Skip to content
Habitus Mind
Network Tracker Fitness Blog Access FAQ Request access
Request access

Contents

  1. Who is responsible
  2. What we collect
  3. Health data
  4. Data about other people
  5. AI processing
  6. Cookies and analytics
  7. Lawful bases
  8. Who receives it
  9. How long we keep it
  10. How we protect it
  11. Your GDPR rights
  12. Your PDPA rights
  13. Children
  14. Changes
  15. Contact and complaints

Privacy

Privacy notice

Version 1.0 · Last updated 5 September 2026

Habitus Mind holds real personal data — your account, what you log about your body, and details of people you meet. This notice sets out exactly what is stored, where it goes, and what you can make us do about it. Two parts deserve your attention above the rest: health data and data about other people.

1. Who is responsible

The controller (GDPR) and data user (Malaysia PDPA) for habitusmind.com is Habitus Mind [registered entity + SSM no., or "a business operated by [full name]"], based in Kuala Lumpur, Malaysia.

We publish no email address. Both routes below reach us directly:

  • Contact form — habitusmind.com/contact
  • WhatsApp — +60 12-210 4914

Under Article 12 a request is valid however it reaches us. We will not refuse one for arriving through the "wrong" channel.

2. What we collect

CategoryWhat it isWhere it comes from
AccountUsername, display name, hashed password, group, status, and — if you enable it — an encrypted two-factor secretYou, at sign-up
SecuritySign-in attempts with IP address, sessions, password-reset and two-factor challenges, rate-limit countersAutomatic
AuditA log of significant actions taken in your accountAutomatic
FitnessFood entries, exercise entries, weight logs, targets, quests, generated summariesYou
Number MethodNames, dates of birth and notes for people you add, and the readings generated from themYou
Network TrackerContact names, phone numbers, emails, employers, job titles, locations, social handles, traits, free-text notes, meeting records, and photographs including name cardsYou
EnquiriesName, email, message and IP address from the contact formYou
UsageCredits consumed and AI token usageAutomatic

We do not collect payment card details. We do not sell personal data, and we do not share it with data brokers or advertisers.

3. Health data — and what that means legally

What you log in the fitness module is health data. Weight, food intake and exercise say things about your body, and under GDPR Article 9 that is a "special category" — the most strictly protected class of personal data there is.

We process it on the basis of your explicit consent under Article 9(2)(a), given by choosing to use the fitness module and enter data into it. You can withdraw that consent at any time by asking us to delete your fitness records; we will do so, and you can keep using everything else.

It is visible only to you and to administrators of your group. We never use it for advertising, never sell it, and never share it with insurers or employers.

This is not a medical service. Nothing generated by the fitness module is medical advice, a diagnosis, or a substitute for a qualified professional.

4. Data about other people

Network Tracker and Number Method exist so you can store information about other people — their names, dates of birth, phone numbers, employers, notes about your conversations, and photographs of their name cards. Those people are data subjects too, and they did not give it to us. They gave it to you.

You are responsible for what you enter about them. Only record what you have a proper reason to record, keep it accurate, and do not enter anything a person would be shocked to read about themselves. Under Article 14, someone whose data you hold may be entitled to be told that you hold it.

If someone asks us to remove data another user holds about them, we will locate it and act — we can, because those records are indexed by owner. Ask through either channel in section 1.

5. AI processing

Some features send your content to Anthropic to be processed by a Claude model: reading and fitness summaries, name-card text extraction, and contact recall prompts. That means the relevant text or image — including the personal data it contains — leaves our servers and is processed in the United States.

Anthropic acts as our processor and, under its commercial terms, does not use the data to train its models. If you would rather no AI feature ever touched a particular record, do not run an AI action on it; the rest of the app works without them.

6. Cookies and analytics

We use a strictly necessary session cookie to keep you signed in. It cannot be turned off — without it there is no sign-in — and it needs no consent.

We also load Google Analytics 4, Google Tag Manager, and Google reCAPTCHA on the contact form.

