Legal
Privacy notice
This notice explains how OwnCadence handles personal data when you visit our website, create an account, or use the AI-supported productivity and routine service.
The short version
- Your goal, plan, check-ins, and optional context are used to provide the service—not for advertising or sale.
- Optional sensitive context is off by default and requires separate, explicit consent.
- AI receives only the context needed for the requested feature; important plan changes remain under your control.
- You can access, correct, export, or delete your data and withdraw optional consent.
1. Who is responsible for your data
FUTUREFORGE LABS SRL, registered office at Str. Ion Țuculeșcu nr. 8C, Timișoara, județul Timiș, România, trade register no. J35/705/2024, fiscal code 49616330, EUID ROONRC.J35/705/2024 ("Futureforge", "we", "us") is the data controller for OwnCadence.
For privacy questions or rights requests, email hello@owncadence.com. We have not appointed a data protection officer because the service is not currently required to have one; the same address reaches the person responsible for privacy matters.
2. Personal data we process
| Category | Examples and source |
|---|---|
| Account and identity | Email address, external identity-provider identifier, locale, account state, and authentication/security events. You provide the email; Auth0 provides the identity identifier and sign-in events. |
| Goal and plan content | Your goal, onboarding answers, constraints, schedule preferences, weekly program, action status, check-ins, reflections, and edits that you enter or create through the service. |
| Memory and personalization | Facts you explicitly save, observations derived from your use, proposed inferences, and your decisions to accept, correct, dispute, stop using, or delete them. |
| Optional sensitive context | Limited context about sleep, food, exercise, mood, or family circumstances when you choose to provide it and separately consent. Do not provide detailed medical records or information about other people unless necessary and lawful. |
| Device and service operations | Device/session identifiers, browser and app version, timestamps, IP-derived security data, request identifiers, error category, feature state, and content-free reliability or AI-run metadata. |
| Support and rights requests | Messages you send us, attachments you choose to provide, verification information, and records of our response. |
| Website delivery data | Standard server or CDN request data such as IP address, user agent, requested URL, timestamp, and security/routing information. We do not currently run optional product analytics, advertising trackers, or session replay on the marketing website. |
We do not intentionally collect precise location, contacts, calendars, voice recordings, wearable data, payment-card data, or advertising identifiers in the current service. If a future feature needs a new category, we will provide information and obtain any required permission before activation.
3. Why we use data and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure your account; provide the goal, plan, check-in, memory, export, and deletion features | Account, goal, plan, memory, device, and request data | Performance of our contract with you (GDPR Art. 6(1)(b)); legal obligations where applicable (Art. 6(1)(c)). |
| Personalize suggestions and generate AI-supported explanations or proposed adaptations | Only the goal, plan, recent evidence, and context needed for that request | Performance of our contract (Art. 6(1)(b)). Optional sensitive context relies on explicit consent (Arts. 6(1)(a) and 9(2)(a)). |
| Protect accounts, prevent abuse, diagnose failures, maintain availability, and defend legal claims | Identity, device, security, minimized operational metadata, and relevant support records | Our legitimate interests in operating a secure and reliable service (Art. 6(1)(f)), balanced against your rights; and legal obligations (Art. 6(1)(c)). |
| Answer support, privacy, and consumer requests | Contact, request, verification, and response records | Contract, legal obligation, and legitimate interests, depending on the request (Arts. 6(1)(b), (c), and (f)). |
| Optional product analytics, if introduced | Minimized categorical events only after a separate control is offered | Consent (Art. 6(1)(a)). This processing is currently disabled. |
Where we rely on legitimate interests, those interests are service security, abuse prevention, reliability, and the establishment or defence of legal claims. You may object as explained below. We do not use legitimate interests to override explicit-consent controls for optional sensitive context.
4. How AI processing works
OwnCadence is an AI-supported service. When an AI feature is enabled and you request it, our server assembles a minimized context from the relevant goal, plan, recent evidence, and preferences, then sends that context to the configured AI provider. We do not give the provider direct access to your account, database, calendar, email, or device.
The planned provider is OpenAI through its business API. OpenAI states that API inputs and outputs are not used to train its general models by default. Under its standard controls, customer content may be retained in abuse-monitoring logs for up to 30 days, and some Responses API application state may be retained for up to 30 days. We will describe any materially different provider or retention arrangement before it is used.
OwnCadence does not store raw model prompts and responses in its general operational logs by default. We may keep content-free run evidence—such as provider, model/version reference, status, timing, safety outcome, and request correlation—for up to 30 days. Your accepted plan, saved memory, or text you intentionally keep remains normal account content.
- OpenAI API data controls
Current provider information about training, retention, and regional controls.
- OwnCadence AI & Safety
Capabilities, limitations, controls, and urgent-safety guidance.
