Last updated September 17, 2026
Privacy
Privacy policy for the Cadence marketing site and hosted personal behavior tracker.
Scope and operator
This policy describes the Cadence marketing site and hosted personal behavior tracker operated by Identity Scaffolding LLC, a Wyoming limited liability company assumed authorized in New York, at 30 N Gould St Ste R, Sheridan, WY 82801.
The public marketing site presents product information. It does not use marketing analytics, advertising pixels, payment tracking, or social tracking. Hosting infrastructure may still process ordinary request data such as an IP address, browser details, requested path, and request time.
Account and behavior data
Google sign-in can provide an account identifier, email address, and profile information. Cadence stores the profile timezone and the records needed to operate the account.
Those records can include categories, Behaviors, Schedules, reminders, Occurrences, Decisions, notes, optional timing data, definition and Decision history, imports, export activity, push subscriptions, and reminder delivery records.
Notes are free text. Users should not enter information they do not want stored in Cadence.
Optional Google Calendar
The Google Calendar connector is optional and currently limited to Google OAuth test users while the app remains in Testing mode. Where enabled, it requires separate read-only consent for the same Google account used to sign in. Cadence reads your subscribed calendar list so you can choose calendars, then reads events from selected calendars intersecting displayed days, including readable titles, descriptions, times, locations, organizers, attendees, conference details, attachment links, and Google event links. It does not create, edit, or delete Google events or download attachments automatically.
Cadence uses Calendar information to show selected events in Timeline and provide advisory overlap context. It does not sell Calendar information, use it for advertising, or send it to AI providers.
Vercel runtime processes Calendar API requests and returned event details while serving a refresh. Supabase stores the account's connector status, calendar selections, display preferences, and encrypted Google refresh credential. Cadence does not store Google event details in its hosted database. The web app holds returned event details in memory. Desktop can store the last complete normalized event snapshot in a separate account-bound cache for offline display; its account session and pending consent state use macOS Keychain.
Calendar details and credentials are excluded from Cadence exports, account synchronization, and user-created desktop tracking backups. Supabase daily infrastructure backups can retain deleted connector records and sealed credential ciphertext for no more than seven days.
Disconnect Google Calendar marks the account connection disconnected, clears selected calendar IDs, deletes the live server credential, and requests Google grant revocation. If Google cannot confirm revocation, the user must remove Cadence in Google Account permissions. Other clients stop refreshing after they next receive the connection change; an offline desktop device may retain stale cached event details until it reconnects or its Cadence account is disconnected.
Ordinary web sign-out ends that browser's Cadence session but leaves the account-level Calendar connection active. Desktop Cadence account disconnect or reconnect clears that Mac's Calendar cache and pending consent state but does not revoke the global Google grant. Account deletion attempts revocation and removes the live Auth user and owner-scoped connector records. If revocation fails, Google Account permissions may still show the grant.
Cadence's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Read the Google API Services User Data PolicyExports and external AI services
Cadence provides JSONL, JSON, CSV, Markdown, BehaviorLog bundle exports. The user chooses when and where to download or share an export.
Cadence provides prepared prompts, but it does not send behavior data to an AI provider. If a user shares an export or prompt with an external AI service, that service's terms and privacy policy govern its processing.
How Cadence uses data
Cadence uses data to authenticate accounts, generate scheduled Occurrences, display records, save explicit Decisions and notes, provide optional timing, send configured reminders, calculate basic analytics, create exports, secure the service, prevent abuse, diagnose failures, and respond to requests.
Cadence does not sell personal information or share it for cross-context behavioral advertising. Cadence does not automatically turn an Unresolved Occurrence into a failure.
Processors
Cadence uses the following service providers for the stated purposes. A provider processes data under its own service terms and the operator's configuration.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application and marketing hosting, including Calendar refresh processing | Request and runtime data, including returned Calendar details during a refresh |
| Supabase | Google authentication and database storage | Account and Cadence records, Calendar connector records, selections, and sealed credential ciphertext |
| User-selected Google sign-in and optional Google Calendar consent and API access | Google account, authentication, selected-calendar, and readable event data | |
| Browser push services | Optional browser reminders | Push endpoint and reminder delivery data |
| Sequenzy | Optional email reminders | Email address and reminder message data |
| Microsoft 365 | Privacy, support, and dispute correspondence | Contact details and message content |
Retention
Cadence uses the retention periods below. A provider may delete data sooner. Specific records may be kept longer when required for a security investigation, fraud prevention, or legal preservation.
Provider settings and published capabilities were verified before this policy took effect.
| Record | Retention period | Active control |
|---|---|---|
| Routine logs | No more than 7 days | Vercel Pro runtime logs: 1 day; Supabase Pro API and database logs: 7 days |
| Security-incident logs | Up to 90 days or the end of the investigation | Records are preserved only when needed for an active investigation |
| Backups | No more than 7 days | Supabase Pro daily backups: 7 days |
| Deleted-account live data | Immediately or within 7 days | Auth deletion and database cascades remove live account data immediately when deletion succeeds |
| Deleted-account backup remnants | No more than 7 days | Supabase daily backups: 7 days |
| Google Calendar connector records | Live credential until Calendar disconnect, access revocation, or account deletion; connector status and preferences until account deletion | Disconnect deletes the live credential; Supabase daily backup remnants retain for no more than 7 days |
| Desktop Google Calendar cache | Until replacement, Calendar disconnect, Cadence account disconnect or reconnect, or local app-data removal | Separate local cache; excluded from Cadence exports, account synchronization, and user-created desktop backups |
| Browser-push payloads | No more than 24 hours after send | Cadence sends a 24-hour TTL; the push service may retain the payload for less |
| Sequenzy transactional data | Under Sequenzy's active service terms and controls | Subscriber data remains while the account is active and is deleted within 30 days after account termination |
| Support messages | 12 months after resolution | Microsoft 365 mailbox retention is configured for this period |
Security
Cadence uses Google sign-in through Supabase Auth, account-scoped database Row Level Security, server-side privileged operations, secret scanning, and export and account-deletion controls.
No internet service is completely secure. Users should protect their Google account, sign out on shared devices, and avoid placing sensitive information in free-text notes.
User choices and deletion
Users can export records as JSONL, JSON, CSV, Markdown, BehaviorLog bundle, manage reminder choices, edit their records, and delete their account in Settings. Export needed records before deletion because account deletion is permanent.
A user can deny browser notification permission or leave optional email reminders disabled. Required account and service processing cannot be disabled while using the hosted tracker.
Children and international access
Cadence is only for people age 18 or older. Cadence is not directed to children and does not knowingly permit anyone under 18 to register.
Cadence operates from the United States. A person who accesses Cadence from another country understands that data may be processed in the United States and other places where the listed providers operate, subject to applicable law.
California disclosures
Cadence does not sell personal information or share it for cross-context behavioral advertising. Cadence has no actual knowledge that it sells or shares personal information of people under 16.
Subject to applicable law, California residents may request access, correction, deletion, or a copy of personal information and may exercise privacy rights without discriminatory treatment. Cadence may verify a request before acting.
Changes and contact
Identity Scaffolding LLC may update this policy when Cadence, its providers, or legal requirements change. A material update will receive a new date and any notice required by law.
Privacy questions and requests may be sent to privacy@identityscaffolding.com or mailed to Identity Scaffolding LLC, 30 N Gould St Ste R, Sheridan, WY 82801.