Privacy Policy
Effective Date: August 30, 2026 • Version 2.5
At appx.work, we believe your personal thoughts, weekly schedules, and private notes belong to you. We do not sell your personal data, we do not show advertisements, and we do not use your notes or tasks to train AI models.
1. Information We Collect
We collect only the minimum necessary information required to provide, synchronize, and secure the Service:
- Account & Authentication Data: Email address for passwordless authentication (OTP / Magic Link) or OAuth profile identifiers (Google Sign-In).
- User-Generated Content: Task lists, weekly plans, notes, checklist items, file attachments, and category boards.
- Third-Party Calendar Integration Data: When you connect Google Calendar or Microsoft Outlook, we store OAuth tokens and fetch event metadata (event title, start time, end time, meeting URL, and event ID) to display them in your planner.
- Payment Information: Transactions are handled directly by our Merchant of Record (Paddle.com). We never see or store full credit card numbers.
2. Google API Services User Data Policy (Limited Use Disclosure)
appx.work's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only request read-only access (
calendar.events.readonly) to display your schedule inside your planner. - We never transfer, share, or sell Google user data to third-party advertising platforms, data brokers, or information resellers.
- We never use Google user data to train generalized AI or machine learning models.
- You can disconnect and revoke access at any time in Settings or via your Google Account Permissions.
3. How We Use Your Information
- To provide real-time multi-device cloud synchronization and offline-first data caching.
- To authenticate your identity and protect against unauthorized account access.
- To display your selected calendar events alongside your daily tasks.
- To respond to your bug reports, feature suggestions, and customer support inquiries.
4. Data Storage, Security & Encryption
We enforce PostgreSQL Row Level Security (RLS), TLS 1.3 encryption in transit, and sandboxed offline local caching.
5. Your Rights & Data Control (GDPR & CCPA)
You have the right to access, export (JSON/PDF), edit, and permanently delete your data or account at any time.
6. Contact Information
For questions regarding this Privacy Policy, email [email protected].