Being straight with you: consent controls for analytics are not built yet. Analytics currently loads on page view rather than waiting for you to agree, which is not where we intend to leave it. A consent banner with a genuine reject option is the next change to this site. Until it ships, your browser's own cookie controls and tracking protection are the effective way to stop it, and Google's opt-out add-on blocks Analytics outright.

CookieSet byPurpose
Session cookieHabitus MindKeeps you signed in. HttpOnly, Secure, SameSite=Lax, checked server-side on every request
_ga, _ga_*Google AnalyticsCounts visits and distinguishes browsers
reCAPTCHA cookiesGoogleTells humans from bots on the contact form

7. Lawful bases

  • Contract (Art. 6(1)(b)) — running your account and the modules you use.
  • Explicit consent (Art. 9(2)(a)) — fitness and health data.
  • Consent (Art. 6(1)(a)) — analytics, once the controls in section 6 exist.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available: sign-in attempt logging, rate limiting, audit trails, and answering enquiries you send us.
  • Legal obligation (Art. 6(1)(c)) — where the law requires us to retain or disclose something.

8. Who receives it

  • Cloudflare, Inc. — hosting, CDN, and the D1 database your data lives in.
  • Anthropic, PBC — AI processing, as described in section 5.
  • Google LLC / Google Ireland Limited — analytics and reCAPTCHA.

All three are US-based, so personal data is transferred outside the EEA and outside Malaysia. Those transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses in each provider's data processing terms. We also disclose data where legally compelled to.

9. How long we keep it

DataKept for
Account, fitness, contacts, readingsUntil you delete them, or until your account is closed
Sessions, reset and two-factor challengesUntil they expire, then removed
Sign-in attempts and rate-limit counters[retention window] — kept only as long as needed to detect abuse
Audit log[retention window]
EnquiriesUntil archived and cleared, and deleted on request
Google AnalyticsNo longer than 14 months, the platform maximum

When you ask us to close your account we delete your records rather than keeping a dormant copy, except where we must retain something to meet a legal obligation.

10. How we protect it

  • Passwords are hashed with PBKDF2-SHA256, a unique random salt per user, and compared in constant time. We never store, log or transmit your password.
  • Optional two-factor authentication, with its secret stored encrypted.
  • Sessions use 256-bit random tokens checked against the database on every request, so disabling an account or signing out takes effect immediately.
  • Rate limiting and account lockout on repeated failed sign-ins.
  • A strict Content Security Policy, HSTS, and CSRF protection on state-changing requests.

No system is perfectly secure. If something does go wrong, our breach notification commitments set out exactly what we will tell you and when.

11. Your GDPR rights

Where the GDPR applies to you, you may request access to your data, correction, erasure, restriction, portability, and object to processing we base on legitimate interests. Where we rely on consent — including the explicit consent for health data — you may withdraw it at any time, without affecting processing already carried out.

We respond within one month, and will tell you if we need longer. We do not charge for this. Because you hold an account, we can identify your records precisely, so these rights are real and actionable here rather than theoretical.

12. Your PDPA rights

Malaysia's Personal Data Protection Act 2010, as amended, gives you rights of access and correction, the right to withdraw consent, the right to limit processing for direct marketing, and — following the 2024 amendments — data portability. Use either channel in section 1.

13. Children

Habitus Mind is not intended for children, and accounts are issued on request rather than by open sign-up. We do not knowingly process children's data. If you believe a child's data is held here — including as a contact recorded by another user — tell us and we will remove it.

14. Changes

Material changes update the version and date at the top of this page. If a change widens what we collect or introduces a new purpose, we will ask you again rather than rely on a decision you made about something narrower.

15. Contact and complaints

Use the contact form or WhatsApp, and say that your message is a privacy request so it is not read as a general enquiry. Security issues go through the security page instead.

You may complain to a supervisory authority without coming to us first. In the EEA or UK that is your national authority; in Malaysia, the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).

© 2026 Habitus Mind — AI technology for your social network and fitness, built in Malaysia.
Privacy Terms Security