Privacy Policy

Last updated: March 2, 2026

1. Introduction

Welcome to HALO (Holistic Ascension Life Optimization). This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the HALO application at app.halo.fit and our marketing site at halo.fit (collectively, the "Service").

We are committed to protecting your privacy and ensuring that your personal data is handled responsibly and in compliance with the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws.

Please read this Privacy Policy carefully. By creating an account or using the Service, you acknowledge that you have read and understood this policy.

Data Controller:
Khejan, LLC, d/b/a HALO
Contact: privacy@halo.fit

2. Data We Collect

We collect only the data necessary to provide and improve the Service. The categories of personal data we process are set out below.

2.1 Account Data

When you create an account, we collect:

  • Name — to personalise your experience
  • Email address — for authentication, account recovery, and essential communications
  • Password — stored in hashed form only; we never store or have access to your plaintext password

2.2 Health and Wellbeing Data (Special Category Data)

If you choose to use our health tracking features, we may collect:

  • Hydration logs — daily water intake amounts and timestamps
  • Fitness data — exercises, workout plans, session logs including sets, reps, and weights
  • Mood logs — mood levels, notes, and tags
  • Sleep logs — sleep hours, bedtime, wake time, and quality ratings
  • Pain logs — body location, sensation type, intensity, and notes
  • Nutrition data — dietary tracking information
  • Energy levels — daily energy tracking

Important: Health data constitutes "special category data" under Article 9 of the GDPR. We process this data only with your explicit consent, which you provide when you voluntarily enter this information into the Service. You are never required to use these features, and you may stop using them at any time.

2.3 Financial Data

If you choose to use our wealth management features, we may collect:

  • Financial accounts — account names, types, and balances
  • Transactions — transaction descriptions, amounts, dates, and categories
  • Budgets — budget categories and amounts
  • Recurring expenses — expense descriptions, amounts, and schedules
  • Debt information — debt balances and payment tracking

Financial data receives enhanced security protections as described in Section 7.

2.4 Goals, Habits, and Tasks Data

  • Goals — titles, categories, SMART framework fields, target dates, milestones, and progress
  • Habits — habit names, schedules, tracking entries, and streak data
  • Tasks — task lists, task details, priorities, due dates, time tracking, and subtasks

2.5 Family Data

If you choose to use family-related features, we may collect:

  • Family member information — names and relevant details you choose to enter about family members

You are responsible for ensuring that you have the appropriate authority or consent to enter information about other individuals.

2.6 Home Data

If you choose to use home management features, we may collect:

  • Home maintenance data — maintenance schedules, tasks, and related notes

2.7 Technical Data

We automatically collect limited technical data necessary to operate the Service:

  • Session data — essential session cookies required for authentication and security
  • Server logs — IP addresses, browser type, and access timestamps retained for security purposes

3. Lawful Basis for Processing

Under the GDPR, we must have a lawful basis for processing your personal data. The bases we rely on are:

Data Category Lawful Basis GDPR Article
Account data (name, email, password)Performance of a contract — necessary to provide the Service you have signed up forArticle 6(1)(b)
Health and wellbeing dataExplicit consent — you voluntarily provide this special category data by entering it into the ServiceArticle 6(1)(a) and Article 9(2)(a)
Financial dataPerformance of a contract — necessary to provide the wealth management features you useArticle 6(1)(b)
Goals, habits, tasks, family, and home dataPerformance of a contract — necessary to provide the Service features you useArticle 6(1)(b)
Technical and security dataLegitimate interest — necessary to maintain the security and integrity of the ServiceArticle 6(1)(f)

Where we rely on consent, you have the right to withdraw that consent at any time (see Section 9). Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

4. How We Use Your Data

We use your personal data exclusively for the following purposes:

  • Providing the Service — displaying your dashboards, tracking your health, finances, goals, habits, tasks, and other features you choose to use
  • Account management — authentication, account recovery, and essential account-related communications
  • Security — protecting against unauthorised access, fraud, and other security threats
  • Service improvement — aggregated, anonymised analytics to improve features and fix issues (no individual tracking)

We do not use your data for:

  • Advertising or marketing profiling
  • Selling to third parties
  • Automated decision-making or profiling (see Section 11)
  • Any purpose incompatible with those listed above

5. Third-Party Services

We share data with a limited number of third-party service providers, strictly as necessary to operate the Service. We do not sell, rent, or trade your personal data.

Provider Purpose Data Shared
StripePayment processingPayment method details, billing information (processed directly by Stripe; we do not store full payment card numbers)
GoogleCalendar synchronisation (optional)Calendar event titles, dates, times, and descriptions are exchanged via the Google Calendar API when you connect your Google account. OAuth tokens are stored encrypted.
CloudflareSecurity, DDoS protection, and content deliveryIP addresses and request metadata (processed by Cloudflare as part of web traffic routing)

Each third-party provider processes data under their own privacy policy and in accordance with their obligations as data processors. We have data processing agreements in place with these providers as required by Article 28 of the GDPR.

Google Calendar integration is entirely optional. If you connect your Google Calendar, you may disconnect at any time from Settings, which revokes our access.

