Legal

Privacy Policy

Last updated: 4 June 2026

Lagan ("we", "our", or "us") provides a habit tracking app and website. This policy explains what personal data we collect, why we use it, when we share it, and the choices you have.

1. Data we collect

Account data. When you create an account, we collect your email address, authentication identifiers, and any profile details you choose to add, such as display name and avatar settings.

Habit and progress data. We store the habits you create, goals, reminder settings, completion logs, streaks, XP, badges, sleep entries, and related progress statistics.

Health and sensor data. If you grant permission, Lagan reads step-count and sleep data from Android Health Connect, sleep data from Apple HealthKit, and step data from your device pedometer or motion sensor. You can also enter sleep and habit data manually.

AI feature inputs. When you use AI Coach, AI routine refinement, AI smart reminders, validation, or weekly reports, we process relevant habit names, progress, completion history, reminder context, onboarding answers, and similar app data needed to generate the response.

Subscription data. If you subscribe to Lagan Pro, we receive subscription status, entitlement, product ID, billing period, platform, and store identifiers from RevenueCat. We do not receive or store your payment card details.

Device, diagnostics, and support data.We may process app version, platform, operating system, device model, crash reports, error logs, product analytics events, feedback messages, support requests, and approximate technical identifiers needed to operate and secure the service.

2. Health data commitments

Lagan uses Health Connect, HealthKit, pedometer, and motion data only to provide the health and fitness features you choose, such as step habits, sleep tracking, sleep scores, habit progress, and reminders.

  • We request only the health data types needed for the feature you enable.
  • You can deny or revoke health permissions in your device settings.
  • Manual habit and sleep logging remains available if you do not grant access.
  • We do not sell health data, use it for advertising, transfer it to data brokers, use it for creditworthiness, or use it for unrelated secondary purposes.
  • Health data may be stored in your Lagan account when needed to sync your progress across devices and display it inside the app.

3. How we use data

We use personal data to:

  • Provide habit tracking, streaks, XP, badges, leaderboards, sleep tracking, and data export.
  • Generate AI coaching, routine suggestions, smart reminders, and progress reports.
  • Send reminders and push notifications you configure or allow.
  • Verify Lagan Pro trials, subscriptions, restore purchases, and entitlements.
  • Respond to support, feedback, security, and account deletion requests.
  • Measure product reliability and improve features using limited analytics and crash data.
  • Prevent abuse, protect accounts, comply with law, and enforce our Terms.

We do not sell your personal data.

4. AI processing

Lagan uses Google Gemini through server-side Supabase Edge Functions for AI-powered habit coaching, routine refinement, smart reminders, habit validation, and weekly reports. We send only the data reasonably needed for the specific AI feature. We do not send passwords, payment card data, or raw store payment details to the AI model.

AI outputs may be inaccurate or incomplete. Lagan validates and limits many AI responses before showing them, but AI features are not medical, legal, financial, or professional advice.

5. Cookies and local storage

On the website, we use Supabase authentication cookies to keep you signed in and a timezone cookie named lagan_tz to show dates in your local timezone. In the mobile app, we use local storage and secure storage for session state, opt-out preferences, tracking preferences, and similar app settings.

6. Sharing and public features

We share data with service providers only to operate Lagan, process subscriptions, deliver notifications, provide AI features, monitor reliability, support users, and comply with legal obligations.

If you opt in to the leaderboard by setting a display name, your display name, avatar, rank, XP, level, streak, and aggregate habit stats may be visible to other users in leaderboard and sharing features. You can opt out by removing your display name from the leaderboard.

7. Third-party services

Supabase

Authentication, database storage, serverless functions, and website auth cookies.

RevenueCat

Subscription management, purchase restoration, and App Store / Google Play entitlement verification.

Google Gemini

AI coaching, routine refinement, smart reminders, habit validation, and progress reports.

PostHog

Product analytics events. We do not intentionally send habit names, notes, email addresses, or health samples in analytics events. You can opt out in Settings.

Sentry

Crash reporting and error monitoring. You can opt out of crash reporting in Settings.

Google Cloud / Firebase Cloud Messaging

Android push notification delivery and related cloud infrastructure.

Apple APNs

iOS push notification delivery.

Apple App Store and Google Play

In-app purchase billing, subscription renewals, refunds, and store account management.

Google Sign-In

Optional account sign-in using your Google identity.

8. Data retention and deletion

We keep account and app data while your account is active or as needed to provide the service. When your account deletion request completes, we delete your authentication account, profile, habits, completions, sleep entries, and feedback linked to your account.

We may retain limited operational records, security logs, subscription records, completed deletion audit records, and legal or tax records where necessary for security, abuse prevention, compliance, dispute handling, or store-policy audit obligations. These retained records are not used to restore your deleted account.

9. Your choices and rights

Depending on your location, you may have rights to access, correct, export, object to, or delete personal data. You can:

  • Export your data in the mobile app from Settings, then Privacy & Data, then View my data export.
  • Delete your account from Settings, then Privacy & Data, then Request account deletion, or visit our account deletion page.
  • Opt out of analytics and crash reporting from Settings, then Privacy & Data.
  • Control health permissions in Android Health Connect, Apple Health, or your device settings.
  • Control notifications in Lagan reminder settings and your device notification settings.
  • Contact us at privacy@lagan.health.

10. International transfers

Lagan and its service providers may process data in countries other than where you live. Where required, we rely on appropriate legal safeguards and service-provider terms for these transfers.

11. Children

Lagan is not directed to children under 13 or the minimum digital-consent age in your jurisdiction. We do not knowingly collect personal data from children. If you believe a child has provided data to Lagan, contact us and we will take appropriate steps to delete it.

12. Security

We use technical and organizational safeguards designed to protect personal data, including encrypted transport, access controls, row-level database protections, and monitoring. No system is completely secure, so you should use a strong password and protect access to your email and device.

13. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date. For material changes, we may also provide notice by email, in-app message, website notice, or another appropriate method.

14. Contact

For privacy questions or requests, email privacy@lagan.health or contact support at support@lagan.health.

Lagan Health