TealDrop

Privacy Policy

Last updated: August 6, 2026


This policy describes how Othvane LLC ("TealDrop", "we") handles personal information, including as required by the California Online Privacy Protection Act, Washington's My Health My Data Act, the EU/UK GDPR and Brazil's LGPD. It is also written to align with India's Digital Personal Data Protection Act, 2023, whose substantive obligations take effect in May 2027. Contact for all privacy matters (including our LGPD encarregado, and our contact for questions or grievances about data processing under India's DPDP Act): legal@othvane.com.

Where your data is stored, and what that means in Brazil. Our servers are in the United States. If you tell us you are in Brazil, or your connection indicates Brazil, we ask separately at sign-up for your specific agreement to store your data there, because Brazil has not recognized the United States as offering an equivalent level of protection and Article 33 of the LGPD requires that agreement to be its own decision rather than part of accepting these terms. We record the date you gave it. You may withdraw it at any time by writing to legal@othvane.com, and we will tell you what your options are, including exporting and deleting everything we hold. We are also asking our hosting provider whether it will enter into the standard contractual clauses published by the ANPD; if it does, we will move to that basis and update this policy. Patterns, and why they never reach us. If you turn Patterns on in Settings, TealDrop looks at numbers you have already recorded in a single planner and works out, in your browser, whether they tend to move together. The result is shown to you and discarded when the screen closes. It is never written to our database, never sent to us, and never shared. We do not receive it, cannot see it, and keep no record of what any pattern said. The only thing stored is your choice to have the feature on, with the date you chose it, so we can show you the setting and evidence that you asked for it. Patterns are off until you switch them on, and switching them off stops the calculation entirely. EU and UK representatives. We are based in the United States. Under Article 27 of the GDPR and of the UK GDPR we have appointed Prighter Group, with its local partners, as our privacy representative and your point of contact for the European Union and the United Kingdom. Prighter gives you a direct way to exercise your privacy rights, such as asking for access to or erasure of your personal data. To contact us through our representative, or to make a data subject request, visit https://app.prighter.com/portal/13936242094. You can also always reach us directly at legal@othvane.com.

2. What we collect.

(a) Account data: email, name, password (hashed), language, preferences, and any logo image you upload to customize your planners. (b) Planner entries you log: e.g. habits, budgets, meals, workouts, mood, reading, goals, reminders you set. (c) Purchase data: payments are handled by Stripe; we store what you bought, never card numbers. If you unlock a planner with a redemption code, we store only that the code was used and which planner it unlocked. (d) Technical data: logs needed to run and secure the service. To warn you if someone else signs in as you, we also keep a short record of the devices your account has signed in from: an opaque code that identifies the browser, and a plain label such as Safari on iPhone. We do NOT store your IP address or your full browser details for this, and the code cannot be linked to you on any other account. You can see and remove these at any time by deleting your account, and they are deleted with it. (e) Analytics events (feature usage, page views) only if you accept analytics in the consent banner; we configure analytics so the CONTENT of your entries is never sent. (f) Diagnostic error reports: if the app malfunctions and you have accepted analytics, we receive the error message, a technical stack trace, and the page path where it happened (never the content of your entries) so we can find and fix bugs. We also receive automated uptime and error alerts about the service itself.

3. Why we use it.

To provide the service you request (store entries, render dashboards, generate PDFs, send the reminders and recap emails or push notifications you enable), process payments, provide support, secure the service, and—with consent—understand feature usage. The reminders, recaps, and push notifications you turn on are service messages tied to features you enabled; you can turn them off in Settings. If we ever send a marketing email it will include an unsubscribe link. We may use aggregated or de-identified data (which cannot identify you) to understand and improve the product. We do not sell personal information and do not share it for cross-context behavioral advertising.

4. The AI planning assistant.

When you use the AI assistant, the text you send is processed by Anthropic to generate a reply. You are interacting with an AI system, not a person. Anthropic processes these requests under contract as our processor and, under its commercial API terms, does not use your prompts or the replies to train its models by default. We do not use your planner content to train any AI model. We do not make automated decisions that produce legal or similarly significant effects about you. We do not keep what you send. Your prompt is assembled, sent to Anthropic, and the reply is returned to you; none of it is written to our database. One exception: if you ask the assistant to fill in a planner page and you then choose to apply its draft, that draft becomes an entry you saved — it is marked as AI-drafted and stored like any other entry, and you can edit or delete it as you would your own. The only record we keep is that a request happened — your account, which feature you used, and when — which we need to enforce usage limits, and which is deleted after seven days. Planners that can reveal health or wellbeing, meaning the ADHD, self-care, fitness and meal planners, are withheld from the AI entirely unless you switch that on in Settings; you can switch it off again at any time. Where the assistant recognizes distress it will say plainly that it is an AI inside a planning app, not a therapist or a crisis service, and point you to findahelpline.com.

