Privacy Policy

Privacy Policy for Turtle - Family Habit & Goal Tracker

Introduction

Welcome to Turtle! Your privacy and the privacy of your family members is extremely important to us. This Privacy Policy explains how Turtle ("we," "our," "us") collects, uses, stores, shares, and protects your personal information when you use our mobile application and related services (collectively, the "App").

Turtle is a family habit and goal tracking application. Because families may include children under the age of 13, we take special care to comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

By using Turtle, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.

1. Information We Collect

We collect several types of information to provide and improve our services:

1.1 Personal Information You Provide Directly

When you create an account and use Turtle, you voluntarily provide us with:

  • Account Information:

    • Name (first and last name)

    • Email address

    • Password (encrypted and stored securely)

    • Date of birth (to verify age and provide age-appropriate experiences)

  • Family Member Information:

    • Names of family members you add to your family group

    • Dates of birth of family members

    • Relationships (e.g., parent, child, grandparent)

    • Profile pictures (optional)

  • User-Generated Content:

    • Habits you create and track (descriptions, frequency, progress)

    • Goals you set (descriptions, target dates, milestones, progress)

    • Notes, comments, and reflections you add

    • Completion records and tracking data

    • Any other content you voluntarily input into the App

  • Subscription and Payment Information:

    • Subscription tier (Explorer, Premium Monthly, Premium Annual)

    • Payment information is processed by Apple App Store or Google Play Store. We do not directly collect or store your full credit card information, but we receive transaction receipts and subscription status from these platforms.

1.2 Information Collected Automatically

When you use Turtle, we automatically collect certain information:

  • Device Information:

    • Device type, model, and operating system (iOS/Android version)

    • Unique device identifiers (e.g., IDFA on iOS, Advertising ID on Android)

    • Mobile network information

    • Device language and region settings

  • Usage Information:

    • Features you use within the App

    • Time spent on the App

    • Frequency of use

    • Pages or screens viewed

    • Actions taken (e.g., habits completed, goals updated)

    • App crashes and performance data

  • Location Information (Optional):

    • We may collect approximate location data (city/country level) based on your IP address for analytics and regional features, but we do not collect precise GPS location unless you explicitly grant permission for location-based features.

  • Cookies and Similar Technologies:

    • We may use cookies, pixel tags, and similar technologies to enhance user experience, understand usage patterns, and remember your preferences. You can control cookies through your device settings.

1.3 Information from Third Parties

We may receive information from third-party services we use to operate Turtle:

  • Authentication Services: If you sign in using Apple Sign-In, Google Sign-In, or other social authentication, we receive basic profile information (name, email) as permitted by those services.

  • Subscription Management Services: We use RevenueCat to manage subscriptions. RevenueCat provides us with subscription status, purchase events, and transaction data.

  • Analytics Services: We use analytics tools to understand how users interact with the App (see Section 4 for details).

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 To Provide and Improve Our Services

  • Create and manage your account and family group

  • Enable habit and goal tracking functionality

  • Store and sync your data across devices

  • Provide personalized features and recommendations

  • Improve App performance, features, and user experience

  • Conduct research and analytics to understand user behavior

  • Develop new features and services

2.2 To Communicate with You

  • Send important service notifications (e.g., account updates, subscription status)

  • Respond to your inquiries and support requests

  • Send push notifications about habit reminders and goal milestones (you can opt out in settings)

  • Send promotional emails about new features or offers (you can opt out at any time)

2.3 To Process Payments and Subscriptions

  • Process subscription purchases through Apple App Store or Google Play Store

  • Manage subscription renewals, upgrades, and cancellations

  • Verify subscription status and entitlements

  • Prevent fraud and unauthorized access

2.4 To Ensure Safety and Security

  • Protect against fraud, abuse, and security threats

  • Enforce our Terms of Service

  • Comply with legal obligations

  • Protect the rights, property, and safety of Turtle, our users, and others

2.5 For Legal and Compliance Purposes

  • Comply with applicable laws, regulations, and legal processes

  • Respond to lawful requests from public authorities

  • Establish, exercise, or defend legal claims

3. Legal Basis for Processing (GDPR Compliance)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

  • Consent: You have given us explicit consent to process your personal information for specific purposes (e.g., sending marketing communications, collecting optional profile pictures).

  • Contractual Necessity: Processing is necessary to perform our contract with you (i.e., providing the Turtle App services you've signed up for).

  • Legitimate Interests: We process your data for our legitimate business interests, such as improving our services, analytics, fraud prevention, and security, provided these interests do not override your fundamental rights and freedoms.

  • Legal Obligation: We process your data to comply with legal obligations, such as tax requirements or responding to lawful requests.

You have the right to withdraw consent at any time, though this will not affect the lawfulness of processing based on consent before its withdrawal.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. However, we may share your information in the following limited circumstances:

4.1 Service Providers

We share information with trusted third-party service providers who help us operate Turtle:

  • Cloud Hosting: We use [AWS/Google Cloud/Firebase - specify your provider] to host and store your data securely.

