Draft for review. Last updated: 2026-08-22
⚖️ This is a working draft written to match what the software actually does
today. Before you publish it, three things must happen:
1. Replace every[BRACKET]with your real details.
2. Have a lawyer read it — I am not one, and the GDPR/Israeli PPL claims below
carry legal weight.
3. Re-check it against the code whenever you add a data source. The fastest way
to lose a beta tester's trust is a policy that says less than the app does.
This page is now live at/privacy. It is what Google's OAuth reviewers
read and what your testers read, so the brackets are no longer a private
matter.
Project Amon ("Amon", "we") is a private beta of a personal planning assistant, operated by [YOUR LEGAL NAME / COMPANY], [ADDRESS]. Questions, or any request below: [YOUR EMAIL]. For GDPR purposes we are the data controller for the information described here.
A closed beta with a small number of invited testers. It is not a finished product, it is not sold, and it may lose data. Do not put anything in it you cannot afford to lose. We will tell you before that changes.
You give us:
| Data | Why |
|---|---|
| Email address | To identify your account, send a verification code, and let you reset your password |
| Name | To address you in the app |
| Password | Stored only as a scrypt hash with a per-password salt. We never see or store the password itself |
| Time zone, working hours, sleep window, shift pattern | The planner is worthless without them |
| Tasks, plans, rituals, and anything you type to the assistant | This is the product |
| Feedback you send | To fix things |
| Who you are connected to, and what you have chosen to share with each of them | So the right person sees the right part of your day, and nobody sees the rest |
| Messages you send to people you are connected to | So they can be delivered and read |
You connect, and we then read:
| Source | What we read | What we never do |
|---|---|---|
| Google Calendar, if you connect it | Event titles, times, locations, video-call links, and whether you accepted or declined. Read-only — the permission we ask for is calendar.readonly | Write to it, delete from it, or ask for any other Google data. We never request access to your email |
A published .ics address (Google, Outlook, iCloud, Fastmail, a phone) | The same, from whichever calendar that address points at | Anything but read it. Treat the address like a password: anyone holding it can read that calendar |
| Jira, Todoist or Linear, if you connect them | Your open tasks: title, estimate, due date, and a link back | Write to them, or read anything that is not a task assigned to you |
How the credentials are held. Google's tokens and any API token you paste are encrypted before they are stored, with AES-256-GCM, and are never sent back to your screen — you only ever see the last four characters. Disconnect a Google account and we hand the grant back to Google rather than merely forgetting it. Deleting your account does the same. Where imported events end up. Timed events become fixed blocks on your day. All-day entries — holidays, leave — are stored against the date rather than turned into hours. Both are replaced wholesale on each sync, so something deleted upstream disappears here. If you publish a scheduling link:
| Data | Whose | Why | Kept |
|---|---|---|---|
| Name, email address, and an optional note | The person booking — not yours | So you know who is coming, and so they can be sent a confirmation and a cancellation link | Until the meeting is cancelled or you delete your account |
That person has no account here and has agreed to nothing, so we keep the minimum that makes a booking work: no tracking, no marketing, no sharing, and nothing about them beyond what they typed into that one form. The page they use sets no cookies, loads nothing from anywhere else, and is never indexed by search engines. Anyone with the link sees only when you are free — never a title, never a count, never a reason. A scheduling link is a URL that gets forwarded, and it is designed on that assumption. Created automatically as you use it:
| Data | Why | Kept |
|---|---|---|
| Session records — device type, browser, sign-in and last-used time | So you can see where you are signed in and revoke it | Until you revoke, or 30 days after last use |
| Push subscriptions | To deliver reminders to your devices | Until you disable notifications or the browser expires it |
| An activity log — the actions taken on your account | Security, and so you can see what the assistant did | 12 months |
| Sleep log — the length and rating of your sleep window | Rewards, and to adjust tomorrow's capacity | Until you delete your account |
| Product analytics — that something happened, never what it was about | To see where people get stuck. Event names come from a fixed list; no titles, no content, no IP address, no device fingerprint, and no third-party analytics service is involved | Raw events 180 days; a daily "was this account active" flag for as long as the account exists |
| Server errors | To find bugs. Grouped by fingerprint, with secrets stripped out | Until resolved, then pruned |
We do not collect: your location, your contacts, your files, advertising identifiers, or any biometric data. We do not use cookies for tracking or advertising. The only cookie we set is the one that keeps you signed in.
database on that machine, backed up to Tigris object storage in the EU.
