← Back to Horizon OS

Privacy Policy

Horizon OS — Last updated: October 1, 2026 · Effective date: September 17, 2026

Before we start

This policy exists to tell you, plainly and honestly, what data Horizon OS collects, why, and what we do with it. We wrote it to be read, not to bury things in legal jargon.

The short version: we use your data to run the app and make it better. We never sell it, share it for advertising, or use it to train AI models.

Everything below describes the app as it actually works today. Where a practice is less flattering than it could be — that a developer can see your content while running a database query, that all your data sits in the United States — we say so rather than leave it out.

If you’re in the EU or UK, we also explain your GDPR rights at the bottom. They’re real rights that we take seriously.

Who we are

Horizon OS is a personal life operating system — a PWA (Progressive Web App) for todos, habits, journaling, money tracking, a vision board, Google Calendar sync, and an AI coach. It is built and operated by:

Under GDPR, we are the data controller — the party responsible for deciding how and why your personal data is processed. If you have any questions or requests about your data, contact us directly at the email above. If Horizon OS is later incorporated as a company, we will update this section and tell you.

One exception: if you buy a subscription, Paddle is the seller and the controller of your payment data, not us. See “Payments” below.


What data we collect and why

1. Account and authentication

What: You sign in with Google, or with an email address and a password. With Google we receive your email address, your name, your Google profile picture URL, and a unique user ID; with email we receive your email address and store only a hash of your password, never the password itself. Supabase Auth stores the account record and issues your session token.

Bot check: When you sign in, sign up or reset your password with email, a Cloudflare Turnstile check runs to keep automated sign-ups out. Cloudflare receives your IP address, your browser’s user-agent and a TLS fingerprint for that check. It is used to tell people from bots, not for advertising or to profile you. Usually you see nothing; occasionally it asks you to tick a box. Google sign-in does not use it.

Why: To let you log in and keep your data associated with your account.

Legal basis (GDPR): Performance of a contract — you cannot use the app without an account.

2. Your personal content

What: Everything you create inside the app — todos, habits, rituals, journal entries, gratitude notes, energy and mood check-ins, money transactions, vision board items, coach conversation history, and your app settings. All of it is stored as a single record per user in our database.

Why: This is the core purpose of the app. We store it so you can reach it across devices and sessions.

Legal basis (GDPR): Performance of a contract.

Do we read it? Here is the honest answer, because the honest answer is not “no”.

Sensitive content. Journal entries, mood check-ins and financial data are more personal than the rest. They are encrypted in transit and encrypted at rest in our database provider’s infrastructure, and they are covered by everything above.

3. The AI coach

What: When you talk to the AI coach, your message and a summary assembled by the app are sent to Anthropic’s Claude API to generate a reply. The summary can include: your name, focus areas and vision; today’s to-dos, routine, non-negotiables, habits and energy check-in; a one-line summary of each of the last 7 days; your streak and training count; recent wins; short excerpts of your recent journal entries; and the titles and times of your calendar events (Horizon OS and Google Calendar) for today and the next two days. It is sent only to generate the reply you asked for. The conversation is stored with the rest of your data so the coach can remember context.

Why: To power the coaching feature. Without sending your messages, it cannot work.

Legal basis (GDPR): Performance of a contract — you opt in by using the feature.

Who receives it:

Voice input on other devices. On Chrome, Android and desktop browsers, transcription is done by the speech recognition built into your browser (the Web Speech API) — not by Horizon OS and not by Deepgram. On Chrome and most Chromium browsers this means your audio is sent to Google’s speech servers, under Google’s terms with you.

You are told you are talking to an AI. The coach is labelled “AI coach” wherever it appears, and the first line of every conversation says so. If you ask whether it is a person, it says it is an AI.

4. Google Calendar sync

What: If you connect Google Calendar, we ask for OAuth permission to read and write your calendar events. Your refresh token is stored server-side in a table that only our server can read — never in your browser’s storage. We read events to display them and write events you create from the app.

Why: To sync your calendar with Horizon OS’s planning features.

Legal basis (GDPR): Your explicit consent, given in the Google authorization screen.

Who receives it: Google, in requests our server makes on your behalf. Your calendar data goes to no other third party. You can revoke access at any time from your Google Account permissions page. Google’s privacy policy

Google API Services User Data Policy — Limited Use. Horizon OS’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

5. We do not collect usage analytics

Horizon OS has no analytics. There is no Google Analytics, no Plausible, no PostHog, no Vercel Analytics, no Facebook Pixel, no advertising SDK, and no event log of any kind — not even our own. Nothing records which screens you open, which buttons you press, or how long you spend anywhere.

We know which features get used the way described in section 2: by querying the database directly, occasionally, by hand.

