Privacy Policy
Effective 29 July 2026
Draftly (the “planner”, “we”, “us”) is operated by Gavin Adams (Australia). This page explains what information the planner keeps, why, and how you can see, export, or delete it at any time. If anything here is unclear, email admin@draftly.info.
The short version
Your planner lives on your own device by default. Nothing is sent anywhere unless you deliberately turn on cloud backup or an integration. There are no ads, no analytics trackers, and we never sell or share your data.
What's stored on your device
Everything you type — days, lists, habits, bills, moods, and so on — is saved in your browser's local storage as a single document. Any photos you attach (bill snapshots, receipts, decorative photo spots) are saved in your browser's IndexedDB storage. None of this leaves your device unless cloud backup is turned on — and even then, photos are not included in cloud backup; they stay local to the device that took or uploaded them.
Optional cloud backup (Google sign-in)
If you choose to “sign in with Google” in Settings, we store your email address and your planner document (the same JSON that's on your device) in our database, tied to your account, so it can follow you to another device. Row-level security means only you can read or write your own row — not other users, and not us, outside of responding to a support request you initiate.
Turning cloud backup off (sign out) stops future syncing; it does not by itself delete what's already stored — see “Deleting your data” below for that.
Optional integrations (Google Calendar, Gmail)
Connecting Calendar or Gmail in Integrations asks Google for read-only access, used only to pull relevant events or messages into your planner view. We never post, send, edit, or delete anything in your connected Google account.
What Google data we access
We request exactly two scopes, both read-only:
-
Google Calendar (
calendar.readonly) — we read the upcoming events (the next 90 days) on your primary calendar so your planner can show what's on that day. From each event we read its title, its start date and time (including whether it is an all-day event), its location, and its description. We do not read guest lists, attachments, or any other calendar. -
Gmail (
gmail.readonly) — we read only messages you have starred in Gmail (ais:starredquery, up to 50 of the most recent). From each starred message we take only the sender name, the subject line, and Gmail's own short preview snippet. We do not read your unstarred mail, your full message bodies, your attachments, or your contacts.
How we use it
Calendar events are displayed in your planner's day view. Starred emails become “waiting on” items in your lists, so you can act on them without switching back to Gmail. That is the entire purpose. This data is never used for advertising, never used for credit or lending decisions, never used to build a profile of you, and never used to develop, improve or train any AI or machine-learning model — ours or anyone else's. The planner sends no Google user data to any AI service.
Where it's stored, and for how long
Appointments imported from your calendar are saved into your planner document — an appointment that vanished on refresh would be useless. Each sync refreshes the imported appointments in place rather than piling up copies.
Items created from starred emails are saved into your planner document for the same reason. That means the sender, subject and preview snippet of a starred email — and the title, time, location and description of a calendar event — are stored on your device, and, if you have cloud backup switched on, in your own row in our database. They stay there until you delete the item or appointment, clear the planner, or delete your account. Deleting the list item or appointment removes those details.
Your Google authorisation itself is stored as a refresh token in a separate, own-row-protected table and exchanged for short-lived access tokens on demand. The underlying Google client secret is held server-side and is never exposed to any browser. Disconnecting an integration deletes that refresh token immediately.
Who we share it with
Nobody. We do not sell, rent, trade or transfer Google user data — raw, aggregated or anonymised — to any third party, for any purpose. There are no data brokers, no advertisers, no analytics processors and no AI vendors in this product. The only party that ever holds this data besides you is our hosting and database provider, Supabase, which stores your own row on our behalf as infrastructure and does not access or use it for its own purposes.
How we protect it
All traffic between your browser, our servers and Google's APIs runs over HTTPS (TLS). Data stored in our database is encrypted at rest by the hosting provider. Access is restricted by row-level security, so a signed-in account can read and write only its own row — a policy enforced by the database itself, not by application code that could be bypassed. Google refresh tokens are held in a separate table under the same row-level protection, and are never returned to the browser. The Google client secret and all service credentials are stored as server-side environment secrets, never committed to source control and never shipped to any client. Account deletion runs as a privileged server-side routine that removes your planner document, your stored tokens and your sign-in account together.
Google API Services User Data Policy: Draftly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Apple Health has no real integration behind it — there's no public web API for HealthKit — so “connecting” it only unlocks a manual CSV export button. Nothing is transmitted anywhere; the file is generated and downloaded directly on your device.
Deleting your data
Settings gives you three levels, from lightest to most complete:
- Disconnect an integration — removes the stored Google refresh token for that integration immediately.
- Clear planner — wipes everything stored on the current device, including any items created from starred emails and appointments imported from your calendar.
- Delete my account & cloud data — permanently deletes your cloud-stored planner document, any stored integration tokens, and your sign-in account itself. This cannot be undone.
You can also just email admin@draftly.info and ask us to delete anything listed above on your behalf. You can revoke Draftly's access to your Google account at any time, independently of us, at myaccount.google.com/permissions.
No analytics, no ads, no selling data
The planner doesn't run any analytics or advertising trackers, and we don't sell, rent, or share your data with third parties for marketing purposes. The only outside services involved are Google (for optional sign-in/backup/integrations, described above), Supabase (our database and hosting provider) and your browser's own local storage.
Children
The planner isn't directed at children, and we don't knowingly collect information from anyone under 13.
Changes to this policy
If this policy changes, we'll update the effective date above and post the revised version here — there's no separate mailing list to do it through.
Contact & governing law
Questions, requests, or complaints: admin@draftly.info. This policy is governed by the laws of Australia.