Privacy Policy
Last updated: 2026-09-05
1. Introduction
Restivity ("we", "our", "us") is a productivity application that helps you manage tasks, projects, and time. This Privacy Policy explains how we collect, use, and protect your information when you use our service at restivity.ai.
The data controller (titolare del trattamento) is Leotech di Zaky Abanoub Adel Thabet, Via Calpurnio Pisone 111, 00175 Roma (RM), Italy — VAT IT18574271005, REA RM-1793795, PEC zaky.abanoub@pec.it. You can reach the controller at privacy@restivity.ai.
2. Information We Collect
We collect the following types of information:
- Account information: When you sign up, we collect your email address, display name, and profile photo (if provided via Google sign-in).
- App data: Tasks, projects, work sessions, and settings you create within the application.
- Google Calendar data:If you connect your Google account, we access your calendar events to display them alongside your tasks. We can also create or delete calendar events you explicitly ask us to manage from a task using the "Add to Calendar" button. We never modify events you did not create through Restivity.
- Newsletter subscribers: If you sign up for product news (site footer or help center), we store your email address, the language you chose, the time and version of the privacy policy you consented to, and the IP address and browser of the request — the proof of your consent. The subscription starts only after you confirm it from the email we send (double opt-in); requests that are never confirmed are deleted after 30 days.
- Usage data: Basic analytics to improve the service (page views, feature usage) via Vercel Analytics, plus a small set of product events (account created, onboarding completed, first task, first focus session, checkout started and completed) that carry no personal data.
3. How We Use Your Information
We use your information for the purposes below, each on a legal basis under Article 6 of the GDPR:
- To provide and maintain the Restivity service — accounts, tasks, projects, work sessions, teams and workspaces. Legal basis: performance of a contract (Art. 6(1)(b)).
- To authenticate you, secure your account and prevent abuse — session cookies, rate limits, security and error logs. Legal basis: performance of a contract and our legitimate interest in keeping the Service secure (Art. 6(1)(f)).
- To process payments and issue invoices for paid plans, and to keep the tax records the law requires. Legal basis: performance of a contract and compliance with a legal obligation (Art. 6(1)(c)).
- To display and manage your Google Calendar events within the app. Legal basis: your consent, given when you connect your Google account and revocable at any time (Art. 6(1)(a)).
- To run the AI assistant on the content you submit to it. Legal basis: performance of a contract — the assistant only runs when you invoke it.
- To send you service emails (account, workspace and notification emails) and, where you opted in, product news and digests — including the newsletter, which needs no account. Legal basis: performance of a contract for service emails; your consent for product emails and the newsletter, revocable from Settings or the unsubscribe link in every message. When you unsubscribe from the newsletter we keep your address only to make sure we do not write to it again.
- To improve the application from aggregated usage patterns (page views, feature usage). Legal basis: our legitimate interest in improving the Service. The analytics are cookieless and never identify you.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Data Storage and Security
Your data is stored securely using Supabase (PostgreSQL) with row-level security policies. All data is transmitted over HTTPS. We do not sell, rent, or share your personal data with third parties.
Retention: we keep your account data for as long as your account exists. When you delete your account it enters a recovery window of 30 days during which you can restore it; after that window it is permanently purged together with your tasks, projects, work sessions, the workspaces you own and your connected integrations. AI assistant conversations and in-app notifications are deleted after 90 days. Invoices you have issued, and their frozen billing lines, are kept for 10 years after issue as required by Italian tax law, even if you delete your account. Security and error logs are retained for up to 90 days. Encrypted backups kept by our hosting providers for disaster recovery expire on a rolling schedule.
5. Third-Party Services
We use the following third-party services:
- Supabase: Authentication and database hosting (EU region)
- Vercel: Application hosting and analytics
- Google: OAuth sign-in and Calendar integration (optional)
- Polar: Payment processing. Polar Software Inc. acts as Merchant of Record for paid plans: it is the seller of record and processes your billing identity, order, invoice, and tax data. We never see or store your card details.
- Resend: Transactional email delivery (account, team, and notification emails). Receives your email address and the content of the emails we send you.
- OpenAI and Anthropic:AI assistant processing. When you use the AI assistant (or the optional AI title suggestions), the content you submit and the task/project context needed to answer are sent to OpenAI and/or Anthropic APIs for processing. We do not use your data to train their models (API traffic is excluded from training per both providers' API terms), and the assistant only runs when you invoke it.
