AcademiX

Privacy Policy

AcademiX Privacy Policy

Version of 16 September 2026

Contents

This privacy policy is drawn up in Polish and translated into English. If the versions differ in meaning, the Polish version prevails (section 19.6).

This policy explains what data about you the AcademiX app processes, why, who we pass it to, how long we keep it and what rights you have. This is information required by the GDPR (Articles 13 and 14). You do not have to accept it. You accept the terms of service separately when you create an account. We ask for consent to the energy feature and to the AI assistant separately in the app.

1. Who is responsible for your data

1.1. Controller. The controller of your data is Joachim Woźniak, a natural person who does not run a business. Address for service: electronic only — email kontakt@academix.pl. In this policy, “we” means the controller.

1.2. Contact. For all matters concerning personal data, write to kontakt@academix.pl.

1.3. Data protection officer. We have not appointed a data protection officer (DPO). You can handle data matters at the address in section 1.2.

1.4. What we are responsible for. We are responsible for all processing described in this policy, including processing that takes place only on your phone, such as reading Apple Health and calculating energy. However, we have no access to the measurements themselves.

1.5. Where to find this policy. The current version is at academix.pl/polityka-prywatnosci and in the app: Settings → About. The terms of service are at academix.pl/regulamin.

1.6. A few terms.

  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council, the EU rules on the protection of personal data (in Polish: RODO).
  • EEA — the European Economic Area: the European Union plus Iceland, Liechtenstein and Norway.
  • Consent A — Energy from Apple Health and Consent B — AI assistant — the two consents we ask for in the app (section 12).
  • Readiness — a number from 0 to 100 that shows how you are doing today compared with your typical day.
  • Energy windows — the times of day when, by our estimate, you have the most energy for demanding tasks.
  • Apple Health — on iPhone, this is the Health app.

2. What data we collect and where it comes from

2.1. Account and sign-in. We save your email address and account identifier. If you sign in with Apple and hide your address, we get an Apple relay address. When you sign in with Google, we also get your full name, the address of your profile photo and your Google account identifier, and the app passes a Google access token to the Supabase sign-in service. Signing in creates session data: IP address, device and software information, and the time of sign-in and of session refresh. The data comes from you and from Apple or Google. The Supabase sign-in service stores it. We save the first name from your Apple account only on your phone. Sign-in tokens are kept in the iOS Keychain.

2.2. Calendars. When you connect Google Calendar or Apple Calendar, the app fetches the list of calendars (name, color, permissions) and events: title, description, location, start and end, time zone, whether the event lasts all day, guests and identifiers. From Google Calendar we get a guest's name and email address, and from Apple Calendar their name. We fetch events from 12 months back to 12 months ahead. The range grows when you browse further months. Apple Calendar also includes subscribed calendars and the birthdays calendar from Contacts. This data is on your phone. Only the copy described in section 2.3 goes to your account.

2.3. Copy of events in your account. From connected calendars, we save a copy of events in your account: title, start and end, event identifier, source (Google or Apple) and calendar identifier. In Google Calendar, the calendar identifier is usually the email address of its owner. The copy does not include descriptions, locations or guests. Supabase stores it.

2.4. Events we save in your calendars. On your instruction, we save in Google Calendar or Apple Calendar the events you create, change, move or delete in AcademiX, task blocks, blocks of an approved day plan and changes you confirm with the assistant. When you add guests to an event in Google Calendar, their email addresses go to Google.

2.5. Tasks. We save the task title, due time (“when I will do it”), deadline (“by when”), duration, load (light, moderate, demanding), category, priority, flag, whether to remind you, whether the task is completed, creation date and the link to a block in the calendar. The data comes from you. AI can suggest the category and priority if you turn on Consent B (section 2.11). Supabase stores tasks.

2.6. Data from Apple Health (Consent A with the “from Apple Health” scope). The app reads seven data types from Apple Health from the last 90 days: sleep stages, heart rate variability (HRV), heart rate, resting heart rate, steps, wrist temperature during sleep and blood oxygen saturation. It also reads the names of the apps that the HRV and resting heart rate measurements come from. From this data, it calculates readiness, the energy curve during the day and energy windows on your phone. The measurements are only in the phone's memory while the calculation runs. The exception is the file in section 4.3.

2.7. Morning energy rating (Consent A). This is your answer to “How's your energy today?” (a scale from 1 to 5) and today's wake-up time. We save them only on your phone and only if Consent A is on. We ask for them in the morning on the Today screen. Onboarding does not ask for them.

2.8. Onboarding answers, onboarding profile and plan settings. During onboarding before you create an account, on a card on the Today screen and in Settings → Daily plan → Week and sleep, we ask about:

  • what most often ruins your day;
  • what your week looks like (fixed hours, studies, your own rhythm, or shifts and nights), and with fixed hours also what time you start and how long your commute takes;
  • the kind of work you do (mainly thinking, people or movement) — this question is optional, does not change the plan today, and we save the answer to prepare fitting the plan to the kind of work;
  • your usual wake-up time on work or study days — with fixed hours, the app calculates it from your start time and commute, and you confirm or change it;
  • the days on which you usually have no work or classes, and your usual times of falling asleep and waking up on working days and on free days (or information that your alarm also rings on free days).

You can skip any question. We save all answers on your phone as plan settings.

Some of the answers make up your onboarding profile. After you sign in and accept the terms of service, we also save it in your account at Supabase:

  • what most often ruins your day;
  • your kind of week;
  • your kind of work;
  • your usual wake-up time on work or study days — this is what you declare, not a measurement; with shift work there is none;
  • the date of your latest answer or its confirmation.

The onboarding profile tells us who is testing the beta version. On the phone, the answers are also used for the day plan. When you change your answers when you go through onboarding again, in Settings → Daily plan → Week and sleep or on the card on the Today screen, we save the onboarding profile in your account again, and the new one replaces the previous one. Questions you skip do not go to your account.

The following stay only on your phone: free days, sleep times, start time and commute, skipped questions, sleep goal and working days. We do not send this data off the phone.

2.9. Conversation with the AI assistant (Consent B). Your messages (typed, dictated or read from a photo), the assistant's replies and the data in section 5.2. We do not save the conversation in the database or in the phone's permanent storage. It exists only in the memory of the running app and disappears at the latest when the app is closed. It reaches Anthropic through our server function at Supabase.

