uptrend.today
Get in touch
Legal

Privacy Policy

How Today collects, uses, stores, and shares your information — including calendar, email, and health data you choose to connect.

Effective date August 21, 2026Last updated August 21, 2026

This Privacy Policy explains how Uptrendsoft AI Labs LLP ("Uptrend", "we", "us", or "our") collects, uses, stores, and shares information when you use Today (the "App" or "Service"), available at https://uptrend.today and as apps for iOS, Android, macOS, and the web.

Today is a personal planner with an AI assistant. To do its job it handles personal information, including, if you choose to connect them, your calendar, email, and health data. We have tried to explain plainly what we do with it.

This Policy should be read together with our Terms of Service.

1. Who We Are

The data controller responsible for your personal information is:

Uptrendsoft AI Labs LLP
Primrose Floors, K-2, 17 FF, Vatika India Next, Narsinghpur
Gurugram, Haryana 122004, India
Email: contact@uptrendsoft.com

2. Information We Collect

2.1Information you provide

  • Account information: your email address, name, and a password (if you sign up with email), or the basic profile information (name, email, profile picture) shared by Google, Apple, or Facebook (Meta) when you sign in through them.
  • Planning content: goals, milestones, tasks, routines, routine steps, notes, tags, categories, custom stats, and onboarding answers you enter.
  • Chat content: messages you exchange with the AI assistant, including voice messages you dictate (converted to text on your device or by your operating system's speech-recognition service; we receive only the text transcript).
  • Memories: facts about you that you ask the assistant to remember, or that it saves from your conversations so future answers can use them. You can review and delete each Memory in the App.
  • Settings and preferences: theme, notification preferences, AI-initiation preferences, and similar settings.
  • Support communications: anything you send us when you contact us.

2.2Information from connected accounts (optional)

You can connect third-party accounts from Profile → Integrations. We access only what is needed for the features you enable:

Google Calendar and Microsoft Outlook Calendar
We read your events (title, description, location, start/end time, attendees, organizer, meeting link, recurrence, status) and store a copy so that your schedule appears in the App, works offline, and can be used by the AI assistant. If you grant write access, we can create, update, delete, or RSVP to events when you ask. We also subscribe to change notifications (webhooks) from the provider so your calendar stays current.

Gmail and Microsoft Outlook Mail
When you ask the assistant something that requires your email (for example, "what did Priya send me about the offsite?"), we fetch the relevant messages (including attachments, where needed to answer) and pass them to the AI model to generate a reply. Email content is processed on demand and is not stored on our servers, in our database, or in the App's local cache. If you grant send permission, we can send an email on your behalf when you explicitly ask, and only after you have confirmed it.

Apple Health (iOS)
With your permission we read daily totals for steps, exercise minutes, sleep, and mindfulness minutes. We store these daily totals on our servers so they sync across your devices, appear in your stats, auto-complete matching routine steps, and can be referenced by the AI assistant (for example, to notice that you slept poorly before suggesting a lighter day). We never read raw sensor or clinical records, and we do not use Health data for advertising or share it with any advertising or data-broker service.

For each connected account we store the account email, display name, the permissions you granted, provider sync cursors, and the OAuth tokens needed to keep the connection alive. Refresh tokens are stored server-side only, are never sent to the App on your device, and are used solely to call the provider's APIs on your behalf.

2.3Information collected automatically

  • Device and usage data: device type, operating system, app version, language, time zone, and product analytics events such as "app opened" and "sign-up completed". See Section 6 for how we limit this.
  • Push notification tokens: a device token issued by Apple or Google (via Firebase Cloud Messaging) so we can deliver reminders, digests, and assistant messages you have opted into.
  • Sync metadata: timestamps and watermarks used to keep your devices in sync.
  • Server logs: IP address, request timestamps, and error information, retained for a limited period to keep the Service secure and reliable.
  • Approximate region: on first launch we use your device's time zone, and in some cases a one-time IP-based lookup (via ipapi.co), to determine whether local law requires us to ask for analytics consent. We do not store your IP address for this purpose.

We do not collect precise location, contacts, photos, or advertising identifiers.

3. How We Use Information

We use the information described above to:

  • provide, maintain, and sync the Service across your devices, including offline use;
  • generate AI responses, suggestions, plans, summaries, daily or weekly digests, and proactive check-ins (see Section 4);
  • display your calendar, answer questions about your email, and perform the calendar or email actions you request;
  • send reminders and notifications you have enabled;
  • personalise the assistant using your Memories, goals, routines, and (if connected) Health data;
  • understand how the App is used in aggregate so we can improve it;
  • secure the Service, prevent abuse, and debug problems;
  • communicate with you about the Service, respond to support requests, and meet legal obligations.

We do not sell your personal information, and we do not use it for third-party advertising.

4. How AI Features Use Your Data

The assistant is powered by large language models from OpenAI. When you send a message, or when a scheduled digest or proactive check-in runs, we send the model the information it needs to respond. Depending on the request, this may include your message, recent conversation history, relevant goals, tasks, routines, notes, Memories, calendar events, daily Health totals, and, for email questions, the content of the messages it fetches.

  • Data is sent to OpenAI under its API terms, which provide that API data is not used to train OpenAI's models.
  • We do not use your content to train AI models ourselves.
  • Proactive check-ins: if enabled, a scheduled job on our servers periodically reviews your recent activity and may start a new chat thread with you (for example, a morning plan or a nudge about a stalled goal). These runs use read-only access to your data; the assistant never changes your goals, tasks, or calendar without you confirming it in the chat. You can turn this off in Settings.
  • Chat threads and Memories are stored in your account so you can revisit them. You can delete individual Memories, threads, or your whole account at any time.

5. Google User Data: Limited Use Disclosure

Today's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, for data obtained through Google Calendar and Gmail scopes:

  • we use it only to provide and improve the user-facing calendar and email features described in Section 2.2;
  • we do not transfer it to others except as necessary to provide those features (for example, to the AI model to answer your question), to comply with law, or as part of a merger or acquisition with notice to you;
  • we do not use it for advertising, and we do not allow humans to read it except with your explicit consent for a specific message, where necessary for security or abuse investigation, to comply with law, or in aggregated and anonymised form for internal operations;
  • we do not use Gmail data to train generalised AI or machine-learning models.

6. Analytics and Cookies

We use Mixpanel to understand product usage: events such as app opens and sign-ups, together with platform and app version. Analytics are tied to a pseudonymous user ID.

  • If you are in the EU/EEA, UK, Switzerland, or California, analytics are off by default and we ask for your consent on first launch. You can change your choice at any time in Settings.
  • Elsewhere, analytics are on by default and can be turned off in Settings.
  • We do not use analytics data for advertising, and we do not share it with ad networks.

The web app uses local storage and IndexedDB to keep your data available offline and to remember your sign-in session. We do not use third-party advertising or tracking cookies.

7. Who We Share Information With

We share personal information only with service providers that process it on our behalf and under contract, and only to the extent needed for the purposes above:

ProviderPurposeData involved
SupabaseDatabase, authentication, file storage, serverless functions, realtime syncAll account and planning data, connected-account tokens, calendar events, Health totals, chat history
OpenAIAI model inferenceContent sent to generate responses (see Section 4)
Google (Firebase Cloud Messaging)Push notificationsDevice push token, notification content
Apple (APNs)Push notifications on iOS/macOSDevice push token, notification content
MixpanelProduct analyticsUsage events, device/app metadata (subject to Section 6)
ipapi.coOne-time region check for consent promptsIP address (not stored by us)
Google, Microsoft, AppleSign-in and connected accountsAs described in Sections 2.1 and 2.2

We may also disclose information if required by law or legal process, to protect the rights, safety, or property of Uptrend, our users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you before your information becomes subject to a different privacy policy).

We do not share your information with advertisers or data brokers.