Google (Android/Chrome), Apple (iOS/Safari) or Mozilla. The reminder's title and body are encrypted so that only your device can read them, but those services see that a message was sent to your device and when.
Resend, who processes your email address to deliver them.
request to the assistant, that sentence and a short summary of your day are sent to Anthropic to work out what you asked for. Anthropic does not train on it. If the feature is switched off, nothing leaves our server — the planner itself is deterministic and runs locally. Current status: DISABLED — no model is configured, so nothing is sent to Anthropic and the planner runs entirely on this server.
Atlassian, Todoist or Linear to read your data. We do not send them anything about you beyond the credential you granted, and we never write.
| Who | What they hold | Where |
|---|---|---|
| Fly.io | The database: everything above | Frankfurt, Germany (EU) |
| Tigris Data | Continuous backups of that database | Distributed object storage, EU region |
| Resend | Your email address, to deliver verification codes, password resets and booking confirmations | — |
| Google, Apple or Mozilla | That a push message went to your device, and when. The contents are encrypted so only your device can read them | — |
| Google (only if you connect a calendar) | Nothing of yours. We read from them | — |
| Anthropic (only if the assistant is enabled) | The sentence you typed, and a summary of your day | — |
There is no analytics vendor on this list, and there never has been. The usage analytics are first-party and record that something happened, never what it was about. We do not sell your data. We do not share it with advertisers. There is no analytics provider receiving your task or event titles — or anything else.
Nobody, unless you have deliberately shown them. For most people that is nobody at all: sharing is off for everything until you switch a specific thing on for a specific person.
You can ask another Amon user to connect, by their email address. They have to agree. Connecting on its own shares nothing — it only makes sharing possible. You then choose, per person and per category, one of three things:
| What they can see | |
|---|---|
| Hidden | Nothing at all. This is where everything starts |
| Busy only | That a period of time is taken. Not what it is |
| Names shown | What each thing in that category is called |
So a colleague can be shown your Work by name while your Hobbies appear only as busy time and your Private category stays invisible — and somebody else can be given entirely different answers. What a person you share with never receives, at any level: the reason a block is there, its notes, a meeting link, the task behind it, which calendar it was imported from, your sleep window, your working hours, or anything at all about a category you did not share. **Anything you have not filed under a category cannot be shared at all**, by you or by accident. Ending a connection removes every share in both directions, immediately, along with any messages between you. Deleting a category removes whatever was shared through it. Re-connecting to the same person later starts again from nothing.
Connected people can send each other plain text. We store those messages so they can be read, and delete them when either of you ends the connection or deletes their account. There are no attachments and no read receipts.
Administrators of this beta — currently one person — can see counts and account metadata: how many blocks you have, when you last signed in, how many devices are registered. **The administration tools cannot return the content of your plan.** No task titles, no event titles, no sleep data, no assistant conversations. This is enforced in the software, not only in this document, and there is an automated test that fails the build if it stops being true. An administrator also cannot set your password. They can only trigger the same reset email you could request yourself, so any access to your account leaves a trace in your inbox.
Under GDPR (and Israeli Privacy Protection Law where it applies) you can:
Download everything. One JSON file with every plan, task, ritual, sleep entry and activity record we hold. No waiting, no request form.
erases your account and everything attached to it immediately. It cannot be undone. Backups still holding your data roll off within 30 days.
Protection Authority. We will not make you jump through hoops for any of this. The first two are buttons in the app.
While your account exists, plus up to 30 days in backups after you delete it. The activity log is kept 12 months. When this beta ends we will give you notice, and delete everything unless you have moved to a live version.
Passwords are hashed with scrypt. Session tokens are stored only as hashes. Administrator accounts require a second factor. Traffic is encrypted in transit. Sessions can be revoked from any device. What is not yet true: task and event titles are stored unencrypted in the database. Anyone with access to the server or a backup file could read them. We consider this acceptable for a small beta among people who know us, and we are telling you rather than implying otherwise. Do not store anything sensitive. If we ever suffer a breach affecting you, we will tell you within 72 hours of becoming aware, with what happened and what to do.
Amon is not for anyone under 16. We do not knowingly hold data on children.
If we change this materially we will tell you in the app before it takes effect.
Contact: [YOUR EMAIL]