Kdence — Privacy Policy
Effective date: 13 August 2026
Data controller: George Zoiade, Romania.
Contact for privacy matters: privacy@k-dence.app
1. In plain language
Kdence helps you plan and track personal tasks, goals, focus time, and weekly reflections. To make the app work — and to improve it over time — we collect a small amount of information about how you use it. Here's the short version:
- The content of your tasks, goals, reflections, and focus notes never leaves your device unless you sign in to sync it to our servers (Supabase). Even then, it's yours — you can delete it any time.
- We collect anonymous usage events (which screens you open, which buttons you tap) to understand which features actually help people. You can turn this off in Settings, and there's a step during onboarding to make the choice explicit.
- We do not sell your data, we do not share it with advertisers, and we do not use tracking identifiers across other apps or websites.
- You can request a copy of your data or delete your account at any time. Deletion is permanent.
This document explains the details.
2. Who runs Kdence
Kdence is developed and operated as a solo project by:
George Zoiade Romania
Contact for anything privacy-related: privacy@k-dence.app
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Romanian Law 190/2018, I am the data controller for the personal data processed through Kdence.
3. What we collect and why
3.1 Data you enter yourself
When you use Kdence, you create tasks, goals, reflections, and focus sessions. This content lives on your device (in the app's local database). If you're signed in, it's also synced to our cloud database (Supabase) so it survives across devices and reinstalls.
We collect this because it's literally what the app is for. Without it, there's nothing to display.
Legal basis (GDPR Art. 6(1)(b)): performance of the service you asked for.
3.2 Account and profile data
During onboarding we ask a small set of profiling questions:
- Daily available minutes (how much time you have for productive activities)
- Improvement areas (categories like "Health & Fitness", "Learning")
- Work type (employed / self-employed / student / etc.)
- Work schedule (fixed hours, shifts, or flexible)
If you sign in with email or Google, we also collect:
- Email address
- Display name (if you choose one)
- Google user ID (if you use Google Sign-In)
We use this to personalize the app's suggestions (e.g. scheduling advice that matches your work hours) and to sign you in on other devices.
Legal basis (GDPR Art. 6(1)(b)): performance of the service.
3.3 Usage analytics (opt-in, everywhere)
We record anonymous events about how you interact with the app: which screens you open, which buttons you tap, when you complete a task, when you finish a focus session, when a streak breaks. These events help us understand which features actually help people build habits — and which ones don't.
What the events contain: durable IDs (task ID, category ID), enums (priority, time segment), and numeric counts (elapsed minutes, streak length).
What they never contain: the text of your tasks, goals, or reflections. Payloads are restricted to structural data by design — free-form text never enters the analytics pipeline.
These events are sent to Firebase Analytics (Google) and to our own database (Supabase, EU Frankfurt region). Keeping a copy in our own database means we can answer questions about how the product is used without depending on a third party's dashboards. Firebase's advertising-identifier collection is explicitly disabled, so this is not "tracking" in the sense of Apple's App Tracking Transparency framework.
This happens whether or not you have an account. Usage analytics follow your Settings choice, not your sign-in status — see Section 6 for how this differs from the content you create. A copy is also held in the app's local database on your device, and all copies are deleted if you delete your account.
Nothing is collected until you say yes. The onboarding flow asks you to explicitly opt in — wherever you are in the world — and the default is off. Until you opt in, the analytics SDK collects nothing at all, not even the automatic events it would otherwise gather on its own. You can turn it off again at any time in Settings → Privacy → "Share usage data".
Legal basis (GDPR Art. 6(1)(a)): your consent. If you turn it off, we stop collecting these events immediately.
3.3a Engagement records
Separately from the analytics above, we keep a small set of records about your use of the app that the app itself needs in order to work:
- Active days — the calendar dates you opened the app. This drives your streaks, your daily digest, and the timing of occasional prompts.
- Rescheduling and focus-interruption history — when you move a task's due date, or pause a focus session. These let the app show you patterns in your own behaviour (for example, "you've moved this task five times").
These records are part of the service rather than optional analytics, so they are not covered by the "Share usage data" toggle — turning analytics off does not disable your streaks. They contain no free-form text.
They are stored in our Supabase database (EU, Frankfurt) whether or not you have an account. That's deliberate: without it, reinstalling the app or changing phone would silently reset your streak and your history, and most people use Kdence for a while before creating an account.
