How we care for your data

Using Onsara requires trust. Here's what we collect, how we protect it, and the control you have.

Last updated November 11, 2025

What we collect

Your account

Email address, encrypted password (bcrypt hashed, never stored plain), account creation date

Your work

Tasks you create (titles, notes, dates, completion status), focus session history, onboarding preferences, app settings

Your subscription

Stripe customer ID, subscription status and dates. We never see or store your credit card information—Stripe handles all payment data.

Anonymous patterns

Usage analytics to improve the app (feature usage, session completion rates, performance metrics, error logs). These are anonymized and cannot be linked to your identity.

How we use it

Core functionality

Store and sync your tasks across devices

Personalization

Generate AI insights and recommendations based on your task patterns

Payment processing

Handle subscriptions and billing through Stripe (PCI-DSS compliant)

Improvement

Analyze anonymous usage patterns to enhance features and fix issues

Communication

Send account-related notifications and important updates

Who helps us

Supabase

Database & authentication

Hosts your encrypted data with TLS/SSL protection. Your tasks, sessions, and account information live here.

Their privacy policy →

Stripe

Payment processing

Handles all payment information. PCI-DSS compliant. We never see your credit card details—only subscription status.

Their privacy policy →

Google Gemini

AI insights

Generates focus preparation prompts and pattern detection. Receives task context only—no personal data like email or payment info.

Their privacy policy →

How we protect it

Encryption everywhere

Data encrypted at rest (in database) and in transit (TLS/SSL). Passwords hashed with bcrypt before storage.

Local caching

Some data cached on your device for offline access. Controlled by you, never sent elsewhere.

Retention periods

Account data kept while active. Tasks kept unless you delete. Subscription data retained 7 years (legal/tax compliance). Analytics anonymized after 90 days.

What you control

Access

Request a copy of your personal data

Correction

Update or correct your information

Deletion

Request full deletion of your account and data

Export

Download your data in portable format

Opt-out

Disable analytics tracking in app settings

To exercise any of these rights:

privacy@onsara.app

Legal requirements

Children's privacy

Onsara is not intended for users under 13. We do not knowingly collect information from children. If you believe we have, contact us immediately.

Policy changes

We may update this policy. Changes will be posted here with an updated date. Continued use means acceptance of updates.

Your agreement

By using Onsara, you agree to this privacy policy. If you have concerns, please reach out before continuing to use the app.