Privacy Policy

What we hold, why we hold it, who else touches it, and how to get it back or get rid of it.

Version 1.0 · Effective


The short version

  • Your entries are yours. We store them so the app works. We do not sell them, we do not advertise against them, and we do not train AI models on them.
  • We do not read your data as a matter of course. Nothing in the product mines your entries for our own purposes. The narrow exceptions are listed in section 4 and they are real ones — fixing a fault you reported, investigating abuse, or a legal obligation.
  • The AI agent is the exception you should know about. When you use it, the content it needs is sent to the AI providers listed on our Sub-processors page. Nothing is sent when you are not using it.
  • Health data gets special treatment, because European law says it must. We ask for your explicit consent, and you can withdraw it.
  • Your data is stored in the United States today, under the safeguards described in section 9.
  • You can get all of it out, or delete all of it, at any time.

1. Who is responsible for your data

The controller of your personal data is Danielius Korsakas, a sole trader registered in the Republic of Lithuania under registration number 977976, trading as Kaizendex.

Contact for anything in this policy, including to exercise your rights: trackguilds@gmail.com.

We have not appointed a Data Protection Officer. We are a one-person operation and our processing, while sensitive in kind, is not "large scale" within the meaning of Article 37 GDPR. We keep this under review.

2. What we collect, why, and on what legal basis

WhatWhy we have itLegal basisHow long
Account data — email, display name, password hash, avatar, authentication tokensTo create and run your account, sign you in, and contact you about the servicePerformance of our contract with you (Art. 6(1)(b))While your account exists
Your tracking content — collections, properties, entries, values, notes, dashboards, views, files and photos you uploadThis is the product. It exists to hold exactly thisContract (Art. 6(1)(b))Until you delete it, or your account
Health, fitness, mood, food, sleep, body and location data you record or syncTo track what you asked the app to trackYour explicit consent (Art. 9(2)(a)), on top of the contract basis. Withdrawable at any timeUntil you delete it, or your account
Data from connected services — Google Health, Fitbit, and similarTo sync what you asked us to syncYour explicit consent, given per provider and revocable by disconnectingUntil you delete it, disconnect, or delete the account
Screen-time and browser activity, if you install the extension or desktop appTo run the activity tracker you enabledYour explicit consent, per deviceUntil you delete it, or your account
AI conversations, agent memory, and the capability audit logTo run the agent, let you review and revert what it did, count your allowance, and debug failuresContract, and our legitimate interest in a working, abuse-free service (Art. 6(1)(f))While your account exists
Usage counters — message counts, storage used, sync activity, feature countsTo enforce plan limits and understand what to buildContract, and legitimate interestWhile your account exists
Technical and error data — IP address, browser and device type, timestamps, crash reports and stack tracesTo keep the service secure and working, and to fix crashesLegitimate interest (Art. 6(1)(f))Up to 90 days
Billing data — subscription status, plan, invoices, the last four digits and type of your cardTo take payment, meet accounting and tax dutiesContract, and legal obligation (Art. 6(1)(c))As long as tax law requires, normally 10 years for invoices
Published Library items and your display name next to themTo show what you chose to publishYour consent, given per publicationUntil you unpublish; copies others made stay theirs
Support correspondenceTo answer youContract, legitimate interest2 years

We never receive your full card number. Card details go directly to our payment processor.

3. What we do not do

  • We do not sell your personal data, and we never have.
  • We do not share it with advertisers, data brokers, or ad networks.
  • We run no advertising trackers, no third-party analytics scripts, no advertising cookies, and no cross-site tracking pixels.
  • We do not use your content to train AI models, and our AI providers process your content only to return the response you asked for — not to train on it.
  • We do not build profiles about you for anyone else's benefit, and we make no automated decisions that produce legal or similarly significant effects on you.

4. When a human can see your content

Access to the production database is limited to the operator of the service — today, one person. Your content is looked at only when:

  1. you ask us to — for example, you report a bug and we need to reproduce it on your account;
  2. we have to investigate abuse or a security incident, and the investigation cannot be done without it; or
  3. the law requires it — a valid order from a competent authority. Where we are legally allowed to tell you, we will.

Access is not automated, not routine, and not used to look at anyone's tracking data out of curiosity.

5. The AI agent, in detail

When you send a message to the agent, or use a feature the agent powers, the following is sent to an AI provider: your message, the relevant slice of your data the agent needs to answer, your agent's instructions and memory, and the tools it may call. The providers, and which ones your chosen model preset uses, are listed on the Sub-processors page.

  • Your content is sent only when you use those features.
  • Providers process it to produce a response, under their API terms.
  • We do not use it for training, and we do not permit our providers to use it for training.
  • The agent's writes to your data are logged and reversible, so you can always see what it did.
  • Voice input is transcribed by a speech-to-text provider; the audio is sent for transcription and not retained by us beyond producing the text.

Choosing a model preset changes which companies process your content, including their country. If that matters to you, check the Sub-processors page before choosing, and pick the preset that suits you in Settings.

