SetOut — Privacy Policy (DRAFT v0.3, 2026-09-30)
Effective date: [DATE OF LAUNCH]
SetOut ("SetOut", "we", "us") is a personal weekly planner available at setout.website. This policy explains what personal data we process when you use SetOut, why, and what rights you have. It is written to be read, not skimmed: every processor and every retention period below is real and reflects how the service is actually built.
1. Who is responsible
The data controller is Vladyslav Molodan, sole proprietor (FOP) registered in Ukraine, registration number [FOP REGISTRATION NUMBER], registered address [REGISTERED ADDRESS]. Contact for all privacy matters: support@setout.website.
2. What we collect, and why
Account data. Your email address and a password (or a Google account, if you sign in with Google). Authentication is handled by Supabase Auth. We do not store your password: when you sign in, it travels over an encrypted connection through our server to Supabase Auth, which keeps only a hashed form; our server never writes it to disk or to logs. We also store the time you registered and the time you were last active. Purpose: to create and secure your account. Legal basis: performance of our contract with you.
Planner content. Tasks and their notes, subtasks, labels, tags, repeat rules, reminders, "Someday" items, cards (including photos you upload), and interface settings. Purpose: this is the service itself. Legal basis: contract.
Wellbeing entries (mood). SetOut keeps a daily mood score — one number from one to five, chosen with a single tap, one per day. That is the whole of it: there is no diary text, no free-text field, and nothing is inferred about your state from anything else you write. Because a mood score can reveal information about your health and wellbeing, this is off until you explicitly consent — with the separate, optional checkbox when you create your account, or later in Settings. You can withdraw consent at any time in Settings; withdrawing deletes your mood entries and returns the module to its initial, off state. Legal basis: your explicit consent (GDPR Art. 9(2)(a)).
Google Calendar (optional). If you connect a Google Calendar, SetOut requests read-only access (calendar.readonly) and caches event titles, times and calendar names so they can be shown beside your week. Connecting is a separate consent screen from signing in, and you can disconnect at any time in Settings, which deletes the cached events and revokes our access token with Google. SetOut's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we use calendar data only to display it to you inside SetOut, never for advertising, never for training models, and we do not transfer it to anyone except as needed to provide this feature. Legal basis: consent.
Reminders and push notifications (optional). If you enable notifications on a device, we store the push subscription (endpoint and keys) for that device and a log of which reminders were delivered, so that a reminder is never sent twice. Legal basis: consent (you enable it per device).
Your device's time zone. When you open your week, we record your device's time zone (for example, Asia/Bangkok) with your settings in each calendar you own, so that reminders without a set time ring at your local hour even when the app is closed. It is part of your export and is deleted with your account. Purpose: this is the service itself. Legal basis: contract.
Sessions and security. For each sign-in we store a session record with a device label derived from your browser's user-agent string and the sign-in time, so you can see and revoke sessions in Settings. We keep a short-lived, hashed record of failed sign-in attempts per email address to lock out password guessing. We do not store your IP address in our database. Our hosting provider (Vercel) keeps standard server logs, which include IP addresses, for a short period for security and debugging. Legal basis: legitimate interest in keeping accounts secure.
Feedback. Messages you send through the in-app feedback thread and our replies. The thread is readable by you and by SetOut support, and by no one else; it travels over HTTPS and is stored encrypted at rest, but it is not end-to-end encrypted — support has to be able to read what you write. Please do not send passwords or payment details through it. Your thread is deleted together with your account. Legal basis: legitimate interest in answering you.
Billing. Payments are processed by Paddle (Paddle.com Market Ltd, UK, or Paddle.com Inc., US, depending on where you are), who acts as Merchant of Record: Paddle is the seller you buy from, and Paddle — not SetOut — collects your card details, billing address and tax information under Paddle's own privacy policy. From Paddle we receive only your subscription status, plan, billing period and Paddle's identifiers for the subscription. Legal basis: contract; legal obligation (tax and accounting records).
