Privacy Policy
Sunday is a to-do list that can do some of your tasks for you — drafting emails, preparing reviews, setting reminders and watching for replies — always holding anything outbound for your explicit approval. This policy explains exactly what we process to make that work.
What we collect
- Account information — your name (as you enter it), email address, and sign-in sessions.
- Your to-dos and content — the tasks you type, drafts Sunday prepares for you, your edits, approvals and completions.
- Connected-service data — only if you connect a tool (such as Gmail, Google Calendar, Google Drive, Notion or Slack): the emails, events, documents and messages those services return, used to ground Sunday's work for you. You choose what to connect; nothing is connected by default.
- Diagnostic records — server logs and receipts of actions Sunday performed on your behalf (for example, the ID of an email you approved and sent). We do not use third-party analytics or advertising SDKs, and the app contains no trackers.
What we do with it
- Provide the product: classify your to-dos, prepare drafts and reviews, schedule reminders and watches, and carry out actions you explicitly approve.
- Ground Sunday's work in your own context when you have connected tools.
- Keep an auditable record (receipts) of every action performed for you.
We do not sell your data, we do not use it for advertising, and we do not track you across other apps or websites.
AI processing
Sunday uses large language models to understand your to-dos and draft content. Relevant task text and grounding context are processed by our model providers (currently Google and OpenAI APIs) under their API data-use terms, which do not permit training on this data. Model output is always held for your review before anything leaves your account.
Where your data lives
Your data is stored with Supabase (hosted on AWS, Singapore region). Our processing servers run on Fly.io. Connected-service access tokens are stored encrypted and are destroyed when you disconnect a tool or delete your account. Data may be processed in countries other than your own; we apply the safeguards our processors provide.
Subprocessors
- Supabase (database, authentication)
- Fly.io (application servers)
- Google, OpenAI (model APIs)
- Google (OAuth for connected tools you choose)
Retention and deletion
- Your data is retained while your account is active.
- Delete your account any time in the app: Settings → Delete account. This permanently deletes your account, to-dos, receipts, and stored connector tokens immediately, and purges bulk synced data within 30 days.
- Content you contributed to a shared workspace remains with that workspace.
- Server logs are retained briefly for reliability and security.
Disconnecting tools
You can disconnect a connected tool at any time in the app; its stored access token is deleted. You can additionally revoke Sunday's access from your provider's security settings (for Google: myaccount.google.com → Security → Third-party access).
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict processing. Email support@n71.ai and we will honor them.
Security
All traffic is encrypted in transit (HTTPS). Access tokens are stored encrypted. Every consequential action requires your explicit approval and produces a receipt.
Changes
We will update this page when the policy changes and note the new effective date above. Material changes will be announced in the app.