6. Health and other special-category data

Sleep, weight, food, mood, symptoms, medication, menstrual-adjacent tracking, and precise location are treated by the GDPR as special-category data — the most protected kind. We process them only with your explicit consent under Article 9(2)(a).

  • Consent is asked for separately from these documents, in plain terms, not buried in a checkbox.
  • You can withdraw it at any time in your settings, or by emailing trackguilds@gmail.com. Withdrawal does not affect processing that already happened.
  • If you withdraw, we offer to export your data first, then delete the affected records.
  • The rest of Kaizendex keeps working if you never give this consent — you simply do not use those trackers.

7. Cookies and what we store on your device

We use strictly necessary cookies only: the session cookies that keep you signed in, and a small number of preference values. We set no advertising or analytics cookies, which is why you do not see a cookie banner — under the ePrivacy rules, strictly necessary cookies do not require consent.

Kaizendex is a local-first app, so most of what you see is stored on your own device, in your browser's IndexedDB or in the app's local database, and synced with our servers. Clearing your browser storage or signing out clears the local copy; your account data on the server is unaffected.

8. Who else touches your data

We use a small number of service providers ("sub-processors") to run Kaizendex — hosting, database, error monitoring, AI, transcription, payments. Each is bound by a contract that limits them to processing your data on our instructions.

The current list, what each one does, and where it processes data, is published and kept up to date at /legal/subprocessors.

Beyond those, we share personal data only:

  • with authorities, where a valid legal obligation requires it;
  • with professional advisers under confidentiality, where necessary;
  • to establish, exercise or defend legal claims; or
  • with a successor, if the business is ever sold or transferred — you would be told beforehand.

9. Where your data is stored, and international transfers

Our database, file storage and authentication run in the United States (our hosting provider's us-east-1 region). Our web hosting, AI routing and error monitoring providers are also established in the United States, and some AI providers are established elsewhere, including in Asia — the Sub-processors page states this per provider.

That means your personal data, including special-category data where you have consented to it, is transferred outside the European Economic Area. Those transfers are made under the European Commission's Standard Contractual Clauses, or another Article 46 GDPR safeguard where one applies, together with the technical measures in section 11.

You should understand this plainly: countries outside the EEA may not offer the same level of legal protection, and public authorities in those countries may have powers of access that EU law would not permit. You can ask us for details of the safeguards that apply at trackguilds@gmail.com.

10. How long we keep things

  • Your content stays until you delete it, or you delete your account.
  • Account deletion: you can schedule deletion from your settings. There is a 7-day grace period during which signing back in cancels it. After that, your account and personal data are permanently deleted within 30 days, except where we must keep something (below).
  • Backups are overwritten on a rolling cycle; deleted data disappears from backups within 30 days.
  • Published Library items are unpublished when you delete your account. Copies other users already made remain in their accounts, because those are now their objects.
  • Invoices and accounting records are kept for as long as Lithuanian tax law requires, typically 10 years, regardless of account deletion.
  • Error and security logs are kept for up to 90 days.

11. Security

We protect your data with encryption in transit (HTTPS everywhere) and at rest, row-level security in the database so one account cannot read another's rows, hashed passwords we never see, access tokens for connected providers stored encrypted and never synced to your devices, and least-privilege access to production.

No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights, we will tell you and the supervisory authority as the GDPR requires.

12. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and get a copy;
  • rectify anything inaccurate — most of it you can edit yourself;
  • erase your data ("right to be forgotten");
  • restrict or object to processing based on legitimate interests;
  • portability — receive your data in a structured, machine-readable format, and have it sent elsewhere where technically feasible;
  • withdraw consent at any time, including for health data, without affecting past processing; and
  • complain to a supervisory authority.

How to actually exercise them:

RightThe fastest route
Access / portabilityEmail trackguilds@gmail.com — we send a machine-readable copy within 30 days. Our kzx command-line tool can also project your whole account into plain files on your own disk
RectificationEdit it in the app; email us for anything you cannot reach
ErasureSettings → Account → delete your account, or delete individual items in the app
Withdraw health consentSettings → your privacy controls, or email us
Disconnect a providerSettings → Integrations
Object / restrictEmail trackguilds@gmail.com

We answer within one month, and will tell you if we need longer because a request is complex. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.

Your right to complain. If you think we have handled your data badly, please tell us first — but you can complain directly to the Lithuanian supervisory authority, the Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), at vdai.lrv.lt, or to the authority in the EU country where you live or work.

13. Children

Kaizendex is not for people under 16. We do not knowingly collect data from anyone under that age. If you believe a child has an account, email trackguilds@gmail.com and we will delete it.

14. Changes to this policy

We may update this policy. The version number and effective date at the top of this page always tell you which version is current. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect, and where the law requires it we will ask for your consent again.

15. Contact

Danielius Korsakas, trading as Kaizendex — a sole trader registered in the Republic of Lithuania, registration number 977976.

Email: trackguilds@gmail.com