1. Scope and operator
This Privacy Policy applies to SupaTodo, a personal research prototype hosted at a Cloudflare Workers address and backed by a Supabase project. It does not apply to any employer, enterprise platform, production system, or separate service.
The prototype is operated by the project owner who provided access. Privacy requests should be made through the same channel through which access to the prototype was provided. A dedicated public privacy contact, formal controller address, and production request workflow have not yet been established.
2. Information processed
| Category | Examples | Source |
|---|---|---|
| Account and identity | Supabase user UUID, anonymous-account status, optional email address, verification and sign-in timestamps. | Created by Supabase Auth or supplied by you. |
| Task content | Task title, completion status, creation time, update time, and owning user UUID. | Entered or changed by you. |
| Session data | Authentication tokens, pending email state, and a timestamp used to prevent repeated email requests. | Stored locally by your browser. |
| Technical and security data | IP address, request URL, browser or device information, timestamps, routing data, errors, and security events. | Processed by Cloudflare, Supabase, and their infrastructure when you use the service. |
The prototype does not intentionally collect payment information, precise location, address-book contacts, advertising identifiers, or analytics profiles.
3. Why information is used
- Authenticate a guest or verified email account and maintain the session.
- Create, read, update, and delete tasks for the correct user.
- Enforce row-level authorization and prevent one user from accessing another user’s tasks.
- Send requested verification or magic-link emails.
- Operate, troubleshoot, secure, and evaluate the prototype.
- Comply with applicable legal obligations and respond to valid legal requests.
Where a legal basis is required, processing is generally performed to provide functionality you request, based on your choice to supply an email, and for legitimate interests in operating and securing the prototype. The exact legal basis may vary by jurisdiction.
4. Browser storage and tracking
The application uses browser local storage to maintain the Supabase session, remember an email-verification state, and enforce a local cooldown between authentication-email requests. Clearing browser storage can remove an anonymous session and permanently prevent you from recovering that guest account.
The prototype does not intentionally use advertising cookies, behavioral analytics, cross-site tracking pixels, or profiling technologies. Cloudflare and Supabase may process technical request data as necessary to deliver and protect their services.
6. Retention and deletion
- Tasks remain until you delete them, the related Auth user is deleted, the prototype is reset, or the project is discontinued.
- Anonymous Supabase users are not automatically cleaned up by the current prototype.
- Authentication and infrastructure logs are retained according to the project plan, provider configuration, security needs, and provider policies.
- Browser-local session data remains until it expires, is replaced, you sign out, or browser storage is cleared.
This research build does not yet provide a self-service account-deletion or data-export screen. Requests should be made through the project owner. Identity verification may be required before fulfilling a request.
7. Security controls
The prototype uses encrypted HTTPS connections, Supabase Auth tokens, a public client key intended for browser use, PostgreSQL grants, and row-level security policies tied to the authenticated user UUID. Cloudflare supplies network delivery and security controls.
No system is completely secure. Do not submit passwords, API keys, financial data, health data, government identifiers, confidential enterprise information, or other sensitive or regulated data.
8. Your choices and rights
Depending on applicable law, you may have rights to know, access, correct, update, delete, restrict, object to, or obtain a copy of personal information. Colombian data-protection rules, for example, recognize rights to know, update, rectify, and in appropriate cases suppress personal data or revoke authorization.
- You can view and delete individual tasks in the application.
- You can choose guest use without supplying an email.
- You can attach an email to make a guest account recoverable.
- You can sign out and clear browser-local data, but doing so may make an unsaved guest account unrecoverable.
Requests that cannot be completed in the interface should be directed to the project owner through the access channel.
9. International processing
Cloudflare and Supabase operate infrastructure and use subprocessors in multiple countries. Information may therefore be processed outside your country of residence. Provider contractual safeguards and applicable transfer mechanisms govern their processing where required.
10. Children
SupaTodo is not directed to children and should not be used by anyone who cannot legally consent to the processing described here. The prototype does not knowingly solicit information from children.
11. Changes and contact
This policy may change as the prototype evolves. The effective date and version at the top of the page identify the current policy. Material changes should be reviewed before continuing to use the prototype.
For privacy questions or requests, contact the project owner through the same channel used to provide access. Before any public or production release, the operator should publish a verified privacy email, legal identity, address, response procedure, and jurisdiction-specific notices.