2.10. Quick Add. The entry text, time zone, the initial recognition of title, date and time done on the phone, and a draft of an unfinished entry, which stays on the phone. With Consent B, the text goes to Anthropic (section 5.4).

2.11. Category and priority from AI (Consent B). The entry category (personal, university, health, work) and the priority chosen by the AI model. This is an inference about what the entry concerns. The “health” category can say something about your health. We save the category and priority in your account together with the event or task.

2.12. Dictation and text from a photo. When you dictate, the app uses the microphone, and the recognized text goes into the field where you are typing. We do not save the recording. Apple recognizes the speech (section 5.13). When you choose a photo, the phone reads the text from it. We do not save or send the photo.

2.13. Acceptance of the terms and decisions about consents. We save the type (acceptance of the terms, Consent A with its scope, or Consent B), the decision (given or withdrawn), the version and language of the text, the app version, the date and time of the decision and the moment it was saved on the server. Before you create an account, the record is only on your phone. After you sign in, it goes to your account at Supabase.

2.14. Messages to us. The content of the email and the sender's address. A report sent from the app (the “Write to us” sheet: a problem, an idea or a data question) is saved in your account in Supabase: the type, your text, the app version, the iOS version, the phone model, the language, the source of today's readiness (Apple Health, the morning answer, the sample profile or none — no numbers or measurements), which calendars are connected, and the date it was written and saved. Reports are read by our team. You do not send screenshots from the app.

2.15. Technical data.

  • The iOS version and the names and versions of software libraries that the app attaches to connections with Supabase and with Google.
  • When you sign in with Google, if Google requests it: information on whether the phone has a passcode set.
  • Server logs: AI model usage counters without content, error codes and, if account deletion fails, the account identifier.
  • The times of your recent requests to the assistant and to Quick Add, needed for the request limit.
  • The account identifier in the addresses of requests that the app sends to the database.

2.16. Notifications. A morning message with fixed content and task reminders with the task title. The phone schedules them. We do not use a notification server.

2.17. Analytics and third-party libraries. We do not put analytics, advertising or crash-reporting tools into the app ourselves. We do not track you in other apps or on websites. The app contains Google's sign-in library (Google Sign-In), which it uses when you sign in with Google and when you connect Google Calendar. According to the privacy declaration included with this library, it collects data linked to the user: for sign-in to work, name, email address, phone number, approximate location, user identifier and other data, and for analytics also device identifier, usage data, user identifier and other data. We describe Google in section 7.3.

2.18. Data we produce ourselves. Readiness, the energy curve and energy windows. The start of the curve and the end of the planning day, set from your usual sleep times until the app knows them from your nights. Proposed times in the day plan. The category and priority from AI.

2.19. Health data. We treat the following as health data: Apple Health measurements, readiness, the energy curve and energy windows, and the morning energy rating with the wake-up time. If you write something in an event title, a task or a message about health, religion, beliefs, sexual orientation or other specially protected matters, that is also specially protected data. This also applies to information about other people.

2.20. Do you have to provide data? Providing data is voluntary. However, your email address and sign-in data are required to create an account and conclude the contract. Consequences of not providing data:

  • without an account you cannot use the app; only onboarding works;
  • without Consent A, the calendar and tasks work, but the app does not read Apple Health, does not save the morning energy rating and does not arrange a day plan based on energy;
  • without Consent B, the assistant and AI suggestions are turned off, and Quick Add recognizes the date and time on the phone;
  • if you do not connect a calendar, you will not see its events in AcademiX;
  • if you skip the onboarding questions, the plan uses default settings, and skipped answers do not go into the onboarding profile in your account.

3. Why we process data and on what legal basis

3.1. The rule. Every processing activity has a legal basis in Article 6 of the GDPR. We process Apple Health data only with your explicit consent (Consent A). We save the morning energy rating and use it for the plan only with your explicit consent (Consent A). We send content to the AI assistant only with explicit consent (Consent B), because it may contain specially protected data. Both are explicit consents within the meaning of Article 9(2)(a) of the GDPR.

3.2. Purposes and legal bases.

  • Account, sign-in and keeping your session (section 2.1) — performance of the contract, that is, the terms of service (Article 6(1)(b) of the GDPR). Without an account we cannot provide the service.
  • Calendar: displaying events, combining Google Calendar and Apple Calendar without duplicates, saving changes on your instruction and the copy of events in your account (sections 2.2–2.4) — performance of the contract (Article 6(1)(b)).
  • Tasks, task blocks in the calendar and reminders (sections 2.5, 2.16) — performance of the contract (Article 6(1)(b)).
  • Onboarding and plan settings: the day plan from your answers (section 2.8) — performance of the contract (Article 6(1)(b)). The answers help arrange the day plan around your week. Usual sleep and wake-up times and free days are plan settings: the times when you usually start and end your day, and the days on which you usually have no work or classes. We lay out the day plan from them on your phone. We do not assess your sleep or health based on them. Every question is voluntary, and you can delete the answers from your phone at any time.
  • Onboarding profile in your account (section 2.8) — legitimate interests (Article 6(1)(f)). We save it to know who is testing the beta version and to adapt the app accordingly. We do not treat the onboarding profile as health data: your usual wake-up time on workdays is the time from which we lay out the day plan, not an assessment of your sleep.
  • Energy: reading Apple Health, the morning energy rating, readiness, energy windows and a day plan based on energy (sections 2.6, 2.7) — Consent A (Article 6(1)(a) and Article 9(2)(a)).
  • The file from the “What I see in Health” screen (section 4.3) — Consent A (Article 6(1)(a) and Article 9(2)(a)).
  • Your energy result in the assistant (section 4.3) — Consent A and Consent B (Article 6(1)(a) and Article 9(2)(a)).
  • AI assistant (sections 2.9, 5.2) — Consent B (Article 6(1)(a) and Article 9(2)(a)).
  • Category and priority suggestions in Quick Add and saving them (sections 2.10, 2.11) — Consent B (Article 6(1)(a) and Article 9(2)(a)).
  • Dictation and reading text from a photo (section 2.12) — performance of the contract (Article 6(1)(b)). After that, we treat the text as if it were typed: it goes to AI only with Consent B.
  • Data of guests and other people (section 6) — legitimate interests (Article 6(1)(f)).
  • Security, request limits and error logs (section 2.15) — legitimate interests (Article 6(1)(f)).
  • Record of acceptance of the terms and of decisions about consents (section 2.13) — legitimate interests (Article 6(1)(f)).
  • Handling your rights under section 10 — legal obligation (Article 6(1)(c) in conjunction with Articles 12–22 of the GDPR).
  • Replying to other messages you send us (section 2.14) — legitimate interests (Article 6(1)(f)).

