Legal · version 1.0 · effective 20 July 2026
Privacy Policy
This policy explains how Disciplio processes personal data for the free public beta. The English version is the reference version used to prepare translations; it may be used to understand intended meaning where a translation differs, without limiting mandatory rights under applicable law.
controller
The controller is Oleksii Ihnatenko, an individual based in Poland. Disciplio is operated by Oleksii Ihnatenko, an individual based in Poland. Contact privacy@disciplio.me. No Data Protection Officer has been appointed; an EU representative is not applicable because the controller is based in the EU.
scope
This policy covers the Disciplio website, app, support channels, and optional AI features. It does not cover independent services you access through their own websites.
data
We process account data (name, email, password hash, internal ID, status and timestamps); authentication/security data (refresh-token records, session and request information, and IP or device information where logged); preferences (language, currency, interface, onboarding, timezone and local-time-derived data); and productivity data (goals, plans, tasks, calendar data, metrics, notes and reflections). We also process AI outputs, provider/model/usage metadata, policy records, and support reports. We do not process payment-card data because payments are not active. If you use the optional Google sign-in, we also process a stable Google account identifier (subject), your verified Google email, and the profile name Google returns; Google sign-in is necessary functionality for authentication, not product analytics, and we do not request or receive access to your Google mailbox, Calendar, Drive, or contacts.
collection
Data comes from you, your use of the service, and technical requests needed to operate it. There is no external calendar integration and no user-upload or file-storage feature.
purposes-bases
We process account and workspace data to perform the requested service; authentication and abuse data for contract performance and our legitimate security interests; support data to provide support and protect the service; and policy acceptance records for legitimate interests and legal compliance. Essential cookies and user-requested functional storage support the requested service and legitimate interests where appropriate.
ai-processing
When you request AI, selected goal, task, plan, scheduling, reflection or daily-note context, local date/time, language, your name where needed for context, and selected administrator-managed knowledge-base context may be sent to external AI providers through Disciplio’s internal OpenRouter/LiteLLM integration layer. Disciplio currently uses OpenRouter to route these requests to selected AI model providers. Your email address is not included in the AI payload. Raw prompts are not stored in PostgreSQL or intentionally written to application logs; outputs and usage metadata are stored. AI acknowledgement is separate from Terms acceptance, and you can disable AI while retaining core non-AI features.
embeddings-rag
The All-MiniLM-L6-v2 sentence-transformers model runs locally on Disciplio-controlled production infrastructure. It supports administrator-managed knowledge-base content in Qdrant; user goals, tasks, notes, and reflections are not embedded there. Hugging Face is a model source/licensor, not a recipient of your personal data for this local embedding flow.
cookies
See the Cookie and Browser Storage Policy for the exact inventory. Disciplio uses essential authentication storage and user-requested functional browser storage, plus optional, consent-based PostHog product analytics and session replay that stay off until you accept them in the storage-preferences banner. Disciplio does not use advertising or marketing cookies.
recipients
Active providers are Hetzner (VPS hosting in Nuremberg, Germany, including backend data services and backups), Cloudflare (frontend delivery, DNS, TLS/security delivery and email routing), OpenRouter (AI request routing) and selected AI model providers reached through OpenRouter, PostHog (optional, consent-based product analytics and session replay, EU-hosted), and Google (Google/Gmail as the destination mailbox for support and privacy email routed through Cloudflare, and separately, Google Identity Services, used only to verify your identity when you choose the optional Google sign-in). We disclose data only as needed to operate the service, comply with law, or protect rights and security.
transfers
Primary application infrastructure is hosted in Germany. OpenRouter and selected AI model providers may process requests in other regions under their applicable terms and safeguards. We do not state that all processing remains exclusively in Germany or the EEA.
retention
Active account and workspace data is retained while the account exists. Refresh tokens expire within 90 days and can end earlier on logout, revocation, expiry, or account deletion. Linked support reports are deleted with the account; a scheduled retention purge for other reports is not currently configured. De-identified AI usage and cost metadata may be retained up to 12 months for accounting, quota monitoring, reliability, abuse detection, and aggregate statistics. Consent records currently delete with the account; they are not retained for six years.
deletion
Deleting an account removes the active PostgreSQL user/profile, settings, tokens, consent records, onboarding data, quota windows, dismissals, plans, goals, tasks, contributions, reflections, stored recommendations, recommendation links, and linked support reports through the implemented deletion and database cascades. AI usage rows are de-identified by setting user and recommendation links to null while provider, model, token, cost, timing, and status metadata remain.
export
Automated export is not yet available. You may request a copy by emailing privacy@disciplio.me. We normally verify identity through the authenticated account or the email address associated with it; do not send government ID, PESEL, passport copies, or passwords unless we specifically and lawfully need another method.
rights
Subject to applicable law, you may request access, rectification, deletion, restriction, objection, portability, or withdrawal of an optional AI acknowledgement. Email privacy@disciplio.me. We handle GDPR requests within the period required by applicable law.
complaint
You may complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) or another competent supervisory authority.
security
We use measures such as HTTPS transport, password hashing, access controls, private backend services, restricted administrative access, backups, and security monitoring. Authorized administrators may access stored reflections or recommendations when necessary for support, security, abuse investigation, legal compliance, or technical troubleshooting. No system can guarantee absolute security.
children
Disciplio is not for people under 18. Do not create an account if you are under 18.
sensitive
Free-text areas can include reflections, notes, planning content, and support reports. Please minimise sensitive data and do not enter unnecessary medical, mental-health, political, religious, trade-union, biometric, genetic, sexual, banking, credential, API-key, token, passport, PESEL, government-ID, or third-party personal data. We cannot technically prevent every such entry.
no-sale
We do not sell personal data or use reflections, notes, or AI prompts for advertising, public sharing, unrelated analytics, or unrelated model training.
analytics
Both the Disciplio app (app.disciplio.me) and the public landing page (disciplio.me) use the same PostHog project, an EU-hosted analytics processor, for privacy-safe product analytics and optional session replay, each behind its own opt-in consent banner. We collect page views, feature-usage or navigation events, and a small set of attributes (language, placement, and, on the app, account role and onboarding status); we never send task, goal, or reflection text, AI prompts or output, contact-form content, your name, or your email address to PostHog. Session replay masks or fully blocks all such content, and the landing-page contact form is fully blocked from replay. Once an account is identified with the Admin role, the app opts out of further captures and replay; a PostHog exclusion filter is also required to hide historical admin activity from analysis. Because both surfaces share one PostHog project and PostHog's identifier is scoped to the shared disciplio.me domain, an anonymous visit to the landing page can be linked to the app activity that follows once you accept analytics on both surfaces and PostHog's normal identity-merge behavior applies — accepting on one surface does not automatically enable the other. You can withdraw consent at any time from the storage-preferences banner (app) or the analytics banner (landing page), or your account privacy settings, which stops capture and clears PostHog's local data immediately. No Google Analytics, Cloudflare Web Analytics, Sentry, advertising analytics, or marketing-email system is active for this release.
changes
We may update this policy. Material changes will be posted here and, where appropriate, announced in the app.
contact
Privacy and data-rights requests: privacy@disciplio.me. General support: support@disciplio.me. We usually aim to answer support messages in 3–5 business days; this is a target, not a guaranteed service level.
version
Effective date: 20 July 2026. Document version: 1.0. Reference language: English.