align
Privacy Policy
Last updated: September 2026
Align is operated by [LEGAL NAME], based at [BUSINESS ADDRESS, COUNTRY]. This page is a placeholder for the operator's legal identity and must be completed with real details before this policy is treated as final.
Align is a personal planner. This policy describes the information used to provide your account, planning, family calendar, and optional integrations. It covers both the web app and the Android/iOS apps, and the backend services they use.
Information we process
- Account and profile: email and authentication information, your name and birthday, and optional profile settings such as gender. Supabase handles password authentication.
- Private planner: tasks, habits, reminders, journal entries, goals, budgeting and financial entries, meals, workouts, weight, fasting, and optional cycle and wellness records. These may contain sensitive personal information you choose to enter.
- Family calendar: household name, member display names, membership identifiers, invitations, and shared event titles, dates, times, categories, assignments and notes. Members of your household can see its shared events and member names. Your private planner is separate.
- Health bridge: metrics you choose to send through Apple Shortcuts, such as steps, sleep, heart-rate variability, resting heart rate and screen time, together with their dates. A personal token authorizes these writes. Tokens expire after 90 days and can be replaced or revoked in Account settings.
- Android Health Connect: on Android, with your permission, the app reads only the data types you pick (daily step count, sleep duration, and resting heart rate or the day's lowest heart rate) for the last seven days, and saves them to your private planner. Align never writes to Health Connect. You can revoke access in Health Connect or disconnect in the app; readings already saved stay until you delete them or your account.
- Voice: microphone audio is processed by your browser or device speech service, which may send audio to its provider for transcription. Processing is not guaranteed to stay on your device. Where voice interpretation is enabled, transcripts are sent through our backend to our self-hosted interpretation server. Text supplied for spoken responses is sent to our speech server. Planner entries you create by voice are saved like typed entries. The current app does not create separate command transcript logs; older versions did store transcripts, normalized text and parsed commands. Previously saved voice phrase aliases and historical logs remain associated with your account until deleted.
- Conversational assistant: where enabled, your latest 40 conversation messages and up to 30 memories you approve are saved with your private planner. Recent messages, saved memories and a limited selection of relevant planner records are sent through our backend to our self-hosted model on Hetzner. The assistant does not automatically read journal entries. You can clear the conversation and edit or forget memories in the assistant; forgetting or editing a memory also clears conversation history to avoid recalling outdated information. This feature uses no paid external AI API. Browser or device speech recognition remains subject to the voice processing described above.
- Google Calendar: when you connect it, we retain authorization tokens and event mappings to copy supported planner tasks and bills into your Calendar. Connection attempts temporarily store an expiring authorization state.
- Notifications: when you opt in to supported browser push reminders, we store a subscription endpoint and encryption keys. Notification content can contain task, bill, habit or wellness reminder names and may be visible on your lock screen.
- Payments: Stripe processes payment details. Align stores customer and subscription identifiers and subscription status, rather than card numbers. New subscriptions may be unavailable while billing is disabled.
- Local storage and technical records: your browser stores login sessions and preferences. Unsaved planner drafts are stored in the current browser session to recover failed saves. Hosting and service providers may process connection information such as IP addresses and operational logs.
Why and with whom
We use this information to operate your planner, synchronize your devices, provide the integrations you enable, manage access and payments, and diagnose failures. We do not sell planner data or use it for advertising.
- Supabase: authentication, database and backend hosting.
- Stripe: subscription and payment processing when used.
- Google: Calendar when connected. The main app also loads fonts from Google Fonts, which causes your browser to contact Google even without a Calendar connection.
- Browser and device providers: optional speech recognition and browser push delivery. Their processing is governed by their own service policies.
- Our hosting and self-hosted voice infrastructure: serving the app, interpreting voice text and generating spoken responses where enabled.
- Your household members: information you put in the shared family calendar. Share invitations only with people you want to grant access.
Security and your choices
The app uses authenticated access and database access rules to separate private planner records and restrict shared calendar access to household members. Connections to production services use HTTPS. These measures do not make data immune to security incidents.
You can edit planner information, disable microphone permission or browser notifications, disconnect Calendar, revoke a Health token, and leave a family calendar in the app. Household owners can remove members or delete their household calendar. Removing a member does not erase copies they previously made. Protect your account and any exported drafts or Health tokens.
Retention and deletion
Account-linked records remain while your account is active unless you remove them. Expiring tokens and invitations stop granting access when they expire; expiry does not necessarily erase their database records immediately.
Use Account → Delete account to request permanent deletion, including when subscription access has expired. Deletion first cancels linked subscriptions; if cancellation fails, the app reports a failure and retains the account so you can retry. Successful account deletion removes account-linked planner records, historical voice logs, tokens and notification subscriptions from the active database.
Deleting an account that owns a household also deletes that household and its shared events for everyone. Deleting another member's account removes their membership and events they created. Events already copied into Google Calendar are not erased by disconnecting or deleting Align. Stripe and other providers may retain records under their own retention policies or applicable obligations. Backup copies and operational logs may remain until the provider's retention cycle completes; account deletion does not promise immediate removal from every backup or external system.
For an account deletion request outside the app, see Delete your Align account. To request a copy or removal of specific information, contact support@wearealign.app. We may need to verify account ownership before responding.
Children
Align is not directed at children under 13. If you believe a child has supplied personal information, contact us.
Changes and contact
We update the date above when this policy changes. Questions can be sent to support@wearealign.app.