8. Data Storage, Security, and Retention

Where data is stored. Your data is stored in our Supabase-hosted database and, for offline use, in an encrypted-at-rest local database on each of your devices (SQLite on iOS/Android/macOS, IndexedDB on the web). Mail content is never stored.

Security. Data is encrypted in transit (TLS) and at rest. Row-level security ensures each user can access only their own records. Connected-account refresh tokens are stored server-side only and are never exposed to client apps. Access to production systems is limited to personnel who need it. No system is perfectly secure, and we cannot guarantee absolute security.

Retention.

  • Account and planning data is kept for as long as your account exists.
  • Mail content fetched for the assistant is held in memory only for the duration of the request.
  • Connected-account tokens are deleted when you disconnect the account or delete your account; disconnecting also revokes the token with the provider where the provider supports it.
  • Analytics data is retained by Mixpanel according to our project settings, and pseudonymised.
  • Server logs are retained for a limited period (typically no more than 30 days) unless needed for an ongoing security investigation.
  • When you delete your account, all of the data above is deleted from our production database immediately, including chat history, Memories, calendar copies, Health totals, and connected-account tokens. Copies may persist in encrypted backups for up to 30 days before being overwritten.

9. Your Rights and Choices

Wherever you live, you can:

  • Access and edit your data directly in the App.
  • Disconnect Google, Microsoft, or Apple Health at any time from Profile → Integrations, or revoke access from the provider (for Google, at myaccount.google.com/permissions).
  • Delete Memories, chat threads, and individual items from within the App.
  • Turn off analytics, notifications, and proactive AI check-ins in Settings.
  • Delete your account from Profile → Account. This removes your data as described in Section 8.
  • Request a copy of your data, a correction, or deletion by emailing contact@uptrendsoft.com. We will respond within 30 days.

If you are in the EU/EEA, UK, or Switzerland, you additionally have the rights to data portability, to restrict or object to processing, to withdraw consent at any time (without affecting processing before withdrawal), and to lodge a complaint with your local supervisory authority. Our legal bases for processing are: performance of our contract with you (providing the Service), your consent (analytics in regulated regions, connected accounts, Health data, notifications), and our legitimate interests (security, debugging, and aggregate product improvement).

If you are in California, you have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising these rights. We do not "sell" or "share" personal information as defined by the CCPA/CPRA.

If you are in India, you have the rights under the Digital Personal Data Protection Act, 2023 to access, correct, and erase your personal data, to nominate another person to exercise your rights, and to raise a grievance with us. Our grievance contact is contact@uptrendsoft.com.

10. International Transfers

We are based in India and use service providers in other countries, including the United States. Your information may therefore be transferred to, stored, and processed outside your country. Where required, we rely on appropriate safeguards such as standard contractual clauses and our providers' data-processing agreements.

11. Children

The Service is not directed to children. You must be at least 13 years old to use it (16 in the EU/EEA, UK, and Switzerland; 18 in India), as set out in our Terms of Service. We do not knowingly collect personal information from anyone below the applicable age. If you believe a child has provided us with personal information, contact us and we will delete it.

12. Desktop App

The macOS desktop app can launch coding agents (such as Claude Code or Codex) that are installed on your computer, inside a terminal in the App. Those agents run locally with your user permissions and are governed by their own privacy policies; we do not receive the content of those terminal sessions except for session metadata (such as the working directory and status) that you choose to associate with a goal in your account.

13. Changes to This Policy

We may update this Policy from time to time. If we make material changes, particularly to how we handle connected-account or Health data, we will notify you in the App or by email before the changes take effect, and update the "Last updated" date above. The current version is always available at https://uptrend.today/privacy.

14. Contact Us

Questions, requests, or complaints about this Policy or your data:

Uptrendsoft AI Labs LLP
Primrose Floors, K-2, 17 FF, Vatika India Next, Narsinghpur
Gurugram, Haryana 122004, India
Email: contact@uptrendsoft.com