3.3. Our legitimate interests.

  • Security of the service: protection against abuse and overload, including limits that protect against a loop of requests to the AI provider, and investigating errors.
  • Enabling you to use your own calendar in the app and to get a full answer from the assistant about meetings with other people.
  • Being able to show that we asked for consents and acceptance of the terms, and establishing, exercising and defending legal claims.
  • Replying to the messages you send us.
  • Knowing who is testing the beta version of AcademiX and adapting the app to these people — this is why we save the onboarding profile in your account (section 2.8).

You have the right to object to processing on this basis (section 10.7). If you object to the onboarding profile, we will delete it from your account.

3.4. Health information in titles. We store event and task titles in your account in the form in which you enter them. If you put health information in a title, it goes to your account together with the title. If you do not want that, do not put such information in titles.

3.5. After you withdraw consent, we do not look for another legal basis to keep using the data covered by that consent. What remains: the record of the consent and its withdrawal (section 2.13), entries you approved earlier in the calendar and tasks, plan settings on the phone (section 12.6), and categories and priorities assigned earlier by AI (section 5.12).

3.6. What we do not do. We do not use your data for marketing, advertising or analytics. We do not profile you in any way other than described in section 17.

4. What happens on your phone

4.1. Calculating energy. When you turn on Consent A with the “from Apple Health” scope, the app reads the data in section 2.6 and calculates readiness, the energy curve and energy windows in the phone's memory. With the “from your answer” scope, it calculates them from the morning energy rating and the wake-up time. This is done by an algorithm based on fixed rules, without artificial intelligence (section 17). We do not save the measurements on our server and do not send them to Anthropic. We have no access to them unless you send us the file in section 4.3.

4.2. Writing to Apple Health. The app does not write anything to Apple Health.

4.3. What energy data leaves the phone. Only the following:

  • To the assistant, when both consents (A and B) are on. With every message we send information about the source of the result. When the result comes from an Apple Health measurement, we add readiness (0–100) and the times of energy windows with the date and time zone. When there is no measured result today, including when the result comes from your morning answer, the assistant only gets the information “no result” (or information that the app is showing a preview profile) and the number 50 — the same for everyone, not your result. We do not send the times of energy windows in that case. Our server knows which account this data came from. Anthropic receives it without the account identifier.
  • Day plan. When you approve a plan, we save the block times with task titles in the calendar you choose (Google or Apple), and in your account: the task time, the link to the block and the copy of the event (section 2.3). The algorithm chooses the block times to fit your energy curve.
  • The file from the “What I see in Health” screen. On this screen, the app prepares a temporary file on your phone with data from the last 90 days: nights (falling asleep, waking up, sleep quality, awakenings), HRV and resting heart rate measurements with dates, today's steps, sleep goal, today's energy rating and time zone. The file leaves the phone only if you choose “Share”, and it goes only where you send it. We have no control over the copy held by the recipient. We delete the temporary file from the phone when you close this screen.
  • The data export file. In Settings → Privacy and data → Data export, the app prepares a temporary JSON file on your phone with the data listed in section 10.5. The file leaves the phone only if you choose “Share”, and it goes only where you send it. We have no control over the copy held by the recipient. We delete the temporary file from the phone when you close this screen and when you sign out.
  • Phone backup. If you have iCloud Backup turned on or back up your phone to a computer, iOS includes the data saved by the app (section 4.4) in the backup. You and Apple manage the backup, not us.

4.4. What the app saves on your phone.

  • Morning energy rating and wake-up time — to calculate today's energy. We use them only on the day they were given. We delete them when you turn off Consent A, sign out or delete your account.
  • Onboarding answers, sleep goal and working days (plan settings) — for the day plan. You can see, change and delete the answers in Settings → Daily plan → Week and sleep (“Delete answers”). This button deletes the answers from the phone. The onboarding profile in your account remains as described in section 9.13. You can change the sleep goal in Settings → Daily plan → Sleep goal. There is no delete button there, and when you sign out, the sleep goal returns to the default value. We delete plan settings from the phone when you sign out and when you delete your account.
  • Record of acceptance of the terms and of decisions about consents — so that the app knows what you have agreed to. We delete it from the phone when you sign out and when you delete your account. In your account it remains as described in section 9.5.
  • Event cache from connected calendars, including descriptions, locations and guests — to show the calendar quickly. We overwrite it at every sync and delete it when you sign out.
  • Calendar settings: which calendars are visible, the default calendar with the Google account address, and connection status — to display and save events. We delete them when you sign out, except for the information that Apple Calendar has been connected on this phone.
  • Decisions on plan proposals (task title, day, choice, times) — so that we do not propose the same thing a second time. We delete them after 14 days and when you sign out.
  • Quick Add draft — to restore an unfinished entry. It disappears after saving, after clearing and when you sign out.
  • First name from your Apple account — for the greeting. It stays after you sign out. We delete it when you delete your account.
  • Supabase and Google sign-in tokens in the iOS Keychain — to keep you signed in and to access Google Calendar. We delete them when you sign out.
  • Scheduled notifications — a reminder disappears after it is shown or when you complete or delete the task. We also delete scheduled task reminders when you sign out and when you delete your account. The morning message repeats every day. You can turn notifications off in iOS settings.
  • Preferences: language, view layout, last tab, information on which explanatory screens have already been shown and whether you have completed onboarding. We delete some of them when you sign out, the information about onboarding when you delete your account, and the rest is removed only when you delete the app.
  • The file from the “What I see in Health” screen — we delete it when you close this screen (section 4.3).
  • The data export file — we delete it when you close the export screen and when you sign out (section 4.3).
  • Focus session (Deep Work) records from an earlier test version, if the feature was used: duration and readiness result at the start. We delete them when you sign out and when you delete your account (sections 11.4 and 11.9).

