Legal

Privacy Policy

Effective August 18, 2026 · Last updated September 12, 2026

The short version

  • Axis stores the data you put into it (tasks, notes, calendar blocks, routines, finances, fitness) so it can show it back to you across your devices. If you track a run or walk, it records your location for that activity only.
  • Every record is isolated to your account with database-level policies. Other users cannot read your rows.
  • Your password vault is encrypted on your device before it is stored. We cannot read it and cannot reset it.
  • Bank connections go through Plaid. Axis never sees your bank login. Google Calendar access is read-only.
  • The built-in assistant (Nova) sends the parts of your data needed to answer you to whichever model provider you have selected — OpenAI by default, or Anthropic if you switch it in Settings. If you talk to Nova instead of typing, your voice is streamed to OpenAI, which also speaks the replies. Your data is not used to train their models under the terms we use.
  • We do not sell your data or run ads. We use one privacy-limited analytics provider (PostHog) to count how Axis is used — which screens are opened and whether features work. It is configured so that it never records your screen, never captures the text you tap on, and never receives the content of your tasks, notes, finances or vault. There are no advertising trackers.
  • You can export your data as JSON and delete your account at any time from Settings → Account.

1. Who we are

Axis (axisproductivityapp.com) is operated by Jonathan Finkbeiner ("Axis", "we", "us"). Contact: jonathanf.2258@gmail.com.

2. What we collect

Account information

Your email address and, if you sign in with Google, the name and profile picture Google shares with us. Passwords for email sign-in are handled by our authentication provider (Supabase) and stored hashed; we never see them.

Content you create

Tasks, projects, goals, routines and completion history, calendar blocks, notes, journal entries, brainstorm maps, people you add (names, contact details, notes), places you log (with addresses, ratings, and photos you upload), books, movies, inventory items, subscriptions, and settings such as your time zone, theme, and layout.

Financial data (only if you connect it)

If you connect a bank or card through Plaid: account names and types, balances, transactions (date, amount, merchant, category), and investment holdings. Manual accounts and budgets you type in. Credit-card details you enter (statement day, due day, limit, rewards). We never receive your bank username or password; those go directly to Plaid.

Fitness data (only if you use it)

Workouts, sets, body metrics, nutrition entries you log, and, if you connect Strava, your Strava activities.

Location (only if you track a run or walk)

When you start tracking in Routes, Axis records your device's precise GPS coordinates for the duration of that activity and saves the resulting route to your account. Tracking runs only while Axis is open and you have started it; it stops when you finish, and it stops on its own when your screen locks. Routes you draw by tapping a map are stored the same way, as a list of coordinates. Your phone will ask permission the first time, and you can withdraw it at any time in iOS Settings › Privacy & Security › Location Services — the rest of Axis works normally without it. Saved routes are yours to delete individually, and they are removed with your account.

Password vault

Entries you save in the vault are encrypted on your device with AES-GCM before they are sent to us. The encryption key is protected by your PIN and a one-time recovery phrase that only you hold. We store ciphertext only. If you lose both the PIN and the recovery phrase, the vault cannot be recovered by anyone, including us.

Technical data

Standard server logs from our hosting provider (IP address, browser type, timestamps) used to keep the service running and secure. A push-notification subscription (a browser-issued endpoint and keys) if you turn on reminders. Your device time zone, if you allow it, so reminders arrive at the right local time.

Product analytics

We use PostHog to understand how Axis is used so we know what to build and what is broken. What it receives is deliberately narrow:

What it does not receive, by configuration and not merely by policy: session recording is disabled (PostHog never records your screen), autocapture is disabled (it never reads the text of what you tap, which in Axis would be note titles and merchant names), and no content of your tasks, notes, journal, finances, health data or vault is ever sent. We do not use advertising SDKs or tracking pixels.

Analytics loads separately from the app and only after Axis has started, so blocking it in your browser has no effect on Axis working.

3. How we use it

4. Who processes your data on our behalf

ProviderWhat they doWhat they receive
SupabaseDatabase, authentication, file storageAll account data, at rest in their cloud (US region unless configured otherwise)
VercelHosting and server functionsRequests to Axis, including the data those requests carry; server logs
GoogleOptional sign-in; optional read-only Google CalendarYour Google account identity; Axis reads your calendar events and stores an encrypted refresh token to keep syncing
PlaidOptional bank and card connectionsYour bank login (entered directly with Plaid, never seen by Axis); Plaid returns account and transaction data to Axis
StravaOptional activity syncYour Strava authorization; Axis stores an encrypted token and imports your activities
OpenAIThe default model behind Nova, briefs, digests, and AI helpers; all voice featuresSee section 5. Also, when you use voice: a live two-way audio stream of what you say and what Nova says back, and the text Nova speaks
AnthropicThe alternative model behind Nova, briefs, digests, and AI helpers, when you select it in SettingsSee section 5
PostHogProduct analytics — how Axis is used and what breaksYour Axis user ID, screen names from a fixed list, named events, and truncated error messages. No screen recordings, no tapped text, and none of your content.
ResendTransactional email (reminders you enable)Your email address and the reminder text
Your browser's push service (Apple, Google, Mozilla)Delivering push notificationsReminder title and body, encrypted to your device
Google Maps PlatformAddress autocomplete and map display for places you log in DatesThe address text you type as you type it, plus your IP address and approximate location

Integration tokens (Google, Plaid, Strava) are stored encrypted at rest and only decrypted on our servers when syncing.

5. AI features

Nova is the assistant built into Axis. When you use Nova or an AI feature, Axis sends the relevant parts of your data to a model provider. Two providers are offered, and you choose between them in Settings: OpenAI, which is the default, or Anthropic. Whichever you pick handles every AI feature listed below. Specifically:

Voice. Talking to Nova always goes to OpenAI, whichever model provider you have selected for text, because the voice models are OpenAI's. When you start a voice conversation, Axis opens a live connection and streams your microphone audio to OpenAI for as long as the call is running; OpenAI returns spoken replies, which Axis plays back. The same snapshot of your data described above is available to Nova during that call, so it can answer questions about your tasks, calendar and notes out loud. Nothing is recorded or stored by Axis — the audio exists only for the duration of the call. Your microphone is used only while a voice conversation is open, and iOS shows its own indicator the whole time. If you never start one, no audio ever leaves your device.

Requests are made through the providers' APIs under their business terms, which do not use API inputs to train their models. Nova cannot delete anything or add anything to your calendar without your explicit approval in the app.

6. How long we keep it

For as long as your account exists. When you delete your account, your data, uploads, and integration tokens are deleted from our database and storage; backups held by our hosting provider expire on their normal schedule (typically within 30 days). Server logs are retained by our hosting provider for a limited period.

7. Your choices and rights

Depending on where you live (for example the EU/UK or California), you may have additional rights to access, correct, delete, or port your data, or to object to certain processing. Email us and we will honor them.

8. Security

Row-level security policies isolate every table to the signed-in account. Integration tokens are encrypted at rest. The vault is end-to-end encrypted. Traffic is encrypted in transit (HTTPS). No system is perfectly secure; if we learn of a breach affecting your data we will tell you promptly.

9. Children

Axis is not directed at children under 13 (or the age of digital consent where you live), and we do not knowingly collect their data.

10. Changes

If we change this policy in a way that matters, we will update the date above and notify you in the app or by email before the change takes effect.

11. Contact

jonathanf.2258@gmail.com