5. Consumer health data.

Some entries may relate to health or wellness: fitness logs, meals, water intake, mood, self-care, sleep notes. We collect these only because you type them in, use them only to show them back to you and power your dashboards, share them only with our hosting processor (Supabase) as needed to store them, and never sell them or use them for advertising. If you are in Washington State, our separate Consumer Health Data Privacy Policy sets this out in the form Washington law requires — open the Health Data tab. Nevada residents have similar protections. You may access, correct, export, or delete this data anytime in the app, or withdraw consent by deleting the entries or your account. To exercise rights or appeal a decision, email legal@othvane.com.

6. Cookies, local storage, and opt-out signals.

We use only what is needed to keep you signed in, remember your language and preferences, and — if you accept — run analytics. We do not use advertising cookies. Our analytics run only if you accept them in the consent banner, and declining counts as opting out. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of any sharing of your information.

7. Processors.

Supabase (database, auth, storage), Stripe (payments), Vercel (hosting), Resend (email), PostHog (consent-based analytics), Anthropic (AI assistant requests you send), Cloudflare (bot protection on our forms). Each processes data under contract for us and only on our instructions.

7b. Screenshots you attach to feedback.

If you attach a screenshot when sending feedback, it is stored in a private area that only you and the TealDrop team can read, and it is linked to your feedback message. A screenshot of a planner page can contain what you wrote in it, so please avoid attaching anything you would rather not share with us. Attaching one is always optional, feedback works without it, and the screenshot is included in your data export and removed when you delete your account.

7a. Calendar subscriptions (optional, off by default).

If you create a calendar link in Settings, you can subscribe to your TealDrop reminder dates from Apple Calendar, Google Calendar, Outlook or any other calendar app. Two things you should know before you turn it on. First, subscribed calendars are fetched by the calendar provider’s servers, not by your device, so the contents of that feed are sent to and cached by that provider (for example Apple or Google). Those providers are not our processors for this: you are choosing to send the information to them, and their own privacy terms apply. Second, for exactly that reason the feed contains dates only by default: every event reads “TealDrop reminder”, and the content of your entries stays out of it. You can choose to change that. In Settings there is a separate, clearly-labeled option to show what each reminder is about, which is off unless you turn it on; we record the date and time you turned it on. If you do, the text you wrote is sent to and stored by your calendar provider and can be read by anyone who can see your calendar. Even then, entries from planners that would disclose something about your health or wellbeing — the ADHD, self-care, fitness and meal planners — are never included, whatever that setting says; that exclusion is enforced on our servers, not in the app, so it cannot be bypassed. The name of a planner is never included either. The link contains a random secret and anyone holding it can see your reminder dates, so treat it like a password; you can create a new link or turn the feed off at any time in Settings, which immediately stops the old link working. The feed covers only workspaces you own, never dashboards shared with you.

8. How we protect your data.

Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. Database access is restricted per account so you can only reach your own records. Passwords are stored hashed, never in plain text, and you can turn on two-factor authentication in Settings. If your account is signed in on a device we do not recognize, we email you so you can react if it was not you; because this is a security notice rather than marketing, it cannot be switched off. Access is limited to the founder and the processors listed above, on a need-to-know basis. No system is perfectly secure, but we take reasonable steps to protect your information.

9. International transfers.

Data is processed in the United States. Where GDPR/UK GDPR applies, transfers rely on our processors' Standard Contractual Clauses. Legal bases: contract (Art. 6(1)(b)) for the service; consent (6(1)(a)) for analytics and for any health-related entries; legitimate interests (6(1)(f)) for security, including the device records and sign-in alerts described in section 1(d).

10. Retention.

Account data and entries are kept while your account exists and deleted when you delete your account (backups purge on rotation, within 30 days).

11. Your rights.

Depending on where you live (California, EU/UK, Brazil, India, and others): access, correction, deletion, portability, restriction, objection, and the right not to be discriminated against. In-app: Settings → Export my data, and Settings → Delete account. Anything else: email legal@othvane.com; we respond within the time your law requires (generally 30–45 days). You may also complain to your local supervisory authority. California Shine the Light: we do not share personal information with third parties for their own direct marketing, so there is nothing to report, but you can ask at legal@othvane.com.

12. If the business changes hands.

If Othvane LLC is ever sold or merged, or its assets are transferred, your information may transfer to the new owner, who would have to honor this policy. We will tell you in the app or by email if that happens.

13. If something goes wrong.

If a data breach affects your personal information, we will notify you and any required authorities without undue delay, as the law requires (for EU/UK users, within 72 hours where feasible).

14. Age.

You must be 16 or older to create an account or buy our products. We do not knowingly collect data from anyone under 16; if we learn that we have, we will delete it. We set 16 as the minimum everywhere, which means we never need a parent's permission to handle your data under EU or UK rules. If you are 16 or 17, UK law still treats you as a child: we keep analytics off unless you turn it on, we do not profile you or track your location, we do not sell or share your data, and you can export or delete everything at any time in Settings. Contact legal@othvane.com.

15. Accessibility.

Need this policy in another format? Email legal@othvane.com and we will help.

16. Changes.

Updates are posted here with a new date; material changes are announced in the app or by email.