Privacy Policy
Effective and last updated: September 15, 2026
- What's stored: the content you type into the app, plus basic product‑usage analytics.
- Who sees it: only you (enforced by database security rules) and our processors, Google Firebase and PostHog, who host the infrastructure.
- Your control: edit or delete any item in the app; delete your entire account and data in Settings at any time.
- Scope of this policy
- Information we collect
- Information we do not collect
- How we use information
- Legal bases for processing
- How we share information
- Data retention
- Your choices and rights
- Anonymous accounts & no password recovery
- Security
- Children's privacy
- International data transfers
- Changes to this policy
- Contact us
1.Scope of this policy
This Privacy Policy explains how EisenhowerOS ("EisenhowerOS," "we," "us," or "our") collects, uses, discloses, and protects information when you use the EisenhowerOS mobile application (the "App") and this website at eisenhowerimpact.web.app (the "Site"), together the "Services." EisenhowerOS is developed and operated by an individual developer, Mahir Ahmed.
There is no company backend server behind the App. It is a client application that reads and writes directly to Google Firebase (Cloud Firestore and Firebase Authentication) using access rules scoped to your own account, and sends product‑usage analytics to PostHog. That architecture is the basis for everything described below.
2.Information we collect
a. Account data
When you first open the App, we automatically create an anonymous account for you via Firebase Authentication. This assigns your device a random, unique identifier (a "UID"). No name, email address, or password is required to create or use an account.
During onboarding you may optionally enter an email address as a profile field. This is stored on your account document but is not used as a login credential — it is not verified, and there is no password‑reset or account‑recovery flow built around it. You can leave it blank, and you can change or clear it later from Settings.
b. Content you create
Everything you enter into the App — task and routine titles, project details, goals, notes, due dates, priority classifications, completion history, and similar productivity data — is stored in Cloud Firestore under your account's UID. We do not read, review, or use this content ourselves; it exists solely so the App can display it back to you and, if you use the App on more than one device signed into the same account, keep it in sync.
c. Usage and diagnostic data (product analytics)
The App uses PostHog, a product‑analytics service, to understand how the App is used and to fix bugs. This includes:
- Feature interactions and in‑app events (e.g., which screens you open, which actions you take), identified only by your anonymous UID;
- App lifecycle events (app opened, backgrounded, foregrounded);
- Basic device and app diagnostics such as device model, operating system and version, app version, locale, and general (city/region‑level, IP‑derived) location automatically included by the analytics provider's infrastructure.
We do not use this data to individually track you across other companies' apps or websites, and it is not linked to any advertising identifier.
d. Website data
If you submit your email address on this Site to join the waitlist, we store that email, the form you submitted it from, and a timestamp. This entry is write‑only from the browser — the Site itself cannot read back submitted emails once sent.
The Site also uses Google Analytics (via Firebase/gtag.js) and PostHog's web analytics to measure page visits and general engagement, which may use cookies or similar local‑storage identifiers in your browser.
3.Information we do not collect
The App does not request or access your precise device location, contacts, camera, photo library, microphone, push‑notification token, biometric data (Face ID/Touch ID are, if you use a device passcode manager, handled entirely by your OS and never reach us), health data, or payment/financial information. The App contains no third‑party advertising SDKs and does not display ads.
4.How we use information
- To provide the Service: storing and syncing the tasks, routines, projects, and goals you create, and remembering your account and preferences.
- To understand and improve the product: using aggregated, pseudonymous usage analytics to see which features are used and where the App breaks.
- To operate the waitlist: using the email you submit on the Site to notify you about beta access.
- To communicate with you: if you've given us an email address (via onboarding or the waitlist) and contact us, or if we need to reach you about your account.
- To maintain security: Firestore access rules and authentication state are used to make sure only you can read or write your own data.
We do not use your data to build advertising profiles, and we do not sell, rent, or trade personal information to third parties.
