Hibi is a local-first app. Your habits, dates, notes, and goals live on your device and nowhere else. There is no account, no analytics, and no third-party tracker. The one time anything leaves your phone is if you tap yes on the Weekly Recap, which sends habit names only — and even then, nothing is stored at the other end.
What Hibi collects
Nothing about you goes to a server we run. There is no server we run.
Everything you enter into Hibi — habit names, goals, dates you marked, timer sessions, calendar notes — is written to a local database on your device. When you delete the app, that database is deleted with it. There is no copy elsewhere for us to hand over, sell, subpoena, or lose in a breach.
What Hibi does not collect
- No account. There is no sign-up, no email, no password, no social login. The app opens straight into the first habit.
- No analytics. Hibi ships without a single third-party analytics SDK — no Firebase Analytics, no Mixpanel, no PostHog, no Amplitude. We do not know how many people opened the app today.
- No advertising identifiers. Hibi never requests your IDFA (iOS) or Advertising ID (Android). We do not participate in ad networks.
- No crash reporting that phones home by default. If the app crashes and you agreed to share the report at the OS-level prompt, iOS sends it to Apple in an anonymised form. We receive an aggregate summary from Apple — never your habit data.
- No location, contacts, photos, or microphone access. Hibi asks for none of these permissions.
The one exception — Weekly Recap
Once a week, if you turn on the optional Weekly Recap, Hibi asks a language model to write a short review of the week that just ended. To do that, it sends the following:
- The names of your habits
- Which dates in the past week each habit was kept, missed, or partial
That is the entire payload. No account identifier goes with it — the request is not tied to a "you" anywhere. The reply comes back, is shown to you on Flow, and is written to your local database. Nothing about the request or reply is retained at the other end.
This feature is off until you turn it on, and it prompts for your consent again before the first send. You can turn it off any time in Settings.
The Weekly Recap request is sent to Anthropic's Claude API. Anthropic's data policy for API requests without account association is available at anthropic.com/legal/privacy. Anthropic states that API request data is not used to train models by default.
Local backup and export
Hibi offers two ways to move your data:
- iCloud backup (iOS). If you have iCloud Backup enabled on your device, iOS may include Hibi's local database in the encrypted device backup Apple stores on your behalf. We do not read it and cannot access it — it is between you and Apple. See Apple's iCloud privacy page for the specifics.
- Export. Settings → Export creates a JSON file of your habits, dates, and notes and saves it to a location you pick. That file goes wherever you send it, and nowhere else. We never receive it.
Children
Hibi does not knowingly collect information from anyone, of any age. Since we collect nothing, no age gate is required.
Changes to this policy
If we ever change what Hibi collects or where it sends anything, this page is updated first, and the change is called out in the app's release notes. The date at the top of this page shows when the current version took effect. Older versions of this policy are kept in the app's GitHub repository so you can compare them.
Contact
Questions, corrections, or a request to check what any of this means for you: hello@sequoia-lab.com.
Hibi is made by Sequoia Lab. This policy is written in plain language on purpose — if any part reads like it means something different from what it says, tell us and we will fix it.