Privacy Policy
Effective date: August 30, 2026
Last updated: August 30, 2026
This Privacy Policy explains how Kaushal Jha (“we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Ensora mobile application (the “App”). We built Ensora to respect your privacy: we collect only what the App needs to work, we do not sell your data, and we do not use it for advertising.
If you have questions about this policy, contact us at support@getensora.com.
1. Summary
- We collect the account information needed to sign you in (email, and — if you use Google or Apple sign-in — your name).
- Your content (tasks, categories, journal reflections, closing-ritual entries, and settings) is stored in our database so it can sync across your devices, and is also cached on your device.
- We use one privacy-conscious analytics service (PostHog) that receives usage metadata only — never the text of your tasks, notes, or reflections.
- We do not use any AI or machine-learning service, and we never send your content to any AI/LLM provider.
- We do not collect crash logs, we do not show ads, we do not use tracking for advertising, and we do not sell your data.
- We do not access your location, contacts, photos, camera, or microphone.
2. Information We Collect
2.1 Account information (required to sign in)
Authentication is handled by Supabase Auth. Depending on how you sign in, we collect:
- Email/password sign-up: your email address, and a password. Your password is hashed and stored by Supabase Auth; we never see or store your plaintext password.
- Sign in with Google: your email address, name, and profile picture URL, as provided by Google. We display your name and picture, but we do not upload, copy, or store your profile picture — the App simply renders the image hosted by Google. We do not receive a password.
- Sign in with Apple: your email address and, on your first sign-in only, your name, as provided by Apple. If you choose Apple’s “Hide My Email” feature, we only receive Apple’s private relay email address. We do not receive a password.
If you sign up with email/password and provide no name, the App shows a default display name.
2.2 Content you create in the App
When you use Ensora, you create content that we store in our database (hosted on Supabase, running on Amazon Web Services) so it can sync across your devices. This includes:
- Tasks and subtasks — title, description, category, category color, duration, scheduled time, completion time, reminder time, tags, repeat rules, sort order, and calendar-mirror metadata.
- Categories — name and color.
- Reflections (journal) — the free text you write and a “favorite” flag.
- Closing-ritual entries — mood, an optional reflection note, task counts, and hours worked/planned.
- Profile and settings — your closing time, daily capacity, focus hours, reminder preferences, hard-stop setting, subscription status, and the identifier and name of any Apple calendar you choose to connect.
Each record is associated with your user ID and is protected by database Row-Level Security, so only you can access your own data. This content is also cached on your device (using local storage) so the App works offline; changes sync when you reconnect.
2.3 Calendar data (read-only, mostly on-device)
If you grant calendar access, the App reads events from your device’s calendar on the device to display them alongside your tasks and to let you “mirror” an event.
- The App reads calendar events; it does not create, edit, or delete events in your calendar.
- Raw calendar events are not sent to our servers.
- When you choose to “mirror” an event, the App creates an independent copy as a task (title, notes, and times) in your account. The original calendar event is never modified. Once mirrored, that task is stored like any other task (see §2.2).
2.4 Usage analytics (metadata only)
We use PostHog (US cloud) to understand how the App is used so we can improve it. Analytics events contain metadata only — for example, that a task was created (with its category and whether it had a reminder), that the timer was started, or that the paywall was viewed. Analytics events never include the text of your tasks, notes, reflections, or any other content you write.
We associate analytics with your account using your Supabase user ID (a random identifier) plus a small set of technical properties such as platform, app version, and whether you have an active subscription. We do not send your email or name to PostHog. Autocapture of taps and screens and session replay are not enabled.
2.5 Subscription information
If you purchase Ensora Pro, the transaction is processed by Apple through the App Store using StoreKit, and managed on our side by RevenueCat. We (and RevenueCat) receive your subscription status and entitlement so we can unlock Pro features. We never receive your full payment card details — Apple handles billing. See §5.
2.6 What we do NOT collect
We do not collect or use:
- Location, contacts, photos, camera, or microphone data (there is no in-app photo, avatar, or camera feature on iOS).
- Crash logs or crash-reporting data (no crash-reporting SDK is installed).
- Advertising identifiers, and we do not use any advertising or ad-tracking SDKs.
- Any data for AI or machine-learning processing (see §4).
- Remote push notification device tokens (the App uses local notifications only — see §6).
3. How We Use Information
We use the information above only to:
- Create and secure your account and sign you in.
