Habit Networks
Privacy Policy
Effective and last updated:
This policy explains how Habit Networks handles information in connection with our website, client workspaces, Eyes browser extension, support services, and connected accounts. The information processed depends on the features you use and the permissions you grant.
Who this policy covers
Habit Networks operates the Habit Networks website and services. This policy covers information we handle for our own website, account administration, support, and service operations. When an organization uses our tools to manage its websites or work, that organization also determines how its workspace content is used. Ask your workspace administrator about your organization’s instructions and policies.
Information we receive
- Account and contact information: names, email addresses, workspace membership, account identifiers, and correspondence provided when you use our services or contact us.
- Work content: requests, comments, messages, files, website addresses, repository information, code, task history, and results submitted or generated while completing work.
- Browser captures: screenshots, recordings, interaction traces, page content, browser details, and diagnostic information when capture or verification features are used. Depending on what is visible or recorded, these materials can include personal information from the website being captured.
- Meetings and media: participant names, meeting chat, camera or screen recordings, audio, transcripts, uploaded images and videos, and extracted action items when those features are used.
- Connected-service information: authorization and refresh tokens, granted permissions, account and project identifiers, resource metadata, connection status, and content retrieved or changed to carry out authorized work.
- Technical and usage information: IP addresses, request and error logs, browser and device information, referring pages, page interactions, session identifiers, and preferences.
- Domain listing inquiries: name, email address, optional offer amount, and message submitted on a domain listing page. We use this to reply about a possible acquisition.
Do not include passwords, payment-card details, identity documents, health information, or other sensitive information in captures or work requests unless a separate agreement and an appropriate workflow specifically support that information.
How we use information
We use information to operate accounts and workspaces, respond to requests, investigate problems, prepare and verify website or code changes, manage authorized integrations, communicate about work, maintain security, prevent misuse, and understand and improve service performance. Features that access a connected account act within the granted permissions and the applicable workspace configuration.
Cloudflare account connections
When enabled for your workspace, the Habit Networks Cloudflare integration lets an authorized user connect selected Cloudflare accounts. You authorize access on Cloudflare’s website; the integration does not ask you to give Habit Networks your Cloudflare password.
- Account Settings Read is used to discover the accounts you authorize.
- Pages Read is used to discover and inspect Pages projects.
- Pages Write supports creating an empty preview project when explicitly requested through the setup workflow. The permission granted by Cloudflare is broader than this particular action.
- Workers Scripts Read is used to discover existing Worker services.
These permissions apply at the Cloudflare account level; they are not limited by Cloudflare to a single project. Our application applies additional workspace and preview-target restrictions. The current connection setup does not request DNS-write, Worker-write, database, or storage permissions.
The integration stores authorization tokens encrypted and associates connection records with the appropriate workspace. You can disconnect the integration through Habit Networks where available, ask your administrator to disconnect it, or revoke the application’s access in Cloudflare. Revocation stops future authorized access but does not automatically delete previously created resources or previously collected work records. Contact us to request deletion of information we retain.
Other integrations and AI processing
Enabled workflows can use GitHub for repositories and change requests, Google services for connected email or analytics, Cloudflare for hosting and infrastructure, and OpenAI or Anthropic tools for AI-assisted work. Work instructions, relevant code, submitted files, captures, and diagnostic context may be processed by the services needed for the selected workflow. The providers involved depend on your configuration, including whether you use a connected agent on your own computer.
AI-generated output can contain mistakes or reproduce information included in its input. Review the material you submit and the results before sharing or publishing them. Third-party services also apply their own privacy policies and terms to information they process.
Browser permissions, cookies, and analytics
Eyes capture features use enrollment, consent, and allowed-site settings. Only activate recording or browser-control features on sites and accounts you are authorized to access. Review captures before submission and use available pause, stop, or revocation controls when needed.
Our site and applications use browser storage and session identifiers for sign-in, preferences, and functionality. Marketing pages use Google Analytics, which may use cookies and collect usage and device information. Domain listing pages instead record page views in our own database: the path, the date, and a hashed network identifier. We do not store raw IP addresses for those views. Some pages load fonts from Google, and Cloudflare processes requests to deliver and protect the site. You can manage cookies and storage in your browser; blocking them may affect sign-in or preferences. Google also provides an Analytics opt-out browser add-on.
When information is shared
Information may be available to authorized workspace members and administrators, service providers needed to operate a workflow, and third parties you direct us to interact with, such as a repository or hosting provider. Publishing a site, sharing a preview, or posting a change to a repository can make the associated content available to its recipients or the public. We may disclose information when required by law, to protect rights and security, or as part of a business transfer subject to applicable protections.
Retention and security
Retention depends on the type of record, workspace settings, service needs, and applicable legal obligations. Capture artifacts have configurable expiration and cleanup. Account records, correspondence, work history, integration metadata, and backups may have different retention periods. Disconnecting an integration or stopping a recording does not by itself delete all historical information.
We use controls such as authenticated access, workspace authorization, scoped capture permissions, and encryption of integration credentials. No system can guarantee absolute security. Contact us about suspected unauthorized access or a deletion request. We may need to verify your identity and authority, and retain information needed for legal obligations, security, dispute resolution, or the rights of others.
Your choices and requests
You can manage browser permissions, choose which services to connect, revoke an integration, and ask your workspace administrator about access to your organization’s data. Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of your personal information, or to object to or restrict particular processing. Send a request to [Public contact email awaiting confirmation], identifying your relationship with Habit Networks and the information concerned. Do not send passwords or access tokens. We will evaluate requests under applicable law; some requests about organization-controlled information must be directed to that organization.
International processing and children
Habit Networks and its providers may process information in countries other than the country where you live. Applicable protections depend on the services and agreements involved. Contact us before using the service for data that requires a particular location or processing agreement.
Our account and workspace services are intended for adults acting on their own behalf or for a business or organization, not for children under 13. If you believe a child has provided personal information through these services, contact us so we can investigate. Suggested uses of a domain offered for sale do not mean Habit Networks operates a children’s service under that domain.
Changes and contact
We will update the date on this page when this policy changes and provide additional notice when required. For privacy questions or requests, contact Habit Networks at [Public contact email awaiting confirmation].