a clock: no account ID, no email address, no habit text, and no call to PostHog's
identify(). Withdrawing consent in Settings stops collection from that moment on. And because nothing in an event points back to an account, we cannot pick one reader's events out of the set to delete on request — anonymity cuts both ways (Art. 11 GDPR). - Crash reports — 90 days.
- Contact-form messages — kept as long as the conversation is live, and for up to 12 months afterwards in case you write again.
- The Google Play notification list — closed on 21 August 2026 and no longer accepting addresses. The remaining addresses are deleted once the single promised message has been sent, and in any case by 31 December 2026.
11. No profiling, no ads, no selling
There is no automated decision-making and no profiling within the meaning of Article 22 GDPR. Nothing about you is scored, ranked or predicted. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act — there is no advertising in this app at all, so there is nothing to opt out of.
12. Changes to this policy
If this policy changes meaningfully we update the effective date at the top, and for material changes we tell signed-in users in the app rather than hoping they re-read this page. Earlier versions are available from us on request.
13. Contact
Questions, requests, or general grumbles: start@djump.io. A person reads it.