Privacy Policy
Last updated: 2 October 2026
This policy explains what Hundrd collects, why, where it goes, and how to get rid of it. Hundrd is a longevity challenge app: you take on health habits, check in daily, and track consistency.
Hundrd is operated by Good Orbit AI Studio, sole proprietor Shriharsha Ramachandra Bhagwat, Herzogstandstraße 19, 85540 Haar, Germany — referred to here as "we". Shriharsha Ramachandra Bhagwat is the controller for the personal data described below. Questions or requests: hello@goodorbit.ai.
The short version. We store your account, your challenges, your check-ins and anything you post to the community. We do not sell your data and we do not run ads. Your blood-marker values for the biological-age estimate never leave your device. You can export or permanently delete everything from inside the app. We always keep a short technical log so we can tell when the app is broken — but anything about how you use features is off until you switch it on.
What we collect
| Data | Why |
|---|---|
| Account — email address, the sign-in provider you chose (Google, Apple, or email + password), and an account identifier | To create your account, sign you in, and tie your data to you |
| Onboarding profile — your motivation, how consistent you say your habits are, the time you have, your difficulty preference, the health areas you care about, and any constraints you enter | To pick and rank challenges that fit you |
| Challenge activity — the challenges you take on, your daily check-ins, focus sessions, and yearly goals | The core function of the app; streaks and consistency are calculated from it |
| Community content — posts, comments, reactions and reports, plus the anonymous handle generated for you | To run the community feed. Posts are shown under your anonymous handle, not your name or email |
| Shared challenges — invitations you send or accept, membership, and check-ins shared with that group | So people you invite can see shared progress |
| Coach messages — your conversations with the in-app AI coach and curator | To keep the conversation available when you come back |
| Subscription status — whether you have an active premium entitlement | To unlock paid features. We never see or store your card details |
| Diagnostics — that a screen opened or a request finished, how long it took and whether it failed, the kind of error, your app and operating-system version, the platform, and a session identifier generated fresh each time you open the app. Your country too, if the app already knows it | To keep the app working — to see that something is broken, how badly, and on which platform. This is the minimum needed to run the service and is not covered by the switches below |
| Product analytics — a small set of named events (signed up, created a challenge, saved a check-in, viewed the paywall, completed a purchase) | Only if you turn it on. To see which features people actually use, so we build the right ones |
| Sign-up steps — before you have an account, which screens of the sign-up flow this installation reached (first open, welcome, goal picker, the account form, account created). Sent as a bare count per day and platform, with no identifier of you or your device attached; the app remembers on your device which steps it has already counted, so each is counted once. To stop the counts being faked, the scrambled form of the network address described under security records is kept alongside a tally of how many counts it sent that day — no step, nothing else — and deleted after two days | Only if you say yes on the question the app asks the first time you open it. To see where people give up before they get started |
| Activation totals — counts of how many accounts created on a given day went on to start a challenge or check in during their first week, computed from the account data we already hold | To see whether the app is getting in people's way. Nothing new is collected for this, and the result is a number per day, never a list of people |
| Crash reports — the technical details of a crash | Only if you turn it on. To fix crashes. No content from the app is included |
| Marketing preference — whether you have agreed to marketing and personalised ads | Off unless you turn it on. Saying "Allow" on the first-launch question does not turn it on; only its own switch does |
| Security records — failed sign-ins, refused requests, rate-limit hits, and a one-way scrambled form of the network address they came from | To notice someone attacking accounts. We do not store your IP address: the scrambled form is computed with a secret that never leaves our database and cannot be turned back into an address |
| Administrative record — a log of actions taken on data: a moderator's decision on a post, a change to the shared challenge library, a change to your privacy choices, and requests to export or delete an account | So we can show what was done, and by whom. See how long we keep it — this is the one record that outlives a deleted account, on purpose |
None of the diagnostic, analytics or security records contain anything you wrote — no post, no coach message, not even a challenge title — and none of them carry a health value. An event records that you saved a check-in. It never records what was in it, or which health area it belonged to.
What stays on your device
Some data is deliberately never uploaded. It is stored only in the app's local storage on the device you entered it on, and is erased when you uninstall the app:
- Biological-age inputs, including blood biomarker values (such as albumin, creatinine, glucose, C-reactive protein and the other PhenoAge markers) and your questionnaire answers. These are used to compute an estimate on your device. They are not sent to our servers, not backed up by us, and not visible to us.
- App preferences — theme, language, list ordering, filters, notification settings.
Because these live only on the device, they do not transfer between your devices, and we cannot recover them for you if the device is lost.
