Koda · legal

Privacy Policy

Last updated: July 8, 2026

Koda is a mobile app for tracking habits, tasks, and calendar events. This document explains what data Koda collects, why, where it is stored, and what rights you have. It is written in plain language — without legal jargon where it can be avoided.

1. Data controller

Koda is a personal project by Oleksandr Zinchenko (Ukraine), with no legal entity at the time of publication of this document. Contact for all data-related questions: support.koda@gmail.com.

2. What data we collect

Koda processes the following categories of data:

  • Account data: email and Google ID obtained during sign-in via Google Sign-In. Name and avatar are not stored on the server.
  • User content: habits, completion logs, tasks, calendar events, subtasks, reminders, interface settings, attached files (up to 10 MB each). You enter all of this yourself.
  • Google Calendar data (optional): if you connect Google Calendar sync, Koda performs one-way reads of events from your selected calendars within a window of today..today+90 days. Koda does not write back to Google.
  • Google Tasks data (optional): if you choose to import from Google Tasks, Koda performs a one-time, read-only fetch of your task lists and tasks and copies them into your Koda inbox. Koda does not write back to Google and does not keep an ongoing sync.

Koda does not collect: contacts, photo library, precise location, microphone, usage data of other apps, advertising identifiers.

3. Why we collect this data and the legal basis

Purposes of processing and corresponding legal bases under Art. 6(1) GDPR:

  • Performance of a contract (Art. 6(1)(b) GDPR) — email/Google ID for sign-in and synchronization, user content for the app's operation, Google Calendar data to display events, Google Tasks data to import your existing tasks, processing of payments for Pro/Lifetime
  • Legitimate interests (Art. 6(1)(f) GDPR) — correspondence with our support team about your requests, detection of abuse and protection of the service, crash reporting and aggregated product analytics (see section 6) that never include your content
  • Consent (Art. 6(1)(a) GDPR) — for future optional features (e.g., a planned AI coach). No such features exist in the app today; we will ask for your consent before launching them, and consent can be withdrawn at any time via the app's settings

We do not use your data for advertising, profiling, sale to third parties, or training AI models. Koda currently uses no artificial intelligence (AI) models or services at all — neither our own nor third-party ones (see section 6).

4. Where and how data is stored

All data is stored in a secured Supabase database (region eu-central-1, Frankfurt, Germany). Attached files live in Supabase Storage with owner-only access (Row Level Security). Each user sees only their own data — isolation is enforced at the database level through RLS policies user_id = auth.uid().

The connection between the app and the server uses TLS. Passwords are not stored (sign-in is via Google OAuth only).

5. How we protect your data

Security procedures are in place to protect the confidentiality of your data, including sensitive data obtained from Google APIs:

  • Encryption in transit: all communication between the app and our servers uses TLS (HTTPS). Koda has no unencrypted endpoints.
  • Encryption at rest: the database and file storage are encrypted at rest (AES-256) on Supabase infrastructure.
  • Access control: every table is protected by Row Level Security — each user can only access their own rows (user_id = auth.uid()). Attached files live in a private bucket with owner-only access and expiring signed URLs.
  • Google tokens are not stored on our servers:Google OAuth access tokens are handled by the Google Sign-In SDK on your device and are never written to our database. You can revoke Koda's access at any time at myaccount.google.com/permissions.
  • Data minimization: we request read-only Google scopes, store no passwords, and collect no data beyond what section 2 describes.

6. Third-party services

Koda uses the following third-party services, each with its own policy:

  • Google (Sign-In + Calendar API + Tasks API): for authentication and optional reading of your calendar events and Google Tasks. policies.google.com/privacy
  • Supabase (Supabase Inc., USA; infrastructure in eu-central-1, Frankfurt): database storage, authorization, file storage. supabase.com/privacy
  • Google Play Billing (Google Ireland Ltd. / Google LLC): payment processing for Pro and Lifetime. Koda does not receive card numbers — only subscription status.
  • RevenueCat (RevenueCat Inc., USA): subscription status management for Pro. Receives an app user identifier and purchase status only — no user content and no Google user data. revenuecat.com/privacy
  • Sentry (Functional Software, Inc.; EU data region): crash reports, so we can find and fix errors. Reports contain technical device data only — never your habits, tasks, events, or Google user data. sentry.io/privacy
  • PostHog(PostHog Inc.; EU cloud): anonymous product analytics (e.g., "a habit was created"). Events never include the names or content of your habits, tasks, or events, and no Google user data. posthog.com/privacy

Koda does not use any artificial intelligence (AI) models or services — neither our own nor third-party ones. An AI coach is a possible future feature; if it is introduced, we will update this policy beforehand and ask for your explicit consent, and Google user data will never be used to train AI or ML models.

7. With whom we share, transfer, or disclose data — including Google user data

We do not sell your personal data. We do not transfer or disclose your information — including Google user data (your Google Calendar events and Google Tasks) — to third parties for purposes other than the ones described in this policy. The only cases in which your data leaves Koda are:

  • Infrastructure and service providers (processors) listed in section 6, which store or process data solely on our behalf to operate the app (e.g., Supabase hosts the database). Google user data is shared only with Supabase, as the database where your synced events and imported tasks are stored;
  • Legal requirements — if disclosure is required by applicable law or a valid legal request.

Koda's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is never used for advertising, never sold, never used to train AI or ML models, and is not read by humans, except with your affirmative agreement, when necessary for security purposes, or to comply with applicable law.

8. International data transfers

Koda's primary database is located within the European Union (Supabase, Frankfurt). However, some services we use operate in the USA or other countries outside the EEA — in particular, Google (Sign-In, Calendar API, Play Billing) and the parent company of Supabase.

Transfers of personal data to such countries take place on the basis of the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, which Google and key Supabase subprocessors have joined. This ensures a level of protection equivalent to GDPR.

9. How long we retain data

  • While your account is active — all data is retained
  • After account deletion — full removal within 30 days
  • Supabase backups — up to 7 days, then automatically overwritten

10. Your rights (GDPR and beyond)

Under Chapter III of GDPR, you have the right at any time to:

  • Access (Art. 15) — see your data inside the app, or write to us and receive a JSON export within 30 days
  • Rectification (Art. 16) — any field is editable in the app
  • Erasure (Art. 17) — Settings → Delete account. Everything is removed within 30 days
  • Restriction of processing (Art. 18) — write to support; while a dispute is being resolved, data will only be stored, not processed
  • Data portability (Art. 20) — receive your data in a structured format (JSON) and transfer it to another service
  • Objection (Art. 21) — against any processing based on legitimate interests; we will stop unless we have overriding lawful grounds
  • Withdraw consent (Art. 7(3)) — for optional services (analytics, crash reports, AI coach)
  • Revoke Google Calendar permission — within the app, or via myaccount.google.com/permissions
  • Lodge a complaint with a supervisory authority (Art. 77) — to the data protection authority in your country (for users in the EU — your national DPA; for Ukraine — Ukrainian Parliament Commissioner for Human Rights)

To exercise your rights, write to support.koda@gmail.com. We respond within 30 days (a GDPR requirement).

11. Children

Koda is not intended for children under 13. We do not knowingly collect data from anyone under 13. If you are a parent and discover that your child has created an account, write to support and we will delete it.

12. Changes to this policy

We may update this document. The date at the top reflects the most recent revision. We will notify you in-app or by email before material changes (new categories of data, new third parties) take effect.

13. Contact

For any privacy-related questions, write to support.koda@gmail.com. We respond within 7 days.

Questions? support.koda@gmail.com