Privacy Policy
Exactly what we store, why, for how long, and who else sees it.
Version 1.2.0 ยท in effect from 2026-08-25
This page is generated from the application's data-practices manifest. It describes what the software actually does, because the same manifest drives the code and is verified against it on every build.
1. What we store
Near Pace is a planning tool, so almost everything it holds is content you typed yourself. The table below is the complete list - it is generated from the database schema, so it cannot omit anything.
Personal data
| Category | What it is | Why we hold it | Sent to AI? |
|---|---|---|---|
| Account details | users |
Identify you, sign you in, and let you recover access to your account. If you set a password it is stored one-way, so nobody here can read or recover it. If you sign in with Google or Microsoft instead, there is no password on your account at all. | Never |
| Linked sign-in accounts | identities |
Let you sign in with Google or Microsoft instead of a password. We store the provider name, the opaque account identifier it gives us, and the email address on that account. We never receive or store your Google or Microsoft password, and we request only your basic profile and email - no access to your mail, files or calendar. | Never |
| Goals and milestones | goals |
Store the goals you create so the app can plan around them and show progress. Goal titles and descriptions are sent to the AI provider only when you use an AI feature and have AI enabled. | Only when you use an AI feature |
| Milestones | milestones |
Break a goal into checkpoints so progress is measurable. | Only when you use an AI feature |
| Tasks | tasks |
Track the individual actions that move a goal forward. | Only when you use an AI feature |
| Habits and check-ins | habits |
Track recurring behaviours you want to build, and how consistently you keep them. | Only when you use an AI feature |
| Habit completion history | habit_entries |
Record which days a habit was completed, so streaks and consistency can be calculated. Only aggregate counts derived from this are ever used in AI prompts - never the raw date history. | Never |
| Notes and journal entries | notes |
Store the notes and reflections you write. Journal entries are the most sensitive thing here. They are sent to the AI provider only when you explicitly ask for a reflection, and only if AI is enabled. | Only when you use an AI feature |
| Subscription | subscriptions |
Record which plan you are on, when it renews, and any referral credit you have earned. Card details are never stored here. Payment is handled by the payment provider and we only keep the plan and its renewal date. | Never |
| Referrals | referrals |
Track which accounts you referred so the free months you earned can be applied. The person you referred is never told who referred them, and you are never shown their activity - only that a referral succeeded. | Never |
| What the AI remembers about you | ai_memory |
Hold short, readable notes the AI keeps so its suggestions fit how you actually work. Written in plain sentences you can read, not an opaque profile. You can see every item and delete any of them at any time, and deleting one removes it outright rather than hiding it. | Only when you use an AI feature |
| Sign-in sessions | sessions |
Keep you signed in between page loads, and let you see and end your other sessions. Each session records the browser it was started from and when it was last used, so you can recognise it on the sign-in security page. The IP address is stored only as a salted hash, never in the clear. | Never |
| AI usage records | ai_usage |
Enforce fair-usage limits and let you see what AI has been used on your account. This records THAT a feature ran and how many tokens it used. It never stores the prompt or the response. | Never |
| Workspaces | organizations |
Group a small team so they can plan against shared goals. A workspace holds a name and a seat count. It does not give anyone access to private goals - only to goals that have been deliberately shared with it. | Never |
| Workspace membership | memberships |
Record who belongs to a workspace and what they are allowed to do in it. An invitation stores the email address it was sent to. Invitation tokens are stored one-way, so the stored value cannot be used to accept an invitation. | Never |
| Tags | tags |
Let you group goals, tasks, habits and notes by your own labels. Tag names are written by you, so they are treated as your content. They are not included in AI prompts. | Never |
| Two-factor recovery codes | recovery_codes |
Let you back into your account if you lose your authenticator app. Stored one-way exactly like a password, so nobody here can read them. They are shown to you once, when they are created. | Never |
| Calendar connection | calendar_connections |
Show your existing meetings alongside your plan for the day. Read-only. We ask only for permission to read events and never write to, move or delete anything in your calendar. The access tokens are encrypted before they are stored. | Never |
| Calendar events | calendar_events |
Hold a local copy of your upcoming events so the day view loads without contacting your calendar provider every time. We copy the title and the times. Attendees, locations, attachments and descriptions are never requested or stored. Event titles are never sent to the AI provider. | Never |
| Weekly reviews | weekly_reviews |
Keep what you wrote in your weekly review so you can look back on it. The weekly review works entirely without AI. Nothing you write in it is sent to the AI provider. | Never |
| Templates you saved | goal_templates |
