Legal
Privacy notice
Last updated September 12, 2026
We use the information needed to run Uredan, protect your account, show Google Calendar events you explicitly connect, provide optional bounded task suggestions when available, and, only when separately enabled and authorized, explicitly capture the Gmail message already in view as one linked task or prepare a fully reviewed Gmail-owned draft. We do not sell your task, Google Calendar, Gmail account, captured-message metadata, or reviewed-draft content.
1. Who controls your information
Uredan is responsible for the personal information used to operate the planner. For a paid purchase, the merchant of record identified at checkout independently processes payment, tax, and transaction information under its own privacy terms.
2. Information we collect
- Account information: your Google account identifier, name, email address, and profile image where Google provides them.
- Planner content: task titles, notes, completion state, dates, ordering, estimates, and preferences such as timezone and appearance choices.
- Subscription information: customer and subscription identifiers, plan, status, renewal date, and cancellation state. We do not receive or store your full card number.
- Technical information: security logs, device and browser information, IP address, and service errors needed to protect and operate Uredan.
- Notification information: if you enable browser reminders, we store your browser's push-service endpoint, public encryption key, authentication secret, and expiry information. Reminder messages contain generic copy rather than task content.
- Google Calendar information: if you connect a Google Calendar account, we store its verified email label, readable calendar names, access roles, timezones, your calendar selections, and the minimum event projection needed for Planner, Plan, and Timeline. That projection can include an event title or Busy, dates and times, all-day state, timezone, recurrence identity, update markers, and a validated Google Calendar link. We do not retain event descriptions, attendee identities, organizer addresses, locations, conference details, attachments, or raw Google responses.
- Gmail connection, current-message capture, and reviewed-draft information: if the separately gated Gmail integration is available to you and you connect an account, we store its verified email label, a pseudonymous binding to the immutable Google account, granted permission and connection-health state, and encrypted credentials. If you explicitly invoke current-message capture from the Gmail add-on, Uredan processes only the exact message already in view and retains a bounded projection: its message and thread identifiers, subject, normalized reply address, valid reply-thread identifiers, capture time, and a provider-generated, account-aware backlink after exact validation. If you explicitly prepare a draft, Uredan processes the exact connected account, task and task version, To, Cc, and Bcc recipients, subject, complete body, and whether to create a new message or use an eligible retained thread. Uredan does not scan or search a mailbox or retain Gmail message bodies, snippets, quoted history, attachments, labels, or raw Gmail responses from capture.
3. Why we use it
We process this information to:
- Authenticate you and provide the planner.
- Save, synchronize, and roll forward your tasks.
- Provide optional task-property suggestions and automatic new-task duration when those features are available and enabled.
- Show selected Google Calendar events read-only beside your tasks and keep that view synchronized across your signed-in devices.
- When separately enabled for your protected alpha cohort and explicitly invoked from the Gmail add-on, validate the exact current message and connected account, then atomically create one linked Uredan task without scanning the mailbox or creating an unlinked fallback.
- When the separately enabled Gmail draft capability is available and you explicitly confirm its exact account and complete editable fields, ask Gmail to create one provider-owned draft. Uredan never sends the draft or reads, lists, updates, deletes, archives, labels, or otherwise changes Gmail content.
- Deliver browser reminders that you explicitly enable.
- Administer alpha access, future trials, subscriptions, and customer support.
- Secure, debug, and improve service reliability.
- Meet legal, tax, accounting, and fraud-prevention obligations.
Depending on your location and the activity, our legal basis is performance of our contract, legitimate interests in operating and securing Uredan, compliance with law, or consent where required.
4. Google Calendar and Gmail data
Connecting Google Calendar is optional and separate from signing in to Uredan. Uredan requests read-only access to your calendar list and events. It uses calendar-list data to let you choose calendars. It uses the selected, privacy-minimized event projections only to show events in Planner, Plan, and Timeline; let you explicitly create a separate Uredan task from an event; let derived automatic task placement avoid timed events that Google marks Busy. Uredan cannot create, edit, delete, accept, or decline Google Calendar events.
