Add-on Slug: habit • Published by bb12ett (Brett)
Effective Date: September 2026
Our Foundational Commitment:
HABit was designed from its first line of code with complete data privacy as its core principle. bb12ett runs no central servers, no cloud databases, and no telemetry services. All your budget data, account balances, spending history, and personal PINs remain strictly on your own self-hosted Home Assistant instance.
1. Information We Do Not Collect
Because HABit is a self-hosted Home Assistant add-on, the author (bb12ett) collects zero personal information:
- No account registration, user logins, names, or email addresses required
- No financial figures, income amounts, transaction histories, or account balances are ever sent to bb12ett
- No analytics telemetry, tracking beacons, event logs, or error monitoring SDKs
- No IP address logging, hardware profiling, or advertising identifiers
2. 100% Local Data Storage
All data created or imported within HABit is stored exclusively on your local Home Assistant disk:
- Local Database: Your budget records, accounts, direct debits, and categories persist inside
/data/budget.json on your Home Assistant filesystem.
- Multi-User PIN Protection: Sensitive account balances and salary figures can be locked with an on-device 4-digit PIN code to preserve household privacy.
- User Control: You have absolute ownership of your data. You can export complete standalone JSON backups, restore archives, or purge all records at any time directly through the app settings.
3. Optional Open Banking Integration (BYOK Model)
HABit provides optional support for automated bank synchronisation via Open Banking providers (including TrueLayer, EnableBanking, GoCardless, and SimpleFin).
This feature operates strictly on a Bring Your Own Key (BYOK) client-side model:
- Direct Peer-to-Provider Communication: All API communication takes place directly between your local Home Assistant server and the selected provider's official endpoints (e.g.
https://auth.truelayer.com and https://api.truelayer.com). No data passes through or touches any server operated by bb12ett.
- Your Own Developer Keys: You provide your own personal developer API keys (e.g., TrueLayer Client ID & Client Secret) obtained directly from the provider. bb12ett possesses no access to your API keys.
- Bank Credentials: You authenticate directly on your financial institution's official banking portal via the provider's regulated interface. HABit never sees, collects, or handles your online banking passwords, credentials, or security factors.
- Strictly Read-Only Access (AIS): The Open Banking connection is strictly limited to Account Information Services (retrieving account names, balances, and transaction history). The application is structurally incapable of initiating payments, transferring funds, or altering your accounts.
- Third-Party Privacy Policies: Your interaction with the Open Banking aggregator is governed directly by their privacy policy (e.g. TrueLayer Privacy Policy).
- Revocability: You can disconnect your bank accounts, clear stored access tokens, or revoke Open Banking access at any time directly within HABit or through your bank's Open Banking management dashboard.
4. Zero Advertising & Zero Commercial Monetisation
HABit is free and open-source software (licensed under AGPLv3):
- No banner advertisements, sponsored content, or promotional links
- No commercial monetisation of user data or financial habits
- No third-party ad networks, marketing trackers, or data broker integrations
5. Home Assistant Ecosystem & System Backups
HABit runs in a sandboxed Docker container managed by the Home Assistant Supervisor. When you generate standard Home Assistant backups (full or partial), your HABit database is included within your encrypted Home Assistant backup archive according to your Home Assistant configuration.
6. Data Security and Deletion
Because no personal data is ever received by bb12ett servers, there is no remote data to request deletion of. You can erase all application data at any time by performing a factory reset within the HABit settings or by uninstalling the add-on from Home Assistant.
7. Contact Us
If you have any questions or feedback regarding this Privacy Policy, please reach out: