Privacy Policy

Last updated: 29 July 2026

Who we are

Koaline is operated by 8BITES, David Rudman s.p., a sole proprietor registered in Slovenia, with registered office at Vrh pri Ljubnu 2B, 8000 Novo mesto. Matična številka: 8058865000. Davčna številka: 22436286 (not VAT-registered, pursuant to Article 76.a of ZDDV-1). We are the data controller for information collected through this site and can be reached at david@koaline.app.

What we collect

When you subscribe to our newsletter, we collect your email address. When you create an account in the Koaline app, we additionally collect information you provide (name, email, password hash) and data you enter as part of using the product (tasks, notes, time entries, linked integrations). The app sets a session cookie to keep you signed in — strictly necessary for the service to work, so it needs no consent banner. We do not use advertising pixels or third-party tracking cookies.

How we use it

Newsletter emails are used solely to send occasional product updates. Account data is used to provide the Koaline service itself — syncing tasks, storing notes, and tracking time. We won't sell or rent your data, and we don't share it with anyone except the service providers described in this policy and listed at koaline.app/subprocessors, who process it on our instructions. The legal basis for processing is your consent (GDPR Art. 6(1)(a)) for the newsletter, performance of contract (GDPR Art. 6(1)(b)) for app usage, and our legitimate interest (GDPR Art. 6(1)(f)) in keeping Koaline reliable and secure for product analytics and error monitoring. You can withdraw consent at any time.

Analytics and diagnostics

On this marketing site we use privacy-friendly, cookieless analytics that tell us things like page views and referrers in aggregate. They set no cookies, do not track you across sites, and collect no personal data — so no consent banner is required.

Inside the Koaline app we use a product-analytics service to understand how the product is used and an error-monitoring service to detect and diagnose failures, both running in their EU regions. These record product events, your user identifier, name, and email address, and technical error details. Both are configured so they do not capture the content you work with — see How we protect your data below.

Service providers and where data lives

Application data (tasks, notes, time entries, integration connections) is stored in a Postgres database inside the EU and served by our API, which also runs inside the EU. Beyond that, a small set of providers process data on our instructions: website and app hosting (which also handles newsletter sign-ups), product analytics, error monitoring, and transactional email (welcome and password-reset messages, using your name and email address). The current list of providers, with their roles and regions, is always at koaline.app/subprocessors.

Where a provider processes data outside the EU, the transfer is covered by appropriate safeguards (Standard Contractual Clauses).

How we protect your data

We treat account credentials, integration tokens, and the content you sync into Koaline — including Google user data — as sensitive, and protect them with the following measures.

Encryption

All traffic between your browser, our servers, and third-party APIs travels over HTTPS with TLS; we do not serve the app or accept API requests over unencrypted connections. Connections between our API and our database are TLS-encrypted and enforced server-side. OAuth access and refresh tokens for every connected integration, including Google Calendar, are encrypted with AES-256-GCM before they are written to the database, using a key held in a dedicated secrets manager and never stored in our source code or repository. Tokens received when you sign in with Google are likewise encrypted at rest. Data at rest is additionally encrypted at the storage layer by our database provider. Account passwords are stored only as salted one-way hashes — never in plaintext, and never recoverable by us.

Data minimisation

We store as little sensitive data as the product allows. We do not store the content of your Google Calendar events on our servers. Events are fetched from Google over TLS at the moment you view your schedule, held in memory only for the duration of that request, and rendered in your browser — they are never written to our database, and no copy remains after the request completes. The only Google-derived data we persist is your encrypted access and refresh tokens, the email address of the connected Google account, and the name, identifier, and colour of the calendars you chose to sync.

Access controls

We request the narrowest OAuth scopes that make the feature work, and no others. We do not request Google's broad calendar scope, never create or delete calendars, and never modify calendar sharing or permissions. Within Koaline, every database query is scoped to the authenticated user's own records at the data-access layer, so one account cannot read or modify another account's data. Sessions are validated on our server for every request.

Administrative access to our production systems and provider accounts is strictly limited — today that means the founder alone — and protected by multi-factor authentication. It is used solely for operating and maintaining the service or responding to a support request you have raised — never to browse your tasks, notes, or calendar content.

Diagnostics and analytics do not capture your content

Our error-monitoring and product-analytics tools are configured so that they do not collect the content you work with. Session recordings mask all form inputs and all on-screen text, capturing only layout and interaction patterns, and browser console output is not recorded. Access tokens, refresh tokens, passwords, and API keys are never written to application logs.

Retention and deletion

When you disconnect an integration in Koaline, the stored connection — including the encrypted access and refresh tokens — is deleted from our database immediately, and we stop making any further calls to that provider on your behalf. When your account is deleted, all associated records, including every integration connection and token, are removed by cascade. Beyond that, account data is kept only for as long as your account exists, newsletter addresses are kept until you unsubscribe, and product analytics and error diagnostics expire on our providers' standard retention schedules. You can request deletion at any time by emailing privacy@koaline.app.

Incident response

If we become aware of a personal data breach, we will notify the competent supervisory authority within 72 hours as required by GDPR Article 33, and inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34.

Google Calendar

If you connect Google Calendar, Koaline requests two calendar scopes — See and edit events on your calendars (calendar.events) and See the list of your calendars (calendar.calendarlist.readonly) — together with Google's basic identity scopes (openid, email, profile), which identify the connected account. We use these only to show your calendar next to your tasks and to let you create, reschedule, and delete events from within Koaline. We read the list of your calendars so you can choose which ones to sync. We never create or delete calendars and never change calendar sharing or permissions.

For calendars you enable, we access event details — title, description, start and end time, location, attendees, and meeting links — only for the date range you are viewing in Koaline. Nothing is fetched in the background.

How Google user data is protected. Event details are retrieved from Google over an encrypted TLS connection each time you view your schedule and are never written to our database — they exist only in memory for the duration of that request and in your browser while you are looking at them. The only Google data we store is your encrypted access and refresh tokens, the email address of the connected Google account, and the names, identifiers, and colours of the calendars you selected. Those tokens are encrypted with AES-256-GCM before being written, held on infrastructure inside the EU, and the encryption key is kept in a separate secrets manager. Google Calendar data is never included in our analytics or error-monitoring data: session recordings mask all inputs and on-screen text, and tokens are never logged. The full set of measures is described under How we protect your data.

You can disconnect Google Calendar at any time from your Koaline settings. Disconnecting deletes the stored connection and its encrypted tokens from our database immediately and stops all further access to your calendars. You can also revoke access directly from your Google Account permissions. Deleting your Koaline account removes all Google Calendar connections and tokens along with it.

Separately from Calendar, you can sign in to Koaline with your Google account. Sign-in uses only the basic identity scopes and gives us your name, email address, and profile picture, which become your Koaline account profile; the associated sign-in tokens are encrypted at rest.

Koaline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising, and we do not sell it or share it with third parties.

Your rights

You can request deletion of your data at any time by emailing privacy@koaline.app. Under the GDPR you also have the right to access, rectify, and port your data, to restrict or object to its processing, and to withdraw consent at any time. If you believe we have mishandled your data, you can lodge a complaint with the Slovenian Information Commissioner (Informacijski pooblaščenec) or your local supervisory authority.

Changes to this policy

When our practices change, we will update this page and revise the date at the top. For material changes we will give notice in the app or by email.

Questions?

Reach out at privacy@koaline.app.