Last updated September 17, 2026

Privacy

Privacy policy for the Cadence marketing site and hosted personal behavior tracker.

Scope and operator

This policy describes the Cadence marketing site and hosted personal behavior tracker operated by Identity Scaffolding LLC, a Wyoming limited liability company assumed authorized in New York, at 30 N Gould St Ste R, Sheridan, WY 82801.

The public marketing site presents product information. It does not use marketing analytics, advertising pixels, payment tracking, or social tracking. Hosting infrastructure may still process ordinary request data such as an IP address, browser details, requested path, and request time.

Account and behavior data

Google sign-in can provide an account identifier, email address, and profile information. Cadence stores the profile timezone and the records needed to operate the account.

Those records can include categories, Behaviors, Schedules, reminders, Occurrences, Decisions, notes, optional timing data, definition and Decision history, imports, export activity, push subscriptions, and reminder delivery records.

Notes are free text. Users should not enter information they do not want stored in Cadence.

Optional Google Calendar

The Google Calendar connector is optional and currently limited to Google OAuth test users while the app remains in Testing mode. Where enabled, it requires separate read-only consent for the same Google account used to sign in. Cadence reads your subscribed calendar list so you can choose calendars, then reads events from selected calendars intersecting displayed days, including readable titles, descriptions, times, locations, organizers, attendees, conference details, attachment links, and Google event links. It does not create, edit, or delete Google events or download attachments automatically.

Cadence uses Calendar information to show selected events in Timeline and provide advisory overlap context. It does not sell Calendar information, use it for advertising, or send it to AI providers.

Vercel runtime processes Calendar API requests and returned event details while serving a refresh. Supabase stores the account's connector status, calendar selections, display preferences, and encrypted Google refresh credential. Cadence does not store Google event details in its hosted database. The web app holds returned event details in memory. Desktop can store the last complete normalized event snapshot in a separate account-bound cache for offline display; its account session and pending consent state use macOS Keychain.

Calendar details and credentials are excluded from Cadence exports, account synchronization, and user-created desktop tracking backups. Supabase daily infrastructure backups can retain deleted connector records and sealed credential ciphertext for no more than seven days.

Disconnect Google Calendar marks the account connection disconnected, clears selected calendar IDs, deletes the live server credential, and requests Google grant revocation. If Google cannot confirm revocation, the user must remove Cadence in Google Account permissions. Other clients stop refreshing after they next receive the connection change; an offline desktop device may retain stale cached event details until it reconnects or its Cadence account is disconnected.

Ordinary web sign-out ends that browser's Cadence session but leaves the account-level Calendar connection active. Desktop Cadence account disconnect or reconnect clears that Mac's Calendar cache and pending consent state but does not revoke the global Google grant. Account deletion attempts revocation and removes the live Auth user and owner-scoped connector records. If revocation fails, Google Account permissions may still show the grant.

Cadence's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Read the Google API Services User Data Policy

Exports and external AI services

Cadence provides JSONL, JSON, CSV, Markdown, BehaviorLog bundle exports. The user chooses when and where to download or share an export.

Cadence provides prepared prompts, but it does not send behavior data to an AI provider. If a user shares an export or prompt with an external AI service, that service's terms and privacy policy govern its processing.

How Cadence uses data

Cadence uses data to authenticate accounts, generate scheduled Occurrences, display records, save explicit Decisions and notes, provide optional timing, send configured reminders, calculate basic analytics, create exports, secure the service, prevent abuse, diagnose failures, and respond to requests.

Cadence does not sell personal information or share it for cross-context behavioral advertising. Cadence does not automatically turn an Unresolved Occurrence into a failure.

Processors

Cadence uses the following service providers for the stated purposes. A provider processes data under its own service terms and the operator's configuration.

Cadence service providers and purposes
ProviderPurposeData involved
VercelApplication and marketing hosting, including Calendar refresh processingRequest and runtime data, including returned Calendar details during a refresh
SupabaseGoogle authentication and database storageAccount and Cadence records, Calendar connector records, selections, and sealed credential ciphertext
GoogleUser-selected Google sign-in and optional Google Calendar consent and API accessGoogle account, authentication, selected-calendar, and readable event data
Browser push servicesOptional browser remindersPush endpoint and reminder delivery data
SequenzyOptional email remindersEmail address and reminder message data
Microsoft 365Privacy, support, and dispute correspondenceContact details and message content

Retention

Cadence uses the retention periods below. A provider may delete data sooner. Specific records may be kept longer when required for a security investigation, fraud prevention, or legal preservation.

Provider settings and published capabilities were verified before this policy took effect.

Cadence retention periods as of August 31, 2026
RecordRetention periodActive control
Routine logsNo more than 7 daysVercel Pro runtime logs: 1 day; Supabase Pro API and database logs: 7 days
Security-incident logsUp to 90 days or the end of the investigationRecords are preserved only when needed for an active investigation
BackupsNo more than 7 daysSupabase Pro daily backups: 7 days
Deleted-account live dataImmediately or within 7 daysAuth deletion and database cascades remove live account data immediately when deletion succeeds
Deleted-account backup remnantsNo more than 7 daysSupabase daily backups: 7 days
Google Calendar connector recordsLive credential until Calendar disconnect, access revocation, or account deletion; connector status and preferences until account deletionDisconnect deletes the live credential; Supabase daily backup remnants retain for no more than 7 days
Desktop Google Calendar cacheUntil replacement, Calendar disconnect, Cadence account disconnect or reconnect, or local app-data removalSeparate local cache; excluded from Cadence exports, account synchronization, and user-created desktop backups
Browser-push payloadsNo more than 24 hours after sendCadence sends a 24-hour TTL; the push service may retain the payload for less
Sequenzy transactional dataUnder Sequenzy's active service terms and controlsSubscriber data remains while the account is active and is deleted within 30 days after account termination
Support messages12 months after resolutionMicrosoft 365 mailbox retention is configured for this period

Security

Cadence uses Google sign-in through Supabase Auth, account-scoped database Row Level Security, server-side privileged operations, secret scanning, and export and account-deletion controls.

No internet service is completely secure. Users should protect their Google account, sign out on shared devices, and avoid placing sensitive information in free-text notes.

User choices and deletion

Users can export records as JSONL, JSON, CSV, Markdown, BehaviorLog bundle, manage reminder choices, edit their records, and delete their account in Settings. Export needed records before deletion because account deletion is permanent.

A user can deny browser notification permission or leave optional email reminders disabled. Required account and service processing cannot be disabled while using the hosted tracker.

Children and international access

Cadence is only for people age 18 or older. Cadence is not directed to children and does not knowingly permit anyone under 18 to register.

Cadence operates from the United States. A person who accesses Cadence from another country understands that data may be processed in the United States and other places where the listed providers operate, subject to applicable law.

California disclosures

Cadence does not sell personal information or share it for cross-context behavioral advertising. Cadence has no actual knowledge that it sells or shares personal information of people under 16.

Subject to applicable law, California residents may request access, correction, deletion, or a copy of personal information and may exercise privacy rights without discriminatory treatment. Cadence may verify a request before acting.

Changes and contact

Identity Scaffolding LLC may update this policy when Cadence, its providers, or legal requirements change. A material update will receive a new date and any notice required by law.

Privacy questions and requests may be sent to privacy@identityscaffolding.com or mailed to Identity Scaffolding LLC, 30 N Gould St Ste R, Sheridan, WY 82801.