Privacy Notice

Last updated 19 August 2026

Introduction

This privacy notice describes how we collect, use, share and otherwise process your personal data in connection with your use of the Trabbit mobile application (App).

Trabbit is not intended for children, and we do not knowingly collect data relating to children.

Please read the following carefully to understand our practices regarding your personal data and how we treat it.

Who we are

Matthew Bowler is the controller and is responsible for your personal data (we, us, or our in this notice).

If you have any questions about this notice or how we handle your data, contact us at bowlerm007@gmail.com, or visit our Support page.

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues.

Changes to this notice

We keep this notice under regular review. If we make a material change, we'll show an in-app notice the next time you open Trabbit — this is the one channel guaranteed to reach every user, since push notifications require you to have separately opted in via Settings.

It's important the personal data we hold about you is accurate and current — you can update your name, season phase, and other profile details at any time from within the App.

The data we collect about you

We collect the following categories of personal data:

  • Identity Data — your name and age range, provided during onboarding.
  • Contact Data — your email address, used for sign-in and account recovery.
  • Account Data — your Trabbit account credentials, or, if you choose Sign in with Apple or Google, the identity information those providers share with us (typically your name and email).
  • Health Data — if you link a habit to Apple Health, we read specific metrics (for example step count) from HealthKit to automatically mark that habit complete for the day. This access is read-only — Trabbit never writes to or modifies your Apple Health data. You control this per habit, and can revoke access at any time in iOS Settings.
  • Wearable Data — if you connect a WHOOP account, we read recovery, HRV, resting heart rate, sleep performance, and day strain data via WHOOP's API to automatically mark linked habits complete and to show your history over time. This access is also read-only, and you can disconnect it at any time in Settings.
  • Content Data — the habits, logs, and tests you create, including their names, schedules, categories, colors/icons, and the values or journal entries you record against them.
  • Feedback Data — any message you submit via the feedback form in Settings.
  • Device and Usage Data — basic technical information needed to operate the App and diagnose problems, such as your device type and operating system version.
  • Notification Preferences — whether you've opted in to backlog-alert or evening-reminder push notifications (both default off), and your push token if so.
  • Payment Data — if you subscribe, Apple processes your payment directly; we receive only your subscription status and entitlement from our payments provider (RevenueCat), never your card details.

We do not collect any special category data beyond the Health/Wearable Data described above, and we do not collect location data or data from advertising networks or data brokers — Trabbit has no ads and no location tracking.

How we collect your data

  • Registration. We collect your Identity and Contact Data when you create an account, either directly or via Sign in with Apple/Google.
  • Using the App. Each time you create or update a habit, log, or test, we collect the Content Data you enter.
  • Apple Health. If you link a habit to Apple Health and grant permission, we read the relevant Health Data from your device.
  • WHOOP. If you connect your WHOOP account, we read the relevant Wearable Data via WHOOP's API on your behalf.
  • Feedback. If you submit the in-app feedback form, we collect your message and associate it with your account so we can act on it — this is a one-way channel; we don't offer in-app live chat or phone support.
  • Notifications. If you opt in to either reminder toggle in Settings, we collect a device push token to deliver it.
  • Subscribing. If you subscribe, Apple and RevenueCat process the transaction and share your subscription status with us.

How we use your personal data

We only use your personal data when we have a lawful basis to do so:

PurposeData usedLawful basis
Create and manage your accountIdentity, Contact, AccountPerformance of a contract
Operate the App's core features (habits, logs, tests, streaks)Content DataPerformance of a contract
Auto-complete Health- or WHOOP-linked habitsHealth Data, Wearable DataConsent (you link each habit individually)
Send backlog-alert or evening-reminder push notificationsNotification PreferencesConsent (both toggles default off)
Process your subscriptionPayment DataPerformance of a contract
Respond to feedback or support requestsFeedback Data, Contact DataLegitimate interests (supporting our users)
Maintain security and prevent misuseDevice and Usage DataLegitimate interests (keeping the App and its users safe)
Comply with legal obligationsAs relevant to the requestLegal obligation

We do not use your data for advertising, do not sell it, and do not make any decisions about you based solely on automated processing.

Who we share your data with

  • Supabase (our backend/database provider), which hosts our database and authentication in the EEA (Ireland). Every table in our database enforces row-level security, so your data is only ever accessible to your own authenticated account, even at the database layer.
  • Apple and Google, if you choose to sign in with either — they process your sign-in identity data under their own privacy policies.
  • WHOOP, if you connect your account — WHOOP processes the authorization under their own privacy policy.
  • RevenueCat, our subscription management provider, which relays your entitlement status from Apple to our backend.
  • Apple, as the distributor of the App through the App Store, for payment processing, and for HealthKit access if you enable it.
  • Law enforcement or regulators, where we're legally required to disclose information.

We do not share your data with marketing partners, advertisers, or data brokers — we don't work with any.

International transfers

Your data is primarily stored in the EEA (Ireland), via Supabase. Because Trabbit is used from the UK, this involves a transfer of your data outside the UK to the EEA, which is covered by the UK's own adequacy regulations for EEA countries — no additional safeguard is required for this specific transfer.

If you sign in with Apple or Google, or connect WHOOP, a limited amount of identity/wearable data is processed by those companies as part of the relevant flow, under their own respective privacy policies and transfer safeguards.

Data security

  • Your data is stored on Supabase's infrastructure in the EEA (Ireland), and all connections between the App and our backend use TLS (HTTPS) encryption in transit.
  • Every table in our database has row-level security enabled, restricting access to your own data even if a database credential were compromised — access is enforced at the database layer, not just in the App's own code.
  • A small amount of non-sensitive local state (for example, which sections of a screen you've expanded) is cached on your device; this never includes your account credentials.
  • You're responsible for keeping your device and account credentials secure — don't share your password with anyone.

Data retention

We retain your account data for as long as you have an active account.

You can delete your account and all associated data at any time from within the App, in Settings — this is immediate and permanent.

Your legal rights

Under UK data protection law, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data — you can update most of this yourself in the App.
  • Delete your data — available immediately and directly in Settings, or by contacting us.
  • Object to processing based on legitimate interests.
  • Restrict our processing of your data in certain circumstances.
  • Port your data to another service, where technically feasible.
  • Withdraw consent at any time for anything we process on that basis (Health/Wearable Data access, push notifications) — directly in the App or in iOS Settings.

To exercise any of these rights, contact us at bowlerm007@gmail.com. You can also complain directly to the ICO at any time.

Description of data categories

  • Identity Data: name, age range.
  • Contact Data: email address.
  • Account Data: your Trabbit credentials, or Apple/Google sign-in identity data.
  • Health Data: the specific Apple Health metrics you've linked to a habit (read-only).
  • Wearable Data: the specific WHOOP metrics you've linked to a habit (read-only).
  • Content Data: habit, log, and test names, schedules, categories, and the values/entries you record.
  • Feedback Data: the text of any feedback you submit.
  • Device and Usage Data: device type, OS version, and basic diagnostic information.
  • Notification Preferences: your reminder toggle settings and device push token, if enabled.
  • Payment Data: your subscription status and entitlement (never your card details, which Apple processes directly).

Trabbit is a trading name of Matthew Bowler. Copyright Matthew Bowler 2026.