Política de privacidade
Esta página está disponível apenas em inglês.
This policy explains what personal data Sunlet handles when you use the website at sunlet.app, the web app, the installable phone app and the macOS app, why we handle it, and the choices you have. If anything here is unclear, write to hello@sunlet.app.
What we collect
- Account details. Your name and email address. If you sign up with a password, it is stored only as a secure hash. If you sign in with Google, Apple or Microsoft, we receive your name and email address from that provider.
- What you put into Sunlet. Tasks, notes, lists, tags, subtasks, dates, times and plans, plus settings such as language and time zone. Deleted tasks stay recoverable in Settings.
- Assistant conversations. The messages you send to the assistant, its replies, and the changes it proposes, so you can continue a conversation and undo changes.
- Billing. If you subscribe to Pro, payment is handled by Stripe. We receive your subscription status, plan, currency and country. We never see or store full card numbers.
- Feedback you send from the app.
- Reminders. If you turn on notifications, a push subscription for that device so we can deliver reminders.
- Usage and device data. Pages and screens viewed, clicks, errors, performance measurements, browser and device type, and approximate location derived from your IP address. We also record sessions to see where the product is confusing; text you type into fields is masked in these recordings.
How we use it
- To run Sunlet: store and sync your tasks across devices, keep them available offline, and send reminders you ask for.
- To send account emails, such as email verification and password resets.
- To answer your assistant requests.
- To handle subscriptions and plan limits.
- To keep the service secure, for example by limiting the number of requests and detecting abuse.
- To understand how Sunlet is used and improve it.
We do not sell your personal data, and we do not use your tasks for advertising.
Legal bases
Where the GDPR or similar laws apply, we rely on these legal bases: performing our contract with you (running your account, sync, the assistant, billing); our legitimate interests (security, fixing errors and improving Sunlet); your consent (notifications, which you can turn off at any time); and legal obligations (for example keeping billing records).
The assistant
When you use the assistant, your message and the task details it needs to answer are sent to our AI provider, OpenAI, and some requests may be processed by AI models running on Cloudflare. OpenAI states that data sent through its API is not used to train its models by default. Our product analytics record that an assistant request happened, how long it took and whether it failed, but not the text of your conversation or your tasks. The assistant only proposes changes; nothing in your workspace changes until you apply them.
Service providers
We use a small number of providers to run Sunlet. They process data on our behalf and only for these purposes:
- Cloudflare: hosting, database, network delivery and some AI models.
- OpenAI: processing assistant requests.
- Resend: sending account emails.
- PostHog (EU hosting): product analytics, error reports and session recordings.
- Stripe: payments. Stripe sells Pro subscriptions as merchant of record and handles payment details and taxes under its own privacy policy.
- Google, Apple and Microsoft: only if you choose to sign in with them, and Apple, Google and Mozilla push services to deliver notifications you turn on.
Some of these providers process data outside the European Economic Area, including in the United States. Where that happens, transfers rely on safeguards such as the European Commission's standard contractual clauses or an adequacy decision.
Cookies and storage on your device
Sunlet uses a cookie to keep you signed in, and your browser's storage for preferences such as language and theme, offline copies of your tasks and edits waiting to sync. Our analytics provider, PostHog, sets its own cookie to recognize returning visits. You can clear these at any time in your browser settings; signing out removes the sign-in cookie.
How long we keep data
We keep your account and everything in it for as long as your account exists. When you delete your account in Settings, your account, tasks, lists, assistant conversations, feedback and reminder subscriptions are deleted from our database. Copies may remain in backups for a short period before they are overwritten. Billing records are kept by Stripe and by us for as long as tax law requires. Analytics data is kept for a limited period and then deleted.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, to restrict or object to its use, and to withdraw consent. Many of these you can do yourself: export your tasks and delete your account in Settings. For anything else, write to hello@sunlet.app. You also have the right to complain to your local data protection authority.
Children
Sunlet is not intended for children under 16, and we do not knowingly collect their data.
Changes
We will update this page when our practices change and change the date at the top. If a change is significant, we will tell you in the app or by email before it takes effect.
Contact
Questions or requests about your data: hello@sunlet.app. See also our Terms of Service.