  • Subscription Management: We use RevenueCat to process and manage in-app subscriptions.

  • Analytics: We use [Google Analytics/Mixpanel/Firebase Analytics - specify] to understand app usage and improve our services.

  • Authentication: We use Apple Sign-In, Google Sign-In, or similar services for secure login.

  • Customer Support: We may use customer support platforms to respond to your inquiries.

  • Email Services: We use [specify provider, e.g., SendGrid, AWS SES] to send transactional and promotional emails.

These service providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders, warrants)

  • Requests from government authorities

  • National security or law enforcement requirements

  • Protection of our rights, property, or safety, or that of our users or the public

4.3 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email or prominent notice in the App before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5. Children's Privacy (COPPA Compliance)

Turtle is designed for families, which may include children under the age of 13. We are committed to protecting children's privacy and complying with the Children's Online Privacy Protection Act (COPPA).

5.1 Parental Consent

  • Verifiable Parental Consent Required: We require a parent or legal guardian to create the family account. By adding a child under 13 to your family group, you confirm that you are the parent or legal guardian and consent to the collection of that child's information as described in this Privacy Policy.

  • What We Collect from Children: For children under 13, we collect only the following information:

    • First name (or nickname)

    • Age or date of birth

    • Habit and goal tracking data

    • Usage information (how they interact with the App)

  • How We Use Children's Information: We use this information solely to:

    • Enable habit and goal tracking for the child

    • Provide age-appropriate content and features

    • Sync data across family members' devices

    • Improve the App's functionality

  • We Do Not:

    • Require children to provide more information than reasonably necessary

    • Share children's information with third parties except as described in Section 4

    • Display personalized advertisements to children

    • Allow children to publicly share personal information

5.2 Parental Rights and Controls

Parents and legal guardians have the following rights regarding their children's information:

  • Review: Request access to the personal information we have collected from your child

  • Delete: Request deletion of your child's personal information

  • Refuse Further Collection: Refuse to allow further collection or use of your child's information (though this may limit the child's ability to use the App)

  • Remove Child: Remove a child from your family group at any time

To exercise these rights, please contact us at privacy@turtlehabits.com or through the App's settings.

5.3 Age Verification

We verify that the account creator is at least 18 years old (or the age of majority in their jurisdiction) through date of birth verification during account creation.

6. Your Rights Under GDPR (European Users)

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

6.1 Right of Access

You have the right to request access to the personal information we hold about you and receive a copy of that data.

6.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal information.

6.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal information under certain circumstances (e.g., when the data is no longer necessary, you withdraw consent, or you object to processing).

6.4 Right to Restriction of Processing

You have the right to request that we limit how we process your personal information in certain situations.

6.5 Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format and request that we transfer it to another service provider.

6.6 Right to Object

You have the right to object to our processing of your personal information, particularly for direct marketing purposes or when we process data based on legitimate interests.

6.7 Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority in your country if you believe we have violated your privacy rights.

To exercise these rights, please contact us at privacy@turtlehabits.com.

7. Your Rights Under CCPA (California Residents)

If you are a resident of California, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information:

7.1 Right to Know

You have the right to request details about:

  • The categories and specific pieces of personal information we have collected about you

  • The categories of sources from which we collected your information

  • The business or commercial purpose for collecting your information

  • The categories of third parties with whom we share your information

7.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., to complete a transaction, comply with legal obligations, or detect security incidents).

7.3 Right to Opt-Out of Sale

We do not sell your personal information. If our practices change in the future, we will update this Privacy Policy and provide you with an opportunity to opt out.

7.4 Right to Non-Discrimination

You will not be discriminated against for exercising your CCPA rights. We will not:

  • Deny you access to the App

  • Charge you different prices or rates

  • Provide you with a different level or quality of service

7.5 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority.

To exercise these rights, please contact us at privacy@turtlehabits.com or submit a request through the App settings.

We will verify your identity before responding to your request and will respond within 45 days.

8. Data Security

We take the security of your personal information seriously and implement reasonable technical, administrative, and physical safeguards to protect it:

8.1 Security Measures

  • Encryption: All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols.

  • Secure Storage: Personal information is stored on secure servers with encryption at rest.

  • Access Controls: We limit access to personal information to authorized employees and service providers who need it to perform their duties.

  • Regular Audits: We conduct regular security assessments and audits to identify and address vulnerabilities.

  • Password Protection: User passwords are hashed and salted using strong cryptographic algorithms.

8.2 No Guarantee of Absolute Security

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security practices.

8.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

9.1 Active Accounts

  • While your account is active, we retain all personal information, habits, goals, and tracking data to provide you with ongoing service.

9.2 Account Deletion

  • When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal, tax, or regulatory purposes.

  • Backup copies may persist in our systems for up to 90 days before complete deletion.

