Legal

Privacy Policy

Short version: calendar connection is optional. Today's event titles and times are read in your browser and are not stored in the ActEarly database. We do not sell personal data. Calendar access can be disconnected in ActEarly and revoked from your Google or Microsoft account.

Effective date: September 10, 2026 · ActEarly (early access)

1. Who we are

ActEarly ("we", "our") is an early-stage, unincorporated project operated from India. It provides a desk-break scheduling tool at actearly.app. Questions about this policy: +91 89391 11367.

2. What we collect

Account data. When you sign in with email and password, Google, or Microsoft, we receive the account information needed to identify you, such as your name, email address, and profile photo when provided. We store this in our database.

Calendar data. Calendar connection is optional and separate from login. For Google we request https://www.googleapis.com/auth/calendar.events; for Microsoft we request delegated Calendars.ReadWrite. We use this access to read today's primary calendar event titles and start/end times to find gaps between meetings, then create, update, or delete ActEarly break events in those gaps. We do not read event descriptions, attachments, video links, or events outside of today.

Onboarding and preference data. During onboarding you can provide body area priorities, work hours, break rhythm, work setup, desk and screen time, age range, height, weight, fitness level, goals, injury choices or notes, notification tone, and calendar preferences. We store these answers so your setup and progress are available when you return. Body area priorities route movement sessions. Some other answers support preference restoration and early-access product research.

Usage data. We record product events such as pages viewed, reminder actions, movement starts and completions, session length, and calendar connection or scheduling outcomes. Supabase stores account-linked product events. Firebase Analytics receives a pseudonymous local analytics identifier. We do not intentionally include calendar titles, injury notes, names, or email addresses in analytics event properties.

Technical data. Standard server logs may include IP address, browser type, operating system, and referring URL. These are kept for security and debugging purposes only.

3. How we use it

  • To find gaps in your calendar and write break events into them.
  • To route exercise sessions to the body regions you selected.
  • To send break prompts at times that fit your actual schedule.
  • To understand product use through account-linked and pseudonymous analytics.
  • To respond to support requests you send us.

We do not use your personal data for advertising. We do not use your calendar event content for any purpose beyond scheduling and managing your ActEarly breaks.

4. Data sharing

We do not make your account data available to your employer or another organization. Authorized ActEarly staff may access it when needed to operate the service, investigate security or reliability issues, or respond to support requests. The service providers listed below process limited data on our behalf.

We never sell personal data. This is not something we have ever done or will do.

Legal requirements. We may disclose data if required by law, subpoena, or to protect our legal rights. We will notify you where legally permitted.

5. Third-party services

  • Google OAuth and Calendar API. We use Google Sign-In for authentication and the Google Calendar API to read your schedule and create, update, or delete ActEarly break events. Google's privacy policy: policies.google.com/privacy.
  • Supabase. Your account data and preferences are stored in Supabase with row-level security. Data at rest is encrypted. Supabase privacy policy: supabase.com/privacy.
  • Microsoft OAuth and Microsoft Graph. We use Microsoft Sign-In for authentication and, only when separately connected, Microsoft Graph to read calendar timing and create, update, or delete ActEarly break events. Microsoft privacy: privacy.microsoft.com/privacystatement.
  • Firebase Analytics. Used for pseudonymous product analytics only. Firebase is not used for authentication or primary account storage. Firebase privacy: firebase.google.com/support/privacy.
  • Cloudflare Turnstile. We use Turnstile on the desk-strain assessment form to help prevent automated submissions. Read Cloudflare's Turnstile Privacy Addendum.
  • Sentry. Used for website error monitoring and diagnostics. Our configuration excludes request bodies, headers, cookies, and session replay, and does not intentionally send personal information. Sentry privacy: sentry.io/privacy.

6. Calendar access in detail

We request Google's calendar.events scope or Microsoft's delegated Calendars.ReadWrite permission. Both allow viewing and editing calendar events. We use them for one purpose: reading today's primary calendar events to find gaps, and creating, updating, or deleting ActEarly break events in those gaps.

We do not access shared calendars belonging to other users, read content beyond event titles and times, or store calendar data between sessions.

ActEarly's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect calendar access inside ActEarly Settings. You can also revoke Google access at myaccount.google.com/permissions. Microsoft access can be revoked at account.live.com/consent/Manage. If you do, the calendar timeline will show a reconnect prompt and break auto-scheduling will pause until you reconnect.

7. Data retention and deletion

We keep your account data, onboarding answers, settings, activity progress, and product analytics for as long as your account is active. If you delete your account, we delete your data within 30 days, except where we are required by law to retain it.

Calendar event data is read at request time and not persisted in our database. It is held in browser memory only while needed to display and schedule the current day.

To request account deletion, message us on +91 89391 11367 with the text "Delete my account."

8. Your rights

Depending on where you are located, you may have the right to:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Ask us to correct inaccurate data.
  • Deletion. Ask us to delete your personal data.
  • Portability. Request your data in a machine-readable format.
  • Objection. Object to certain processing activities.
  • Restriction. Ask us to restrict processing while a dispute is resolved.

To exercise any of these rights, message us on +91 89391 11367. We will respond within 30 days.

If you are in the European Economic Area, you have the right to lodge a complaint with your local data protection supervisory authority.

9. Children

ActEarly is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have done so, message us on +91 89391 11367 and we will delete it promptly.

10. Security

We use industry-standard measures to protect your data: encrypted connections (HTTPS/TLS), row-level security on the database so users can only access their own records, and bearer token authentication for all API requests. OAuth tokens are never exposed in URL query strings.

No transmission method is 100% secure. If you discover a security issue, message us on +91 89391 11367 and we will investigate promptly.

11. Changes to this policy

We will notify you of material changes by in-app notice at least 30 days before they take effect. The effective date at the top of this page reflects when the current version took effect.

Continued use of ActEarly after the effective date means you accept the updated policy.

12. Contact

Privacy questions: +91 89391 11367

ActEarly (early-access project) · Terms of Service