Skip to content
OwnCadence
How it works Why it adapts Control & privacy FAQ Blog
RO Sign in Start your plan
How it works Why it adapts Control & privacy FAQ Blog Start your plan
← Back to OwnCadence

Legal

Privacy notice

This notice explains how OwnCadence handles personal data when you visit our website, create an account, or use the AI-supported productivity and routine service.

Effective
14 August 2026
Version
1.0

The short version

  • Your goal, plan, check-ins, and optional context are used to provide the service—not for advertising or sale.
  • Optional sensitive context is off by default and requires separate, explicit consent.
  • AI receives only the context needed for the requested feature; important plan changes remain under your control.
  • You can access, correct, export, or delete your data and withdraw optional consent.

On this page

  1. 1. Who is responsible for your data
  2. 2. Personal data we process
  3. 3. Why we use data and our legal bases
  4. 4. How AI processing works
  5. 5. Who receives personal data
  6. 6. International transfers
  7. 7. How long we keep data
  8. 8. Cookies and local storage
  9. 9. Security
  10. 10. Your data-protection rights
  11. 11. Required data, optional data, and automated decisions
  12. 12. Adults only
  13. 13. Changes and contact

1. Who is responsible for your data

FUTUREFORGE LABS SRL, registered office at Str. Ion Țuculeșcu nr. 8C, Timișoara, județul Timiș, România, trade register no. J35/705/2024, fiscal code 49616330, EUID ROONRC.J35/705/2024 ("Futureforge", "we", "us") is the data controller for OwnCadence.

For privacy questions or rights requests, email hello@owncadence.com. We have not appointed a data protection officer because the service is not currently required to have one; the same address reaches the person responsible for privacy matters.

Scope

This notice covers the OwnCadence marketing website, web application, account, support, exports, and related service operations. A third-party site you choose to visit has its own privacy notice.

2. Personal data we process

Categories of personal data
CategoryExamples and source
Account and identityEmail address, external identity-provider identifier, locale, account state, and authentication/security events. You provide the email; Auth0 provides the identity identifier and sign-in events.
Goal and plan contentYour goal, onboarding answers, constraints, schedule preferences, weekly program, action status, check-ins, reflections, and edits that you enter or create through the service.
Memory and personalizationFacts you explicitly save, observations derived from your use, proposed inferences, and your decisions to accept, correct, dispute, stop using, or delete them.
Optional sensitive contextLimited context about sleep, food, exercise, mood, or family circumstances when you choose to provide it and separately consent. Do not provide detailed medical records or information about other people unless necessary and lawful.
Device and service operationsDevice/session identifiers, browser and app version, timestamps, IP-derived security data, request identifiers, error category, feature state, and content-free reliability or AI-run metadata.
Support and rights requestsMessages you send us, attachments you choose to provide, verification information, and records of our response.
Website delivery dataStandard server or CDN request data such as IP address, user agent, requested URL, timestamp, and security/routing information. We do not currently run optional product analytics, advertising trackers, or session replay on the marketing website.

We do not intentionally collect precise location, contacts, calendars, voice recordings, wearable data, payment-card data, or advertising identifiers in the current service. If a future feature needs a new category, we will provide information and obtain any required permission before activation.

3. Why we use data and our legal bases

Purposes and GDPR legal bases
PurposeDataLegal basis
Create and secure your account; provide the goal, plan, check-in, memory, export, and deletion featuresAccount, goal, plan, memory, device, and request dataPerformance of our contract with you (GDPR Art. 6(1)(b)); legal obligations where applicable (Art. 6(1)(c)).
Personalize suggestions and generate AI-supported explanations or proposed adaptationsOnly the goal, plan, recent evidence, and context needed for that requestPerformance of our contract (Art. 6(1)(b)). Optional sensitive context relies on explicit consent (Arts. 6(1)(a) and 9(2)(a)).
Protect accounts, prevent abuse, diagnose failures, maintain availability, and defend legal claimsIdentity, device, security, minimized operational metadata, and relevant support recordsOur legitimate interests in operating a secure and reliable service (Art. 6(1)(f)), balanced against your rights; and legal obligations (Art. 6(1)(c)).
Answer support, privacy, and consumer requestsContact, request, verification, and response recordsContract, legal obligation, and legitimate interests, depending on the request (Arts. 6(1)(b), (c), and (f)).
Optional product analytics, if introducedMinimized categorical events only after a separate control is offeredConsent (Art. 6(1)(a)). This processing is currently disabled.