9.3 Subscription Data

  • Subscription and transaction records may be retained for up to 7 years to comply with tax and financial regulations.

9.4 Analytics Data

  • Aggregated, anonymized analytics data may be retained indefinitely as it cannot be used to identify you.

10. International Data Transfers

Turtle is operated from [specify your country, e.g., United States]. If you are located outside of [your country], please note that the information we collect will be transferred to and processed in [your country] and other countries where our service providers operate.

10.1 EEA/UK Data Transfers

For users in the EEA or UK, we ensure that international data transfers comply with GDPR through:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our service providers.

  • Adequacy Decisions: We may transfer data to countries deemed to provide adequate protection by the European Commission.

  • Your Consent: In some cases, we may rely on your explicit consent for data transfers.

11. Third-Party Links and Services

The App may contain links to third-party websites, services, or applications (e.g., social media platforms, help articles). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any personal information.

12. Push Notifications

Turtle may send you push notifications to remind you about habits, goal milestones, or important updates. You can control push notifications through your device settings or within the App settings at any time.

13. Your Choices and Controls

You have several choices regarding your information:

13.1 Account Settings

  • Update your name, email, profile picture, and other account information in the App settings.

13.2 Family Members

  • Add or remove family members from your family group at any time.

13.3 Marketing Communications

  • Opt out of promotional emails by clicking the "unsubscribe" link in any marketing email or adjusting your email preferences in the App.

13.4 Push Notifications

  • Disable push notifications in your device settings or App settings.

13.5 Data Access and Deletion

  • Request access to your data or request deletion of your account through the App settings or by emailing privacy@turtlehabits.com.

13.6 Cookie Controls

  • Manage cookies and tracking technologies through your device or browser settings.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or App features. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Privacy Policy

  • Notify you via email (if you have provided an email address) or through an in-App notification

  • In some cases, request your consent if required by law

We encourage you to review this Privacy Policy periodically. Your continued use of the App after any changes indicates your acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Turtle - Family Habit & Goal Tracker
Email: privacy@turtlehabits.com
Support: info@turtlehabits.com

For GDPR-related inquiries (EEA/UK users):
Data Protection Officer: [Name/Email if applicable]

For COPPA-related inquiries (parents/guardians):
Email: privacy@turtlehabits.com
Subject Line: "COPPA Request - Children's Privacy"

We will respond to all legitimate requests within 30 days (or as required by applicable law).

16. App Store Privacy Labels

For transparency, here is a summary of how our privacy practices align with App Store and Google Play Store privacy labels:

Data Linked to You:

  • Name, email address, date of birth

  • User-generated content (habits, goals, notes)

  • Usage data and analytics

  • Device identifiers

Data Not Linked to You:

  • Aggregated analytics (anonymized)

Data Used to Track You:

  • Device identifiers for analytics and advertising (if applicable)

17. Compliance Summary

This Privacy Policy complies with:

  • ✅ General Data Protection Regulation (GDPR) - EEA/UK

  • ✅ California Consumer Privacy Act (CCPA) - California, USA

  • ✅ Children's Online Privacy Protection Act (COPPA) - USA

  • ✅ Apple App Store Privacy Requirements

  • ✅ Google Play Store Privacy Requirements

  • ✅ Other applicable state, federal, and international privacy laws

By using Turtle, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Last Updated: 27th April 2027

Introduction

Welcome to Turtle! Your privacy and the privacy of your family members is extremely important to us. This Privacy Policy explains how Turtle ("we," "our," "us") collects, uses, stores, shares, and protects your personal information when you use our mobile application and related services (collectively, the "App").

Turtle is a family habit and goal tracking application. Because families may include children under the age of 13, we take special care to comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

By using Turtle, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.

1. Information We Collect

We collect several types of information to provide and improve our services:

1.1 Personal Information You Provide Directly

When you create an account and use Turtle, you voluntarily provide us with:

  • Account Information:

    • Name (first and last name)

    • Email address

    • Password (encrypted and stored securely)

    • Date of birth (to verify age and provide age-appropriate experiences)

  • Family Member Information:

    • Names of family members you add to your family group

    • Dates of birth of family members

    • Relationships (e.g., parent, child, grandparent)

    • Profile pictures (optional)

  • User-Generated Content:

    • Habits you create and track (descriptions, frequency, progress)

    • Goals you set (descriptions, target dates, milestones, progress)

    • Notes, comments, and reflections you add

    • Completion records and tracking data

    • Any other content you voluntarily input into the App

  • Subscription and Payment Information:

    • Subscription tier (Explorer, Premium Monthly, Premium Annual)

    • Payment information is processed by Apple App Store or Google Play Store. We do not directly collect or store your full credit card information, but we receive transaction receipts and subscription status from these platforms.

