Scope and operator
This Privacy Policy explains how NRTHSTR handles personal information through its websites, applications, and related services. In this draft, “NRTHSTR”, “we”, “us”, and “our” refer to [INSERT LEGAL ENTITY NAME].
This is a development placeholder. The final policy must accurately describe the production product, every material data flow, the countries in which NRTHSTR is offered, and the legal entity responsible for the information.
Replace [INSERT LEGAL ENTITY NAME] and identify any separate controller, processor, or regional representative that applies.
Information we collect
The information NRTHSTR handles depends on the features you use and the choices you make.
- Account information, such as your name, email address, profile details, account identifiers, and authentication-provider information.
- Content you create, such as goals, projects, tasks, notes, labels, schedules, attachments, preferences, and completion history.
- Technical and usage information, such as device type, app version, operating system, language, approximate region, timestamps, diagnostics, crash data, security events, and interactions with features.
- Communications, such as support requests, feedback, survey responses, and messages you send to us.
- Transaction information if paid features are introduced, while complete payment-card details are generally handled by the relevant payment provider rather than NRTHSTR.
- Information received from connected services when you choose to sign in with or connect a third-party provider.
How we use information
We use personal information only for legitimate product, security, support, and legal purposes described in the final policy.
- Provide accounts, authentication, synchronisation, reminders, backups, and the features you request.
- Maintain, troubleshoot, test, secure, and improve NRTHSTR.
- Personalise settings and restore your preferred experience across supported devices.
- Respond to support requests, feedback, and administrative communications.
- Detect, investigate, and prevent fraud, abuse, unauthorised access, and technical harm.
- Comply with legal obligations, enforce agreements, and protect rights, safety, and property.
- Measure product performance and understand feature usage using appropriately limited analytics.
Before launch, map each purpose to the production systems and any legal basis or consent requirement that applies in target regions.
Private content and assisted features
Your goals, tasks, projects, and notes are treated as private account content unless you deliberately use a sharing or collaboration feature.
The current product intention is not to sell private task content or use it for third-party targeted advertising. Confirm this statement against the final business model before publication.
If NRTHSTR introduces AI-assisted features, the final policy must explain what content is sent to model providers, why it is sent, available controls, retention settings, whether content is used for model training, and any human-review process.
Do not ship an AI feature under this placeholder alone. Add feature-specific disclosure and vendor details first.
Service providers and international processing
NRTHSTR may use service providers located in different countries. As a result, information may be stored or processed outside the country where you live.
The final policy must name or categorise the important providers, identify relevant storage regions where practical, and describe the safeguards used for international transfers where required.
Complete a production vendor inventory covering authentication, database, storage, analytics, crash reporting, email, notifications, payments, support, and AI providers.
Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in the final policy, including providing the service, maintaining security and backups, resolving disputes, and meeting legal obligations.
When an account or content is deleted, removal from active systems may not be immediate, and limited copies may remain temporarily in backups or where retention is legally required. The final policy should publish realistic deletion and backup timelines.
Define concrete retention periods for active accounts, deleted accounts, backups, logs, support records, analytics, and financial records.
Security
We use administrative, technical, and organisational measures intended to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.
No system is completely secure. You should protect your devices and sign-in methods, use strong authentication where available, and contact us promptly if you suspect unauthorised account activity.
Your choices and rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain uses of your personal information, withdraw consent, or complain to a privacy regulator.
NRTHSTR should provide practical in-product controls for profile changes, connected accounts, notification preferences, export, and account deletion wherever those features apply. We may need to verify your identity before completing a privacy request.
Until a dedicated request flow is available, contact [INSERT LEGAL CONTACT EMAIL].
Document the request-verification process, response workflow, exceptions, appeal process, and regional rights before public release.
Children
NRTHSTR is not intended for children below the minimum age stated in the final policy. We do not knowingly collect personal information from children in circumstances where parental consent is required but has not been obtained.
If we learn that information was collected contrary to the final age requirements, we will take reasonable steps to delete it or obtain any required authorisation.
Set the minimum age and parental-consent model consistently across onboarding, app-store listings, Terms of Use, and this policy.
Cookies and analytics
NRTHSTR websites may use cookies, local storage, or similar technologies for essential functions such as authentication, security, preferences, and session continuity.
If non-essential analytics, advertising, or marketing technologies are introduced, the final policy and consent controls must describe them and provide the choices required in the regions where NRTHSTR operates.
Changes, questions, and complaints
We may update the final Privacy Policy as NRTHSTR, its providers, or legal obligations change. The published policy should show its effective date and explain how users will be notified of material changes.
Privacy questions, requests, and complaints should be sent to [INSERT LEGAL CONTACT EMAIL].
The final policy should also identify the responsible privacy contact, a postal address where required, and the relevant escalation or regulator information for supported regions.
Create and monitor the privacy mailbox, assign an owner, and add the final complaint-escalation process.