Privacy Policy
Last updated: 26 August 2026
РусскийWhat data we store
Account: the email address you sign in with. Kotomka has no passwords at all — you sign in with a one-time code sent by email, or with Yandex ID (in that case Yandex passes us the verified email address of your account). We also store your sign-in session and the browser user-agent string: the “Devices” screen uses it to show where you signed in from, so you can end any session you no longer need.
Dashboard: your spheres, projects, tasks, ideas, resources, habits, skills, journal entries and finances — so that your data is available on any device.
Where it is stored
The application runs on Vercel, the database is Neon (PostgreSQL). A copy of your data is also kept in your browser — that is what makes Kotomka fast and lets it survive network outages.
What Google user data Kotomka accesses
Only if you connect Google Calendar yourself in the settings. Kotomka requests the https://www.googleapis.com/auth/calendar, openid and email scopes, and receives:
- the email address of your Google account — shown on the integration screen so that you can see which account is connected;
- the list of your calendars (their names and identifiers) — you pick from it which calendars to link to your spheres;
- events of the linked calendars only: event identifier, title, start and end date and time (or the “all-day” flag), recurrence rule, creation and last modification time, deletion status, and Kotomka’s own private property holding the identifier of the matching task.
Nothing else. Kotomka does not read the contents of calendars you have not linked; event descriptions, attendee lists and attachments are not used. Gmail, contacts, Google Drive files, photos and other Google services are not requested at all.
How we use Google user data
The single purpose is two-way synchronization of your own tasks with the calendars you linked:
- a task with a date becomes a calendar event: Kotomka creates it, updates it whenever the task changes (title, time, recurrence, “done” mark) and deletes it when you delete the task;
- on your explicit command Kotomka creates a dedicated calendar for a sphere in Google Calendar and renames it when the sphere is renamed — it only ever modifies calendars it created itself;
- events you created or edited in the linked calendars are read by Kotomka and offered to you as tasks or as updates to existing tasks.
Google user data is never used for advertising, never sold, never transferred to third parties, never used for profiling and never used to train AI models. Kotomka staff do not read the contents of your calendars. When you disconnect the integration, the access token is revoked on Google’s side and deleted on ours, while the events and calendars in your Google account remain untouched.
Kotomka’s use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
- all data is transmitted over TLS (HTTPS) only;
- calendar access secrets (Google OAuth tokens, Apple app-specific password) are stored in the database encrypted with AES-256-GCM; the encryption key lives in a protected environment variable and is not kept in the source code;
- data is isolated per owner: every server request verifies that the account is accessing its own data;
- sign-in uses a one-time code that expires in 10 minutes and is burned after use; sign-in attempts are rate-limited;
- sessions are stored server-side — any session can be terminated from any device on the “Devices” screen;
- when an integration is disconnected, the access secrets are deleted immediately and the Google token is additionally revoked on Google’s side;
- the secret MCP connector URL is stored only as an irreversible hash and can be revoked in one click;
- no human reads the contents of your calendars or dashboard; server logs contain technical errors only.
AI assistant, MCP connector and your data
Both features are off by default and are enabled only by you.
- AI panel. You enter your own Anthropic or OpenAI API key. The key is stored in your browser only and never reaches our server. Requests go straight from your browser to api.anthropic.com or api.openai.com — our server is not part of that chain and never sees the conversation.
- MCP connector. You connect your own AI client to your own dashboard using a secret URL, and you choose which sections (spheres and tasks, inbox, journal, habits, finances, skills) it may read and whether it may write. From there on it is your client, not us, that passes the data to an AI provider.
In both cases the AI provider you chose may receive the contents of your dashboard, including tasks created from events of the linked calendars. Under their API terms, Anthropic and OpenAI do not use data submitted through the API to train their models (Anthropic, OpenAI). Kotomka uses no aggregators, gateways or model hubs, and runs no self-hosted models. We neither use nor transfer any Google user data to create, train or improve AI/ML models.
Apple Calendar
Apple Calendar is connected with an iCloud app-specific password and follows the same rules: Kotomka sees the list of your calendars and the events of the linked ones only, uses them solely to synchronize your tasks, stores the app password encrypted and deletes it the moment you disconnect the integration.
Deleting your data and revoking access
You can disconnect Google Calendar at any time in Kotomka’s settings — the access token is revoked and deleted immediately. You can also revoke the app’s access on Google’s side at myaccount.google.com/permissions.
To delete your account and all of your data, write to hello@kotomka.app from the address you sign in with.