1.2 Information Collected Automatically

When you use Turtle, we automatically collect certain information:

  • Device Information:

    • Device type, model, and operating system (iOS/Android version)

    • Unique device identifiers (e.g., IDFA on iOS, Advertising ID on Android)

    • Mobile network information

    • Device language and region settings

  • Usage Information:

    • Features you use within the App

    • Time spent on the App

    • Frequency of use

    • Pages or screens viewed

    • Actions taken (e.g., habits completed, goals updated)

    • App crashes and performance data

  • Location Information (Optional):

    • We may collect approximate location data (city/country level) based on your IP address for analytics and regional features, but we do not collect precise GPS location unless you explicitly grant permission for location-based features.

  • Cookies and Similar Technologies:

    • We may use cookies, pixel tags, and similar technologies to enhance user experience, understand usage patterns, and remember your preferences. You can control cookies through your device settings.

1.3 Information from Third Parties

We may receive information from third-party services we use to operate Turtle:

  • Authentication Services: If you sign in using Apple Sign-In, Google Sign-In, or other social authentication, we receive basic profile information (name, email) as permitted by those services.

  • Subscription Management Services: We use RevenueCat to manage subscriptions. RevenueCat provides us with subscription status, purchase events, and transaction data.

  • Analytics Services: We use analytics tools to understand how users interact with the App (see Section 4 for details).

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 To Provide and Improve Our Services

  • Create and manage your account and family group

  • Enable habit and goal tracking functionality

  • Store and sync your data across devices

  • Provide personalized features and recommendations

  • Improve App performance, features, and user experience

  • Conduct research and analytics to understand user behavior

  • Develop new features and services

2.2 To Communicate with You

  • Send important service notifications (e.g., account updates, subscription status)

  • Respond to your inquiries and support requests

  • Send push notifications about habit reminders and goal milestones (you can opt out in settings)

  • Send promotional emails about new features or offers (you can opt out at any time)

2.3 To Process Payments and Subscriptions

  • Process subscription purchases through Apple App Store or Google Play Store

  • Manage subscription renewals, upgrades, and cancellations

  • Verify subscription status and entitlements

  • Prevent fraud and unauthorized access

2.4 To Ensure Safety and Security

  • Protect against fraud, abuse, and security threats

  • Enforce our Terms of Service

  • Comply with legal obligations

  • Protect the rights, property, and safety of Turtle, our users, and others

2.5 For Legal and Compliance Purposes

  • Comply with applicable laws, regulations, and legal processes

  • Respond to lawful requests from public authorities

  • Establish, exercise, or defend legal claims

3. Legal Basis for Processing (GDPR Compliance)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

  • Consent: You have given us explicit consent to process your personal information for specific purposes (e.g., sending marketing communications, collecting optional profile pictures).

  • Contractual Necessity: Processing is necessary to perform our contract with you (i.e., providing the Turtle App services you've signed up for).

  • Legitimate Interests: We process your data for our legitimate business interests, such as improving our services, analytics, fraud prevention, and security, provided these interests do not override your fundamental rights and freedoms.

  • Legal Obligation: We process your data to comply with legal obligations, such as tax requirements or responding to lawful requests.

You have the right to withdraw consent at any time, though this will not affect the lawfulness of processing based on consent before its withdrawal.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. However, we may share your information in the following limited circumstances:

4.1 Service Providers

We share information with trusted third-party service providers who help us operate Turtle:

  • Cloud Hosting: We use [AWS/Google Cloud/Firebase - specify your provider] to host and store your data securely.

  • Subscription Management: We use RevenueCat to process and manage in-app subscriptions.

  • Analytics: We use [Google Analytics/Mixpanel/Firebase Analytics - specify] to understand app usage and improve our services.

  • Authentication: We use Apple Sign-In, Google Sign-In, or similar services for secure login.

  • Customer Support: We may use customer support platforms to respond to your inquiries.

  • Email Services: We use [specify provider, e.g., SendGrid, AWS SES] to send transactional and promotional emails.

These service providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders, warrants)

  • Requests from government authorities

  • National security or law enforcement requirements

  • Protection of our rights, property, or safety, or that of our users or the public

4.3 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email or prominent notice in the App before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5. Children's Privacy (COPPA Compliance)

Turtle is designed for families, which may include children under the age of 13. We are committed to protecting children's privacy and complying with the Children's Online Privacy Protection Act (COPPA).

5.1 Parental Consent

  • Verifiable Parental Consent Required: We require a parent or legal guardian to create the family account. By adding a child under 13 to your family group, you confirm that you are the parent or legal guardian and consent to the collection of that child's information as described in this Privacy Policy.