4.5. Why these records exist. They are needed for the features you use to work. We are responsible for processing on the phone in the same way as for processing on the server (section 1.4). Section 10.6 explains how to see and delete this data.

5. AI assistant and Quick Add suggestions

5.1. When. Only after you turn on Consent B. Without it, the Assistant tab sends no data either to our server function or to Anthropic, and Quick Add recognizes the date and time on the phone. At the start of a conversation, the assistant says that it is AI and that its replies are generated by a language model.

5.2. What goes to Anthropic when you send a message to the assistant. You send a message with the button, with the Return key or by choosing a suggestion. After dictation, it is sent automatically: when no new words appear for 2.5 seconds, dictation ends, and after another 2 seconds the message is sent, unless you tap the text field before then. Together with the message we send:

  • events from calendars visible in AcademiX, from 7 days back to 45 days ahead, at most 120 (20 past and 100 upcoming): title, start and end, whether the event lasts all day and whether it is read-only, location and guests (at most 8 per event, each as a full name or an email address). We replace event identifiers with sequence numbers;
  • incomplete tasks, at most 100: title, planned time, deadline, load and duration;
  • the conversation from the current screen: up to the last 36 messages, yours and the assistant's;
  • the current time rounded to 5 minutes, the time zone, week boundaries and the app language;
  • with both consents, the energy data in section 4.3.

5.3. What we do not send to Anthropic. Event descriptions and notes, calendar names and colors, completed tasks, Apple Health measurements, your email address, the name from your account or your account identifier. Our server function checks your sign-in token to know that it is you and to count the request limit. It does not pass the token to Anthropic.

5.4. Quick Add. While you type, the text is sent automatically, without pressing a button: from 3 characters, half a second after each change. Together with it we send the time zone and the initial recognition of title, date and time done on the phone. Dictated text, text read from a photo and text restored from a draft are sent in the same way. If the suggestion does not arrive before a new entry is saved, we send the text once more after saving, unless you set the category and priority manually. When you edit an existing task, we do not send the text. From the model's reply, the app takes the category and priority. If the reply arrives before saving, you will see them and can change them before saving. If it arrives after saving, the app adds them to the entry, only in the fields that were not set manually. You can later change a task's category and priority when you edit the task.

5.5. Purpose. Only to prepare the assistant's replies and proposals and the category and priority suggestions.

5.6. The assistant only proposes. An event is created, moved or deleted, and a task is saved, only when you confirm the proposal or save the edit form. The assistant does not change read-only events. The model chooses the entry's category, including “health”. It is saved together with the entry after your confirmation.

5.7. AI can make mistakes. Replies are generated by a language model and can contain errors. Check them before you rely on them. The assistant is for planning your calendar and tasks. Its replies are not medical or legal advice.

5.8. Provider. Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland. We use the Claude language model (currently Claude Haiku 4.5). Anthropic processes data on our behalf under a data processing agreement.

5.9. Model training. Under the terms of the agreement, Anthropic does not train models on the data we pass to it. We do not turn on the option to share data for training and do not send Anthropic ratings of replies. Data from Google is not used to train any AI models (section 13).

5.10. How long Anthropic keeps data. Anthropic deletes inputs and replies within 30 days of receiving or generating them. It keeps them longer only when its safety system flags a conversation as violating the rules for using the service (content for up to 2 years, and the result of that assessment for up to 7 years), and when the law requires it. To reply faster, Anthropic remembers the conversation together with the data in section 5.2 for a few minutes and then deletes it. The app has no function that would delete this data at Anthropic sooner.

5.11. Where. Anthropic stores data in the USA and processes it in the USA, Europe, Asia and Australia (section 8.3).

5.12. When you withdraw Consent B, the app immediately stops sending data to Anthropic, and the assistant and AI suggestions are turned off. Anthropic deletes data sent earlier as described in section 5.10. Categories and priorities assigned earlier by AI stay with the entries. For tasks, you can change them when you edit the task. For events, write to us — we will delete them.

5.13. Dictation. An Apple service turns speech into text. The recording may go to Apple's servers — iOS decides this. Do not dictate health information or other data that you do not want to pass to Apple. The recognized text goes into the field where you are dictating, and then as described in section 5.2 or 5.4.

5.14. What to keep in mind. Event and task titles, guests and your messages go to Anthropic in the form they are in. If they contain information about your health, your beliefs or other people, that information goes there too.

6. Data of other people

6.1. Who this concerns. Guests of events in our users' calendars, owners of shared calendars and senders of invitations, people mentioned in the titles, locations and content of events, tasks and conversations, and people in the birthdays calendar. This section is also information for these people (Article 14 of the GDPR).

6.2. Where we get the data. From the AcademiX user: from the calendars they connected and from the content they entered. We do not collect data from public sources.

6.3. What data. A guest's name and email address (from Google Calendar), a guest's name (from Apple Calendar), the calendar identifier (in Google, usually an email address), the title and other event information entered by the user, and entries from the birthdays calendar (title and date).

6.4. What we do with it.

  • We show it to the user on their phone.
  • Event titles and calendar identifiers go into the copy of events in the user's account at Supabase (section 2.3). We do not save guest data on the server.
  • When the user turns on Consent B, event data goes to Anthropic so that the assistant can answer about the user's plan. It includes at most 8 guests per event, each as a full name or an email address.
  • When the user creates an event with guests in Google Calendar in the app, the guests' email addresses go to Google.
  • We do not build a contact database and do not send messages to guests ourselves.

6.5. Legal basis. Legitimate interests (Article 6(1)(f) of the GDPR): enabling the user to use their calendar in the app and the assistant. We limit the guest data sent to AI to the data in section 6.4.

6.6. How long. The same as the user's event data (section 9). At Anthropic, as described in section 5.10.

6.7. Recipients and transfers outside the EEA. Supabase and Anthropic (section 7), and, when events with guests are saved in Google Calendar, also Google. Supabase Pte. Ltd. is based in Singapore, and Anthropic stores data in the USA and also processes it in other countries. We describe the safeguards in section 8.

6.8. Rights of other people. If your data is in the calendar of an AcademiX user, you have the right of access to it, to its rectification, erasure and restriction of processing, the right to object and the right to lodge a complaint with the President of UODO (section 10). Write to kontakt@academix.pl.