Keep a plan you have already built so you can start the same shape of work again. A template is a copy taken at the moment you saved it. Changing the goal it came from does not change the template, and deleting that goal does not remove it. | Never |
| Read-only share links | goal_shares |
Let you show one goal to somebody who has no account, without giving them access to anything else. The link is stored one-way, so the full address exists only in the copy you were shown. Anyone holding it can read that one goal and nothing else, and they can never change it. Revoking takes effect immediately. | Never |
| Passkeys | passkeys |
Sign you in using the fingerprint, face or screen lock on your own device. Only the public half of the key is here. The private half never leaves your device and cannot be read by us, by this application, or by anyone who obtains this database. | Never |
| Cancellation feedback | cancellation_feedback |
Understand why people stop paying, so the product can be improved. Answering is optional and you can skip it. Only counts by reason are ever shown on the internal dashboard - never your text, and never your name against an answer. | Never |
| Security audit log | audit_log |
Detect and investigate unauthorised access to your account. IP addresses are stored only as a salted hash, never in the clear. Records security events (sign-in, sign-out, password change, data export, account deletion) - never the content of your data. | Never |
Everything else
| Category | What it is | Why we hold it | Sent to AI? |
|---|---|---|---|
| Display and accessibility preferences | user_preferences |
Remember your language, theme, text size and other comfort settings. | Never |
| AI feature preferences | ai_preferences |
Remember which AI features you have turned on or off. | Never |
| Tag assignments | taggings |
Record which tag is attached to which item. | Never |
2. Why we store it
Each purpose above is the only thing we use that data for. We do not sell it, we do not share it with advertisers, and we do not build profiles for anyone else. Data is collected because a feature needs it, not in case it is useful later.
Where we rely on your consent - the AI features - you can withdraw it at any time, and withdrawing it stops the processing rather than merely hiding it in the interface.
3. What the AI features see
AI is optional. With it switched off, nothing you write ever leaves our systems for a model provider. With it on, only the categories below can be sent, and only while you are actively using the relevant feature.
- Goals and milestones - Store the goals you create so the app can plan around them and show progress.
- Milestones - Break a goal into checkpoints so progress is measurable.
- Tasks - Track the individual actions that move a goal forward.
- Habits and check-ins - Track recurring behaviours you want to build, and how consistently you keep them.
- Notes and journal entries - Store the notes and reflections you write.
- What the AI remembers about you - Hold short, readable notes the AI keeps so its suggestions fit how you actually work.
The full breakdown of which feature sends what is on the How we use AI page.
4. How long we keep it
| Category | Retention |
|---|---|
| Account details | Kept while your account is open. Deleting your account removes it immediately. |
| Linked sign-in accounts | Kept until you unlink the provider or delete your account. |
| Goals and milestones | Kept until you delete the goal or your account. |
| Milestones | Kept until you delete the milestone, its goal, or your account. |
| Tasks | Kept until you delete the task or your account. |
| Habits and check-ins | Kept until you delete the habit or your account. |
| Habit completion history | Kept until you delete the habit or your account. |
| Notes and journal entries | Kept until you delete the entry or your account. |
| Subscription | Kept while your account is open, then removed with it. |
| Referrals | Kept while either account is open. |
| Display and accessibility preferences | Kept while your account is open. |
| What the AI remembers about you | Kept until you forget an item or delete your account. Nothing here is permanent. |
| Sign-in sessions | Expires 14 days after your last activity, or immediately when you sign out. |
| AI feature preferences | Kept while your account is open. |
| AI usage records | Kept for 90 days, then deleted automatically. |
| Workspaces | Kept until the owner deletes the workspace or their account. |
| Workspace membership | Kept until the membership is removed, or the workspace or account is deleted. |
| Tags | Kept until you delete the tag or your account. |
| Tag assignments | Removed when either the tag or the item it points at is deleted. |
| Two-factor recovery codes | Kept until used, regenerated, or your account is deleted. |
| Calendar connection | Kept until you disconnect the calendar or delete your account. Disconnecting deletes the stored tokens immediately. |
| Calendar events | Only the next 30 days are stored. Deleted as soon as you disconnect the calendar. |
| Weekly reviews | Kept until you delete the review or your account. |
| Templates you saved | Kept until you delete the template or your account. |
| Read-only share links | Kept until you revoke the link or delete the goal or your account. |
| Passkeys | Kept until you remove the passkey or delete your account. |
| Cancellation feedback | Kept until you delete your account. |
| Security audit log | Kept for 365 days, then deleted automatically. |
5. Who else sees it
These are every third party involved in running Near Pace.
Microsoft Azure
Role: Hosting, database, secret storage and logging
Region: Canada Central
Receives: All data you store, at rest in the database and in application logs.
