Disciplio
ProductFeaturesPricingAbout
Resources hubSupportContactPrivacy
EnglishPolskiУкраїнська
Log inGet Started
ProductFeaturesPricingAboutResourcesSupportContact
Language
ENPLUA
Log inGet Started

Legal · version 1.0 · effective 20 July 2026

Privacy Policy

This policy explains how Disciplio processes personal data for the free public beta. The English version is the reference version used to prepare translations; it may be used to understand intended meaning where a translation differs, without limiting mandatory rights under applicable law.

controller

The controller is Oleksii Ihnatenko, an individual based in Poland. Disciplio is operated by Oleksii Ihnatenko, an individual based in Poland. Contact privacy@disciplio.me. No Data Protection Officer has been appointed; an EU representative is not applicable because the controller is based in the EU.

scope

This policy covers the Disciplio website, app, support channels, and optional AI features. It does not cover independent services you access through their own websites.

data

We process account data (name, email, password hash, internal ID, status and timestamps); authentication/security data (refresh-token records, session and request information, and IP or device information where logged); preferences (language, currency, interface, onboarding, timezone and local-time-derived data); and productivity data (goals, plans, tasks, calendar data, metrics, notes and reflections). We also process AI outputs, provider/model/usage metadata, policy records, and support reports. We do not process payment-card data because payments are not active.

collection

Data comes from you, your use of the service, and technical requests needed to operate it. There is no external calendar integration and no user-upload or file-storage feature.

purposes-bases

We process account and workspace data to perform the requested service; authentication and abuse data for contract performance and our legitimate security interests; support data to provide support and protect the service; and policy acceptance records for legitimate interests and legal compliance. Essential cookies and user-requested functional storage support the requested service and legitimate interests where appropriate.

ai-processing

When you request AI, selected goal, task, plan, scheduling, reflection or daily-note context, local date/time, language, your name where needed for context, and selected administrator-managed knowledge-base context may be sent to OpenAI through Disciplio’s internal LiteLLM integration layer. Your email address is not included in the AI payload. Raw prompts are not stored in PostgreSQL or intentionally written to application logs; outputs and usage metadata are stored. AI acknowledgement is separate from Terms acceptance, and you can disable AI while retaining core non-AI features.

embeddings-rag

The All-MiniLM-L6-v2 sentence-transformers model runs locally on Disciplio-controlled production infrastructure. It supports administrator-managed knowledge-base content in Qdrant; user goals, tasks, notes, and reflections are not embedded there. Hugging Face is a model source/licensor, not a recipient of your personal data for this local embedding flow.

cookies

See the Cookie and Browser Storage Policy for the exact inventory. Disciplio currently uses only essential authentication storage and user-requested functional browser storage; it does not use advertising, analytics, session replay, or marketing cookies.

recipients

Active providers are Hetzner (VPS hosting in Nuremberg, Germany, including backend data services and backups), Cloudflare (frontend delivery, DNS, TLS/security delivery and email routing), OpenAI (requested AI generation), and Google/Gmail (destination mailbox for support and privacy email routed through Cloudflare). We disclose data only as needed to operate the service, comply with law, or protect rights and security.

transfers

Primary application infrastructure is hosted in Germany. OpenAI processing may involve other regions under its applicable terms and safeguards. We do not state that all processing remains exclusively in Germany or the EEA.

retention

Active account and workspace data is retained while the account exists. Refresh tokens expire within 90 days and can end earlier on logout, revocation, expiry, or account deletion. Linked support reports are deleted with the account; a scheduled retention purge for other reports is not currently configured. De-identified AI usage and cost metadata may be retained up to 12 months for accounting, quota monitoring, reliability, abuse detection, and aggregate statistics. Consent records currently delete with the account; they are not retained for six years.

deletion

Deleting an account removes the active PostgreSQL user/profile, settings, tokens, consent records, onboarding data, quota windows, dismissals, plans, goals, tasks, contributions, reflections, stored recommendations, recommendation links, and linked support reports through the implemented deletion and database cascades. AI usage rows are de-identified by setting user and recommendation links to null while provider, model, token, cost, timing, and status metadata remain.

export

Automated export is not yet available. You may request a copy by emailing privacy@disciplio.me. We normally verify identity through the authenticated account or the email address associated with it; do not send government ID, PESEL, passport copies, or passwords unless we specifically and lawfully need another method.

rights

Subject to applicable law, you may request access, rectification, deletion, restriction, objection, portability, or withdrawal of an optional AI acknowledgement. Email privacy@disciplio.me. We handle GDPR requests within the period required by applicable law.

complaint

You may complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) or another competent supervisory authority.

security

We use measures such as HTTPS transport, password hashing, access controls, private backend services, restricted administrative access, backups, and security monitoring. Authorized administrators may access stored reflections or recommendations when necessary for support, security, abuse investigation, legal compliance, or technical troubleshooting. No system can guarantee absolute security.

children

Disciplio is not for people under 18. Do not create an account if you are under 18.

sensitive

Free-text areas can include reflections, notes, planning content, and support reports. Please minimise sensitive data and do not enter unnecessary medical, mental-health, political, religious, trade-union, biometric, genetic, sexual, banking, credential, API-key, token, passport, PESEL, government-ID, or third-party personal data. We cannot technically prevent every such entry.

no-sale

We do not sell personal data or use reflections, notes, or AI prompts for advertising, public sharing, unrelated analytics, or unrelated model training.

analytics

No PostHog, Google Analytics, Cloudflare Web Analytics, Sentry, session replay, advertising analytics, or marketing-email system is active for this release.

changes

We may update this policy. Material changes will be posted here and, where appropriate, announced in the app.

contact

Privacy and data-rights requests: privacy@disciplio.me. General support: support@disciplio.me. We usually aim to answer support messages in 3–5 business days; this is a target, not a guaranteed service level.

version

Effective date: 20 July 2026. Document version: 1.0. Reference language: English.

Terms of ServicePrivacy PolicyCookies and Browser Storage Policy
Disciplio

Intelligent planning for a disciplined life.

Product

  • Product
  • Features
  • Pricing
  • Start for free

Company

  • About
  • Contact
  • Support

Resources

  • Resources
  • Terms
  • Privacy
  • Cookies

Follow us

© 2026 Disciplio. All rights reserved.

PrivacyTermsCookiesContactSupport