Olantio

Privacy policy

Last updated: 16 August 2026

Olantio is a personal daily planner and time tracker, used at app.olantio.com. It is run by a sole proprietorship registered in Poland, which is the data controller for everything described here. This policy covers both this website and the app.

It describes what the app actually stores, field by field, rather than what a policy template would guess.

What Olantio stores

There are three groups of data, and there is no fourth.

1. Your account

You sign in with Google. From that sign-in Olantio receives and stores your email address, the name on your Google account, and the web address of your Google profile picture. Olantio never receives or stores your Google password. The picture itself is not copied — when the app shows it, your browser fetches it directly from Google.

2. What you plan and track

This is the product itself. The database holds:

Every one of those rows carries your account identifier and nothing else that identifies you.

3. Timestamps

Each row records when it was created and when it last changed, so that edits made on two devices can be reconciled.

What Olantio does not do

Where your data is stored

Supabase and Vercel process data on Olantio’s behalf, as does Google for sign-in. Both hosting providers keep their own operational logs, which can include your IP address and basic request information. Olantio adds no logging of its own.

Who can read your data

Only you. Every table enforces row-level security inside the database: a signed-in account can read and write only the rows carrying its own identifier, and a visitor who is not signed in is granted no access to any table at all. That rule is enforced by the database, not merely by the app in front of it.

The operator of Olantio has administrative access to the database, as the person responsible for running it. That access is used to keep the service working — not to read your day.

Signing in

Sign-in is Google only, handled by Supabase Auth using the PKCE flow. There is no password to store, and Olantio stores none. Today the app asks Google for identity information only — the three fields listed above — and for nothing else.

Google Calendar

Olantio can show your Google Calendar events on the same timeline as the day you are planning, so that meetings you have already agreed to are visible next to your own intentions. Connecting a calendar is optional and Olantio works without it. Calendar access is requested separately from signing in, at the moment you choose to connect — never as a condition of having an account.

What is read

Access is read-only, through two narrow Google scopes rather than one broad one. Each is requested because a specific thing below needs it, and nothing is requested that nothing needs:

Nothing else is stored. Event descriptions, locations, attachments, conferencing links, and the identities of other attendees are not copied into Olantio.

What is never done

Olantio never creates, edits, moves, or deletes a calendar event, never responds to an invitation on your behalf, and never invites anyone to anything. Neither scope above permits writing, so this is a property of the access itself and not only a promise about how it is used.

Access tokens

Connecting a calendar gives Olantio an access token and a refresh token issued by Google. Both are stored encrypted. The key that decrypts them is held on the server and never leaves it, so the stored values cannot be read without it. No part of the app returns a token to your browser. They are used for one purpose: reading the calendar data listed above.

Disconnecting

You can disconnect your calendar at any time from Olantio’s settings. Disconnecting revokes the tokens with Google and deletes them, and deletes the mirrored calendar data — the copies of your events that Olantio kept in order to draw them. Your own planned and tracked entries belong to you and are not affected.

You can also revoke Olantio’s access directly from your Google account at myaccount.google.com/permissions, which stops all access immediately.

Google Limited Use

Olantio’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, Google Calendar data is:

Why Olantio is allowed to hold this data

Under the GDPR, the data above is processed to provide the service you asked for — the contract between you and Olantio. There is no processing for any other purpose, so there is nothing here that rests on legitimate interest or on consent you would need to withdraw.

Keeping and deleting your data

Your data is kept for as long as your account exists. Ask for your account to be deleted and everything listed above is deleted with it. Ask for a copy and you will be sent one.

Deleting your Google Calendar connection does not delete your account, and deleting your account does not touch anything in your Google Calendar.

Your rights

Because Olantio is run from Poland and stores data in the EU, the GDPR applies. You have the right to access your data, to correct it, to have it deleted, to receive a copy in a portable form, and to object to or restrict its processing. Write to the address below and you will get an answer.

If you think your data has been handled wrongly, you can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

Changes to this policy

If this policy changes, the date at the top of the page changes with it. Olantio will not reduce the protections described here for data already collected without saying so.

Contact

Questions, requests, and data-protection matters: support@olantio.com

TODO: placeholder address — this inbox is not yet live or monitored.