5.Legal bases for processing (EEA/UK users)
If you are in the European Economic Area or United Kingdom, our legal bases for processing are: performance of a contract (to provide the App's core functionality), legitimate interests (to keep the Service secure and to understand product usage in aggregate), and, where applicable, your consent (for example, submitting your email to the waitlist). You may withdraw consent at any time as described in Section 8.
6.How we share information
We do not sell personal information. We share information only with the infrastructure providers ("sub‑processors") needed to run the Service, each acting under their own privacy commitments:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase / Google Cloud (Google LLC) | Authentication, database (Cloud Firestore), and website hosting/analytics | Account UID, optional email, app content, hosting logs |
| PostHog | Product analytics (app & website) | Anonymous UID, event data, device/app diagnostics |
We may also disclose information if required to do so by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. If EisenhowerOS is ever involved in a merger, acquisition, or sale of assets, account data may be transferred as part of that transaction, subject to this policy or a policy at least as protective.
7.Data retention
We retain your account data for as long as your account exists. If you delete your account in the App (see Section 8), your profile document and every task, routine, project, and goal you created are permanently deleted from Cloud Firestore immediately, followed by deletion of the underlying authentication record. This action cannot be undone. Waitlist email submissions are retained until the beta program the waitlist supports has concluded, or until you ask us to remove them. Aggregated analytics events are retained by PostHog per their standard retention windows and are not individually actionable once your account is deleted.
8.Your choices and rights
- Access and correction: everything you've stored is visible and editable directly inside the App — there is no separate copy to request.
- Deletion (self‑service): open Settings → Account in the App and choose to permanently delete your account. This immediately and irreversibly deletes your profile, tasks, routines, projects, and goals, then removes your authentication record.
- Waitlist removal: email us (below) to have a waitlist submission removed.
- Analytics opt‑out: you may use your device or browser's tracking‑limitation settings; PostHog also honors Do Not Track signals on the web where technically supported.
Depending on where you live, you may have additional rights under laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA), including the right to request access to, correction of, deletion of, or a copy of your personal information, and the right to object to or restrict certain processing. Because the App has no traditional login, we generally cannot verify identity for requests made outside the App itself beyond confirming the email address associated with an account — the fastest and most complete way to exercise these rights is the in‑app deletion described above. For anything else, contact us at the email in Section 14.
9.Anonymous accounts & no password recovery
Because EisenhowerOS uses anonymous authentication rather than a traditional email/password login, your account is tied to your device's local app installation, not to a credential you can enter elsewhere. This means:
- Uninstalling the App, clearing its local storage, or switching to a new device will permanently lose access to that account and its data — there is no "forgot password" or account‑recovery flow to get it back.
- If you entered an optional email address, it identifies your profile but cannot, by itself, be used to sign back in to a lost account.
We disclose this here because it directly affects how long your data practically persists and how you should think about backing up anything important elsewhere.
10.Security
Your data is protected by Cloud Firestore security rules that only allow a request to read or write a given user's data when it is authenticated as that same user (request.auth.uid == userId) — no other user, and no public request, can read your tasks, routines, projects, or goals. Data is encrypted in transit (TLS) and at rest by Google Cloud's infrastructure. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
11.Children's privacy
EisenhowerOS is not directed to, and is not intended for use by, children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
12.International data transfers
Our infrastructure providers (Google Firebase/Google Cloud and PostHog) may process and store data in the United States and other countries where they or their sub‑processors operate. Where required, such transfers rely on the mechanisms those providers make available for cross‑border data transfer (such as Standard Contractual Clauses).
13.Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the App, the Site, or applicable law. We will update the "last updated" date above when we do, and for material changes we will provide additional notice where appropriate (for example, an in‑app notice). Continued use of the Services after a change takes effect constitutes acceptance of the revised policy.
14.Contact us
If you have questions about this Privacy Policy, want to exercise a privacy right, or want a waitlist submission removed, contact:
Mahir Ahmed — EisenhowerOS