Connecting Gmail is optional and separate from Google sign-in and every Google Calendar connection. Gmail account administration, current-message capture, and reviewed-draft creation are separate capabilities, independently disabled by default, and limited to a protected owner cohort while their provider and release gates are evaluated. When capture is enabled for you, the Gmail add-on acts only after you invoke it for the message already in view. It resolves that exact message under temporary current-message authority and obtains a provider-generated, account-aware backlink. Uredan validates the exact account, message, thread, host, path, and bounded link fields before any write. Only then does one transaction create the canonical task, source link, bounded Gmail projection, and content-free receipt. A missing or unsafe backlink creates none of them and never creates an unlinked fallback task.
Current-message capture keeps only the minimal metadata described in section 2. The add-on does not traverse the thread, scan or search the mailbox, or retain a message body, snippet, quoted history, attachment, label, temporary current-message token, or raw provider event. A broader temporary current-message permission is not permission for Uredan to inspect other messages or retain their content.
If reviewed-draft creation is separately enabled and you invoke it for one connected account, Uredan requests Google's restricted gmail.compose permission just in time. Google describes that permission as allowing draft management and sending, but Uredan's provider adapter uses only Gmail's create-draft operation. It contains no send, read, list, update, delete, archive, or label operation. You review and may edit the exact account, To, Cc, Bcc, subject, complete body, and thread-association choice before explicit confirmation. Uredan reports only draft creation acknowledged by Gmail; editing, sending, or deleting that Gmail-owned draft remains entirely in Gmail and never changes the Uredan task.
Before the provider request, Uredan binds the reviewed fields to the exact owner, task version, Gmail connection and permission revision, preview revision and digest, and a UUID idempotency key. The reviewed recipients, subject, body, and trusted thread context enter only a bounded encrypted replay command. If Gmail may have created a draft but its response is lost, Uredan records Creation uncertain and never calls Gmail again for that same key. A new possible duplicate always requires a new explicit action.
Availability and provider approval. Implemented code, local tests, a configured OAuth client, and a deployed route are not Google approval or live proof. Google OAuth verification, the restricted-scope security assessment, Workspace Marketplace or add-on approval and listing visibility, supported-host conformance, protected-cohort smoke, exact-release deployment, and live production behavior are separate evidence gates. Until the applicable gates pass for each capability, Gmail draft creation and Gmail current-message capture stay default-off and unavailable outside the approved protected cohort. Enabling one does not enable the other. A protected alpha enablement is not public Marketplace availability or global release.
Who receives Google user data. Uredan shares, transfers, or otherwise discloses Google account information, Google Calendar data, and the separately enabled Gmail data described above only to the following recipients and only for the purposes stated:
- Google: Google provides sign-in, Calendar authorization, Gmail authorization, the explicitly invoked Gmail add-on, and the Google APIs from which Uredan requests the data you authorize. During separately enabled current-message capture, Google supplies temporary authority for only the message in view and the provider-generated backlink that Uredan validates. Only after you explicitly confirm a separately enabled reviewed-draft action does Uredan transfer its exact reviewed MIME content to Gmail's create-draft endpoint for the connected account.
- Vercel and Neon: Vercel hosts Uredan and processes sign-in and Calendar requests and responses, plus separately enabled Gmail requests and responses. Neon provides database and authentication infrastructure where Google account identifiers, encrypted Calendar credentials, encrypted Gmail credentials, calendar selections, bounded event projections, bounded Gmail current-message projections and capture receipts, encrypted draft replay commands, and content-free draft receipts are stored. They process Google user data on Uredan's behalf only to host, store, secure, and operate the corresponding user-facing features.
