Privacy Policy

Data We Collect

  • Account information: email address, display name, and avatar
  • Task and project data you create within the app
  • AI conversation history when you use the AI assistant
  • Usage metadata: timestamps, XP, and achievement progress

Third-Party AI Services

When you use AI features, your messages are sent to the AI provider you selected (Anthropic, OpenAI, or Google). These providers process your messages to generate responses. Your data is not used for model training by any of these providers when accessed via their APIs.

Your API key is encrypted at rest and only decrypted server-side when making requests to the provider.

Data Retention

Your data is retained for as long as your account is active. You can delete all your data at any time using the "Delete My Account" option in your profile settings. Account deletion is immediate and irreversible.

Your Rights

  • Access: View all your data within the app
  • Rectification: Edit your profile and task data at any time
  • Erasure: Delete your entire account and all associated data
  • Portability: Your data is stored in standard formats

Security

We use encryption in transit (HTTPS) and at rest for sensitive data like API keys. Authentication is handled by Supabase Auth with support for multi-factor authentication. Sessions use secure, HTTP-only cookies with refresh token rotation.

Contact

For privacy-related questions or concerns, please open an issue on the project repository or contact the project maintainer.