← Back to EasyDooo

Privacy Notice

Last updated 24 August 2026

Who is responsible for your data

[controller legal name], [registered address], is the controller of the personal data described here. For anything in this notice, including to exercise the rights below, contact [privacy contact email].

What we collect, and why

Your account. Your email address, your name if you give one, and a password hash if you did not sign in with Google. We need this to give you an account at all, so the basis is performance of our contract with you.

What you put in the app. Tasks, projects, notes, ideas, budget entries, trips, calendar events, and the contacts and notes you keep about people. This is the service; the basis is again our contract with you. If you record information about other people, you decide what goes in and you should only enter what those people would reasonably expect.

Crash reports. Only if you turn them on. There is a switch on the website and another in the mobile app, they are separate, and neither is on until you use it. The basis is your consent, you can withdraw it in either place at any time, and nothing stops working when you do.

Keeping the service running. Logs and error reports from our own servers, used to keep the service available and secure. These are not the crash reports above: they are about our machines rather than your browser or phone, we cannot detect our own outages without them, and so the basis is our legitimate interest in a working service rather than your consent.

Billing. Only if you buy a paid plan. Your email address and a record of what you bought, so that we can charge you and prove that we did. The basis is performance of our contract with you — you bought something, and charging you for it is the deal — and, for the tax records, the legal obligation to keep them.

We do not use your data to train AI models, we do not sell it, and we do not profile you or make automated decisions with legal effects.

Cookies, and how we measure the site

Cookies. This website sets one kind of cookie: the session cookie that keeps you signed in. It is strictly necessary — without it every page would ask you to log in again — so the cookie rules do not require your consent for it, and that is why you are never shown a cookie banner here. There are no advertising cookies, no cross-site trackers, and nothing for a “reject all” button to reject.

Page views. This deployment counts nothing. No analytics or measurement script is loaded on any page, first-party or third-party, so there is nothing here to opt out of.

Who else sees it

This is the full list of third parties your data reaches. Each of them acts on our instructions as a processor, and each may use its own vetted suppliers to do so.

WhoForWhat they receiveWhere
GroqAI featuresThe text of the idea, task or trip you are working on. For a catch-up brief, the contact's name and the notes you have written about them.United States
GoogleSign-in, Calendar sync, contact importYour email address and name if you sign in with Google. Calendar events and contacts, only if you connect those features.United States
SentryCrash and error reportingThe error, a stack trace, and the app version and device type. Your account id, email address, cookies and request headers are stripped out of the report before it is sent. Sentry's servers still see the IP address your connection comes from, the way every site you visit does — that follows from making the request at all, and is not something we attach.Reports are ingested and stored in Sentry's EU region. Sentry Inc. is a US company.
ResendEmail deliveryYour email address and the content of the reminder or digest being sent.United States
ExpoPush notificationsA device push token and the notification text.United States
RazorpayPayments — only if you start a paid-plan checkoutA reference to your account and which plan you chose. We do not send your email address: the details on the payment page are ones you enter there yourself, and your card number goes directly to Razorpay and never touches our servers — the payment page is theirs, not ours. Invoices and payment history live with Razorpay for as long as tax law requires us to keep them.Razorpay Software Private Limited is an Indian company, and payments are processed in India.
StripePayments — only on deployments still configured for Stripe checkoutYour email address and a customer reference when you start a checkout. Your card number goes directly to Stripe and never touches our servers — the payment page is theirs, not ours. Invoices and payment history live with Stripe for as long as tax law requires us to keep them.Stripe Inc. is a US company.
VercelRunning the website and the APIEverything you send to EasyDooo and everything it sends back, because Vercel is the machine it runs on. Their request logs record your IP address and which pages you asked for.Vercel Inc. is a US company. The app is served from the region set on our deployment.
SupabaseDatabase hostingEverything in your account, because this is where it is stored. They do not read it; they run the database it sits in.Supabase Inc. is a US company. The database sits in the region our project was created in.
AnalyticsCounting page views — only if analytics is switched on for this deploymentThat a page was viewed, and on the marketing page which button was pressed (never by whom): its address, the address that linked you to it, and coarse facts your request already carries — browser, operating system, device type, country. No cookie is set and nothing is written to or read from your browser's storage, so no identifier is kept that could recognise you on a later visit or follow you to another site. Nothing you typed into the app is sent, and neither is your name, your email address nor your account id. The tag is not loaded at all on a shared link, or on any page reached with an address or a reset token in its URL, because on those pages the address itself would be the private part. The service sees the IP address your connection comes from, the way every server you connect to does; we neither send it nor keep it.No analytics service is configured on this deployment, so no page views are sent anywhere and this row receives nothing.

Groq, Google, Resend, Expo, Stripe, Vercel and Supabase are US companies, so using them means transferring your data outside the EEA. Razorpay is an Indian company, which is a transfer outside the EEA too, and India has no European adequacy decision. All of these transfers rely on the Standard Contractual Clauses in our agreements with each of them. Sentry is only a partial exception: the crash reports themselves are ingested and stored in Sentry’s EU region, but Sentry Inc. is US-established, so the same Clauses cover the access that implies.

How long we keep it

Your content stays until you delete it or close your account. When you delete something it is hidden immediately and permanently destroyed after 30 days — the delay is what lets a phone that has been offline learn that the item is gone.

If you have turned crash reports on, each report is kept for [crash report retention period] and then deleted by Sentry. We set that period to the shortest one that still lets us find a bug that only shows up now and then, rather than keeping reports for as long as the tool allows.

Deleting your account removes it and everything attached to it from our database. That is not reversible, and we keep no separate archive of it. What it does not do is reach back into the providers in the table above: a crash report already sent, or an email already delivered, ages out on that provider’s own schedule instead. Write to [privacy contact email] if you want us to chase a specific one.

If you have ever bought a paid plan, the billing records — invoices and payment history — are kept for as long as tax law requires, even after you delete your account. That is a legal obligation, not a choice we get to make (Article 17(3)(b) allows exactly this), and telling you that deletion erases your invoices would be the pleasant lie. If you never bought anything, there are no billing records and none of this applies to you.

Your rights

  • Access. Ask for a copy of your data. Settings → Export produces one immediately.
  • Portability. The export is machine-readable JSON you can take elsewhere.
  • Erasure. Settings → Delete Account removes your account and everything attached to it from our database. See "How long we keep it" for what that does not reach.
  • Rectification. Edit anything in the app, or ask us.
  • Restriction and objection. Ask us to stop a particular use of your data.
  • Withdraw consent. Turn crash reporting off — on the website or in the mobile app, wherever you turned it on — or disconnect Google, at any time.

Write to [privacy contact email] for anything the app cannot do itself. If you think we have handled your data badly you can complain to your national data protection authority; we would rather you told us first.

Changes

If this notice changes in a way that affects you we will say so in the app rather than quietly updating the date at the top.