Health information
Habits, check-ins and onboarding answers can reveal information about your health and lifestyle. We treat them accordingly: they are protected by per-user database access rules so that only your account can read them, and they are never sold, rented, or used for advertising. Hundrd is a wellbeing and habit tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment. The biological-age estimate is an educational calculation based on published formulas, not a clinical result — talk to a doctor about your actual health.
Artificial intelligence features
The AI coach, the challenge curator, and community moderation are powered by third-party language models operated by Anthropic and OpenAI. When you use those features, the relevant content — your message, the challenge context, or the post being moderated — is sent to those providers to generate a response. We send it through our own server and do not include your email address or your name. These providers process the content to return a result; per their API terms, content sent through their APIs is not used to train their models. Your biomarker values are never part of any of this.
If you would rather not have content processed this way, do not use the AI coach or curator. Posting to the community does require automated moderation.
Who else processes your data
| Provider | Role |
|---|---|
| Supabase | Database, authentication and server functions — where your account, your activity and the diagnostic, security and administrative records above are stored (in the EU) |
| Anthropic, OpenAI | AI coach, curator and content moderation |
| RevenueCat | Subscription and entitlement management |
| Apple App Store, Google Play | Payment processing for subscriptions — they handle your payment details, we never receive them |
| Google Firebase Crashlytics | Crash reporting on Android and iOS — only if you have switched it on. We do not use Firebase Analytics |
| Cloudflare | Hosting for the web version of the app and these pages |
These providers act on our behalf and may store data outside your country, including in the United States. Where data leaves the European Economic Area, the transfer is covered either by an adequacy decision of the European Commission (including the EU–US Data Privacy Framework, where the provider is certified under it) or by the Commission's Standard Contractual Clauses. We do not sell your personal information, and we do not share it with advertisers or data brokers.
How long we keep it
We keep your account data for as long as your account exists. If you delete your account, it and your content are deleted from our database, and the diagnostic, analytics and security records that referred to you are stripped of everything linking them to you.
Those operational records also expire on a fixed schedule of their own, whether or not you delete your account:
| Record | Kept for |
|---|---|
| Diagnostics | 30 days |
| Product analytics | 90 days |
| Security records | 180 days |
| AI usage counts, for our own billing | 400 days |
| Administrative record | 36 months |
One exception to deletion. The administrative record is kept for 36 months and is not erased when an account is. It holds an account identifier and what was done — that an export was provided, that a deletion was carried out, that a post was approved or rejected — but none of your content. We keep it so that we can demonstrate we handled such requests properly, which Article 17(3) of the GDPR permits. It is append-only: it cannot be edited afterwards, including by us.
Backups and provider logs may retain copies for a short period before they age out. Anonymised or aggregate figures that cannot identify you (for example, total check-in counts) may be retained.
Your choices and rights
- Export — Profile → Settings has an export that gives you a copy of your data.
- Delete — Profile → Settings → delete account permanently removes your account and its data. This cannot be undone. If you no longer have the app installed, see how to delete your account.
- Correct — you can edit your profile, challenges, goals and posts in the app.
- Notifications — reminders are opt-in and can be turned off at any time in Settings or in your device's system settings.
- Analytics and crash reports — the first time you open the app it asks whether you agree to both; "No thanks" and "Allow" are equal choices, and "Adjust" lets you choose each separately. After that, Profile → Settings → Account has a switch for each, plus a third for marketing and personalised ads, which "Allow" never turns on. All three start off and stay off until you turn them on. An answer you give before creating an account is kept on your device and becomes your account's answer when you sign up; after that a change applies to your account on every device, not only the one you changed it on. Diagnostics and security records are not covered by these switches — they are what keeps the service running and your account safe.
Depending on where you live (for example in the EEA, the UK, or California) you may also have the right to object to or restrict processing, to request portability, and to complain to your data protection authority. Write to hello@goodorbit.ai and we will respond within the period the law requires.
Where the GDPR applies, our legal bases are: performing our contract with you (running your account and the features you use); your consent (notifications, optional AI features, and the product-analytics, crash-report and marketing switches — which you can withdraw at any time, as easily as you gave it — and the sign-up step counts, which follow the analytics switch); our legitimate interests in keeping the service available and secure, which is what the diagnostics and security records above are for, and in understanding whether the app helps people get started, which is what the activation totals are for; and compliance with our legal obligations, which is why the administrative record exists.
Children
Hundrd is not intended for children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
Security
Data is transmitted over encrypted connections and stored with per-user access rules enforced at the database level, so one account cannot read another's data. No system is perfectly secure, but we work to keep this one sound.
Changes
If we change this policy we will update the date at the top, and we will tell you in the app if the change is significant.