Error monitoring. We use Sentry to learn when the service breaks. Error reports contain technical details (URL path, browser, stack trace) and your internal account identifier — not your email, not your IP address, and never the contents of a request. We do not use session replay. Legal basis: legitimate interest in keeping the service working.
Product metrics. We count registrations, activations and trial conversions from our own database, in aggregate. We do not use third-party analytics, advertising pixels or tracking cookies. Legal basis: legitimate interest.
What we do not do. We do not sell personal data. We do not use your data for advertising. We do not use your data to train AI models, and SetOut contains no AI features that read your content. We make no automated decisions about you that have legal or similarly significant effects.
3. Cookies and local storage
SetOut sets only cookies the service needs to work, and none of them is used for tracking or advertising: setout_session keeps you signed in (HttpOnly, Secure); setout_oauth_state protects a connection to Google (sign-in or Google Calendar) and expires after ten minutes; setout_profile remembers which of your calendars is open; setout_theme, setout_tz and setout_input let the server draw your first screen in your theme, in your time zone and for touch or mouse. Your browser's local storage holds interface preferences (for example, which banners you have dismissed) and never leaves your device. Because we use no analytics or advertising cookies, there is no cookie banner to click through.
4. Who processes data on our behalf
We rely on the following providers (sub-processors), each bound by a data processing agreement:
| Provider | Role | Location |
|---|---|---|
| Supabase | database, authentication, file storage (photos) | Singapore (AWS ap-southeast-1) |
| Vercel | hosting and delivery of the application | United States / global edge network |
| Cloudflare | DNS, traffic protection and rate limiting | global edge network |
| Resend | transactional email (verification, password reset, notices) | United States |
| sign-in with Google; Calendar API (only if you connect a calendar) | United States | |
| Paddle | payments and subscription billing (Merchant of Record — an independent controller for payment data) | United Kingdom |
| Sentry | error monitoring (no personal content, see above) | United States |
We will update this table before adding a provider that processes personal data.
5. International transfers
Your data is stored in Singapore and processed by providers in the United States and the United Kingdom. Where you are in the EEA, the UK or Switzerland, transfers are covered by the providers' Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework), which you can request from us.
6. How long we keep data
- While your account exists, we keep your data so the service works.
- When you delete your account (Settings → Delete account), your sign-in credentials, your account, your calendars, content, photos, push subscriptions, mood entries and feedback thread are deleted immediately — there is no grace period and nothing can be restored afterwards; calendar access tokens are revoked with Google. Copies in encrypted backups expire within [30] days.
- Wellbeing entries are deleted immediately when you withdraw consent by turning the module off.
- Inactive accounts. If you have not signed in for 24 months, we email you twice (60 and 14 days before) with a link to export your data and a button to keep the account; without a response, the account is deleted.
- Billing records held by Paddle are kept for as long as tax law requires.
7. Your rights
Depending on where you live (including under the GDPR, the UK GDPR and the Law of Ukraine "On Personal Data Protection"), you have the right to access, correct, export, restrict or delete your personal data, to object to processing based on legitimate interest, to withdraw consent at any time, and to lodge a complaint with a supervisory authority. In SetOut you can exercise the most important ones yourself: export (Settings → Export — a ZIP with data.json, README.html and CSV files), correct (edit anything in the planner), delete (Settings → Delete account), withdraw consent (Settings → Account & security → Delete mood data, disconnect a calendar, disable notifications on a device). For anything else, write to support@setout.website; we answer within 30 days.
8. Security
All traffic is encrypted in transit (TLS); data is encrypted at rest by our providers. Access to production systems is limited to the operator. Every request to the service is checked on the server against your session — permissions are never decided in the browser. If a breach affecting your data ever occurs, we will notify the competent authority within 72 hours where required and inform you without undue delay.
9. Children
SetOut is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
10. Changes
If we change this policy in a way that matters to you, we will tell you by email or in the app at least 14 days before the change takes effect. The version date is at the top.
11. Contact
Vladyslav Molodan, FOP · [REGISTERED ADDRESS] · support@setout.website