Undesk — Privacy Policy
Effective date: June 18, 2026 · Last updated: June 18, 2026
Undesk ("the app," "we") is a workday micro-workout app for desk workers that
delivers short, calendar-aware movement sessions. This policy explains exactly
what data Undesk handles. It is operated by Undesk, contact
hello@undesk.fit.
In short: Undesk collects only what it needs to deliver
personalized, calendar-aware notifications. We never read your calendar
events themselves — only free/busy windows. We do not sell your data, and
we use industry-standard services for hosting, push delivery, and basic
product analytics.
What Undesk stores
The following data is stored on our infrastructure (Supabase, hosted in
the United States) so that the app can function across your devices:
- Account data: email address, securely hashed password,
and session tokens.
- Profile data: display name (optional), timezone,
onboarding state, daily session goal.
- Reminder preferences: notification mode (reactive or
proactive), daily count, active hours, minimum spacing between
notifications.
- Calendar integration: if you connect Google Calendar,
we store an encrypted access token and refresh token to query your
free/busy availability. The token is scoped to
calendar.freebusy only — Undesk cannot see the content,
titles, or attendees of your calendar events.
- Push subscriptions: web push endpoints (for web users)
or Apple Push Notification Service device tokens (for iOS users), used to
deliver session reminders.
- Session activity: which sessions you started or
completed, used for streak tracking and to generate session
recommendations.
- Dispatch logs: timestamps and outcomes of reminders
sent to you, used to enforce daily quotas and spacing constraints.
What Undesk sends, and to whom
Undesk uses a small set of third-party services to deliver the product:
- Supabase — authentication, database, and serverless
functions. Your account and app data live here.
- Vercel — hosts the web application and serves it to
your browser.
- Google Calendar API — Undesk queries the free/busy
endpoint at
googleapis.com using your authorized token. We
query only free/busy data (no event content) and only at the times your
reminders are scheduled to fire.
- Apple Push Notification Service — delivers
notifications to your iOS device. Apple receives a device token and
notification payload (the lead-in text and any in-app deep link). The
payload does not contain personal data beyond the standard reminder
message.
- Web Push (browser-native) — delivers notifications to
browsers via the user-agent's push endpoint (e.g., FCM for Chrome, Apple
Push for Safari).
- PostHog — product analytics. We record anonymized
product usage events (e.g., onboarding completed, session started) tied
to a randomized identifier, used to understand which features are useful.
PostHog does not receive your email, password, calendar data, or
session content.
- Sentry — crash and error monitoring. When the app
encounters an error, technical context (stack trace, app version, OS
version) is sent to Sentry. Personally identifying user data is scrubbed
from error reports.
What Undesk does not do
- We do not read, store, or transmit the content of your calendar
events. The Google integration uses the free/busy scope exclusively.
- We do not sell your data, share it with advertisers, or use it for
cross-site tracking.
- We do not access your photos, contacts, location, microphone, or any
other device data beyond what is needed for notifications and the basic
app experience.
- We do not run ads inside the app.
Data retention and deletion
You can delete your account at any time from Settings → Account → Delete
Account. When you delete your account, your authentication record, profile,
preferences, calendar integration, push subscriptions, sessions, and
dispatch logs are permanently removed from our database within 7 days.
Aggregated analytics events (PostHog) that have already been anonymized may
persist for longer in summary form.
You can also disconnect your Google Calendar at any time from Settings →
Calendar → Disconnect. This revokes the stored token and removes the
calendar integration row from our database. Undesk will fall back to
non-calendar-aware notification dispatch.
Security
Calendar OAuth tokens are encrypted at rest in our database using a
server-side key. Authentication passwords are hashed using industry-standard
algorithms and are never stored in plain text. All network traffic between
your device and our infrastructure is encrypted via HTTPS.
No system is perfectly secure, but we apply current best practices and
minimize the data we retain.
Children
Undesk is not directed at children under 13 and does not knowingly
collect data from them.
Changes
We may update this policy from time to time. Material changes will be
reflected by the "last updated" date above and, where appropriate,
announced in the app.
Apple App Store privacy
Undesk's iOS app is distributed via the Apple App Store. Apple's App
Store privacy disclosure ("nutrition label") reflects the same data
practices described above. We do not share data with Apple beyond what is
inherent to App Store distribution and standard iOS frameworks (e.g.,
push notification delivery).
Your rights
Depending on your jurisdiction (e.g., GDPR for EU residents, CCPA for
California residents), you may have the right to access, correct, or
request deletion of your data. To exercise these rights, email us at
hello@undesk.fit.
Contact
hello@undesk.fit