This policy describes how Othvane LLC ("TealDrop", "we") handles personal information, including as required by the California Online Privacy Protection Act, Washington's My Health My Data Act, the EU/UK GDPR and Brazil's LGPD. It is also written to align with India's Digital Personal Data Protection Act, 2023, whose substantive obligations take effect in May 2027. Contact for all privacy matters (including our LGPD encarregado, and our contact for questions or grievances about data processing under India's DPDP Act): legal@othvane.com.
Where your data is stored, and what that means in Brazil. Our servers are in the United States. If you tell us you are in Brazil, or your connection indicates Brazil, we ask separately at sign-up for your specific agreement to store your data there, because Brazil has not recognized the United States as offering an equivalent level of protection and Article 33 of the LGPD requires that agreement to be its own decision rather than part of accepting these terms. We record the date you gave it. You may withdraw it at any time by writing to legal@othvane.com, and we will tell you what your options are, including exporting and deleting everything we hold. We are also asking our hosting provider whether it will enter into the standard contractual clauses published by the ANPD; if it does, we will move to that basis and update this policy. Patterns, and why they never reach us. If you turn Patterns on in Settings, TealDrop looks at numbers you have already recorded in a single planner and works out, in your browser, whether they tend to move together. The result is shown to you and discarded when the screen closes. It is never written to our database, never sent to us, and never shared. We do not receive it, cannot see it, and keep no record of what any pattern said. The only thing stored is your choice to have the feature on, with the date you chose it, so we can show you the setting and evidence that you asked for it. Patterns are off until you switch them on, and switching them off stops the calculation entirely. EU and UK representatives. We are based in the United States. Under Article 27 of the GDPR and of the UK GDPR we have appointed Prighter Group, with its local partners, as our privacy representative and your point of contact for the European Union and the United Kingdom. Prighter gives you a direct way to exercise your privacy rights, such as asking for access to or erasure of your personal data. To contact us through our representative, or to make a data subject request, visit https://app.prighter.com/portal/13936242094. You can also always reach us directly at legal@othvane.com.
2. What we collect.
(a) Account data: email, name, password (hashed), language, preferences, and any logo image you upload to customize your planners. (b) Planner entries you log: e.g. habits, budgets, meals, workouts, mood, reading, goals, reminders you set. (c) Purchase data: payments are handled by Stripe; we store what you bought, never card numbers. If you unlock a planner with a redemption code, we store only that the code was used and which planner it unlocked. (d) Technical data: logs needed to run and secure the service. To warn you if someone else signs in as you, we also keep a short record of the devices your account has signed in from: an opaque code that identifies the browser, and a plain label such as Safari on iPhone. We do NOT store your IP address or your full browser details for this, and the code cannot be linked to you on any other account. You can see and remove these at any time by deleting your account, and they are deleted with it. (e) Analytics events (feature usage, page views) only if you accept analytics in the consent banner; we configure analytics so the CONTENT of your entries is never sent. (f) Diagnostic error reports: if the app malfunctions and you have accepted analytics, we receive the error message, a technical stack trace, and the page path where it happened (never the content of your entries) so we can find and fix bugs. We also receive automated uptime and error alerts about the service itself.
3. Why we use it.
To provide the service you request (store entries, render dashboards, generate PDFs, send the reminders and recap emails or push notifications you enable), process payments, provide support, secure the service, and—with consent—understand feature usage. The reminders, recaps, and push notifications you turn on are service messages tied to features you enabled; you can turn them off in Settings. If we ever send a marketing email it will include an unsubscribe link. We may use aggregated or de-identified data (which cannot identify you) to understand and improve the product. We do not sell personal information and do not share it for cross-context behavioral advertising.
