← Back

Privacy Policy

Last updated: July 20, 2026

1. Information We Collect

When you create an account, we collect your email address, and — if you sign in with Google or Apple — your name and profile picture. You can also register with an email address and password. We use this to create and manage your account.

If you enable Google Calendar integration, we access your calendar events to help schedule tasks. We only read and create events in calendars you explicitly authorize. If you connect iCloud Reminders, we access your reminder lists — using an app-specific password you provide — to sync the tasks you choose.

If you enable push notifications, we store the device or browser push token needed to deliver them.

We store the tasks, subtasks, notes, and preferences you create within the app.

If you use the baby-tracking features, we store the information you log about your child: their profile (name, birth date), care entries (feeds, sleep, diapers), growth measurements, milestones, and medical records — immunizations, checkup and sick-visit entries, and the care-provider contact details you add. This is sensitive health information about a child; it is stored only to show it back to you and the caregivers you explicitly invite, it is never used for advertising, and it is deleted with your account.

2. How We Use Your Information

  • To provide, operate, and improve Drift
  • To power AI features (task decomposition, walkthroughs, smart suggestions) using anonymized task context
  • To process payments and manage your subscription
  • To send transactional emails related to your account
  • To measure the effectiveness of our advertising — sharing only a hashed version of your email (and, for Reddit, IP) with the ad platforms noted below, never your account content

3. Third-Party Services

We use the following third-party services:

  • Google — for OAuth sign-in and optional Google Calendar sync
  • Apple — for Sign in with Apple and optional iCloud Reminders sync
  • Stripe — for web payment processing. We never store your credit card details.
  • RevenueCat — for managing App Store (iOS) subscriptions
  • Anthropic (Claude) — for AI-powered features such as task decomposition, chat, and suggestions. Task titles and descriptions may be sent to generate responses; we do not send your name, email, or payment details.
  • OpenAI — for voice mode. When you use voice, audio and relevant task context are processed to power the real-time conversation.
  • Vercel — for hosting and analytics
  • Amazon Web Services (AWS) — for encrypted, off-site database backups. Regular backups of our database are encrypted and stored in AWS S3 for disaster recovery.
  • Meta (Facebook)— for measuring the performance of our ads. When you visit our public site we load the Meta Pixel, and when you sign up we report the conversion to Meta’s Conversions API. Any email address sent is hashed (irreversibly, with SHA-256) before it leaves our servers; we never send Meta your tasks or account content.
  • Reddit— for measuring the performance of our ads. When you visit our public site we load the Reddit Pixel, and when you sign up we report the conversion to Reddit’s Conversions API. Any email address and IP sent are hashed (irreversibly, with SHA-256) before they leave our servers; we never send Reddit your tasks or account content.

4. Data Storage & Security

Your data is stored securely in encrypted databases. We use HTTPS for all data transmission. We also keep encrypted, off-site backups of our database for disaster recovery. We retain your data for as long as your account is active. You can delete your account at any time from Settings → Delete account. Deletion is immediate and permanent: it erases your account and the data associated with it — including your tasks, routines, chat history, and preferences — and we cannot restore it afterwards. Residual copies may persist in our encrypted backups until those backups age out.

5. Cookies

We use essential cookies for authentication and theme preferences. We use Vercel Analytics for basic, privacy-friendly usage metrics, and we record first-party usage events — such as feature usage and onboarding progress — in our own database to operate and improve the app.

We also use advertising measurement pixels from Meta (Facebook) and Reddit, paired with their server-side Conversions APIs, so we can tell which ads lead to sign-ups and spend our advertising budget effectively. These may set cookies and, on sign-up, share a hashed (SHA-256) version of your email address (and, for Reddit, IP address) with those platforms for conversion matching. We never share your tasks, notes, or other account content with them. If you visit from the EEA or the UK, these advertising trackers are disabled until you opt in through our cookie banner, and you can decline them entirely.

6. Your Rights

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Delete your account and data yourself, at any time, from Settings → Delete account
  • Export your task data

7. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email or an in-app notice.

8. Contact

If you have questions about this policy, contact us at cody@layer3d.io.

Terms of Service