- Vercel AI Gateway and OpenAI: when optional built-in task suggestions are enabled, Vercel AI Gateway is Uredan's only AI gateway and routes requests only to OpenAI's
openai/gpt-5.6-lunamodel. Manual-suggestion content is limited to the bounded task title and limited notes, applicable active label names represented by request-local references, or the selected task titles needed for the requested result. A manual or automatic duration request can also include up to four relevant prior task titles and planned-duration-minute values. Automatic new-task duration is on by default when this feature is available, and you can disable it in Planning settings; its request uses the new task's bounded title and limited notes. A task you explicitly create from a Calendar event keeps the copied event title and planned date; a timed event can also supply planned start and planned-duration minutes. Of those copied values, its title may later be included in a manual duration, label, or grouping-title suggestion, and its title and duration, when present, may be included in a relevant history example for a later manual or automatic duration request. Calendar credentials, calendar-list data, raw event responses, attendee identities, descriptions, organizer addresses, locations, conference details, attachments, and Google event links are excluded. Gmail credentials, raw Gmail responses, message and thread identifiers, draft recipients, reviewed draft subject and body, MIME content, and provider draft IDs are also excluded from this built-in suggestion pathway. Each request carries a one-way owner pseudonym and content-free environment, feature, and suggestion-kind tags for abuse controls and routing; Uredan does not send your email address or Google account identifier for this purpose. Vercel AI Gateway does not store prompt content in Uredan's request logs, and Uredan has not enabled optional data sharing for model training or improvement. OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. No other downstream model provider, self-hosted model, or offline model is used for this feature. Uredan does not claim Zero Data Retention: OpenAI may retain API inputs and outputs in its default abuse-monitoring logs for up to 30 days unless longer retention is legally required. - Protected ChatGPT and Codex access from OpenAI: for the approved production owner cohort, after you deliberately complete OAuth, the connected client receives only the Uredan tool results you request. Those results may include selected read-only Calendar projections and ordinary task fields, including a copied event title, planned date, planned start, or planned-duration minutes that remain in a task after Unlink, Calendar disconnect, or duplication as described above. The purpose is to let you view and manage your own Uredan planner in that client. If Gmail reviewed drafts are separately enabled and you deliberately invoke that MCP tool, the client sends Uredan the exact task reference, Gmail connection selection, To, Cc, Bcc, subject, complete body, thread-association choice, explicit confirmation, preview binding, and UUID idempotency key. The requested preview can return the exact reviewed fields and bounded account label; creation returns only its state and content-free receipt. Uredan does not send Google credentials, raw Google responses, unselected calendars, attendee identities, Calendar details excluded above, temporary Gmail tokens, raw message metadata, or Gmail message or thread identifiers through MCP. Browser and MCP draft inputs do not accept message IDs, thread IDs, provider headers, temporary tokens, or raw message metadata as trusted values. Retained-thread context, if it later becomes eligible, is resolved only on the server. This protected validation requires the approved host account's account-wide model-improvement control to remain off.
- WorkOS: when external-client access is available and you authorize a client to use Uredan through MCP, WorkOS processes your Uredan owner identifier and Google-authenticated email address to complete that authorization. WorkOS does not receive your Calendar credentials or event projection, or your Gmail credentials or reviewed draft content. During protected validation, WorkOS assigns all nine canonical Uredan permissions from your account role because dynamic clients cannot select a smaller custom-permission subset. The ninth permission includes external-draft write authority, but assigning it does not enable Gmail, authorize an account, bypass explicit review, or override the default-off provider and capability gates. Connected-client revocation is available in authenticated Settings, and account deletion revokes provider access before deleting the Uredan identity or stops if that cleanup cannot be confirmed.
- Security, support, and legal recipients: authorized Uredan personnel or contractors may access specific data only with your permission for support, when necessary to investigate security or abuse, or when required by law. We may disclose the minimum data required to courts, regulators, law enforcement, or other competent public authorities when legally obligated.
- A business successor: a transfer as part of a merger, acquisition, or sale of assets would occur only after obtaining your explicit prior consent.
