Privacy Policy

Last updated: 29 August 2026

hapje is a habit tracker you share with a small circle of people you choose. This policy explains exactly what the app stores, why, and how to get rid of it.

The short version: everything stays on our own server, nothing is sold or shared, there is no advertising and no analytics of any kind, and you can delete your account and all of its data from inside the app at any time.

Who is responsible

Benjamin Amhof
Hertensteinstrasse 2, 6004 Luzern, Switzerland
Contact: team@slackers.dev

We are the data controller for the information described below.

What we collect

Account information. Your username, your email address and your password. The password is never stored as text — it is hashed with bcrypt, so we cannot read it or recover it for you.

The things you create in the app. Your habits and their daily entries (including any note you add), your to-dos, the challenges and rivalry scoreboards you take part in, and the profile emoji and statistics you choose to display.

Photos. If you take part in a photo challenge, the app opens the camera and you take a proof photo. Photos can only be taken live in the app — you cannot pick one from your library — and they are stored on our server. They are shown only to people who are both accepted members of that challenge and following you.

Who you are connected to. The people you follow, and anyone you have blocked.

Reports you file. If you report a photo or a person, we store what you reported, the reason and any detail you add, so we can review it.

Notification token. On the web version, if you switch on notifications we store the token your browser needs to receive them; switching them off removes it. The iOS app does not send notifications and stores no token.

What we do not collect

Your IP address passes through our server to protect the login and registration endpoints against brute-force attempts. It is held only in memory for that purpose and is never written to the database.

Why we process it

We process your account details to let you sign in and to keep your data separate from everyone else's. We process the content you create because displaying it back to you and to the people you have chosen to share it with is what the app does. We process blocks and reports to keep the app usable and to meet our safety obligations.

The legal basis is the performance of our contract with you (providing the app), and our legitimate interest in keeping it safe and functioning.

Who can see your data

Other users, but only what you deliberately share: a habit is private unless you mark it public, and a proof photo is visible only to challenge members who follow you. To-dos are visible only to the people you put on them.

Nobody else. We do not share your data with third parties at all. The iOS app sends no data anywhere except to our own server.

Our servers are located in Switzerland/the EU. We may disclose data if we are legally required to.

How long we keep it

For as long as your account exists. When you delete your account, everything described above is deleted immediately and permanently — habits, entries, to-dos, photos, scores, follows, blocks and notification tokens. There is no grace period and no backup from which we restore individual accounts.

Two things deliberately survive, because they are no longer only about you:

Your rights

You can access, correct, export or erase your data, object to processing, and lodge a complaint with a supervisory authority — the Swiss FDPIC, or your local authority in the EU/EEA.

Most of this you can do yourself: your data is visible in the app, editable in the app, and deletable in the app under Profile → Delete Account. For anything else, write to team@slackers.dev and we will respond within 30 days.

Deleting your account

In the app: Profile → Delete Account. You confirm with your password, and the deletion happens straight away.

Children

hapje is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

Security

Traffic is encrypted with HTTPS. Passwords are hashed with bcrypt. Sessions use signed tokens that expire after seven days and are invalidated when you change your password. Photos are served only after we check the requester is allowed to see them.

No system is perfectly secure, but we do not keep data we do not need, which is the most reliable protection available.

Changes

If we change this policy we will update the date above and, for anything significant, tell you in the app.

Contact

team@slackers.dev