We do not use:

  • Third-party tracking cookies
  • Analytics services that track individual users
  • Advertising networks
  • Social media tracking pixels

6. Cookies

We use only essential session cookies that are strictly necessary for the Service to function. These cookies:

  • Maintain your authenticated session
  • Provide CSRF (cross-site request forgery) protection
  • Do not track you across websites
  • Do not collect data for marketing or advertising
  • Expire when your session ends or after a reasonable inactivity period

Because these cookies are strictly necessary for the operation of the Service, they do not require consent under the ePrivacy Directive.

7. Data Security

We take the security of your data seriously, particularly given the sensitive nature of health and financial information.

Technical Measures

  • Encryption in transit — all data transmitted between your device and our servers is encrypted using TLS (HTTPS)
  • Encryption at rest — all stored data is encrypted at rest on our servers
  • Password hashing — passwords are stored using strong, one-way hashing algorithms and are never stored in plaintext
  • Secure hosting — data is hosted on secure servers with access controls and monitoring
  • DDoS protection — Cloudflare provides protection against distributed denial-of-service attacks

Organisational Measures

  • Access to personal data is restricted to authorised personnel on a need-to-know basis
  • Regular security reviews and updates
  • Incident response procedures in place

Financial Data Protection

  • Strict access controls limiting who can access financial data
  • We do not store full payment card numbers (these are handled directly by Stripe)
  • Financial account data is encrypted alongside all other data at rest

Despite our efforts, no method of transmission or storage is 100% secure. If you become aware of any security issue, please contact us immediately at privacy@halo.fit.

8. Data Retention

We retain your personal data in accordance with the following principles:

  • Active account data — retained for as long as your account remains active and you continue to use the Service
  • Deleted account data — when you delete your account, all of your personal data is permanently deleted from our systems within 30 days of account deletion
  • Server logs — retained for a limited period necessary for security purposes, then automatically deleted
  • Backups — data in encrypted backups is purged in accordance with our backup rotation schedule, and no later than 30 days after account deletion

We do not retain data longer than necessary for the purposes described in this policy.

9. Your Rights

9.1 Rights for All Users

All users of the Service have the right to:

  • Export your data — download a complete copy of all your data in CSV/ZIP format at any time through your account settings
  • Delete your account — permanently delete your account and all associated data through your account settings

9.2 Rights Under the GDPR (EU/EEA and UK Users)

If you are located in the European Union, the European Economic Area, or the United Kingdom, you have the following rights under the GDPR:

  • Right of access (Article 15) — request a copy of the personal data we hold about you
  • Right to rectification (Article 16) — request correction of inaccurate or incomplete personal data
  • Right to erasure (Article 17) — request deletion of your personal data ("right to be forgotten")
  • Right to restriction of processing (Article 18) — request that we limit how we use your data
  • Right to data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format (CSV/ZIP)
  • Right to object (Article 21) — object to processing based on legitimate interest
  • Right to withdraw consent (Article 7(3)) — withdraw consent for processing of special category data at any time

How to Exercise Your Rights

You can exercise most of these rights directly through the Service:

  • Data export is available in your account settings
  • Account deletion is available in your account settings
  • Data correction can be done by editing your data within the Service

For any other requests, or if you need assistance, contact us at privacy@halo.fit. We will respond to your request within 30 days as required by the GDPR.

Right to Lodge a Complaint

If you believe that we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection supervisory authority.

10. International Data Transfers

If your data is transferred outside of the EU/EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Compliance with the EU-US Data Privacy Framework where relevant

Our third-party providers (Stripe and Cloudflare) maintain appropriate data transfer mechanisms as required by the GDPR.

11. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling as defined under Article 22 of the GDPR. No decisions with legal or similarly significant effects are made about you based solely on automated processing.

Any statistics, charts, or summaries displayed within the Service (such as streak counts, progress bars, or health correlations) are purely informational tools for your personal use and do not constitute profiling or automated decision-making.

12. Age Restriction

The Service is intended for users aged 16 years and older, in accordance with Article 8 of the GDPR. We do not knowingly collect personal data from individuals under 16.

If we become aware that we have collected personal data from a person under 16 without appropriate parental or guardian consent, we will take steps to delete that data promptly. If you believe that a child under 16 has provided us with personal data, please contact us at privacy@halo.fit.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify you via email or through a prominent notice within the Service before the changes take effect
  • Where required by law, we will obtain your consent to material changes

14. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 of the GDPR
  • Document all breaches, including their effects and the remedial action taken

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@halo.fit

We aim to respond to all enquiries within 30 days.

16. Summary of Key Points

Topic Summary
What we collectAccount info, plus health, financial, goals, habits, tasks, family, and home data you choose to provide
Why we collect itTo provide the Service, manage your account, and maintain security
Special category dataHealth data processed only with your explicit consent
Third partiesStripe (payments) and Cloudflare (security/CDN) only; no data sold
CookiesEssential session cookies only; no tracking cookies
SecurityEncrypted at rest and in transit; hosted on secure servers
Your rightsAccess, rectify, erase, restrict, port, object, withdraw consent, export, delete account
RetentionKept while account active; deleted within 30 days of account deletion
Age requirement16 years and older
Automated decisionsNone

Related Documents