Privacy policy.
What we collect, why, who else processes it, how long it stays and what you can do about it. Written to describe what the product actually does rather than what a template says. Last updated August 1, 2026.
Your workspace lives in your browser first. If you sign in with Google it syncs to our database so it works across devices. We do not sell it, do not use it for advertising, and do not train any AI on it. Export or delete everything yourself at any time.
Who is responsible
PomoZentra is operated by Nozentra, an independent product studio, which is the controller of personal data described here. Contact: info@pomozentra.com.
What this covers
The website at pomozentra.com, the application at app.pomozentra.com, and the emails we send you about the product. It does not cover other companies' sites we link to.
What we collect
Information you give us
| Data | When | Why |
|---|---|---|
| Name, email address and profile picture from your Google account | When you sign in | To create and identify your account |
| Your workspace: work area names, weekly plans, task titles, logged blocks, the yes/partly/no answers, optional outputs and notes | As you use the product | It is the product. Without it there is nothing to show you |
| Settings, including timer lengths, goals and preferences | As you change them | To make the app behave as you configured it |
| Feedback you submit in the app, which may include an optional voice recording, screen recording or screenshot that you choose to attach | Only when you submit feedback | To understand and reproduce the problem you are reporting |
| Your email address if you join the launch or blog mailing list | Only when you submit the form | To send the message you asked for |
| Anything you write to us by email or through the contact form | When you contact us | To answer you |
The contact form on this site does not transmit anything by itself. It opens a draft in your own email application, so the message reaches us as an ordinary email from your address.
Information collected automatically
- Product analytics in the app. Page views and feature usage counts, so we can see which parts of the loop people actually use. Session replay is deliberately switched off, so your screen is never recorded by analytics.
- Error reports. When something breaks, a report including the error, the browser type and the page it happened on.
- Server and delivery logs. Standard request logs kept by our hosting provider, including IP address, for security and reliability.
The marketing pages you are reading now carry no analytics or advertising scripts at all.
What we do not do
- We do not sell your data, and we do not share it with advertisers.
- We do not use your task titles, notes or logs for advertising or profiling.
- There is no AI feature in the product. Your content is not sent to an AI provider and no model is trained on it. If that ever changes it will be announced before it happens, not buried in an update to this page.
- We do not read your workspace except where you have asked us to look at something, or where it is unavoidable while fixing a fault you reported.
Why we are allowed to process it
Where data protection law of the kind that applies in the UK and EU is relevant, our bases are: performance of a contract for everything needed to run the account and the product; consent for the mailing list and for optional feedback recordings, both of which are entirely voluntary and withdrawable; and legitimate interests for security, fraud prevention, error monitoring, and understanding aggregate product usage so we can improve it.
Who else processes it
These are the only third parties that receive any of it, and each gets only what it needs for that job.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database, authentication and file storage | Account identity and your synced workspace, plus feedback attachments |
| Sign-in | The authentication exchange. Google tells us your name, email and profile picture | |
| Cloudflare | Hosting and delivery | Request data including IP address |
| Sentry | Error monitoring | Error reports and technical context |
| PostHog | Product analytics in the app | Usage events, no session recordings |
| Resend | Transactional email | Your email address and the message content |
These providers operate internationally, so your data may be processed outside your country, including in the United States. We rely on the transfer protections each provider offers in its own terms.
How long it is kept
- Your workspace: until you delete it. There is no automatic expiry.
- Your account: until you delete it, or until you ask us to remove the sign-in record.
- Feedback and attachments: until you ask us to remove them.
- Mailing list: until you unsubscribe.
- Error reports, analytics and server logs: retained on each provider's own schedule and not kept indefinitely by us.
- Backups: our database provider keeps rolling backups, so a residual copy of deleted data may persist there for a limited period before it rotates out.
Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, take it elsewhere, object to certain processing, or withdraw consent. Two of those are self-serve and do not require asking us:
- Export: Settings has CSV and JSON export of everything, at any time.
- Delete: Settings deletes your workspace and signs you out. The data deletion page explains exactly what that removes and the one step that still needs a person.
For anything else, email info@pomozentra.com. If you are unhappy with how we have handled a privacy request you can also complain to your local data protection authority.
Cookies and browser storage
The marketing site sets no analytics or advertising cookies. The app uses browser storage to hold your workspace locally and to keep you signed in. The cookie policy lists everything, including what it is for and how long it lasts.
Security
Traffic runs over HTTPS, and your workspace sits in a managed database with row-level security so an account can only reach its own row. We hold no security certifications and do not claim your data is completely secure. The security page describes what is actually in place and how to report a vulnerability.
Children
PomoZentra is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
Marketing
Contacting us does not add you to any mailing list. The only emails you receive without asking are two product emails tied to your account, a short welcome and a week-one summary, and both can be switched off in Settings.
Changes to this policy
When something meaningful changes we will update this page, change the date at the top, and note it on the changelog. For a change that materially affects how your data is used, we will tell you directly rather than relying on you re-reading this page.
Contact
Questions, requests or complaints about privacy: info@pomozentra.com.
This policy is written in plain language to describe what the product genuinely does. It is not legal advice, and it will be reviewed by a qualified professional before PomoZentra takes on business customers or leaves early access.