7. Who we pass data to

7.1. Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. It processes data on our behalf under a data processing agreement. It runs the account database, the sign-in service, server functions (assistant, Quick Add, account deletion) and logs. The company is based in Singapore. The database and server functions run in Ireland, on Amazon Web Services infrastructure. Supabase uses sub-processors, including Supabase, Inc. (technical support, USA) and Amazon Web Services, Inc. (hosting). List of sub-processors: supabase.com/legal/customer-resources/subprocessor-list.

7.2. Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland. It processes data on our behalf under a data processing agreement. It provides the AI model for the assistant and Quick Add suggestions. The company is based in Ireland. It stores data in the USA and processes it in the USA, Europe, Asia and Australia. For security, support and incidents, Anthropic group companies in the USA, the United Kingdom, Canada, Switzerland, France, Japan, Germany, South Korea and Australia also have access to the data. Anthropic's sub-processors, including Google Cloud Platform, Amazon Web Services, Microsoft Azure and Cloudflare, operate worldwide. List of sub-processors: trust.anthropic.com/subprocessors.

7.3. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A separate controller. This concerns signing in with Google and Google Calendar, which is a source of data and the place where we save events on your instruction. Google processes data under its own policy: policies.google.com/privacy.

7.4. Apple Distribution International Limited (Ireland). A separate controller when you sign in with Apple and for Apple's email relay. If we reply to a relay address, the message passes through Apple. Apple also recognizes speech during dictation (section 5.13). According to Apple, data is generally stored by Apple Inc. in the USA. Apple's policy: apple.com/legal/privacy.

7.5. Email provider that hosts the kontakt@academix.pl mailbox. It stores the messages you send us.

7.6. Recipients you choose. The file from the “What I see in Health” screen or an email sent through the system share sheet goes wherever you send it.

7.7. Apple features on the phone. Apple Health, Calendar, reading text from photos, notifications and the Keychain work on the phone. To that extent, we do not pass data to Apple. You and Apple manage Apple Calendar syncing in iCloud and the phone backup.

7.8. No sale of data. We do not sell data and do not share it with advertisers or data brokers.

7.9. Data protection at recipients. Supabase and Anthropic process your data under data processing agreements (Article 28 of the GDPR), which oblige them to protect data in line with the GDPR. Google and Apple are separate controllers and protect data under their own policies.

8. Transfers of data outside the EEA

8.1. Supabase. Supabase is based in Singapore, outside the EU, so we have signed with it a model contract of the European Commission, in which it undertakes to protect data as in the EU. This model contract is the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 2: controller to processor). They are part of the data processing agreement with Supabase Pte. Ltd. We use them because the European Commission has not found that Singapore provides an adequate level of data protection. The database and server functions run in Ireland.

8.2. Supabase sub-processors. Supabase uses sub-processors, including in the USA, and support staff in various countries that it does not name. We will send you information about the safeguards for these transfers on request (section 8.6).

8.3. Anthropic. We pass data to Anthropic Ireland, Limited in Ireland, that is, in the EEA. However, Anthropic stores it in the USA and routes requests to data centers in the USA, Europe, Asia and Australia. Outside the EEA, Anthropic group companies in the USA, the United Kingdom, Canada, Switzerland, Japan, South Korea and Australia, as well as infrastructure sub-processors operating worldwide, also have access to the data. European Commission decisions on an adequate level of protection cover the United Kingdom, Switzerland, Canada (commercial organizations), Japan and South Korea. There is no such decision for Australia or for the transfer of this data to the USA. Anthropic does not name the countries in Asia to which traffic goes. We will send you information about the safeguards Anthropic applies on request (section 8.6).

8.4. Google and Apple. As separate controllers based in Ireland, they inform about their transfers outside the EEA in their own policies (sections 7.3 and 7.4).

8.5. No consent to transfers. We do not base regular transfers outside the EEA on your consent to the transfer or on other derogations under Article 49 of the GDPR.

8.6. Copy of the safeguards. Write to kontakt@academix.pl, and we will send you a copy of the standard contractual clauses used with Supabase and information about the safeguards on the side of Supabase and Anthropic. Text of Decision 2021/914: eur-lex.europa.eu.

9. How long we keep data

9.1. Account and sign-in data (email address, identifier, data from Google or Apple, sessions with IP address and device information) — until you delete your account.

9.2. Tasks — until you delete the task or delete your account. A deleted task disappears from the database after 5 seconds, during which you can tap “Undo”.

9.3. Copy of events — until you delete your account. Before that, we delete the copy of an event you delete in AcademiX, and copies from Google Calendar or Apple Calendar when you disconnect that calendar.

9.4. Category and priority from AI — as long as the entry they belong to.

9.5. Record of acceptance of the terms and of decisions about consents — for as long as you use your account and for 6 years after you delete it. This is the general limitation period for claims (Article 118 of the Polish Civil Code). Before you create an account, the record is only on your phone (section 4.4).

9.6. Conversation with the assistant — we do not save it. It stays in the app's memory at most until the app is closed.

9.7. Data passed to Anthropic — up to 30 days, with the exceptions in section 5.10.

9.8. Technical logs at Supabase — up to 7 days.

9.9. Database backups — in line with the provider's (Supabase's) terms.

9.10. Emails to us — up to 12 months after the matter is closed.

9.11. Times of recent requests for the request limit — only in server memory: the account identifier and the times of your recent requests. Times older than 60 seconds are deleted at your next request, and everything disappears when the server restarts the function.

9.12. Data on the phone — as described in section 4.4.

9.13. Onboarding profile in your account (section 2.8) — until you delete your account or object (section 10.7). When you change your answers, the new onboarding profile replaces the previous one. “Delete answers” in Settings and signing out do not delete the onboarding profile from your account.

10. Your rights

10.1. Access (Article 15 of the GDPR). We will tell you whether we process data about you and what data, and send you a copy of it: account and sign-in data (including data from Google or Apple, and IP addresses and device information from sessions), tasks, copies of events, the onboarding profile, the record of acceptance of the terms and of decisions about consents, the names of recipients and information about transfers outside the EEA. The first copy is free of charge.

