Privacy policy
Effective date: 2 October 2026
Set it Now ("the App") is a daily planner application developed by Tim ("we", "us", "our"). This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
1. Information we collect
1.1 Account information
- Anonymous account — When you first open the App, a unique anonymous account is created automatically via Firebase Authentication. No personal information is required.
- Sign in with Apple — If you choose to sign in with Apple, we receive your name and email address, or a private relay address if you choose to hide your email, from Apple.
- Google sign-in — If you choose to sign in with Google, we receive your name, email address, and profile photo from Google.
- Email and password — If you create an account with email, we store your email address and a securely hashed password via Firebase Authentication.
1.2 Content you create
All content you create in the App is stored in Google Cloud Firestore, linked to your user ID:
- Tasks, to-do items, and their details (title, date, time, tags, location, notes, recurrence rules)
- Calendar events (imported from Apple Calendar, Google Calendar, Microsoft Calendar, or ICS files)
- Work shifts (title, times, location)
- Habit tracking data (water intake, step count, reading sessions, meditation minutes)
- Medication records (name, dosage, frequency, scheduled times, dose logs, adherence data)
- Shopping list items
- Journal entries (text content, mood, automatically detected tags)
- Shared calendar data (calendar names, events shared with other users you invite)
- Focus timer sessions (duration, linked task, completion status)
- App preferences and settings
1.3 Device permissions and sensor data
| Permission | Purpose | Platform |
|---|---|---|
| Calendar access | Import and sync events from your device calendar | iOS, Android |
| Notifications | Send task reminders, medication reminders, and daily briefings | iOS, Android, Web |
| Motion and pedometer | Track daily step count for the Habits feature | iOS, Android |
| Location | Attach locations to tasks and shifts; display shift locations on a map; show the local weather (see Section 1.14) | iOS, Android, Web |
| Microphone | Voice input for the voice assistant feature (speech-to-text) | iOS, Android, Web |
| Speech recognition | Convert spoken queries to text for the voice assistant (processed on-device by the operating system or browser) | iOS, Android, Web |
Web-specific permissions: On the web app, your browser may prompt you separately for notification, microphone and location access. Push notifications on the web use Firebase Cloud Messaging (FCM) and require a notification permission grant from your browser. You can revoke these at any time in your browser settings.
All permissions are optional. The App will function without granting any of these permissions, though some features will be limited.
1.4 Automatically collected data
- Analytics — We use Firebase Analytics (Google) to collect anonymous usage data such as screen views, feature usage, app crashes, and device type. This data is not linked to your personal identity.
- Push notification tokens — A device token is generated to deliver push notifications. This token is stored in Firestore and deleted when you disable notifications.
1.5 No advertising
The App shows no ads, on any platform or plan. We do not use advertising identifiers such as the iOS IDFA or the Android Advertising ID, we do not set advertising cookies, and we do not share your data with advertising networks.
1.6 Voice assistant data
The App includes an optional voice assistant feature that lets you ask questions about your schedule using voice or text. Speech recognition is performed on-device by your operating system (Apple Speech Framework on iOS, Android SpeechRecognizer on Android, Web Speech API in browsers). Your spoken words are converted to text locally and are not sent to our servers. The resulting text query is processed locally against your task and event data to generate a response.
1.7 Features that use Google Gemini
The App uses Google Gemini AI (via Firebase Cloud Functions) for several features. Where your device has its own AI model, some of these can run on your device first and nothing is sent (see Section 1.15). All data is sanitised before transmission. The specific data sent varies by feature:
| Feature | Data sent to Google Gemini |
|---|---|
| Task classification | Task or event title only |
| Batch import classification | Up to 50 event/task titles |
| Find a time (smart schedule) | Titles, durations and priorities of the tasks being scheduled; your free time slots |
| Voice assistant, when the phone can't answer on its own | Your spoken or typed question; your task list (titles, dates, times, tags) |
| Wrapped summary (Pro) | Counts only (tasks completed, habit rate, focus minutes, busiest hour). Task titles are not sent |
| Plan my day (schedule builder) | Task titles, durations, priorities, tags; event times; focus time preference; productivity patterns |
| Optimise week | Task titles, dates, times, durations, priorities, tags, completion status; 14-day productivity patterns |
| Break down a task | Task title, optional notes (up to 500 characters), task category |
| Analytics insights | Aggregated scores and statistics only (life score, completion rates, peak hours, category breakdowns) — individual task titles are not sent |
Permanent account required. All AI-powered features listed above, along with directions lookups and text to speech (Section 1.8), are available only to users who have signed in with an Apple, Google or email and password account. Anonymous sessions do not have access to these features — server-side checks refuse anonymous requests, and where a local on-device fallback exists (such as keyword-based task tagging) it is used instead. This restriction protects the service against automated abuse and keeps usage-based AI costs sustainable.