- Sentry: Error tracking. Receives exception stack traces and breadcrumbs strictly when an error occurs. OAuth secrets and request bodies are scrubbed before transmission.
- BetterStack: Operational diagnostics (EU region — Frankfurt). Receives anonymous OAuth event metadata (event name, OAuth client identifier, error code) for service-quality monitoring. No user identifiers, IP addresses, or request bodies are transmitted.
- Third-party agents (Dynamic Client Registration, RFC 7591): When you authorize a third-party AI tool (e.g. Claude.ai, ChatGPT, Cursor) to connect to your Restivity account through its native Custom Connector / MCP UI, the tool registers itself with Restivity at the moment you paste the connector URL. The tool becomes a sub-processor for as long as you keep it connected and receives ONLY the data covered by the OAuth scopes you explicitly authorize on the consent screen (e.g. `tasks:read`). Vendor-supplied metadata (display name, logo, terms-of-service URL, privacy-policy URL) is stored to render the consent screen and to audit-trail any abuse incidents. You can revoke the integration at any time via Settings → Integrations or via your account permissions on the third-party side.
International transfers:Your core application data (database, authentication, file storage) is hosted in the EU (AWS Frankfurt, via Supabase), application compute runs in Frankfurt (Vercel), and error telemetry is stored in Sentry's EU region. Some of the providers above (Vercel, Polar, Resend, OpenAI, Anthropic, Google) are US companies and may process certain data in the United States. Where that happens, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
6. Google User Data
Restivity's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Accessed
When you sign in with Google or connect your Google account, Restivity accesses:
- Basic profile information: Your name, email address, and profile photo, used solely to create and display your Restivity account.
- Google Calendar events:If you grant calendar access, we retrieve your calendar events to display them alongside your tasks within the app, and we can create or delete events you explicitly ask us to create from a task (the "Add to Calendar" timeboxing button). We request the
calendar.eventsscope, meaning we can read, create, and delete events on your calendar. We never create, edit, or delete events you did not ask us to manage from inside Restivity.
Data Usage
Google user data is used exclusively to:
- Authenticate your identity and maintain your session
- Display your name and profile photo within the Restivity interface
- Show your Google Calendar events in the Restivity calendar view
Data Storage and Sharing
- Google Calendar event data is fetched in real-time and is not permanently stored in our database.
- Your Google profile information (name, email, photo URL) is stored in your Restivity user profile.
- We do not sell, share, or transfer your Google user data to any third party.
- We do not use your Google user data for advertising or profiling purposes.
Revoking Access
You can disconnect your Google account from Restivity at any time through your account settings. You can also revoke Restivity's access directly from your Google Account Permissions.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Disconnect third-party integrations (e.g., Google Calendar) at any time
- Lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it)
- Receive a copy of your data in a portable format (data portability)
- Request restriction of processing, or object to processing based on our legitimate interests
- Withdraw a consent you have given (for example, disconnecting Google Calendar or unsubscribing from product emails) at any time, without affecting the lawfulness of processing before the withdrawal
8. Cookies
We use only first-party cookies and browser storage, and no third-party tracking cookies. Usage analytics (Vercel Analytics) are cookieless.
- Authentication and session: the Supabase session cookies (
sb-…-auth-token),restivity_active_accountandrestivity_active_workspace(which account and workspace you are working in),restivity_csrf(protects forms against cross-site requests) andgoogle_connect_state(lives only for the seconds of a Google connection). Essential — the Service does not work without them. - Preferences:
NEXT_LOCALE(language, mirrored in browser storage asi18nextLng),rv_onboarded,rv_acct_changes_last_seen,rv_comeback_seen,restivity_helpandrv_tz_notice(browser storage) remember choices you made in the interface so we do not ask again. They contain no personal data beyond the choice itself. - Attribution:
rv_ftremembers the campaign parameters, the referring site and the landing page of your first visit for 90 days, so we know which channel brought you; it is read once, when an account is created, and never afterwards. - Administration:
rv_impersonationandrv_admin_railexist only in Restivity staff sessions.
9. Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes via the application.
10. Contact
If you have questions about this privacy policy, contact us at privacy@restivity.ai.