The one automatic counter we do keep is a daily count of AI coach and voice calls per account, stored as a number per user per day per endpoint. It exists to enforce per-day usage limits so a single account cannot run up an unbounded bill, and it records only how many calls were made — never what was said. If we ever add real analytics, we will add a section here and tell you before it starts.

6. Beta access applications (closed)

What: The invite-only beta ended on October 1, 2026; new accounts no longer apply. For people who applied during the beta we still hold your email address, your display name, your written answer to why you want to use Horizon OS, your application status, when you last signed in, and how many times you have signed in. If you send us written feedback, we store that too.

Why: To decide who gets into a limited beta, and to know whether people who were let in are actually using it.

Legal basis (GDPR): Performance of a contract (steps taken at your request before entering one), and our legitimate interest in running a limited beta.

7. Support messages

What: If you send a bug report or feedback from inside the app, we store your email address, the type of report, its title and your description of the problem, and we send ourselves an email copy.

Why: To answer you and fix what you reported.

Legal basis (GDPR): Legitimate interest in supporting our own product.

8. Payments

Status: paid subscriptions are live. Everything below describes what happens today, not what is planned.

What: Horizon OS uses Paddle as its merchant of record. That means Paddle — not us — is the legal seller of any subscription, and Paddle is the controller of your payment data. Your card number, billing address and tax details are entered on Paddle’s checkout and go to Paddle. We never see or store your card details. What we receive back from Paddle is limited to what we need to run your account: your subscription’s status, plan, renewal date, and the email address associated with it.

Why: To sell subscriptions without handling card data ourselves, and to know whether your account is on a paid plan.

Legal basis (GDPR): Performance of a contract, and compliance with tax and accounting law for the records Paddle keeps.

Who receives it: Paddle, and the payment networks and tax authorities Paddle is obliged to deal with. Paddle’s privacy policy. Horizon OS uses no other payment processor.

9. Emails we send you

What: We send transactional emails — account confirmation and password-reset links, a welcome email when you create an account, payment receipts (sent by Paddle), and replies about support tickets. We also send one re-engagement email if your account goes quiet for about a week: a short note asking whether you want to keep going.

For the re-engagement email we store, per account: a random unsubscribe token, whether you have unsubscribed, when we last sent one, and how many we have sent. The token is a random 256-bit string that exists only so an unsubscribe link can work without you logging in — it identifies nothing about you, is never shown to anyone but you, and does exactly one thing: stops the emails.

Why: To operate your account, and — for the quiet-week note — a genuine interest in reminding someone who set up a habits app that it is still there.

Legal basis (GDPR): Performance of a contract for transactional email; legitimate interest for the re-engagement note, which you can stop at any time.

How to stop it: Every re-engagement email has an unsubscribe link. One click and we never send another. It never affects transactional email about your own account.

Who receives it: Resend, our email delivery provider, receives your email address, your name if we use it, and the message text. Resend’s privacy policy

10. Error reports

What: When the app crashes or cannot save your data, it sends us a report so the failure is not invisible. Two kinds:

The IP address part, stated plainly. Boot reports come from browsers we cannot identify, so to stop the endpoint being abused we rate-limit by IP address. We do not store your IP address. We store a salted SHA-256 hash of it, with a count, in a rate-limit table. Because we keep the salt, that hash is pseudonymised personal data under GDPR, not anonymous data — someone holding both the salt and a candidate IP address could confirm a match. It is not linked to your account, it is never used for anything but counting, and the rows are cleared periodically.

Why: To find out about failures that would otherwise leave a person with a broken app and us with no idea.

Legal basis (GDPR): Legitimate interest in a working, debuggable service.

11. Backups

What: The app keeps automatic backups of your data — a full copy of your app state, stored as a separate row with a timestamp, so a bad sync or a mistaken deletion can be undone. Several recent copies are kept per account and older ones are pruned. You can also download a backup file yourself, and restore from one, in Settings.

Why: So that losing your data is recoverable.

Legal basis (GDPR): Legitimate interest in not losing your work, which is also plainly in your interest.

Note: backups contain the same personal content as section 2, and are deleted when your account is deleted.

12. Currency exchange rates

What: If you set a secondary currency in the money tracker, your browser fetches exchange rates from open.er-api.com, a free public rates API. The request contains a currency code and nothing else — no account identifier and none of your financial data. Like any web request, it necessarily reveals your IP address to that service.

Why: To show your spending in a second currency.

Legal basis (GDPR): Performance of a contract — it happens only if you turn the feature on.

13. Technical and infrastructure data

What: Vercel, our hosting provider, logs standard server-side request metadata — method, path, response time, status code, and the IP address the request came from — as any web host does. We do not build anything from these logs; they exist for reliability and abuse prevention and expire on Vercel’s own schedule.

Why: To keep the app running and to debug server errors.

Legal basis (GDPR): Legitimate interest in maintaining a functioning service.

