Satoshi HabitsPRIVACY POLICY
Effective: July 13, 2026
Satoshi Habits works without accounts. There is no login, no user name, and no email address. Most of what you do in the app stays on your device. Some features send data to our servers or to service providers — this policy lists each one, what it sends, and why. We use no analytics, tracking, or advertising frameworks.
WHO IS RESPONSIBLE
Satoshi Habits is responsible (the "controller") for the processing described in this policy. Contact for all privacy matters: info@satoshihabits.com.
YOUR DEVICE IDENTIFIER
On first launch the app generates a random identifier (the "device ID"). It is not your name, not an email address, and not Apple’s advertising identifier — it identifies the installation, not you as a person. It is stored in your device’s Keychain, which means it survives deleting the app: if you uninstall and reinstall, or set up a new iPhone from a backup, the app keeps the same device ID. This is deliberate — it is how your purchases and Signature Cards remain yours without an account. The server-side records described below are keyed to this device ID.
DATA THAT STAYS ON YOUR DEVICE
Habits, tasks, alarm settings, streaks, in-app balances, and your card collection are stored only on your device. We hold no copy of them and cannot read them. Your settings stay on the device too, except the few a feature needs server-side — your app language, timezone, and the reach-alert switch, described under Notifications. Like most app data, local data is included in your device backups, and the app additionally keeps a backup of it (including your habit and task titles and settings) in your personal iCloud so a new iPhone can restore your progress. Both live in your own iCloud under Apple’s terms — they are not sent to us.
NOTIFICATIONS
Alarm and daily-reminder notifications are scheduled locally on your device. If you enable notifications, the app also registers for remote notifications about your own Signature Cards — review results, the day your card is featured, and "reach" alerts when your card is collected in new places. For this we store on our server: your device ID, a push token, your platform, the app language, and your device’s timezone. Delivery goes through Apple’s and Expo’s push services. You can turn off reach alerts with the "Card Reach Alerts" switch in the Node tab, and all notifications in your device Settings. Push tokens that stop working are removed automatically.
COUNTRY DERIVED FROM YOUR TIMEZONE
Our server derives a country from your device’s timezone setting (for example, Europe/Berlin → Germany) — nothing more precise. The app uses no GPS and no IP-address geolocation, and never reads your location. The country is used for counting the countries a Signature Card has reached and for wording creator notifications; the timezone itself is used to time them (for example, sending "your card is featured today" in the creator’s local morning). Timezones that do not map to one identifiable country are counted as unknown.
SIGNATURE CARDS — WHAT YOU UPLOAD AND WHO SEES IT
Signature Cards are optional and user-created. When you forge one, we store on our servers: the card image, title, text, the creator name you choose (it does not need to be your real name — the app offers a pseudonym), your device ID, and the purchase transaction identifiers. Every card is reviewed by a human before other users can see it; new submissions also notify us by email so review can start quickly. Once approved, the card — image, title, text, creator name, and its draw statistics — is shown to all users of the app in the Daily Draw and the shared gallery.
Card images are stored in a public storage bucket and served from a web address: anyone who has the exact link can open the image, including before your card is approved. The link is long and random and is not published anywhere, but you should treat anything you upload as potentially public from the moment you upload it.
CARD STATISTICS
When another user collects your card, our server counts the draw and the drawer’s country. These statistics are stored per card only — the device ID of the person who drew the card is not stored with them. The resulting totals (draws, countries) are visible to all users.
REPORTS AND MODERATION
Any user can report any card. A report stores the card, the reason, your note, and your (the reporter’s) device ID on our server, and is additionally sent to us by email so we can react quickly. Reports are kept as moderation records. Creators who violate the Content Guidelines can be blocked by device ID.
AI ARTWORK ("SIGNATURE STYLE" AND "AI GENERATE")
While forging a card you can optionally use AI, in one of two ways. With "Signature Style", the cropped image you uploaded is sent through our server to Google’s "Nano Banana 2" image model (part of Google’s Gemini API), together with a fixed styling instruction that lives on our server. With "AI Generate", no image is sent — instead, the description you type is sent through our server to that same Google model, placed inside a fixed instruction template that lives on our server. Before it is sent, your description is shortened to at most 160 characters and stripped of invisible control characters; apart from that, it is sent as you wrote it — so please do not type anything you would not want to share with Google. In both cases the resulting image comes back to your device. Our server does not keep a copy of the image you send, of the description you type, or of the result; we store only a per-device counter of AI attempts. Your description is kept on your device, alongside the image, in the app’s local sketch history until you delete it. Google processes the image or the description as our service provider under its own terms — see Google’s Gemini API terms and privacy policy for how Google handles submitted content. Nothing is sent to Google unless you tap the style or the generate button.