We also use your active-day record to decide who receives occasional promotional access to premium features. You can object to this use at any time by emailing privacy@k-dence.app; doing so does not affect your streaks or digest.
Legal basis (GDPR Art. 6(1)(b) and (f)): performance of the service for the features themselves, and our legitimate interest in rewarding engaged users for the promotional use.
3.4 Diagnostic data
If the app crashes or hits an unexpected error, Firebase Crashlytics records a report so we can find and fix the bug. Reports include the device model, OS version, and a stack trace — no personal content from your tasks or reflections.
Legal basis (GDPR Art. 6(1)(f)): legitimate interest in delivering a working app.
3.4a Bot protection
When you create an account, we run an invisible Cloudflare Turnstile challenge to confirm the request isn't automated — Supabase requires this token before it will accept a sign-up. Cloudflare receives your IP address and basic browser/device signals in order to make that assessment; we receive only a pass/fail token, never the underlying signals.
The challenge runs during sign-up only — never while you are using the app — and no content from your tasks, goals or reflections is sent.
Legal basis (GDPR Art. 6(1)(f)): legitimate interest in preventing automated abuse of the sign-up endpoint.
3.5 Data we don't collect
For clarity, here's what Kdence does not collect:
- Your location (precise or approximate)
- Your contacts, calendar, photos, or files
- Your device's advertising identifier (IDFA, GAID)
- Any biometric data
- Your browsing history in other apps
- Data purchased or received from third-party data brokers
4. Who else sees your data
Kdence uses three third-party service providers to operate. Each processes data on our behalf under a written data-processing agreement.
| Provider | Purpose | Where data is stored | Their privacy policy |
|---|---|---|---|
| Supabase (Supabase Inc., USA / EU) | Cloud database, authentication + usage analytics | EU (Frankfurt region) | supabase.com/privacy |
| Firebase / Google (Google LLC, USA) | Crash reports + high-level analytics | Global (Google-controlled) | policies.google.com/privacy |
| Cloudflare (Cloudflare, Inc., USA) | Bot protection on sign-up (Turnstile) | Processed at the nearest Cloudflare edge; not stored by us | cloudflare.com/privacypolicy |
We do not sell your data to anyone. We do not share your data with advertisers.
For transfers of data outside the EU/EEA (Firebase, Cloudflare), the transfers rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent GDPR-approved mechanisms.
5. How long we keep your data
- Data you enter (tasks, goals, focus sessions, reflections): kept for as long as you have an active account. Deleted when you delete your account.
- Analytics events (opted-in users): held by Firebase Analytics under Google's retention controls, in our own database (Supabase), and in the app's local database on your device. All are cleared when you delete your account.
- Engagement records (active days, rescheduling and focus-interruption history): kept for as long as you have an active account. Deleted when you delete your account.
- Aggregate analytics (counts, funnels — no user ID attached): kept indefinitely for product research.
- Crash reports: kept for 90 days (Firebase default).
- Authentication records: deleted immediately when you delete your account.
Inactive accounts. If you don't open Kdence for 24 months, we delete your account and everything associated with it — your content, your analytics and engagement records, and your authentication record. This applies whether or not you created an account with an email address.
You can trigger immediate deletion at any time — see Section 7.
6. Where your data is stored
-
On your device: in the app's local SQLite database (Drift). Encrypted at rest by the operating system.
-
Content you create — tasks, goals, focus sessions, reflections — is stored in our cloud (Supabase, EU Frankfurt region) only if you're signed in. Until then it never leaves your device. Encrypted at rest by Supabase and in transit via TLS.
-
Records about your usage are different. Two kinds don't wait for you to sign in:
- Usage analytics — if you've left analytics on in Settings, those events go to Firebase and to our Supabase database (see Section 3.3).
- Engagement records — your active days and the rescheduling / focus-interruption history described in Section 3.3a.
Both are stored in our Supabase database (EU, Frankfurt) whether or not you have an account. The distinction is between what you write — which stays on your device until you sign in — and facts about how you use the app, which we keep so your streaks and history survive reinstalling or changing phone.
-
Firebase / Crashlytics: Google's global infrastructure. Encrypted at rest and in transit.
