Privacy Policy

Last updated: 2026-10-05

This policy explains what The 30-Day AI Habit ("we", "us") collects when you use The 30-Day AI Habit (the "app"), why, and the choices you have. We keep it short because we collect very little.

What we collect

We do not collect your conversations with any AI tool, your contacts, your location, or advertising identifiers. The app has no ads and no third-party analytics or tracking.

Usage statistics

To understand how the course is used and to improve it, we record simple events against your account: when you sign up and sign in, open the app, finish set-up, complete a day, play a Catch It quiz or Pop Quiz, or save a prompt. We look at these mainly in aggregate (for example, how many people reach Day 7). This data is deleted with your account.

Where you came from, and the Catch the AI game

If you arrive through a tagged link (for example one ending in ?ref=reddit) or from another website, we remember that source, in your browser for up to 30 days and, if you create an account, with your account. We use it only to learn which channels bring people to the course. It contains no personal details.

The public "Catch the AI" game needs no account. When you finish a round we record the score, which questions were answered correctly and the same source information. We do not record your name, email address, IP address or any account identifier with a game result, so game results are anonymous. If you then create an account on the same device, we link your account to that one result so we can tell how many sign-ups come from the game.

Optional marketing emails

At sign-up you can choose to receive occasional tips and updates by email. The box is not ticked by default, it is never required to use the app, and you can change your choice at any time in Me → Account & password. We only send marketing email to people who ticked it, and every message will let you opt out. Password-reset and account emails are service messages and are sent regardless.

How we use it

We never sell your data and we do not share it for advertising.

Reminders

Daily and weekly reminders are scheduled on your device as local notifications. They need your permission, and no push-notification service receives your data.

Where it is stored and who can access it

Your data is stored in a managed Postgres database (Neon) and the app and API are hosted on Vercel. Account and password-reset emails are sent through Resend. These providers process data on our behalf only to run the service. Connections to the app and database are encrypted in transit (HTTPS/TLS) and the database is encrypted at rest by the provider. Passwords are stored only as bcrypt hashes and sign-in tokens only as SHA-256 hashes. Only we can access the database, and only to operate and support the service. A signed-in session token is stored in your device's secure storage (Keychain / Keystore) or, on the web, in your browser's local storage.

Keeping your data

We keep your data while your account exists. Sign-in sessions expire after 90 days of inactivity.

Your choices and rights

Depending on where you live (for example the EU/UK under GDPR, or California under CCPA) you may have additional rights, including to object to or restrict processing and to complain to your data-protection authority. Contact us to exercise them.

Children

The app is not directed at children under 13 (or under 16 where local law requires), and we do not knowingly collect their data.

A reminder from the course

The 30-Day AI Habit teaches you not to paste private information into AI tools. Please follow that advice in this app too: don't put passwords, client secrets or other sensitive details in your notes.

Changes

If we change this policy in a meaningful way we will update the date above and, where appropriate, tell you in the app.

Contact

The 30-Day AI Habit · ask@shaaz.online