Privacy Policy

Beaver Habit Tracker for iOS · Effective August 9, 2026

1. Data Collection

1.1 Local Mode

Beaver Habit Tracker works locally by default. In local mode, your habits, completions, reminders, and notes remain on your device. The app does not require an account and does not connect to a default server.

1.2 Optional iCloud Sync (Subscription)

If you enable iCloud sync, you must purchase an auto-renewing subscription through the App Store. Payment is processed by Apple; we do not receive your payment card details. When subscribed, your habits, completions, reminders, and notes are stored in your personal iCloud account so they can appear on your other Apple devices. You can turn iCloud sync off at any time; the app then keeps working from the local copy on that device. Manage or cancel the subscription in your Apple ID account settings.

1.3 Optional Self-Hosted Sync

If you connect a compatible self-hosted server, the app sends your account credentials and synchronized data (habits, tags, reminders, completions, and notes) to the server you select. Your password is not stored; after sign-in, the authentication token is kept in the iOS Keychain. The server operator controls how that data is processed and retained.

2. Analytics, Advertising & Tracking

We do not use advertising, analytics, or tracking SDKs. We do not sell your personal data. Data is transmitted only when needed for a feature you choose, such as iCloud sync or synchronization with your selected self-hosted server.

3. Disconnecting & Deleting Data

Turning off iCloud sync keeps a local copy on this device and stops updating the iCloud document from this app. Disconnecting a self-hosted server stops synchronization and removes the saved authentication token from the app, but it does not delete data already stored on that server.

When connected to a compatible server, you can use Delete Account in the app to permanently disable access and remove your synchronized and personally identifiable account data from that server. A server may retain an anonymous, disabled archival record that cannot be used to sign in or recover your data. This action cannot be undone. Removing the app deletes its local app data from your device, but does not by itself delete an account or data retained by a self-hosted server.

4. Security

Connections to internet-hosted servers must use HTTPS. The app also supports HTTP connections to servers on your local network for self-hosting. You are responsible for selecting and securing the server you connect to.

5. Contact

If you have questions about this policy, please contact us at GitHub Issues.

6. Changes

We may update this policy from time to time. Changes will be posted on this page.

© 2026 Changjian Zhu. All rights reserved.