10.2. Rectification (Article 16). You can correct tasks and events in the app. Category and priority work differently. For tasks, you can change them when you edit the task. For events, write to us — we will delete them. For other data, write to us.

10.3. Erasure (Article 17). Delete your account in the app (section 11) or write to us. We will also delete the onboarding profile from your account without deleting the account — an email is enough.

10.4. Restriction of processing (Article 18). Write to us.

10.5. Data portability (Article 20). You can download a copy of your data in the app: Settings → Privacy and data → Data export. The app prepares a JSON file on your phone with account and sign-in data, the onboarding profile, tasks, decisions on plan proposals, settings (including the “Week and sleep” answers, which are only on your phone), the record of terms acceptance and consent decisions, and focus sessions saved on the phone. The file goes only where you send it (section 4.3). The file does not include copies of events — they are in your Google and Apple Calendar; we will email you the copy from your account within one month on request. It also does not include readiness and energy windows, because they are calculated data that we do not have on the server. You can see them in the app.

10.6. Data that is only on your phone. You can see Apple Health measurements on the “What I see in Health” screen and your morning energy rating on the Today screen. You can see, change and delete onboarding answers from your phone in Settings → Daily plan → Week and sleep, and change the sleep goal in Settings → Daily plan → Sleep goal. You stop reading Apple Health by turning off Consent A. You can also change the app's access to Apple Health in iOS settings. We have no copy of this data, so we cannot send it to you by email. The exception is the onboarding profile, which we have in your account (sections 2.8 and 10.1). Section 4.4 explains when we delete data from the phone.

10.7. Right to object (Article 21). You can object at any time to the processing of your data that we base on legitimate interests (section 3.3). After you object, we stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. Send your objection to the onboarding profile (section 2.8) to kontakt@academix.pl, and we will delete it from your account. The app does not yet have a switch that turns off saving the onboarding profile. If you later answer these questions again or confirm your answers, the onboarding profile will return to your account. To avoid this, delete your answers in Settings → Daily plan → Week and sleep and skip these questions. People whose data is in a user's calendar have this right as described in section 6.8.

10.8. Withdrawing consent. You can withdraw any consent at any time, as easily as you give it (section 12.5). Withdrawal does not affect the lawfulness of processing carried out before it.

10.9. Automated decisions. We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. Details: section 17.

10.10. How to make a request. Use the feature in the app or write to kontakt@academix.pl from the email address linked to your account. We confirm your identity through your signed-in account or the account's email address. We do not ask for a scan of an identity document. If you sign in with Apple with a hidden address, write from any address. We will then agree with you how to confirm that the account belongs to you.

10.11. Deadline. We respond without undue delay, at the latest within one month. For complex or numerous requests, we can extend this by another two months. We will tell you so within the first month. Handling requests is free of charge. If we refuse, we will give the reason and inform you of the right to lodge a complaint.

10.12. Informing recipients. We inform the recipients to whom we disclosed data about rectification, erasure or restriction of processing, unless this is impossible or involves disproportionate effort. At your request, we will tell you who these recipients are.

10.13. Complaint. You can lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO): ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland, uodo.gov.pl, e-Delivery address (e-Doręczenia): AE:PL-67085-31860-RWFHC-35. You can also lodge it with the supervisory authority in the EU country where you live or work, or where the infringement took place. You also have the right to go to court.

11. Deleting your account and signing out

11.1. Where. In the app: Settings → Account → Delete account. Before deletion, you will see what will be deleted and confirm your decision twice.

11.2. What we delete from the server immediately. Your account in the Supabase sign-in service together with sessions and data from Google or Apple, your profile, including the onboarding profile, tasks, copies of events and categories assigned by AI.

11.3. Google and Apple. We ask Google and Apple to revoke AcademiX's access. This does not always work (for example, without an internet connection). If revoking Google access fails, the “Account deleted” message tells you so — then remove the access in your Google account settings (Security → Your connections to third-party apps and services). Check Apple access in your Apple Account settings (Apple's instructions).

11.4. On the phone, we sign you out and delete AcademiX data: morning energy ratings, onboarding answers, plan settings, the record of consents, the event cache, calendar settings, drafts, decisions on plan proposals, saved focus sessions, the data export file, sign-in tokens, the first name from your Apple account, the information that you have completed onboarding, and scheduled task reminders. Data that iOS included in a phone backup stays in that backup.

11.5. Confirmation or error. After successful deletion, you will see the message “Account deleted”. If deletion fails, you will see the message “We couldn't finish deleting your account. The account may still exist, and some data may already be gone.” Try again or write to kontakt@academix.pl. We will then delete the account without undue delay, at the latest within one month.

11.6. The record of consents remains. We keep the record of acceptance of the terms and of your decisions about Consent A and Consent B for 6 years after the account is deleted (section 9.5). We need it to be able to show that we asked for consent and to defend against claims (Article 6(1)(f) of the GDPR). We do not use it for anything else.

11.7. What disappears later, according to the retention periods:

  • data passed to Anthropic — as described in section 5.10;
  • database backups — in line with Supabase's terms;
  • technical logs at Supabase — after 7 days at the latest;
  • emails sent to kontakt@academix.pl and reports sent from the app — up to 12 months after the matter is closed; reports from the app are also deleted together with your account.

11.8. What we do not delete, because it is outside our control:

  • events and blocks that AcademiX saved in your Google or Apple calendar — these are your calendars, so you delete them in the calendar;
  • recordings processed by Apple during dictation, if they were sent;
  • data held by Google and Apple (Google account, Apple Account);
  • files you shared and the phone backup.

11.9. Signing out does not delete your account. Your account, tasks, copies of events, the onboarding profile and the record of consents stay on the server. From the phone, we then delete morning energy ratings, onboarding answers, plan settings, the record of consents, the event cache, calendar settings, the Quick Add draft, decisions on plan proposals, saved focus sessions, the data export file, sign-in tokens and scheduled task reminders. When you sign in again, the app downloads the state of your consents from your account (section 12.5). It does not download the onboarding profile back to the phone.

12. Consents and withdrawing them

12.1. Two consents. AcademiX asks for two consents. Both are turned off by default and are separate from the terms of service and from each other. The calendar and tasks work without them.