External AI access is limited to protected validation. Only the approved production owner cohort may authorize the validated ChatGPT or Codex account described above. OAuth completion, bearer use, and Settings reject non-cohort owners. Public setup, Claude from Anthropic, Cursor from Anysphere, and other compatible clients remain unavailable because Uredan cannot infer their model, account or service tier, workspace policy, or provider data-use setting from a client name. Uredan's separate Copy for assistant and Open in Codexactions and their Settings controls are also unavailable; ordinary provider-neutral copy remains available for the owner's own use. Google approved Uredan's read-only Calendar data-access review on August 31, 2026. That approval does not approve another owner, another external-client provider plan, public marketplace access, or assistant handoffs. Optional built-in task suggestions remain a separate, reviewed in-app capability governed by the provider, field-minimization, no-training, retention, rollout, and rollback terms above.
Outside the protected OpenAI client and other recipients and limited circumstances listed above, Uredan does not disclose Google user data to external AI clients, Stripe, browser push services, unrelated integration providers, advertisers, data brokers, information resellers, or credit and lending providers. We do not sell it or use or transfer it for advertising, credit decisions, or lending. We do not use or transfer Google user data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
Uredan's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5. Service providers
Uredan uses carefully selected infrastructure and service providers. These currently include Neon for database and authentication, Vercel for application hosting, Google for sign-in, optional Google Calendar authorization and data access, and separately gated Gmail authorization, explicit current-message capture, and draft creation; WorkOS for optional external-client authorization; Vercel AI Gateway and OpenAI for the optional bounded task suggestions described in section 4; and Stripe Managed Payments for checkout, subscriptions, payment processing, tax, and merchant-of-record services. A separately authorized ChatGPT or Codex client operates under OpenAI's terms during the protected owner-cohort validation described in section 4. Claude, Cursor, other compatible clients, public setup, and the separate assistant handoff actions remain unavailable. If you enable browser reminders, your browser's push service also processes the subscription endpoint and delivery request. They process information under their own terms or our instructions, depending on their role.
Only the recipients and limited circumstances identified in section 4 receive Google user data. Stripe and browser push services do not receive Google user data from Uredan. Uredan does not prefill Stripe Checkout with your Google-authenticated account email; you provide purchase contact and payment details directly to Stripe.
6. Retention
Planner data is kept while your account remains open. When you delete the account, we delete or de-identify product data within a reasonable operational period, subject to backups and records we must retain for security, dispute resolution, tax, accounting, or other legal obligations. Payment records may be retained separately by the merchant of record.
Google Calendar event projections are limited to the planning window around today. An event projection that has not been confirmed for 30 days is removed. Disabling a calendar or disconnecting an account removes the affected local choices, credentials, and event projections after the server confirms the change. An exact shared event may remain if another connected account still provides selected access to it.
A task you explicitly create from a Calendar event is separate ordinary planner data. It keeps the copied event title and chosen planned date; a timed event also supplies a planned start and planned-duration minutes. Each copied task field remains until you change that field, permanently delete the task, or delete your Uredan account. Moving the task to Trash does not erase these fields; Trash retains it until permanent deletion.
Choosing Unlink removes the task's current Calendar origin, source link, and event association, but it does not erase the copied task fields. Disconnecting a Calendar account removes that connection's credentials, selections, and event projections, but it does not alter a task already created from an event or remove that task's Calendar origin and source link. You can separately Unlink, edit, move to Trash, or permanently delete that task. Duplicating it creates a separate unlinked task that keeps ordinary copied fields including its title, planned date, and duration when present, but not its Calendar source link or planned start. Those duplicated fields follow the same edit, permanent-deletion, and account-deletion retention rules.
An explicit Gmail capture retains the exact message and thread identifiers, bounded subject and reply metadata, validated account-aware backlink, capture timestamps, source state, and a content-free interaction receipt with the linked task. The task and source remain local Uredan data when completed, moved, or recoverably trashed. Disconnect removes the credential, account label, permission state, retained subject, and future-draft reply metadata and makes the source action unavailable; it does not change the task or Gmail. Removing the Gmail link follows Uredan's recoverable unlink flow. Permanent task deletion removes the link and eligible unreferenced Gmail source identity, and Uredan account deletion removes the remaining Gmail capture data. Neither action deletes or changes a Gmail message.