  • What We Collect from Children: For children under 13, we collect only the following information:

    • First name (or nickname)

    • Age or date of birth

    • Habit and goal tracking data

    • Usage information (how they interact with the App)

  • How We Use Children's Information: We use this information solely to:

    • Enable habit and goal tracking for the child

    • Provide age-appropriate content and features

    • Sync data across family members' devices

    • Improve the App's functionality

  • We Do Not:

    • Require children to provide more information than reasonably necessary

    • Share children's information with third parties except as described in Section 4

    • Display personalized advertisements to children

    • Allow children to publicly share personal information

5.2 Parental Rights and Controls

Parents and legal guardians have the following rights regarding their children's information:

  • Review: Request access to the personal information we have collected from your child

  • Delete: Request deletion of your child's personal information

  • Refuse Further Collection: Refuse to allow further collection or use of your child's information (though this may limit the child's ability to use the App)

  • Remove Child: Remove a child from your family group at any time

To exercise these rights, please contact us at privacy@turtlehabits.com or through the App's settings.

5.3 Age Verification

We verify that the account creator is at least 18 years old (or the age of majority in their jurisdiction) through date of birth verification during account creation.

6. Your Rights Under GDPR (European Users)

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

6.1 Right of Access

You have the right to request access to the personal information we hold about you and receive a copy of that data.

6.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal information.

6.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal information under certain circumstances (e.g., when the data is no longer necessary, you withdraw consent, or you object to processing).

6.4 Right to Restriction of Processing

You have the right to request that we limit how we process your personal information in certain situations.

6.5 Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format and request that we transfer it to another service provider.

6.6 Right to Object

You have the right to object to our processing of your personal information, particularly for direct marketing purposes or when we process data based on legitimate interests.

6.7 Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority in your country if you believe we have violated your privacy rights.

To exercise these rights, please contact us at privacy@turtlehabits.com.

7. Your Rights Under CCPA (California Residents)

If you are a resident of California, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information:

7.1 Right to Know

You have the right to request details about:

  • The categories and specific pieces of personal information we have collected about you

  • The categories of sources from which we collected your information

  • The business or commercial purpose for collecting your information

  • The categories of third parties with whom we share your information

7.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., to complete a transaction, comply with legal obligations, or detect security incidents).

7.3 Right to Opt-Out of Sale

We do not sell your personal information. If our practices change in the future, we will update this Privacy Policy and provide you with an opportunity to opt out.

7.4 Right to Non-Discrimination

You will not be discriminated against for exercising your CCPA rights. We will not:

  • Deny you access to the App

  • Charge you different prices or rates

  • Provide you with a different level or quality of service

7.5 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority.

To exercise these rights, please contact us at privacy@turtlehabits.com or submit a request through the App settings.

We will verify your identity before responding to your request and will respond within 45 days.

8. Data Security

We take the security of your personal information seriously and implement reasonable technical, administrative, and physical safeguards to protect it:

8.1 Security Measures

  • Encryption: All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols.

  • Secure Storage: Personal information is stored on secure servers with encryption at rest.

  • Access Controls: We limit access to personal information to authorized employees and service providers who need it to perform their duties.

  • Regular Audits: We conduct regular security assessments and audits to identify and address vulnerabilities.

  • Password Protection: User passwords are hashed and salted using strong cryptographic algorithms.

8.2 No Guarantee of Absolute Security

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security practices.

8.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

9.1 Active Accounts

  • While your account is active, we retain all personal information, habits, goals, and tracking data to provide you with ongoing service.

9.2 Account Deletion

  • When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal, tax, or regulatory purposes.

  • Backup copies may persist in our systems for up to 90 days before complete deletion.

9.3 Subscription Data

  • Subscription and transaction records may be retained for up to 7 years to comply with tax and financial regulations.

9.4 Analytics Data

  • Aggregated, anonymized analytics data may be retained indefinitely as it cannot be used to identify you.

10. International Data Transfers

Turtle is operated from [specify your country, e.g., United States]. If you are located outside of [your country], please note that the information we collect will be transferred to and processed in [your country] and other countries where our service providers operate.

10.1 EEA/UK Data Transfers

For users in the EEA or UK, we ensure that international data transfers comply with GDPR through:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our service providers.

  • Adequacy Decisions: We may transfer data to countries deemed to provide adequate protection by the European Commission.

  • Your Consent: In some cases, we may rely on your explicit consent for data transfers.

11. Third-Party Links and Services

The App may contain links to third-party websites, services, or applications (e.g., social media platforms, help articles). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any personal information.

12. Push Notifications

Turtle may send you push notifications to remind you about habits, goal milestones, or important updates. You can control push notifications through your device settings or within the App settings at any time.

13. Your Choices and Controls

You have several choices regarding your information:

13.1 Account Settings

  • Update your name, email, profile picture, and other account information in the App settings.

13.2 Family Members

  • Add or remove family members from your family group at any time.

13.3 Marketing Communications

  • Opt out of promotional emails by clicking the "unsubscribe" link in any marketing email or adjusting your email preferences in the App.

13.4 Push Notifications

  • Disable push notifications in your device settings or App settings.

13.5 Data Access and Deletion

  • Request access to your data or request deletion of your account through the App settings or by emailing privacy@turtlehabits.com.

