Privacy policy
Last updated: 16 August 2026
Olantio is a personal daily planner and time tracker, used at app.olantio.com. It is run by a sole proprietorship registered in Poland, which is the data controller for everything described here. This policy covers both this website and the app.
It describes what the app actually stores, field by field, rather than what a policy template would guess.
What Olantio stores
There are three groups of data, and there is no fourth.
1. Your account
You sign in with Google. From that sign-in Olantio receives and stores your email address, the name on your Google account, and the web address of your Google profile picture. Olantio never receives or stores your Google password. The picture itself is not copied — when the app shows it, your browser fetches it directly from Google.
2. What you plan and track
This is the product itself. The database holds:
- Tasks — a title, an optional description, an optional estimate in minutes, a status (in your inbox, done, or archived), a priority, an optional due date, when you marked it done, and its position in your list.
- Timeline entries — every block you plan and every block you track: a title, a start time, an end time, whether it is a plan or a record of what actually happened, where it came from (a timer, typed in by hand, a calendar, or an import), an optional note, and the time zone you were in when it was recorded.
- Types and projects — the categories you sort work into: their names, colours, order, and whether you have archived them.
- Preferences — a handful of per-account settings: how your task list is sorted, and two display flags.
Every one of those rows carries your account identifier and nothing else that identifies you.
3. Timestamps
Each row records when it was created and when it last changed, so that edits made on two devices can be reconciled.
What Olantio does not do
- No analytics, no tracking pixels, no advertising, no profiling.
- No third-party scripts, on this website or in the app.
- No cookies. Neither this website nor the app sets a cookie, which is why there is no cookie banner.
- One preference, kept in your browser. When you use the appearance control in the header, this website saves your choice under the name
olantio.theme, with the valueauto,light, ordark. That is the only thing it stores, and it is stored so the next page you open looks the way you left it. It is written only when you use that control, it is never sent to a server, and it identifies nothing — clearing your browser’s site data removes it. Browser storage is per-site, so this website’s copy and the app’s are separate: choosing a theme in one does not change the other. - In the app, that same preference sits alongside your signed-in session, which is likewise held in your browser’s local storage and cleared when you sign out.
- Your data is never sold, and never shared with anyone for their own purposes.
Where your data is stored
- The database and the sign-in system are Supabase’s managed cloud, in the eu-central-1 region (Frankfurt, Germany) — inside the European Union.
- This website and the app are served by Vercel.
Supabase and Vercel process data on Olantio’s behalf, as does Google for sign-in. Both hosting providers keep their own operational logs, which can include your IP address and basic request information. Olantio adds no logging of its own.
Who can read your data
Only you. Every table enforces row-level security inside the database: a signed-in account can read and write only the rows carrying its own identifier, and a visitor who is not signed in is granted no access to any table at all. That rule is enforced by the database, not merely by the app in front of it.
The operator of Olantio has administrative access to the database, as the person responsible for running it. That access is used to keep the service working — not to read your day.
Signing in
Sign-in is Google only, handled by Supabase Auth using the PKCE flow. There is no password to store, and Olantio stores none. Today the app asks Google for identity information only — the three fields listed above — and for nothing else.
Google Calendar
Olantio can show your Google Calendar events on the same timeline as the day you are planning, so that meetings you have already agreed to are visible next to your own intentions. Connecting a calendar is optional and Olantio works without it. Calendar access is requested separately from signing in, at the moment you choose to connect — never as a condition of having an account.
What is read
Access is read-only, through two narrow Google scopes rather than one broad one. Each is requested because a specific thing below needs it, and nothing is requested that nothing needs:
https://www.googleapis.com/auth/calendar.calendarlist.readonly— your calendar list: the names and identifiers of the calendars on your Google account, so that you can choose which of them to show. This scope reads the list itself; it does not open any calendar.https://www.googleapis.com/auth/calendar.events.readonly— the events on the calendars you chose. From each event Olantio reads three things and no more:- event times — the start and end time, and whether it is an all-day event;
- the event title — so a block on your timeline is recognisable;
- your participation status — whether you accepted, declined, tentatively accepted, or have not yet answered, so that a meeting you declined is not drawn as time you owe.
Nothing else is stored. Event descriptions, locations, attachments, conferencing links, and the identities of other attendees are not copied into Olantio.
What is never done
Olantio never creates, edits, moves, or deletes a calendar event, never responds to an invitation on your behalf, and never invites anyone to anything. Neither scope above permits writing, so this is a property of the access itself and not only a promise about how it is used.
Access tokens
Connecting a calendar gives Olantio an access token and a refresh token issued by Google. Both are stored encrypted. The key that decrypts them is held on the server and never leaves it, so the stored values cannot be read without it. No part of the app returns a token to your browser. They are used for one purpose: reading the calendar data listed above.
Disconnecting
You can disconnect your calendar at any time from Olantio’s settings. Disconnecting revokes the tokens with Google and deletes them, and deletes the mirrored calendar data — the copies of your events that Olantio kept in order to draw them. Your own planned and tracked entries belong to you and are not affected.
You can also revoke Olantio’s access directly from your Google account at myaccount.google.com/permissions, which stops all access immediately.
Google Limited Use
Olantio’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, Google Calendar data is:
- never sold;
- never shared with third parties, other than the hosting providers named above that store it on Olantio’s behalf;
- never used for advertising, ad targeting, or profiling;
- never used to train, fine-tune, or evaluate artificial-intelligence or machine-learning models;
- never read by a person, except where you have explicitly asked for support that requires it, or where it is necessary for security, or where the law requires it.
Why Olantio is allowed to hold this data
Under the GDPR, the data above is processed to provide the service you asked for — the contract between you and Olantio. There is no processing for any other purpose, so there is nothing here that rests on legitimate interest or on consent you would need to withdraw.
Keeping and deleting your data
Your data is kept for as long as your account exists. Ask for your account to be deleted and everything listed above is deleted with it. Ask for a copy and you will be sent one.
Deleting your Google Calendar connection does not delete your account, and deleting your account does not touch anything in your Google Calendar.
Your rights
Because Olantio is run from Poland and stores data in the EU, the GDPR applies. You have the right to access your data, to correct it, to have it deleted, to receive a copy in a portable form, and to object to or restrict its processing. Write to the address below and you will get an answer.
If you think your data has been handled wrongly, you can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
Changes to this policy
If this policy changes, the date at the top of the page changes with it. Olantio will not reduce the protections described here for data already collected without saying so.
Contact
Questions, requests, and data-protection matters: support@olantio.com
TODO: placeholder address — this inbox is not yet live or monitored.