We enforce per-user rate limits on all AI and directions endpoints. Requests that exceed the limit are temporarily refused until the window resets.
No passwords, email addresses, location data, or full account details are ever sent to Gemini. All AI processing is subject to Google's AI Terms of Service.
1.8 Text to speech
Spoken replies and briefings are turned into audio by Microsoft Azure AI Speech, hosted in Australia. The text to be spoken (up to 2,000 characters, which can include task and event titles) is sent to Azure only to produce the audio. For Pro users the App sends this text from your device straight to Azure using a short-lived access token issued by our servers; otherwise it goes through our servers. On the free plan, the voice assistant's replies use your device's own voice instead and are not sent to Azure (see Section 1.15). Microsoft processes it under the Microsoft Products and Services Data Protection Addendum and does not use it to train its models.
If Azure is unavailable, our servers send the same text to Google Cloud Text-to-Speech instead, which is separate from Gemini and subject to the Google Cloud Terms of Service. Generated audio may be cached on your device and in our database so repeated phrases play faster, and is deleted once it has gone unused for 7 days.
1.9 Focus timer and soundscapes
The focus timer tracks session durations, timer mode (focus/break), and links sessions to tasks. This data is stored in Firestore under your account. Soundscape audio files are streamed locally and no listening data is collected.
1.10 Medication tracking
The medications feature stores prescription names, dosages, frequencies, scheduled dose times, and daily dose logs in Firestore under your account. Medication names may be looked up against the RxNorm database (U.S. National Library of Medicine) for autocomplete suggestions — only the search query text is sent, and no personal data is transmitted.
1.11 Payments and subscriptions
Pro subscriptions on mobile are processed by Apple App Store (iOS) and Google Play (Android). On the web, subscriptions are processed by Paddle (our Merchant of Record). We do not store your credit card details. Paddle may collect your name, email, and billing address as described in Paddle's Privacy Policy. We receive a subscription status, plan type, and Paddle customer ID to manage your Pro access.
1.12 Contact and feedback form
If you send us a message through the contact form on our website, we collect what you submit so we can read and respond to it:
- Message type — general feedback, feature request, bug report, or other
- Your message — the free-text content you write. Please do not include sensitive personal or health information
- Email address — optional, and used only to reply to you. Leave it blank to submit without giving us a contact address
Before a message is accepted, Cloudflare Turnstile checks that it was sent by a person rather than an automated program. To do this, Cloudflare processes technical information such as your IP address and browser details, as described in Cloudflare's Privacy Policy. To limit how many messages can be sent each day, we keep a one-way hash of your IP address alongside a daily count; we do not store the IP address itself. Sending a message does not create a Set it Now account. Messages are stored in our Firestore database and forwarded to our support inbox by email. The form is send-only: submitted messages cannot be read back from the website.
1.13 Body log and health app sync
If you turn on the Body log, Set it Now stores the period days, symptoms, pulse readings and salt you enter, one record per day, in your account. If you also connect Apple Health or Health Connect, it reads your resting heart rate and period days, only after you allow it. If you run a guided stand test, it reads your heart rate only for the length of the test (2 to 15 minutes), after you allow it, and keeps just the two pulse numbers it fills in and how long you stood. During a test started on your phone, your Apple Watch also sends your heart rate straight to your phone so you can see it live. Those live readings stay on your phone. This data is never sold, never used for ads, never sent to any AI feature and never shared through the Set it Now API. Deleting your account deletes it.
1.14 Weather
If you allow location access, the App shows the current weather. To get it, your device sends its location coordinates (latitude and longitude) directly to Open-Meteo, a weather service. The request goes straight from your device to Open-Meteo, not through our servers, and no account details are sent with it. Like any website you connect to, Open-Meteo also sees your IP address. We do not store your coordinates in your account; the forecast is kept on your device for a short time so it isn't fetched again on every visit. This is subject to Open-Meteo's terms.
1.15 AI on your device
Where your device has its own AI model (Apple Intelligence on supported iPhones, the built-in model in Chrome on computers) and we have turned this on for it, the App asks it first to sort tasks, break tasks into steps and, on iPhone, answer voice questions. When it does, that text stays on your device. If the device can't do the job, the App uses Google Gemini as described in Section 1.7. Turn on "Keep AI on this phone" (or "Keep AI on this computer") in Settings and the App won't send that text to Gemini. On the free plan, the voice assistant speaks its replies with your device's built-in voice instead of our speech service.