Vercel’s privacy policy


Cookies and local storage

Cookies: Horizon OS sets no tracking cookies of any kind. There is no advertising tag, no pixel, and no third-party cookie.

Your login session is kept by Supabase Auth in your browser’s localStorage, not in a cookie. It is strictly necessary — it is what keeps you signed in — and you cannot opt out of it and continue using the app.

Other local storage: the app stores a handful of your own preferences on your device (phone-mode display setting, font size, whether you dismissed a tip, auto-backup timing). These never leave your device.

Offline cache: Horizon OS is an installable app with a service worker, which caches the app’s own files so it starts without a connection. It caches program files, not a second copy of your personal data for anyone else to read.

Do we need a cookie consent banner? No. Our only stored identifier is the strictly-necessary login session, and we run no analytics and no cookie-based tracking, so nothing here requires consent under the ePrivacy Directive.

Data we do NOT collect

To be explicit:

Who we share data with

We share data only with the providers needed to operate the app. All act as processors on our instructions, except Paddle, which is a separate controller for payment data, and your browser vendor, which is not our provider at all.

ProviderPurposeData sharedRole
SupabaseDatabase, authentication, backupsAll account data and app contentProcessor (DPA)
VercelHosting, serverless functionsRequest logs incl. IPProcessor (DPA)
AnthropicAI coach repliesCoach messages + context (day summary, journal excerpts, calendar titles)Processor (commercial API terms; no training)
YouTube (Google)Practice-library videos and thumbnails; the demo video on our home pageYour IP address and browser details when a video or thumbnail loads (embedded in privacy-enhanced mode)Their controller relationship with you
DeepgramSpoken coach replies; voice-to-text on iPhone/iPadText of the coach’s reply; short voice recordings while you use the microphone (not stored)Processor (DPA)
Cloudflare (Turnstile)Bot check on email sign-in, sign-up and password resetIP address, browser user-agent, TLS fingerprint during the checkProcessor for the check; controller for improving its bot detection
GoogleCalendar sync, Google Sign-InCalendar events, account identityProcessor / OAuth
ResendSending emailEmail address, name, messageProcessor (DPA)
PaddleSelling subscriptions (merchant of record)Card and billing details (direct to Paddle), subscription statusIndependent controller
open.er-api.comCurrency ratesA currency code, plus the IP any request carriesThird-party service, no personal data sent
Your browser’s maker (Google)Voice-to-text in the coach on Chrome / Android / desktopMicrophone audio during an active voice sessionTheir controller relationship with you, not ours

We do not give data to law enforcement except under a valid legal order, and we will tell you if we are permitted to.

Where your data is stored

All of it is in the United States. Horizon OS runs on a single database in Supabase’s US East (Ohio, us-east-2) region. There is no EU region and no region choice at signup.

Our other providers process in the US as well (Anthropic, Deepgram, Resend), and Vercel serves the app from its global edge network.

Data retention and deletion

We keep your data while your account exists.

Deleting your account deletes it. Settings → Danger Zone → Delete my account removes your authentication record, and everything keyed to it goes with it in the same operation, immediately rather than on a 30-day schedule: your app content, your backups, your beta application, your support tickets, your Google Calendar token, your error reports, your daily AI usage counters (section 5), and your re-engagement email record.

One thing is worth stating precisely:

Server logs held by Vercel expire on Vercel’s own retention schedule and are outside our direct control. We may keep records that tax or accounting law requires — for subscriptions, most of those records are Paddle’s, not ours.

Your rights

Wherever you are, you can:

If you’re in the EU, UK, or a country with equivalent law, you also have these rights under GDPR:

To exercise any of these: email support@horizon-os.app. We respond within 30 days and we don’t charge for reasonable requests.

Complaints: you can complain to your local data protection authority. In the EU, find yours via the EDPB; in the UK it’s the ICO.

For payment data, Paddle is the controller — a request about your card or billing details should go to Paddle, and we’ll point you there.

International data transfers

Your data is stored and processed in the United States (see above). If you are in the EU or UK, that is a transfer outside your jurisdiction, and it is covered by Standard Contractual Clauses in our agreements with each provider:

Children’s privacy

Horizon OS is not intended for anyone under 16. We do not knowingly collect data from children, and we do not currently verify age at signup. If you believe a child has created an account, contact us and we will delete it.

Security

We do not claim your content is technically unreadable by us — see section 2, where we say plainly who can see what.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority within 72 hours, as GDPR requires.

Changes to this policy

When this policy changes, we update the “Last updated” date at the top of this page. Please check it from time to time. We will not make a change that reduces your privacy without giving you the chance to export your data and delete your account first.

Contact us

Questions? Data requests? Something here doesn’t match what you see in the app?

If something in this policy is inaccurate, we want to know — the whole point of rewriting it was to make it match the software.