-
In your device's own backup: if you use your platform's device backup — Android Backup (to your Google Drive) or iCloud Backup on iOS — the app's local database is included, so your data survives a phone upgrade or a new device. This is your backup, not ours: we have no access to it and cannot read, restore, or delete it. Android backups are end-to-end encrypted with your device's lock-screen PIN or pattern, which Google cannot read. Apple's iCloud Backup is encrypted in transit and at rest, and is end-to-end encrypted only if you have turned on Advanced Data Protection. You can exclude Kdence from device backups in your operating system's settings.
7. Your rights
Under GDPR and Romanian Law 190/2018, you have the following rights over your personal data. You can exercise any of them by emailing privacy@k-dence.app. We respond within 30 days (extendable by 60 more days if the request is complex, with prior notice).
- Right of access — you can ask us for a copy of everything we hold about you.
- Right to rectification — if any of it is wrong, we'll fix it.
- Right to erasure — you can ask us to delete your account and all associated data. You can also do this in-app via Settings → Account → Delete Account (this is the fastest path).
- Right to restriction of processing — you can ask us to freeze processing while a dispute is resolved.
- Right to data portability — you can ask for your data in a machine-readable format.
- Right to object — you can object to processing based on legitimate interest (crash reports, the promotional use of your active-day record).
- Right to withdraw consent — where processing is based on consent (usage analytics), you can withdraw it at any time via the Settings → Privacy → "Share usage data" toggle; it takes effect immediately.
- Right to lodge a complaint — if you're unhappy with how we've handled your data, you can complain to the Romanian data-protection authority (ANSPDCP) at dataprotection.ro or your local EU data-protection authority.
Requests are free of charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse — but this is rare and we'll explain the reason.
More detail: the GDPR Addendum sets out the legal basis for each category of processing and the precise mechanism for exercising each right. For EU/EEA users, it is the authoritative source wherever it and this policy differ.
8. What happens when you delete your account
When you tap Settings → Account → Delete Account:
- Your account is deleted from our Supabase database. Every row we hold that belongs to you — tasks, goals, focus sessions, reflections, categories, profile, analytics events and engagement records — is removed with it. This is immediate and irreversible.
- The app's local database on your device is wiped: the same content, plus any analytics events still queued there.
- Your Firebase Analytics record is reset. This regenerates the anonymous identifier the events were collected under, severing them from you; Google's data-retention controls handle the rest.
- Your authentication record is deleted immediately. We keep nothing back.
- You'll be signed out on all devices, and the app returns to its anonymous, empty state — as if freshly installed.
If you'd rather delete a specific piece of data (a single task, goal, etc.) without deleting your whole account, use the in-app delete on that item.
9. Children
Kdence is not intended for children under 16. This is aligned with Romanian Law 190/2018 Art. 8, which sets the digital-consent age at 16.
By using Kdence, you confirm you are at least 16 years old, or that you have permission from a parent or legal guardian.
If you're a parent or guardian and you believe your child under 16 has provided us data, please email privacy@k-dence.app and we will delete it.
10. Cookies and tracking technologies
The Kdence mobile app does not use cookies.
Our public marketing website (k-dence.app), if any, may use minimal privacy-friendly analytics (e.g. server-side counts). Any cookies used there will be disclosed in a separate cookie notice on the site itself.
We do not use tracking pixels, ad networks, or cross-app tracking identifiers.
11. Security
We take reasonable technical and organizational measures to protect your data:
- Data in transit is encrypted with TLS (HTTPS everywhere).
- Data at rest is encrypted by the underlying storage (device OS, Supabase, Firebase).
- Access to production databases is restricted to the developer (George Zoiade) via strong authentication.
- We do not store passwords in plain text — authentication is handled by Supabase's built-in secure password hashing.
No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify you and the Romanian data-protection authority (ANSPDCP) within 72 hours of discovery, as required by GDPR.
12. Changes to this policy
We may update this policy from time to time — for example, when we add new features or change service providers. Material changes will be communicated in-app before they take effect. Non-material updates (typos, clarifications) will be published to this page with an updated "Effective date" at the top.
Older versions of this policy are archived in the app's public repository.
13. Contact
For anything privacy-related — questions, requests, complaints — email:
privacy@k-dence.app
Response time: within 30 days of your request.
If you're not satisfied with our response, you can lodge a complaint with:
ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) dataprotection.ro B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
Or your local EU/EEA data-protection authority if you're outside Romania.