2. How we use your information
- Provide, maintain, and improve the App's features
- Sync your data across devices via your account
- Send task reminders, medication reminders, and notifications you have configured
- Enable shared calendars so you can collaborate with people you invite
- Automatically categorise tasks and calendar events using on-device keyword matching, your device's own AI model where available (see Section 1.15) and, as a fallback, Google Gemini AI
- Generate schedule suggestions, weekly optimisations and Wrapped summaries using AI. Daily briefings are written without AI
- Track focus sessions, habit progress, and medication adherence
- Answer voice questions about your schedule, on your device where it can and with Google Gemini when it can't
- Process subscription payments and manage Pro access
- Analyse aggregate usage patterns to improve the App (via Firebase Analytics)
- Diagnose crashes and technical issues
3. Data storage and security
Your data is stored in Google Cloud Firestore and Firebase Authentication, hosted on Google Cloud infrastructure. Data is encrypted in transit (TLS) and at rest. Firestore security rules ensure that each user can only access their own data. A copy of your tasks is also kept with Cloudflare (Durable Objects, encrypted at rest) so search can find anything you have ever saved and older history loads quickly. Only you can read it, and it is deleted when you delete your account.
4. Data sharing
We do not sell your personal data. We share data only with:
- Google Firebase — authentication, database, analytics, and cloud messaging (as our infrastructure provider)
- Google Gemini AI — task/event data for classification, scheduling, voice questions, Wrapped summaries and insights as detailed in Section 1.7 (subject to Google's AI Terms)
- Microsoft Azure AI Speech — text of spoken replies and briefings for audio conversion, as detailed in Section 1.8
- Google Cloud Text-to-Speech — the same text when Azure is unavailable (subject to Google Cloud Terms)
- U.S. National Library of Medicine (RxNorm) — medication name search queries for autocomplete (no personal data transmitted)
- Paddle — payment processing for web Pro subscriptions (name, email, billing address as described in Paddle's Privacy Policy)
- Mailgun — delivery of contact-form messages to our support inbox (subject to Mailgun's Privacy Policy)
- Cloudflare Turnstile — checks that contact-form messages, and the web app once you sign in, are used by a person rather than an automated program, using technical signals such as your IP address and browser details (subject to Cloudflare's Privacy Policy)
- Cloudflare — stores a copy of your tasks to power search and task history (subject to Cloudflare's Privacy Policy)
- Open-Meteo — your device's location coordinates, sent directly from your device when you allow location access, to show the local weather (Section 1.14)
- OpenStreetMap (Nominatim) — the place or address you type into a location field, sent directly from your browser to suggest matches, and the map shown for a shift location (subject to the OSM Foundation Privacy Policy)
- Apple / Google — in-app purchase processing for mobile Pro subscriptions (subject to their respective privacy policies)
- Other users you invite — If you create a shared calendar and invite someone, they will see the calendar name, events in that calendar, and your display name/email. You control who is invited.
We may disclose data if required by law or to protect our legal rights.
5. Your choices and rights
- Permissions — You can revoke any device permission (calendar, location, notifications, motion, microphone) at any time in your device or browser settings.
- Web permissions — On the web app, you can manage notification, microphone and location permissions in your browser's site settings.
- Keep AI on your device — Turn on "Keep AI on this phone" or "Keep AI on this computer" in Settings and task sorting, breakdowns and voice replies never send your text to Google Gemini. Other AI features, such as planning your day, still use Gemini. The setting appears only on devices where on-device AI is available.
- Manage your subscription — You can manage or cancel your Pro subscription through the App Store (iOS), Google Play (Android), or your Paddle customer portal (web).
- Delete your data — You can delete your account and all associated data from the App's Settings screen (see how to delete your account). This permanently removes your tasks, habits, shifts, medications, journal entries, shopping lists, and account information from our servers.
- Export — You can export your data as CSV, iCal or a full JSON backup from the App at any time, free of charge.
6. Children's privacy
The App is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
7. Third-party services
The App integrates with third-party calendar services (Apple Calendar, Google Calendar, Microsoft Calendar) at your request. When you connect these services, their respective privacy policies apply to the data they share with us. We only import event titles, dates, and times — we do not access your full calendar account.
8. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the App after changes constitutes acceptance of the updated policy.
9. Contact us
If you have questions about this Privacy Policy or your data, contact us at:
Email: tim@setitnow.online