Azure OpenAI Service
Role: Generates AI suggestions and recommendations
Region: Canada Central, with an individual request possibly handled in another region
Receives: Only the specific content listed against each AI feature, and only when you use that feature with AI enabled.
Runs inside our own Azure tenant, and content is not used to train the underlying models or kept by them afterwards. The service is ours in Canada Central, but the model runs on the provider's global capacity, so a single request may be handled in another region and the answer returned here. Nothing is stored outside Canada. If you would rather no content left the country at all, every AI feature can be switched off in Settings and the rest of the product works exactly the same.
Role: Optional sign-in provider
Region: Global
Receives: Only involved if you choose "Continue with Google". Google tells us your account identifier, name and email address; we tell Google nothing about what you do here.
We request the basic profile and email scopes only - never access to your mail, files or calendar. Your Google password is never seen by us.
Microsoft
Role: Optional sign-in provider
Region: Global
Receives: Only involved if you choose "Continue with Microsoft". Microsoft tells us your account identifier, name and email address; we tell Microsoft nothing about what you do here.
We request the OpenID profile and email scopes only - never access to your mail, files or calendar. Your Microsoft password is never seen by us.
6. Cookies
Near Pace sets 2 cookies, both strictly necessary. There are no analytics, advertising or tracking cookies, which is why there is no consent banner to dismiss.
| Name | Category | Purpose | Duration |
|---|---|---|---|
tl.sid |
strictly-necessary | Keeps you signed in. | 14 days, or until you sign out. |
tl.csrf |
strictly-necessary | Protects forms against cross-site request forgery. | Session only. |
7. What our staff can see
Near Pace has an administrator account used to run the service. Being specific about it is more useful than a vague reassurance, so here is exactly where the line sits.
An administrator can see
- Total number of accounts, and how many were created recently.
- Your email address, display name, and when you signed up and last signed in.
- Whether AI is switched on for your account, and which sign-in method you use.
- Counts of how many goals, tasks, habits and notes exist - numbers only.
- Aggregate AI usage: how many times each feature ran across the service.
- System health, error rates and security events such as failed sign-ins.
An administrator cannot see
- The content of your goals, milestones, tasks, habits, notes or journal entries.
- Anything you typed into an AI feature, or anything it replied.
- Your password - it is stored only as a hash, and administrators cannot reverse or read it.
- Your Google or Microsoft account beyond the email address you signed in with.
This is not a policy promise layered over a system that could do otherwise. The administration screen is built only from aggregate counts and account metadata, and the test suite fails the build if any query behind it reads a content column.
8. Your rights
Each of these is a working feature, not a request you have to email us about.
- Access and portability - Download everything on your account as JSON. /app/settings/export
- Correction - Edit any goal, task, habit or note directly in the app. /app
- Erasure - Delete your account. Every row above is removed immediately. /app/settings
- Withdraw AI consent - Turn AI off entirely, or per feature, at any time. /app/settings/ai
- See and delete what AI remembers - Read every note the AI keeps about you and forget any of them. /app/settings/memory
- End other sessions - Sign out of every other device at once. /app/settings
Deleting your account removes every row in the table above immediately. There is no grace period during which we quietly retain it.
9. How we protect it
- Passwords are stored one-way, using a deliberately slow method. Nobody here can read or recover yours.
- You can sign in with Google or Microsoft instead of a password, and we never see that password either.
- Everything you send travels over an encrypted connection, and your data is encrypted where it is stored.
- Your data is scoped to your account on every single request, so one account cannot reach another.
- Repeated failed sign-in attempts are slowed down and recorded.
- You can turn on two-factor authentication, so your password alone is not enough to sign in.
- You can see every device you are signed in on, and end any of them individually or all at once.
- Secrets that have to be readable again - your two-factor key and any calendar tokens - are encrypted before they are stored, so reading the database alone does not make them usable.
- A goal is only visible to a workspace if you deliberately share it. Notes, journal entries, habits and unshared goals are never shared with anyone.
- Access to production systems is limited, logged, and reviewed.
- Where our security records need your IP address, it is stored scrambled rather than in the clear.
Your data is stored in Canada, and everything the product does with it happens there - with one exception, which is worth stating plainly rather than burying. When you use an AI feature, the content that feature sends is handled by our AI provider in Canada or another region, wherever the provider has capacity at the time. Nothing is stored outside Canada; the answer comes back and the copy sent for processing is not kept. AI is off unless you turn it on, and switching it off in Settings means nothing leaves Canada at all.
No system is perfectly secure; if a breach affected your personal data we would tell you and the relevant regulator within the statutory deadline.
10. Contact
Questions about this policy go through the info@kwistech.ca. If you are not satisfied with our response, you can complain to your local data protection authority.