Where we rely on legitimate interests, those interests are service security, abuse prevention, reliability, and the establishment or defence of legal claims. You may object as explained below. We do not use legitimate interests to override explicit-consent controls for optional sensitive context.

4. How AI processing works

OwnCadence is an AI-supported service. When an AI feature is enabled and you request it, our server assembles a minimized context from the relevant goal, plan, recent evidence, and preferences, then sends that context to the configured AI provider. We do not give the provider direct access to your account, database, calendar, email, or device.

The planned provider is OpenAI through its business API. OpenAI states that API inputs and outputs are not used to train its general models by default. Under its standard controls, customer content may be retained in abuse-monitoring logs for up to 30 days, and some Responses API application state may be retained for up to 30 days. We will describe any materially different provider or retention arrangement before it is used.

OwnCadence does not store raw model prompts and responses in its general operational logs by default. We may keep content-free run evidence—such as provider, model/version reference, status, timing, safety outcome, and request correlation—for up to 30 days. Your accepted plan, saved memory, or text you intentionally keep remains normal account content.

No decision with legal or similarly significant effect

AI output is advisory. Deterministic rules validate proposals, and you decide whether to accept material changes. OwnCadence does not use AI to make employment, credit, insurance, healthcare, legal, or other decisions that produce legal or similarly significant effects about you.

  • OpenAI API data controls ↗

    Current provider information about training, retention, and regional controls.

  • OwnCadence AI & Safety

    Capabilities, limitations, controls, and urgent-safety guidance.

5. Who receives personal data

Service providers and recipients
RecipientRole and data
Auth0 by OktaAccount authentication and identity security, using a European-region tenant. It receives account identifiers and sign-in/security data.
OVHcloudEuropean hosting infrastructure for the application, API, database, cache, and operational services.
Bunny.netWebsite delivery, DNS, and private object storage for encrypted exports/backups. Standard delivery and security logs may be processed.
OpenAIAI inference only when an AI feature is enabled and requested; receives the minimized request context described above.
Professional advisers and authoritiesLawyers, accountants, auditors, insurers, courts, regulators, or law-enforcement bodies only where necessary for advice, claims, compliance, or a lawful request.

Processors act under contracts and instructions appropriate to their role. We do not sell personal data, share it for cross-context behavioural advertising, or let advertisers build a profile from your goal or routine content. If the business is reorganized, data may transfer under confidentiality and applicable-law safeguards, with notice where required.

6. International transfers

We select European hosting and identity regions where practical, but some providers and their approved subprocessors may process data outside the European Economic Area. In particular, the standard OpenAI API arrangement may involve processing in the United States or other countries.

Where the destination is not covered by an adequacy decision, we rely on safeguards such as the European Commission's Standard Contractual Clauses, a provider data-processing agreement, transfer-risk measures, and data minimization, as applicable. You may ask for information about the relevant safeguard at our contact address, subject to protection of confidential security terms.

7. How long we keep data

Current retention schedule
DataRetention
Account, goal, active plan, check-ins, and saved memoryWhile your account is active and needed to provide the service. After you request account deletion, a 7-day recovery grace period applies; live account data is then deleted or irreversibly de-identified unless a narrow legal or security exception requires retention.
Onboarding recordUp to 1 year from completion or the last relevant account activity, and no longer than the account lifecycle unless a documented legal need applies.
Operational, security, and content-free AI-run evidenceNormally up to 30 days from the event; longer only for an active security incident, legal duty, or claim, with access restricted to that purpose.
Portable export fileOne-time access for up to 15 minutes, then the export object expires. Creating a new export does not extend an older link.
Database backupsUp to 30 days. Deletion tombstones are reapplied after a restore so deleted accounts are not brought back into active use.
Consent, privacy-request, support, and legal recordsFor as long as needed to prove the choice, answer the request, meet a legal duty, or establish or defend a claim; then deleted or minimized under the applicable limitation period.