13.6 Cookie Controls

  • Manage cookies and tracking technologies through your device or browser settings.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or App features. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Privacy Policy

  • Notify you via email (if you have provided an email address) or through an in-App notification

  • In some cases, request your consent if required by law

We encourage you to review this Privacy Policy periodically. Your continued use of the App after any changes indicates your acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Turtle - Family Habit & Goal Tracker
Email: privacy@turtlehabits.com
Support: info@turtlehabits.com

For GDPR-related inquiries (EEA/UK users):
Data Protection Officer: [Name/Email if applicable]

For COPPA-related inquiries (parents/guardians):
Email: privacy@turtlehabits.com
Subject Line: "COPPA Request - Children's Privacy"

We will respond to all legitimate requests within 30 days (or as required by applicable law).

16. App Store Privacy Labels

For transparency, here is a summary of how our privacy practices align with App Store and Google Play Store privacy labels:

Data Linked to You:

  • Name, email address, date of birth

  • User-generated content (habits, goals, notes)

  • Usage data and analytics

  • Device identifiers

Data Not Linked to You:

  • Aggregated analytics (anonymized)

Data Used to Track You:

  • Device identifiers for analytics and advertising (if applicable)

17. Compliance Summary

This Privacy Policy complies with:

  • ✅ General Data Protection Regulation (GDPR) - EEA/UK

  • ✅ California Consumer Privacy Act (CCPA) - California, USA

  • ✅ Children's Online Privacy Protection Act (COPPA) - USA

  • ✅ Apple App Store Privacy Requirements

  • ✅ Google Play Store Privacy Requirements

  • ✅ Other applicable state, federal, and international privacy laws

By using Turtle, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Last Updated: 27th April 2027

Introduction

Welcome to Turtle! Your privacy and the privacy of your family members is extremely important to us. This Privacy Policy explains how Turtle ("we," "our," "us") collects, uses, stores, shares, and protects your personal information when you use our mobile application and related services (collectively, the "App").

Turtle is a family habit and goal tracking application. Because families may include children under the age of 13, we take special care to comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

By using Turtle, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.

1. Information We Collect

We collect several types of information to provide and improve our services:

1.1 Personal Information You Provide Directly

When you create an account and use Turtle, you voluntarily provide us with:

  • Account Information:

    • Name (first and last name)

    • Email address

    • Password (encrypted and stored securely)

    • Date of birth (to verify age and provide age-appropriate experiences)

  • Family Member Information:

    • Names of family members you add to your family group

    • Dates of birth of family members

    • Relationships (e.g., parent, child, grandparent)

    • Profile pictures (optional)

  • User-Generated Content:

    • Habits you create and track (descriptions, frequency, progress)

    • Goals you set (descriptions, target dates, milestones, progress)

    • Notes, comments, and reflections you add

    • Completion records and tracking data

    • Any other content you voluntarily input into the App

  • Subscription and Payment Information:

    • Subscription tier (Explorer, Premium Monthly, Premium Annual)

    • Payment information is processed by Apple App Store or Google Play Store. We do not directly collect or store your full credit card information, but we receive transaction receipts and subscription status from these platforms.

1.2 Information Collected Automatically

When you use Turtle, we automatically collect certain information:

  • Device Information:

    • Device type, model, and operating system (iOS/Android version)

    • Unique device identifiers (e.g., IDFA on iOS, Advertising ID on Android)

    • Mobile network information

    • Device language and region settings

  • Usage Information:

    • Features you use within the App

    • Time spent on the App

    • Frequency of use

    • Pages or screens viewed

    • Actions taken (e.g., habits completed, goals updated)

    • App crashes and performance data

  • Location Information (Optional):

    • We may collect approximate location data (city/country level) based on your IP address for analytics and regional features, but we do not collect precise GPS location unless you explicitly grant permission for location-based features.

  • Cookies and Similar Technologies:

    • We may use cookies, pixel tags, and similar technologies to enhance user experience, understand usage patterns, and remember your preferences. You can control cookies through your device settings.

1.3 Information from Third Parties

We may receive information from third-party services we use to operate Turtle:

  • Authentication Services: If you sign in using Apple Sign-In, Google Sign-In, or other social authentication, we receive basic profile information (name, email) as permitted by those services.

  • Subscription Management Services: We use RevenueCat to manage subscriptions. RevenueCat provides us with subscription status, purchase events, and transaction data.

  • Analytics Services: We use analytics tools to understand how users interact with the App (see Section 4 for details).