- Store, sync, and display your tasks, categories, reflections, closing-ritual entries, and settings across your devices.
- Display your device calendar events and support the mirror-to-task feature.
- Send local notifications you enable (reminders and timer alarms) from your device.
- Provide and manage Ensora Pro subscriptions and unlock Pro features.
- Understand aggregate product usage and improve the App (via metadata-only analytics).
- Prevent abuse, debug problems, and comply with legal obligations.
We do not use your information for advertising, and we do not sell or rent it.
4. Artificial Intelligence
Ensora does not use artificial intelligence. Despite the App’s name, no AI or machine-learning SDK is installed, no model or LLM API is called, and no prompts exist. All scheduling and suggestion logic is ordinary deterministic code that runs on your device. Your tasks, notes, and reflections are never sent to any AI or LLM service (such as OpenAI, Anthropic, or Google) for processing.
5. Subscriptions and In-App Purchases
Ensora offers an optional Ensora Pro subscription, sold as an auto-renewing in-app subscription through the Apple App Store. Billing is handled by Apple; entitlements are managed through RevenueCat.
- Pricing, currency, and any free-trial length are shown to you in the App and on the App Store confirmation screen before you buy, and may vary by region.
- Subscriptions auto-renew unless you cancel at least 24 hours before the end of the current period.
- You can manage or cancel your subscription any time in your Apple ID Settings → Subscriptions. Deleting the App does not cancel a subscription.
- Payment is charged to your Apple ID account at confirmation of purchase.
For billing terms, see the Terms of Use and Apple’s Standard EULA.
6. Notifications
Ensora uses local notifications only — reminders and timer alarms are scheduled by your device. The App does not use remote/push notifications; no push notification token is collected or sent to any server. You can disable notifications any time in iOS Settings.
7. Third-Party Services (Sub-processors)
We share data with the following service providers only as needed to operate the App:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, database, and session storage (our primary data processor; runs on AWS, region ap-northeast-2 (Seoul)) | Account info and your content (§2.1–§2.2) |
| “Sign in with Google” (via Supabase OAuth) | Email, name, profile picture URL | |
| Apple | “Sign in with Apple,” App Store billing, and iOS system services | Email and (first sign-in only) name; subscription/payment |
| RevenueCat | Subscription and entitlement management on top of Apple StoreKit | Subscription status, a subscription identifier, technical metadata |
| PostHog (US cloud) | Product usage analytics | Usage metadata and a random user ID (no content, no email/name) |
We do not use Firebase, Sentry, or any other crash reporter; any AI/LLM provider; or any advertising SDK.
8. Data Storage, Retention, and Deletion
Storage. Your account and content are stored on our database provider (Supabase) and cached locally on your device. Data in transit is protected by encryption (HTTPS/TLS), and access to your records is restricted by Row-Level Security so only your account can read them.
Retention. We keep your account and content for as long as your account is active. When you delete content in the App, it is first marked as deleted (a “soft delete”) so the change can sync reliably across your devices, and is then removed on our normal reconciliation cycle.
Deleting your account. You can delete your account from Profile → Delete Account in the App. When you do:
- Your profile and associated content are marked for deletion and removed from the App, and you are signed out on all devices.
- We retain a minimal record of the email address associated with the deleted account to prevent abuse of the sign-up process. You may request removal of this record by contacting support@getensora.com.
If you would like us to expedite full erasure of your data, or need help, contact support@getensora.com and we will act on your request.
9. Your Rights
Depending on where you live (for example, under the EU/UK GDPR or the California CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Ensora lets you:
- Access and edit your content directly in the App.
- Delete your account and content from within the App (§8).
To exercise any other right — including a copy/export of your data — email us at support@getensora.com and we will respond as required by applicable law. We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising.
10. Children’s Privacy
Ensora is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact support@getensora.com and we will delete it.
11. International Users
We operate the App from India and use service providers that may store and process data in the United States and other countries. By using the App, you understand your information may be transferred to and processed in countries with different data-protection laws than your own. Where required, we rely on appropriate safeguards for such transfers.
12. Security
We use industry-standard measures — encryption in transit, hashed passwords, and per-user access controls — to protect your information. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security, but we work to protect your data and to promptly address any issues.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the App. Your continued use of the App after an update means you accept the revised policy.
14. Contact Us
If you have any questions about this Privacy Policy or your data, contact us at:
Kaushal Jha
Email: support@getensora.com