Privacy Policy
Last updated: August 2026
1. Information We Collect
Authentication: Email address and password (hashed) via Supabase Auth.
Profile: Display name (optional), plan tier, and IANA timezone used to keep each daily Line on your local calendar day.
Usage Data: Tasks, projects, notes, labels, and daily Line commits stored in our database.
Analytics: Opt-in client events cover the landing demo, authentication mode, onboarding beats, Task actions, Line commits, mode changes, and checkout-return actions. Minimal server events record waitlist signup, first Line, first Done, and confirmed Pro activation. Events never include email, Task titles, Project names, or notes. No session recording.
MCP beta: For API-token calls, we store key metadata plus tool name, success, latency, a normalized client category, and error category. MCP audit rows never contain Task titles, notes, Project names, email, raw tokens, or arbitrary User-Agent text.
2. How We Use Your Data
- Provide and improve the Nowva service.
- Understand usage patterns via anonymous analytics (PostHog, if enabled).
- Send transactional emails (subscription changes, account recovery).
3. Data Retention & Deletion
You can delete your account and all associated data at any time via the Settings panel or by requesting DELETE /api/account.
MCP keys and MCP audit rows are retained while the account exists and are deleted with the account.
We commit to deletion within 30 days (GDPR Art. 17). Soft-deleted data is purged after 90 days.
4. Third-Party Services
Supabase: Postgres database + Auth. Data Processing Agreement available.
PostHog: Product analytics. Client capture is opt-in; minimal server lifecycle events are waitlist_signup, first_line_committed, first_done, and pro_activated. No event includes content fields or email.
Vercel: Hosting and edge functions.
5. Your Rights
- GDPR (EU): Right to access (Art. 15), delete (Art. 17), rectify (Art. 16).
- CCPA (US): Right to know (§1798.100), delete (§1798.105).
- LGPD (Brazil): Right to access, delete, port data (Arts. 17–19).
Request data export: GET /api/account/export.
6. Security
Data in transit: TLS. At rest: AES-256 (Supabase). Database: user_id isolation via Row-Level Security (RLS).
7. Contact
Privacy questions: privacy@nowva.app
8. GDPR Disclaimer
Nowva is a task management tool, not a substitute for professional medical or mental health treatment. If you are experiencing a mental health crisis, please seek professional help.