A temporary Gmail authorization transaction stores its encrypted OAuth handshake and bounded outcome metadata and expires after 15 minutes. Owner-independent cleanup runs hourly and normally deletes expired transactions in the next sweep; an outage or bounded-cleanup backlog can delay physical deletion, so Uredan does not promise an exact deletion time.
A reviewed Gmail draft's exact To, Cc, Bcc, subject, body, and trusted thread context are stored only inside an encrypted replay command. The current replay window is 24 hours, and the application refuses any configured replay window longer than seven days. An owner-independent cleanup runs hourly and normally erases expired command ciphertext in the next sweep; an outage or a bounded-cleanup backlog can delay physical deletion. Before erasing a command that may have reached Gmail, Uredan records a content-free Creation uncertain receipt so that the same idempotency key cannot call Gmail again.
A durable draft receipt contains no recipient, subject, body, MIME content, credential, raw provider response, or provider exception. It retains only the owner-scoped task, connection and permission-revision binding, version and content digests, UUID idempotency key, acknowledged or uncertain status, bounded timestamps, and, after acknowledgement, the provider draft ID and a validated safe link when available. It can remain after task deletion or Gmail disconnect so a replay cannot create a duplicate, and is deleted with the Uredan account. Disconnect purges retained encrypted commands, removes the local Gmail credential, account label, permission state, and provider configuration after server confirmation, and does not delete or change a Gmail draft.
When optional built-in task suggestions are enabled, application and Vercel AI Gateway request logs do not store prompt content. Uredan may retain content-free operational records such as a request identifier, model, token counts, latency, outcome, and a one-way owner pseudonym. As described in section 4, Uredan does not claim Zero Data Retention: OpenAI may retain API inputs and outputs in its default abuse-monitoring logs for up to 30 days unless longer retention is legally required.
7. International transfers
Our providers may process information in countries outside your own. Where required, we and our providers use recognized safeguards for those transfers, such as adequacy decisions or standard contractual clauses.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to complain to a data-protection authority. You can change planner information directly and delete your account from account settings. You can choose individual calendars, disconnect a Google Calendar account in Integrations, and also revoke Uredan in your Google Account access controls. If the separately gated Gmail connection is available to you, you decide whether to connect each account, whether to invoke current-message capture for a message already in view, and whether to request its separate restricted draft permission. You can remove a retained Gmail source link without changing Gmail. Disconnect first purges retained encrypted commands and removes the local connection. Only after that local cleanup succeeds does Uredan ask Google to revoke the grant. When Google cannot confirm remote revocation, Uredan reports it as unconfirmed rather than claiming success, and you can revoke Uredan directly in Google Account access controls. A local cleanup failure keeps the connection and skips remote revocation rather than claiming that it was removed. Denying or revoking draft permission leaves ordinary Uredan tasks unchanged. You may also revoke an authorized MCP client in Settings; its ninth external-draft permission does not bypass the Gmail connection, rollout, exact review, or confirmation requirements. When built-in task suggestions are available, you choose whether to request a manual suggestion; automatic new-task duration is on by default and can be disabled in Planning settings. You can disable browser reminders in Uredan settings and in your browser or operating system. Use Uredan support for another privacy request.
9. Cookies and local storage
Uredan uses strictly necessary cookies or similar storage to maintain authentication, security, essential preferences, offline task access, and a bounded read-only cache of Calendar events you requested. Calendar cache data is owner- and session-bound and is cleared when the corresponding calendar or account access is removed. If we introduce optional analytics or advertising technologies, we will update this notice and request consent where the law requires it.
10. Security
We use access controls, encrypted connections, environment isolation, and monitoring intended to protect personal information. Google Calendar refresh credentials are encrypted at rest and isolated from Uredan sign-in credentials. Gmail credentials and reviewed-draft replay commands use separate encrypted envelopes and keyrings and are not reused from sign-in or Calendar connections. No security measure is perfect, so please keep your Google account secure and report suspected unauthorized access promptly.
11. Changes and contact
We may update this notice as Uredan changes. Material updates will be communicated through the service or another reasonable channel. Privacy questions can be submitted through Uredan support.