4. The AI planning assistant.
When you use the AI assistant, the text you send is processed by Anthropic to generate a reply. You are interacting with an AI system, not a person. Anthropic processes these requests under contract as our processor and, under its commercial API terms, does not use your prompts or the replies to train its models by default. We do not use your planner content to train any AI model. We do not make automated decisions that produce legal or similarly significant effects about you. We do not keep what you send. Your prompt is assembled, sent to Anthropic, and the reply is returned to you; none of it is written to our database. The only record we keep is that a request happened — your account, which feature you used, and when — which we need to enforce usage limits, and which is deleted after seven days. Planners that can reveal health or wellbeing, meaning the ADHD, self-care, fitness and meal planners, are withheld from the AI entirely unless you switch that on in Settings; you can switch it off again at any time. Where the assistant recognises distress it will say plainly that it is an AI inside a planning app, not a therapist or a crisis service, and point you to findahelpline.com.
5. Consumer health data.
Some entries may relate to health or wellness: fitness logs, meals, water intake, mood, self-care, sleep notes. We collect these only because you type them in, use them only to show them back to you and power your dashboards, share them only with our hosting processor (Supabase) as needed to store them, and never sell them or use them for advertising. If you are in Washington State, our separate Consumer Health Data Privacy Policy sets this out in the form Washington law requires — open the Health Data tab. Nevada residents have similar protections. You may access, correct, export, or delete this data anytime in the app, or withdraw consent by deleting the entries or your account. To exercise rights or appeal a decision, email legal@othvane.com.
6. Cookies, local storage, and opt-out signals.
We use only what is needed to keep you signed in, remember your language and preferences, and — if you accept — run analytics. We do not use advertising cookies. Our analytics run only if you accept them in the consent banner, and declining counts as opting out. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of any sharing of your information.
7. Processors.
Supabase (database, auth, storage), Stripe (payments), Vercel (hosting), Resend (email), PostHog (consent-based analytics), Anthropic (AI assistant requests you send), Cloudflare (bot protection on our forms). Each processes data under contract for us and only on our instructions.
8. How we protect your data.
Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. Database access is restricted per account so you can only reach your own records. Passwords are stored hashed, never in plain text, and you can turn on two-factor authentication in Settings. If your account is signed in on a device we do not recognise, we email you so you can react if it was not you; because this is a security notice rather than marketing, it cannot be switched off. Access is limited to the founder and the processors listed above, on a need-to-know basis. No system is perfectly secure, but we take reasonable steps to protect your information.
9. International transfers.
Data is processed in the United States. Where GDPR/UK GDPR applies, transfers rely on our processors' Standard Contractual Clauses. Legal bases: contract (Art. 6(1)(b)) for the service; consent (6(1)(a)) for analytics and for any health-related entries; legitimate interests (6(1)(f)) for security, including the device records and sign-in alerts described in section 1(d).
10. Retention.
Account data and entries are kept while your account exists and deleted when you delete your account (backups purge on rotation, within 30 days).
11. Your rights.
Depending on where you live (California, EU/UK, Brazil, India, and others): access, correction, deletion, portability, restriction, objection, and the right not to be discriminated against. In-app: Settings → Export my data, and Settings → Delete account. Anything else: email legal@othvane.com; we respond within the time your law requires (generally 30–45 days). You may also complain to your local supervisory authority. California Shine the Light: we do not share personal information with third parties for their own direct marketing, so there is nothing to report, but you can ask at legal@othvane.com.
12. If the business changes hands.
If Othvane LLC is ever sold or merged, or its assets are transferred, your information may transfer to the new owner, who would have to honor this policy. We will tell you in the app or by email if that happens.
13. If something goes wrong.
If a data breach affects your personal information, we will notify you and any required authorities without undue delay, as the law requires (for EU/UK users, within 72 hours where feasible).
14. Age.
You must be 16 or older to create an account or buy our products. We do not knowingly collect data from anyone under 16; if we learn that we have, we will delete it. We set 16 as the minimum everywhere, which means we never need a parent's permission to handle your data under EU or UK rules. If you are 16 or 17, UK law still treats you as a child: we keep analytics off unless you turn it on, we do not profile you or track your location, we do not sell or share your data, and you can export or delete everything at any time in Settings. Contact legal@othvane.com.
15. Accessibility.
Need this policy in another format? Email legal@othvane.com and we will help.
16. Changes.
Updates are posted here with a new date; material changes are announced in the app or by email.