Privacy Policy
Effective date: 11 October 2026
Algorithm is designed to keep personal planning data private and to request only the access needed for features a user chooses to use.
Information Algorithm processes
- Guest workspaces are stored in the browser's local storage and IndexedDB. They are not synchronised unless the user signs in and chooses to merge them into an account.
- Signed-in workspaces use a Google identity for authentication and store the user's email, account identifier, workspace records, and reminder state in Supabase. Workspace rows are restricted to their owner.
- Email reminders send the subject and message created by the user to the user's configured recipient through the reminder service and its email delivery provider. Delivery status is retained so retries are not duplicated.
- When link-title lookup is requested, the submitted public URL is sent to Algorithm's metadata endpoint so its public title can be retrieved. Private and local-network targets are rejected.
Google user data
Google Sign-In supplies the identity information needed to authenticate an Algorithm
account. Google Drive access is separate and optional. Algorithm requests
https://www.googleapis.com/auth/drive.file only after the user chooses a Drive
action. This permission lets Algorithm access a PDF or folder the user explicitly selects
through Google Picker; it does not grant general access to the user's Drive.
The selected PDF and short-lived Drive access token are handled in the browser. Algorithm does not send the token or PDF bytes to Supabase, the reminder service, workspace sync, or ordinary workspace backups. If the user explicitly chooses Save PDF + annotations, the PDF and its notes are stored only in that browser's IndexedDB. A signed-in user may persist the ID and name of an explicitly mounted folder in workspace sync. For PDFs opened from that mount, Algorithm reads and writes `.algorithm-pdf-annotations.json` in the selected folder so meanings and notes can follow the document across Algorithm sessions. The sidecar is governed by that folder's Drive sharing permissions and can be removed by the user.
Algorithm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising, used to determine creditworthiness, or provided to humans except when the user explicitly asks for support and access is necessary with their consent, or when required by law.
Sharing and service providers
Algorithm relies on Cloudflare for website delivery, Supabase for authentication and private synchronisation, Google for identity and optional Drive selection, and an email delivery provider for requested reminder messages. These providers process only the data required for their role. Algorithm does not sell personal information.
Choices, retention and deletion
Guests can export or clear browser data. Signed-in users can export their workspace, unmount Drive folders, delete a mounted folder's annotation sidecar in Drive, and revoke Google access from their Google Account. To request account-data deletion or obtain help, email saahilw26@gmail.com. Data may be retained temporarily where necessary for backup integrity, security, fraud prevention, or legal obligations.
Security and changes
Algorithm uses HTTPS, provider-managed authentication, and owner-scoped database controls. No system can guarantee absolute security. Material changes to this policy will be posted here with an updated effective date.
Algorithm