6. International transfers
We select European hosting and identity regions where practical, but some providers and their approved subprocessors may process data outside the European Economic Area. In particular, the standard OpenAI API arrangement may involve processing in the United States or other countries.
Where the destination is not covered by an adequacy decision, we rely on safeguards such as the European Commission's Standard Contractual Clauses, a provider data-processing agreement, transfer-risk measures, and data minimization, as applicable. You may ask for information about the relevant safeguard at our contact address, subject to protection of confidential security terms.
7. How long we keep data
| Data | Retention |
|---|---|
| Account, goal, active plan, check-ins, and saved memory | While your account is active and needed to provide the service. After you request account deletion, a 7-day recovery grace period applies; live account data is then deleted or irreversibly de-identified unless a narrow legal or security exception requires retention. |
| Onboarding record | Up to 1 year from completion or the last relevant account activity, and no longer than the account lifecycle unless a documented legal need applies. |
| Operational, security, and content-free AI-run evidence | Normally up to 30 days from the event; longer only for an active security incident, legal duty, or claim, with access restricted to that purpose. |
| Portable export file | One-time access for up to 15 minutes, then the export object expires. Creating a new export does not extend an older link. |
| Database backups | Up to 30 days. Deletion tombstones are reapplied after a restore so deleted accounts are not brought back into active use. |
| Consent, privacy-request, support, and legal records | For as long as needed to prove the choice, answer the request, meet a legal duty, or establish or defend a claim; then deleted or minimized under the applicable limitation period. |
A legal preservation duty, unresolved dispute, security investigation, or technically unavoidable backup cycle can delay final erasure of a limited record. Such data is isolated from ordinary product use and removed when the exception ends. Withdrawing optional-sensitive-context consent stops new use for that purpose and triggers deletion or de-identification unless another legal ground requires a narrow record.
9. Security
We use measures designed for the risk, including encrypted network transport, access controls, server-side provider credentials, private storage, purpose-limited logs, schema and safety validation, deletion tombstones, backups, and monitoring. Access is limited to people and processors who need it for an authorized purpose.
No online service can guarantee absolute security. Protect your sign-in account, use a secure device, and contact us promptly if you suspect unauthorized access. Where a personal-data breach creates a legal notification duty, we will notify the competent authority and affected people as required.
10. Your data-protection rights
- Access: ask whether we process your data and receive a copy and related information.
- Rectification: correct inaccurate or incomplete data; many account and memory items can be edited directly.
- Erasure: delete individual memories or request account deletion, subject to limited legal exceptions.
- Restriction: ask us to limit processing in the situations provided by law.
- Portability: receive data you provided in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller.
- Objection: object to processing based on legitimate interests, including on grounds relating to your particular situation.
- Withdraw consent: change your optional-sensitive-context or future analytics choice at any time, without affecting earlier lawful processing.
- Complaint and remedy: complain to a supervisory authority and seek a judicial remedy. In Romania, the authority is ANSPDCP.
Use the in-app export, memory, consent, or deletion controls where available, or email hello@owncadence.com. Please state what you are requesting. We may ask for proportionate information to confirm identity and protect the account. We respond without undue delay and in principle within one month; a complex or numerous request may lawfully require an extension, and we will explain it. Rights are normally free, subject to the GDPR rules for manifestly unfounded or excessive requests.
- Email hello@owncadence.com
Privacy questions and rights requests.
- ANSPDCP complaint information
Romanian data-protection supervisory authority.
- EU data-protection rights
European Commission overview.
11. Required data, optional data, and automated decisions
An email/account identifier and enough goal and scheduling information to create a plan are required for the contracted service. If you do not provide them, we cannot create the account or program. Reflections, detailed notes, and optional sensitive context are voluntary; choosing not to provide them may make suggestions less tailored but does not block the core service.
OwnCadence does not make decisions based solely on automated processing that produce legal or similarly significant effects. AI may propose a routine adjustment or memory candidate, but product rules and your decision control whether a material change becomes part of the plan.
12. Adults only
OwnCadence is intended for people aged 18 and over. We do not knowingly offer the service to children or knowingly collect their data. If you believe a child has created an account, contact us so we can investigate and delete it as appropriate.
13. Changes and contact
We may update this notice when the service, providers, or law changes. We will post the new version and date here and provide a prominent or direct notice before a material change where required. A new optional purpose will not be applied retroactively without a valid legal basis and any required consent.
FUTUREFORGE LABS SRL, registered office at Str. Ion Țuculeșcu nr. 8C, Timișoara, județul Timiș, România, trade register no. J35/705/2024, fiscal code 49616330, EUID ROONRC.J35/705/2024. Privacy and support email: hello@owncadence.com.