VOICE INPUT (DICTATION)
In the Verify tab you can dictate a task instead of typing it. Dictation uses Apple’s speech recognition: on devices that support on-device transcription for your language, your speech is transcribed entirely on the device and the audio never leaves it; on devices that do not, iOS sends the audio to Apple’s servers for transcription under Apple’s terms. Either way, we never receive the audio or the transcript — the recognized text only fills the task field on your screen, and the task you keep is stored on your device like any typed task. Nothing is recorded unless you tap the microphone, and listening stops when you stop speaking.
DEVICE INTEGRITY CHECK
The AI styling feature is protected with Apple App Attest, which proves a request comes from a genuine copy of the app. For this, an Apple-generated key identifier and public key are stored on our server, bound to your device ID. This involves no personal information beyond the device ID.
PURCHASES
All purchases are processed by Apple. We never see your payment details, your name, or your Apple ID. Subscription status is managed by RevenueCat under an anonymous identifier that RevenueCat generates — we do not give RevenueCat your device ID. Our server keeps a log of purchase events (product, price, currency, transaction identifiers, and the event data RevenueCat delivers) to operate purchases and keep records. For Signature Cards, the App Store transaction identifiers are stored with the card so your purchase can be honored across reinstalls. If you redeem a promo code, the code and your device ID are stored so each code can only be used once.
FEEDBACK
The feedback form in the Node tab sends us your message, the subject you pick, a shortened form of your device ID, and — only if you choose to type one — an email address, which we use solely to reply.
MARKET DATA AND OTHER CONNECTIONS
The app fetches public Bitcoin data directly from mempool.space and CoinGecko, mining-pool logos from GitHub, and app content (such as card images and sounds) from our storage provider. If the bundled start-screen 3D model cannot load, a display library may be fetched from Google’s content network as a fallback. Like every internet request, these services see your IP address; the app sends them no personal data.
IP ADDRESSES AND SERVER LOGS
Our server uses IP addresses in memory to limit request rates (abuse prevention). They are not stored in our database and are never used for geolocation. Standard technical server logs exist at the infrastructure level, as on virtually every online service.
WHAT WE DO NOT COLLECT
No analytics, no tracking, no advertising identifiers, no contacts, no GPS or precise location, no cookies. We do not use Firebase, Amplitude, Mixpanel, Google Analytics, Facebook SDK, or any other analytics or advertising framework. There are no user accounts, and we do not know your name or — unless you type it into the feedback form — your email address.
DEVICE PERMISSIONS
• Notifications — alarm and reminder alerts, and Signature Card notifications
• Camera / Photo Library — Signature Card image selection
• Motion & Accelerometer — shake-to-wake alarm and card tilt effects
• Microphone — voice input for dictating tasks in the Verify tab
• Speech Recognition — transcribing dictated tasks (see Voice Input above)
YOUR CHOICES
• Turn "Card Reach Alerts" off in the Node tab to stop reach notifications.
• Disable notifications entirely in your device Settings.
• Report any card from the gallery; you can also hide any card from your own view.
• Ask us to delete your server-side data — see below.
DATA RETENTION AND DELETION
Deleting the app removes all local data, but not the device ID (it lives in the Keychain and survives uninstall) and not the server-side records described above. Signature Cards remain published until removed; push tokens are kept until notifications are disabled or the token stops working; reports and purchase records are kept as moderation and accounting records. To have your server-side data deleted — including your cards — contact us via the feedback form in the Node tab (it includes the shortened device ID we need to find your records) or email info@satoshihabits.com. We delete data we can link to your device unless we are legally required to keep it.
YOUR RIGHTS (EU/GDPR)
Where the GDPR applies, the legal bases for the processing described here are: performance of a contract (operating the app, purchases, hosting and publishing your Signature Cards — Art. 6(1)(b)); your consent (notifications, AI styling, voice input, the feedback email — Art. 6(1)(a)), which you can withdraw at any time; and our legitimate interests (moderation, abuse prevention and rate limiting, aggregated card statistics — Art. 6(1)(f)). You have the right to access, correct, delete, and receive a copy of your data, to restrict or object to processing, and to complain to a data protection authority. Because the app has no accounts, we can only link data to you through your device ID — contact us as described above and we will help.
CHILDREN’S PRIVACY
Satoshi Habits is not directed at children under the age of 13. We do not knowingly collect or solicit personal information from children.
SERVICE PROVIDERS
We use Supabase (database and storage), Hetzner (server hosting), Apple (purchases, and speech transcription on devices that cannot transcribe on-device), RevenueCat (purchases), Expo (push delivery), and Google (AI styling). Some of these providers process data outside the EU/EEA.
CHANGES TO THIS POLICY
Updates will be reflected on this page with a revised effective date. Continued use of the app after changes constitutes acceptance.
CONTACT
info@satoshihabits.comEMBEDDED VIDEOS (WEBSITE ONLY)
This website embeds a promo video on its /satoshi-habits page. The video does not load until you press play. When you play it, it is loaded from YouTube’s extended-privacy domain (youtube-nocookie.com), and data such as your IP address may be transmitted to Google/YouTube. See Google’s privacy policy: https://policies.google.com/privacy.