12.2. Consent A — Energy from Apple Health has two scopes:

  • from Apple Health — reading 7 data types from the last 90 days from Apple Health (section 2.6), calculating readiness and energy windows on the phone, and the morning energy rating and wake-up time;
  • from your answer — only the morning energy rating and wake-up time, without reading Apple Health.

Both scopes cover saving the morning energy rating and wake-up time on the phone, a day plan based on energy and saving the times of approved plan blocks in the calendar. A measured result goes to the AI assistant only with the “from Apple Health” scope and only with Consent B (section 4.3). Without Consent A, the app does not read Apple Health and does not save the morning energy rating. We ask for this consent on an app screen before the Apple Health system prompt appears and before we save your first morning rating.

12.3. Consent B — AI assistant covers passing to Anthropic the content needed by the assistant and by Quick Add suggestions (sections 5.2 and 5.4). We ask for it before your first message to the assistant and before the first Quick Add suggestion. Your energy result goes to the assistant only with both consents.

12.4. How you give consent. By tapping “I agree” on the consent screen. You can refuse just as easily by choosing “Not now”. This answer does not block the calendar or tasks. On the Consent A screen with Apple Health you have three equal buttons: “I agree”, “Morning answer only” and “Not now”. “Morning answer only” is consent in the narrower “from your answer” scope, without Apple Health. The text of Consent A and Consent B ends with a statement that you are 16 or older (section 15.2), and below the text there is a link to this policy. We record every giving and withdrawal of consent as described in section 2.13. If we change the content of a consent, for example by adding a new purpose, new data sent off the phone, a new recipient or a new type of data from Apple Health, we will ask you for consent again.

12.5. How to withdraw. In the app: Settings → Privacy and data → Consents. Withdrawal takes effect immediately, but not retroactively. The app refreshes the state of your consents from your account every time you return to the app. This way, withdrawing a consent on one phone also takes effect on another phone with the same account when you open the app on it. If decisions were made on different phones, the one the server saved last applies.

12.6. After you withdraw Consent A, the app stops reading Apple Health, calculating energy and sending energy results to the assistant. We delete today's energy rating and wake-up time from the phone. Plan settings (answers about your week and sleep, sleep goal, working days) stay on the phone, and the onboarding profile stays in your account. You can delete the answers in Settings → Daily plan → Week and sleep, and change the sleep goal in Settings → Daily plan → Sleep goal. Plan blocks you approved earlier stay in the calendar and with the tasks. You change the app's system access to Apple Health separately in iOS settings.

12.7. After you withdraw Consent B, the app stops sending data to Anthropic, the assistant and AI suggestions are turned off, and Quick Add recognizes the date and time on the phone. Section 5.12 describes categories assigned earlier.

12.8. iOS system permissions are separate from Consent A and Consent B and do not replace them: Apple Health (read), Calendar (full access to events, to display and save them), Microphone and Speech Recognition (dictation), and Notifications. You can change them in iOS settings. Choosing a photo to read text from does not require access to your whole photo library.

12.9. Disconnecting calendars.

  • Apple Calendar can be disconnected in Settings → Connections → Apple Calendar → “Disconnect Apple Calendar”. Apple events then disappear from AcademiX and from the copy in your account. The calendars on your phone stay unchanged. Turning off Calendar access in iOS settings on its own does not delete the copy from your account.
  • Google Calendar can be disconnected in Settings → Connections → Google Calendar → “Disconnect Google Calendar”. Google events then disappear from AcademiX and from the copy in your account, and the app revokes its access to your Google account. The calendar in your Google account stays unchanged. If revoking access fails, the app tells you and points to the Google account settings where you can do it yourself. If you sign in with a Google account, disconnecting the calendar does not sign you out, but the next sign-in with that Google account connects the calendar again (Google asks for access together with sign-in). Revoking access in your Google account settings alone, without disconnecting in the app, does not delete the copy from your AcademiX account — in that case disconnect the calendar in the app or write to us.

12.10. Notifications. When you allow them in the iOS system prompt, the app schedules a morning message at 7:30 and task reminders with the task title. Whether the title is visible on the lock screen depends on your iOS settings. We do not send marketing notifications.

13. Data from Google

13.1. What data. From signing in with Google: email address, full name, profile photo address and account identifier. From Google Calendar: the list of calendars and events with the data in section 2.2. On your instruction, we create, change and delete events in Google Calendar.

13.2. Scope of access. When you sign in with Google and when you connect Google Calendar, we ask for full access to Google Calendar. We use it only to read the list of calendars and events and to create, change and delete events on your instruction.

13.3. How we use it. To display the calendar, to combine it with Apple Calendar without duplicates, for the day plan, to save changes on your instruction, for the copy of events in your account (section 2.3) and, after Consent B, for the AI assistant.

13.4. Where it is kept and who we pass it to. On the phone (cache), at Supabase (sign-in data in section 2.1 and the copy of events) and, after Consent B, at Anthropic. We do not pass it to anyone else, we do not sell it and we do not use it for advertising.

13.5. Statement of compliance with Google's policies.

13.6. What this means in practice. We use data from Google only in features visible in the app. We pass it to Anthropic only as part of the assistant you use, and only after Consent B. People on our team do not read this data unless you agree to it for specific data, security requires it (for example, investigating abuse) or the law requires it.

13.7. AI models. Data obtained through Google Workspace APIs is not used to develop, improve, or train non-personalized AI and/or ML models. This includes data from Google Calendar.

13.8. Copies of Google data. We keep the copy of events from Google Calendar in your account for the period in section 9.3.

13.9. Signing in with Apple and Google Calendar. If you sign in with Apple with a hidden email address and connect Google Calendar, the identifiers of your Google calendars (usually the email address of the Google account) will be saved in the copy of events in your account, and the Google account address in the calendar settings on the phone.

13.10. Revoking access and deletion. Sections 12.9 and 11.3 describe them.

14. Apple Health

14.1. What data and why. We read the data types in section 2.6 from Apple Health only to calculate energy and arrange the day plan in AcademiX.

14.2. What we do not do. We do not use data from Apple Health, or results calculated from it, for advertising, marketing or analysis for other purposes. We do not sell it and do not pass it to advertising platforms, data brokers or information resellers.

14.3. What leaves the phone. Only what section 4.3 describes. Results go to Anthropic only with Consent A and Consent B, and only so that the assistant can fit its proposals to your energy.

