24Fold

Privacy Policy

Last updated: 19 July 2026

This Privacy Policy explains how your personal data is collected, used, and protected when you use 24Fold (the “App”), a progressive web application (PWA) that you can use in your browser or save to your mobile home screen. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”).

Please read this policy carefully. By using 24Fold, you confirm that you have read and understood it.

1. Who we are (Data Controller)

24Fold is operated by an individual acting as the data controller responsible for your personal data.

If you have any questions about this policy or how your data is handled, please contact us using the email address above.

2. What the App does

24Fold lets you log the time you spend on important daily activities across life domains — such as sleep, eating, learning, and hobbies — and review weekly and monthly patterns to derive insights about how you spend your time. 24Fold is a personal tool: there are no social features, and your data is never shared with or visible to other users.

24Fold also offers Insights, an optional feature that uses artificial intelligence to turn your logged activities and notes into a short written reflection on your month. Insights is on by default and can be switched off at any time in Settings.

3. What personal data we collect

3.1 Account data

You sign in either with Google (OAuth) or with an email address and password. Depending on the method, we process:

When you use Google sign-in, we do not receive or store your Google password and we do not request access to any other Google data (such as contacts, calendar, or files). Passwords for email sign-in are handled securely by our authentication provider and are not visible to us.

3.2 Activity data you create

This is the content you enter into the App — the activities and life domains you log across the day’s time slots, the time spent, any notes or end-of-day reflections you choose to write, and your settings (your activity palette, start-of-day hour, reminder time, and timezone). This data is used to generate your patterns and insights and to sync them across your devices.

3.3 Notification data

If you enable daily reminders, we store the push-notification subscription token your browser provides, so we can deliver the reminders you’ve chosen. You can disable reminders at any time, which removes this.

3.4 Analytics data

We use PostHog (on its EU-hosted infrastructure) to understand product usage and improve the App. Analytics are off by default and run only with your consent — you choose whether to allow them, and you can turn them on or off at any time in Settings → Analytics. When enabled, PostHog may process information such as the features used, device and browser type, and approximate, non-precise location derived from your IP address, and associates these events with your account identifier and email. If you do not consent, no analytics data is collected.

3.5 Insights (AI processing)

Insights generates a short written reflection on your month from the activities you have logged and any notes or reflections you have written. When Insights is enabled, this data is sent to our AI sub-processor, Anthropic, which processes it to produce the reflection and returns it to the App. We do not send your name or email address for this purpose. Insights is on by default, and you can turn it off at any time in Settings — when it is off, no data is sent for this purpose. Sections 5, 6 and 7 explain where this processing happens, who is involved, and how long data is kept.

4. How we use your data and the legal basis

Under the GDPR, we must have a valid legal basis for each purpose for which we process your data:

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

5. Where your data is stored and processed

Your account and activity data are stored on cloud servers located within the European Union / European Economic Area (EU/EEA), in Frankfurt, Germany. We use Supabase (EU region) to host your account and activity data, Vercel to host the application, and PostHog’s EU infrastructure for analytics where you have consented.

Because our hosting is located in the EU/EEA, your data is generally not transferred outside the EEA. If any provider involves a transfer outside the EEA, we will ensure appropriate safeguards are in place, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, as required by Chapter V of the GDPR.

If you use Insights, the data described in section 3.5 is processed by Anthropic in the United States. This transfer outside the EEA is covered by the European Commission’s Standard Contractual Clauses under our data processing agreement with Anthropic.

6. Sharing your data

We do not sell your personal data, and we do not share it with other users. We share data only with service providers (“processors”) who help us run the App, and only to the extent necessary:

Reminder notifications are delivered through your browser/operating-system push service (for example Apple or Google). These providers act on our instructions under data processing agreements. We may also disclose data where required by law or to protect our legal rights.

7. How long we keep your data

We keep your account and activity data for as long as your account remains active. If you delete your account, or request deletion, we will delete your personal data within a reasonable period (typically within 30 days), except where we are required to retain certain information to comply with legal obligations. Invalid push subscriptions are removed automatically, and backups containing your data are deleted on a rolling basis as backup cycles expire.

Where you use Insights, the data sent to Anthropic may be retained by Anthropic for a limited period (up to 30 days) for trust-and-safety purposes and then deleted. Anthropic does not use data submitted through its API to train its models.

8. Your rights under the GDPR

As a data subject in the EU/EEA, you have the following rights:

To exercise any of these rights, contact us at 24fold.app@gmail.com. We will respond within one month, as required by the GDPR.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live or work. In Germany, supervisory authority is handled at the state (Land) level; a list of authorities is available via the German Federal Commissioner for Data Protection and Freedom of Information (BfDI).

9. Data security

We take appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS/TLS), authentication through Google OAuth and our authentication provider, access controls, and storage with a reputable EU-based cloud provider. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Cookies and local storage

As a PWA, 24Fold uses your browser’s local storage and similar technologies to keep you signed in, remember your preferences, and record your analytics choice. These are strictly necessary for the App to work and do not require consent. Non-essential analytics storage is created only after you consent, and not before.

11. Children’s privacy

24Fold is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect new features or legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the App.

13. Contact

If you have any questions, requests, or complaints about this Privacy Policy or your personal data, please contact us at 24fold.app@gmail.com.