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 To Provide and Improve Our Services

  • Create and manage your account and family group

  • Enable habit and goal tracking functionality

  • Store and sync your data across devices

  • Provide personalized features and recommendations

  • Improve App performance, features, and user experience

  • Conduct research and analytics to understand user behavior

  • Develop new features and services

2.2 To Communicate with You

  • Send important service notifications (e.g., account updates, subscription status)

  • Respond to your inquiries and support requests

  • Send push notifications about habit reminders and goal milestones (you can opt out in settings)

  • Send promotional emails about new features or offers (you can opt out at any time)

2.3 To Process Payments and Subscriptions

  • Process subscription purchases through Apple App Store or Google Play Store

  • Manage subscription renewals, upgrades, and cancellations

  • Verify subscription status and entitlements

  • Prevent fraud and unauthorized access

2.4 To Ensure Safety and Security

  • Protect against fraud, abuse, and security threats

  • Enforce our Terms of Service

  • Comply with legal obligations

  • Protect the rights, property, and safety of Turtle, our users, and others

2.5 For Legal and Compliance Purposes

  • Comply with applicable laws, regulations, and legal processes

  • Respond to lawful requests from public authorities

  • Establish, exercise, or defend legal claims

3. Legal Basis for Processing (GDPR Compliance)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

  • Consent: You have given us explicit consent to process your personal information for specific purposes (e.g., sending marketing communications, collecting optional profile pictures).

  • Contractual Necessity: Processing is necessary to perform our contract with you (i.e., providing the Turtle App services you've signed up for).

  • Legitimate Interests: We process your data for our legitimate business interests, such as improving our services, analytics, fraud prevention, and security, provided these interests do not override your fundamental rights and freedoms.

  • Legal Obligation: We process your data to comply with legal obligations, such as tax requirements or responding to lawful requests.

You have the right to withdraw consent at any time, though this will not affect the lawfulness of processing based on consent before its withdrawal.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. However, we may share your information in the following limited circumstances:

4.1 Service Providers

We share information with trusted third-party service providers who help us operate Turtle:

  • Cloud Hosting: We use [AWS/Google Cloud/Firebase - specify your provider] to host and store your data securely.

  • Subscription Management: We use RevenueCat to process and manage in-app subscriptions.

  • Analytics: We use [Google Analytics/Mixpanel/Firebase Analytics - specify] to understand app usage and improve our services.

  • Authentication: We use Apple Sign-In, Google Sign-In, or similar services for secure login.

  • Customer Support: We may use customer support platforms to respond to your inquiries.

  • Email Services: We use [specify provider, e.g., SendGrid, AWS SES] to send transactional and promotional emails.

These service providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders, warrants)

  • Requests from government authorities

  • National security or law enforcement requirements

  • Protection of our rights, property, or safety, or that of our users or the public

4.3 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email or prominent notice in the App before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5. Children's Privacy (COPPA Compliance)

Turtle is designed for families, which may include children under the age of 13. We are committed to protecting children's privacy and complying with the Children's Online Privacy Protection Act (COPPA).

5.1 Parental Consent

  • Verifiable Parental Consent Required: We require a parent or legal guardian to create the family account. By adding a child under 13 to your family group, you confirm that you are the parent or legal guardian and consent to the collection of that child's information as described in this Privacy Policy.

  • What We Collect from Children: For children under 13, we collect only the following information:

    • First name (or nickname)

    • Age or date of birth

    • Habit and goal tracking data

    • Usage information (how they interact with the App)

  • How We Use Children's Information: We use this information solely to:

    • Enable habit and goal tracking for the child

    • Provide age-appropriate content and features

    • Sync data across family members' devices

    • Improve the App's functionality

  • We Do Not:

    • Require children to provide more information than reasonably necessary

    • Share children's information with third parties except as described in Section 4

    • Display personalized advertisements to children

    • Allow children to publicly share personal information

5.2 Parental Rights and Controls

Parents and legal guardians have the following rights regarding their children's information:

  • Review: Request access to the personal information we have collected from your child

  • Delete: Request deletion of your child's personal information

  • Refuse Further Collection: Refuse to allow further collection or use of your child's information (though this may limit the child's ability to use the App)

  • Remove Child: Remove a child from your family group at any time

To exercise these rights, please contact us at privacy@turtlehabits.com or through the App's settings.

5.3 Age Verification

We verify that the account creator is at least 18 years old (or the age of majority in their jurisdiction) through date of birth verification during account creation.

6. Your Rights Under GDPR (European Users)

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

6.1 Right of Access

You have the right to request access to the personal information we hold about you and receive a copy of that data.

6.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal information.

6.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal information under certain circumstances (e.g., when the data is no longer necessary, you withdraw consent, or you object to processing).

6.4 Right to Restriction of Processing

You have the right to request that we limit how we process your personal information in certain situations.

6.5 Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format and request that we transfer it to another service provider.

6.6 Right to Object

You have the right to object to our processing of your personal information, particularly for direct marketing purposes or when we process data based on legitimate interests.

6.7 Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority in your country if you believe we have violated your privacy rights.

To exercise these rights, please contact us at privacy@turtlehabits.com.

7. Your Rights Under CCPA (California Residents)

If you are a resident of California, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information:

7.1 Right to Know

You have the right to request details about:

  • The categories and specific pieces of personal information we have collected about you

  • The categories of sources from which we collected your information

  • The business or commercial purpose for collecting your information

  • The categories of third parties with whom we share your information

7.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., to complete a transaction, comply with legal obligations, or detect security incidents).