14.4. iCloud and notifications. We do not store raw data from Apple Health, readiness or energy windows in iCloud (iCloud Drive, CloudKit) and do not put them in notifications. The block times of an approved plan go to the calendar you choose. If this is Apple Calendar with iCloud syncing, Apple stores them in iCloud according to your settings. Section 4.3 describes the phone backup.

14.5. Writing to Apple Health. The app does not write data to Apple Health.

14.6. This is not a medical device. AcademiX helps you plan your day and is not a medical device. Readiness and energy windows are an estimate for planning, not an assessment of your health. For health matters, contact a doctor.

15. Age

15.1. From 16. AcademiX is for people who are 16 or older.

15.2. Statement. When you create an account, you tick the box “I am 16 or older and accept the terms of service”. Without it, you cannot create an account. We record the statement together with the acceptance of the terms (section 2.13). You make the statement that you are 16 or older again in the text of Consent A and Consent B: their text ends with the sentence “I confirm that I am 16 or older.” We record the version of this text together with the giving of consent (section 2.13).

15.3. Onboarding. Onboarding before you create an account has no separate question about age. If you give a consent already during onboarding, its text contains the statement that you are 16 or older (section 15.2). Until you sign in, onboarding answers are only on the phone. We save the onboarding profile in your account only after you accept the terms of service, where you confirm that you are 16 or older (section 2.8). Onboarding does not ask for an energy rating.

15.4. People under 16. If we learn that an account was created by a person under 16, we will delete that account together with its data.

15.5. People aged 16–17 use AcademiX, including the energy feature and the AI assistant, on the same terms as adults. They can withdraw any consent at any time and ask for deletion of the data collected on its basis (sections 10.3 and 10.8).

16. Security

16.1. Encrypted connections. The app connects to our server and to Google over encrypted connections (HTTPS).

16.2. Tokens. Sign-in tokens are stored in the iOS Keychain.

16.3. Access to data. In the database, your account has access only to your data. Server functions work only for a signed-in user. The assistant and Quick Add have limits: 20 and 30 requests per minute per account.

16.4. Encryption at providers. According to the providers' documents, Supabase and Anthropic encrypt data stored on their servers and data sent over the internet.

16.5. Less data for AI. We do not send your email address or account identifier to Anthropic. The app has no analytics or advertising tools.

16.6. Logs. Server function logs do not contain the content of your messages, events or tasks.

16.7. Breaches. No safeguard gives complete protection. If a personal data breach occurs, we will act in line with the GDPR: we will notify the President of UODO, and if the breach poses a high risk to you, we will inform you without undue delay.

16.8. What to watch out for. Sections 5.14 and 5.7 describe what goes to the AI provider and how to treat AI replies. Reminders with task titles appear on the lock screen if your iOS settings allow it, so protect your phone with a passcode. On a phone that several people use, sign out when you are done. The Apple Calendar connection is saved on the phone, so before another person signs in on it, disconnect Apple Calendar (section 12.9).

17. Profiling and automated decisions

17.1. What the energy result is. Readiness, the energy curve and energy windows are profiling within the meaning of the GDPR: based on health data, the app estimates how much energy you have today to help you plan your day.

17.2. How it works. The algorithm on the phone takes into account nights from the last 90 days (time of falling asleep and waking up, sleep quality, awakenings and sleep stages), HRV and resting heart rate compared with your own history, heart rate during the last night, today's steps, wrist temperature during sleep and blood oxygen saturation. From these, it estimates sleep debt and the times of day when you usually have more or less energy. Without current measurements (for example, when you do not wear a watch), it relies on the morning energy rating and the wake-up time. If you do not give a wake-up time today, the curve starts from your usual wake-up time from the onboarding answers. The end of the planning day is set by your usual bedtime until the algorithm knows it from your nights. Free days split the week when the rhythm is calculated from your nights. The algorithm calculates with fixed formulas, without artificial intelligence. When there is not enough data, the app shows a preview profile, that is, sample data that does not describe you.

17.3. What the result is used for. To show your energy level on the Today screen, to propose times in the day plan, for “what now” suggestions and, with both consents and a measured result, as context for the assistant.

17.4. What effects it has. The result only makes suggestions. No plan proposal goes into the calendar or tasks without your approval, and you can reject any proposal. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 of the GDPR).

17.5. Automatic task block. When you give a task a time and a duration, the app saves a block for it in your default calendar. When you delete the task, its time or its duration, the app deletes that block. The app also fills in the link between the task and its block in your account by itself. This is carrying out your instruction, not an assessment.

18. Turned-off features

18.1. Focus sessions (Deep Work) are turned off. The app does not create new sessions and does not send their data. There is no data from this feature on the server.

18.2. Old records. If this feature was used on this phone in an earlier test version, the session records (duration, readiness result at the start) stay on the phone until the app is deleted.

18.3. Before the feature returns, we will update this policy and the text of Consent A and ask you for consent again.

19. Changes to this policy

19.1. Versions. Every version of the policy has a date. You can find the current version at the address in section 1.5 and in the app.

19.2. Significant changes. We inform you in the app about significant changes, such as a new purpose, a new recipient or AI provider, new data sent from the phone, a new type of data from Apple Health, a change of controller or of how you exercise your rights, before the change takes effect.

19.3. New data and new uses. New data will not start leaving the phone before we update this policy and the consent screen. If a change goes beyond the consent you gave, we will ask for it again. Before we use data from Google in a new way or for a new purpose, we will show you the change in the app and ask for your consent.

19.4. Reviews. We review the policy before every app version that changes data processing, and after changes in the law or in providers' terms.

19.5. Version history.

  • 14 September 2026 — first version.
  • 16 September 2026 — data export in the app (sections 4.3, 4.4, 10.5); message about a failed revocation of Google access (section 11.3); focus session records and the export file in the list of data deleted from the phone (sections 4.4, 11.4, 11.9); disconnecting Google Calendar in the app — deletion of the copy of Google events from the account and revocation of access (sections 9.3, 12.9).

19.6. Language versions. This policy is drawn up in Polish. The English version is a translation. If the versions differ in meaning, the Polish version prevails. This does not limit the rights that consumer protection laws give you.

Questions? Write to kontakt@academix.pl.