Account information: Name, email address, username, and password (hashed)
Content you create: Goals, habits, journal entries, notes, time blocks, and other data you enter
Feedback you send: Messages you submit through "Send feedback", and (if you choose) the page you were on
Feedback on our preview pages: If you answer "What do you think?" on a landing page preview, we store your answers and, only if you enter it, your email so we can reply. These answers aren't linked to an account, and we don't store your IP address with them.
Usage data: Features used, session duration, and interactions (for product improvement)
Screen-use analytics: When you open a screen in the app (for example Plan, Notes › Journal, or Work Mode) we record the screen's name, the time, and your account and workspace. This is first-party product analytics: it is stored only in our own database, never sent to third parties or advertising/analytics services, and only viewed in aggregate (which screens are used, and by how many people) to decide how to improve the app. These records are kept for up to 180 days and are deleted with your account.
Weather location (optional): Only if you turn on Weather. We store your city, region, country, time zone, preferred units, and coordinates rounded to two decimal places (about 1 km) — never your exact position. "Use my location" rounds the coordinates on your device before they are sent to us. Turning Weather off keeps the city until you choose "Forget location", which deletes it.
Third-party connections: OAuth tokens for Google when you connect Google Calendar or sign in with Google, and for Microsoft when you connect an Outlook or Microsoft 365 calendar
Calendars you connect (optional): Connecting Google Calendar or Outlook / Microsoft 365 gives Ascanti read-only access to your calendars; Ascanti never creates, changes or deletes events. We store a refresh token, encrypted, so we can keep reading your calendar, plus each calendar's name and color. Google events are read when you open your plan and are not stored. Outlook events, and events from a calendar link you add, are copied into our database (title, time, place, attendees and the meeting link) so they show in your plan; events marked private are stored only as “Busy”. To stop, click Disconnect in Settings › Integrations › Calendar: we delete the token and the copied events. You can also remove access in your Google Account or Microsoft account settings. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: calendar data is used only to show your calendar in Ascanti, is never sold or used for advertising, and is not used to train AI models.
Tasks you import: The tasks, projects and labels in a file you import from another app. If you import with an access token instead of a file, the token is used once, on our server, to read your tasks from that app, and is never stored
Payment information: Processed by Stripe; we do not store credit card numbers
2. How We Use Your Information
To provide and improve the Ascanti service
To generate AI coaching responses using Anthropic's Claude (your goals and context are sent to the AI for personalized coaching)
To send service-related communications (account verification, billing)
To send optional daily emails, only if you turn them on: a "Good morning" email and a "Daily recap" built from your own tasks, habits and goals. These are off by default. We also send a "Weekly goals report", a once-a-week summary of your own planned time, goals, tasks and habits; it is on by default and you can turn it off any time in Settings or with one click from the email. We may also send one check-in email if you haven't opened Ascanti for 30 days; you can turn that off in Settings. Every one of these emails has a one-click unsubscribe link.
To process payments through Stripe
To show events from calendars you connect (Google Calendar, Outlook / Microsoft 365, or a calendar link) in your plan, at your request
To add tasks you import from another app, once, at your request
3. AI Data Processing
Ascanti uses Anthropic's Claude AI to provide coaching and other AI features (such as the daily briefing, task suggestions, capture suggestions, and reading text from images you upload). When you use these features, your goals, habits, tasks, and relevant context are sent to Anthropic's API for processing. Anthropic does not use your data to train their models. See Anthropic's Privacy Policy.
4. Data Sharing
We do not sell your personal information. We share data only with the service providers that run Ascanti, and with services you choose to connect:
Hetzner: Hosts the servers and database where your data is stored
Cloudflare: Content delivery and security (all traffic passes through Cloudflare), plus Cloudflare Web Analytics, a cookieless page-view measurement script
Anthropic: For AI features (as described above)
Resend: Sends transactional email (welcome, password reset, invitations, reminders, the weekly goals report and daily emails you turn on)
Fastmail: Hosts our own mailboxes, so it processes email you send us and feedback forwarded to us
Stripe: For payment processing
Google: When you connect Google Calendar or sign in with Google
Microsoft: When you connect an Outlook or Microsoft 365 calendar, our server reads your calendars from Microsoft Graph
The app you import tasks from: Only if you import with an access token: our server sends that token to the app once to read your tasks. Nothing is sent back to it, and the token is not kept
Weather providers (only if you turn on Weather): Our server — never your browser — sends the rounded, city-level coordinates (no account or personal details) to the U.S. National Weather Service (api.weather.gov) for US locations and, where enabled, to Open-Meteo (open-meteo.com) for other locations. City searches are sent to Open-Meteo's geocoder or, when Open-Meteo is not enabled, to the U.S. Census Bureau's place lookup. Forecasts are cached by rounded location and shared across users in the same area.
Stability AI: We used Stability AI to pre-generate some of the ambient audio in Focus mode. No user data is sent to Stability AI.
5. Data Security
We protect your data with:
HTTPS encryption for all data in transit
Scrypt password hashing (passwords are never stored in plain text)
HttpOnly, SameSite cookies with CSRF protection
Rate limiting and security headers
Regular database backups
For more detail on how we protect your data, see Trust & security.
6. Your Rights
You have the right to:
Export your data: Settings > Data > Export JSON
Delete your account: Settings > Profile > Delete Account (permanently removes all your data)
Access your data: All your data is visible within the app
Correct your data: Edit any information in your profile or goals
7. Data Retention
We retain your data for as long as your account is active. When you delete your account, your data is permanently deleted from the live database immediately. Backups containing deleted data are overwritten within 30 days.
Screen-use analytics records are deleted after 180 days, or immediately when you delete your account.
When you delete your account, we keep one anonymous statistical record so we can learn why people leave. It contains no identifying information: no email, name, username, account or workspace ID, IP address, or anything you wrote. It holds only broad facts such as the month you signed up and the month you left, how long you had the account, your plan, rough ranges of how much you used (for example "6–20 tasks"), which features you tried, and any reasons you picked from the list when leaving. The optional comment you type when leaving is deleted with your account. Because the record cannot be linked back to you, it is not personal data and is kept for product analysis.
Security audit logs (records of actions such as sign-ins, account changes, and the IP address and browser they came from) are retained, including after an account is deleted, so that we can investigate abuse and security incidents. If you joined the waitlist, your waitlist entry (email and the details you gave) is also kept separately from your account.
7a. Workspaces and Admins
Each account belongs to a workspace. If you were invited from the waitlist, you get your own workspace and you are its admin. If someone invites you into their workspace, that workspace's admins and any manager assigned to you can see your name and email, the names of your active projects, the titles of your recent tasks, activity counts, and the workspace activity log (security events such as sign-ins, with IP address). They cannot see the contents of your journal, notes, or goals. Ascanti's operators can see account details (name, email, workspace) to run the service.
8. Cookies
We use only essential cookies:
Session cookie: Keeps you logged in (HttpOnly, 14-day expiry)
CSRF token: Prevents cross-site request forgery
Theme preference: Stored in localStorage (not a cookie)
We do not use tracking cookies or third-party analytics cookies. Cloudflare Web Analytics measures page views without cookies.
9. Children's Privacy
Ascanti is not intended for children under 16. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes via email or in-app notification.