Privacy Policy
Last updatedMarch 2026
CoordlyOS (“we”, “our”, or “the service”) is a personal productivity and life-operating-system app. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights regarding your data. We aim to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) where applicable.
We review this policy periodically and update the “Last updated” date when we make material changes. Continued use of the service after changes means you accept the revised policy where permitted by law.
1. Data we collect
Account data: When you sign in (e.g. via magic link), we collect your email address and associate it with your account. We store this in our user and profile systems.
Productivity and usage data: Data you create in the app — such as tasks, inbox items, life areas, goals, habits, journal entries, focus sessions, and time blocks — is stored so we can provide and sync the service across your devices.
Feedback and support: If you submit feedback or bug reports while signed in, we store the content you provide (e.g. category, subject, message, and the page you were on), your account identifier, and optional image attachments you upload, so we can respond and improve the product.
Promotional access: If you redeem a launch or promotional code, we record the code, your account, and redemption time to enforce limits (e.g. first N users) and to grant the associated benefits.
Technical data: We may log basic technical information (e.g. request logs, errors) to operate and improve the service. We do not sell your personal data.
2. Legal basis (GDPR)
We process your data on the basis of: (a) contract — to provide the service you requested; (b) legitimate interests — to operate, secure, and improve the service; and (c) where you opt in, consent (e.g. optional web push notifications).
3. Retention
We retain your account and productivity data for as long as your account is active. If you delete your account or request deletion, we will delete or anonymise your personal data in line with our data retention and deletion procedures, except where we must retain data for legal or regulatory reasons.
4. Who we share data with
We use the following processors to run the service:
- Supabase — authentication and database (hosting of your account and productivity data). Supabase processes data on our behalf; their privacy and data processing terms apply.
- Stripe — payment processing for Pro subscriptions. When you subscribe, payment and billing-related data is processed by Stripe in accordance with their privacy policy.
We do not sell your data to third parties. We may disclose data if required by law or to protect our rights and safety.
5. Your rights
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal data (subject to legal exceptions).
- Portability — receive your data in a structured, machine-readable format.
- Object or restrict processing — in certain circumstances under GDPR.
- Withdraw consent — where processing is based on consent (e.g. disabling push notifications).
To exercise these rights, contact us using the details in the “Contact” section below. If you are in the EEA/UK, you also have the right to lodge a complaint with a supervisory authority.
6. Web push notifications
If you install the app as a PWA and opt in to push notifications, we may send you reminders (e.g. overdue inbox, weekly review due). This is optional and can be disabled in your device or browser settings or in the app’s Settings. Push delivery may involve platform providers (e.g. Apple, Google); their policies apply to that delivery.
7. Security
We use industry-standard measures to protect your data (e.g. encryption in transit and at rest, access controls). No method of transmission or storage is 100% secure; we strive to minimise risk and respond to incidents appropriately.
8. Contact
For privacy-related requests, questions, or complaints, contact us via the in-app Feedback page (sign-in required) or at the email or address published on our website. We will respond within a reasonable time as required by applicable law.