A legal preservation duty, unresolved dispute, security investigation, or technically unavoidable backup cycle can delay final erasure of a limited record. Such data is isolated from ordinary product use and removed when the exception ends. Withdrawing optional-sensitive-context consent stops new use for that purpose and triggers deletion or de-identification unless another legal ground requires a narrow record.

8. Cookies and local storage

The marketing website does not currently set optional analytics or advertising cookies and does not use session replay. Our delivery providers may process standard request logs for routing, availability, and security.

The application uses strictly necessary authentication/session mechanisms and local device storage to keep you signed in, protect requests, remember settings, and support a limited offline experience. Blocking necessary storage may prevent sign-in or core features. If we introduce optional analytics or another non-essential technology, we will explain it and request consent where required before activation.

9. Security

We use measures designed for the risk, including encrypted network transport, access controls, server-side provider credentials, private storage, purpose-limited logs, schema and safety validation, deletion tombstones, backups, and monitoring. Access is limited to people and processors who need it for an authorized purpose.

No online service can guarantee absolute security. Protect your sign-in account, use a secure device, and contact us promptly if you suspect unauthorized access. Where a personal-data breach creates a legal notification duty, we will notify the competent authority and affected people as required.

10. Your data-protection rights

  • Access: ask whether we process your data and receive a copy and related information.
  • Rectification: correct inaccurate or incomplete data; many account and memory items can be edited directly.
  • Erasure: delete individual memories or request account deletion, subject to limited legal exceptions.
  • Restriction: ask us to limit processing in the situations provided by law.
  • Portability: receive data you provided in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller.
  • Objection: object to processing based on legitimate interests, including on grounds relating to your particular situation.
  • Withdraw consent: change your optional-sensitive-context or future analytics choice at any time, without affecting earlier lawful processing.
  • Complaint and remedy: complain to a supervisory authority and seek a judicial remedy. In Romania, the authority is ANSPDCP.

Use the in-app export, memory, consent, or deletion controls where available, or email hello@owncadence.com. Please state what you are requesting. We may ask for proportionate information to confirm identity and protect the account. We respond without undue delay and in principle within one month; a complex or numerous request may lawfully require an extension, and we will explain it. Rights are normally free, subject to the GDPR rules for manifestly unfounded or excessive requests.

  • Email hello@owncadence.com

    Privacy questions and rights requests.

  • ANSPDCP complaint information ↗

    Romanian data-protection supervisory authority.

  • EU data-protection rights ↗

    European Commission overview.

11. Required data, optional data, and automated decisions

An email/account identifier and enough goal and scheduling information to create a plan are required for the contracted service. If you do not provide them, we cannot create the account or program. Reflections, detailed notes, and optional sensitive context are voluntary; choosing not to provide them may make suggestions less tailored but does not block the core service.

OwnCadence does not make decisions based solely on automated processing that produce legal or similarly significant effects. AI may propose a routine adjustment or memory candidate, but product rules and your decision control whether a material change becomes part of the plan.

12. Adults only

OwnCadence is intended for people aged 18 and over. We do not knowingly offer the service to children or knowingly collect their data. If you believe a child has created an account, contact us so we can investigate and delete it as appropriate.

13. Changes and contact

We may update this notice when the service, providers, or law changes. We will post the new version and date here and provide a prominent or direct notice before a material change where required. A new optional purpose will not be applied retroactively without a valid legal basis and any required consent.

FUTUREFORGE LABS SRL, registered office at Str. Ion Țuculeșcu nr. 8C, Timișoara, județul Timiș, România, trade register no. J35/705/2024, fiscal code 49616330, EUID ROONRC.J35/705/2024. Privacy and support email: hello@owncadence.com.

  • Contact hello@owncadence.com
  • Terms of service
  • AI & Safety
↑ Back to top
OwnCadence

OwnCadence by FUTUREFORGE LABS SRL

Contact: hello@owncadence.com

Blog Privacy Terms AI & Safety Sign in RO

© 2026 FUTUREFORGE LABS SRL. All rights reserved.