7.3 Right to Opt-Out of Sale

We do not sell your personal information. If our practices change in the future, we will update this Privacy Policy and provide you with an opportunity to opt out.

7.4 Right to Non-Discrimination

You will not be discriminated against for exercising your CCPA rights. We will not:

  • Deny you access to the App

  • Charge you different prices or rates

  • Provide you with a different level or quality of service

7.5 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority.

To exercise these rights, please contact us at privacy@turtlehabits.com or submit a request through the App settings.

We will verify your identity before responding to your request and will respond within 45 days.

8. Data Security

We take the security of your personal information seriously and implement reasonable technical, administrative, and physical safeguards to protect it:

8.1 Security Measures

  • Encryption: All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols.

  • Secure Storage: Personal information is stored on secure servers with encryption at rest.

  • Access Controls: We limit access to personal information to authorized employees and service providers who need it to perform their duties.

  • Regular Audits: We conduct regular security assessments and audits to identify and address vulnerabilities.

  • Password Protection: User passwords are hashed and salted using strong cryptographic algorithms.

8.2 No Guarantee of Absolute Security

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security practices.

8.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

9.1 Active Accounts

  • While your account is active, we retain all personal information, habits, goals, and tracking data to provide you with ongoing service.

9.2 Account Deletion

  • When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal, tax, or regulatory purposes.

  • Backup copies may persist in our systems for up to 90 days before complete deletion.

9.3 Subscription Data

  • Subscription and transaction records may be retained for up to 7 years to comply with tax and financial regulations.

9.4 Analytics Data

  • Aggregated, anonymized analytics data may be retained indefinitely as it cannot be used to identify you.

10. International Data Transfers

Turtle is operated from [specify your country, e.g., United States]. If you are located outside of [your country], please note that the information we collect will be transferred to and processed in [your country] and other countries where our service providers operate.

10.1 EEA/UK Data Transfers

For users in the EEA or UK, we ensure that international data transfers comply with GDPR through:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our service providers.

  • Adequacy Decisions: We may transfer data to countries deemed to provide adequate protection by the European Commission.

  • Your Consent: In some cases, we may rely on your explicit consent for data transfers.

11. Third-Party Links and Services

The App may contain links to third-party websites, services, or applications (e.g., social media platforms, help articles). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any personal information.

12. Push Notifications

Turtle may send you push notifications to remind you about habits, goal milestones, or important updates. You can control push notifications through your device settings or within the App settings at any time.

13. Your Choices and Controls

You have several choices regarding your information:

13.1 Account Settings

  • Update your name, email, profile picture, and other account information in the App settings.

13.2 Family Members

  • Add or remove family members from your family group at any time.

13.3 Marketing Communications

  • Opt out of promotional emails by clicking the "unsubscribe" link in any marketing email or adjusting your email preferences in the App.

13.4 Push Notifications

  • Disable push notifications in your device settings or App settings.

13.5 Data Access and Deletion

  • Request access to your data or request deletion of your account through the App settings or by emailing privacy@turtlehabits.com.

13.6 Cookie Controls

  • Manage cookies and tracking technologies through your device or browser settings.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or App features. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Privacy Policy

  • Notify you via email (if you have provided an email address) or through an in-App notification

  • In some cases, request your consent if required by law

We encourage you to review this Privacy Policy periodically. Your continued use of the App after any changes indicates your acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Turtle - Family Habit & Goal Tracker
Email: privacy@turtlehabits.com
Support: info@turtlehabits.com

For GDPR-related inquiries (EEA/UK users):
Data Protection Officer: [Name/Email if applicable]

For COPPA-related inquiries (parents/guardians):
Email: privacy@turtlehabits.com
Subject Line: "COPPA Request - Children's Privacy"

We will respond to all legitimate requests within 30 days (or as required by applicable law).

16. App Store Privacy Labels

For transparency, here is a summary of how our privacy practices align with App Store and Google Play Store privacy labels:

Data Linked to You:

  • Name, email address, date of birth

  • User-generated content (habits, goals, notes)

  • Usage data and analytics

  • Device identifiers

Data Not Linked to You:

  • Aggregated analytics (anonymized)

Data Used to Track You:

  • Device identifiers for analytics and advertising (if applicable)

17. Compliance Summary

This Privacy Policy complies with:

  • ✅ General Data Protection Regulation (GDPR) - EEA/UK

  • ✅ California Consumer Privacy Act (CCPA) - California, USA

  • ✅ Children's Online Privacy Protection Act (COPPA) - USA

  • ✅ Apple App Store Privacy Requirements

  • ✅ Google Play Store Privacy Requirements

  • ✅ Other applicable state, federal, and international privacy laws

By using Turtle, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Last Updated: 27th April 2027